{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T01:10:02Z","timestamp":1750209002799,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,12,3]],"date-time":"2018-12-03T00:00:00Z","timestamp":1543795200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,12,3]]},"DOI":"10.1145\/3289239.3289245","type":"proceedings-article","created":{"date-parts":[[2018,12,5]],"date-time":"2018-12-05T13:05:06Z","timestamp":1544015106000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["SysTaint"],"prefix":"10.1145","author":[{"given":"Gabriele","family":"Viglianisi","sequence":"first","affiliation":[{"name":"Politecnico di Milano"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[{"name":"Politecnico di Milano"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mario","family":"Polino","sequence":"additional","affiliation":[{"name":"Politecnico di Milano"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Continella","sequence":"additional","affiliation":[{"name":"Politecnico di Milano"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[{"name":"Politecnico di Milano"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,12,3]]},"reference":[{"volume-title":"McAfee Labs Threat Report","year":"2017","key":"e_1_3_2_1_1_1","unstructured":"2017. McAfee Labs Threat Report December 2017 . https:\/\/www.mcafee.com\/uk\/resources\/reports\/rp-quarterly-threats-dec-2017.pdf 2017. McAfee Labs Threat Report December 2017. https:\/\/www.mcafee.com\/uk\/resources\/reports\/rp-quarterly-threats-dec-2017.pdf"},{"key":"e_1_3_2_1_2_1","unstructured":"2018. Cuckoo Sandbox. https:\/\/cuckoosandbox.org\/  2018. Cuckoo Sandbox. https:\/\/cuckoosandbox.org\/"},{"key":"e_1_3_2_1_3_1","unstructured":"2018. Rekall memory forensic framework. http:\/\/www.rekall-forensic.com\/  2018. Rekall memory forensic framework. http:\/\/www.rekall-forensic.com\/"},{"key":"e_1_3_2_1_4_1","unstructured":"2018. VxStream Sandbox. https:\/\/www.payload-security.com\/products\/vxstream-sandbox  2018. VxStream Sandbox. https:\/\/www.payload-security.com\/products\/vxstream-sandbox"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653737"},{"key":"e_1_3_2_1_6_1","volume-title":"Prometheus: Analyzing WebInject-based information stealers. Journal of Computer Security","author":"Continella Andrea","year":"2017","unstructured":"Andrea Continella , Michele Carminati , Mario Polino , Andrea Lanzi , Stefano Zanero , and Federico Maggi . 2017 . Prometheus: Analyzing WebInject-based information stealers. Journal of Computer Security (2017). Andrea Continella, Michele Carminati, Mario Polino, Andrea Lanzi, Stefano Zanero, and Federico Maggi. 2017. Prometheus: Analyzing WebInject-based information stealers. Journal of Computer Security (2017)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991110"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2007.06.008"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2843859.2843867"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516697"},{"key":"e_1_3_2_1_11_1","unstructured":"The Volatility Foundation. 2018. Volatility Framework - Volatile memory extraction utility framework. https:\/\/github.com\/volatilityfoundation\/volatility.  The Volatility Foundation. 2018. Volatility Framework - Volatile memory extraction utility framework. https:\/\/github.com\/volatilityfoundation\/volatility."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2421000"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_3"},{"key":"e_1_3_2_1_14_1","unstructured":"George Hotz. 2016. QIRA. http:\/\/qira.me\/  George Hotz. 2016. QIRA. http:\/\/qira.me\/"},{"key":"e_1_3_2_1_15_1","unstructured":"Jaros\u0142aw Jedynak. 2018. Mtracker - our take on malware tracking - CERT Polska. https:\/\/www.cert.pl\/en\/news\/single\/mtracker-our-take-malware-tracking\/  Jaros\u0142aw Jedynak. 2018. Mtracker - our take on malware tracking - CERT Polska. https:\/\/www.cert.pl\/en\/news\/single\/mtracker-our-take-malware-tracking\/"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134045"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076790"},{"key":"e_1_3_2_1_18_1","volume-title":"Proc. of USENIX Security.","author":"Kirat Dhilung","year":"2014","unstructured":"Dhilung Kirat , Giovanni Vigna , and Christopher Kruegel . 2014 . BareCloud: Baremetal Analysis-based Evasive Malware Detection .. In Proc. of USENIX Security. Dhilung Kirat, Giovanni Vigna, and Christopher Kruegel. 2014. BareCloud: Baremetal Analysis-based Evasive Malware Detection.. In Proc. of USENIX Security."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2012.83"},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the 15th Symposium on Network and Distributed System Security (NDSS).","author":"Lin Zhiqiang","year":"2008","unstructured":"Zhiqiang Lin , Xuxian Jiang , Dongyan Xu , and Xiangyu Zhang . 