{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:13:26Z","timestamp":1784391206059,"version":"3.55.0"},"reference-count":99,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2008,3,5]],"date-time":"2008-03-05T00:00:00Z","timestamp":1204675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2012,2]]},"abstract":"<jats:p>Anti-virus vendors are confronted with a multitude of potentially malicious samples today. Receiving thousands of new samples every day is not uncommon. The signatures that detect confirmed malicious threats are mainly still created manually, so it is important to discriminate between samples that pose a new unknown threat and those that are mere variants of known malware.<\/jats:p>\n          <jats:p>This survey article provides an overview of techniques based on dynamic analysis that are used to analyze potentially malicious samples. It also covers analysis programs that leverage these It also covers analysis programs that employ these techniques to assist human analysts in assessing, in a timely and appropriate manner, whether a given sample deserves closer manual inspection due to its unknown malicious behavior.<\/jats:p>","DOI":"10.1145\/2089125.2089126","type":"journal-article","created":{"date-parts":[[2012,3,6]],"date-time":"2012-03-06T13:18:22Z","timestamp":1331039902000},"page":"1-42","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":558,"title":["A survey on automated dynamic malware-analysis techniques and tools"],"prefix":"10.1145","volume":"44","author":[{"given":"Manuel","family":"Egele","sequence":"first","affiliation":[{"name":"Vienna University of Technology, Vienna, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Theodoor","family":"Scholte","sequence":"additional","affiliation":[{"name":"SAP Research, Sophia Antipolis"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Institute Eurecom, Sophia Antipolis"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2008,3,5]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Anubis. Analysis of unknown binaries. http:\/\/anubis.iseclab.org. (Last accessed 5\/10.)  Anubis. Analysis of unknown binaries. http:\/\/anubis.iseclab.org. (Last accessed 5\/10.)"},{"key":"e_1_2_1_2_1","unstructured":"Avira Press Center. 2007. Avira warns: targeted malware attacks increasingly also threatening German companies. http:\/\/www.avira.com\/en\/security_news\/targeted_attacks_threatening_companies.html. (Last accessed 5\/10.)  Avira Press Center. 2007. Avira warns: targeted malware attacks increasingly also threatening German companies. http:\/\/www.avira.com\/en\/security_news\/targeted_attacks_threatening_companies.html. (Last accessed 5\/10.)"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.18"},{"key":"e_1_2_1_4_1","unstructured":"Baecher P. and Koetter M. x86 shellcode detection and emulation. http:\/\/libemu.mwcollect.org\/. (Last accessed 5\/10.)  Baecher P. and Koetter M. x86 shellcode detection and emulation. http:\/\/libemu.mwcollect.org\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS'09)","author":"Bayer U.","unstructured":"Bayer , U. , Milani Comparetti , P. , Hlauschek , C. , Kr\u00fcgel , C. , and Kirda , E . 2009. Scalable, Behavior-Based Malware Clustering . In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS'09) . Bayer, U., Milani Comparetti, P., Hlauschek, C., Kr\u00fcgel, C., and Kirda, E. 2009. Scalable, Behavior-Based Malware Clustering. In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS'09)."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0012-2"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the FREENIX Track of the USENIX Annual Technical Conference.","author":"Bellard F.","year":"2005","unstructured":"Bellard , F. 2005 . QEMU, a fast and portable dynamic translator . In Proceedings of the FREENIX Track of the USENIX Annual Technical Conference. Bellard, F. 2005. QEMU, a fast and portable dynamic translator. In Proceedings of the FREENIX Track of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_8_1","unstructured":"Bennett J. AutoIt Script Home Page. http:\/\/www.autoitscript.com\/. (Last accessed 5\/10.)  Bennett J. AutoIt Script Home Page. http:\/\/www.autoitscript.com\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_9_1","unstructured":"Bochs. Bochs: The open source IA-32 emulation project. http:\/\/bochs.sourceforge.net\/. (Last accessed 5\/10.)  