{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T03:45:31Z","timestamp":1772163931294,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2006,10,20]],"date-time":"2006-10-20T00:00:00Z","timestamp":1161302400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2006,10,20]]},"DOI":"10.1145\/1168857.1168862","type":"proceedings-article","created":{"date-parts":[[2007,1,16]],"date-time":"2007-01-16T20:15:56Z","timestamp":1168978556000},"page":"25-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["Temporal search"],"prefix":"10.1145","author":[{"given":"Jedidiah R.","family":"Crandall","sequence":"first","affiliation":[{"name":"University of California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gary","family":"Wassermann","sequence":"additional","affiliation":[{"name":"University of California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniela A. S.","family":"de Oliveira","sequence":"additional","affiliation":[{"name":"University of California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhendong","family":"Su","sequence":"additional","affiliation":[{"name":"University of California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S. Felix","family":"Wu","sequence":"additional","affiliation":[{"name":"University of California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frederic T.","family":"Chong","sequence":"additional","affiliation":[{"name":"University of California"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2006,10,20]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.37"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/874075.876409"},{"key":"e_1_3_2_1_3_1","first-page":"169","volume-title":"USENIX Security Symposium","author":"Christodorescu M.","year":"2003","unstructured":"M. Christodorescu and S. Jha . Static Analysis of Executables to Detect Malicious Patterns . USENIX Security Symposium , pages 169 -- 186 , August 2003 .]] M. Christodorescu and S. Jha. Static Analysis of Executables to Detect Malicious Patterns. USENIX Security Symposium, pages 169--186, August 2003.]]"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.20"},{"key":"e_1_3_2_1_5_1","volume-title":"Model Checking","author":"Clarke E.M.","year":"1999","unstructured":"E.M. Clarke , O. Grumberg , and D.A. Peled . Model Checking . MIT Press , 1999 .]] E.M. Clarke, O. Grumberg, and D.A. Peled. Model Checking. MIT Press, 1999.]]"},{"key":"e_1_3_2_1_6_1","first-page":"240","volume-title":"7th DoD\/NBS Computer Security Conference Proceedings","author":"Cohen F.","year":"1984","unstructured":"F. Cohen . Computer viruses : Theory and experiments . In 7th DoD\/NBS Computer Security Conference Proceedings , pages 240 -- 263 , September 1984 .]] F. Cohen. Computer viruses: Theory and experiments. In 7th DoD\/NBS Computer Security Conference Proceedings, pages 240--263, September 1984.]]"},{"key":"e_1_3_2_1_7_1","volume-title":"On the Revolutions of Heavenly Spheres. (Available from Prometheus Books","author":"Copernicus N.","unstructured":"N. Copernicus . On the Revolutions of Heavenly Spheres. (Available from Prometheus Books , Amherst , New York ), 1543.]] N. Copernicus. On the Revolutions of Heavenly Spheres. (Available from Prometheus Books, Amherst, New York), 1543.]]"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.4"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.26"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102152"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_3"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_3"},{"key":"e_1_3_2_1_13_1","volume-title":"A Discipline of Programming","author":"Dijkstra E.W.","year":"1976","unstructured":"E.W. Dijkstra . A Discipline of Programming . Prentice-Hall , 1976 .]] E.W. Dijkstra. A Discipline of Programming. Prentice-Hall, 1976.]]"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/844128.844148"},{"key":"e_1_3_2_1_15_1","volume-title":"July","author":"Security Eye Digital","year":"2001","unstructured":"e Eye Digital Security . Advisories and Alerts : . ida Code Red Worm , July 2001 .]] eEye Digital Security. Advisories and Alerts: .ida Code Red Worm, July 2001.]]"},{"key":"e_1_3_2_1_16_1","volume-title":"ARO-DARPA-DHS Special Workshop on Botnets","author":"Franklin J.","year":"2006","unstructured":"J. Franklin , M. Luk , J. McCune , A. Seshadri , A. Perrig , and L. van Doorn . Remote virtual machine monitor detection . Presented at the ARO-DARPA-DHS Special Workshop on Botnets , June , 2006 .]] J. Franklin, M. Luk, J. McCune, A. Seshadri, A. Perrig, and L. van Doorn. Remote virtual machine monitor detection. Presented at the ARO-DARPA-DHS Special Workshop on Botnets, June, 2006.]]"