{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T07:43:15Z","timestamp":1784014995568,"version":"3.55.0"},"reference-count":66,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Malware analysis is a task of utmost importance in cyber-security. Two approaches exist for malware analysis: static and dynamic. Modern malware uses an abundance of techniques to evade both dynamic and static analysis tools. Current dynamic analysis solutions either make modifications to the running malware or use a higher privilege component that does the actual analysis. The former can be easily detected by sophisticated malware while the latter often induces a significant performance overhead. We propose a method that performs malware analysis within the context of the OS itself. Furthermore, the analysis component is camouflaged by a hypervisor, which makes it completely transparent to the running OS and its applications. The evaluation of the system\u2019s efficiency suggests that the induced performance overhead is negligible.<\/jats:p>","DOI":"10.1186\/s42400-021-00083-9","type":"journal-article","created":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:04:21Z","timestamp":1622592261000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["Hypervisor-assisted dynamic malware analysis"],"prefix":"10.1186","volume":"4","author":[{"given":"Roee S.","family":"Leon","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Kiperberg","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anat Anatey","family":"Leon Zabag","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3496-7925","authenticated-orcid":false,"given":"Nezer Jacob","family":"Zaidenberg","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,6,2]]},"reference":[{"issue":"6","key":"83_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3365001","volume":"52","author":"A Afianian","year":"2019","unstructured":"Afianian, A, et al. (2019) Malware dynamic analysis evasion techniques: A survey. ACM Comput Surv (CSUR) 52(6):1\u201328.","journal-title":"ACM Comput Surv (CSUR)"},{"key":"83_CR2","first-page":"6","volume-title":"ECCWS 2019 18th European Conference on Cyber Warfare and Security","author":"A Algawi","year":"2019","unstructured":"Algawi, A, Kiperberg M, Leon R, Resh A, Zaidenberg N (2019) Creating Modern Blue Pills and Red Pills In: ECCWS 2019 18th European Conference on Cyber Warfare and Security, 6.. Academic Conferences and publishing limited, UK. https:\/\/jyx.jyu.fi\/bitstream\/handle\/123456789\/67098\/1\/CreatingModernBluePillsandRedPills.pdf."},{"key":"83_CR3","unstructured":"AMD (2010) AMD64 Architecture Programmer\u2019s Manual Volume 2: System Programming. https:\/\/www.amd.com\/system\/files\/TechDocs\/24593.pdf."},{"key":"83_CR4","unstructured":"ARM Ltd. (2013) ARM Architecture Reference Manual, ARMv8, for ARMv8-A architecture profile. https:\/\/developer.arm.com\/documentation\/ddi0487\/latest."},{"key":"83_CR5","volume-title":"Proceedings of the 19th ACM Symposium on Operating System Principles","author":"P Barham","year":"2003","unstructured":"Barham, P, Dragovic B, Fraser K, Hand S, Harris T, Ho A, Neugebauer R, Pratt I, Warfield A (2003) XEN and the art of virtualization In: Proceedings of the 19th ACM Symposium on Operating System Principles.. SOSSP, Bolton Landing."},{"issue":"4","key":"83_CR6","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/s11416-013-0185-4","volume":"9","author":"D Basya","year":"2013","unstructured":"Basya, D, Low R, Stamp M (2013) Structural entropy and metamorphic malware. J Comput Virol Hacking Tech 9(4):179\u2013192.","journal-title":"J Comput Virol Hacking Tech"},{"issue":"1","key":"83_CR7","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1007\/s11416-006-0012-2","volume":"2","author":"U Bayer","year":"2006","unstructured":"Bayer, U, et al. (2006) Dynamic analysis of malicious code. J Comput Virol 2(1):67\u201377.","journal-title":"J Comput Virol"},{"key":"83_CR8","unstructured":"Bayer, U, Kruegel C, Kirda E (2005) TTanalyze: A Tool for Analyzing Malware In: EICAR, 180\u2013192. https:\/\/scholar.google.com\/scholar?cites=7834276370136238241&as_sdt=2005&sciodt=0,5&hl=en."