{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T01:43:36Z","timestamp":1743039816812,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":32,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642238215"},{"type":"electronic","value":"9783642238222"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-23822-2_13","type":"book-chapter","created":{"date-parts":[[2011,9,7]],"date-time":"2011-09-07T14:38:34Z","timestamp":1315406314000},"page":"227-244","source":"Crossref","is-referenced-by-count":8,"title":["DriverGuard: A Fine-Grained Protection on I\/O Flows"],"prefix":"10.1007","author":[{"given":"Yueqiang","family":"Cheng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuhua","family":"Ding","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert H.","family":"Deng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"13_CR1","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1145\/1346281.1346286","volume-title":"ASPLOS XIII: Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems","author":"R. Bhargava","year":"2008","unstructured":"Bhargava, R., Serebrin, B., Spadini, F., Manne, S.: Accelerating two-dimensional page walks for virtualized systems. In: ASPLOS XIII: Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems, pp. 26\u201335. ACM, New York (2008)"},{"key":"13_CR2","first-page":"27","volume-title":"Proceedings of CCS 2008","author":"E. Buchanan","year":"2008","unstructured":"Buchanan, E., Roemer, R., Shacham, H., Savage, S.: When good instructions go bad: Generalizing return-oriented programming to RISC. In: Syverson, P., Jha, S. (eds.) Proceedings of CCS 2008, pp. 27\u201338. ACM Press, New York (2008)"},{"key":"13_CR3","first-page":"559","volume-title":"Proceedings of CCS 2010","author":"S. Checkoway","year":"2010","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A.R., Shacham, H., Winandy, M.: Return-oriented programming without returns. In: Keromytis, A., Shmatikov, V. (eds.) Proceedings of CCS 2010, pp. 559\u2013572. ACM Press, New York (2010)"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Chen, X., Garfinkel, T., Lewis, E.C., Subrahmanyam, P., Waldspurger, C.A., Boneh, D., Dwoskin, J., Ports, D.R.K.: Overshadow: A virtualization-based approach to retrofitting protection in commodity operating systems. In: Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 2008), Seattle, WA, USA (March 2008)","DOI":"10.1145\/1346281.1346284"},{"key":"13_CR5","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1145\/502034.502042","volume-title":"Proceedings of the Eighteenth ACM Symposium on Operating Systems Principles, SOSP 2001","author":"A. Chou","year":"2001","unstructured":"Chou, A., Yang, J., Chelf, B., Hallem, S., Engler, D.: An empirical study of operating systems errors. In: Proceedings of the Eighteenth ACM Symposium on Operating Systems Principles, SOSP 2001, pp. 73\u201388. ACM, New York (2001), http:\/\/doi.acm.org\/10.1145\/502034.502042"},{"key":"13_CR6","unstructured":"Gadgetweb.de: How to: Building your own kernel space keylogger (2010), http:\/\/www.gadgetweb.de\/programming\/39-how-to-building-your-own-kernel-space-keylogger.html"},{"key":"13_CR7","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1145\/1346281.1346303","volume-title":"Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS XIII","author":"V. Ganapathy","year":"2008","unstructured":"Ganapathy, V., Renzelmann, M.J., Balakrishnan, A., Swift, M.M., Jha, S.: The design and implementation of microdrivers. In: Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS XIII, pp. 168\u2013178. ACM, New York (2008), http:\/\/doi.acm.org\/10.1145\/1346281.1346303"},{"key":"13_CR8","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1145\/945445.945464","volume-title":"Proceedings of the 9th ACM Symposium on Operating Systems Principles","author":"T. Garfinkel","year":"2003","unstructured":"Garfinkel, T., Pfaff, B., Chow, J., Rosenblum, M., Boneh, D.: Terra: a virtual machine-based platform for trusted computing. In: Proceedings of the 9th ACM Symposium on Operating Systems Principles, pp. 193\u2013206. ACM, New York (2003)"},{"key":"13_CR9","unstructured":"Trusted\u00a0Computing Group: TPM main specification. Main Specification Version 1.2 rev. 85 (February 2005)"},{"key":"13_CR10","unstructured":"Langweg, H.: Building a trusted path for applications using cots components. In: In Proceedings of NATO RTO IST Panel Symposium on Adaptive Defence in Unclassified Networks (2004)"},{"key":"13_CR11","unstructured":"Lineberry, A.: Malicious code injection via \/dev\/mem. In: Black Hat (March 2009)"},{"key":"13_CR12","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1109\/SP.2010.17","volume-title":"Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010","author":"J.M. McCune","year":"2010","unstructured":"McCune, J.M., Li, Y., Qu, N., Zhou, Z., Datta, A., Gligor, V., Perrig, A.: Trustvisor: Efficient tcb reduction and attestation. In: Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010, pp. 143\u2013158. IEEE Computer Society, Washington, DC, USA (2010), http:\/\/dx.doi.org\/10.1109\/SP.2010.17"},{"key":"13_CR13","doi-asserted-by":"crossref","unstructured":"McCune, J.M., Parno, B., Perrig, A., Reiter, M.K., Isozaki, H.: Flicker: An execution infrastructure for TCB minimization. In: Proceedings of the ACM European Conference in Computer Systems (EuroSys) (April 2008)","DOI":"10.1145\/1352592.1352625"},{"key":"13_CR14","unstructured":"McCune, J.M., Perrig, A., Reiter, M.K.: Safe passage for passwords and other sensitive data. In: Proceedings of the Symposium on Network and Distributed Systems Security (NDSS) (February 2009)"},{"key":"13_CR15","unstructured":"Mercenary: Kernel based keylogger (2002), http:\/\/goo.gl\/7qwmr"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Neugschwandtner, M., Platzer, C., Comparetti, P.M., Bayer, U.: danuis - dynamic device driver analysis based on virtual machine introspection. In: Proceedings of the 7th Detection of Intrusions and Malware & Vulnerability Assessment (2010)","DOI":"10.1007\/978-3-642-14215-4_3"},{"key":"13_CR17","doi-asserted-by":"crossref","unstructured":"Nomoto, T., Oyama, Y., Eiraku, H., Shingawa, T., Kato, K.: Using a hypervisor to migrate running operating systems to secure virtual machines. In: Proceedings of the 34th Annual IEEE Computer Software and Application Conference (2010)","DOI":"10.1109\/COMPSAC.2010.11"},{"key":"13_CR18","doi-asserted-by":"crossref","unstructured":"Onoue, K., Oyama, Y., Yonezawa, A.: Control of system calls from outside of virtual machines. In: Proceedings of Symposium of Applied Computing (2008)","DOI":"10.1145\/1363686.1364196"},{"key":"13_CR19","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1109\/SP.2008.24","volume-title":"Proceedings of the 2008 IEEE Symposium on Security and Privacy","author":"B.D. Payne","year":"2008","unstructured":"Payne, B.D., Carbone, M., Sharif, M., Lee, W.: Lares: An architecture for secure active monitoring using virtualization. In: Proceedings of the 2008 IEEE Symposium on Security and Privacy, pp. 233\u2013247. IEEE Computer Society, Washington, DC, USA (2008), http:\/\/portal.acm.org\/citation.cfm?id=1397759.1398072"},{"key":"13_CR20","unstructured":"Phrack: Writing linux kernel keylogger (2002), http:\/\/www.phrack.org\/issues.html?issue=59"},{"key":"13_CR21","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1145\/1294261.1294294","volume-title":"Proceedings of Twenty-first ACM SIGOPS Symposium on Operating Systems Principles, SOSP 2007","author":"A. Seshadri","year":"2007","unstructured":"Seshadri, A., Luk, M., Qu, N., Perrig, A.: Secvisor: a tiny hypervisor to provide lifetime kernel code integrity for commodity oses. In: Proceedings of Twenty-first ACM SIGOPS Symposium on Operating Systems Principles, SOSP 2007, pp. 335\u2013350. ACM, New York (2007), http:\/\/doi.acm.org\/10.1145\/1294261.1294294"},{"key":"13_CR22","first-page":"552","volume-title":"Proceedings of CCS 2007","author":"H. Shacham","year":"2007","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In: De Capitani di Vimercati, S., Syverson, P. (eds.) Proceedings of CCS 2007, pp. 552\u2013561. ACM Press, New York (2007)"},{"key":"13_CR23","doi-asserted-by":"crossref","unstructured":"Shi, E., Perrig, A., Doorn, L.V.: Bind: A fine-grained attestation service for secure distributed systems. