{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:03:34Z","timestamp":1780589014698,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":115,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785293","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"68-82","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["TRM: An Efficient Hypervisor-Based Framework For Malware Analysis and Memory Reconstruction"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-5810-4549","authenticated-orcid":false,"given":"Mohammad Sina","family":"Karvandi","sequence":"first","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8478-2470","authenticated-orcid":false,"given":"Soroush","family":"Meghdadizanjani","sequence":"additional","affiliation":[{"name":"Stony Brook University, Stony Brook, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-5950-8245","authenticated-orcid":false,"given":"Sima","family":"Arasteh","sequence":"additional","affiliation":[{"name":"University of Southern California, Los Angeles, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5369-5270","authenticated-orcid":false,"given":"Saleh Khalaj","family":"Monfared","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Worcester, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8271-3885","authenticated-orcid":false,"given":"Mohammad K.","family":"Fallah","sequence":"additional","affiliation":[{"name":"Chosun University, Gwangju, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5898-4872","authenticated-orcid":false,"given":"Saeid","family":"Gorgin","sequence":"additional","affiliation":[{"name":"Sungkyunkwan University, Suwon, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5166-0629","authenticated-orcid":false,"given":"Jeong-A","family":"Lee","sequence":"additional","affiliation":[{"name":"Chosun University, Gwangju, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0416-3751","authenticated-orcid":false,"given":"Asia","family":"Slowinska","sequence":"additional","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0312-9913","authenticated-orcid":false,"given":"Erik","family":"van der Kouwe","sequence":"additional","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"2020 International Conference on Cyber Warfare and Security (ICCWS). IEEE, 1\u20138.","author":"Afreen Asad","year":"2020","unstructured":"Asad Afreen, Moosa Aslam, and Saad Ahmed. 2020. Analysis of fileless malware and its evasive behavior. In 2020 International Conference on Cyber Warfare and Security (ICCWS). IEEE, 1\u20138."},{"key":"e_1_3_2_1_2_1","unstructured":"National Security Agency. 2023. BlackLotus Mitigation Guide. https:\/\/media.defense.gov\/2023\/Jun\/22\/2003245723\/-1\/-1\/0\/CSI_BlackLotus_Mitigation_Guide.PDF."},{"key":"e_1_3_2_1_3_1","volume-title":"Accessed","author":"National Security Agency.","year":"2025","unstructured":"National Security Agency. 2025. Ghidra is a software reverse engineering (SRE) framework. https:\/\/github.com\/NationalSecurityAgency\/ghidra. Accessed: Jan 15, 2025."},{"key":"e_1_3_2_1_4_1","unstructured":"AMD64 Technology 2023. AMD64 Architecture Programmer's Manual - Rev. 3.40. AMD64 Technology 15.25.13. Guest Mode Execute Trap Extension."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101760"},{"key":"e_1_3_2_1_6_1","volume-title":"Stolen Nvidia certificates used to sign malware. https:\/\/www.malwarebytes.com\/blog\/news\/2022\/03\/stolen-nvidia-certificates-used-to-sign-malware-heres-what-to-do. Accessed","author":"Arntz Pieter","year":"2024","unstructured":"Pieter Arntz. 2022. Stolen Nvidia certificates used to sign malware. https:\/\/www.malwarebytes.com\/blog\/news\/2022\/03\/stolen-nvidia-certificates-used-to-sign-malware-heres-what-to-do. Accessed: February 7, 2024."},{"key":"e_1_3_2_1_7_1","volume-title":"2020 IEEE International Conference on Big Data (Big Data). IEEE, 2242\u20132253","author":"Banin Sergii","year":"2020","unstructured":"Sergii Banin and Geir Olav Dyrkolbotn. 