},{"key":"83_CR9","doi-asserted-by":"crossref","unstructured":"Ben Yehuda, R, Shlingbaum E, Tayouri S, Gershfeld Y, Zaidenberg NJ (2021) Hypervisor Memory acquisition for ARM In Forensic Science International: Digital Investigation.","DOI":"10.1016\/j.fsidi.2020.301106"},{"key":"83_CR10","unstructured":"Branco, RR, Barbosa GN, Neto PD (2012) Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-VM techniques, 1\u201327. https:\/\/scholar.google.com\/scholar?cluster=10089934970221990271&hl=en&as_sdt=2005&sciodt=0,5."},{"key":"83_CR11","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.diin.2016.12.004","volume":"20","author":"A Case","year":"2017","unstructured":"Case, A, Richard III GG (2017) Memory forensics: The path forward. Digit Investig 20:23\u201333.","journal-title":"Digit Investig"},{"key":"83_CR12","first-page":"32","volume-title":"Proceedings of the 2005 IEEE Symposium on Security and Privacy (Oakland 2005), Oakland, CA, USA, May 2005","author":"M Christodorescu","year":"2005","unstructured":"Christodorescu, M, Jha S, Seshia SA, Song D, Bryant RE (2005) Semantics-aware malware detection In: Proceedings of the 2005 IEEE Symposium on Security and Privacy (Oakland 2005), Oakland, CA, USA, May 2005, 32\u201346.. ACM Press, New York."},{"key":"83_CR13","volume-title":"Robust Linux Memory Acquisition with Minimal Target Impact. Johannes Stuettgen and Michael Cohen","author":"M Cohen","year":"2014","unstructured":"Cohen, M (2014) Robust Linux Memory Acquisition with Minimal Target Impact. Johannes Stuettgen and Michael Cohen. The proceedings of The Digital Forensic Research Conference DFRWS 2014 EU, Amsterdam."},{"key":"83_CR14","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1016\/j.eswa.2018.02.039","volume":"102","author":"A Cohen","year":"2018","unstructured":"Cohen, A, Nissim N (2018) Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory. Expert Syst Appl 102:158\u2013178.","journal-title":"Expert Syst Appl"},{"key":"83_CR15","doi-asserted-by":"publisher","first-page":"2750","DOI":"10.1109\/TIFS.2020.2976559","volume":"15","author":"DC D\u2019Elia","year":"2020","unstructured":"D\u2019Elia, DC, Coppa E, Palmaro F, Cavallaro L (2020) On the Dissection of Evasive Malware. IEEE Trans Inf Forensic Secur 15:2750\u20132765.","journal-title":"IEEE Trans Inf Forensic Secur"},{"key":"83_CR16","unstructured":"Das MalwerkMalware Samples. https:\/\/dasmalwerk.eu\/, https:\/\/das-malwerk.herokuapp.com\/about. Accessed Sept 2019."},{"key":"83_CR17","doi-asserted-by":"publisher","first-page":"S13","DOI":"10.1016\/j.diin.2012.05.013","volume":"9","author":"Z Deng","year":"2012","unstructured":"Deng, Z, Xu D, Zhang X, Jiang X (2012) Introlib: Efficient and transparent library call introspection for malware forensics. Digit Investig 9:S13\u2013S23.","journal-title":"Digit Investig"},{"key":"83_CR18","unstructured":"Dinaburg, A, Royal P, SHARIF MI, LEE W (2012) Ether: malware analysis via hardware virtualization extensions In: Proceedings of the ACM Conference on Computer and Communications Security (CCS), 51\u201362.. IEEE. https:\/\/ieeexplore.ieee.org\/document\/6329220."},{"key":"83_CR19","doi-asserted-by":"publisher","first-page":"479","DOI":"10.1109\/ARES.2012.16","volume-title":"2012 Seventh International Conference on Availability, Reliability and Security","author":"B Ding","year":"2012","unstructured":"Ding, B, Wu Y, He Y, Tian S, Guan B, Wu G (2012) Return-oriented programming attack on the xen hypervisor In: 2012 Seventh International Conference on Availability, Reliability and Security, 479\u2013484.. IEEE, Prague. https:\/\/doi.org\/10.1109\/ARES.2012.16."