Bochs. Bochs: The open source IA-32 emulation project. http:\/\/bochs.sourceforge.net\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_10_1","unstructured":"Brumley D. Hartwig C. Liang Z. Newsome J. Poosankam P. Song D. and Yin H. 2007. Automatically identifying trigger-based behavior in malware. In Botnet Analysis and Defense W. Lee et. al. Eds.  Brumley D. Hartwig C. Liang Z. Newsome J. Poosankam P. Song D. and Yin H. 2007. Automatically identifying trigger-based behavior in malware. In Botnet Analysis and Defense W. Lee et. al. Eds."},{"key":"e_1_2_1_11_1","unstructured":"Buehlmann S. and Liebchen C. Joebox: a secure sandbox application for Windows to analyse the behaviour of malware. http:\/\/www.joebox.org\/. (Last accessed 5\/10.)  Buehlmann S. and Liebchen C. Joebox: a secure sandbox application for Windows to analyse the behaviour of malware. http:\/\/www.joebox.org\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/876871.878282"},{"key":"e_1_2_1_13_1","unstructured":"Carrier B. The sleuth kit. http:\/\/www.sleuthkit.org\/sleuthkit\/. (Last accessed 5\/10.)  Carrier B. The sleuth kit. http:\/\/www.sleuthkit.org\/sleuthkit\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_8"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 11th Annual Network and Distributed System Security Symposium (NDSS'04)","author":"Chen H.","unstructured":"Chen , H. , Dean , D. , and Wagner , D . 2004. Model Checking One Million Lines of C Code . In Proceedings of the 11th Annual Network and Distributed System Security Symposium (NDSS'04) . Chen, H., Dean, D., and Wagner, D. 2004. Model Checking One Million Lines of C Code. In Proceedings of the 11th Annual Network and Distributed System Security Symposium (NDSS'04)."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586142"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the IEEE International Conference on Dependable Systems and Networks With FTCS and DCC (DSN'08)","author":"Chen X.","unstructured":"Chen , X. , Andersen , J. , Mao , Z. , Bailey , M. , and Nazario , J . 2008. Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware . In Proceedings of the IEEE International Conference on Dependable Systems and Networks With FTCS and DCC (DSN'08) . 177--186. Chen, X., Andersen, J., Mao, Z., Bailey, M., and Nazario, J. 2008. Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware. In Proceedings of the IEEE International Conference on Dependable Systems and Networks With FTCS and DCC (DSN'08). 177--186."},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Chow J.","unstructured":"Chow , J. , Pfaff , B. , Garfinkel , T. , Christopher , K. , and Rosenblum , M . 2004. Understanding data lifetime via whole system simulation . In Proceedings of the 13th USENIX Security Symposium. Chow, J., Pfaff, B., Garfinkel, T., Christopher, K., and Rosenblum, M. 2004. Understanding data lifetime via whole system simulation. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1287624.1287628"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.26"},{"key":"e_1_2_1_21_1","unstructured":"Dan Goodin (The Register). 2008. SQL injection taints BusinessWeek.com. http:\/\/www.theregister.co.uk\/2008\/09\/16\/businessweek_hacked\/. (Last accessed 5\/10.)  Dan Goodin (The Register). 2008. SQL injection taints BusinessWeek.com. http:\/\/www.theregister.co.uk\/2008\/09\/16\/businessweek_hacked\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 2nd USENIX Workshop on Offensive Technologies (WOOT'08)","author":"Daniel M.","unstructured":"Daniel , M. , Honoroff , J. , and Miller , C . 2008. Engineering heap overflow exploits with javascript . In Proceedings of the 2nd USENIX Workshop on Offensive Technologies (WOOT'08) . Daniel, M., Honoroff, J., and Miller, C. 2008. Engineering heap overflow exploits with javascript. In Proceedings of the 2nd USENIX Workshop on Offensive Technologies (WOOT'08)."},{"key":"e_1_2_1_23_1","unstructured":"Daniloff I. 1997. Virus analysis 3 fighting talk. Virus Bull. J. 10--12.  Daniloff I. 1997. Virus analysis 3 fighting talk. Virus Bull. J. 10--12."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the USENIX Annual Technical Conference. 