2020. Detection of Previously Unseen Malware using Memory Access Patterns Recorded Before the Entry Point. In 2020 IEEE International Conference on Big Data (Big Data). IEEE, 2242\u20132253."},{"key":"e_1_3_2_1_8_1","unstructured":"Sergii Banin Andrii Shalaginov and Katrin Franke. 2016. Memory access patterns for malware detection. (2016)."},{"key":"e_1_3_2_1_9_1","volume-title":"FREENIX Track","volume":"41","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard. 2005. QEMU, a fast and portable dynamic translator. In USENIX annual technical conference, FREENIX Track, Vol. 41. California, USA, 46."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678892"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2021.301220"},{"key":"e_1_3_2_1_12_1","first-page":"1","article-title":"Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-vm technologies","volume":"1","author":"Branco Rodrigo Rubira","year":"2012","unstructured":"Rodrigo Rubira Branco, Gabriel Negreira Barbosa, and Pedro Drimel Neto. 2012. Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-vm technologies. Black Hat 1, 2012 (2012), 1\u201327.","journal-title":"Black Hat"},{"key":"e_1_3_2_1_13_1","volume-title":"Proc. Int. Conf. IEEE\/ACM Code Generation and Optimi zation (CGO)","author":"Bruening Derek","year":"2013","unstructured":"Derek Bruening and Timothy Garnett. 2013. Building dynamic instrumentation tools with dynamorio. In Proc. Int. Conf. IEEE\/ACM Code Generation and Optimi zation (CGO), Shen Zhen, China."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22110-1_37"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2338965.2336768"},{"key":"e_1_3_2_1_16_1","volume-title":"Accessed","author":"Community Linux","year":"2025","unstructured":"Linux Community. 2025. Shadow stacks for user space. https:\/\/lwn.net\/Articles\/885220\/. Accessed: Jan 17, 2025."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3465481.3465752"},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 29th Annual Computer Security Applications Conference. 289\u2013298","author":"Deng Zhui","year":"2013","unstructured":"Zhui Deng, Xiangyu Zhang, and Dongyan Xu. 2013. Spider: Stealthy binary program instrumentation and debugging via hardware virtualization. In Proceedings of the 29th Annual Computer Security Applications Conference. 289\u2013298."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of SYSTOR 2009: The Israeli Experimental Systems Conference. 1\u20138.","author":"Dong Yaozu","year":"2009","unstructured":"Yaozu Dong, Jinquan Dai, Zhiteng Huang, Haibing Guan, Kevin Tian, and Yunhong Jiang. 2009. Towards high-quality I\/O virtualization. In Proceedings of SYSTOR 2009: The Israeli Experimental Systems Conference. 1\u20138."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2006.03.012"},{"key":"e_1_3_2_1_22_1","volume-title":"ESORICS 2020, Guildford, UK, September 14-18, 2020, Proceedings, Part I 25","author":"Du Yunlan","year":"2020","unstructured":"Yunlan Du, Zhenyu Ning, Jun Xu, Zhilong Wang, Yueh-Hsun Lin, Fengwei Zhang, Xinyu Xing, and Bing Mao. 2020. Hart: Hardware-assisted kernel module tracing on arm. In Computer Security-ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14-18, 2020, Proceedings, Part I 25. Springer, 316\u2013337."},{"key":"e_1_3_2_1_23_1","unstructured":"Matthieu Faou. 2019. Turla LightNeuron."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1858996.1859085"},{"key":"e_1_3_2_1_25_1","volume-title":"Accessed","author":"Foundation Volatility","year":"2025","unstructured":"Volatility Foundation. 2025. Volatility - An advanced memory forensics framework. https:\/\/github.com\/volatilityfoundation\/volatility. Accessed: Jan 22, 2025."},{"key":"e_1_3_2_1_26_1","unstructured":"Adam Furmanek. 