},{"key":"83_CR20","doi-asserted-by":"crossref","unstructured":"Deng, Z, Zhang X, Xu D (2013) Spider: Stealthy binary program instrumentation and debugging via hardware virtualization In: Proceedings of the 29th Annual Computer Security Applications Conference, ACSAC 13, 289\u2013298.","DOI":"10.1145\/2523649.2523675"},{"issue":"2","key":"83_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2089125.2089126","volume":"44","author":"M Egele","year":"2008","unstructured":"Egele, M, Scholte T, Kirda E, Kruegel C (2008) A survey on automated dynamic malware-analysis techniques and tools. ACM Comput Surv (CSUR) 44(2):1\u201342.","journal-title":"ACM Comput Surv (CSUR)"},{"key":"83_CR22","unstructured":"Feng, Y, Anand S, Dillig I, Aiken A (2014) Apposcopy: Semantic-Based detection of android malware through static analysis In: Proceedings of the 22nd ACM SIGSOFT International Symposium on the Foundations of Software Engineering (FSE 2014), 576\u2013587. https:\/\/dl.acm.org\/doi\/abs\/10.1145\/2635868.2635869?casa_token=Cd0d2xUKguYAAAAA:g-q0Fjc4W0JxkZ8nd3aqV-2kpnwilJwLQjMofj0nlLNaKOymYZVJ3BaqgXITEdrWAMRvXS9kDRJh."},{"key":"83_CR23","first-page":"1","volume":"5","author":"P Ferrie","year":"2006","unstructured":"Ferrie, P (2006) Attacks on virtual machine emulators. Symantec Adv Threat Res 5:1\u20133. https:\/\/scholar.google.com\/scholar?cluster=490094371751728691&hl=en&as_sdt=2005&sciodt=0,5.","journal-title":"Symantec Adv Threat Res"},{"key":"83_CR24","doi-asserted-by":"publisher","DOI":"10.1145\/1368506.1368518","volume-title":"Remote Detection of Virtual Machine Monitors with Fuzzy Benchmarking","author":"J Franklin","year":"2008","unstructured":"Franklin, J, Luk M, McCune JM, Seshadri A, Perrig A, van Doorn L (2008) Remote Detection of Virtual Machine Monitors with Fuzzy Benchmarking, Vol. 42. Association for Computing Machinery, New York. https:\/\/doi.org\/10.1145\/1368506.1368518."},{"issue":"02","key":"83_CR25","first-page":"56","volume":"5","author":"E Gandotra","year":"2014","unstructured":"Gandotra, E, Bansal D, Sofat S (2014) Malware analysis and classification: A survey. J Inf Secur 5(02):56.","journal-title":"J Inf Secur"},{"key":"83_CR26","first-page":"1","volume-title":"USENIX Workshop on Hot Topics in Operating Systems (HotOS)","author":"T Garfinkel","year":"2007","unstructured":"Garfinkel, T, Adams K, Warfield A, Franklin J (2007) Compatibility Is Not Transparency: VMM detection myths and realities In: USENIX Workshop on Hot Topics in Operating Systems (HotOS), 1\u20136.. USENIX Association, USA."},{"key":"83_CR27","unstructured":"Guarnieri, C, Fernandes D (2010) Cuckoo Automated Malware Analysis System. http:\/\/www.cuckoobox.org\/."},{"issue":"1","key":"83_CR28","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1186\/s40163-019-0097-9","volume":"8","author":"G Hull","year":"2019","unstructured":"Hull, G, John H, Arief B (2019) Ransomware deployment methods and analysis: views from a predictive model and human responses. Crime Sci 8(1):2.","journal-title":"Crime Sci"},{"key":"83_CR29","unstructured":"Intel Corporation (2007) Intel 64 and IA-32 Architectures Software Developer\u2019s Manual, vol. 3. https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents-tps\/253668-sdm-vol-3a.pdf."},{"key":"83_CR30","first-page":"757","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"A Kharaz","year":"2016","unstructured":"Kharaz, A, Arshad S, Mulliner C, Robertson W, Kirda E (2016) UNVEIL: A large-scale, automated approach to detecting ransomware In: 25th USENIX Security Symposium (USENIX Security 16), 757\u2013772.. USENIX Association, Austin."},{"key":"83_CR31","first-page":"174","volume-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","author":"J Kinder","year":"2005","unstructured":"Kinder, J, Katzenbeisser S, Schallhart C, Veith H (2005) Detecting malicious code by model checking In: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, 174\u2013187.. Springer, Berlin, Heidelberg. https:\/\/www.springer.com\/gp\/book\/9783540266136."},{"key":"83_CR32","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076790","volume-title":"ACSAC","author":"D Kirat","year":"2011","unstructured":"Kirat, D, Vigna G, Kruegel C (2011) BareBox: efficient malware analysis on bare-metal In: ACSAC.. ACM, New York. https:\/\/doi.org\/10.1145\/2076732.2076790."},{"key":"83_CR33","unstructured":"Kirat, D, Vigna G, Kruegel C (2014) Barecloud: bare-metal analysis-based evasive malware detection In: USENIX Security, 287\u2013301, San Diego. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/kirat."