233--246","author":"Egele M.","unstructured":"Egele , M. , Kruegel , C. , Kirda , E. , Yin , H. , and Song , D. X . 2007. Dynamic spyware analysis . In Proceedings of the USENIX Annual Technical Conference. 233--246 . Egele, M., Kruegel, C., Kirda, E., Yin, H., and Song, D. X. 2007. Dynamic spyware analysis. In Proceedings of the USENIX Annual Technical Conference. 233--246."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/11790754_2"},{"key":"e_1_2_1_27_1","unstructured":"Falliere N. 2007. Windows anti-debug reference. http:\/\/www.symantec.com\/connect\/es\/articles\/windows-anti-debug-reference. (Last accessed 5\/10.)  Falliere N. 2007. Windows anti-debug reference. http:\/\/www.symantec.com\/connect\/es\/articles\/windows-anti-debug-reference. (Last accessed 5\/10.)"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 194--208","author":"Feng H. H.","unstructured":"Feng , H. H. , Giffin , J. T. , Huang , Y. , Jha , S. , Lee , W. , and Miller , B. P . 2004. Formalizing sensitivity in static analysis for intrusion detection . In Proceedings of the IEEE Symposium on Security and Privacy. 194--208 . Feng, H. H., Giffin, J. T., Huang, Y., Jha, S., Lee, W., and Miller, B. P. 2004. Formalizing sensitivity in static analysis for intrusion detection. In Proceedings of the IEEE Symposium on Security and Privacy. 194--208."},{"key":"e_1_2_1_29_1","unstructured":"Ferrie P. 2007. Attacks on virtual machine emulators. www.symantec.com\/avcenter\/reference\/Virtual_Machine_Threats.pdf. (Last accessed 5\/10.)  Ferrie P. 2007. Attacks on virtual machine emulators. www.symantec.com\/avcenter\/reference\/Virtual_Machine_Threats.pdf. (Last accessed 5\/10.)"},{"key":"e_1_2_1_30_1","unstructured":"Fossi M. Johnson E. Mack T. Turner D. Blackbird J. Low M. K. Adams T. McKinney D. Entwisle S. Laucht M. P. Wueest C. Wood P. Bleaken D. Ahmad G. Kemp D. and Samnani A. 2009. Symantec global Internet security threat report trends for 2008. http:\/\/www4.symantec.com\/Vrt\/wl?tu_id=gCGG123913789453640802. (Last accessed 5\/10.)  Fossi M. Johnson E. Mack T. Turner D. Blackbird J. Low M. K. Adams T. McKinney D. Entwisle S. Laucht M. P. Wueest C. Wood P. Bleaken D. Ahmad G. Kemp D. and Samnani A. 2009. Symantec global Internet security threat report trends for 2008. http:\/\/www4.symantec.com\/Vrt\/wl?tu_id=gCGG123913789453640802. (Last accessed 5\/10.)"},{"key":"e_1_2_1_31_1","unstructured":"Free Software Foundation. Code Gen Options - Using the GNU Compiler Collection (GCC). http:\/\/gcc.gnu.org\/onlinedocs\/gcc-4.3.2\/gcc\/Code-Gen-Options.html&num;Code-Gen-Options. (Last accessed 1\/10.)  Free Software Foundation. Code Gen Options - Using the GNU Compiler Collection (GCC). http:\/\/gcc.gnu.org\/onlinedocs\/gcc-4.3.2\/gcc\/Code-Gen-Options.html&num;Code-Gen-Options. (Last accessed 1\/10.)"},{"key":"e_1_2_1_32_1","unstructured":"FRISK Software International. 2003. F-prot virus signature updates cause false alarm in Windows 98. http:\/\/www.f-prot.com\/news\/vir_alert\/falsepos_invictus.html. (Last accessed 5\/10.)  FRISK Software International. 2003. F-prot virus signature updates cause false alarm in Windows 98. http:\/\/www.f-prot.com\/news\/vir_alert\/falsepos_invictus.html. (Last accessed 5\/10.)"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI).","author":"Garfinkel T.","unstructured":"Garfinkel , T. , Adams , K. , Warfield , A. , and Franklin , J . 2007. Compatibility is Not Transparency: VMM Detection Myths and Realities . In Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI). Garfinkel, T., Adams, K., Warfield, A., and Franklin, J. 2007. Compatibility is Not Transparency: VMM Detection Myths and Realities. In Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI)."},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 10th Annual Network and Distributed System Security Symposium (NDSS'03)","author":"Garfinkel T.","unstructured":"Garfinkel , T. and Rosenblum , M . 2003. A virtual machine introspection based architecture for intrusion detection . In Proceedings of the 10th Annual Network and Distributed System Security Symposium (NDSS'03) . Garfinkel, T. and Rosenblum, M. 2003. A virtual machine introspection based architecture for intrusion detection. In Proceedings of the 10th Annual Network and Distributed System Security Symposium (NDSS'03)."