{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:49:43Z","timestamp":1780634983780,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":26,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,12,5]],"date-time":"2011-12-05T00:00:00Z","timestamp":1323043200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-09-1-0553"],"award-info":[{"award-number":["W911NF-09-1-0553"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N000140911042"],"award-info":[{"award-number":["N000140911042"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0845559CNS-0905537"],"award-info":[{"award-number":["CNS-0845559CNS-0905537"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,12,5]]},"DOI":"10.1145\/2076732.2076790","type":"proceedings-article","created":{"date-parts":[[2011,12,13]],"date-time":"2011-12-13T15:46:00Z","timestamp":1323791160000},"page":"403-412","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":67,"title":["BareBox"],"prefix":"10.1145","author":[{"given":"Dhilung","family":"Kirat","sequence":"first","affiliation":[{"name":"University of California, Santa, Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[{"name":"University of California, Santa, Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, Santa, Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2011,12,5]]},"reference":[{"key":"e_1_3_2_1_2_1","unstructured":"T. Raffetseder C. Kruegel and E. Kirda \"Detecting system emulators.\"  T. Raffetseder C. Kruegel and E. Kirda \"Detecting system emulators.\""},{"key":"e_1_3_2_1_3_1","volume-title":"Tech. Rep.","author":"Ferrie P.","year":"2007","unstructured":"P. Ferrie , \"Attacks on virtual machine emulators,\" Symantec Corporation , Tech. Rep. , 2007 . P. Ferrie, \"Attacks on virtual machine emulators,\" Symantec Corporation, Tech. Rep., 2007."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1972551.1972554"},{"key":"e_1_3_2_1_5_1","volume-title":"or how to detect vmm using (almost) one cpu instruction","author":"Rutkowska J.","year":"2004","unstructured":"J. Rutkowska , \"Red pill... or how to detect vmm using (almost) one cpu instruction ,\" 2004 . {Online}. Available: http:\/\/invisiblethings.org\/papers\/redpill.html J. Rutkowska, \"Red pill... or how to detect vmm using (almost) one cpu instruction,\" 2004. {Online}. Available: http:\/\/invisiblethings.org\/papers\/redpill.html"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"e_1_3_2_1_7_1","volume-title":"The malware analyst's blue pill","author":"Royal P.","year":"2008","unstructured":"P. Royal , \"Alternative medicine : The malware analyst's blue pill ,\" Aug 2008 . P. Royal, \"Alternative medicine: The malware analyst's blue pill,\" Aug 2008."},{"key":"e_1_3_2_1_8_1","volume-title":"May","author":"Garfinkel T.","year":"2007","unstructured":"T. Garfinkel , K. Adams , A. Warfield , and J. Franklin , \" Compatibility is Not Transparency: VMM Detection Myths and Realities,\" in Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI) , May 2007 . T. Garfinkel, K. Adams, A. Warfield, and J. Franklin, \"Compatibility is Not Transparency: VMM Detection Myths and Realities,\" in Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI), May 2007."},{"key":"e_1_3_2_1_9_1","unstructured":"\"Qwmu open source processor emulator.\" {Online}. Available: http:\/\/wiki.qemu.org\/  \"Qwmu open source processor emulator.\" {Online}. Available: http:\/\/wiki.qemu.org\/"},{"key":"e_1_3_2_1_10_1","unstructured":"\"Anubis: Analyzing unknown binaries.\" {Online}. Available: http:\/\/anubis.iseclab.org\/  \"Anubis: Analyzing unknown binaries.\" {Online}. Available: http:\/\/anubis.iseclab.org\/"},{"key":"e_1_3_2_1_11_1","volume-title":"A fistful of red-pills: How to automatically generate procedures to detect CPU emulators,\" in Proceedings of the 3  rd  USENIX Workshop on Offensive Technologies (WOOT). Montreal","author":"Paleari R.","unstructured":"R. Paleari , L. Martignoni , G. Fresi Roglia , and D. Bruschi , \" A fistful of red-pills: How to automatically generate procedures to detect CPU emulators,\" in Proceedings of the 3 rd USENIX Workshop on Offensive Technologies (WOOT). Montreal , Canada : ACM. R. Paleari, L. Martignoni, G. Fresi Roglia, and D. Bruschi, \"A fistful of red-pills: How to automatically generate procedures to detect CPU emulators,\" in Proceedings of the 3 rd USENIX Workshop on Offensive Technologies (WOOT). Montreal, Canada: ACM."},{"key":"e_1_3_2_1_12_1","volume-title":"CA","author":"Balzarotti D.","year":"2010","unstructured":"D. Balzarotti , M. Cova , C. Karlberger , C. Kruegel , E. Kirda , and G. Vigna , \" Efficient Detection of Split Personalities in Malware,\" in Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego , CA , February 2010 . D. Balzarotti, M. Cova, C. Karlberger, C. Kruegel, E. Kirda, and G. Vigna, \"Efficient Detection of Split Personalities in Malware,\" in Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2010."},{"key":"e_1_3_2_1_13_1","volume-title":"Emulating emulation-resistant malware,\" EECS Department","author":"Kang M. G.","year":"2009","unstructured":"M. G. Kang , H. Yin , S. Hanna , S. McCamant , and D. Song , \" Emulating emulation-resistant malware,\" EECS Department , University of California , Berkeley, Tech . Rep., May 2009 . M. G. Kang, H. Yin, S. Hanna, S. McCamant, and D. Song, \"Emulating emulation-resistant malware,\" EECS Department, University of California, Berkeley, Tech. Rep., May 2009."