},{"key":"83_CR34","doi-asserted-by":"crossref","unstructured":"Lengyel, TK, Maresca S, Payne BD, Webster GD, Vogl S, Kiayias A (2014) Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system In: Proceedings of the 30th Annual Computer Security Applications Conference on ASAC \u201914, 386\u2013395. https:\/\/dl.acm.org\/doi\/abs\/10.1145\/2664243.2664252.","DOI":"10.1145\/2664243.2664252"},{"issue":"5","key":"83_CR35","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1109\/MSEC.2019.2910218","volume":"17","author":"RS Leon","year":"2018","unstructured":"Leon, RS, Kiperberg M, Zabag Leon AA, Resh A, Algawi A, Zaidenberg N (2018) Hypervisor-Based Whitelisting of Executables. IEEE Sec Priv 17(5):58\u201367. https:\/\/doi.org\/10.1109\/MSEC.2019.2910218.","journal-title":"IEEE Sec Priv"},{"key":"83_CR36","doi-asserted-by":"publisher","unstructured":"Li, J, Wang Q, Jayasinghe D, Park J, Zhu T, Pu C (2013) Performance Overhead Among Three Hypervisors: An Experimental Study using Hadoop Benchmarks. IEEE Int Conf Big Data. 9\u201316. https:\/\/doi.org\/10.1109\/BigData.Congress.2013.11.","DOI":"10.1109\/BigData.Congress.2013.11"},{"key":"83_CR37","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1016\/j.cose.2017.11.010","volume":"73","author":"C-H Lin","year":"2018","unstructured":"Lin, C-H, Pao H-K, Liao J-W (2018) Efficient dynamic malware analysis using virtual time control mechanics. Comput Secur 73:359\u2013373.","journal-title":"Comput Secur"},{"key":"83_CR38","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1007\/978-3-642-23644-0_18","volume-title":"International Workshop on Recent Advances in Intrusion Detection","author":"M Lindorfer","year":"2011","unstructured":"Lindorfer, M, Kolbitsch C, Comparetti PM (2011) Detecting environment-sensitive malware In: International Workshop on Recent Advances in Intrusion Detection, 338\u2013357.. Springer, Berlin, Heidelberg."},{"key":"83_CR39","unstructured":"Mandl, T, Bayer U, Nentwich F (2009) ANUBIS ANalyzing unknown BInarieS the automatic way In: Virus bulletin conference, 2."},{"key":"83_CR40","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1016\/j.cose.2015.04.001","volume":"52","author":"A Mohaisen","year":"2015","unstructured":"Mohaisen, A, Alrawi O, Mohaisen M (2015) AMAL: high-fidelity, behavior-based automated malware analysis and classification. Comput Secur 52:251\u2013266.","journal-title":"Comput Secur"},{"key":"83_CR41","doi-asserted-by":"crossref","unstructured":"Moser, A, Kruegel C, Kirda E (2007) Limits of static analysis for malware detection In: Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), 421\u2013430.. IEEE. https:\/\/doi.org\/10.1109\/ACSAC.2007.21. https:\/\/ieeexplore.ieee.org\/abstract\/document\/4413008.","DOI":"10.1109\/ACSAC.2007.21"},{"key":"83_CR42","doi-asserted-by":"crossref","unstructured":"Murray, DG, Milos G, Hand S (2008) Improving Xen security through disaggregation In: Proceedings of the fourth ACM SIGPLAN\/SIGOPS international conference on Virtual execution environments, 151\u2013160. https:\/\/dl.acm.org\/doi\/abs\/10.1145\/1346256.1346278.","DOI":"10.1145\/1346256.1346278"},{"key":"83_CR43","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1109\/ACSAC.2009.48","volume-title":"2009 Annual Computer Security Applications Conference","author":"AM Nguyen","year":"2009","unstructured":"Nguyen, AM, Schear N, Jung H, Godiyal A, King ST, Nguyen HD (2009) Mavmm: Lightweight and purpose built vmm for malware analysis In: 2009 Annual Computer Security Applications Conference, 441\u2013450.. IEEE, Honolulu. https:\/\/doi.org\/10.1109\/ACSAC.2009.48."},{"issue":"5","key":"83_CR44","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MSP.2011.98","volume":"9","author":"P O\u2019Kane","year":"2011","unstructured":"O\u2019Kane, P, Sezer S, McLaughlin M (2011) Obfuscation: the hidden malware. IEEE Secur Priv 9(5):41\u201347.","journal-title":"IEEE Secur Priv"},{"key":"83_CR45","volume-title":"International Conference on Information Systems, Technology and Management","author":"J Oh","year":"2010","unstructured":"Oh, J, Im C, Jeong H (2010) A system for analyzing advance bot behavior In: International Conference on Information Systems, Technology and Management.. Springer, Berlin, Heidelberg."