},{"key":"e_1_2_1_35_1","volume-title":"Survey of virtual machine research","author":"Goldberg R. P.","unstructured":"Goldberg , R. P. 1974. Survey of virtual machine research . IEEE Comput. Mag . June, 34--45. Goldberg, R. P. 1974. Survey of virtual machine research. IEEE Comput. Mag. June, 34--45."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_6"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.21"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the 3rd USENIX Windows NT Symposium. USENIX Association","author":"Hunt G.","unstructured":"Hunt , G. and Brubacher , D . 1999. Detours: binary interception of Win32 functions . In Proceedings of the 3rd USENIX Windows NT Symposium. USENIX Association , Berkeley, CA, 135--143. Hunt, G. and Brubacher, D. 1999. Detours: binary interception of Win32 functions. In Proceedings of the 3rd USENIX Windows NT Symposium. USENIX Association, Berkeley, CA, 135--143."},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the IEEE International Conference on Communications (ICC).","author":"Inoue D.","unstructured":"Inoue , D. , Yoshioka , K. , Eto , M. , Hoshizawa , Y. , and Nakao , K . 2008. Malware behavior analysis in isolated miniature network for revealing malware's network activity . In Proceedings of the IEEE International Conference on Communications (ICC). Inoue, D., Yoshioka, K., Eto, M., Hoshizawa, Y., and Nakao, K. 2008. Malware behavior analysis in isolated miniature network for revealing malware's network activity. In Proceedings of the IEEE International Conference on Communications (ICC)."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0306-4573(03)00067-0"},{"key":"e_1_2_1_41_1","unstructured":"John Leyden (The Register). 2007. Kaspersky false alarm quarantines Windows Explorer. http:\/\/www. channelregister.co.uk\/2007\/12\/20\/kaspersky_false_alarm\/. (Last accessed 5\/10.)  John Leyden (The Register). 2007. Kaspersky false alarm quarantines Windows Explorer. http:\/\/www. channelregister.co.uk\/2007\/12\/20\/kaspersky_false_alarm\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_42_1","unstructured":"Juzt-Reboot Technology. Juzt-reboot intelligent back-up technology instant recovery. http:\/\/www.juzt-reboot.com\/. (Last accessed 5\/10.)  Juzt-Reboot Technology. Juzt-reboot intelligent back-up technology instant recovery. http:\/\/www.juzt-reboot.com\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314389.1314399"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455774"},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the 1st International Conference on Availability, Reliability and Security. 355--362","author":"Kim H. C.","unstructured":"Kim , H. C. , Keromytis , A. D. , Covington , M. , and Sahita , R . 2009. Capturing information flow with concatenated dynamic taint analysis . In Proceedings of the 1st International Conference on Availability, Reliability and Security. 355--362 . Kim, H. C., Keromytis, A. D., Covington, M., and Sahita, R. 2009. Capturing information flow with concatenated dynamic taint analysis. In Proceedings of the 1st International Conference on Availability, Reliability and Security. 355--362."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.38"},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Kirda E.","unstructured":"Kirda , E. , Kruegel , C. , Banks , G. , Vigna , G. , and Kemmerer , R. A . 2006. Behavior-based spyware detection . In Proceedings of the 15th USENIX Security Symposium. Kirda, E., Kruegel, C., Banks, G., Vigna, G., and Kemmerer, R. A. 2006. Behavior-based spyware detection. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_1_48_1","first-page":"1","article-title":"Vx reversing III yellow fever (Griyo 29a)","volume":"2","author":"Labir E.","year":"2005","unstructured":"Labir , E. 2005 . Vx reversing III yellow fever (Griyo 29a) . CodeBreakers J. 2 , 1 . Labir, E. 2005. Vx reversing III yellow fever (Griyo 29a). CodeBreakers J. 2, 1.","journal-title":"CodeBreakers J."