2018. Windows Research Kernel Part 1 \u2014 Compiling and debugging. https:\/\/blog.adamfurmanek.pl\/2018\/07\/21\/windows-research-kernel-part-1\/index.html."},{"key":"e_1_3_2_1_27_1","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC 20)","author":"Ge Xinyang","year":"2020","unstructured":"Xinyang Ge, Ben Niu, and Weidong Cui. 2020. Reverse debugging of kernel failures in deployed systems. In 2020 USENIX Annual Technical Conference (USENIX ATC 20). 281\u2013292."},{"key":"e_1_3_2_1_28_1","volume-title":"Recent Advances in Intrusion Detection: 12th International Symposium, RAID 2009, Saint-Malo, France, September 23-25, 2009. Proceedings 12","author":"Griffin Kent","year":"2009","unstructured":"Kent Griffin, Scott Schneider, Xin Hu, and Tzi-cker Chiueh. 2009. Automatic generation of string signatures for malware detection. In Recent Advances in Intrusion Detection: 12th International Symposium, RAID 2009, Saint-Malo, France, September 23-25, 2009. Proceedings 12. Springer, 101\u2013120."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2566673","article-title":"Memory encryption: A survey of existing techniques","volume":"46","author":"Henson Michael","year":"2014","unstructured":"Michael Henson and Stephen Taylor. 2014. Memory encryption: A survey of existing techniques. ACM Computing Surveys (CSUR) 46, 4 (2014), 1\u201326.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2969514"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2969514"},{"key":"e_1_3_2_1_32_1","unstructured":"Joel H\u00f6ner and Florian Bernd. 2023. Fast and lightweight x86\/x86-64 disassembler and code generation library. https:\/\/github.com\/zyantific\/zydis."},{"key":"e_1_3_2_1_33_1","unstructured":"VMware Inc. 2019. Performance Evaluation of Intel EPT Hardware Assist. https:\/\/www.vmware.com\/pdf\/Perf_ESX_Intel-EPT-eval.pdf."},{"key":"e_1_3_2_1_34_1","volume-title":"Accessed","year":"2025","unstructured":"Intel. 2025. Pin - A Dynamic Binary Instrumentation Tool. ttps:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/tool\/pin-a-dynamic-binary-instrumentation-tool.html. Accessed: Jan 15, 2025."},{"issue":"6","key":"e_1_3_2_1_35_1","first-page":"2","article-title":"Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3C","volume":"25","author":"Intel Corporation","year":"2023","unstructured":"Intel Corporation 2023. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3C. Intel Corporation, 25.6.2. Intel Virtualization Technology (Intel VT).","journal-title":"Intel Corporation"},{"issue":"6","key":"e_1_3_2_1_36_1","first-page":"2","article-title":"Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3C","volume":"25","author":"Intel Corporation","year":"2023","unstructured":"Intel Corporation 2023. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3C. Intel Corporation, 25.6.2. Processor-Based VM-Execution Controls.","journal-title":"Intel Corporation"},{"issue":"3","key":"e_1_3_2_1_37_1","first-page":"6","article-title":"Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3C","volume":"29","author":"Intel Corporation","year":"2023","unstructured":"Intel Corporation 2023. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3C. Intel Corporation, 29.3.6. Page-Modification Logging.","journal-title":"Intel Corporation"},{"key":"e_1_3_2_1_38_1","volume-title":"Rethinking anti-emulation techniques for large-scale software deployment. computers & security 83","author":"Jang Daehee","year":"2019","unstructured":"Daehee Jang, Yunjong Jeong, Sungman Lee, Minjoon Park, Kuenhwan Kwak, Donguk Kim, and Brent Byunghoon Kang. 2019. Rethinking anti-emulation techniques for large-scale software deployment. computers & security 83 (2019), 182\u2013200."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2556464.2556465"},{"key":"e_1_3_2_1_40_1","unstructured":"Mateusz Jurczyk. 