{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:10:11Z","timestamp":1772039411603,"version":"3.50.1"},"publisher-location":"Cham","reference-count":48,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030299613","type":"print"},{"value":"9783030299620","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-29962-0_11","type":"book-chapter","created":{"date-parts":[[2019,9,14]],"date-time":"2019-09-14T23:03:29Z","timestamp":1568502209000},"page":"217-238","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Nighthawk: Transparent System Introspection from Ring -3"],"prefix":"10.1007","author":[{"given":"Lei","family":"Zhou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jidong","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kevin","family":"Leach","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Westley","family":"Weimer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fengwei","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guojun","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,9,15]]},"reference":[{"key":"11_CR1","unstructured":"Adore-ng (2018). https:\/\/github.com\/trimpsyw\/adore-ng\/"},{"key":"11_CR2","unstructured":"RootKits List (2018). https:\/\/github.com\/d30sa1\/RootKits-List-Download"},{"issue":"3","key":"11_CR3","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1535\/itj.1003.02","volume":"10","author":"D Abramson","year":"2006","unstructured":"Abramson, D., et al.: Intel virtualization technology for directed I\/O. Intel Technol. J. 10(3), 179\u2013192 (2006)","journal-title":"Intel Technol. J."},{"key":"11_CR4","doi-asserted-by":"crossref","unstructured":"Azab, A.M., et al.: Hypervision across worlds: real-time kernel protection from the arm trustzone secure world. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security (CCS) (2014)","DOI":"10.1145\/2660267.2660350"},{"key":"11_CR5","doi-asserted-by":"crossref","unstructured":"Azab, A.M., Ning, P., Wang, Z., Jiang, X., Zhang, X., Skalsky, N.C.: HyperSentry: enabling stealthy in-context measurement of hypervisor integrity. In: Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS) (2010)","DOI":"10.1145\/1866307.1866313"},{"key":"11_CR6","doi-asserted-by":"crossref","unstructured":"Chevalier, R., Villatel, M., Plaquin, D., Hiet, G.: Co-processor-based behavior monitoring: application to the detection of attacks against the system management mode. In: Proceedings of the 33rd Annual Computer Security Applications Conference (2017)","DOI":"10.1145\/3134600.3134622"},{"key":"11_CR7","unstructured":"Combs, G.: Wireshark (2019). https:\/\/www.wireshark.org"},{"key":"11_CR8","unstructured":"Corna, N.: ME cleaner: tool for partial deblobbing of Intel ME\/TXE firmware images (2017). https:\/\/github.com\/corna\/me_cleaner"},{"key":"11_CR9","unstructured":"Duflot, L., Levillain, O., Morin, B., Grumelard, O.: Getting into the SMRAM: SMM Reloaded. CanSecWest (2009)"},{"key":"11_CR10","unstructured":"Erica, P., Peter, E.: Intel\u2019s Management Engine is a security hazard, and users need a way to disable it (2017). https:\/\/www.eff.org\/deeplinks\/2017\/05\/intels-management-engine-security-hazard-and-users-need-way-disable-it"},{"key":"11_CR11","unstructured":"Ermolov, M., Goryachy, M.: Disabling Intel ME 11 via undocumented mode (2017). http:\/\/blog.ptsecurity.com\/2017\/08\/disabling-intel-me.html"},{"key":"11_CR12","unstructured":"Ermolov, M., Goryachy, M.: How to Hack a Turned-Off Computer, or Running Unsigned Code in Intel Management Engine. Black Hat Europe (2017)"},{"key":"11_CR13","unstructured":"Gael, H.I.: Intel AMT and the Intel ME (2009). https:\/\/intel.com\/en-us\/blogs\/2011\/12\/14\/intelr-amt-and-the-intelr-me"},{"key":"11_CR14","doi-asserted-by":"crossref","unstructured":"Garfinkel, T., Pfaff, B., Chow, J., Rosenblum, M., Boneh, D.: Terra: a virtual machine-based platform for trusted computing. In: ACM SIGOPS Operating Systems Review (2003)","DOI":"10.1145\/945445.945464"},{"key":"11_CR15","unstructured":"Github: ToorKit (2015). https:\/\/github.com\/deb0ch\/toorkit"},{"key":"11_CR16","unstructured":"Intel: Innovation Engine (2015). https:\/\/en.wikichip.org\/wiki\/intel\/innovation_engine"},{"key":"11_CR17","unstructured":"Intel Corporation: Intel 3 Series Express Chipset Family (2007). https:\/\/www.intel.com\/Assets\/PDF\/datasheet\/316966.pdf"},{"key":"11_CR18","unstructured":"Intel Corporation: Intel Trusted Execution Technology (Intel TXT): Software Development Guide (2017). https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/guides\/intel-txt-software-development-guide.pdf"},{"key":"11_CR19","doi-asserted-by":"crossref","unstructured":"Jang, D., Lee, H., Kim, M., Kim, D., et al.: Atra: address translation redirection attack against hardware-based external monitors. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security (2014)","DOI":"10.1145\/2660267.2660303"},{"key":"11_CR20","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through VMM-based out-of-the-box semantic view reconstruction. In: Proceedings of the 14th ACM conference on Computer and Communications Security (CCS) (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"11_CR21","doi-asserted-by":"crossref","unstructured":"Jones, S.T., Arpaci-Dusseau, A.C., Arpaci-Dusseau, R.H.: VMM-based hidden process detection and identification using Lycosid. In: Proceedings of the fourth ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments (VEE) (2008)","DOI":"10.1145\/1346256.1346269"},{"key":"11_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-45719-2_1","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"L Koromilas","year":"2016","unstructured":"Koromilas, L., Vasiliadis, G., Athanasopoulos, E., Ioannidis, S.: GRIM: leveraging GPUs for kernel integrity monitoring. In: Monrose, F., Dacier, M., Blanc, G., Garcia-Alfaro, J. (eds.) RAID 2016. LNCS, vol. 9854, pp. 3\u201323. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-45719-2_1"},{"key":"11_CR23","unstructured":"Lee, H., et al.: KI-Mon: a hardware-assisted event-triggered monitoring platform for mutable kernel object. In: USENIX Security Symposium (2013)"},{"key":"11_CR24","unstructured":"Lipp, M., Schwarz, M., Gruss, D., Prescher, T., Haas, W., Fogh, A., et al.: Meltdown: reading kernel memory from user space. In: Proceedings of the 27th Conference on USENIX Security Symposium (2018)"},{"key":"11_CR25","doi-asserted-by":"crossref","unstructured":"Malka, M., Amit, N., Ben-Yehuda, M., Tsafrir, D.: rIOMMU: efficient IOMMU for I\/O devices that employ ring buffers. In: ACM SIGPLAN Notices (2015)","DOI":"10.1145\/2694344.2694355"},{"key":"11_CR26","unstructured":"McCalpin, J.D.: STREAM (2018). http:\/\/www.cs.virginia.edu\/stream\/ref.html"},{"key":"11_CR27","doi-asserted-by":"crossref","unstructured":"Moon, H., Lee, H., Lee, J., Kim, K., Paek, Y., Kang, B.B.: Vigilare: toward snoop-based kernel integrity monitor. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security (CCS) (2012)","DOI":"10.1145\/2382196.2382202"},{"key":"11_CR28","unstructured":"National Institute of Standards, NIST: National Vulnerability Database (2018). http:\/\/nvd.nist.gov"},{"key":"11_CR29","unstructured":"Partow, A.: General Purpose Hash Function Algorithms (2018). http:\/\/www.partow.net\/programming\/hashfunctions"},{"key":"11_CR30","doi-asserted-by":"crossref","unstructured":"Perkins, J.H., et al.: Automatically patching errors in deployed software. In: Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles (2009)","DOI":"10.1145\/1629575.1629585"},{"key":"11_CR31","unstructured":"Persmule: Neutralize ME firmware on SandyBridge and IvyBridge platforms (2016). https:\/\/hardenedlinux.github.io\/firmware\/2016\/11\/17\/neutralize_ME_firmware_on_sandybridge_and_ivybridge.html"},{"key":"11_CR32","unstructured":"Petroni Jr, N.L., Fraser, T., Molina, J., Arbaugh, W.A.: Copilot-a Coprocessor-based Kernel Runtime Integrity Monitor. In: USENIX Security Symposium (2004)"},{"key":"11_CR33","doi-asserted-by":"crossref","unstructured":"Ruan, X.: Platform Embedded Security Technology Revealed: Safeguarding the Future of Computing with Intel Embedded Security and Management Engine. Apress (2014)","DOI":"10.1007\/978-1-4302-6572-6"},{"key":"11_CR34","doi-asserted-by":"crossref","unstructured":"Seshadri, A., Luk, M., Qu, N., Perrig, A.: SecVisor: a tiny hypervisor to provide lifetime