{"id":"W1546317334","doi":"","title":"Hypervisor support for identifying covertly executing binaries","year":2008,"lang":"en","type":"article","venue":"","topic":"Security and Verification in Computing","field":"Computer Science","cited_by":202,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Toronto","funders":"","keywords":"Rootkit; Hypervisor; Computer science; Malware; Operating system; Executable; Code (set theory); Kernel (algebra); Source code; System call; Linux kernel; Semantic gap; Embedded system; Virtualization; Programming language; Cloud computing","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001210375,0.0005607535,0.0004027082,0.001183489,0.0004169674,0.001579616,0.001698882,0.0006827169,0.003126985],"category_scores_gemma":[0.007456655,0.0006274296,0.0002848162,0.0004362493,0.0008528588,0.003180238,0.001980466,0.0009993602,0.0008035984],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0005217002,"about_ca_system_score_gemma":0.0007301606,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0006738057,"about_ca_topic_score_gemma":0.0008502225,"domain_scores_codex":[0.9984655,0.0003125513,0.0001251272,0.0003248513,0.0005935898,0.0001784243],"domain_scores_gemma":[0.9923046,0.002124353,0.001079819,0.003223403,0.001029244,0.0002385562],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.005201413,0.0004512924,0.06402536,0.0007021268,0.0002768877,0.001580365,0.002151282,0.01706026,0.4067835,0.0240167,0.009705792,0.4680451],"study_design_scores_gemma":[0.0001650286,0.0006148557,0.01847357,0.0001414664,0.000127068,0.0012761,0.0002233142,0.3495001,0.6008346,0.009717742,0.01881558,0.0001104969],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.560579,0.0005406282,0.3342478,0.00032208,0.00009737644,0.0002905593,0.0005211582,0.09335621,0.01004523],"genre_scores_gemma":[0.9301316,0.0001191125,0.06627819,0.00007998469,0.00001977352,0.00006049116,0.0004943944,0.000725884,0.002090588],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.003126985,"threshold_uncertainty_score":0.01046079,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.1085937034258301,"score_gpt":0.304664452298402,"score_spread":0.1960707488725719,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}