{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T03:47:30Z","timestamp":1769744850699,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,12,2]],"date-time":"2019-12-02T00:00:00Z","timestamp":1575244800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,12,2]]},"DOI":"10.1145\/3344341.3368810","type":"proceedings-article","created":{"date-parts":[[2019,11,27]],"date-time":"2019-11-27T13:23:09Z","timestamp":1574860989000},"page":"219-227","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Container-based Sandboxes for Malware Analysis"],"prefix":"10.1145","author":[{"given":"Ayrat","family":"Khalimov","sequence":"first","affiliation":[{"name":"Innopolis University, Innopolis, Russian Fed."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sofiane","family":"Benahmed","sequence":"additional","affiliation":[{"name":"Innopolis University, Innopolis, Russian Fed."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rasheed","family":"Hussain","sequence":"additional","affiliation":[{"name":"Innopolis University, Innopolis, Russian Fed."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S.M. Ahsan","family":"Kazmi","sequence":"additional","affiliation":[{"name":"Innopolis University, Innopolis, Russian Fed."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alma","family":"Oracevic","sequence":"additional","affiliation":[{"name":"Innopolis University, Innopolis, Russian Fed."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fatima","family":"Hussain","sequence":"additional","affiliation":[{"name":"Royal Bank of Canada, Toronto, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Farhan","family":"Ahmad","sequence":"additional","affiliation":[{"name":"University of Derby, Derby, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chaker Abdelaziz","family":"Kerrache","sequence":"additional","affiliation":[{"name":"University of Ghardaia, Ghardaia, Algeria"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,12,2]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. BSTJ version of C.ACM Unix paper. https:\/\/www.bell-labs.com\/usr\/dmr\/ www\/cacm.html. (Accessed on 09\/09\/2019).  [n. d.]. BSTJ version of C.ACM Unix paper. https:\/\/www.bell-labs.com\/usr\/dmr\/ www\/cacm.html. (Accessed on 09\/09\/2019)."},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. capabilities(7) - Linux manual page. http:\/\/man7.org\/linux\/man-pages\/ man7\/capabilities.7.html. (Accessed on 08\/31\/2019).  [n. d.]. capabilities(7) - Linux manual page. http:\/\/man7.org\/linux\/man-pages\/ man7\/capabilities.7.html. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_3_1","unstructured":"[n. d.]. dockercon-workshop\/capabilities at master \u00c2 riyazdf\/dockerconworkshop \u00c2 GitHub. https:\/\/github.com\/riyazdf\/dockercon-workshop\/tree\/ master\/capabilities. (Accessed on 08\/31\/2019).  [n. d.]. dockercon-workshop\/capabilities at master \u00c2 riyazdf\/dockerconworkshop \u00c2 GitHub. https:\/\/github.com\/riyazdf\/dockercon-workshop\/tree\/ master\/capabilities. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_4_1","unstructured":"[n. d.]. GitHub - draios\/sysdig: Linux system exploration and troubleshooting tool with first class support for containers. https:\/\/github.com\/draios\/sysdig. (Accessed on 08\/31\/2019).  [n. d.]. GitHub - draios\/sysdig: Linux system exploration and troubleshooting tool with first class support for containers. https:\/\/github.com\/draios\/sysdig. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_5_1","unstructured":"[n. d.]. GitHub - iovisor\/bcc: BCC - Tools for BPF-based Linux IO analysis networking monitoring and more. https:\/\/github.com\/iovisor\/bcc. (Accessed on 08\/31\/2019).  [n. d.]. GitHub - iovisor\/bcc: BCC - Tools for BPF-based Linux IO analysis networking monitoring and more. https:\/\/github.com\/iovisor\/bcc. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_6_1","unstructured":"[n. d.]. GitHub - strace\/strace: strace is a diagnostic debugging and instructional userspace utility for Linux. https:\/\/github.com\/strace\/strace. (Accessed on 08\/31\/2019).  [n. d.]. GitHub - strace\/strace: strace is a diagnostic debugging and instructional userspace utility for Linux. https:\/\/github.com\/strace\/strace. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_7_1","unstructured":"[n. d.]. Hard links and Unix file system nodes (inodes). http:\/\/teaching.idallen. com\/dat2330\/04f\/notes\/links_and_inodes.html. (Accessed on 09\/09\/2019).  [n. d.]