2018. Detecting kernel memory disclosure with x86 emulation and taint tracking."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560649"},{"key":"e_1_3_2_1_42_1","unstructured":"Sina Karvandi. 2020. Hypervisor From Scratch - Part 7: Using EPT & Page-Level Monitoring Features. https:\/\/rayanfam.com\/topics\/hypervisor-from-scratch-part-7\/."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.3390\/s23020612"},{"key":"e_1_3_2_1_44_1","article-title":"A Review on Fileless Malware Analysis Techniques","volume":"9","author":"Khushali Vala","year":"2020","unstructured":"Vala Khushali. 2020. A Review on Fileless Malware Analysis Techniques. International Journal of Engineering Research & Technology (IJERT) 9, 05 (2020).","journal-title":"International Journal of Engineering Research & Technology (IJERT)"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076790"},{"key":"e_1_3_2_1_46_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security","author":"Kirsch J","year":"2018","unstructured":"J Kirsch, Z Zhechev, B Bierbaumer, and T PwIN Kittel. 2018. Pwning Intel piN: Why DBI is unsuitable for security applications. In Proceedings of the European Symposium on Research in Computer Security, Copenhagen, Denmark. 26\u201330."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046740"},{"key":"e_1_3_2_1_48_1","volume-title":"Proceedings of the","author":"Kuehner CJ","year":"1968","unstructured":"CJ Kuehner and Brian Randell. 1968. Demand paging in perspective. In Proceedings of the December 9-11, 1968, fall joint computer conference, part II. 1011\u20131018."},{"key":"e_1_3_2_1_49_1","volume-title":"Information and Communications Security: 23rd International Conference, ICICS","author":"Kwon Bumjun","year":"2021","unstructured":"Bumjun Kwon, Sanghyun Hong, Yuseok Jeon, and Doowon Kim. 2021. Certified Malware in South Korea: A Localized Study of Breaches of Trust in Code-Signing PKI Ecosystem. In Information and Communications Security: 23rd International Conference, ICICS 2021, Chongqing, China, November 19-21, 2021, Proceedings, Part I 23. Springer, 59\u201377."},{"key":"e_1_3_2_1_50_1","volume-title":"EfiGuard: a portable x64 UEFI bootkit. https:\/\/github.com\/Mattiwatti\/EfiGuard. Accessed","author":"Lavrijsen Matthijs","year":"2024","unstructured":"Matthijs Lavrijsen. 2024. EfiGuard: a portable x64 UEFI bootkit. https:\/\/github.com\/Mattiwatti\/EfiGuard. Accessed: February 7, 2024."},{"key":"e_1_3_2_1_51_1","unstructured":"ldpreload. 2023. BlackLotus UEFI Windows Bootkit. https:\/\/github.com\/ldpreload\/BlackLotus."},{"key":"e_1_3_2_1_52_1","volume-title":"TIE: Principled reverse engineering of types in binary programs. In NDSS.","author":"Lee JongHyup","year":"2011","unstructured":"JongHyup Lee, Thanassis Avgerinos, and David Brumley. 2011. TIE: Principled reverse engineering of types in binary programs. In NDSS."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00083-9"},{"key":"e_1_3_2_1_54_1","volume-title":"2011 International Conference on Network Computing and Information Security","volume":"1","author":"Li Xianxian","year":"2011","unstructured":"Xianxian Li, Changhui Jiang, Jianxin Li, and Bo Li. 2011. Vminsight: Hardware virtualization-based process security monitoring system. In 2011 International Conference on Network Computing and Information Security, Vol. 1. IEEE, 62\u201366."},{"key":"e_1_3_2_1_55_1","volume-title":"The art of memory forensics: detecting malware and threats in windows, linux, and Mac memory","author":"Ligh Michael Hale","unstructured":"Michael Hale Ligh, Andrew Case, Jamie Levy, and Aaron Walters. 2014. The art of memory forensics: detecting malware and threats in windows, linux, and Mac memory. John Wiley & Sons."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.5555\/2788959.2788964"},{"key":"e_1_3_2_1_57_1","volume-title":"Stuxnet under the microscope. ESET LLC (September 2010) 6","author":"Matrosov Aleksandr","year":"2010","unstructured":"Aleksandr Matrosov, Eugene Rodionov, David Harley, and Juraj Malcho. 