{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T14:13:22Z","timestamp":1770819202111,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,12,3]],"date-time":"2012-12-03T00:00:00Z","timestamp":1354492800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["01BY-1205A"],"award-info":[{"award-number":["01BY-1205A"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Ministry of Economic Affairs and Energy of the State of North Rhine-Westphalia","award":["315-43-02\/2-005-WFBO-009"],"award-info":[{"award-number":["315-43-02\/2-005-WFBO-009"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,12,3]]},"DOI":"10.1145\/2420950.2420980","type":"proceedings-article","created":{"date-parts":[[2012,12,19]],"date-time":"2012-12-19T14:12:22Z","timestamp":1355926342000},"page":"189-198","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":33,"title":["Down to the bare metal"],"prefix":"10.1145","author":[{"given":"Carsten","family":"Willems","sequence":"first","affiliation":[{"name":"Ruhr-University Bochum"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ralf","family":"Hund","sequence":"additional","affiliation":[{"name":"Ruhr-University Bochum"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andreas","family":"Fobian","sequence":"additional","affiliation":[{"name":"Ruhr-University Bochum"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dennis","family":"Felsch","sequence":"additional","affiliation":[{"name":"Ruhr-University Bochum"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thorsten","family":"Holz","sequence":"additional","affiliation":[{"name":"Ruhr-University Bochum"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amit","family":"Vasudevan","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,12,3]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"AMD","author":"Devices Advanced Micro","year":"2010","unstructured":"Advanced Micro Devices . AMD Lightweight Profiling Specification. Specification , AMD , 2010 . Advanced Micro Devices. AMD Lightweight Profiling Specification. Specification, AMD, 2010."},{"key":"e_1_3_2_1_2_1","volume-title":"Giovanni Vigna. Efficient Detection of Split Personalities in Malware. In Network and Distributed System Security Symposium (NDSS)","author":"Balzarotti Davide","year":"2010","unstructured":"Davide Balzarotti , Marco Cova , Christoph Karlberger , Engin Kirda , Christopher Kruegel , and Giovanni Vigna. Efficient Detection of Split Personalities in Malware. In Network and Distributed System Security Symposium (NDSS) , 2010 . Davide Balzarotti, Marco Cova, Christoph Karlberger, Engin Kirda, Christopher Kruegel, and Giovanni Vigna. Efficient Detection of Split Personalities in Malware. In Network and Distributed System Security Symposium (NDSS), 2010."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0012-2"},{"key":"e_1_3_2_1_4_1","volume-title":"Bellard. QEMU: A Fast and Portable Dynamic Translator. In USENIX Annual Technical Conference","author":"Fabrice","year":"2005","unstructured":"Fabrice Bellard. QEMU: A Fast and Portable Dynamic Translator. In USENIX Annual Technical Conference , 2005 . Fabrice Bellard. QEMU: A Fast and Portable Dynamic Translator. In USENIX Annual Technical Conference, 2005."},{"key":"e_1_3_2_1_5_1","volume-title":"USENIX Security Symposium","author":"Bhatkar Sandeep","year":"2003","unstructured":"Sandeep Bhatkar , Daniel C. DuVarney , and R. Sekar . Address Obfuscation: an Efficient Approach to Combat a Broad Range of Memory Error Exploits . In USENIX Security Symposium , 2003 . Sandeep Bhatkar, Daniel C. DuVarney, and R. Sekar. Address Obfuscation: an Efficient Approach to Combat a Broad Range of Memory Error Exploits. In USENIX Security Symposium, 2003."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.20"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.12"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772720"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966920"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"e_1_3_2_1_11_1","volume-title":"Dawn Song. Dynamic Spyware Analysis. In USENIX Annual Technical Conference","author":"Egele Manuel","year":"2007","unstructured":"Manuel Egele , Christopher Kruegel , Engin Kirda , Heng Yin , and Dawn Song. Dynamic Spyware Analysis. In USENIX Annual Technical Conference , 2007 . Manuel Egele, Christopher Kruegel, Engin Kirda, Heng Yin, and Dawn Song. Dynamic Spyware Analysis. In USENIX Annual Technical Conference, 2007."