{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T10:55:16Z","timestamp":1777287316061,"version":"3.51.4"},"reference-count":78,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,2,16]],"date-time":"2024-02-16T00:00:00Z","timestamp":1708041600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,2,16]],"date-time":"2024-02-16T00:00:00Z","timestamp":1708041600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["16KIS1315"],"award-info":[{"award-number":["16KIS1315"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["16KIS1314"],"award-info":[{"award-number":["16KIS1314"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["16KIS1305"],"award-info":[{"award-number":["16KIS1305"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["465958100"],"award-info":[{"award-number":["465958100"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006254","name":"Ruhr-Universit\u00e4t Bochum","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100006254","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des Autom Embed Syst"],"published-print":{"date-parts":[[2024,3]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Large-scale attacks on IoT and edge computing devices pose a significant threat. As a prominent example, Mirai is an IoT botnet with 600,000 infected devices around the globe, capable of conducting effective and targeted DDoS attacks on (critical) infrastructure. Driven by the substantial impacts of attacks, manufacturers and system integrators propose Trusted Execution Environments (TEEs) that have gained significant importance recently. TEEs offer an execution environment to run small portions of code isolated from the rest of the system, even if the operating system is compromised. In this publication, we examine TEEs in the context of system monitoring and introduce the Trusted Monitor (TM), a novel anomaly detection system that runs within a TEE. The TM continuously profiles the system using hardware performance counters and utilizes an application-specific machine-learning model for anomaly detection. In our evaluation, we demonstrate that the TM accurately classifies 86% of 183 tested workloads, with an overhead of less than 2%. Notably, we show that a real-world kernel-level rootkit has observable effects on performance counters, allowing the TM to detect it. Major parts of the TM are implemented in the Rust programming language, eliminating common security-critical programming errors.<\/jats:p>","DOI":"10.1007\/s10617-024-09283-1","type":"journal-article","created":{"date-parts":[[2024,2,16]],"date-time":"2024-02-16T10:02:33Z","timestamp":1708077753000},"page":"23-44","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Profiling with trust: system monitoring from trusted execution environments"],"prefix":"10.1007","volume":"28","author":[{"given":"Christian","family":"Eichler","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonas","family":"R\u00f6ckl","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benedikt","family":"Jung","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ralph","family":"Schlenk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tilo","family":"M\u00fcller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Timo","family":"H\u00f6nig","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,2,16]]},"reference":[{"key":"9283_CR1","unstructured":"Cisco (2020) Annual internet report. https:\/\/www.cisco.com\/c\/en\/us\/solutions\/collateral\/executive-perspectives\/annual-internet-report\/white-paper-c11-741490.html. Accessed 16 June 2021"},{"key":"9283_CR2","unstructured":"Transforma Insights (2022) Number of IoT connected devices worldwide 2019\u20132021, with forecasts to 2030. https:\/\/www.statista.com\/statistics\/1183457\/iot-connected-devices-worldwide\/. Accessed 16 June 2023"},{"key":"9283_CR3","unstructured":"McAfee Labs threats report (2021). https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-quarterly-threats-apr-2021.pdf. Accessed 17 June 2021"},{"key":"9283_CR4","unstructured":"CVE-2021-3156 (2021). https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-3156. Accessed 16 June 2021"},{"key":"9283_CR5","unstructured":"Antonakakis M et al (2017) Understanding the Mirai botnet. In: Proceedings of the 26th USENIX security symposium (USENIX Security \u201917), pp 1093\u20131110. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/antonakakis"},{"key":"9283_CR6","unstructured":"Edwards S, Profetis I (2016) Hajime: analysis of a decentralized internet worm for IoT devices. https:\/\/www.cs.umd.edu\/class\/spring2021\/cmsc614\/papers\/hajime-rapidity.pdf. Accessed 4 Dec 2022"},{"key":"9283_CR7","doi-asserted-by":"publisher","unstructured":"Azab A, Ning P, Sezer E, Zhang X (2009) HIMA: a hypervisor-based integrity measurement agent. In: Proceedings of the 2009 annual computer security applications conference (ACSAC \u201909), pp 461\u2013470. https:\/\/doi.org\/10.1109\/ACSAC.2009.50","DOI":"10.1109\/ACSAC.2009.50"},{"key":"9283_CR8","doi-asserted-by":"publisher","unstructured":"Seshadri A, Luk M, Qu N, Perrig A (2007) SecVisor: a tiny hypervisor to provide lifetime kernel code integrity for commodity OSes. In: Proceedings of the 21st ACM symposium on operating systems principles (SOSP \u201907), pp 335\u2013350. https:\/\/doi.org\/10.1145\/1294261.1294294","DOI":"10.1145\/1294261.1294294"},{"key":"9283_CR9","doi-asserted-by":"publisher","unstructured":"Sharif MI, Lee W, Cui W, Lanzi A (2009) Secure in-VM monitoring using hardware virtualization. In: Proceedings of the 16th ACM conference on computer and communications security (CCS \u201909), pp 477\u2013487. https:\/\/doi.org\/10.1145\/1653662.1653720","DOI":"10.1145\/1653662.1653720"},{"key":"9283_CR10","unstructured":"Garfinkel T, Rosenblum M (2003) A virtual machine introspection based architecture for intrusion detection. In: Proceedings of the network and distributed system security symposium (NDSS \u201903). https:\/\/www.ndss-symposium.org\/ndss2003\/virtual-machine-introspection-based-architecture-intrusion-detection\/"},{"key":"9283_CR11","doi-asserted-by":"crossref","unstructured":"Dunlap GW, King ST, Cinar S, Basrai MA, Chen PM (2002) ReVirt: enabling intrusion analysis through virtual-machine logging and replay. In: Proceedings of the 5th symposium on operating system design and implementation (OSDI \u201902). http:\/\/www.usenix.org\/events\/osdi02\/tech\/dunlap.html","DOI":"10.1145\/1060289.1060309"},{"key":"9283_CR12","unstructured":"Kol M, Oberman S (2020) Ripple20. https:\/\/www.jsof-tech.com\/wp-content\/uploads\/2020\/06\/JSOF_Ripple20_Technical_Whitepaper_June20.pdf. Accessed 21 Apr 2023"},{"key":"9283_CR13","unstructured":"Forescout Research Labs (2020) How TCP\/IP Stacks Breed Critical Vulnerabilities in IoT, OT and IT Devices. https:\/\/www.forescout.com\/company\/resources\/amnesia33-how-tcp-ip-stacks-breed-critical-vulnerabilities-in-iot-ot-and-it-devices\/. Accessed 21 Apr 2023"},{"key":"9283_CR14","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2775111","volume":"48","author":"E Bauman","year":"2015","unstructured":"Bauman E, Ayoade G, Lin Z (2015) A survey on hypervisor-based monitoring: approaches, applications, and evolutions. ACM