2010. Stuxnet under the microscope. ESET LLC (September 2010) 6 (2010)."},{"key":"e_1_3_2_1_58_1","volume-title":"2017 IEEE 24th International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 497\u2013501","author":"Mercier Daniel","year":"2017","unstructured":"Daniel Mercier, Aziem Chawdhary, and Richard Jones. 2017. dynStruct: An automatic reverse engineering tool for structure recovery and memory use analysis. In 2017 IEEE 24th International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 497\u2013501."},{"key":"e_1_3_2_1_59_1","unstructured":"Microsoft. 2022. x64 ABI Conventions. https:\/\/learn.microsoft.com\/en-us\/cpp\/build\/x64-software-conventions?view=msvc-170. Accessed: 2025-01-15."},{"key":"e_1_3_2_1_60_1","volume-title":"Accessed","year":"2025","unstructured":"Microsoft. 2025. WinDbg - Install the Windows debugger. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/debugger\/. Accessed: Jan 17, 2025."},{"key":"e_1_3_2_1_61_1","volume-title":"Microsoft Windows Kernel Privilege Escalation Vulnerability. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-17087. Accessed","author":"Microsoft Corporation","year":"2024","unstructured":"Microsoft Corporation. 2023. Microsoft Windows Kernel Privilege Escalation Vulnerability. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-17087. Accessed: February 7, 2024."},{"key":"e_1_3_2_1_62_1","volume-title":"International Conference on Information Security and Cryptology. Springer, 92\u2013109","author":"Ming Jiang","year":"2012","unstructured":"Jiang Ming, Meng Pan, and Debin Gao. 2012. iBinHunt: Binary hunting with inter-procedural control flow. In International Conference on Information Security and Cryptology. Springer, 92\u2013109."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.21"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.48"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00061"},{"key":"e_1_3_2_1_66_1","volume-title":"Proceedings of the 5th International Workshop on Trustworthy Embedded Devices. 55\u201364","author":"Nordholz Jan","year":"2015","unstructured":"Jan Nordholz, Julian Vetter, Michael Peter, Matthias Junker-Petschick, and Janis Danisevskis. 2015. Xnpro: Lowimpact hypervisor-based execution prevention on arm. In Proceedings of the 5th International Workshop on Trustworthy Embedded Devices. 55\u201364."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"crossref","first-page":"49","DOI":"10.5815\/ijmsc.2019.03.05","article-title":"Signature-based malware detection using approximate Boyer Moore string matching algorithm","volume":"5","author":"Ojugo A","year":"2019","unstructured":"A Ojugo and AO Eboka. 2019. Signature-based malware detection using approximate Boyer Moore string matching algorithm. International Journal of Mathematical Sciences and Computing 5, 3 (2019), 49\u201362.","journal-title":"International Journal of Mathematical Sciences and Computing"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3528102"},{"key":"e_1_3_2_1_69_1","volume-title":"Proceedings of the 27th Annual ACM Symposium on Applied Computing. 1807\u20131814","author":"Oyama Yoshihiro","year":"2012","unstructured":"Yoshihiro Oyama, Tran Truong Duc Giang, Yosuke Chubachi, Takahiro Shinagawa, and Kazuhiko Kato. 2012. Detecting malware signatures in a thin hypervisor. In Proceedings of the 27th Annual ACM Symposium on Applied Computing. 1807\u20131814."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485471"},{"key":"e_1_3_2_1_71_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Pan Jianfeng","year":"2017","unstructured":"Jianfeng Pan, Guanglu Yan, and Xiaocao Fan. 2017. Digtool: A {virtualization-based} framework for detecting kernel vulnerabilities. In 26th USENIX Security Symposium (USENIX Security 17). 