{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T17:23:41Z","timestamp":1743009821210,"version":"3.40.3"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030242640"},{"type":"electronic","value":"9783030242657"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-24265-7_49","type":"book-chapter","created":{"date-parts":[[2019,7,17]],"date-time":"2019-07-17T23:19:24Z","timestamp":1563405564000},"page":"571-583","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["When Side Channel Becomes Good: Kernel Malware Attack Investigation"],"prefix":"10.1007","author":[{"given":"Libo","family":"Yin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chonghua","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rongchao","family":"Yin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Jiao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,7,11]]},"reference":[{"key":"49_CR1","unstructured":"Dkom(direct kernel objectmanipulation). https:\/\/www.blackhat.com\/presentations\/win-usa-04\/bh-win-04-butler.pdf"},{"key":"49_CR2","doi-asserted-by":"crossref","unstructured":"Irazoqui Apecechea, G., Eisenbarth, T., Sunar, B.: S\\$ a: a shared cache attack that works across cores and defies VM sandboxing - and its application to AES. In: 2015 IEEE Symposium on Security and Privacy (S&P), pp. 591\u2013604, San Jose, CA, USA, 17\u201321 May 2015","DOI":"10.1109\/SP.2015.42"},{"key":"49_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1007\/978-3-319-11379-1_15","volume-title":"Research in Attacks, Intrusions and Defenses","author":"G Irazoqui","year":"2014","unstructured":"Irazoqui, G., Inci, M.S., Eisenbarth, T., Sunar, B.: Wait a minute! a fast, cross-VM attack on AES. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) RAID 2014. LNCS, vol. 8688, pp. 299\u2013319. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_15"},{"issue":"1","key":"49_CR4","doi-asserted-by":"publisher","first-page":"2:1","DOI":"10.1145\/2767005","volume":"48","author":"CA Ardagna","year":"2015","unstructured":"Ardagna, C.A., Asal, R., Damiani, E., Vu, Q.H.: From security to assurance in the cloud: a survey. ACM Comput. Surv. 48(1), 2:1\u20132:50 (2015)","journal-title":"ACM Comput. Surv."},{"key":"49_CR5","doi-asserted-by":"crossref","unstructured":"Bahram,S., et al.: Dksm: subverting virtual machine introspection for fun and profit. In: Proceedings of IEEE Symposium on Reliable Distributed Systems (SRDS), pp. 82\u201391 (2010)","DOI":"10.1109\/SRDS.2010.39"},{"key":"49_CR6","unstructured":"Barresi, A., Razavi, K., Payer, M., Gross, T.R.: CAIN: silently breaking ASLR in the cloud. In: 9th USENIX Workshop on Offensive Technologies (WOOT), Washington, DC, USA, 10\u201311 August 2015"},{"key":"49_CR7","unstructured":"Bates, A., Tian, D., Butler, K., Moyer, T.: Trustworthy whole-system provenance for the linux kernel. In: USENIX Security, pp. 319\u2013334 (2015)"},{"key":"49_CR8","doi-asserted-by":"crossref","unstructured":"Carbone, M., Cui, W., Lu, L., Lee, W., Peinado, M., Jiang, X.: Mapping kernel objects to enable systematic integrity checking. In: Proceedings of ACM Conference on Computer and Communications Security (CCS), pp. 555\u2013565 (2009)","DOI":"10.1145\/1653662.1653729"},{"key":"49_CR9","doi-asserted-by":"crossref","unstructured":"Cock, D., Ge, Q., Murray, T.C., Heiser, G.: The last mile: an empirical study of timing channels on seL4. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 570\u2013581, Scottsdale, AZ, USA, 3\u20137 November 2014","DOI":"10.1145\/2660267.2660294"},{"key":"49_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1007\/978-3-319-40667-1_14","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"D Gruss","year":"2016","unstructured":"Gruss, D., Maurice, C., Wagner, K., Mangard, S.: Flush+Flush: a fast and stealthy cache attack. In: Caballero, J., Zurutuza, U., Rodr\u00edguez, R.J. (eds.) DIMVA 2016. LNCS, vol. 9721, pp. 279\u2013299. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-40667-1_14"},{"key":"49_CR11","doi-asserted-by":"crossref","unstructured":"Gullasch, D., Bangerter, E., Krenn, S.: Cache games - bringing access-based cache attacks on AES to practice. In: 32nd IEEE Symposium on Security and Privacy (S&P), pp. 490\u2013505, Berkeley, California, USA, 22\u201325 May 2011","DOI":"10.1109\/SP.2011.22"},{"issue":"2\/3","key":"49_CR12","doi-asserted-by":"publisher","first-page":"141","DOI":"10.3233\/JCS-2000-82-304","volume":"8","author":"J Kelsey","year":"2000","unstructured":"Kelsey, J., Schneier, B., Wagner, D.A., Hall, C.: Side channel cryptanalysis of product ciphers. J. Comput. Secur. 8(2\/3), 141\u2013158 (2000)","journal-title":"J. Comput. Secur."},{"key":"49_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","volume-title":"Advances in Cryptology \u2014 CRYPTO 1996","author":"PC Kocher","year":"1996","unstructured":"Kocher, P.C.: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and Other Systems. In: Koblitz, N. (ed.) CRYPTO 1996. LNCS, vol. 1109, pp. 104\u2013113. