{"id":"https://openalex.org/W2884595190","doi":"https://doi.org/10.1016/j.diin.2018.04.015","title":"Who watches the watcher? Detecting hypervisor introspection from unprivileged guests","display_name":"Who watches the watcher? Detecting hypervisor introspection from unprivileged guests","publication_year":2018,"publication_date":"2018-07-01","ids":{"openalex":"https://openalex.org/W2884595190","doi":"https://doi.org/10.1016/j.diin.2018.04.015","mag":"2884595190"},"language":"en","primary_location":{"id":"doi:10.1016/j.diin.2018.04.015","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.diin.2018.04.015","pdf_url":null,"source":{"id":"https://openalex.org/S67081940","display_name":"Digital Investigation","issn_l":"1742-2876","issn":["1742-2876","1873-202X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Digital Investigation","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1016/j.diin.2018.04.015","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5068129947","display_name":"Tomasz Tuzel","orcid":null},"institutions":[{"id":"https://openalex.org/I4210097321","display_name":"Assured Information Security (United States)","ror":"https://ror.org/00w5xhg82","country_code":"US","type":"company","lineage":["https://openalex.org/I4210097321"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Tomasz Tuzel","raw_affiliation_strings":["Assured Information Security, Greenwood Village, CO, USA"],"affiliations":[{"raw_affiliation_string":"Assured Information Security, Greenwood Village, CO, USA","institution_ids":["https://openalex.org/I4210097321"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022385417","display_name":"Mark P. Bridgman","orcid":null},"institutions":[{"id":"https://openalex.org/I4210097321","display_name":"Assured Information Security (United States)","ror":"https://ror.org/00w5xhg82","country_code":"US","type":"company","lineage":["https://openalex.org/I4210097321"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mark Bridgman","raw_affiliation_strings":["Assured Information Security, Greenwood Village, CO, USA"],"affiliations":[{"raw_affiliation_string":"Assured Information Security, Greenwood Village, CO, USA","institution_ids":["https://openalex.org/I4210097321"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044110628","display_name":"Joshua Zepf","orcid":null},"institutions":[{"id":"https://openalex.org/I4210097321","display_name":"Assured Information Security (United States)","ror":"https://ror.org/00w5xhg82","country_code":"US","type":"company","lineage":["https://openalex.org/I4210097321"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Joshua Zepf","raw_affiliation_strings":["Assured Information Security, Greenwood Village, CO, USA"],"affiliations":[{"raw_affiliation_string":"Assured Information Security, Greenwood Village, CO, USA","institution_ids":["https://openalex.org/I4210097321"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5010465935","display_name":"Tamas K. Lengyel","orcid":"https://orcid.org/0009-0000-6814-1123"},"institutions":[{"id":"https://openalex.org/I4210097321","display_name":"Assured Information Security (United States)","ror":"https://ror.org/00w5xhg82","country_code":"US","type":"company","lineage":["https://openalex.org/I4210097321"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tamas K. Lengyel","raw_affiliation_strings":["Assured Information Security, Greenwood Village, CO, USA"],"affiliations":[{"raw_affiliation_string":"Assured Information Security, Greenwood Village, CO, USA","institution_ids":["https://openalex.org/I4210097321"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5059146233","display_name":"Ken Temkin","orcid":null},"institutions":[{"id":"https://openalex.org/I4210097321","display_name":"Assured Information Security (United States)","ror":"https://ror.org/00w5xhg82","country_code":"US","type":"company","lineage":["https://openalex.org/I4210097321"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"K.J. Temkin","raw_affiliation_strings":["Assured Information Security, Greenwood Village, CO, USA"],"affiliations":[{"raw_affiliation_string":"Assured Information Security, Greenwood Village, CO, USA","institution_ids":["https://openalex.org/I4210097321"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5068129947"],"corresponding_institution_ids":["https://openalex.org/I4210097321"],"apc_list":null,"apc_paid":null,"fwci":2.5247,"has_fulltext":false,"cited_by_count":15,"citation_normalized_percentile":{"value":0.8953801,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":"26","issue":null,"first_page":"S98","last_page":"S106"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10054","display_name":"Parallel Computing and Optimization Techniques","score":0.9961000084877014,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10054","display_name":"Parallel Computing and Optimization Techniques","score":0.9961000084877014,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10772","display_name":"Distributed systems and fault tolerance","score":0.9876000285148621,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9865000247955322,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hypervisor","display_name":"Hypervisor","score":0.9499144554138184},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8898863792419434},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.6808629035949707},{"id":"https://openalex.org/keywords/thread","display_name":"Thread (computing)","score":0.5843230485916138},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.4691530466079712},{"id":"https://openalex.org/keywords/cache","display_name":"Cache","score":0.4425336718559265},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.4286224842071533},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.36985456943511963},{"id":"https://openalex.org/keywords/virtualization","display_name":"Virtualization","score":0.22078397870063782},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.16592463850975037}],"concepts":[{"id":"https://openalex.org/C112904061","wikidata":"https://www.wikidata.org/wiki/Q1077480","display_name":"Hypervisor","level":4,"score":0.9499144554138184},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8898863792419434},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.6808629035949707},{"id":"https://openalex.org/C138101251","wikidata":"https://www.wikidata.org/wiki/Q213092","display_name":"Thread (computing)","level":2,"score":0.5843230485916138},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.4691530466079712},{"id":"https://openalex.org/C115537543","wikidata":"https://www.wikidata.org/wiki/Q165596","display_name":"Cache","level":2,"score":0.4425336718559265},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.4286224842071533},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.36985456943511963},{"id":"https://openalex.org/C513985346","wikidata":"https://www.wikidata.org/wiki/Q270471","display_name":"Virtualization","level":3,"score":0.22078397870063782},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.16592463850975037},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1016/j.diin.2018.04.015","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.diin.2018.04.015","pdf_url":null,"source":{"id":"https://openalex.org/S67081940","display_name":"Digital Investigation","issn_l":"1742-2876","issn":["1742-2876","1873-202X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Digital Investigation","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1016/j.diin.2018.04.015","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.diin.2018.04.015","pdf_url":null,"source":{"id":"https://openalex.org/S67081940","display_name":"Digital Investigation","issn_l":"1742-2876","issn":["1742-2876","1873-202X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Digital Investigation","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4495525370","display_name":null,"funder_award_id":"2017-16120700002","funder_id":"https://openalex.org/F4320333051","funder_display_name":"Intelligence Advanced Research Projects Activity"}],"funders":[{"id":"https://openalex.org/F4320312530","display_name":"Office of the Director of National Intelligence","ror":"https://ror.org/01v3fsc55"},{"id":"https://openalex.org/F4320333051","display_name":"Intelligence Advanced Research Projects Activity","ror":"https://ror.org/01v3fsc55"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":17,"referenced_works":["https://openalex.org/W80033927","https://openalex.org/W2032151752","https://openalex.org/W2087740020","https://openalex.org/W2140807364","https://openalex.org/W2337480911","https://openalex.org/W2496872468","https://openalex.org/W2562036180","https://openalex.org/W2751989915","https://openalex.org/W2917582573","https://openalex.org/W4234048285","https://openalex.org/W4244102997","https://openalex.org/W4285719527","https://openalex.org/W6672436730","https://openalex.org/W6703549403","https://openalex.org/W6723661980","https://openalex.org/W6730881097","https://openalex.org/W6743325655"],"related_works":["https://openalex.org/W2032618280","https://openalex.org/W2140556924","https://openalex.org/W2056590904","https://openalex.org/W2495160385","https://openalex.org/W2032031011","https://openalex.org/W78055790","https://openalex.org/W2112715807","https://openalex.org/W2542906811","https://openalex.org/W1589284876","https://openalex.org/W2011213079"],"abstract_inverted_index":{"We":[0],"present":[1],"research":[2],"on":[3],"the":[4,14,46,53],"limitations":[5],"of":[6,16,52],"detecting":[7,57],"atypical":[8],"activity":[9],"by":[10],"a":[11,17,68],"hypervisor":[12,92],"from":[13,90],"perspective":[15],"guest":[18,69],"domain.":[19],"Individual":[20],"instructions":[21,79],"which":[22],"have":[23],"virtual":[24],"machine":[25],"exiting":[26],"capability":[27],"were":[28],"evaluated,":[29],"using":[30],"wall":[31],"timing":[32,42],"and":[33],"kernel":[34],"thread":[35],"racing":[36],"as":[37],"metrics.":[38],"Cache-based":[39],"memory":[40,59,81],"access":[41],"is":[43,65],"performed":[44],"with":[45],"Flush":[47],"+":[48],"Reload":[49],"technique.":[50],"Analysis":[51],"potential":[54],"methods":[55],"for":[56],"non-temporal":[58],"accesses":[60],"are":[61,83],"also":[62],"discussed.":[63],"It":[64],"found":[66],"that":[67,88],"domain":[70],"can":[71],"use":[72],"these":[73],"techniques":[74],"to":[75],"reliably":[76],"determine":[77],"whether":[78],"or":[80],"regions":[82],"being":[84],"accessed":[85],"in":[86],"manner":[87],"deviates":[89],"normal":[91],"behavior.":[93]},"counts_by_year":[{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