149\u2013165."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.10"},{"key":"e_1_3_2_1_73_1","volume-title":"Advances in Information and Computer Security: 6th International Workshop, IWSEC 2011, Tokyo, Japan, November 8-10, 2011. Proceedings 6. Springer, 96\u2013112","author":"Pfoh Jonas","year":"2011","unstructured":"Jonas Pfoh, Christian Schneider, and Claudia Eckert. 2011. Nitro: Hardware-based system call tracing for virtual machines. In Advances in Information and Computer Security: 6th International Workshop, IWSEC 2011, Tokyo, Japan, November 8-10, 2011. Proceedings 6. Springer, 96\u2013112."},{"key":"e_1_3_2_1_74_1","volume-title":"Virt-ICE: Next-generation debugger for malware analysis. Black Hat USA","author":"Quynh Nguyen Anh","year":"2010","unstructured":"Nguyen Anh Quynh and Kuniyasu Suzaki. 2010. Virt-ICE: Next-generation debugger for malware analysis. Black Hat USA (2010)."},{"key":"e_1_3_2_1_75_1","first-page":"74","article-title":"Camouflage in malware: from encryption to metamorphism","volume":"12","author":"Rad Babak Bashari","year":"2012","unstructured":"Babak Bashari Rad, Maslin Masrom, and Suhaimi Ibrahim. 2012. Camouflage in malware: from encryption to metamorphism. International Journal of Computer Science and Network Security 12, 8 (2012), 74\u201383.","journal-title":"International Journal of Computer Science and Network Security"},{"key":"e_1_3_2_1_76_1","volume-title":"Accessed","author":"Rays Hex","year":"2025","unstructured":"Hex Rays. 2025. IDA Pro. https:\/\/hex-rays.com\/ida-pro. Accessed: Jan 15, 2025."},{"key":"e_1_3_2_1_77_1","first-page":"225","article-title":"Phantasy: Low-latency virtualization-based fault tolerance via asynchronous prefetching","volume":"68","author":"Ren Shiru","year":"2018","unstructured":"Shiru Ren, Yunqi Zhang, Lichen Pan, and Zhen Xiao. 2018. Phantasy: Low-latency virtualization-based fault tolerance via asynchronous prefetching. IEEE Trans. Comput. 68, 2 (2018), 225\u2013238.","journal-title":"IEEE Trans. Comput."},{"key":"e_1_3_2_1_78_1","volume-title":"\u201cbypass","author":"Repository Github","year":"2024","unstructured":"Github Repository. 2022. Driver Sign Enforcement \u201cbypass\u201d using a leaked EV code signing certificate. https:\/\/github.com\/utoni\/PastDSE. Accessed: February 7, 2024."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966940"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/1978672.1978682"},{"key":"e_1_3_2_1_81_1","volume-title":"3rd Workshop on Future Debugging Techniques (DEBT","author":"Ruytenberg Bj\u00f6rn","year":"2025","unstructured":"Bj\u00f6rn Ruytenberg and Mohammad Sina Karvandi. 2025. HyperEvade: Countering Anti-Debugging Techniques - Enhancing Transparency in Nested Virtualization using HyperDbg. Presented at the 3rd Workshop on Future Debugging Techniques (DEBT 2025). https:\/\/www.vusec.net\/projects\/hyperevade\/"},{"key":"e_1_3_2_1_82_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Saltaformaggio Brendan","year":"2014","unstructured":"Brendan Saltaformaggio, Zhongshu Gu, Xiangyu Zhang, and Dongyan Xu. 2014. {DSCRETE}: Automatic rendering of forensic information from memory images via application logic reuse. In 23rd USENIX Security Symposium (USENIX Security 14). 255\u2013269."},{"key":"e_1_3_2_1_83_1","volume-title":"Proceedings of the 2010 ACM symposium on applied computing. 1020\u20131025","author":"Sami Ashkan","year":"2010","unstructured":"Ashkan Sami, Babak Yadegari, Hossein Rahimi, Naser Peiravian, Sattar Hashemi, and Ali Hamze. 2010. Malware detection based on mining API calls. In Proceedings of the 2010 ACM symposium on applied computing. 1020\u20131025."