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945464"},{"key":"e_1_3_2_1_18_1","volume-title":"Network and Distributed System Security Symposium","author":"Garfinkel T.","year":"2003","unstructured":"T. Garfinkel and M. Rosenblum . A Virtual Machine Introspection Based Architecture for Intrusion Detection . Network and Distributed System Security Symposium , 2003 .]] T. Garfinkel and M. Rosenblum. A Virtual Machine Introspection Based Architecture for Intrusion Detection. Network and Distributed System Security Symposium, 2003.]]"},{"key":"e_1_3_2_1_19_1","volume-title":"Tenth Workshop on Hot Topics in Operating Systems (HotOS)","author":"Garfinkel T.","year":"2005","unstructured":"T. Garfinkel and M. Rosenblum . When Virtual is Harder than Real: Security Challenges in Virtual Machine Based Computing Environments . Tenth Workshop on Hot Topics in Operating Systems (HotOS) , June 2005 .]] T. Garfinkel and M. Rosenblum. When Virtual is Harder than Real: Security Challenges in Virtual Machine Based Computing Environments. Tenth Workshop on Hot Topics in Operating Systems (HotOS), June 2005.]]"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.20"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1118605"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095820"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.38"},{"key":"e_1_3_2_1_26_1","volume-title":"Operating System Support for Virtual Machines. In USENIX Security Symposium","author":"King S.T.","year":"2003","unstructured":"S.T. King , G.W. Dunlap , and P.M. Chen . Operating System Support for Virtual Machines. In USENIX Security Symposium , 2003 .]] S.T. King, G.W. Dunlap, and P.M. Chen. Operating System Support for Virtual Machines. In USENIX Security Symposium, 2003.]]"},{"key":"e_1_3_2_1_27_1","volume-title":"Network and Distributed System Security Symposium","author":"King S.T.","year":"2005","unstructured":"S.T. King , Z.M. Mao , D.G. Lucchetti , and P.M. Chen . Enriching Intrusion Alerts through Multi-Host Causality . Network and Distributed System Security Symposium , February 2005 .]] S.T. King, Z.M. Mao, D.G. Lucchetti, and P.M. Chen. Enriching Intrusion Alerts through Multi-Host Causality. Network and Distributed System Security Symposium, February 2005.]]"},{"key":"e_1_3_2_1_28_1","volume-title":"Usenix Security Symposium","author":"Kirda E.","year":"2006","unstructured":"E. Kirda , C. Kruegel , G. Banks , G. Vigna , and R. Kemmerer . Behavior-based spyware detection . In Usenix Security Symposium , 2006 .]] E. Kirda, C. Kruegel, G. Banks, G. Vigna, and R. Kemmerer. Behavior-based spyware detection. In Usenix Security Symposium, 2006.]]"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.18"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972384"},{"key":"e_1_3_2_1_31_1","volume-title":"USENIX Security Symposium","author":"Kruegel C.","year":"2004","unstructured":"C. Kruegel , W. Robertson , F. Valeur , and G. Vigna . Static disassembly of obfuscated binaries . In USENIX Security Symposium , 2004 .]] C. Kruegel,W. Robertson, F. Valeur, and G. Vigna. Static disassembly of obfuscated binaries. In USENIX Security Symposium, 2004.]]"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.19"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/359545.359563"},{"key":"e_1_3_2_1_34_1","unstructured":"LURHQ Threat Intelligence Group. Key Dates in Past and Present Sober Variants. http:\/\/www.lurhq.com\/soberdates.html.]]  LURHQ Threat Intelligence Group. Key Dates in Past and Present Sober Variants. http:\/\/www.lurhq.com\/soberdates.html.]]"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/264107.264146"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_3_2_1_37_1","volume-title":"Sanos source","author":"Ringgaard M.","year":"2002","unstructured":"M. Ringgaard . Sanos source , 2002 .]] M. Ringgaard. Sanos source, 2002.]]"},{"key":"e_1_3_2_1_38_1","volume-title":"USA","author":"Rivest R.L.","year":"1996","unstructured":"R.L. Rivest , A. Shamir , and D.A. Wagner . Time-lock puzzles and timed-release crypto. Technical report, Cambridge, MA , USA , 1996 .]] R.L. Rivest, A. Shamir, and D.A. Wagner. Time-lock puzzles and timed-release crypto. Technical report, Cambridge, MA, USA, 1996.]]"