{"id":"https://openalex.org/W2900822740","doi":"https://doi.org/10.1145/3274694.3274698","title":"Hiding in the Shadows","display_name":"Hiding in the Shadows","publication_year":2018,"publication_date":"2018-12-03","ids":{"openalex":"https://openalex.org/W2900822740","doi":"https://doi.org/10.1145/3274694.3274698","mag":"2900822740"},"language":"en","primary_location":{"id":"doi:10.1145/3274694.3274698","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3274694.3274698","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 34th Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5103119931","display_name":"Sergej Proskurin","orcid":"https://orcid.org/0000-0002-0524-2493"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Sergej Proskurin","raw_affiliation_strings":["Technical University of Munich"],"affiliations":[{"raw_affiliation_string":"Technical University of Munich","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5010465935","display_name":"Tamas K. Lengyel","orcid":"https://orcid.org/0009-0000-6814-1123"},"institutions":[{"id":"https://openalex.org/I82514191","display_name":"Honeywell (United States)","ror":"https://ror.org/02t71h845","country_code":"US","type":"company","lineage":["https://openalex.org/I82514191"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tamas Lengyel","raw_affiliation_strings":["The Honeynet Project"],"affiliations":[{"raw_affiliation_string":"The Honeynet Project","institution_ids":["https://openalex.org/I82514191"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026880771","display_name":"Marius Momeu","orcid":"https://orcid.org/0009-0009-3389-9837"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Marius Momeu","raw_affiliation_strings":["Technical University of Munich"],"affiliations":[{"raw_affiliation_string":"Technical University of Munich","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073408463","display_name":"Claudia Eckert","orcid":"https://orcid.org/0000-0002-2201-3828"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Claudia Eckert","raw_affiliation_strings":["Technical University of Munich"],"affiliations":[{"raw_affiliation_string":"Technical University of Munich","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5065154871","display_name":"Apostolis Zarras","orcid":"https://orcid.org/0000-0002-8480-6989"},"institutions":[{"id":"https://openalex.org/I34352273","display_name":"Maastricht University","ror":"https://ror.org/02jz4aj89","country_code":"NL","type":"education","lineage":["https://openalex.org/I34352273"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Apostolis Zarras","raw_affiliation_strings":["Maastricht University"],"affiliations":[{"raw_affiliation_string":"Maastricht University","institution_ids":["https://openalex.org/I34352273"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5103119931"],"corresponding_institution_ids":["https://openalex.org/I62916508"],"apc_list":null,"apc_paid":null,"fwci":1.6514,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.85473712,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"407","last_page":"417"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9959999918937683,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7732173204421997},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7635634541511536},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.7078267335891724},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5961025357246399},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.48881837725639343},{"id":"https://openalex.org/keywords/hypervisor","display_name":"Hypervisor","score":0.43019038438796997},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.41837990283966064},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.4008675515651703},{"id":"https://openalex.org/keywords/virtualization","display_name":"Virtualization","score":0.3062467575073242},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.13764482736587524}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7732173204421997},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7635634541511536},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.7078267335891724},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5961025357246399},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.48881837725639343},{"id":"https://openalex.org/C112904061","wikidata":"https://www.wikidata.org/wiki/Q1077480","display_name":"Hypervisor","level":4,"score":0.43019038438796997},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.41837990283966064},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.4008675515651703},{"id":"https://openalex.org/C513985346","wikidata":"https://www.wikidata.org/wiki/Q270471","display_name":"Virtualization","level":3,"score":0.3062467575073242},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.13764482736587524},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3274694.3274698","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3274694.3274698","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 34th Annual Computer Security Applications Conference","raw_type":"proceedings-article"},{"id":"pmh:oai:cris.maastrichtuniversity.nl:openaire_cris_publications/23d35e5c-070d-4912-b10b-84807eee6dc2","is_oa":false,"landing_page_url":"https://cris.maastrichtuniversity.nl/en/publications/23d35e5c-070d-4912-b10b-84807eee6dc2","pdf_url":null,"source":{"id":"https://openalex.org/S4306402616","display_name":"Research Publications (Maastricht University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I34352273","host_organization_name":"Maastricht University","host_organization_lineage":["https://openalex.org/I34352273"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proskurin, S, Lengyel, T, Momeu, M, Eckert, C & Zarras, A 2018, Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine Introspection. in 34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018). The Association for Computing Machinery, pp. 407-417, 34th Annual Computer Security Applications Conference (ACSAC), 3/12/18. https://doi.org/10.1145/3274694.3274698","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W17417926","https://openalex.org/W19788882","https://openalex.org/W23711711","https://openalex.org/W1534092936","https://openalex.org/W1546317334","https://openalex.org/W1641762327","https://openalex.org/W1813040609","https://openalex.org/W1865564993","https://openalex.org/W1953268564","https://openalex.org/W1990280725","https://openalex.org/W2070041400","https://openalex.org/W2070386561","https://openalex.org/W2087740020","https://openalex.org/W2102001185","https://openalex.org/W2115175195","https://openalex.org/W2120297918","https://openalex.org/W2140807364","https://openalex.org/W2144006591","https://openalex.org/W2193838104","https://openalex.org/W2273027740","https://openalex.org/W2350778671","https://openalex.org/W2550565492","https://openalex.org/W2752858240","https://openalex.org/W2888194849"],"related_works":["https://openalex.org/W1973516247","https://openalex.org/W1991063492","https://openalex.org/W2743348030","https://openalex.org/W2622620488","https://openalex.org/W2075174112","https://openalex.org/W2145292010","https://openalex.org/W2976854232","https://openalex.org/W2102844359","https://openalex.org/W2747005099","https://openalex.org/W2943837643"],"abstract_inverted_index":{"ARM":[0,41],"has":[1,14,66],"become":[2],"the":[3,22,40,44,81],"leading":[4],"processor":[5],"architecture":[6],"for":[7,71],"mobile":[8],"and":[9,58],"IoT":[10],"devices,":[11],"while":[12],"it":[13,30,78],"recently":[15],"started":[16],"claiming":[17],"a":[18],"bigger":[19],"slice":[20],"of":[21,47],"server":[23],"market":[24],"pie":[25],"as":[26],"well.":[27],"As":[28],"such,":[29],"will":[31],"not":[32],"be":[33,85],"long":[34],"before":[35],"malware":[36,72],"more":[37],"regularly":[38],"target":[39],"architecture.":[42],"Therefore,":[43],"stealthy":[45],"operation":[46],"Virtual":[48],"Machine":[49],"Introspection":[50],"(VMI)":[51],"is":[52],"an":[53],"obligation":[54],"to":[55,84],"successfully":[56],"analyze":[57],"proactively":[59],"mitigate":[60],"this":[61],"growing":[62],"threat.":[63],"Stealthy":[64],"VMI":[65],"proven":[67],"itself":[68],"perfectly":[69],"suitable":[70],"analysis":[73],"on":[74,88],"Intel's":[75],"architecture,":[76],"yet,":[77],"often":[79],"lacks":[80],"foundation":[82],"required":[83],"equally":[86],"effective":[87],"ARM.":[89]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2018-11-29T00:00:00"}
