{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:27:35Z","timestamp":1750307255686,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":28,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,3,22]],"date-time":"2011-03-22T00:00:00Z","timestamp":1300752000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["6.09E+31"],"award-info":[{"award-number":["6.09E+31"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007836","name":"Shanghai Key Laboratory of Intelligent Information Processing","doi-asserted-by":"publisher","award":["IIPL-09-006"],"award-info":[{"award-number":["IIPL-09-006"]}],"id":[{"id":"10.13039\/100007836","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Science Foundation","award":["4082018"],"award-info":[{"award-number":["4082018"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,3,22]]},"DOI":"10.1145\/1966913.1966941","type":"proceedings-article","created":{"date-parts":[[2011,4,7]],"date-time":"2011-04-07T09:36:11Z","timestamp":1302168971000},"page":"217-227","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Detecting stealthy malware with inter-structure and imported signatures"],"prefix":"10.1145","author":[{"given":"Bin","family":"Liang","sequence":"first","affiliation":[{"name":"Renmin University of China, MOE, Beijing, P.R. China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"You","sequence":"additional","affiliation":[{"name":"Renmin University of China, MOE, Beijing, P.R. China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenchang","family":"Shi","sequence":"additional","affiliation":[{"name":"Renmin University of China, MOE, Beijing, P.R. China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhaohui","family":"Liang","sequence":"additional","affiliation":[{"name":"Renmin University of China, MOE, Beijing, P.R. China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,3,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Bypassing Klister. http:\/\/www.rootkit.com\/newsread.php?newsid=235.  Bypassing Klister. http:\/\/www.rootkit.com\/newsread.php?newsid=235."},{"key":"e_1_3_2_1_2_1","unstructured":"Chkrootkit. http:\/\/www.chkrootkit.org.  Chkrootkit. http:\/\/www.chkrootkit.org."},{"key":"e_1_3_2_1_3_1","unstructured":"KSTAT. http:\/\/www.s0ftpj.org\/tools\/kstat24_v1.1-2.tgz.  KSTAT. http:\/\/www.s0ftpj.org\/tools\/kstat24_v1.1-2.tgz."},{"key":"e_1_3_2_1_4_1","unstructured":"QEMU. http:\/\/www.qemu.org.  QEMU. http:\/\/www.qemu.org."},{"key":"e_1_3_2_1_5_1","unstructured":"Rkhunter. http:\/\/www.rootkit.nl\/projects\/rootkit_hunter.html.  Rkhunter. http:\/\/www.rootkit.nl\/projects\/rootkit_hunter.html."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.29"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_3_2_1_8_1","unstructured":"C. Betz. MemParser. http:\/\/sourceforge.net\/projects\/memparser.  C. Betz. MemParser. http:\/\/sourceforge.net\/projects\/memparser."},{"key":"e_1_3_2_1_9_1","unstructured":"C. Bugcheck. Grepexec: Grepping executive objects from pool memory. http:\/\/www.uninformed.org\/?v=4&amp;amp;a=2&amp;amp;t=sumry.  C. Bugcheck. Grepexec: Grepping executive objects from pool memory. http:\/\/www.uninformed.org\/?v=4&amp;amp;a=2&amp;amp;t=sumry."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653729"},{"volume-title":"Prentice Hall Press","year":"2007","author":"Chisnall D.","key":"e_1_3_2_1_11_1"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653730"},{"volume-title":"Proceedings of the 10th Network and Distributed Systems Security Symposium (NDSS)","year":"2003","author":"Garfinkel T.","key":"e_1_3_2_1_13_1"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346256.1346269"},{"volume-title":"Proceedings of the 18th Network and Distributed System Security Symposium (NDSS)","year":"2011","author":"Lin Z.","key":"e_1_3_2_1_16_1"},{"volume-title":"Proceedings of the 15th USENIX Security Symposium","year":"2006","author":"Petroni N.","key":"e_1_3_2_1_17_1"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2009.116"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/1433006.1433008"},{"key":"e_1_3_2_1_20_1","unstructured":"J. Rutkowska. Klister v0.3. https:\/\/www.rootkit.com\/newsread.php?newsid=51.  J. Rutkowska. Klister v0.3. https:\/\/www.rootkit.com\/newsread.php?newsid=51."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.06.010"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294294"},{"key":"e_1_3_2_1_23_1","unstructured":"A. Walters. The volatility framework: Volatile memory artifact extraction utility framework. https:\/\/www.volatilesystems.com\/default\/volatility.  A. Walters. The volatility framework: Volatile memory artifact extraction utility framework. https:\/\/www.volatilesystems.com\/default\/volatility."},{"volume-title":"Black Hat DC","year":"2007","author":"Walters A.","key":"e_1_3_2_1_24_1"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.39"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653728"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_2"},{"volume-title":"Proceedings of the 15th Network and Distributed System Security Symposium (NDSS)","year":"2008","author":"Yin H.","key":"e_1_3_2_1_28_1"}],"event":{"name":"ASIA CCS '11: 6th ACM Symposium on Information, Compuer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Hong Kong China","acronym":"ASIA CCS '11"},"container-title":["Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1966913.1966941","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1966913.1966941","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:52:25Z","timestamp":1750243945000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1966913.1966941"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,3,22]]},"references-count":28,"alternative-id":["10.1145\/1966913.1966941","10.1145\/1966913"],"URL":"https:\/\/doi.org\/10.1145\/1966913.1966941","relation":{},"subject":[],"published":{"date-parts":[[2011,3,22]]},"assertion":[{"value":"2011-03-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}