},{"key":"e_1_2_1_49_1","article-title":"Measuring virtual machine detection in malware using DSD tracer","author":"Lau B.","year":"2008","unstructured":"Lau , B. and Svajcer , V. 2008 . Measuring virtual machine detection in malware using DSD tracer . J. Comput. Virology. Lau, B. and Svajcer, V. 2008. Measuring virtual machine detection in malware using DSD tracer. J. Comput. Virology.","journal-title":"J. Comput. Virology."},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the European Institute for Computer Antivirus Research Conference (EICAR'06)","author":"Lee T.","unstructured":"Lee , T. and Mody , J. J . 2006. Behavioral classification . In Proceedings of the European Institute for Computer Antivirus Research Conference (EICAR'06) . Lee, T. and Mody, J. J. 2006. Behavioral classification. In Proceedings of the European Institute for Computer Antivirus Research Conference (EICAR'06)."},{"key":"e_1_2_1_51_1","unstructured":"Liguori A. 2010. Qemu snapshot mode. http:\/\/wiki.qemu.org\/Manual. (Last accessed 5\/10.)  Liguori A. 2010. Qemu snapshot mode. http:\/\/wiki.qemu.org\/Manual. (Last accessed 5\/10.)"},{"key":"e_1_2_1_52_1","unstructured":"Marcus D. Greve P. Masiello S. and Scharoun D. 2009. Mcafee threats report: Third quarter 2009. http:\/\/www.mcafee.com\/us\/local_content\/reports\/7315rpt_threat_1009.pdf. (Last accessed 5\/10.)  Marcus D. Greve P. Masiello S. and Scharoun D. 2009. Mcafee threats report: Third quarter 2009. http:\/\/www.mcafee.com\/us\/local_content\/reports\/7315rpt_threat_1009.pdf. (Last accessed 5\/10.)"},{"key":"e_1_2_1_53_1","volume-title":"Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC'07)","author":"Martignoni L.","unstructured":"Martignoni , L. , Christodorescu , M. , and Jha , S . 2007. Omniunpack: fast, generic, and safe unpacking of malware . In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC'07) . IEEE Computer Society, Los Alamitos, CA, 431--441. Martignoni, L., Christodorescu, M., and Jha, S. 2007. Omniunpack: fast, generic, and safe unpacking of malware. In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC'07). IEEE Computer Society, Los Alamitos, CA, 431--441."},{"key":"e_1_2_1_54_1","unstructured":"Mehta N. and Clowes S. 2003. Shiva. advances in ELF binary runtime encryption. http:\/\/www. securereality.com.au\/. (Last accessed 5\/10.)  Mehta N. and Clowes S. 2003. Shiva. advances in ELF binary runtime encryption. http:\/\/www. securereality.com.au\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_55_1","unstructured":"Microsoft Corporation. 2006. Microsoft security bulletin MS06-014\u2014Vulnerability in the microsoft data access components (MDAC) function could allow code execution. http:\/\/www.microsoft.com\/technet\/security\/Bulletin\/MS06-014.mspx. (Last accessed May 2010.)  Microsoft Corporation. 2006. Microsoft security bulletin MS06-014\u2014Vulnerability in the microsoft data access components (MDAC) function could allow code execution. http:\/\/www.microsoft.com\/technet\/security\/Bulletin\/MS06-014.mspx. (Last accessed May 2010.)"},{"key":"e_1_2_1_56_1","volume-title":"Microsoft security bulletin MS08-067 Critical","author":"Microsoft Corporation","year":"2010","unstructured":"Microsoft Corporation . 2008. Microsoft security bulletin MS08-067 Critical ; vulnerability in server service could allow remote code execution. http:\/\/www.microsoft.com\/technet\/security\/Bulletin\/MS08-067.mspx. ( Last accessed, May 2010 .) Microsoft Corporation. 2008. Microsoft security bulletin MS08-067 Critical; vulnerability in server service could allow remote code execution. http:\/\/www.microsoft.com\/technet\/security\/Bulletin\/MS08-067.mspx. (Last accessed, May 2010.)"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.17"},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC'07)","author":"Moser A.","unstructured":"Moser , A. , Kruegel , C. , and Kirda , E . 2007b. Limits of static analysis for malware detection . In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC'07) . 421--430. Moser, A., Kruegel, C., and Kirda, E. 2007b. Limits of static analysis for malware detection. In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC'07). 421--430."