{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T18:42:41Z","timestamp":1729622561320,"version":"3.28.0"},"reference-count":43,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,5]]},"DOI":"10.1109\/sp.2012.40","type":"proceedings-article","created":{"date-parts":[[2012,7,19]],"date-time":"2012-07-19T14:39:03Z","timestamp":1342708743000},"page":"586-600","source":"Crossref","is-referenced-by-count":144,"title":["Space Traveling across VM: Automatically Bridging the Semantic Gap in Virtual Machine Introspection via Online Kernel Data Redirection"],"prefix":"10.1109","author":[{"given":"Yangchun","family":"Fu","sequence":"first","affiliation":[]},{"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"19","article-title":"Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software","author":"newsome","year":"0","journal-title":"Proc of the 14th Annual Network and Distributed System Security Symposium (NDSS'05) February 2005"},{"key":"35","article-title":"Automatically bridging the semantic gap using a c interpreter","author":"inoue","year":"0","journal-title":"Proc of the 2011 Annual Symposium on Information Assurance June 2011"},{"journal-title":"The Design of the UNIX Operating System","year":"1986","author":"bach","key":"17"},{"key":"36","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180445"},{"key":"18","article-title":"Understanding data lifetime via whole-system simulation","author":"chow","year":"0","journal-title":"Proc of the 13th USENIX Security Symposium 2004"},{"key":"33","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2010.39"},{"key":"15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.10"},{"key":"34","article-title":"Reuse-oriented camouflaging trojan: Vulnerability detection and attack construction","author":"lin","year":"0","journal-title":"Proc of the 40th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks June 2010"},{"journal-title":"Understanding the Linux Kernel","year":"2005","author":"bovet","key":"16"},{"key":"39","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455820"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"14","article-title":"Binary code extraction and interface identification for security applications","author":"caballero","year":"0","journal-title":"Proc of the 17th Annual Network and Distributed System Security Symposium (NDSS'10) February 2010"},{"key":"37","article-title":"Automated whitebox fuzz testing","author":"godefroid","year":"0","journal-title":"Proc of the 15th Annual Network and Distributed System Security Symposium (NDSS'08) February 2008"},{"key":"11","doi-asserted-by":"publisher","DOI":"10.1109\/IAS.2007.36"},{"key":"38","article-title":"Polyglot: Automatic extraction of protocol format using dynamic binary analysis","author":"caballero","year":"0","journal-title":"Proc of the 14th ACM Conference on Computer and and Communications Security (CCS'07) October 2007"},{"key":"12","article-title":"Traps and pitfalls: Practical problems in system call interposition based security tools","author":"garfinkel","year":"0","journal-title":"Proc of Network and Distributed Systems Security Symposium (NDSS'03) February 2003"},{"key":"21","article-title":"Panorama: Capturing system-wide information flow for malware detection and analysis","author":"yin","year":"0","journal-title":"Proc of the 14th ACM Conferences on Computer and Communication Security (CCS'07) October 2007"},{"key":"20","article-title":"Dynamic spyware analysis","author":"egele","year":"0","journal-title":"Proc of the 2007 USENIX Annual Technical Conference (Usenix'07) June 2007"},{"key":"43","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653729"},{"journal-title":"Leveraging Forensic Tools for Virtual Machine Introspection","year":"2011","author":"dolan-gavitt","key":"42"},{"key":"41","article-title":"Automatic Network Protocol Analysis","author":"wondracek","year":"0","journal-title":"Proc of the 15th Annual Network and Distributed System Security Symposium (NDSS'08) February 2008"},{"key":"40","article-title":"Automatic protocol format reverse engineering through context-aware monitored execution","author":"lin","year":"0","journal-title":"Proc of the 15th Annual Network and Distributed System Security Symposium (NDSS'08) February 2008"},{"key":"22","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"23","article-title":"Improving host security with system call policies","author":"provos","year":"0","journal-title":"Proc of the 12th USENIX Security Symposium August 2003"},{"journal-title":"Classification and Grouping of Linux System Calls","year":"0","author":"sekar","key":"24"},{"journal-title":"QEMU An Open Source Processor Emulator","year":"0","key":"25"},{"journal-title":"Temu Binary Code Analysis Via Whole-System Layered Annotative Execution","year":"2010","author":"yin","key":"26"},{"journal-title":"Xed X86 Encoder Decoder","year":"0","key":"27"},{"key":"28","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"29","article-title":"Automatic reverse engineering of data structures from binary execution","author":"lin","year":"0","journal-title":"Proc of the 17th Annual Network and Distributed System Security Symposium (NDSS'10) February 2010"},{"key":"3","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.10"},{"key":"2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.176"},{"key":"10","article-title":"Copilot - A coprocessor-based kernel runtime integrity monitor","author":"petroni jr","year":"0","journal-title":"Proc of the 13th USENIX Security Symposium August 2004"},{"key":"1","article-title":"A virtual machine introspection based architecture for intrusion detection","author":"garfinkel","year":"0","journal-title":"Proc Network and Distributed Systems Security Symposium (NDSS'03) February 2003"},{"key":"30","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653730"},{"key":"7","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046751"},{"key":"6","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"journal-title":"The Volatility Framework Volatile memory artifact extraction utility framework","year":"0","author":"walters","key":"32"},{"key":"5","article-title":"Stealthy malware detection through vmm-based out-of-the-box semantic view reconstruction","author":"jiang","year":"0","journal-title":"Proc of the 14th ACM Conference on Computer and Communications Security (CCS'07) October 2007"},{"key":"31","article-title":"Siggraph: Brute force scanning of kernel data structure instances using graph-based signatures","author":"lin","year":"0","journal-title":"Proc of the 18th Annual Network and Distributed System Security Symposium (NDSS'11) February 2011"},{"key":"4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.24"},{"key":"9","doi-asserted-by":"publisher","DOI":"10.1109\/HOTOS.2001.990073"},{"key":"8","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1145\/1368506.1368517","article-title":"Forensics examination of volatile system data using virtual introspection","volume":"42","author":"hay","year":"2008","journal-title":"SIGOPS Operating System Review"}],"event":{"name":"2012 IEEE Symposium on Security and Privacy (SP) Conference dates subject to change","start":{"date-parts":[[2012,5,20]]},"location":"San Francisco, CA, USA","end":{"date-parts":[[2012,5,23]]}},"container-title":["2012 IEEE Symposium on Security and Privacy"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6233637\/6234400\/06234438.pdf?arnumber=6234438","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,20]],"date-time":"2017-06-20T17:36:01Z","timestamp":1497980161000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6234438\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,5]]},"references-count":43,"URL":"https:\/\/doi.org\/10.1109\/sp.2012.40","relation":{},"subject":[],"published":{"date-parts":[[2012,5]]}}}