{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:18:34Z","timestamp":1750306714606,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":20,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,9,9]],"date-time":"2014-09-09T00:00:00Z","timestamp":1410220800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,9,9]]},"DOI":"10.1145\/2659651.2659710","type":"proceedings-article","created":{"date-parts":[[2014,12,16]],"date-time":"2014-12-16T13:41:52Z","timestamp":1418737312000},"page":"405-410","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Virtual Machine Introspection"],"prefix":"10.1145","author":[{"given":"Thu Yein","family":"Win","sequence":"first","affiliation":[{"name":"School of Engineering and Built Environment, Glasgow Caledonian University, Glasgow G4 0BA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huaglory","family":"Tianfield","sequence":"additional","affiliation":[{"name":"School of Engineering and Built Environment, Glasgow Caledonian University, Glasgow G4 0BA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quentin","family":"Mair","sequence":"additional","affiliation":[{"name":"School of Engineering and Built Environment, Glasgow Caledonian University, Glasgow G4 0BA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taimur Al","family":"Said","sequence":"additional","affiliation":[{"name":"School of Computer Science and Informatics, Cardiff University, Cardiff CF24 3AA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Omer F.","family":"Rana","sequence":"additional","affiliation":[{"name":"School of Computer Science and Informatics, Cardiff University, Cardiff CF24 3AA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,9,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"I. Ahmed G. G. Richard III A. Zoranic and V. Roussev. Integrity checking of function pointers in kernel pools via virtual machine introspection.  I. Ahmed G. G. Richard III A. Zoranic and V. Roussev. Integrity checking of function pointers in kernel pools via virtual machine introspection."},{"key":"e_1_3_2_1_2_1","volume":"2012","author":"Alarifi S. S.","unstructured":"S. S. Alarifi and S. D. Wolthusen . Detecting anomalies in iaas environments through virtual machine host system call analysis. In Internet Technology And Secured Transactions , 2012 International Conferece For, pages 211--218. IEEE, 2012. S. S. Alarifi and S. D. Wolthusen. Detecting anomalies in iaas environments through virtual machine host system call analysis. In Internet Technology And Secured Transactions, 2012 International Conferece For, pages 211--218. IEEE, 2012.","journal-title":"In Internet Technology And Secured Transactions"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2010.39"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/IAS.2007.25"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2012.145"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33338-5_2"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"e_1_3_2_1_8_1","first-page":"191","volume-title":"Proceedings of Network and Distributed Systems Security Symposium","author":"Garfinkel T.","year":"2003","unstructured":"T. Garfinkel and M. Rosenblum . A virtual machine introspection based architecture for intrusion detection . In Proceedings of Network and Distributed Systems Security Symposium , pages 191 -- 206 , 2003 . T. Garfinkel and M. Rosenblum. A virtual machine introspection based architecture for intrusion detection. In Proceedings of Network and Distributed Systems Security Symposium, pages 191--206, 2003."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2012.113"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNSS.2011.6059967"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"key":"e_1_3_2_1_12_1","volume-title":"Technische Universit\u00e4t M\u00fcnchen (TUM)","author":"Kittel T.","year":"2010","unstructured":"T. Kittel . Design and implementation of a virtual machine introspection based intrusion detection system. diploma thesis , Technische Universit\u00e4t M\u00fcnchen (TUM) , 2010 . T. Kittel. Design and implementation of a virtual machine introspection based intrusion detection system. diploma thesis, Technische Universit\u00e4t M\u00fcnchen (TUM), 2010."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/1018420.1019724"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38631-2_13"},{"key":"e_1_3_2_1_15_1","first-page":"243","volume-title":"USENIX Security Symposium","author":"Litty L.","year":"2008","unstructured":"L. Litty , H. A. Lagar-Cavilla , and D. Lie . Hypervisor support for identifying covertly executing binaries . In USENIX Security Symposium , pages 243 -- 258 , 2008 . L. Litty, H. A. Lagar-Cavilla, and D. Lie. Hypervisor support for identifying covertly executing binaries. In USENIX Security Symposium, pages 243--258, 2008."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.10"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1229313"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2014.36"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2133375.2133377"},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the 18th Annual Network and Distributed Security Symposium","author":"Srivastava A.","year":"2011","unstructured":"A. Srivastava and J. T. Giffin . Efficient monitoring of untrusted kernel-mode execution . In Proceedings of the 18th Annual Network and Distributed Security Symposium , 2011 . A. Srivastava and J. T. Giffin. Efficient monitoring of untrusted kernel-mode execution. In Proceedings of the 18th Annual Network and Distributed Security Symposium, 2011."}],"event":{"name":"SIN '14: The 7th International Conference on Security of Information and Networks","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","MNIT Malaviya National Institute of Technology","Aksaray Univ. Aksaray University","SICSA The Scottish Informatics and Computer Science Alliance","University of Glasgow University of Glasgow"],"location":"Glasgow Scotland UK","acronym":"SIN '14"},"container-title":["Proceedings of the 7th International Conference on Security of Information and Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2659651.2659710","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2659651.2659710","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T07:19:22Z","timestamp":1750231162000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2659651.2659710"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,9,9]]},"references-count":20,"alternative-id":["10.1145\/2659651.2659710","10.1145\/2659651"],"URL":"https:\/\/doi.org\/10.1145\/2659651.2659710","relation":{},"subject":[],"published":{"date-parts":[[2014,9,9]]},"assertion":[{"value":"2014-09-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}