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2007.10.010"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/1377943.1377956"},{"key":"e_1_2_1_62_1","volume-title":"New Riders Publishing","author":"Nebbett G.","unstructured":"Nebbett , G. 2000. Windows NT\/200 0 Native API Reference . New Riders Publishing , Thousand Oaks, CA . Nebbett, G. 2000. Windows NT\/2000 Native API Reference. New Riders Publishing, Thousand Oaks, CA."},{"key":"e_1_2_1_63_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS'05)","author":"Newsome J.","unstructured":"Newsome , J. and Song , D. X . 2005. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software . In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS'05) . Newsome, J. and Song, D. X. 2005. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS'05)."},{"key":"e_1_2_1_64_1","unstructured":"Norman Sandbox. 2003. Norman SandBox Whitepaper. http:\/\/download.norman.no\/whitepapers\/whitepaper_Norman_SandBox.pdf. (Last accessed 5\/10.)  Norman Sandbox. 2003. Norman SandBox Whitepaper. http:\/\/download.norman.no\/whitepapers\/whitepaper_Norman_SandBox.pdf. (Last accessed 5\/10.)"},{"key":"e_1_2_1_65_1","unstructured":"PEiD. PEiD: Packer Identification. http:\/\/www.peid.info\/. (Last accessed 5\/10.)  PEiD. PEiD: Packer Identification. http:\/\/www.peid.info\/. (Last accessed 5\/10.)"},{"key":"e_1_2_1_66_1","unstructured":"Perl Taint. Perl security \/taint mode. http:\/\/perldoc.perl.org\/perlsec.html&num;Taint-mode. (Last accessed 5\/10.)  Perl Taint. Perl security \/taint mode. http:\/\/perldoc.perl.org\/perlsec.html&num;Taint-mode. (Last accessed 5\/10.)"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217938"},{"key":"e_1_2_1_68_1","volume-title":"Proceedings of the 17th USENIX Security Symposium.","author":"Provos N.","unstructured":"Provos , N. , Mavrommatis , P. , Rajab , M. A. , and Monrose , F . 2008. All your iFRAMEs point to us . In Proceedings of the 17th USENIX Security Symposium. Provos, N., Mavrommatis, P., Rajab, M. A., and Monrose, F. 2008. All your iFRAMEs point to us. In Proceedings of the 17th USENIX Security Symposium."},{"key":"e_1_2_1_69_1","volume-title":"Proceedings of the 1st Workshop on Hot Topics in Understanding Botnets (HotBots'07)","author":"Provos N.","unstructured":"Provos , N. , McNamee , D. , Mavrommatis , P. , Wang , K. , and Modadugu , N . 2007. The ghost in the browser: Analysis of web-based malware . In Proceedings of the 1st Workshop on Hot Topics in Understanding Botnets (HotBots'07) . Provos, N., McNamee, D., Mavrommatis, P., Wang, K., and Modadugu, N. 2007. The ghost in the browser: Analysis of web-based malware. In Proceedings of the 1st Workshop on Hot Topics in Understanding Botnets (HotBots'07)."},{"key":"e_1_2_1_70_1","volume-title":"Proceedings of the 10th International Conference on Information Security (ISC'07)","author":"Raffetseder T.","unstructured":"Raffetseder , T. , Kr\u00fcgel , C. , and Kirda , E . 2007. Detecting system emulators . In Proceedings of the 10th International Conference on Information Security (ISC'07) . 1--18. Raffetseder, T., Kr\u00fcgel, C., and Kirda, E. 2007. Detecting system emulators. In Proceedings of the 10th International Conference on Information Security (ISC'07). 1--18."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.38"},{"key":"e_1_2_1_73_1","unstructured":"Rutkowska J. 2004. Red Pill... or how to detect VMM using (almost) one CPU instruction. http:\/\/www.invisiblethings.org\/papers\/redpill.html. (Last accessed 5\/10.)  Rutkowska J. 2004. Red Pill... or how to detect VMM using (almost) one CPU instruction. http:\/\/www.invisiblethings.org\/papers\/redpill.html. (Last accessed 5\/10.)"},{"key":"e_1_2_1_74_1","unstructured":"Rutkowska J. 2006. Introducing Blue Pill. http:\/\/theinvisiblethings.blogspot.com\/2006\/06\/introducing-blue-pill.html. (Last accessed 5\/10.)  Rutkowska J. 2006. Introducing Blue Pill. http:\/\/theinvisiblethings.blogspot.com\/2006\/06\/introducing-blue-pill.html. (Last accessed 5\/10.)"},{"key":"e_1_2_1_75_1","volume-title":"Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS'08)","author":"Sharif M.","unstructured":"Sharif , M. , Lanzi , A. , Giffin , J. , and Lee , W . 2008. Impeding malware analysis using conditional code obfuscation . In Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS'08) . Sharif, M., Lanzi, A., Giffin, J., and Lee, W. 2008. Impeding malware analysis using conditional code obfuscation. In Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS'08)."