},{"key":"e_1_3_2_1_12_1","volume-title":"Xiaowei Xu. A Density-Based Algorithm for Discovering Clusters in Large Spatial Databases with Noise. In Conference on Knowledge Discovery and Data Mining (KDD)","author":"Ester Martin","year":"1996","unstructured":"Martin Ester , Hans-Peter Kriegel , J\u00f6rg Sander , and Xiaowei Xu. A Density-Based Algorithm for Discovering Clusters in Large Spatial Databases with Noise. In Conference on Knowledge Discovery and Data Mining (KDD) , 1996 . Martin Ester, Hans-Peter Kriegel, J\u00f6rg Sander, and Xiaowei Xu. A Density-Based Algorithm for Discovering Clusters in Large Spatial Databases with Noise. In Conference on Knowledge Discovery and Data Mining (KDD), 1996."},{"key":"e_1_3_2_1_13_1","unstructured":"Peter Ferrie. Attacks on virtual machine emulators. http:\/\/pferrie.tripod.com\/papers\/attacks.pdf 2007.  Peter Ferrie. Attacks on virtual machine emulators. http:\/\/pferrie.tripod.com\/papers\/attacks.pdf 2007."},{"key":"e_1_3_2_1_14_1","volume-title":"Workshop on Hot Topics in Operating Systems (HotOS-XI)","author":"Garfinkel Tal","year":"2007","unstructured":"Tal Garfinkel , Keith Adams , Andrew Warfield , and Jason Franklin . Compatibility is Not Transparency: VMM Detection Myths and Realities . In Workshop on Hot Topics in Operating Systems (HotOS-XI) , 2007 . Tal Garfinkel, Keith Adams, Andrew Warfield, and Jason Franklin. Compatibility is Not Transparency: VMM Detection Myths and Realities. In Workshop on Hot Topics in Operating Systems (HotOS-XI), 2007."},{"key":"e_1_3_2_1_15_1","volume-title":"Garfinkel and Mendel Rosenblum. A Virtual Machine Introspection Based Architecture for Intrusion Detection. In Symposium on Network and Distributed System Security (NDSS)","author":"Tal","year":"2003","unstructured":"Tal Garfinkel and Mendel Rosenblum. A Virtual Machine Introspection Based Architecture for Intrusion Detection. In Symposium on Network and Distributed System Security (NDSS) , 2003 . Tal Garfinkel and Mendel Rosenblum. A Virtual Machine Introspection Based Architecture for Intrusion Detection. In Symposium on Network and Distributed System Security (NDSS), 2003."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1375581.1375607"},{"key":"e_1_3_2_1_17_1","volume-title":"Specification","author":"Intel Corporation","year":"2007","unstructured":"Intel Corporation . Intel : 64 and IA-32 Architectures Software Developer's Manual . Specification , Intel , 2007 . http:\/\/www.intel.com\/products\/processor\/manuals\/index.htm. Intel Corporation. Intel: 64 and IA-32 Architectures Software Developer's Manual. Specification, Intel, 2007. http:\/\/www.intel.com\/products\/processor\/manuals\/index.htm."},{"key":"e_1_3_2_1_18_1","volume-title":"Specification","author":"Intel Corporation","year":"2010","unstructured":"Intel Corporation . Intel Microarchitecture Codename Nehalem Performance Monitoring Unit Programming Guide (Nehalem Core PMU) . Specification , Intel , 2010 . Intel Corporation. Intel Microarchitecture Codename Nehalem Performance Monitoring Unit Programming Guide (Nehalem Core PMU). Specification, Intel, 2010."},{"key":"e_1_3_2_1_19_1","unstructured":"Matthew A. Jaro. Unimatch: A record linkage system. http:\/\/books.google.de\/books?id=was9AAAAIAAJ 1978.  Matthew A. Jaro. Unimatch: A record linkage system. http:\/\/books.google.de\/books?id=was9AAAAIAAJ 1978."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655148.1655151"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_18"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.19"},{"key":"e_1_3_2_1_23_1","article-title":"A Portable PC Emulator for Unix\/X","volume":"1996","author":"Lawton Kevin P.","year":"1996","unstructured":"Kevin P. Lawton . Bochs : A Portable PC Emulator for Unix\/X . Linux J. , 1996 , September 1996 . Kevin P. Lawton. Bochs: A Portable PC Emulator for Unix\/X. Linux J., 1996, September 1996.","journal-title":"Linux J."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948149"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1572272.1572303"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1831708.1831730"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.17"},{"key":"e_1_3_2_1_28_1","volume-title":"Network and Distributed System Security Symposium (NDSS)","author":"Newsome James","year":"2005","unstructured":"James Newsome and Dawn Xiaodong Song . Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software . In Network and Distributed System Security Symposium (NDSS) , 2005 . James Newsome and Dawn Xiaodong Song. Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software. In Network and Distributed System Security Symposium (NDSS), 2005."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.55"},{"key":"e_1_3_2_1_30_1","unstructured":"Travis Ormandy. An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environments. http:\/\/taviso.decsystem.org\/virtsec.pdf.  