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 154\u2013168 (2005)","DOI":"10.1109\/SP.2005.4"},{"key":"13_CR24","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1145\/1508293.1508311","volume-title":"Proceedings of the 2009 ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE 2009","author":"T. Shinagawa","year":"2009","unstructured":"Shinagawa, T., Eiraku, H., Tanimoto, K., Omote, K., Hasegawa, S., Horie, T., Hirano, M., Kourai, K., Oyama, Y., Kawai, E., Kono, K., Chiba, S., Shinjo, Y., Kato, K.: Bitvisor: a thin hypervisor for enforcing i\/o device security. In: Proceedings of the 2009 ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE 2009, pp. 121\u2013130. ACM, New York (2009), http:\/\/doi.acm.org\/10.1145\/1508293.1508311"},{"key":"13_CR25","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1145\/945445.945466","volume-title":"Proceedings of the Nineteenth ACM Symposium on Operating Systems Principles, SOSP 2003","author":"M.M. Swift","year":"2003","unstructured":"Swift, M.M., Bershad, B.N., Levy, H.M.: Improving the reliability of commodity operating systems. In: Proceedings of the Nineteenth ACM Symposium on Operating Systems Principles, SOSP 2003, pp. 207\u2013222. ACM, New York (2003), http:\/\/doi.acm.org\/10.1145\/945445.945466"},{"key":"13_CR26","unstructured":"Wang, X., Li, Z., Li, N., Choi, J.Y.: PRECIP: Towards practical and retrofittable confidential information protection. In: Proceedings of NDSS (2008)"},{"key":"13_CR27","doi-asserted-by":"crossref","unstructured":"Wang, Z., Jiang, X.: Hypersafe: A lightweight approach to provide lifetime hypervisor control-flow integrity. In: Proceedings of IEEE Symposium on Security and Privacy (2010)","DOI":"10.1109\/SP.2010.30"},{"key":"13_CR28","doi-asserted-by":"crossref","unstructured":"Wang, Z., Jiang, X., Cui, W., Ning, P.: Countering kernel rootkits with lightweight hook protection. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, pp. 545\u2013554 (2009)","DOI":"10.1145\/1653662.1653728"},{"key":"13_CR29","unstructured":"Willmann, P., Rixner, S., Cox, A.L.: Protection strategies for direct access to virtualized i\/o devices. In: Proceedings of USENIX Annual Technical Conference (2008)"},{"key":"13_CR30","doi-asserted-by":"crossref","unstructured":"Willmann, P., Shafer, J., Carr, D., Menon, A., Rixner, S., Cox, A.L., Zwaenepoel, W.: Concurrent direct network access for virtual machine monitors. In: Proceedings of the 13th International Symposium on High Performance Computer Architecture (2007)","DOI":"10.1109\/HPCA.2007.346208"},{"issue":"2","key":"13_CR31","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1145\/1065545.1065546","volume":"8","author":"Z.E. Ye","year":"2005","unstructured":"Ye, Z.E., Smith, S., Anthony, D.: Trusted paths for browsers. ACM Trans. Inf. Syst. Secur.\u00a08(2), 153\u2013186 (2005)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"13_CR32","first-page":"45","volume-title":"Proceedings of the 7th Symposium on Operating Systems Design and Implementation, OSDI 2006","author":"F. Zhou","year":"2006","unstructured":"Zhou, F., Condit, J., Anderson, Z., Bagrak, I., Ennals, R., Harren, M., Necula, G., Brewer, E.: Safedrive: safe and recoverable extensions using language-based techniques. In: Proceedings of the 7th Symposium on Operating Systems Design and Implementation, OSDI 2006, pp. 45\u201360. USENIX Association, Berkeley (2006), http:\/\/portal.acm.org\/citation.cfm?id=1298455.1298461"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2011"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-23822-2_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,9]],"date-time":"2025-03-09T23:20:23Z","timestamp":1741562423000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-23822-2_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642238215","9783642238222"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-23822-2_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}