. Hard links and Unix file system nodes (inodes). http:\/\/teaching.idallen. com\/dat2330\/04f\/notes\/links_and_inodes.html. (Accessed on 09\/09\/2019)."},{"key":"e_1_3_2_1_8_1","unstructured":"[n. d.]. Malware VM detection techniques evolving: an analysis of GravityRAT | So Long and Thanks for All the Fish. https:\/\/www.andreafortuna.org\/2018\/05\/ 21\/malware-vm-detection-techniques-evolving-an-analysis-of-gravityrat\/. (Accessed on 08\/31\/2019).  [n. d.]. Malware VM detection techniques evolving: an analysis of GravityRAT | So Long and Thanks for All the Fish. https:\/\/www.andreafortuna.org\/2018\/05\/ 21\/malware-vm-detection-techniques-evolving-an-analysis-of-gravityrat\/. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_9_1","unstructured":"[n. d.]. Seccomp security profiles for Docker | Docker Documentation. https: \/\/docs.docker.com\/engine\/security\/seccomp\/. (Accessed on 08\/31\/2019).  [n. d.]. Seccomp security profiles for Docker | Docker Documentation. https: \/\/docs.docker.com\/engine\/security\/seccomp\/. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_10_1","unstructured":"[n. d.]. SystemTap Filtering and Analyzing System Data | System Analysis and Tuning Guide | openSUSE Leap 15.1. https:\/\/doc.opensuse.org\/documentation\/ leap\/tuning\/html\/book.sle.tuning\/cha.tuning.systemtap.html. (Accessed on 08\/31\/2019).  [n. d.]. SystemTap Filtering and Analyzing System Data | System Analysis and Tuning Guide | openSUSE Leap 15.1. https:\/\/doc.opensuse.org\/documentation\/ leap\/tuning\/html\/book.sle.tuning\/cha.tuning.systemtap.html. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_11_1","unstructured":"[n. d.]. What are Containers and their benefits | Google Cloud. https:\/\/cloud. google.com\/containers\/. (Accessed on 09\/02\/2019).  [n. d.]. What are Containers and their benefits | Google Cloud. https:\/\/cloud. google.com\/containers\/. (Accessed on 09\/02\/2019)."},{"key":"e_1_3_2_1_12_1","unstructured":"[n. d.]. What is a Container? | Docker. https:\/\/www.docker.com\/resources\/whatcontainer. (Accessed on 08\/31\/2019).  [n. d.]. What is a Container? | Docker. https:\/\/www.docker.com\/resources\/whatcontainer. (Accessed on 08\/31\/2019)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24858-5_8"},{"key":"e_1_3_2_1_14_1","volume-title":"Malware Dynamic Analysis Evasion Techniques: A Survey. CoRR abs\/1811.01190","author":"Afianian Amir","year":"2018","unstructured":"Amir Afianian , Salman Niksefat , Babak Sadeghiyan , and David Baptiste . 2018. Malware Dynamic Analysis Evasion Techniques: A Survey. CoRR abs\/1811.01190 ( 2018 ). arXiv:1811.01190 http:\/\/arxiv.org\/abs\/1811.01190 Amir Afianian, Salman Niksefat, Babak Sadeghiyan, and David Baptiste. 2018. Malware Dynamic Analysis Evasion Techniques: A Survey. CoRR abs\/1811.01190 (2018). arXiv:1811.01190 http:\/\/arxiv.org\/abs\/1811.01190"},{"key":"e_1_3_2_1_15_1","volume-title":"FRAME: Framework for Real Time Analysis of Malware. In 2018 8th International Conference on Cloud Computing, Data Science Engineering (Confluence). 14--15","author":"Agarwal S.","year":"2018","unstructured":"S. Agarwal and G. Raj . 2018 . FRAME: Framework for Real Time Analysis of Malware. In 2018 8th International Conference on Cloud Computing, Data Science Engineering (Confluence). 14--15 . https:\/\/doi.org\/10.1109\/CONFLUENCE. 2018 . 8442771 10.1109\/CONFLUENCE.2018 S. Agarwal and G. Raj. 2018. FRAME: Framework for Real Time Analysis of Malware. In 2018 8th International Conference on Cloud Computing, Data Science Engineering (Confluence). 14--15. https:\/\/doi.org\/10.1109\/CONFLUENCE.2018. 8442771"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2014.51"},{"key":"e_1_3_2_1_17_1","volume-title":"Os-level failure injection with systemtap. arXiv preprint arXiv:1502.01509","author":"Coti Camille","year":"2015","unstructured":"Camille Coti and Nicolas Greneche . 2015. Os-level failure injection with systemtap. arXiv preprint arXiv:1502.01509 ( 2015 ). Camille Coti and Nicolas Greneche. 2015. Os-level failure injection with systemtap. arXiv preprint arXiv:1502.01509 (2015)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635869"},{"key":"e_1_3_2_1_19_1","unstructured":"Anssi Matti Helin etal 2016. Virtual machine introspection in malware analysis. (2016).  Anssi Matti Helin et al. 2016. Virtual machine introspection in malware analysis. (2016)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3140368.3140371"},{"key":"e_1_3_2_1_21_1","volume-title":"BareCloud: Bare-metal Analysis-based Evasive Malware Detection. In 23rd USENIX Security Symposium (USENIX Security 14)","author":"Kirat Dhilung","year":"2014","unstructured":"Dhilung Kirat , Giovanni Vigna , and Christopher Kruegel . 