Travis Ormandy. An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environments. http:\/\/taviso.decsystem.org\/virtsec.pdf."},{"key":"e_1_3_2_1_31_1","volume-title":"Gregory Andrews. Binary Obfuscation Using Signals. In USENIX Security Symposium","author":"Popov Igor","year":"2007","unstructured":"Igor Popov , Saumya Debray , and Gregory Andrews. Binary Obfuscation Using Signals. In USENIX Security Symposium , 2007 . Igor Popov, Saumya Debray, and Gregory Andrews. Binary Obfuscation Using Signals. In USENIX Security Symposium, 2007."},{"key":"e_1_3_2_1_32_1","volume-title":"Engin Kirda. Detecting System Emulators. In Information Security Conference (ISC)","author":"Raffetseder Thomas","year":"2007","unstructured":"Thomas Raffetseder , Christopher Kr\u00fcgel , and Engin Kirda. Detecting System Emulators. In Information Security Conference (ISC) , 2007 . Thomas Raffetseder, Christopher Kr\u00fcgel, and Engin Kirda. Detecting System Emulators. In Information Security Conference (ISC), 2007."},{"key":"e_1_3_2_1_33_1","unstructured":"Rapid7. The metasploit framework. http:\/\/metasploit.com\/.  Rapid7. The metasploit framework. http:\/\/metasploit.com\/."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.38"},{"key":"e_1_3_2_1_35_1","unstructured":"Joanna Rutkowska. Red Pill... or how to detect VMM using (almost) one CPU instruction. http:\/\/invisiblethings.org\/papers\/redpill.html 2004.  Joanna Rutkowska. Red Pill... or how to detect VMM using (almost) one CPU instruction. http:\/\/invisiblethings.org\/papers\/redpill.html 2004."},{"key":"e_1_3_2_1_36_1","unstructured":"Hex Rays SA. IDA Pro Disassembler and Debugger. http:\/\/www.hex-rays.com\/idapro\/.  Hex Rays SA. IDA Pro Disassembler and Debugger. http:\/\/www.hex-rays.com\/idapro\/."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_3_2_1_39_1","volume-title":"Wenke Lee. Impeding Malware Analysis Using Conditional Code Obfuscation. In Network and Distributed System Security Symposium (NDSS)","author":"Sharif Monirul I.","year":"2008","unstructured":"Monirul I. Sharif , Andrea Lanzi , Jonathon T. Giffin , and Wenke Lee. Impeding Malware Analysis Using Conditional Code Obfuscation. In Network and Distributed System Security Symposium (NDSS) , 2008 . Monirul I. Sharif, Andrea Lanzi, Jonathon T. Giffin, and Wenke Lee. Impeding Malware Analysis Using Conditional Code Obfuscation. In Network and Distributed System Security Symposium (NDSS), 2008."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_1"},{"key":"e_1_3_2_1_41_1","volume-title":"Internet Security Threat Report","year":"2010","unstructured":"Symantec. Internet Security Threat Report , 2010 . Symantec. Internet Security Threat Report, 2010."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/822079.822711"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2011.500"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.9"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"},{"key":"e_1_3_2_1_48_1","first-page":"354","volume-title":"Winkler. String Comparator Metrics and Enhanced Decision Rules in the Fellegi-Sunter Model of Record Linkage. In Proceedings of the Survey Research Methods Section","author":"William","year":"1990","unstructured":"William E. Winkler. String Comparator Metrics and Enhanced Decision Rules in the Fellegi-Sunter Model of Record Linkage. In Proceedings of the Survey Research Methods Section , pages 354 -- 359 , 1990 . William E. Winkler. String Comparator Metrics and Enhanced Decision Rules in the Fellegi-Sunter Model of Record Linkage. In Proceedings of the Survey Research Methods Section, pages 354--359, 1990."}],"event":{"name":"ACSAC '12: Annual Computer Security Applications Conference","location":"Orlando Florida USA","acronym":"ACSAC '12","sponsor":["ACSA Applied Computing Security Assoc"]},"container-title":["Proceedings of the 28th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420980","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2420950.2420980","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:18:33Z","timestamp":1750234713000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420980"}},"subtitle":["using processor features for binary analysis"],"short-title":[],"issued":{"date-parts":[[2012,12,3]]},"references-count":46,"alternative-id":["10.1145\/2420950.2420980","10.1145\/2420950"],"URL":"https:\/\/doi.org\/10.1145\/2420950.2420980","relation":{},"subject":[],"published":{"date-parts":[[2012,12,3]]},"assertion":[{"value":"2012-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}