{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T20:22:27Z","timestamp":1740169347076,"version":"3.37.3"},"reference-count":78,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"JST(Japan Science and Technology Agency) CREST(Core Research for Evolutionary Science and Technology) program","award":["JPMJCR21M3"],"award-info":[{"award-number":["JPMJCR21M3"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/access.2024.3366344","type":"journal-article","created":{"date-parts":[[2024,2,14]],"date-time":"2024-02-14T18:54:04Z","timestamp":1707936844000},"page":"26536-26549","source":"Crossref","is-referenced-by-count":1,"title":["TEE-PA: TEE Is a Cornerstone for Remote Provenance Auditing on Edge Devices With Semi-TCB"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-5026-7380","authenticated-orcid":false,"given":"Taichi","family":"Takemura","sequence":"first","affiliation":[{"name":"Cybozu Inc., Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5504-6004","authenticated-orcid":false,"given":"Ryo","family":"Yamamoto","sequence":"additional","affiliation":[{"name":"Department of Informatics, Graduate School of Informatics and Engineering, The University of Electro-Communications (UEC), Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0912-0087","authenticated-orcid":false,"given":"Kuniyasu","family":"Suzaki","sequence":"additional","affiliation":[{"name":"Institute of Information Security (IISEC), Yokohama, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"volume-title":"Azure IoT Edge Security Manager","year":"2022","key":"ref1"},{"volume-title":"AWS IoT Core","year":"2022","key":"ref2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326083"},{"volume-title":"fireELF","year":"2022","key":"ref4"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00080"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3209355"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICFTSC57269.2022.10040044"},{"key":"ref8","first-page":"3505","article-title":"The circle of life: A large-scale study of the IoT malware lifecycle","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Security)","author":"Alrawi"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35170-9_6"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"key":"ref11","first-page":"319","article-title":"Trustworthy whole-system provenance for the Linux kernel","volume-title":"Proc. 24th USENIX Secur. Symp.","author":"Bates"},{"key":"ref12","first-page":"487","article-title":"SLEUTH: Real-time attack scenario reconstruction from COTS audit data","volume-title":"Proc. 26th USENIX Secur. Symp.","author":"Hossain"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23254"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24167"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329857"},{"volume-title":"Alert (TA13-207A) Risks of Using the Intelligent Platform Management Interface (IPMI)","year":"2016","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053034"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24065"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93524-9_5"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2991431"},{"key":"ref21","first-page":"223","article-title":"Design and implementation of a TCG-based integrity measurement architecture","volume-title":"Proc. 13th USENIX Secur. Symp.","author":"Sailer"},{"key":"ref22","first-page":"91","article-title":"Trusted computing and Linux","volume-title":"Proc. Linux Symp.","author":"Hall"},{"volume-title":"OP-TEE","year":"2022","key":"ref23"},{"article-title":"Securing emerging IoT systems through systematic analysis and design","year":"2020","author":"Wang","key":"ref24"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23227"},{"key":"ref26","first-page":"549","article-title":"ARMageddon: Cache attacks on mobile devices","volume-title":"Proc. 25th USENIX Secur. Symp.","author":"Lipp"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2019.2910861"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3291047"},{"volume-title":"OP-TEE Build","year":"2022","key":"ref29"},{"volume-title":"LKRG","year":"2022","key":"ref30"},{"volume-title":"LKRG-Concepts","year":"2022","key":"ref31"},{"key":"ref32","first-page":"1","article-title":"High accuracy attack provenance via binary-based execution partition","volume-title":"Proc. Symp. Netw. Distrib. Syst. Secur. Symp. (NDSS)","author":"Lee"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24046"},{"volume-title":"Understanding Linux Audit","year":"2022","key":"ref34"},{"volume-title":"Event Tracing for Windows IoT Core","year":"2022","key":"ref35"},{"key":"ref36","first-page":"43","article-title":"Provenance-aware storage systems","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Muniswamy-Reddy"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2015.2489211"},{"key":"ref38","first-page":"241","article-title":"Kernel-supported cost-effective audit logging for causality tracking","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Ma"},{"volume-title":"Intel Software Guard Extensions","year":"2022","key":"ref39"},{"volume-title":"Strengthening VM isolation with integrity protection and more","year":"2020","author":"Sev-Snp","key":"ref40"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"volume-title":"An Open Framework for Architecting Trusted Execution Environments","year":"2022","key":"ref42"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241161"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23068"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516758"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.38"},{"volume-title":"GlobalPlatform TEE Internal Core API Specification v1.3","year":"2022","key":"ref47"},{"volume-title":"GlobalPlatform TEE Client API Specification v1.0","year":"2022","key":"ref48"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180418"},{"key":"ref50","first-page":"1","article-title":"Sprobes: Enforcing kernel code integrity on the Trustzone architecture","volume-title":"Proc. Mobile Secur. Technol. (MoST)","author":"Ge"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23189"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00021"},{"key":"ref54","first-page":"191","article-title":"A virtual machine introspection based architecture for intrusion detection","volume-title":"Proc. Symp. Netw. Distrib. Syst. Secur. (NDSS)","author":"Garfinkel"},{"key":"ref55","first-page":"1","article-title":"AntFarm: Tracking processes in a virtual machine environment","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Jones"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664252"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/2775111"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417862"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00084"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427293"},{"volume-title":"Efficient System Auditing for Real-Time Systems","year":"2021","author":"Kandikuppa","key":"ref61"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-34992-9_15"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833604"},{"article-title":"Effectiveness of Linux rootkit detection tools","year":"2020","author":"Junnila","key":"ref64"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-70852-8_1"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60753-5_19"},{"volume-title":"Paramiko","year":"2022","author":"Forcier","key":"ref67"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384727"},{"volume-title":"Lightaidra","year":"2022","author":"Kirsche","key":"ref69"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241275"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/ISGTEurope.2017.8260283"},{"key":"ref72","first-page":"68","article-title":"Threat modeling-uncover security design flaws using the STRIDE approach","author":"Hernan","year":"2006","journal-title":"MSDN Mag."},{"volume-title":"Arm\u2019s Platform Security Architecture (PSA) Attestation Token","year":"2022","key":"ref73"},{"key":"ref74","first-page":"443","article-title":"Confine: Automated system call policy generation for container attack surface reduction","volume-title":"Proc. 23rd Int. Symp. Res. Attacks, Intrusions Defenses (RAID)","author":"Ghavamnia"},{"key":"ref75","first-page":"1749","article-title":"Temporal system call specialization for attack surface reduction","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Ghavamnia"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2901318.2901341"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3474123.3486762"},{"volume-title":"Chestnut","year":"2022","key":"ref78"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10380310\/10436677.pdf?arnumber=10436677","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,1]],"date-time":"2024-03-01T00:43:55Z","timestamp":1709253835000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10436677\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":78,"URL":"https:\/\/doi.org\/10.1109\/access.2024.3366344","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2024]]}}}