2014 . BareCloud: Bare-metal Analysis-based Evasive Malware Detection. In 23rd USENIX Security Symposium (USENIX Security 14) . USENIX Association, San Diego, CA, 287-- 301. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/ presentation\/kirat Dhilung Kirat, Giovanni Vigna, and Christopher Kruegel. 2014. BareCloud: Bare-metal Analysis-based Evasive Malware Detection. In 23rd USENIX Security Symposium (USENIX Security 14). USENIX Association, San Diego, CA, 287-- 301. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/ presentation\/kirat"},{"key":"e_1_3_2_1_22_1","first-page":"794","article-title":"Implementing cloud based malware container protection","volume":"9","author":"Nikolai Jason A","year":"2017","unstructured":"DavidMKoster, Jason A Nikolai , Adam D Reznechek , and Andrew T Thorstensen . 2017 . Implementing cloud based malware container protection . US Patent 9 , 794 ,287. DavidMKoster, Jason A Nikolai, Adam D Reznechek, and Andrew T Thorstensen. 2017. Implementing cloud based malware container protection. US Patent 9,794,287.","journal-title":"US Patent"},{"key":"e_1_3_2_1_23_1","unstructured":"Michael Sikorski and Andrew Honig. 2012. Practical malware analysis: the handson guide to dissecting malicious software. no starch press.  Michael Sikorski and Andrew Honig. 2012. Practical malware analysis: the handson guide to dissecting malicious software. no starch press."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MCC.2016.111","article-title":"The design and architecture of microservices","volume":"3","author":"Sill Alan","year":"2016","unstructured":"Alan Sill . 2016 . The design and architecture of microservices . IEEE Cloud Computing 3 , 5 (2016), 76 -- 80 . Alan Sill. 2016. The design and architecture of microservices. IEEE Cloud Computing 3, 5 (2016), 76--80.","journal-title":"IEEE Cloud Computing"},{"key":"e_1_3_2_1_25_1","volume-title":"Probabilistic Estimation of Honeypot Detection in Internet of Things Environments. In 2019 International Conference on Computing, Networking and Communications (ICNC). 191--196","author":"Surnin O.","year":"2019","unstructured":"O. Surnin , F. Hussain , R. Hussain , S. Ostrovskaya , A. Polovinkin , J. Lee , and X. Fernando . 2019 . Probabilistic Estimation of Honeypot Detection in Internet of Things Environments. In 2019 International Conference on Computing, Networking and Communications (ICNC). 191--196 . https:\/\/doi.org\/10.1109\/ICCNC. 2019 .8685566 10.1109\/ICCNC.2019.8685566 O. Surnin, F. Hussain, R. Hussain, S. Ostrovskaya, A. Polovinkin, J. Lee, and X. Fernando. 2019. Probabilistic Estimation of Honeypot Detection in Internet of Things Environments. In 2019 International Conference on Computing, Networking and Communications (ICNC). 191--196. https:\/\/doi.org\/10.1109\/ICCNC.2019.8685566"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.11.001"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2008.4630086"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_8"},{"key":"e_1_3_2_1_30_1","unstructured":"Lenny Zeltser. [n. d.]. Docker Containers for Malware Analysis. https:\/\/zeltser. com\/media\/archive\/docker.pdf. (Accessed on 08\/31\/2019).  Lenny Zeltser. [n. d.]. Docker Containers for Malware Analysis. https:\/\/zeltser. com\/media\/archive\/docker.pdf. (Accessed on 08\/31\/2019)."}],"event":{"name":"UCC '19: IEEE\/ACM 12th International Conference on Utility and Cloud Computing","location":"Auckland New Zealand","acronym":"UCC '19","sponsor":["SIGARCH ACM Special Interest Group on Computer Architecture","IEEE TCSC IEEE Technical Committee on Scalable Computing"]},"container-title":["Proceedings of the 12th IEEE\/ACM International Conference on Utility and Cloud Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3344341.3368810","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3344341.3368810","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:25Z","timestamp":1750203865000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3344341.3368810"}},"subtitle":["A Compromise Worth Considering"],"short-title":[],"issued":{"date-parts":[[2019,12,2]]},"references-count":30,"alternative-id":["10.1145\/3344341.3368810","10.1145\/3344341"],"URL":"https:\/\/doi.org\/10.1145\/3344341.3368810","relation":{},"subject":[],"published":{"date-parts":[[2019,12,2]]},"assertion":[{"value":"2019-12-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}