{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,22]],"date-time":"2025-05-22T05:50:40Z","timestamp":1747893040914,"version":"3.40.3"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031355035"},{"type":"electronic","value":"9783031355042"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-35504-2_12","type":"book-chapter","created":{"date-parts":[[2023,6,9]],"date-time":"2023-06-09T08:01:47Z","timestamp":1686297707000},"page":"235-255","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["CEFI: Command Execution Flow Integrity for\u00a0Embedded Devices"],"prefix":"10.1007","author":[{"given":"Anni","family":"Peng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dongliang","family":"Fang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erik","family":"van der Kouwe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yin","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuqing","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,6,10]]},"reference":[{"key":"12_CR1","doi-asserted-by":"crossref","unstructured":"Abera, T., et al.: C-flat: control-flow attestation for embedded systems software. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 743\u2013754 (2016)","DOI":"10.1145\/2976749.2978358"},{"key":"12_CR2","doi-asserted-by":"crossref","unstructured":"Almakhdhub, N.S., Clements, A.A., Bagchi, S., Payer, M.: $$\\mu $$rai: securing embedded systems with return address integrity. In: 27th Annual Network and Distributed System Security Symposium, NDSS 2020, San Diego, California, USA, February 23\u201326 (2020)","DOI":"10.14722\/ndss.2020.24016"},{"key":"12_CR3","unstructured":"ARM Ltd.: Arm compiler software development guide version 6.3 (2022). https:\/\/developer.arm.com\/documentation\/dui0773\/d\/chunkpge1447084556319"},{"key":"12_CR4","unstructured":"Ball, T., Larus, J.R.: Efficient path profiling. In: MICRO 29, pp. 46\u201357. IEEE (1996)"},{"key":"12_CR5","doi-asserted-by":"crossref","unstructured":"Bond, M.D., McKinley, K.S.: Probabilistic calling context. ACM SIPLAN Notices 42(10), 97\u2013112 (2007)","DOI":"10.1145\/1297105.1297035"},{"key":"12_CR6","doi-asserted-by":"crossref","unstructured":"Cerdeira, D., Santos, N., Fonseca, P., Pinto, S.: SoK: understanding the prevailing security vulnerabilities in trustzone-assisted tee systems. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 1416\u20131432. IEEE (2020)","DOI":"10.1109\/SP40000.2020.00061"},{"key":"12_CR7","unstructured":"Clements, A.A., Almakhdhub, N.S., Bagchi, S., Payer, M.: Aces: Automatic compartments for embedded systems. In: USENIX Security 2018, vol. 2018, pp. 65\u201382 (2018)"},{"key":"12_CR8","unstructured":"Feng, B., Mera, A., Lu, L.: P2IM: scalable and hardware-independent firmware testing via automatic peripheral interface modeling. In: USENIX Security 2020, pp. 1237\u20131254 (2020)"},{"key":"12_CR9","unstructured":"Feng, H.H., Kolesnikov, O.M., Fogla, P., Lee, W., Gong, W.: Anomaly detection using call stack information. In: 2003 Symposium on Security and Privacy, 2003, pp. 62\u201375. IEEE (2003)"},{"key":"12_CR10","unstructured":"Gustafson, E., et al.: Toward the analysis of embedded firmware through automated re-hosting. In: RAID 2019, pp. 135\u2013150 (2019)"},{"key":"12_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"577","DOI":"10.1007\/978-3-319-24177-7_29","volume-title":"Computer Security \u2013 ESORICS 2015","author":"B Hassanshahi","year":"2015","unstructured":"Hassanshahi, B., Jia, Y., Yap, R.H.C., Saxena, P., Liang, Z.: Web-to-application injection attacks on android: characterization and detection. In: Pernul, G., Ryan, P.Y.A., Weippl, E. (eds.) ESORICS 2015. LNCS, vol. 9327, pp. 577\u2013598. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-24177-7_29"},{"key":"12_CR12","doi-asserted-by":"crossref","unstructured":"Hassanshahi, B., Yap, R.H.C.: Android database attacks revisited. In: AsiaCCS 2017, pp. 625\u2013639 (2017)","DOI":"10.1145\/3052973.3052994"},{"key":"12_CR13","doi-asserted-by":"crossref","unstructured":"Hu, H., Shinde, S., Adrian, S., Chua, Z.L., Saxena, P., Liang, Z.: Data-oriented programming: on the expressiveness of non-control data attacks. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 969\u2013986. IEEE (2016)","DOI":"10.1109\/SP.2016.62"},{"key":"12_CR14","doi-asserted-by":"crossref","unstructured":"Huo, D., Cao, C., Liu, P., Wang, Y., Li, M., Xu, Z.: Commercial hypervisor-based task sandboxing mechanisms are unsecured? but we can fix it! J. Syst. Architect. 116, 102114 (2021)","DOI":"10.1016\/j.sysarc.2021.102114"},{"key":"12_CR15","doi-asserted-by":"crossref","unstructured":"Jia, Y., et al.: Burglars\u2019 IoT paradise: understanding and mitigating security risks of general messaging protocols on IoT clouds. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 465\u2013481. IEEE (2020)","DOI":"10.1109\/SP40000.2020.00051"},{"key":"12_CR16","doi-asserted-by":"crossref","unstructured":"Koeberl, P., Schulz, S., Sadeghi, A.R., Varadharajan, V.: TrustLite: a security architecture for tiny embedded devices. In: Proceedings of the Ninth European Conference on Computer Systems, pp. 1\u201314 (2014)","DOI":"10.1145\/2592798.2592824"},{"key":"12_CR17","doi-asserted-by":"crossref","unstructured":"Mishra, T., Chantem, T., Gerdes, R.: Survey of control-flow integrity techniques for embedded and real-time embedded systems. arXiv preprint arXiv:2111.11390 (2021)","DOI":"10.1145\/3538275"},{"key":"12_CR18","unstructured":"Newsome, J., Brumley, D., Song, D., Chamcham, J., Kovah, X.: Vulnerability-specific execution filtering for exploit prevention on commodity software. In: NDSS (2006)"},{"key":"12_CR19","doi-asserted-by":"crossref","unstructured":"Novark, G., Berger, E.D., Zorn, B.G.: Exterminator: automatically correcting memory errors with high probability. In: PLDI, pp. 1\u201311 (2007)","DOI":"10.1145\/1273442.1250736"},{"key":"12_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-3-319-66332-6_12","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"T Nyman","year":"2017","unstructured":"Nyman, T., Ekberg, J.-E., Davi, L., Asokan, N.: CFI CaRE: hardware-supported call and\u00a0return enforcement for commercial microcontrollers. In: Dacier, M., Bailey, M., Polychronakis, M., Antonakakis, M. (eds.) RAID 2017. LNCS, vol. 10453, pp. 259\u2013284. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-66332-6_12"},{"key":"12_CR21","doi-asserted-by":"crossref","unstructured":"OConnor, T., Enck, W., Reaves, B.: Blinded and confused: uncovering systemic flaws in device telemetry for smart-home internet of things. In: Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks, pp. 140\u2013150 (2019)","DOI":"10.1145\/3317549.3319724"},{"key":"12_CR22","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y., Wang, R., Hauser, C., Kruegel, C., Vigna, G.: Firmalice-automatic detection of authentication bypass vulnerabilities in binary firmware. In: NDSS, vol. 1, p. 1 (2015)","DOI":"10.14722\/ndss.2015.23294"},{"issue":"5","key":"12_CR23","doi-asserted-by":"publisher","first-page":"1160","DOI":"10.1109\/TSE.2011.70","volume":"38","author":"WN Sumner","year":"2011","unstructured":"Sumner, W.N., Zheng, Y., Weeratunge, D., Zhang, X.: Precise calling context encoding. IEEE Trans. Software Eng. 38(5), 1160\u20131177 (2011)","journal-title":"IEEE Trans. Software Eng."