},{"issue":"5","key":"83_CR46","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3329786","volume":"52","author":"O Or-Meir","year":"2019","unstructured":"Or-Meir, O, et al. (2019) Dynamic malware analysis in the modern era\u2014A state of the art survey. ACM Comput Surv (CSUR) 52(5):1\u201348.","journal-title":"ACM Comput Surv (CSUR)"},{"key":"83_CR47","doi-asserted-by":"crossref","unstructured":"Petsas, T, Voyatzis G, Athanasopoulos E, Polychronakis M, Ioannidis S (2014) Rage against the virtual machine: hindering dynamic analysis of android malware In: Proceedings of the Seventh European Workshop on System Security, 1\u20136. https:\/\/dl.acm.org\/doi\/abs\/10.1145\/2592791.2592796.","DOI":"10.1145\/2592791.2592796"},{"key":"83_CR48","first-page":"74","volume":"12","author":"B Rad","year":"2012","unstructured":"Rad, B, Masrom M, Ibrahim S (2012) Camouflage in Malware: From Encryption to Metamorphism. Int J Comput Sci Netw Secur 12:74\u201383.","journal-title":"Int J Comput Sci Netw Secur"},{"key":"83_CR49","first-page":"1","volume-title":"International Conference on Information Security","author":"T Raffetseder","year":"2007","unstructured":"Raffetseder, T, Kruegel C, Kirda E (2007) Detecting System Emulators In: International Conference on Information Security, 1\u201318.. Springer, Berlin. https:\/\/link.springer.com\/chapter\/10.1007\/978-3-540-75496-1_1."},{"key":"83_CR50","unstructured":"Roesch, M (1999) Snort: Lightweight intrusion detection for networks In: Lisa, Vol. 99, No. 1, 229\u2013238. https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/lisa99\/roesch.html. https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/lisa99\/full_papers\/roesch\/roesch.pdf."},{"issue":"16","key":"83_CR51","first-page":"25","volume":"67","author":"IA Saeed","year":"2013","unstructured":"Saeed, IA, Selamat A, Abuagoub AMA (2013) A Survey on Malware and Malware Detection Systems. Int J Comput Appl 67(16):25\u201331.","journal-title":"Int J Comput Appl"},{"key":"83_CR52","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1016\/j.future.2017.10.016","volume":"80","author":"SAR Shah","year":"2018","unstructured":"Shah, SAR, Issac B (2018) Performance comparison of intrusion detection systems and application of machine learning to Snort system. Futur Gener Comput Syst 80:157\u2013170.","journal-title":"Futur Gener Comput Syst"},{"key":"83_CR53","volume-title":"International Conference on Information Systems Security","author":"D Song","year":"2008","unstructured":"Song, D, et al. (2008) BitBlaze: A new approach to computer security via binary analysis In: International Conference on Information Systems Security.. Springer, Berlin, Heidelberg."},{"key":"83_CR54","unstructured":"Sylve, J (2012) Android Mind Reading: Memory Acquisition and Analysis with DMD and Volatility Shmoocon 2012. https:\/\/www.youtube.com\/watch?v=oWkOyphlmM8. Accessed 25 Feb 2021."},{"key":"83_CR55","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1016\/j.cose.2018.11.001","volume":"81","author":"D Ucci","year":"2019","unstructured":"Ucci, D, Aniello L, Baldoni R (2019) Survey of machine learning techniques for malware analysis. Comput Secur 81:123\u2013147.","journal-title":"Comput Secur"},{"key":"83_CR56","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1145\/2590296.2590325","volume-title":"Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security (ASIACCS \u201914)","author":"T Vidas","year":"2014","unstructured":"Vidas, T, Christin N (2014) Evading Android runtime analysis via sandbox detection In: Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security (ASIACCS \u201914), 447\u2013458.. Association for Computing Machinery, New York. https:\/\/dl.acm.org\/doi\/10.1145\/2590296.2590325."},{"key":"83_CR57","unstructured":"Vinod, P, Laxmi R, Gaur M (2009) Survey on Malware Detection Methods In: Proceedings of the 3rd Hackers\u2019 Workshop on computer and internet security (IITKHACK\u201909), 74\u201379."},{"key":"83_CR58","unstructured":"VMWare (2005) VMware ESX server virtual infrastructure node evaluator\u2019s guide. https:\/\/www.VMware.com\/pdf\/esx_vin_eval.pdf. Accessed Sept 2019."