{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:FO2TUBIM4QSVZXXSO7LZSMF3FR","short_pith_number":"pith:FO2TUBIM","schema_version":"1.0","canonical_sha256":"2bb53a050ce4255cdef277d79930bb2c775e861a5755bb6c8aa0d0265cdd8af7","source":{"kind":"arxiv","id":"2405.00298","version":1},"attestation_state":"computed","paper":{"title":"The Reversing Machine: Reconstructing Memory Assumptions","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Erik van der Kouwe, Jeong-A Lee, Mohammad K. Fallah, Mohammad Sina Karvandi, Saeid Gorgin, Saleh Khalaj Monfared, Sima Arasteh, Soroush Meghdadizanjani","submitted_at":"2024-05-01T03:48:22Z","abstract_excerpt":"Existing anti-malware software and reverse engineering toolkits struggle with stealthy sub-OS rootkits due to limitations of run-time kernel-level monitoring. A malicious kernel-level driver can bypass OS-level anti-virus mechanisms easily. Although static analysis of such malware is possible, obfuscation and packing techniques complicate offline analysis. Moreover, current dynamic analyzers suffer from virtualization performance overhead and create detectable traces that allow modern malware to evade them.\n  To address these issues, we present \\textit{The Reversing Machine} (TRM), a new hyper"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.00298","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2024-05-01T03:48:22Z","cross_cats_sorted":[],"title_canon_sha256":"4486db6c35aae4ee1c926c364d090a3ba546ca5185ff809bc76358bad132863c","abstract_canon_sha256":"8c0cee1d4271068e9db10a1c9cac5da04d014a29a57c0d76caa736015d4d8d18"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:14:11.095024Z","signature_b64":"hduSgOr8MGQkw+O9o/NbD3a0OE/x5ieCT4Dcs+Xu4uhcULWO1Fv1IpLTVAI+GgCEivBEI8poUTXsSqMba0jcCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2bb53a050ce4255cdef277d79930bb2c775e861a5755bb6c8aa0d0265cdd8af7","last_reissued_at":"2026-07-05T08:14:11.094571Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:14:11.094571Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"The Reversing Machine: Reconstructing Memory Assumptions","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Erik van der Kouwe, Jeong-A Lee, Mohammad K. Fallah, Mohammad Sina Karvandi, Saeid Gorgin, Saleh Khalaj Monfared, Sima Arasteh, Soroush Meghdadizanjani","submitted_at":"2024-05-01T03:48:22Z","abstract_excerpt":"Existing anti-malware software and reverse engineering toolkits struggle with stealthy sub-OS rootkits due to limitations of run-time kernel-level monitoring. A malicious kernel-level driver can bypass OS-level anti-virus mechanisms easily. Although static analysis of such malware is possible, obfuscation and packing techniques complicate offline analysis. Moreover, current dynamic analyzers suffer from virtualization performance overhead and create detectable traces that allow modern malware to evade them.\n  To address these issues, we present \\textit{The Reversing Machine} (TRM), a new hyper"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.00298","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.00298/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.00298","created_at":"2026-07-05T08:14:11.094626+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.00298v1","created_at":"2026-07-05T08:14:11.094626+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.00298","created_at":"2026-07-05T08:14:11.094626+00:00"},{"alias_kind":"pith_short_12","alias_value":"FO2TUBIM4QSV","created_at":"2026-07-05T08:14:11.094626+00:00"},{"alias_kind":"pith_short_16","alias_value":"FO2TUBIM4QSVZXXS","created_at":"2026-07-05T08:14:11.094626+00:00"},{"alias_kind":"pith_short_8","alias_value":"FO2TUBIM","created_at":"2026-07-05T08:14:11.094626+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.05974","citing_title":"PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts","ref_index":78,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05974","citing_title":"PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts","ref_index":78,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR","json":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR.json","graph_json":"https://pith.science/api/pith-number/FO2TUBIM4QSVZXXSO7LZSMF3FR/graph.json","events_json":"https://pith.science/api/pith-number/FO2TUBIM4QSVZXXSO7LZSMF3FR/events.json","paper":"https://pith.science/paper/FO2TUBIM"},"agent_actions":{"view_html":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR","download_json":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR.json","view_paper":"https://pith.science/paper/FO2TUBIM","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.00298&json=true","fetch_graph":"https://pith.science/api/pith-number/FO2TUBIM4QSVZXXSO7LZSMF3FR/graph.json","fetch_events":"https://pith.science/api/pith-number/FO2TUBIM4QSVZXXSO7LZSMF3FR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR/action/storage_attestation","attest_author":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR/action/author_attestation","sign_citation":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR/action/citation_signature","submit_replication":"https://pith.science/pith/FO2TUBIM4QSVZXXSO7LZSMF3FR/action/replication_record"}},"created_at":"2026-07-05T08:14:11.094626+00:00","updated_at":"2026-07-05T08:14:11.094626+00:00"}