{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T23:14:36Z","timestamp":1763507676379,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":28,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,12,3]],"date-time":"2012-12-03T00:00:00Z","timestamp":1354492800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["257007"],"award-info":[{"award-number":["257007"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,12,3]]},"DOI":"10.1145\/2420950.2421000","type":"proceedings-article","created":{"date-parts":[[2012,12,19]],"date-time":"2012-12-19T14:12:22Z","timestamp":1355926342000},"page":"339-348","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Towards network containment in malware analysis systems"],"prefix":"10.1145","author":[{"given":"Mariano","family":"Graziano","sequence":"first","affiliation":[{"name":"Institut Eurecom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Corrado","family":"Leita","sequence":"additional","affiliation":[{"name":"Symantec Research Labs"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"Institut Eurecom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,12,3]]},"reference":[{"volume-title":"http:\/\/www.secdev.org\/projects\/scapy\/","year":"2003","key":"e_1_3_2_1_1_1","unstructured":"Scapy. http:\/\/www.secdev.org\/projects\/scapy\/ , 2003 . Scapy. http:\/\/www.secdev.org\/projects\/scapy\/, 2003."},{"key":"e_1_3_2_1_2_1","unstructured":"nfqueue-bindings. :\/\/www.wzdftpd.net\/redmine\/projects\/nfqueue-bindings\/wiki\/ 2008.  nfqueue-bindings. :\/\/www.wzdftpd.net\/redmine\/projects\/nfqueue-bindings\/wiki\/ 2008."},{"volume-title":"http:\/\/anubis.iseclab.org","year":"2009","key":"e_1_3_2_1_3_1","unstructured":"Anubis. http:\/\/anubis.iseclab.org , 2009 . Anubis. http:\/\/anubis.iseclab.org, 2009."},{"volume-title":"http:\/\/www.mwanalysis.org","year":"2009","key":"e_1_3_2_1_4_1","unstructured":"Cwsandbox. http:\/\/www.mwanalysis.org , 2009 . Cwsandbox. http:\/\/www.mwanalysis.org, 2009."},{"volume-title":"http:\/\/www.netzob.org","year":"2009","key":"e_1_3_2_1_5_1","unstructured":"Netzob. http:\/\/www.netzob.org , 2009 . Netzob. http:\/\/www.netzob.org, 2009."},{"key":"e_1_3_2_1_6_1","volume-title":"http:\/\/www.cuckoosandbox.org","author":"Sandbox Cuckoo","year":"2010","unstructured":"Cuckoo Sandbox . http:\/\/www.cuckoosandbox.org , 2010 . Cuckoo Sandbox. http:\/\/www.cuckoosandbox.org, 2010."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS)","author":"Balzarotti D.","year":"2010","unstructured":"D. Balzarotti , M. Cova , C. Karlberger , C. Kruegel , E. Kirda , and G. Vigna . Efficient Detection of Split Personalities in Malware . In Proceedings of the Network and Distributed System Security Symposium (NDSS) , San Diego, CA , February 2010 . D. Balzarotti, M. Cova, C. Karlberger, C. Kruegel, E. Kirda, and G. Vigna. Efficient Detection of Split Personalities in Malware. In Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2010."},{"key":"e_1_3_2_1_8_1","volume-title":"TTAnalyze: A Tool for Analyzing Malware. In 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference","author":"Bayer U.","year":"2006","unstructured":"U. Bayer , C. Kruegel , and E. Kirda . TTAnalyze: A Tool for Analyzing Malware. In 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference , April 2006 . U. Bayer, C. Kruegel, and E. Kirda. TTAnalyze: A Tool for Analyzing Malware. In 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference, April 2006."},{"key":"e_1_3_2_1_9_1","volume-title":"Behavior-Based Malware Clustering. In 16th Symp. on Network and Distributed System Security (NDSS)","author":"Bayer U.","year":"2009","unstructured":"U. Bayer , P. Milani Comparetti , C. Kruegel , and E. Kirda . Scalable , Behavior-Based Malware Clustering. In 16th Symp. on Network and Distributed System Security (NDSS) , 2009 . U. Bayer, P. Milani Comparetti, C. Kruegel, and E. Kirda. Scalable, Behavior-Based Malware Clustering. In 16th Symp. on Network and Distributed System Security (NDSS), 2009."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315286"},{"key":"e_1_3_2_1_11_1","volume-title":"16th USENIX Security Symposium","author":"Cui W.","year":"2007","unstructured":"W. Cui , J. Kannan , and H. J. Wang . Discoverer: Automatic protocol reverse engineering from network traces . In 16th USENIX Security Symposium , 2007 . W. Cui, J. Kannan, and H. J. Wang. Discoverer: Automatic protocol reverse engineering from network traces. In 16th USENIX Security Symposium, 2007."