},{"key":"e_1_2_1_76_1","volume-title":"Malware: Fighting Malicious Code","author":"Skoudis E.","year":"2003","unstructured":"Skoudis , E. and Zeltser , L . 2003 . Malware: Fighting Malicious Code . Prentice Hall PTR , Upper Saddle River, NJ. Skoudis, E. and Zeltser, L. 2003. Malware: Fighting Malicious Code. Prentice Hall PTR, Upper Saddle River, NJ."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/1519065.1519073"},{"key":"e_1_2_1_78_1","unstructured":"Sotirov A. Heap feng shui in javascript. http:\/\/www.phreedom.org\/research\/heap-feng-shui\/heap-feng-shui.html. (Last accessed 5\/10.)  Sotirov A. Heap feng shui in javascript. http:\/\/www.phreedom.org\/research\/heap-feng-shui\/heap-feng-shui.html. (Last accessed 5\/10.)"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.5555\/645382.651657"},{"key":"e_1_2_1_80_1","unstructured":"Stasiukonis S. 2007. Social engineering the USB way. http:\/\/www.darkreading.com\/security\/perimeter\/showArticle.jhtml?articleID=208803634. (Last accessed 5\/10.)  Stasiukonis S. 2007. Social engineering the USB way. http:\/\/www.darkreading.com\/security\/perimeter\/showArticle.jhtml?articleID=208803634. (Last accessed 5\/10.)"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"e_1_2_1_82_1","volume-title":"The Art of Computer Virus Research and Defense","author":"Szor P.","unstructured":"Szor , P. 2005. The Art of Computer Virus Research and Defense . Addison-Wesley Professional . Szor, P. 2005. The Art of Computer Virus Research and Defense. Addison-Wesley Professional."},{"key":"e_1_2_1_83_1","unstructured":"Taha G. 2007. Counterattacking the packers. http:\/\/www.mcafee.com\/us\/local_content\/white_papers\/threat_center\/wp_counterattacking_packers.pdf. (Last accessed 5\/10.)  Taha G. 2007. Counterattacking the packers. http:\/\/www.mcafee.com\/us\/local_content\/white_papers\/threat_center\/wp_counterattacking_packers.pdf. (Last accessed 5\/10.)"},{"key":"e_1_2_1_84_1","volume-title":"Proceedings of the Annual Joint Conference of the IEEE Computer and Communication Societies (INFOCom).","author":"Tanachaiwiwat S.","unstructured":"Tanachaiwiwat , S. and Helmy , A . 2006. Vaccine: War of the worms in wired and wireless networks . In Proceedings of the Annual Joint Conference of the IEEE Computer and Communication Societies (INFOCom). Tanachaiwiwat, S. and Helmy, A. 2006. Vaccine: War of the worms in wired and wireless networks. In Proceedings of the Annual Joint Conference of the IEEE Computer and Communication Societies (INFOCom)."},{"key":"e_1_2_1_85_1","volume-title":"Proceedings of the Hawaii International Conference in Computer Sciences.","author":"Vasudevan A.","unstructured":"Vasudevan , A. and Yerraballi , R . 2004. Sakthi: A retargetable dynamic framework for binary instrumentation . In Proceedings of the Hawaii International Conference in Computer Sciences. Vasudevan, A. and Yerraballi, R. 2004. Sakthi: A retargetable dynamic framework for binary instrumentation. In Proceedings of the Hawaii International Conference in Computer Sciences."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.52"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.9"},{"key":"e_1_2_1_88_1","volume-title":"Proceedings of the 29th Australasian Computer Science Conference. 311--320","author":"Vasudevan A.","unstructured":"Vasudevan , A. and Yerraballi , R . 2006b. Spike: engineering malware analysis tools using unobtrusive binary-instrumentation . In Proceedings of the 29th Australasian Computer Science Conference. 311--320 . Vasudevan, A. and Yerraballi, R. 2006b. Spike: engineering malware analysis tools using unobtrusive binary-instrumentation. In Proceedings of the 29th Australasian Computer Science Conference. 311--320."},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the 14th IEEE International Symposium on High Performance Computer Architecture (HPCA'08","author":"Venkataramani G.","unstructured":"Venkataramani , G. , Doudalis , I. , Solihin , Y. , and Prvulovic , M . 2008. Flexitaint: A programmable accelerator for dynamic taint propagation . In Proceedings of the 14th IEEE International Symposium on High Performance Computer Architecture (HPCA'08 .). 