},{"key":"83_CR59","doi-asserted-by":"publisher","unstructured":"White, JS, Fitzsimmons T, Matthews JN (2013) Quantitative analysis of intrusion detection systems: Snort and Suricata In: Cyber sensing 2013, vol. 8757. International Society for Optics and Photonics, 875704. https:\/\/doi.org\/10.1117\/12.2015616.","DOI":"10.1117\/12.2015616"},{"issue":"2","key":"83_CR60","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems, C, Holz T, Freiling F (2007) CWSandbox: Towards automated dynamic binary analysis. IEEE Secur Priv 5(2):32\u201339. https:\/\/doi.org\/10.1109\/MSP.2007.45.","journal-title":"IEEE Secur Priv"},{"key":"83_CR61","doi-asserted-by":"crossref","unstructured":"Yalew, SD, McGuire G, Haridi S, Correia M (2017) T2Droid: A TrustZone-based dynamic analyser for Android applications In: 2017 IEEE Trustcom\/BigDataSE\/ICESS, 240\u2013247.. IEEE. https:\/\/ieeexplore.ieee.org\/abstract\/document\/8029446.","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.243"},{"key":"83_CR62","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-319-45719-2_8","volume-title":"International Symposium on Research in Attacks, Intrusions, and Defenses","author":"A Yokoyama","year":"2016","unstructured":"Yokoyama, A, Ishii K, Tanabe R, Papa Y, Yoshioka K, Matsumoto T, Kasama T, Inoue D, Brengel M, Backes M, Rossow C (2016) SandPrint: Fingerprinting malware sandboxes to provide intelligence for sandbox evasion In: International Symposium on Research in Attacks, Intrusions, and Defenses, 165\u2013187.. Springer, Cham."},{"key":"83_CR63","doi-asserted-by":"crossref","unstructured":"You, I, Yim K (2010) Malware Obfuscation Techniques: A Brief Survey In: 2010 International conference on broadband, wireless computing, communication and applications, 297\u2013300.. IEEE. https:\/\/doi.org\/10.1109\/BWCCA.2010.85. https:\/\/ieeexplore.ieee.org\/abstract\/document\/5633410.","DOI":"10.1109\/BWCCA.2010.85"},{"key":"83_CR64","volume-title":"Hardware rooted security in industry 4.0 systems","author":"NJ Zaidenberg","year":"2018","unstructured":"Zaidenberg, NJ (2018) Hardware rooted security in industry 4.0 systems, Vol. 51. IOS Press BV, Netherlands. http:\/\/ebooks.iospress.nl\/volumearticle\/50292."},{"key":"83_CR65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-49443-8_15","volume-title":"Information Systems Security and Privacy. ICISSP 2019. Communications in Computer and Information Science, vol 1221","author":"NJ Zaidenberg","year":"2020","unstructured":"Zaidenberg, NJ, Kiperberg M, Yehuda RB, Leon R, Algawi A, Resh A (2020) Hypervisor Memory Introspection and Hypervisor Based Malware Honeypot. In: Mori P, Furnell S, Camp O (eds)Information Systems Security and Privacy. ICISSP 2019. Communications in Computer and Information Science, vol 1221.. Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-030-49443-8_15."},{"key":"83_CR66","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-319-18302-2_13","volume-title":"Cyber Security: Analytics, Technology and Automation","author":"N Zaidenberg","year":"2015","unstructured":"Zaidenberg, N, Neittaanm\u00e4ki P, Kiperberg M, Resh A (2015) Trusted computing and drm In: Cyber Security: Analytics, Technology and Automation, 205\u2013212.. Springer, Cham."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00083-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00083-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00083-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,30]],"date-time":"2023-01-30T03:04:03Z","timestamp":1675047843000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00083-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,2]]},"references-count":66,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2021,12]]}},"alternative-id":["83"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00083-9","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,2]]},"assertion":[{"value":"26 October 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 February 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 June 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors\u2019 declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"19"}}