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-008-0096-y"},{"key":"e_1_3_2_1_15_1","unstructured":"\"Juzt-reboot.\" {Online}. Available: http:\/\/www.juzt-reboot.com\/  \"Juzt-reboot.\" {Online}. Available: http:\/\/www.juzt-reboot.com\/"},{"key":"e_1_3_2_1_16_1","unstructured":"\"Partimage.\" {Online}. Available: http:\/\/www.partimage.org\/  \"Partimage.\" {Online}. Available: http:\/\/www.partimage.org\/"},{"key":"e_1_3_2_1_17_1","first-page":"383","volume-title":"SSYM'09","author":"Hund R.","year":"2009","unstructured":"R. Hund , T. Holz , and F. C. Freiling , \" Return-oriented rootkits: bypassing kernel code integrity protection mechanisms,\" in Proceedings of the 18th conference on USENIX security symposium, ser . SSYM'09 . Berkeley, CA, USA: USENIX Association , 2009 , pp. 383 -- 398 . R. Hund, T. Holz, and F. C. Freiling, \"Return-oriented rootkits: bypassing kernel code integrity protection mechanisms,\" in Proceedings of the 18th conference on USENIX security symposium, ser. SSYM'09. Berkeley, CA, USA: USENIX Association, 2009, pp. 383--398."},{"key":"e_1_3_2_1_18_1","unstructured":"\"Intel\u00ae64 and ia-32 architectures software developer's manual.\" {Online}. Available: http:\/\/www.intel.com\/Assets\/PDF\/manual\/325384.pdf  \"Intel\u00ae64 and ia-32 architectures software developer's manual.\" {Online}. Available: http:\/\/www.intel.com\/Assets\/PDF\/manual\/325384.pdf"},{"key":"e_1_3_2_1_19_1","unstructured":"\"Fast memory copy.\" {Online}. Available: http:\/\/now.cs.berkeley.edu\/Td\/bcopy.html  \"Fast memory copy.\" {Online}. Available: http:\/\/now.cs.berkeley.edu\/Td\/bcopy.html"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1698750.1698752"},{"key":"e_1_3_2_1_21_1","first-page":"177","article-title":"Towards an Understanding of Anti-Virtualization and Anti-Debugging Behavior in Modern Malware,\" in Proceedings of the 38th Annual IEEE International Conference on Dependable Systems and Networks (DSN '08), Anchorage","author":"Chen X.","year":"2008","unstructured":"X. Chen , J. Andersen , Z. M. Mao , M. Bailey , and J. Nazario , \" Towards an Understanding of Anti-Virtualization and Anti-Debugging Behavior in Modern Malware,\" in Proceedings of the 38th Annual IEEE International Conference on Dependable Systems and Networks (DSN '08), Anchorage , Alaska, USA , June 2008 , pp. 177 -- 186 . X. Chen, J. Andersen, Z. M. Mao, M. Bailey, and J. Nazario, \"Towards an Understanding of Anti-Virtualization and Anti-Debugging Behavior in Modern Malware,\" in Proceedings of the 38th Annual IEEE International Conference on Dependable Systems and Networks (DSN '08), Anchorage, Alaska, USA, June 2008, pp. 177--186.","journal-title":"Alaska, USA"},{"key":"e_1_3_2_1_22_1","volume-title":"ICC 2011","author":"Xiong N.","year":"2011","unstructured":"N. Xiong , Y. Zhou , H. Liu , and Y. Zhang , \" Avmm: Virtualize client with a bare-metal and asymmetric partitioning approach,\" Submitted , ICC 2011 , Tech. Rep. , 2011 . N. Xiong, Y. Zhou, H. Liu, and Y. Zhang, \"Avmm: Virtualize client with a bare-metal and asymmetric partitioning approach,\" Submitted, ICC 2011, Tech. Rep., 2011."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755913.1755933"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSNW.2010.5542614"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1952682.1952696"},{"key":"e_1_3_2_1_26_1","first-page":"31","article-title":"The recovery box: Using fast recovery to provide high availability in the unix environment","author":"Baker M.","year":"1992","unstructured":"M. Baker and M. Sullivan , \" The recovery box: Using fast recovery to provide high availability in the unix environment ,\" in In Proceedings USENIX Summer Conference , 1992 , pp. 31 -- 43 . M. Baker and M. Sullivan, \"The recovery box: Using fast recovery to provide high availability in the unix environment,\" in In Proceedings USENIX Summer Conference, 1992, pp. 31--43.","journal-title":"Proceedings USENIX Summer Conference"},{"key":"e_1_3_2_1_27_1","unstructured":"\"Norman sandbox analyzer.\" {Online}. Available: http:\/\/www.norman.com\/products\/sandbox_analyzer\/en  \"Norman sandbox analyzer.\" {Online}. Available: http:\/\/www.norman.com\/products\/sandbox_analyzer\/en"}],"event":{"name":"ACSAC '11: Annual Computer Security Applications Conference","location":"Orlando Florida USA","acronym":"ACSAC '11","sponsor":["ACSA Applied Computing Security Assoc"]},"container-title":["Proceedings of the 27th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2076732.2076790","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2076732.2076790","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:54:46Z","timestamp":1750240486000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2076732.2076790"}},"subtitle":["efficient malware analysis on bare-metal"],"short-title":[],"issued":{"date-parts":[[2011,12,5]]},"references-count":26,"alternative-id":["10.1145\/2076732.2076790","10.1145\/2076732"],"URL":"https:\/\/doi.org\/10.1145\/2076732.2076790","relation":{},"subject":[],"published":{"date-parts":[[2011,12,5]]},"assertion":[{"value":"2011-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}