{"id":"https://openalex.org/W3021843014","doi":"https://doi.org/10.1145/3380786.3391396","title":"PANDAcap","display_name":"PANDAcap","publication_year":2020,"publication_date":"2020-04-27","ids":{"openalex":"https://openalex.org/W3021843014","doi":"https://doi.org/10.1145/3380786.3391396","mag":"3021843014"},"language":"en","primary_location":{"id":"doi:10.1145/3380786.3391396","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3380786.3391396","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 13th European workshop on Systems Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://pure.uva.nl/ws/files/52421826/3380786.3391396.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055916695","display_name":"Manolis Stamatogiannakis","orcid":"https://orcid.org/0000-0002-5527-8726"},"institutions":[{"id":"https://openalex.org/I865915315","display_name":"Vrije Universiteit Amsterdam","ror":"https://ror.org/008xxew50","country_code":"NL","type":"education","lineage":["https://openalex.org/I865915315"]}],"countries":["NL"],"is_corresponding":true,"raw_author_name":"Manolis Stamatogiannakis","raw_affiliation_strings":["Vrije Universiteit Amsterdam"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Amsterdam","institution_ids":["https://openalex.org/I865915315"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029566823","display_name":"Herbert Bos","orcid":"https://orcid.org/0000-0001-6179-1510"},"institutions":[{"id":"https://openalex.org/I865915315","display_name":"Vrije Universiteit Amsterdam","ror":"https://ror.org/008xxew50","country_code":"NL","type":"education","lineage":["https://openalex.org/I865915315"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Herbert Bos","raw_affiliation_strings":["Vrije Universiteit Amsterdam"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Amsterdam","institution_ids":["https://openalex.org/I865915315"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5034924491","display_name":"Paul Groth","orcid":"https://orcid.org/0000-0003-0183-6910"},"institutions":[{"id":"https://openalex.org/I865915315","display_name":"Vrije Universiteit Amsterdam","ror":"https://ror.org/008xxew50","country_code":"NL","type":"education","lineage":["https://openalex.org/I865915315"]},{"id":"https://openalex.org/I887064364","display_name":"University of Amsterdam","ror":"https://ror.org/04dkp9463","country_code":"NL","type":"education","lineage":["https://openalex.org/I887064364"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Paul Groth","raw_affiliation_strings":["Universiteit van Amsterdam"],"affiliations":[{"raw_affiliation_string":"Universiteit van Amsterdam","institution_ids":["https://openalex.org/I865915315","https://openalex.org/I887064364"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5055916695"],"corresponding_institution_ids":["https://openalex.org/I865915315"],"apc_list":null,"apc_paid":null,"fwci":0.104,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.41088327,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12495","display_name":"Electrostatic Discharge in Electronics","score":0.9955000281333923,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12495","display_name":"Electrostatic Discharge in Electronics","score":0.9955000281333923,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9947999715805054,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9932000041007996,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8349305391311646},{"id":"https://openalex.org/keywords/trace","display_name":"TRACE (psycholinguistics)","score":0.7321491837501526},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5776591300964355},{"id":"https://openalex.org/keywords/honeypot","display_name":"Honeypot","score":0.41810864210128784},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.3878485858440399},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.21665874123573303},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.08604860305786133}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8349305391311646},{"id":"https://openalex.org/C75291252","wikidata":"https://www.wikidata.org/wiki/Q1315756","display_name":"TRACE (psycholinguistics)","level":2,"score":0.7321491837501526},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5776591300964355},{"id":"https://openalex.org/C191267431","wikidata":"https://www.wikidata.org/wiki/Q911932","display_name":"Honeypot","level":2,"score":0.41810864210128784},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3878485858440399},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.21665874123573303},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.08604860305786133},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/3380786.3391396","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3380786.3391396","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 13th European workshop on Systems Security","raw_type":"proceedings-article"},{"id":"pmh:oai:dare.uva.nl:openaire/dab86366-1388-48a3-acee-b9a4c30a764e","is_oa":true,"landing_page_url":"https://handle.uba.uva.nl/personal/pure/en/publications/pandacap-a-framework-for-streamlining-collection-of-fullsystem-traces(dab86366-1388-48a3-acee-b9a4c30a764e).html","pdf_url":"https://pure.uva.nl/ws/files/52421826/3380786.3391396.pdf","source":{"id":"https://openalex.org/S4306400088","display_name":"UvA-DARE (University of Amsterdam)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I887064364","host_organization_name":"University of Amsterdam","host_organization_lineage":["https://openalex.org/I887064364"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Stamatogiannakis, M, Bos, H & Groth, P 2020, PANDAcap: A framework for streamlining collection of full-system traces. in EuroSec 2020 : proceedings of the 13th European Workshop on Systems Security : April 27, 2020, Heraklion, Crete, Greece. New York, NY, pp. 1-6, 13th European Workshop on Systems Security, EuroSec 2020, Heraklion, Greece, 