},{"key":"12_CR24","doi-asserted-by":"crossref","unstructured":"Sun, Z., Feng, B., Lu, L., Jha, S.: OAT: attesting operation integrity of embedded devices. In: SP, pp. 1433\u20131449. IEEE (2020)","DOI":"10.1109\/SP40000.2020.00042"},{"key":"12_CR25","doi-asserted-by":"crossref","unstructured":"Szekeres, L., Payer, M., Wei, T., Song, D.: SoK: eternal war in memory. In: 2013 IEEE Symposium on Security and Privacy, pp. 48\u201362. IEEE (2013)","DOI":"10.1109\/SP.2013.13"},{"key":"12_CR26","unstructured":"Tian, Y., et al.: Smartauth: User-centered authorization for the internet of things. In: USENIX Security 2017, pp. 2\u20138 (2017)"},{"key":"12_CR27","doi-asserted-by":"crossref","unstructured":"Van der Veen, V., et al.: Practical context-sensitive CFI. In: CCS, pp. 927\u2013940 (2015)","DOI":"10.1145\/2810103.2813673"},{"key":"12_CR28","doi-asserted-by":"crossref","unstructured":"Wagner, D., Dean, R.: Intrusion detection via static analysis. In: Proceedings 2001 IEEE Symposium on Security and Privacy. S &P 2001, pp. 156\u2013168. IEEE (2000)","DOI":"10.1109\/SECPRI.2001.924296"},{"key":"12_CR29","doi-asserted-by":"crossref","unstructured":"Xu, J., Ning, P., Kil, C., Zhai, Y., Bookholt, C.: Automatic diagnosis and response to memory corruption vulnerabilities. In: CCS, pp. 223\u2013234 (2005)","DOI":"10.1145\/1102120.1102151"},{"key":"12_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"638","DOI":"10.1007\/978-3-030-29959-0_31","volume-title":"Computer Security \u2013 ESORICS 2019","author":"Y Yao","year":"2019","unstructured":"Yao, Y., Zhou, W., Jia, Y., Zhu, L., Liu, P., Zhang, Y.: Identifying privilege separation vulnerabilities in IoT firmware with symbolic execution. In: Sako, K., Schneider, S., Ryan, P.Y.A. (eds.) ESORICS 2019. LNCS, vol. 11735, pp. 638\u2013657. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-29959-0_31"},{"key":"12_CR31","unstructured":"Yuan, B., et al.: Shattered chain of trust: understanding security risks in cross-cloud iot access delegation. In: USENIX Security 2020, pp. 1183\u20131200 (2020)"},{"key":"12_CR32","doi-asserted-by":"crossref","unstructured":"Zeng, Q., Rhee, J., Zhang, H., Arora, N., Jiang, G., Liu, P.: DeltaPath: precise and scalable calling context encoding. In: Proceedings of Annual IEEE\/ACM International Symposium on Code Generation and Optimization, pp. 109\u2013119 (2014)","DOI":"10.1145\/2581122.2544150"},{"key":"12_CR33","doi-asserted-by":"crossref","unstructured":"Zeng, Q., Zhao, M., Liu, P.: Heaptherapy: an efficient end-to-end solution against heap buffer overflows. In: DSN 2015, pp. 485\u2013496. IEEE (2015)","DOI":"10.1109\/DSN.2015.54"},{"key":"12_CR34","unstructured":"Zhou, J., Du, Y., Shen, Z., Ma, L., Criswell, J., Walls, R.J.: Silhouette: efficient protected shadow stacks for embedded systems. In: USENIX, pp. 1219\u20131236 (2020)"},{"issue":"14","key":"12_CR35","doi-asserted-by":"publisher","first-page":"11621","DOI":"10.1109\/JIOT.2021.3059457","volume":"8","author":"W Zhou","year":"2021","unstructured":"Zhou, W., et al.: Reviewing IoT security via logic bugs in IoT platforms and systems. IEEE Internet Things J. 8(14), 11621\u201311639 (2021)","journal-title":"IEEE Internet Things J."},{"key":"12_CR36","unstructured":"Zhou, W., et al.: Discovering and understanding the security hazards in the interactions between IoT devices, mobile apps, and clouds on smart home platforms. In: USENIX, pp. 1133\u20131150 (2019)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-35504-2_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T00:30:26Z","timestamp":1729557026000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-35504-2_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031355035","9783031355042"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-35504-2_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"10 June 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hamburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 July 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva2023.de\/org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"hotcrp.com","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"43","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"12","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}