메뉴 건너뛰기




Volumn , Issue , 2011, Pages 403-412

BareBox: Efficient malware analysis on bare-metal

Author keywords

Bare metal; Dynamic malware analysis; System restore; VM aware

Indexed keywords

AUTOMATED ANALYSIS; COMMODITY HARDWARE; MALICIOUS BEHAVIOR; MALWARE ANALYSIS; MALWARES; PHYSICAL MEMORY; STATE-OF-THE-ART SYSTEM; SYSTEM RESTORE; VIRTUAL ENVIRONMENTS; VIRTUALIZATIONS; VM-AWARE; WINDOWS SYSTEM;

EID: 84855669384     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2076732.2076790     Document Type: Conference Paper
Times cited : (77)

References (27)
  • 1
    • 84855746345 scopus 로고    scopus 로고
    • Tech. Rep. [Online]
    • M. Labs, "Mcafee threats report: First quarter 2011," McAfee, Tech. Rep., 2011. [Online]. Available: https://secure.mcafee.com/us/resources/ reports/rpquarterly-threat-q1-2011.pdf
    • (2011) Mcafee Threats Report: First Quarter 2011
    • Labs, M.1
  • 14
    • 77955172332 scopus 로고    scopus 로고
    • Measuring virtual machine detection in malware using dsd tracer
    • 10.1007/s11416-008-0096-y
    • B. Lau and V. Svajcer, "Measuring virtual machine detection in malware using dsd tracer," Journal in Computer Virology, vol. 6, pp. 181-195, 2010, 10.1007/s11416-008-0096-y.
    • (2010) Journal in Computer Virology , vol.6 , pp. 181-195
    • Lau, B.1    Svajcer, V.2
  • 15
    • 84855682989 scopus 로고    scopus 로고
    • [Online]
    • "Juzt-reboot." [Online]. Available: http://www.juzt-reboot.com/
    • Juzt-reboot
  • 16
    • 84855682993 scopus 로고    scopus 로고
    • [Online]
    • "Partimage." [Online]. Available: http://www.partimage.org/
    • Partimage
  • 17
    • 85029681162 scopus 로고    scopus 로고
    • Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms
    • ser. SSYM'09. Berkeley, CA, USA: USENIX Association
    • R. Hund, T. Holz, and F. C. Freiling, "Return-oriented rootkits: bypassing kernel code integrity protection mechanisms," in Proceedings of the 18th conference on USENIX security symposium, ser. SSYM'09. Berkeley, CA, USA: USENIX Association, 2009, pp. 383-398.
    • (2009) Proceedings of the 18th Conference on USENIX Security Symposium , pp. 383-398
    • Hund, R.1    Holz, T.2    Freiling, F.C.3
  • 19
    • 0037993654 scopus 로고    scopus 로고
    • [Online]
    • "Fast memory copy." [Online]. Available: http://now.cs. berkeley.edu/Td/bcopy.html
    • Fast Memory Copy
  • 20
    • 77949441598 scopus 로고    scopus 로고
    • Stealthy malware detection and monitoring through vmm-based " out-of-the-box" semantic view reconstruction
    • March
    • X. Jiang, X. Wang, and D. Xu, "Stealthy malware detection and monitoring through vmm-based "out-of-the-box" semantic view reconstruction," ACM Trans. Inf. Syst. Secur., vol. 13, pp. 12:1-12:28, March 2010.
    • (2010) ACM Trans. Inf. Syst. Secur. , vol.13 , pp. 121-1228
    • Jiang, X.1    Wang, X.2    Xu, D.3
  • 22
    • 84855682992 scopus 로고    scopus 로고
    • Avmm: Virtualize client with a bare-metal and asymmetric partitioning approach
    • Submitted, Tech. Rep.
    • N. Xiong, Y. Zhou, H. Liu, and Y. Zhang, "Avmm: Virtualize client with a bare-metal and asymmetric partitioning approach," Submitted, ICC 2011, Tech. Rep., 2011.
    • (2011) ICC 2011
    • Xiong, N.1    Zhou, Y.2    Liu, H.3    Zhang, Y.4
  • 23
    • 77954597899 scopus 로고    scopus 로고
    • Otherworld: Givingapplications a chance to survive os kernel crashes
    • A. Depoutovitch and M. Stumm, "Otherworld: givingapplications a chance to survive os kernel crashes," in EuroSys, 2010, pp. 181-194.
    • (2010) EuroSys , pp. 181-194
    • Depoutovitch, A.1    Stumm, M.2
  • 26
    • 84976789801 scopus 로고
    • The recovery box: Using fast recovery to provide high availability in the unix environment
    • M. Baker and M. Sullivan, "The recovery box: Using fast recovery to provide high availability in the unix environment," in In Proceedings USENIX Summer Conference, 1992, pp. 31-43.
    • (1992) Proceedings USENIX Summer Conference , pp. 31-43
    • Baker, M.1    Sullivan, M.2
  • 27
    • 84855678477 scopus 로고    scopus 로고
    • [Online]
    • "Norman sandbox analyzer." [Online]. Available: http://www.norman.com/products/sandbox analyzer/en
    • Norman Sandbox Analyzer


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.