27/04/20. https://doi.org/10.1145/3380786.3391396","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:oai:research.vu.nl:publications/0b6aa4c1-01da-4cb5-97aa-aa90e97c5ed9","is_oa":true,"landing_page_url":"https://research.vu.nl/en/publications/0b6aa4c1-01da-4cb5-97aa-aa90e97c5ed9","pdf_url":"https://research.vu.nl/en/publications/0b6aa4c1-01da-4cb5-97aa-aa90e97c5ed9","source":{"id":"https://openalex.org/S4306400546","display_name":"Digital Academic REpository of VU University Amsterdam (Vrije Universiteit Amsterdam)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I865915315","host_organization_name":"Vrije Universiteit Amsterdam","host_organization_lineage":["https://openalex.org/I865915315"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Stamatogiannakis, M, Bos, H & Groth, P 2020, PANDAcap: A framework for streamlining collection of full-system traces. in EuroSec '20 : Proceedings of the 13th European Workshop on Systems Security. Association for Computing Machinery, Inc, pp. 1-6, 13th European Workshop on Systems Security, EuroSec 2020, Heraklion, Greece, 27/04/20. https://doi.org/10.1145/3380786.3391396","raw_type":"contributionToPeriodical"},{"id":"pmh:uvapub:oai:dare.uva.nl:openaire_cris_publications/dab86366-1388-48a3-acee-b9a4c30a764e","is_oa":true,"landing_page_url":"https://dare.uva.nl/personal/pure/en/publications/pandacap-a-framework-for-streamlining-collection-of-fullsystem-traces(dab86366-1388-48a3-acee-b9a4c30a764e).html","pdf_url":null,"source":{"id":"https://openalex.org/S4306401843","display_name":"Data Archiving and Networked Services (DANS)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1322597698","host_organization_name":"Royal Netherlands Academy of Arts and Sciences","host_organization_lineage":["https://openalex.org/I1322597698"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"EuroSec 2020: proceedings of the 13th European Workshop on Systems Security : April 27, 2020, Heraklion, Crete, Greece, 1 - 6","raw_type":"info:eu-repo/semantics/conferencepaper"}],"best_oa_location":{"id":"pmh:oai:dare.uva.nl:openaire/dab86366-1388-48a3-acee-b9a4c30a764e","is_oa":true,"landing_page_url":"https://handle.uba.uva.nl/personal/pure/en/publications/pandacap-a-framework-for-streamlining-collection-of-fullsystem-traces(dab86366-1388-48a3-acee-b9a4c30a764e).html","pdf_url":"https://pure.uva.nl/ws/files/52421826/3380786.3391396.pdf","source":{"id":"https://openalex.org/S4306400088","display_name":"UvA-DARE (University of Amsterdam)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I887064364","host_organization_name":"University of Amsterdam","host_organization_lineage":["https://openalex.org/I887064364"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Stamatogiannakis, M, Bos, H & Groth, P 2020, PANDAcap: A framework for streamlining collection of full-system traces. in EuroSec 2020 : proceedings of the 13th European Workshop on Systems Security : April 27, 2020, Heraklion, Crete, Greece. New York, NY, pp. 1-6, 13th European Workshop on Systems Security, EuroSec 2020, Heraklion, Greece, 27/04/20. https://doi.org/10.1145/3380786.3391396","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[{"display_name":"Sustainable cities and communities","id":"https://metadata.un.org/sdg/11","score":0.5199999809265137}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3021843014.pdf","grobid_xml":"https://content.openalex.org/works/W3021843014.grobid-xml"},"referenced_works_count":18,"referenced_works":["https://openalex.org/W87604264","https://openalex.org/W2004013580","https://openalex.org/W2060782570","https://openalex.org/W2128105693","https://openalex.org/W2133217855","https://openalex.org/W2215262239","https://openalex.org/W2431100065","https://openalex.org/W2512166484","https://openalex.org/W2746973212","https://openalex.org/W2794801050","https://openalex.org/W2806678366","https://openalex.org/W2886900553","https://openalex.org/W2951565607","https://openalex.org/W2951754944","https://openalex.org/W2951914319","https://openalex.org/W2955573656","https://openalex.org/W2963957599","https://openalex.org/W4256483320"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2789663798","https://openalex.org/W2375896275","https://openalex.org/W4230913293","https://openalex.org/W2166943775","https://openalex.org/W2775236000","https://openalex.org/W2151915331","https://openalex.org/W2071426633","https://openalex.org/W2349754162"],"abstract_inverted_index":{"Full-system,":[0],"deterministic":[1],"record":[2,54],"and":[3,15,27,55,61],"replay":[4,56],"has":[5],"proven":[6],"to":[7,66,78,97,109],"be":[8],"an":[9,111],"invaluable":[10],"tool":[11],"for":[12,89],"reverse":[13],"engineering":[14],"systems":[16],"analysis.":[17],"However,":[18],"acquiring":[19],"a":[20,32,40,48,103],"full-system":[21,53],"recording":[22,39,71],"typically":[23],"involves":[24],"signifcant":[25],"planning":[26],"manual":[28],"effort.":[29],"This":[30],"represents":[31],"distraction":[33],"from":[34],"the":[35,68,80,117],"actual":[36],"goal":[37],"of":[38,70,82,91],"trace,":[41],"i.e.":[42],"analyzing":[43],"it.":[44],"We":[45],"present":[46],"PANDAcap,":[47],"framework":[49],"based":[50],"on":[51],"PANDA":[52,72,99],"tool.":[57],"PANDAcap":[58,86,108],"combines":[59],"off-the-shelf":[60],"custom-built":[62],"components":[63],"in":[64,76,95],"order":[65,96],"streamline":[67],"process":[69],"traces.":[73],"More":[74],"importantly,":[75],"addition":[77],"making":[79],"setup":[81],"one-off":[83],"experiments":[84,94],"easier,":[85],"also":[87],"caters":[88],"streamlining":[90],"systematic":[92],"repeatable":[93],"create":[98],"trace":[100],"datasets.":[101],"As":[102],"demonstration,":[104],"we":[105],"have":[106],"used":[107],"deploy":[110],"ssh":[112,119],"honeypot":[113],"aiming":[114],"at":[115],"studying":[116],"brute-force":[118],"attacks.":[120]},"counts_by_year":[{"year":2021,"cited_by_count":1}],"updated_date":"2026-04-15T08:11:43.952461","created_date":"2020-05-13T00:00:00"}