Comput Surv CSUR 48:1\u201333. https:\/\/doi.org\/10.1145\/2775111","journal-title":"ACM Comput Surv CSUR"},{"key":"9283_CR15","doi-asserted-by":"publisher","unstructured":"Chen X et al (2008) Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems. In: Proceedings of the 13th international conference on architectural support for programming languages and operating systems (ASPLOS \u201908), pp 2\u201313. https:\/\/doi.org\/10.1145\/1346281.1346284","DOI":"10.1145\/1346281.1346284"},{"key":"9283_CR16","doi-asserted-by":"publisher","unstructured":"Wang X, Karri R (2013) NumChecker: detecting kernel control-flow modifying rootkits by using hardware performance counters. In: Proceedings of the 50th annual design automation conference 2013 (DAC \u201913), pp 79:1\u201379:7. https:\/\/doi.org\/10.1145\/2463209.2488831","DOI":"10.1145\/2463209.2488831"},{"key":"9283_CR17","doi-asserted-by":"publisher","unstructured":"Guan L et al (2017) TrustShadow: secure execution of unmodified applications with ARM TrustZone. In: Proceedings of the 15th annual international conference on mobile systems, applications, and services (MobiSys \u201917), pp 488\u2013501. https:\/\/doi.org\/10.1145\/3081333.3081349","DOI":"10.1145\/3081333.3081349"},{"key":"9283_CR18","doi-asserted-by":"publisher","unstructured":"Azab AM et al (2014) Hypervision across worlds: real-time kernel protection from the ARM TrustZone secure world. In: Proceedings of the 2014 ACM SIGSAC conference on computer and communications security (CCS \u201914). https:\/\/doi.org\/10.1145\/2660267.2660350","DOI":"10.1145\/2660267.2660350"},{"key":"9283_CR19","doi-asserted-by":"publisher","unstructured":"Sun H, Sun K, Wang Y, Jing J, Jajodia S (2014) TrustDump: reliable memory acquisition on smartphones. In: Proceedings of the 19th European symposium on research in computer security (ESORICS \u201914). https:\/\/doi.org\/10.1007\/978-3-319-11203-9_12","DOI":"10.1007\/978-3-319-11203-9_12"},{"key":"9283_CR20","doi-asserted-by":"publisher","unstructured":"Busch M, Schlenk R, Heckel H (2019) TEEMo: trusted peripheral monitoring for optical networks and beyond. In: Proceedings of the 4th workshop on system software for trusted execution (SysTEX\u201919), pp 7:1\u20137:6. https:\/\/doi.org\/10.1145\/3342559.3365339","DOI":"10.1145\/3342559.3365339"},{"key":"9283_CR21","doi-asserted-by":"publisher","unstructured":"Nakano T, Kourai K (2021) Secure offloading of intrusion detection systems from VMs with Intel SGX. In: Proceedings of the 14th IEEE international conference on cloud computing (CLOUD \u201921), pp 297\u2013303. https:\/\/doi.org\/10.1109\/CLOUD53861.2021.00043","DOI":"10.1109\/CLOUD53861.2021.00043"},{"key":"9283_CR22","unstructured":"Kuvaiskii D, Chakrabarti S, Vij M (2018) Snort intrusion detection system with Intel Software Guard Extension (Intel SGX). arXiv:1802.00508"},{"key":"9283_CR23","doi-asserted-by":"publisher","unstructured":"Shih M, Kumar M, Kim T, Gavrilovska A (2016) S-NFV: securing NFV states by using SGX. In: Proceedings of the ACM international workshop on security in software defined networks & network function virtualization (SDN-NFV \u201916), pp 45\u201348. https:\/\/doi.org\/10.1145\/2876019.2876032","DOI":"10.1145\/2876019.2876032"},{"key":"9283_CR24","unstructured":"Intel (2022) 12th generation Intel Core processors datasheet. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/processors\/core\/core-technical-resources.html. Accessed 22 June 2022"},{"key":"9283_CR25","unstructured":"ARM Limited (2021) ARM\u2019s solution to the future needs of AI, security and specialized computing is v9. https:\/\/www.arm.com\/company\/news\/2021\/03\/arms-answer-to-the-future-of-ai-armv9-architecture. Accessed 22 June 2022"},{"key":"9283_CR26","doi-asserted-by":"publisher","unstructured":"Lee D, Kohlbrenner D, Shinde S, Asanovi\u0107 K, Song D (2020) Keystone: an open framework for architecting trusted execution environments. In: Proceedings of the 15th European conference on computer systems (EuroSys \u201920). https:\/\/doi.org\/10.1145\/3342195.3387532","DOI":"10.1145\/3342195.3387532"},{"key":"9283_CR27","doi-asserted-by":"publisher","unstructured":"Mohassel P, Rosulek M, Trieu N (2020) Practical privacy-preserving K-means clustering. In: Proceedings of the privacy enhancing technologies (PoPETs \u201920), pp 414\u2013433. https:\/\/doi.org\/10.2478\/popets-2020-0080","DOI":"10.2478\/popets-2020-0080"},{"key":"9283_CR28","unstructured":"Corrigan-Gibbs H, Boneh D (2017) Prio: private, robust, and scalable computation of aggregate statistics. In: Proceedings of the 14th USENIX symposium on networked systems design and implementation (NSDI \u201917), pp 259\u2013282. https:\/\/www.usenix.org\/conference\/nsdi17\/technical-sessions\/presentation\/corrigan-gibbs"},{"key":"9283_CR29","unstructured":"Hunt T, Song C, Shokri R, Shmatikov V, Witchel E (2018) Chiron: privacy-preserving machine learning as a service. arXiv preprint arXiv:1803.05961"},{"key":"9283_CR30","doi-asserted-by":"publisher","unstructured":"Melis L, Song C, De\u00a0Cristofaro E, Shmatikov V (2019) Exploiting unintended feature leakage in collaborative learning. In: Proceedings of the 40th IEEE symposium on security and privacy (S &P \u201919), pp 691\u2013706. https:\/\/doi.org\/10.1109\/SP.2019.00029","DOI":"10.1109\/SP.2019.00029"},{"key":"9283_CR31","unstructured":"Ohrimenko O et al (2016) Oblivious multi-party machine learning on trusted processors. In: Proceedings of the 25th USENIX security symposium (USENIX security \u201916), pp 619\u2013636. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/ohrimenko"},{"key":"9283_CR32","doi-asserted-by":"publisher","unstructured":"Kumar N et al (2020) CrypTFlow: secure TensorFlow inference. In: Proceedings of the 41st IEEE symposium on security and privacy (S &P \u201920), pp 336\u2013353. https:\/\/doi.org\/10.1109\/SP40000.2020.00092","DOI":"10.1109\/SP40000.2020.00092"},{"key":"9283_CR33","doi-asserted-by":"publisher","unstructured":"Bayerl SP et al (2020) Offline model guard: secure and private ML on mobile devices. In: Proceedings of the 2020 design, automation & test in Europe conference & exhibition (DATE \u201920), pp 460\u2013465. https:\/\/doi.org\/10.23919\/DATE48585.2020.9116560","DOI":"10.23919\/DATE48585.2020.9116560"},{"key":"9283_CR34","doi-asserted-by":"publisher","unstructured":"Xia Y, Liu Y, Chen H, Zang B (2012) CFIMon: detecting violation of control flow integrity using performance counters. In: IEEE\/IFIP international conference on dependable systems and networks (DSN \u201912), pp 1\u201312. https:\/\/doi.org\/10.1109\/DSN.2012.6263958","DOI":"10.1109\/DSN.2012.6263958"},{"key":"9283_CR35","doi-asserted-by":"publisher","unstructured":"Yuan L, Xing W, Chen H, Zang B (2011) Security breaches as PMU deviation: detecting and identifying security attacks using performance counters. In: Proceedings of the Asia Pacific workshop on systems (APSys \u201911), pp 1\u20135. https:\/\/doi.org\/10.1145\/2103799.2103807","DOI":"10.1145\/2103799.2103807"},{"key":"9283_CR36","doi-asserted-by":"publisher","unstructured":"Aweke ZB et al (2016) ANVIL: software-based protection against next-generation row hammer attacks. In: Proceedings of the ACM conference on architectural support for programming languages and operating systems (ASPLOS \u201916), pp 743\u2013755. https:\/\/doi.org\/10.1145\/2872362.2872390","DOI":"10.1145\/2872362.2872390"},{"key":"9283_CR37","doi-asserted-by":"publisher","unstructured":"Demme J et al (2013) On the feasibility of online malware detection with performance counters. In: Proceedings of the 40th annual international symposium on computer architecture (ISCA \u201913), pp 559\u2013570. https:\/\/doi.org\/10.1145\/2485922.2485970","DOI":"10.1145\/2485922.2485970"},{"key":"9283_CR38","doi-asserted-by":"publisher","unstructured":"Tang A, Sethumadhavan S, Stolfo SJ (2014) Unsupervised anomaly-based malware detection using hardware features. In: Proceedings of the 17th international symposium on research in attacks, intrusions and defenses (RAID \u201914), pp 109\u2013129. https:\/\/doi.org\/10.1007\/978-3-319-11379-1_6","DOI":"10.1007\/978-3-319-11379-1_6"},{"key":"9283_CR39","doi-asserted-by":"publisher","unstructured":"Bahador MB, Abadi M, Tajoddin A (2014) HPCMalHunter: behavioral malware detection using hardware performance counters and singular value decomposition. In: 4th international conference on computer and knowledge engineering (ICCKE \u201914), pp 703\u2013708. https:\/\/doi.org\/10.1109\/ICCKE.2014.6993402","DOI":"10.1109\/ICCKE.2014.6993402"},{"key":"9283_CR40","doi-asserted-by":"publisher","unstructured":"Singh B, Evtyushkin D, Elwell J, Riley R, Cervesato I (2017) On the detection of kernel-level rootkits using hardware performance counters. In: Proceedings of the ACM Asia conference on computer and communications security (AsiaCCS \u201917), pp 483\u2013493. https:\/\/doi.org\/10.1145\/3052973.3052999","DOI":"10.1145\/3052973.3052999"},{"key":"9283_CR41","doi-asserted-by":"publisher","first-page":"4952","DOI":"10.1109\/TCAD.2022.3149745","volume":"41","author":"AP Kuruvila","year":"2022","unstructured":"Kuruvila AP, Meng X, Kundu S, Pandey G, Basu K (2022) Explainable machine learning for intrusion detection via hardware performance counters. IEEE Trans Comput Aided Des Integr Circuits Syst 41:4952\u20134964. https:\/\/doi.org\/10.1109\/TCAD.2022.3149745","journal-title":"IEEE Trans Comput Aided Des Integr Circuits Syst"},{"key":"9283_CR42","doi-asserted-by":"publisher","unstructured":"Mushtaq M et al (2018) NIGHTs-WATCH: a cache-based side-channel intrusion detector using hardware performance counters. In: Proceedings of the 7th international workshop on hardware and architectural support for security and privacy (HASP \u201918), pp 1:1\u20131:8. https:\/\/doi.org\/10.1145\/3214292.3214293","DOI":"10.1145\/3214292.3214293"},{"key":"9283_CR43","doi-asserted-by":"publisher","first-page":"1320","DOI":"10.1109\/TC.2021.3082471","volume":"71","author":"C Li","year":"2022","unstructured":"Li C, Gaudiot J (2022) Detecting Spectre attacks using hardware performance counters. IEEE Trans Comput 71:1320\u20131331. https:\/\/doi.org\/10.1109\/TC.2021.3082471","journal-title":"IEEE Trans Comput"},{"key":"9283_CR44","doi-asserted-by":"publisher","unstructured":"Zhang Y, Makris Y (2020) Hardware-based detection of spectre attacks: a machine learning approach. In: Proceedings of the Asian hardware oriented security and trust symposium (AsianHOST \u201920), pp 1\u20136. https:\/\/doi.org\/10.1109\/AsianHOST51057.2020.9358255","DOI":"10.1109\/AsianHOST51057.2020.9358255"},{"key":"9283_CR45","doi-asserted-by":"publisher","unstructured":"Zhou B, Gupta A, Jahanshahi R, Egele M, Joshi A (2018) Hardware performance counters can detect malware: myth or fact? In: Proceedings of the Asia conference on computer and communications security (AsiaCCS \u201918), pp 457\u2013468. https:\/\/doi.org\/10.1145\/3196494.3196515","DOI":"10.1145\/3196494.3196515"},{"key":"9283_CR46","doi-asserted-by":"publisher","unstructured":"Das S, Werner J, Antonakakis M, Polychronakis M, Monrose F (2019) SoK: the challenges, pitfalls, and perils of using hardware performance counters for security. In: 2019 IEEE symposium on security and privacy (S &P \u201919), pp 20\u201338. https:\/\/doi.org\/10.1109\/SP.2019.00021","DOI":"10.1109\/SP.2019.00021"},{"key":"9283_CR47","doi-asserted-by":"publisher","unstructured":"Levy A et\u00a0al (2017) The case for writing a kernel in rust. In: Proceedings of the 8th Asia-Pacific workshop on systems (APSys \u201917), pp 1:1\u20131:7. https:\/\/doi.org\/10.1145\/3124680.3124717","DOI":"10.1145\/3124680.3124717"},{"key":"9283_CR48","doi-asserted-by":"publisher","unstructured":"Levy AA et\u00a0al (2015) Ownership is theft: experiences building an embedded OS in rust. In: Proceedings of the 8th workshop on programming languages and operating systems (PLOS \u201915), pp 21\u201326. https:\/\/doi.org\/10.1145\/2818302.2818306","DOI":"10.1145\/2818302.2818306"},{"key":"9283_CR49","doi-asserted-by":"publisher","unstructured":"Levy A et\u00a0al (2017) Multiprogramming a 64kB computer safely and efficiently. In: Proceedings of the 26th symposium on operating systems principles (SOSP \u201917), pp 234\u2013251. https:\/\/doi.org\/10.1145\/3132747.3132786","DOI":"10.1145\/3132747.3132786"},{"key":"9283_CR50","doi-asserted-by":"publisher","unstructured":"Cerdeira D, Santos N, Fonseca P, Pinto S (2020) SoK: understanding the prevailing security vulnerabilities in TrustZone-assisted TEE systems. In: Proceedings of the 41st IEEE symposium on security and privacy (S &P \u201920), pp 1416\u20131432. https:\/\/doi.org\/10.1109\/SP40000.2020.00061","DOI":"10.1109\/SP40000.2020.00061"},{"key":"9283_CR51","unstructured":"Evenchick E (2018) RustZone: writing trusted applications in rust. https:\/\/github.com\/ericevenchick\/rustzone. Accessed 23 May 2021"},{"key":"9283_CR52","doi-asserted-by":"publisher","unstructured":"Wan S, Sun M, Sun K, Zhang N, He X (2020) RusTEE: developing memory-safe ARM TrustZone applications. In: Proceedings of the 2020 annual computer security applications conference (ACSAC \u201920), pp 442\u2013453. https:\/\/doi.org\/10.1145\/3427228.3427262","DOI":"10.1145\/3427228.3427262"},{"key":"9283_CR53","doi-asserted-by":"crossref","unstructured":"Wang H et al (2019) Towards memory safe enclave programming with Rust-SGX. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security (ACM CCS\u201919), pp 2333\u20132350. http:\/\/dx.doi.org\/10.1145\/3319535.3354241","DOI":"10.1145\/3319535.3354241"},{"key":"9283_CR54","unstructured":"Fortanix (2019) Enclave development platform. https:\/\/edp.fortanix.com. Accessed 23 May 2021"},{"key":"9283_CR55","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1016\/j.icte.2020.04.005","volume":"6","author":"Q Ngo","year":"2020","unstructured":"Ngo Q, Nguyen H, Le V, Nguyen D (2020) A survey of IoT malware and detection methods based on static features. Inf Commun Technol ICT Express 6:280\u2013286. https:\/\/doi.org\/10.1016\/j.icte.2020.04.005","journal-title":"Inf Commun Technol ICT Express"},{"key":"9283_CR56","doi-asserted-by":"publisher","unstructured":"Zhang N, Sun K, Shands D, Lou W, Hou YT (2018) TruSense: information leakage from trustzone. In: Proceedings of the 2018 IEEE conference on computer communications (INFOCOM \u201918), pp 