},{"key":"e_1_3_2_1_13_1","volume-title":"The 13th Annual Network and Distributed System Security Symposium (NDSS)","author":"Cui W.","year":"2006","unstructured":"W. Cui , V. Paxson , N. Weaver , and R. H. Katz . Protocol-independent adaptive replay of application dialog . In The 13th Annual Network and Distributed System Security Symposium (NDSS) , February 2006 . W. Cui, V. Paxson, N. Weaver, and R. H. Katz. Protocol-independent adaptive replay of application dialog. In The 13th Annual Network and Distributed System Security Symposium (NDSS), February 2006."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2008.330"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068854"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2010.5544291"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/EDCC-7.2008.15"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_10"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.49"},{"key":"e_1_3_2_1_21_1","volume-title":"15th Annual Network and Distributed System Security Symposium","author":"Lin Z.","year":"2008","unstructured":"Z. Lin , X. Jiang , D. Xu , and X. Zhang . Automatic Protocol Format Reverse Engineering through Context-Aware Monitored Execution . In 15th Annual Network and Distributed System Security Symposium , San Diego, CA , February 2008 . Z. Lin, X. Jiang, D. Xu, and X. Zhang. Automatic Protocol Format Reverse Engineering through Context-Aware Monitored Execution. In 15th Annual Network and Distributed System Security Symposium, San Diego, CA, February 2008."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1453101.1453114"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/0022-2836(70)90057-4"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1978672.1978682"},{"key":"e_1_3_2_1_25_1","unstructured":"Symantec. The Stuxnet worm. http:\/\/go.symantec.com\/stuxnet.  Symantec. The Stuxnet worm. http:\/\/go.symantec.com\/stuxnet."},{"key":"e_1_3_2_1_26_1","unstructured":"Symantec. W32.Duqu the precursor to the next Stuxnet. http:\/\/go.symantec.com\/duqu.  Symantec. W32.Duqu the precursor to the next Stuxnet. http:\/\/go.symantec.com\/duqu."},{"key":"e_1_3_2_1_27_1","unstructured":"Symantec. W32.Koobface. http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2008-080315-0217-99.  Symantec. W32.Koobface. http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2008-080315-0217-99."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095809.1095825"},{"key":"e_1_3_2_1_29_1","volume-title":"15th Annual Network and Distributed System Security Symposium (NDSS'08)","author":"Wondracek G.","year":"2008","unstructured":"G. Wondracek , P. M. Comparetti , C. Kruegel , and E. Kirda . Automatic network protocol analysis . In 15th Annual Network and Distributed System Security Symposium (NDSS'08) , 2008 . G. Wondracek, P. M. Comparetti, C. Kruegel, and E. Kirda. Automatic network protocol analysis. In 15th Annual Network and Distributed System Security Symposium (NDSS'08), 2008."},{"key":"e_1_3_2_1_30_1","volume-title":"2009 Joint Workshop on Information Security (JWIS 2009)","author":"Yoshioka K.","year":"2009","unstructured":"K. Yoshioka , T. Kasama , and T. Matsumoto . Sandbox analysis with controlled internet connection for observing temporal changes of malware behavior . In 2009 Joint Workshop on Information Security (JWIS 2009) , 2009 . K. Yoshioka, T. Kasama, and T. Matsumoto. Sandbox analysis with controlled internet connection for observing temporal changes of malware behavior. In 2009 Joint Workshop on Information Security (JWIS 2009), 2009."}],"event":{"name":"ACSAC '12: Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Orlando Florida USA","acronym":"ACSAC '12"},"container-title":["Proceedings of the 28th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2421000","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2420950.2421000","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:18:33Z","timestamp":1750234713000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2421000"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,12,3]]},"references-count":28,"alternative-id":["10.1145\/2420950.2421000","10.1145\/2420950"],"URL":"https:\/\/doi.org\/10.1145\/2420950.2421000","relation":{},"subject":[],"published":{"date-parts":[[2012,12,3]]},"assertion":[{"value":"2012-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}