2008 . Automatic Protocol Format Reverse Engineering through Context-Aware Monitored Execution . In Proceedings of the 15th Symposium on Network and Distributed System Security (NDSS). Zhiqiang Lin, Xuxian Jiang, Dongyan Xu, and Xiangyu Zhang. 2008. Automatic Protocol Format Reverse Engineering through Context-Aware Monitored Execution. In Proceedings of the 15th Symposium on Network and Distributed System Security (NDSS)."},{"key":"e_1_3_2_1_21_1","unstructured":"No\u00e9 Lutz. 2008. Towards revealing attacker's intent by automatically decrypting network traffic. (2008).  No\u00e9 Lutz. 2008. Towards revealing attacker's intent by automatically decrypting network traffic. (2008)."},{"key":"e_1_3_2_1_22_1","unstructured":"Microsoft. 2017. Time Travel Debugging in WinDbg. https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/debugger\/time-travel-debugging-overview  Microsoft. 2017. Time Travel Debugging in WinDbg. https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/debugger\/time-travel-debugging-overview"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/3154690.3154727"},{"key":"e_1_3_2_1_24_1","unstructured":"Roberto Paleari. 2014. Introducing QTrace a \"zero knowledge\" system call tracer. http:\/\/roberto.greyhats.it\/2014\/03\/qtrace-part1.html  Roberto Paleari. 2014. Introducing QTrace a \"zero knowledge\" system call tracer. http:\/\/roberto.greyhats.it\/2014\/03\/qtrace-part1.html"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_4"},{"key":"e_1_3_2_1_26_1","volume-title":"Toward Systematically Exploring Antivirus Engines. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer.","author":"Quarta Davide","year":"2018","unstructured":"Davide Quarta , Federico Salvioni , Andrea Continella , and Stefano Zanero . 2018 . Toward Systematically Exploring Antivirus Engines. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer. Davide Quarta, Federico Salvioni, Andrea Continella, and Stefano Zanero. 2018. Toward Systematically Exploring Antivirus Engines. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1978672.1978682"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.14"},{"key":"e_1_3_2_1_29_1","unstructured":"Joe Security. 2016. Automated Malware Analysis - Nymaim - evading Sandboxes with API hammering. https:\/\/www.joesecurity.org\/blog\/3660886847485093803  Joe Security. 2016. Automated Malware Analysis - Nymaim - evading Sandboxes with API hammering. https:\/\/www.joesecurity.org\/blog\/3660886847485093803"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93411-2_1"},{"key":"e_1_3_2_1_31_1","volume-title":"Proc. of the Network and Distributed System Security Symposium (NDSS).","author":"Spensky C","year":"2016","unstructured":"C Spensky , H Hu , and K Leach . 2016 . LO-PHI: Low Observable Physical Host Instrumentation . In Proc. of the Network and Distributed System Security Symposium (NDSS). C Spensky, H Hu, and K Leach. 2016. LO-PHI: Low Observable Physical Host Instrumentation. In Proc. of the Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"e_1_3_2_1_33_1","unstructured":"Tomer Teller and Adi Hayon. 2014. Enhancing automated malware analysis machines with memory analysis. (2014).  Tomer Teller and Adi Hayon. 2014. Enhancing automated malware analysis machines with memory analysis. (2014)."},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Wang Ruoyu","year":"2013","unstructured":"Ruoyu Wang , Yan Shoshitaishvili , Christopher Kruegel , and Giovanni Vigna . 2013 . Steal This Movie: Automatically Bypassing DRM Protection in Streaming Media Services .. In Proceedings of the USENIX Security Symposium. Ruoyu Wang, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2013. Steal This Movie: Automatically Bypassing DRM Protection in Streaming Media Services.. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/1813084.1813102"}],"event":{"name":"SSPREW-8: Software Security, Protection, and Reverse Engineering Workshop","acronym":"SSPREW-8","location":"San Juan PR USA"},"container-title":["Proceedings of the 8th Software Security, Protection, and Reverse Engineering Workshop"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3289239.3289245","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3289239.3289245","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:43:38Z","timestamp":1750207418000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3289239.3289245"}},"subtitle":["Assisting Reversing of Malicious Network Communications"],"short-title":[],"issued":{"date-parts":[[2018,12,3]]},"references-count":35,"alternative-id":["10.1145\/3289239.3289245","10.1145\/3289239"],"URL":"https:\/\/doi.org\/10.1145\/3289239.3289245","relation":{},"subject":[],"published":{"date-parts":[[2018,12,3]]},"assertion":[{"value":"2018-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}