1097\u20131105. https:\/\/doi.org\/10.1109\/INFOCOM.2018.8486293","DOI":"10.1109\/INFOCOM.2018.8486293"},{"key":"9283_CR57","doi-asserted-by":"publisher","unstructured":"Dhodapkar AS, Smith JE (2003) Comparing program phase detection techniques. In: Proceedings of the 36th annual IEEE\/ACM international symposium on microarchitecture (MICRO-36), pp 217\u2013227. https:\/\/doi.org\/10.1109\/MICRO.2003.1253197","DOI":"10.1109\/MICRO.2003.1253197"},{"key":"9283_CR58","first-page":"1","volume":"7","author":"G Hamerly","year":"2005","unstructured":"Hamerly G, Perelman E, Lau J, Calder B (2005) Simpoint 3.0: faster and more flexible program phase analysis. J Instr Level Parallelism 7:1\u201328","journal-title":"J Instr Level Parallelism"},{"key":"9283_CR59","doi-asserted-by":"publisher","first-page":"4962","DOI":"10.1109\/TITS.2020.2984197","volume":"22","author":"R Ke","year":"2021","unstructured":"Ke R, Zhuang Y, Pu Z, Wang Y (2021) A smart, efficient, and reliable parking surveillance system with edge artificial intelligence on IoT devices. IEEE Trans Intell Transp Syst 22:4962\u20134974. https:\/\/doi.org\/10.1109\/TITS.2020.2984197","journal-title":"IEEE Trans Intell Transp Syst"},{"key":"9283_CR60","doi-asserted-by":"publisher","unstructured":"Ling X, Sheng J, Baiocchi O, Liu X, Tolentino ME (2017) Identifying parking spaces & detecting occupancy using vision-based IoT devices. In: Proceedings of the 2017 global internet of things summit (GIoTS \u201917), pp 1\u20136. https:\/\/doi.org\/10.1109\/GIOTS.2017.8016227","DOI":"10.1109\/GIOTS.2017.8016227"},{"key":"9283_CR61","unstructured":"DPDK Project\u2014Linux Foundation, LLC (2023) About DPDK. https:\/\/www.dpdk.org\/about\/. Accessed 3 June 2023"},{"key":"9283_CR62","unstructured":"Abadi M et al (2015) TensorFlow: large-scale machine learning on heterogeneous systems. https:\/\/www.tensorflow.org\/. Accessed 14 May 2021"},{"key":"9283_CR63","unstructured":"TensorFlow Developers (2021) TensorFlow lite. https:\/\/www.tensorflow.org\/lite\/guide. Accessed 22 May 2021"},{"key":"9283_CR64","doi-asserted-by":"crossref","unstructured":"ARM Limited (2021) Trusted firmware-A. https:\/\/github.com\/ARM-software\/arm-trusted-firmware. Accessed 1 Dec 2021","DOI":"10.1155\/2021\/4664882"},{"key":"9283_CR65","unstructured":"TrustedFirmware.org (2020) OP-TEE documentation. https:\/\/optee.readthedocs.io\/en\/latest\/general\/about.html. Accessed 27 Apr 2021"},{"key":"9283_CR66","doi-asserted-by":"publisher","unstructured":"Xu M et al (2019) Dominance as a new trusted computing primitive for the internet of things. In: Proceedings of the 40th IEEE symposium on security and privacy (S &P \u201919), pp 1415\u20131430. https:\/\/doi.org\/10.1109\/SP.2019.00084","DOI":"10.1109\/SP.2019.00084"},{"key":"9283_CR67","doi-asserted-by":"publisher","unstructured":"Huber M, Hristozov S, Ott S, Sarafov V, Peinado M (2020) The Lazarus effect: healing compromised devices in the internet of small things. In: Proceedings of the 15th ACM Asia conference on computer and communications security (AsiaCCS \u201920), pp 6\u201319. https:\/\/doi.org\/10.1145\/3320269.3384723","DOI":"10.1145\/3320269.3384723"},{"key":"9283_CR68","doi-asserted-by":"publisher","unstructured":"Suzaki K, Tsukamoto A, Green A, Mannan M (2020) Reboot-oriented IoT: life cycle management in trusted execution environment for disposable IoT devices. In: Proceedings of the 2020 annual computer security applications conference (ACSAC \u201920), pp 428\u2013441. https:\/\/doi.org\/10.1145\/3427228.3427293","DOI":"10.1145\/3427228.3427293"},{"key":"9283_CR69","doi-asserted-by":"publisher","unstructured":"R\u00f6ckl