},{"key":"e_1_3_2_1_84_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Schumilo Sergej","year":"2021","unstructured":"Sergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon W\u00f6rner, and Thorsten Holz. 2021. Nyx: Greybox hypervisor fuzzing using fast snapshots and affine types. In 30th USENIX Security Symposium (USENIX Security 21). 2597\u20132614."},{"key":"e_1_3_2_1_85_1","volume-title":"26th USENIXsecuritysymposium (USENIX Security17). 167\u2013182.","author":"Schumilo Sergej","unstructured":"Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. {kAFL}:{Hardware-Assisted} feedbackfuzzing for {OS} kernels. In 26th USENIXsecuritysymposium (USENIX Security17). 167\u2013182."},{"key":"e_1_3_2_1_86_1","volume-title":"Rootkits: evolution and detection methods. https:\/\/www.ptsecurity.com\/upload\/corporate\/ww-en\/analytics\/PT_Rootkit_ENG.pdf. Accessed","author":"Security Positive","year":"2024","unstructured":"Positive Security. 2020. Rootkits: evolution and detection methods. https:\/\/www.ptsecurity.com\/upload\/corporate\/ww-en\/analytics\/PT_Rootkit_ENG.pdf. Accessed: February 7, 2024."},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-010-0141-5"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.18517\/ijaseit.8.4-2.6827"},{"key":"e_1_3_2_1_90_1","volume-title":"DRAKVUF Malware Sandbox. In Wellington Faculty of Engineering Symposium.","author":"Singh Sukhjinder","year":"2023","unstructured":"Sukhjinder Singh. 2023. DRAKVUF Malware Sandbox. In Wellington Faculty of Engineering Symposium."},{"key":"e_1_3_2_1_91_1","volume-title":"Proceedings of the first ACM asia-pacific workshop on Workshop on systems. 13\u201318","author":"Slowinska Asia","year":"2010","unstructured":"Asia Slowinska, Traian Stancescu, and Herbert Bos. 2010. DDE: dynamic data structure excavation. In Proceedings of the first ACM asia-pacific workshop on Workshop on systems. 13\u201318."},{"key":"e_1_3_2_1_92_1","volume-title":"Howard: A Dynamic Excavator for Reverse Engineering Data Structures. In NDSS.","author":"Slowinska Asia","year":"2011","unstructured":"Asia Slowinska, Traian Stancescu, and Herbert Bos. 2011. Howard: A Dynamic Excavator for Reverse Engineering Data Structures. In NDSS."},{"key":"e_1_3_2_1_93_1","volume-title":"Anti-forensic resilient memory acquisition. Digital investigation 10","author":"St\u00fcttgen Johannes","year":"2013","unstructured":"Johannes St\u00fcttgen and Michael Cohen. 2013. Anti-forensic resilient memory acquisition. Digital investigation 10 (2013), S105-S115."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s42400-019-0043-x","article-title":"An emerging threat Fileless malware: a survey and research challenges","volume":"3","author":"Sushil Kumar Sudhakar","year":"2020","unstructured":"Sudhakar and Sushil Kumar. 2020. An emerging threat Fileless malware: a survey and research challenges. Cybersecurity 3, 1 (2020), 1.","journal-title":"Cybersecurity"},{"key":"e_1_3_2_1_95_1","volume-title":"AES Flow Interception: Key Snooping Method on Virtual Machine-Exception Handling Attack for AES-NI. Cryptology ePrint Archive","author":"Takehisa Tatsuya","year":"2011","unstructured":"Tatsuya Takehisa, Hiroki Nogawa, and Masakatu Morii. 2011. AES Flow Interception: Key Snooping Method on Virtual Machine-Exception Handling Attack for AES-NI. Cryptology ePrint Archive (2011)."},{"key":"e_1_3_2_1_96_1","volume-title":"Accessed","author":"Development Team Cuckoo Sandbox","year":"2025","unstructured":"Cuckoo Sandbox Development Team. 2025. Cuckoo Sandbox - Cuckoo Sandbox is an automated dynamic malware analysis system. https:\/\/github.com\/cuckoosandbox\/cuckoo. Accessed: Jan 17, 2025."},{"key":"e_1_3_2_1_97_1","volume-title":"Accessed","author":"Development Team RIO","year":"2025","unstructured":"DynamoRIO Development Team. 2025. DynamoRIO Memory Debugger for Windows, Linux, Mac, and Android. https:\/\/github.com\/DynamoRIO\/drmemory. Accessed: Jan 15, 2025."