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.176"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095812"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102170"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/859618.859657"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31979-5_9"},{"key":"e_1_3_2_1_44_1","volume-title":"The sciences of the artificial","author":"Simon H.A.","year":"1996","unstructured":"H.A. Simon . The sciences of the artificial ( 3 rd ed.). MIT Press , Cambridge, MA, USA , 1996 .]] H.A. Simon. The sciences of the artificial (3rd ed.). MIT Press, Cambridge, MA, USA, 1996.]]","edition":"3"},{"key":"e_1_3_2_1_45_1","volume-title":"Morgan Kaufmann","author":"Smith J. E.","year":"2005","unstructured":"J. E. Smith and R. Nair . Virtual Machines - Versatile Platforms for Systems and Processes . Morgan Kaufmann , 2005 .]] J. E. Smith and R. Nair. Virtual Machines - Versatile Platforms for Systems and Processes. Morgan Kaufmann, 2005.]]"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029624"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720288"},{"key":"e_1_3_2_1_48_1","volume-title":"The Art of Computer Virus Research and Defense","author":"Szor P.","year":"2005","unstructured":"P. Szor . The Art of Computer Virus Research and Defense . Symantec Press , 2005 .]] P. Szor. The Art of Computer Virus Research and Defense. Symantec Press, 2005.]]"},{"key":"e_1_3_2_1_49_1","unstructured":"VMware. Timekeeping in VMware Virtual Machines.]]  VMware. Timekeeping in VMware Virtual Machines.]]"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095825"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.169"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.5555\/647163.717674"},{"key":"e_1_3_2_1_53_1","volume-title":"Malicious Cryptography: Exposing Cryptovirology","author":"Young A.","year":"2004","unstructured":"A. Young and M. Yung . Malicious Cryptography: Exposing Cryptovirology . Wiley Publishing, Inc. , 2004 .]] A. Young and M. Yung. Malicious Cryptography: Exposing Cryptovirology. Wiley Publishing, Inc., 2004.]]"},{"key":"e_1_3_2_1_54_1","unstructured":"Commmon Malware Enumeration (CME) (Home Page). http:\/\/cme.mitre.org\/.]]  Commmon Malware Enumeration (CME) (Home Page). http:\/\/cme.mitre.org\/.]]"},{"key":"e_1_3_2_1_55_1","unstructured":"\"Decompiled Source For Ms Rpc Dcom Blaster Worm\". http:\/\/www.governmentsecurity.org\/archive\/t4726.html.]]  \"Decompiled Source For Ms Rpc Dcom Blaster Worm\". http:\/\/www.governmentsecurity.org\/archive\/t4726.html.]]"},{"key":"e_1_3_2_1_56_1","unstructured":"Scapy. http:\/\/www.secdev.org\/projects\/scapy\/.]]  Scapy. http:\/\/www.secdev.org\/projects\/scapy\/.]]"},{"key":"e_1_3_2_1_57_1","unstructured":"Symantec Security Response - search for malware description. http:\/\/securityresponse.symantec.com\/.]]  Symantec Security Response - search for malware description. http:\/\/securityresponse.symantec.com\/.]]"}],"event":{"name":"ASPLOS06: Architectural Support for Programming Languages and Operating Systems","location":"San Jose California USA","acronym":"ASPLOS06","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages","SIGOPS ACM Special Interest Group on Operating Systems","ACM Association for Computing Machinery","SIGARCH ACM Special Interest Group on Computer Architecture"]},"container-title":["Proceedings of the 12th international conference on Architectural support for programming languages and operating systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1168857.1168862","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1168857.1168862","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T11:14:09Z","timestamp":1750245249000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1168857.1168862"}},"subtitle":["detecting hidden malware timebombs with virtual machines"],"short-title":[],"issued":{"date-parts":[[2006,10,20]]},"references-count":57,"alternative-id":["10.1145\/1168857.1168862","10.1145\/1168857"],"URL":"https:\/\/doi.org\/10.1145\/1168857.1168862","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/1168919.1168862","asserted-by":"object"},{"id-type":"doi","id":"10.1145\/1168917.1168862","asserted-by":"object"},{"id-type":"doi","id":"10.1145\/1168918.1168862","asserted-by":"object"}]},"subject":[],"published":{"date-parts":[[2006,10,20]]},"assertion":[{"value":"2006-10-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}