kernel code integrity for commodity OSes. In: Proceedings of the 21st ACM Symposium on Operating Systems Principles (SOSP) (2007)","DOI":"10.1145\/1294261.1294294"},{"key":"11_CR35","unstructured":"Sklyarov, D.: Intel ME: flash file system explained. Black Hat Europe (2017)"},{"key":"11_CR36","unstructured":"Sklyarov, D.O.: ME: The Way of the Static Analysis. TROOPERS17 (2017)"},{"key":"11_CR37","doi-asserted-by":"crossref","unstructured":"Spensky, C., Hu, H., Leach, K.: LO-PHI: low-observable physical host instrumentation for malware analysis. In: NDSS (2016)","DOI":"10.14722\/ndss.2016.23121"},{"key":"11_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-642-37300-8_2","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"P Stewin","year":"2013","unstructured":"Stewin, P., Bystrov, I.: Understanding DMA malware. In: Flegel, U., Markatos, E., Robertson, W. (eds.) DIMVA 2012. LNCS, vol. 7591, pp. 21\u201341. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-37300-8_2"},{"key":"11_CR39","unstructured":"Synopsys: embARC (2019). https:\/\/embarc.org\/embarc_osp\/doc\/build\/html\/arc\/arc.html"},{"key":"11_CR40","unstructured":"Tereshkin, A., Wojtczuk, R.: Introducing ring-3 rootkits. Black Hat USA (2009)"},{"key":"11_CR41","unstructured":"The Fedora Project: TBoot (2018). https:\/\/sourceforge.net\/projects\/tboot"},{"key":"11_CR42","unstructured":"UPnP Forum: MeshCommander (2018). http:\/\/www.meshcommander.com\/"},{"key":"11_CR43","doi-asserted-by":"crossref","unstructured":"Wei, J., Payne, B.D., Giffin, J., Pu, C.: Soft-timer driven transient kernel control flow attacks and defense. In: 2008 Annual Computer Security Applications Conference (ACSAC) (2008)","DOI":"10.1109\/ACSAC.2008.40"},{"key":"11_CR44","unstructured":"Wojtczuk, R., Rutkowska, J.: Attacking SMM memory via Intel CPU cache poisoning. Invisible Things Lab (2009)"},{"key":"11_CR45","unstructured":"Yao, J.: SMM Protection in EDK II (2017). https:\/\/uefi.org\/sites\/default\/files\/resources\/Jiewen"},{"key":"11_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, F., Leach, K., Stavrou, A., Wang, H., Sun, K.: Using hardware features for increased debugging transparency. In: 2015 IEEE Symposium on Security and Privacy (SP) (2015)","DOI":"10.1109\/SP.2015.11"},{"key":"11_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-319-11203-9_13","volume-title":"Computer Security - ESORICS 2014","author":"F Zhang","year":"2014","unstructured":"Zhang, F., Wang, H., Leach, K., Stavrou, A.: A framework to secure peripherals at runtime. In: Kuty\u0142owski, M., Vaidya, J. (eds.) ESORICS 2014. LNCS, vol. 8712, pp. 219\u2013238. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11203-9_13"},{"issue":"4","key":"11_CR48","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1109\/TDSC.2013.53","volume":"11","author":"Fengwei Zhang","year":"2014","unstructured":"Zhang, F., Wang, J., Sun, K., Stavrou, A.: Hypercheck: A hardware-assistedintegrity monitor (2014)","journal-title":"IEEE Transactions on Dependable and Secure Computing"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2019"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-29962-0_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,15]],"date-time":"2024-09-15T00:11:58Z","timestamp":1726359118000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-29962-0_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030299613","9783030299620"],"references-count":48,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-29962-0_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"15 September 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Luxembourg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Luxembourg","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 September 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 September 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.laas.fr\/esorics\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"344","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"67","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3,2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"11","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}