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68697-5_9"},{"key":"49_CR14","unstructured":"Lee, K., Zhang, X., Xu, D.: High accuracy attack provenance via binary-based execution partition. In: Proceedings of Network and Distributed System Security Symposium (NDSS) (2013)"},{"key":"49_CR15","doi-asserted-by":"crossref","unstructured":"Lee, K., Zhang, X., Xu, D.: LogGC: garbage collecting audit log. In: Proceedings of ACM Conference on Computer and Communications Security (CCS), pp. 1005\u20131016 (2013)","DOI":"10.1145\/2508859.2516731"},{"key":"49_CR16","unstructured":"Lipp, M., Gruss, D., Spreitzer, R., Maurice, C., Mangard, S.: Armageddon: cache attacks on mobile devices. In: 25th USENIX Security Symposium (Security), pp. 549\u2013564, Austin, TX, USA, 10\u201312 August 2016"},{"key":"49_CR17","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., Lee, R.B.: Last-level cache side-channel attacks are practical. In: 2015 IEEE Symposium on Security and Privacy (S&P), pp. 605\u2013622, San Jose, CA, USA, 17\u201321 May 2015","DOI":"10.1109\/SP.2015.43"},{"key":"49_CR18","unstructured":"Ma, S., Lee, K., Kim, C., Rhee, J., Zhang, X., Xu, D.: Accurate, low cost and instrumentation-free security audit logging for windows. In: Proceedings of Annual Computer Security Applications Conference (ACSAC), pp. 401\u2013410 (2011)"},{"key":"49_CR19","doi-asserted-by":"crossref","unstructured":"Ma, S., Zhang, X., Xu, D.: Protracer: towards practical provenance tracing by alternating between logging and tainting. In: Proceedings of Network and Distributed System Security Symposium (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23350"},{"key":"49_CR20","doi-asserted-by":"crossref","unstructured":"Pei, K., et al.: HERCULE: attack story reconstruction via community discovery on correlated log graph. In: Proceedings of Annual Computer Security Applications Conference (ACSAC), pp. 583\u2013595 (2016)","DOI":"10.1145\/2991079.2991122"},{"key":"49_CR21","doi-asserted-by":"crossref","unstructured":"Pohly, D., McLaughlin, S., McDaniel, P., Butler, K.: Hi-Fi: collecting high-fidelity whole-system provenance. In: Proceedings of Annual Computer Security Applications Conference (ACSAC), pp. 259\u2013268 (2012)","DOI":"10.1145\/2420950.2420989"},{"key":"49_CR22","doi-asserted-by":"crossref","unstructured":"Rhee, J., Riley, R., Xu, D., Jiang, X.: Defeating dynamic data kernel rootkit attacks via VMM-based guest-transparent monitoring. In: 2009 International Conference on Availability, Reliability and Security, pp. 74\u201381 (2009)","DOI":"10.1109\/ARES.2009.116"},{"key":"49_CR23","doi-asserted-by":"crossref","unstructured":"Ristenpart, T., Tromer, E., Shacham, H., Savage, S.: Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. In: Proceedings of the ACM Conference on Computer and Communications Security (CCS), pp. 199\u2013212, Chicago, Illinois, USA, 9\u201313 November 2009","DOI":"10.1145\/1653662.1653687"},{"key":"49_CR24","first-page":"1","volume":"99","author":"E Rudd","year":"2016","unstructured":"Rudd, E., Rozsa, A., Gunther, M., Boult, T.: A survey of stealth malware: attacks, mitigation measures, and steps toward autonomous open world solutions. IEEE Commun. Surv. Tutor. 99, 1\u201328 (2016)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"49_CR25","doi-asserted-by":"crossref","unstructured":"Xu, Z., et al.: High fidelity data reduction for big data security dependency analyses. In: Proceedings of ACM Conference on Computer and Communications Security (CCS), pp. 504\u2013516 (2016)","DOI":"10.1145\/2976749.2978378"},{"key":"49_CR26","unstructured":"Yarom, Y., Falkner, K.: FLUSH+RELOAD: a high resolution, low noise, L3 cache side-channel attack. In: Proceedings of the 23rd USENIX Security Symposium (Security), pp. 719\u2013732, San Diego, CA, USA, 20\u201322 August 2014"},{"key":"49_CR27","doi-asserted-by":"crossref","unstructured":"Zhang, X., Xiao, Y., Zhang, Y.: Return-oriented flush-reload side channels on ARM and their implications for android devices. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 858\u2013870, Vienna, Austria, 24\u201328 October 2016","DOI":"10.1145\/2976749.2978360"},{"key":"49_CR28","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-VM side channels and their use to extract private keys. In: The ACM Conference on Computer and Communications Security (CCS), pp. 305\u2013316, Raleigh, NC, USA, 16\u201318 October 2012","DOI":"10.1145\/2382196.2382230"},{"key":"49_CR29","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-tenant side-channel attacks in PaaS clouds. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 990\u20131003, Scottsdale, AZ, USA, 3\u20137 November 2014","DOI":"10.1145\/2660267.2660356"}],"container-title":["Lecture Notes in Computer Science","Artificial Intelligence and Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-24265-7_49","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,1,13]],"date-time":"2021-01-13T04:05:05Z","timestamp":1610510705000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-24265-7_49"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030242640","9783030242657"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-24265-7_49","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"11 July 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICAIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Artificial Intelligence and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"New York, NY","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 July 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"incodldos2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.icaisconf.com\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}