{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T14:41:38Z","timestamp":1743086498455,"version":"3.40.3"},"publisher-location":"Cham","reference-count":52,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319112022"},{"type":"electronic","value":"9783319112039"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-11203-9_13","type":"book-chapter","created":{"date-parts":[[2014,8,14]],"date-time":"2014-08-14T16:36:46Z","timestamp":1408034206000},"page":"219-238","source":"Crossref","is-referenced-by-count":19,"title":["A Framework to Secure Peripherals at Runtime"],"prefix":"10.1007","author":[{"given":"Fengwei","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haining","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kevin","family":"Leach","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos","family":"Stavrou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"13_CR1","unstructured":"National Institute of Standards, NIST: National Vulnerability Database, \n                  \n                    http:\/\/nvd.nist.gov\n                  \n                  \n                 (access time March 4, 2014)"},{"key":"13_CR2","unstructured":"Mitre: Vulnerability list, \n                  \n                    http:\/\/cve.mitre.org\/cve\/cve.html"},{"key":"13_CR3","unstructured":"Bonkoski, A.J., Bielawski, R., Halderman, J.A.: Illuminating the Security Issues Surrounding Lights-out Server Management. In: Proceedings of the 7th USENIX Conference on Offensive Technologies (WOOT 2013) (2013)"},{"key":"13_CR4","unstructured":"Duflot, L., Perez, Y.A.: Can You Still Trust Your Network Card? In: Proceedings of the 13th CanSecWest Conference (CanSecWest 2010) (2010)"},{"key":"13_CR5","unstructured":"Chen, K.: Reversing and Exploiting an Apple Firmware Update. Black Hat (2009)"},{"key":"13_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-642-37300-8_2","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"P. Stewin","year":"2013","unstructured":"Stewin, P., Bystrov, I.: Understanding DMA Malware. In: Flegel, U., Markatos, E., Robertson, W. (eds.) DIMVA 2012. LNCS, vol.\u00a07591, pp. 21\u201341. Springer, Heidelberg (2013)"},{"key":"13_CR7","unstructured":"Aumaitre, D., Devine, C.: Subverting Windows 7 x64 Kernel With DMA Attacks. In: HITBSecConf Amsterdam (2010)"},{"key":"13_CR8","unstructured":"Triulzi, A.: Project Maux Mk.II. In: CanSecWest (2008)"},{"key":"13_CR9","doi-asserted-by":"crossref","unstructured":"Sang, F., Nicomette, V., Deswarte, Y.: I\/O Attacks in Intel PC-based Architectures and Countermeasures. In: SysSec Workshop (SysSec 2011) (2011)","DOI":"10.1109\/SysSec.2011.10"},{"key":"13_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-41284-4_1","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"P. Stewin","year":"2013","unstructured":"Stewin, P.: A Primitive for Revealing Stealthy Peripheral-Based Attacks on the Computing Platform\u2019s Main Memory. In: Stolfo, S.J., Stavrou, A., Wright, C.V. (eds.) RAID 2013. LNCS, vol.\u00a08145, pp. 1\u201320. Springer, Heidelberg (2013)"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"Sang, F., Lacombe, E., Nicomette, V., Deswarte, Y.: Exploiting an I\/OMMU vulnerability. In: 5th International Conference on Malicious and Unwanted Software (MALWARE 2010), pp. 7\u201314 (2010)","DOI":"10.1109\/MALWARE.2010.5665798"},{"key":"13_CR12","unstructured":"Wojtczuk, R., Rutkowska, J.: Another Way to Circumvent Intel\u00ae Trusted Execution Technology (2009), \n                  \n                    http:\/\/invisiblethingslab.com\/resources\/misc09\/Another"},{"key":"13_CR13","unstructured":"Wojtczuk, R., Rutkowska, J.: Following the White Rabbit: Software Attacks against Intel\u00ae VT-d (2011)"},{"key":"13_CR14","unstructured":"Trusted Computing Group: TCG PC Client Specific Implementation Specification for Conventional BIOS (February 2012), \n                  \n                    http:\/\/www.trustedcomputinggroup.org\/files\/resource_files\/CB0B2BFA-1A4B-B294-D0C3B9075B5AFF17\/TCG_PCClientImplementation_1-21_1_00.pdf"},{"key":"13_CR15","unstructured":"Trusted Computing Group: TPM Main Specification Level 2 Version 1.2, Revision 116 (2011), \n                  \n                    http:\/\/www.trustedcomputinggroup.org\/resources\/tpm_main_specification"},{"key":"13_CR16","unstructured":"Trusted Computing Group: TCG D-RTM Architecture Document Version 1.0.0 (June 2013), \n                  \n                    http:\/\/www.trustedcomputinggroup.org\/resources\/drtm_architecture_specification"},{"key":"13_CR17","unstructured":"Intel: Trusted Execution Technology, \n                  \n                    http:\/\/www.intel.com\/content\/www\/us\/en\/trusted-execution-technology\/trusted-execution-technology-security-paper.html"},{"key":"13_CR18","doi-asserted-by":"crossref","unstructured":"McCune, J., Parno, B., Perrig, A., Reiter, M., Isozaki, H.: Flicker: An Execution Infrastructure for TCB Minimization. In: Proceedings of the 3rd ACM SIGOPS\/EuroSys European Conference on Computer Systems (2008)","DOI":"10.1145\/1352592.1352625"},{"key":"13_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"378","DOI":"10.1007\/978-3-642-23644-0_20","volume-title":"Recent Advances in Intrusion Detection","author":"L. Duflot","year":"2011","unstructured":"Duflot, L., Perez, Y.-A., Morin, B.: What If You Can\u2019t Trust Your Network Card? In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol.\u00a06961, pp. 378\u2013397. Springer, Heidelberg (2011)"},{"key":"13_CR20","doi-asserted-by":"crossref","unstructured":"Li, Y., McCune, J., Perrig, A.: VIPER: Verifying the Integrity of PERipherals\u2019 Firmware. In: Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS 2011) (2011)","DOI":"10.1145\/2046707.2046711"},{"key":"13_CR21","doi-asserted-by":"crossref","unstructured":"Moon, H., Lee, H., Lee, J., Kim, K., Paek, Y., Kang, B.: Vigilare: Toward Snoop-based Kernel Integrity Monitor. In: Proceedings of the 19th ACM Conference on Computer and Communications Security (CCS 2012) (2012)","DOI":"10.1145\/2382196.2382202"},{"key":"13_CR22","doi-asserted-by":"crossref","unstructured":"Wang, J., Sun, K., Stavrou, A.: A Dependability Analysis of Hardware-Assisted Polling Integrity Checking Systems. In: Proceedings of the 42nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN 2012) (2012)","DOI":"10.1109\/DSN.2012.6263962"},{"key":"13_CR23","doi-asserted-by":"crossref","unstructured":"Zaddach, J., Kurmus, A., Balzarotti, D., Blass, E.O., Francillon, A., Goodspeed, T., Gupta, M., Koltsidas, I.: Implementation and Implications of a Stealth Hard-Drive Backdoor. In: Proceedings of the 29th Annual Computer Security Applications Conference (ACSAC 2013) (2013)","DOI":"10.1145\/2523649.2523661"},{"key":"13_CR24","unstructured":"Triulzi, A.: The Jedi Packet Trick Takes Over the Deathstar: Taking NIC Backdoors to the Next Level. In: The 12th Annual CanSecWest Conference (2010)"},{"key":"13_CR25","doi-asserted-by":"crossref","unstructured":"Butterworth, J., Kallenberg, C., Kovah, X.: BIOS Chronomancy: Fixing the Core Root of Trust for Measurement. In: Proceedings of the 20th ACM Conference on Computer and Communications Security (CCS 2013) (2013)","DOI":"10.1145\/2508859.2516714"},{"key":"13_CR26","unstructured":"Coreboot: Open-Source BIOS, \n                  \n                    http:\/\/www.coreboot.org\/"},{"key":"13_CR27","unstructured":"VIA: VT8237R Southbridge, \n                  \n                    http:\/\/www.via.com.tw\/"},{"key":"13_CR28","unstructured":"Broadcom Corporation: Broadcom NetXtreme Gigabit Ethernet Controller, \n                  \n                    http:\/\/www.broadcom.com\/products\/BCM5751"},{"key":"13_CR29","unstructured":"Salihun, D.: BIOS Disassembly Ninjutsu Uncovered, \n                  \n                    http:\/\/bioshacking.blogspot.com\/2012\/02\/bios-disassembly-ninjutsu-uncovered-1st.html"},{"key":"13_CR30","unstructured":"Salihun, D.: Malicious Code Execution in PCI Expansion ROM (June 2012), \n                  \n                    http:\/\/resources.infosecinstitute.com\/pci-expansion-rom\/"},{"key":"13_CR31","unstructured":"Flashrom: Firmware flash utility, \n                  \n                    http:\/\/www.flashrom.org\/"},{"key":"13_CR32","unstructured":"Advanced Micro Devices, Inc.: BIOS and Kernel Developer\u2019s Guide for AMD Athlon 64 and AMD Opteron Processors"},{"key":"13_CR33","unstructured":"William, H., Teukolsky, S.A., Vetterling, W.T., Flannery, B.P.: Numerical Recipes: The Art of Scientific Computing. Cambridge University Press, New York (2007)"},{"key":"13_CR34","unstructured":"MD5 Hash Functions, \n                  \n                    http:\/\/en.wikipedia.org\/wiki\/MD5"},{"key":"13_CR35","unstructured":"Intel: 82574 Gigabit Ethernet Controller Family: Datasheet, \n                  \n                    http:\/\/www.intel.com\/content\/www\/us\/en\/ethernet-controllers\/82574l-gbe-controller-datasheet.html"},{"key":"13_CR36","unstructured":"Jeff: RWEverything Tool, \n                  \n                    http:\/\/rweverything.com\/"},{"key":"13_CR37","unstructured":"SuperPI, \n                  \n                    http:\/\/www.superpi.net\/"},{"key":"13_CR38","unstructured":"Advanced Micro Devices, Inc.: AMD K8 Architecture, \n                  \n                    http:\/\/commons.wikimedia.org\/wiki\/File:AMD_K8.PNG"},{"key":"13_CR39","unstructured":"Wojtczuk, R., Rutkowska, J.: Attacking Intel Trust Execution Technologies (2009), \n                  \n                    http:\/\/invisiblethingslab.com\/resources\/bh09dc\/Attacking"},{"key":"13_CR40","unstructured":"Wojtczuk, R., Rutkowska, J.: Attacking Intel TXT via SINIT Code Execution Hijacking (November 2011), \n                  \n                    http:\/\/www.invisiblethingslab.com\/resources\/2011\/Attacking_Intel_TXT_via_SINIT_hijacking.pdf"},{"key":"13_CR41","doi-asserted-by":"crossref","unstructured":"Azab, A.M., Ning, P., Zhang, X.: SICE: A Hardware-level Strongly Isolated Computing Environment for x86 Multi-core Platforms. In: Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS 2011) (2011)","DOI":"10.1145\/2046707.2046752"},{"key":"13_CR42","unstructured":"Wojtczuk, R., Rutkowska, J.: Attacking SMM Memory via Intel CPU Cache Poisoning (2009)"},{"key":"13_CR43","unstructured":"Duflot, L., Levillain, O., Morin, B., Grumelard, O.: Getting into the SMRAM: SMM Reloaded. In: Proceedings of the 12th CanSecWest Conference (CanSecWest 2009) (2009)"},{"key":"13_CR44","unstructured":"Intel: Intel\u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual"},{"key":"13_CR45","doi-asserted-by":"crossref","unstructured":"Sang, F.L., Nicomette, V., Deswarte, Y.: A Tool to Analyze Potential I\/O Attacks Against PCs. IEEE Security & Privacy (2013)","DOI":"10.1109\/MSP.2013.79"},{"key":"13_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, F., Wang, J., Sun, K., Stavrou, A.: HyperCheck: A Hardware-assisted Integrity Monitor. IEEE Transactions on Dependable and Secure Computing (2013)","DOI":"10.21236\/ADA589948"},{"key":"13_CR47","doi-asserted-by":"crossref","unstructured":"Azab, A.M., Ning, P., Wang, Z., Jiang, X., Zhang, X., Skalsky, N.C.: HyperSentry: Enabling Stealthy In-Context Measurement of Hypervisor Integrity. In: Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS 2010) (2010)","DOI":"10.1145\/1866307.1866313"},{"key":"13_CR48","doi-asserted-by":"crossref","unstructured":"Reina, A., Fattori, A., Pagani, A., Cavallaro, L., Bruschi, D.: When Hardware Meets Software: A Bulletproof Solution to Forensic Memory Acquisition. In: Proceedings of the Annual Computer Security Applications Conference (ACSAC 2012) (2012)","DOI":"10.1145\/2420950.2420962"},{"key":"13_CR49","doi-asserted-by":"crossref","unstructured":"Zhang, F., Leach, K., Sun, K., Stavrou, A.: SPECTRE: A Dependable Introspection Framework via System Management Mode. In: Proceedings of the 43rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN 2013) (2013)","DOI":"10.1109\/DSN.2013.6575343"},{"key":"13_CR50","unstructured":"Zhang, Y., Pan, W., Wang, Q., Bai, K., Yu, M.: HypeBIOS: Enforcing VM Isolation with Minimized and Decomposed Cloud TCB. Technical report, Virginia Commonwealth University (2012)"},{"key":"13_CR51","doi-asserted-by":"crossref","unstructured":"Embleton, S., Sparks, S., Zou, C.: SMM rootkits: A New Breed of OS Independent Malware. In: Proceedings of the 4th International Conference on Security and Privacy in Communication Networks (SecureComm 2008) (2008)","DOI":"10.1145\/1460877.1460892"},{"key":"13_CR52","unstructured":"PCI-SIG: PCI Local Bus Specification Revision 3.0, \n                  \n                    http:\/\/www.pcisig.com\/specifications\/"}],"container-title":["Lecture Notes in Computer Science","Computer Security - ESORICS 2014"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-11203-9_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,22]],"date-time":"2019-09-22T20:08:55Z","timestamp":1569182935000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-11203-9_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319112022","9783319112039"],"references-count":52,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-11203-9_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}