173--184. Venkataramani, G., Doudalis, I., Solihin, Y., and Prvulovic, M. 2008. Flexitaint: A programmable accelerator for dynamic taint propagation. In Proceedings of the 14th IEEE International Symposium on High Performance Computer Architecture (HPCA'08.). 173--184."},{"key":"e_1_2_1_90_1","unstructured":"VMWare snapshots. VMWare using snapshots. http:\/\/www.vmware.com\/support\/ws55\/doc\/ws_preserve_using_sshot.html. (Last accessed 5\/10.)  VMWare snapshots. VMWare using snapshots. http:\/\/www.vmware.com\/support\/ws55\/doc\/ws_preserve_using_sshot.html. (Last accessed 5\/10.)"},{"key":"e_1_2_1_91_1","volume-title":"Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS'07)","author":"Vogt P.","unstructured":"Vogt , P. , Nentwich , F. , Jovanovic , N. , Kruegel , C. , Kirda , E. , and Vigna , G . 2007. Cross site scripting prevention with dynamic data tainting and static analysis . In Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS'07) . Vogt, P., Nentwich, F., Jovanovic, N., Kruegel, C., Kirda, E., and Vigna, G. 2007. Cross site scripting prevention with dynamic data tainting and static analysis. In Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS'07)."},{"key":"e_1_2_1_92_1","volume-title":"Proceedings of the 18th USENIX Conference on System Administration. USENIX Association","author":"Wang Y.-M.","unstructured":"Wang , Y.-M. , Roussev , R. , Verbowski , C. , Johnson , A. , Wu , M.-W. , Huang , Y. , and Kuo , S . -Y. 2004. Gatekeeper: Monitoring auto-start extensibility points (ASEPs) for spyware management . In Proceedings of the 18th USENIX Conference on System Administration. USENIX Association , Berkeley, CA, 33--46. Wang, Y.-M., Roussev, R., Verbowski, C., Johnson, A., Wu, M.-W., Huang, Y., and Kuo, S.-Y. 2004. Gatekeeper: Monitoring auto-start extensibility points (ASEPs) for spyware management. In Proceedings of the 18th USENIX Conference on System Administration. USENIX Association, Berkeley, CA, 33--46."},{"key":"e_1_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICHIS.2004.75"},{"key":"e_1_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.126"},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315261"},{"key":"e_1_2_1_97_1","unstructured":"Zeltser L. 2006. Virtual machine detection in malware via commercial tools. http:\/\/isc.sans.org\/diary.html?storyid=1871. (Last accessed 5\/10.)  Zeltser L. 2006. Virtual machine detection in malware via commercial tools. http:\/\/isc.sans.org\/diary.html?storyid=1871. (Last accessed 5\/10.)"},{"key":"e_1_2_1_98_1","volume-title":"Proceedings of the 7th Workshop on Economics of Information Security.","author":"Zhuge J.","unstructured":"Zhuge , J. , Holz , T. , Song , C. , Guo , J. , Han , X. , and Zou , W . 2008. Studying malicious websites and the underground economy on the Chinese web . In Proceedings of the 7th Workshop on Economics of Information Security. Zhuge, J., Holz, T., Song, C., Guo, J., Han, X., and Zou, W. 2008. Studying malicious websites and the underground economy on the Chinese web. In Proceedings of the 7th Workshop on Economics of Information Security."},{"key":"e_1_2_1_99_1","volume-title":"Proceedings of the Black Hat Briefings and Training Conference.","author":"Zovi D. D.","year":"2006","unstructured":"Zovi , D. D. 2006 . Hardware virtualization based rootkits . In Proceedings of the Black Hat Briefings and Training Conference. Zovi, D. D. 2006. Hardware virtualization based rootkits. In Proceedings of the Black Hat Briefings and Training Conference."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2089125.2089126","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2089125.2089126","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:56:10Z","timestamp":1750254970000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2089125.2089126"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,3,5]]},"references-count":99,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,2]]}},"alternative-id":["10.1145\/2089125.2089126"],"URL":"https:\/\/doi.org\/10.1145\/2089125.2089126","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2008,3,5]]},"assertion":[{"value":"2009-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-03-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}