},{"key":"e_1_3_2_1_98_1","volume-title":"Accessed","author":"Development Team VMI","year":"2025","unstructured":"LibVMI Development Team. 2025. LibVMI - A Library for Virtual Machine Introspection. https:\/\/github.com\/libvmi\/libvmi. Accessed: Jan 22, 2025."},{"key":"e_1_3_2_1_99_1","volume-title":"Accessed","author":"Team Qiling Development","year":"2025","unstructured":"Qiling Development Team. 2025. A True Instrumentable Binary Emulation Framework. https:\/\/github.com\/qilingframework\/qiling. Accessed: Jan 15, 2025."},{"key":"e_1_3_2_1_100_1","volume-title":"Accessed","author":"Team Valgrind Development","year":"2025","unstructured":"Valgrind Development Team. 2025. Valgrind. https:\/\/valgrind.org. Accessed: Jan 15, 2025."},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.163"},{"key":"e_1_3_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.52"},{"key":"e_1_3_2_1_103_1","volume-title":"Accessed","year":"2025","unstructured":"Vector35. 2025. Binary Ninja. https:\/\/binary.ninja. Accessed: Jan 15, 2025."},{"key":"e_1_3_2_1_104_1","first-page":"8","article-title":"peHash: A Novel Approach to Fast Malware Clustering","volume":"9","author":"Wicherski Georg","year":"2009","unstructured":"Georg Wicherski. 2009. peHash: A Novel Approach to Fast Malware Clustering. LEET 9 (2009), 8.","journal-title":"LEET"},{"key":"e_1_3_2_1_105_1","volume-title":"Twentieth Symposium on Usable Privacy and Security (SOUPS","author":"Wong Miuyin Yong","year":"2024","unstructured":"Miuyin Yong Wong, Matthew Landen, Frank Li, Fabian Monrose, and Mustaque Ahamad. 2024. Comparing malware evasion theory with practice: results from interviews with expert analysts. In Twentieth Symposium on Usable Privacy and Security (SOUPS 2024). 61\u201380."},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670340"},{"key":"e_1_3_2_1_107_1","volume-title":"Automation & Test in Europe Conference & Exhibition (DATE)","author":"Xu Zhixing","year":"2017","unstructured":"Zhixing Xu, Sayak Ray, Pramod Subramanyan, and Sharad Malik. 2017. Malware detection using machine learning based analysis of virtual memory access patterns. In Design, Automation & Test in Europe Conference & Exhibition (DATE), 2017. IEEE, 169\u2013174."},{"key":"e_1_3_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1145\/2151024.2151053"},{"key":"e_1_3_2_1_109_1","volume-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 207\u2013227","author":"Yen Ting-Fang","year":"2008","unstructured":"Ting-Fang Yen and Michael K Reiter. 2008. Traffic aggregation for malware detection. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 207\u2013227."},{"key":"e_1_3_2_1_110_1","first-page":"200903","article-title":"Imaging and evaluating the memory access for malware","volume":"32","author":"Y\u00fccel \u00c7a\u011fatay","year":"2020","unstructured":"\u00c7a\u011fatay Y\u00fccel and Ahmet Koltuksuz. 2020. Imaging and evaluating the memory access for malware. Forensic Science International: Digital Investigation 32 (2020), 200903.","journal-title":"Forensic Science International: Digital Investigation"},{"key":"e_1_3_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2018.8648070"},{"key":"e_1_3_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00051"},{"key":"e_1_3_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360563"},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1145\/996841.996873"},{"key":"e_1_3_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-77535-5_5"}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785293","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:43:07Z","timestamp":1780587787000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785293"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":115,"alternative-id":["10.1145\/3779208.3785293","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785293","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}