J, Protsenko M, Huber M, M\u00fcller T, Freiling FC (2021) Advanced system resiliency based on virtualization techniques for IoT devices. In: Proceedings of the 2021 annual computer security applications conference (ACSAC \u201921), pp 455\u2013467. https:\/\/doi.org\/10.1145\/3485832.3485836","DOI":"10.1145\/3485832.3485836"},{"key":"9283_CR70","unstructured":"ARM Limited (2020) Armv8-A architecture registers: PMUSERENR-EL0. https:\/\/developer.arm.com\/documentation\/ddi0595\/2020-12\/AArch64-Registers\/PMUSERENR-EL0--Performance-Monitors-User-Enable-Register. Accessed 2021-06-22"},{"key":"9283_CR71","unstructured":"Ning Z, Zhang F (2017) Ninja: towards transparent tracing and debugging on ARM. In: Proceedings of the 26th USENIX security symposium (USENIX Security \u201917), pp 33\u201349. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/ning"},{"key":"9283_CR72","unstructured":"ARM Limited (2022) Armv8-A architecture registers: MDCR_EL3. https:\/\/developer.arm.com\/documentation\/ddi0601\/2022-03\/AArch64-Registers\/MDCR-EL3-Monitor-Debug-Configuration-Register--EL3-?lang=en. Accessed 22 May 2023"},{"key":"9283_CR73","doi-asserted-by":"publisher","first-page":"130:1","DOI":"10.1145\/3291047","volume":"51","author":"S Pinto","year":"2019","unstructured":"Pinto S, Santos N (2019) Demystifying Arm TrustZone: a comprehensive survey. ACM Comput Surv 51:130:1-130:36. https:\/\/doi.org\/10.1145\/3291047","journal-title":"ACM Comput Surv"},{"key":"9283_CR74","unstructured":"Cerdeira D, Martins J, Santos N, Pinto S (2022) Rezone: disarming TrustZone with TEE privilege reduction. In: Proceedings of the 31st USENIX security symposium (USENIX security \u201922), pp 2261\u20132279. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/cerdeira"},{"key":"9283_CR75","unstructured":"Boundary Devices (2023) Nitrogen8M. https:\/\/boundarydevices.com\/product\/nitrogen8m\/. Accessed 3 June 2023"},{"key":"9283_CR76","unstructured":"Canonical Ltd (2017) stress-ng\u2014a tool to load and stress a computer system. https:\/\/manpages.ubuntu.com\/manpages\/artful\/man1\/stress-ng.1.html. Accessed 26 May 2021"},{"key":"9283_CR77","unstructured":"Arm Limited (2016) ARM Cortex-A72 MPCore processor. https:\/\/developer.arm.com\/documentation\/100095\/0003\/. Accessed 12 Apr 2021"},{"key":"9283_CR78","unstructured":"m0nad (2021) Diamorphine. https:\/\/github.com\/m0nad\/Diamorphine. Accessed 26 May 2021"}],"container-title":["Design Automation for Embedded Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10617-024-09283-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10617-024-09283-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10617-024-09283-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,16]],"date-time":"2024-05-16T11:06:19Z","timestamp":1715857579000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10617-024-09283-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2,16]]},"references-count":78,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,3]]}},"alternative-id":["9283"],"URL":"https:\/\/doi.org\/10.1007\/s10617-024-09283-1","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-3169665\/v1","asserted-by":"object"}]},"ISSN":["0929-5585","1572-8080"],"issn-type":[{"value":"0929-5585","type":"print"},{"value":"1572-8080","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,2,16]]},"assertion":[{"value":"14 July 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 January 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 February 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}