{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T15:36:19Z","timestamp":1777649779847,"version":"3.51.4"},"reference-count":19,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T00:00:00Z","timestamp":1768348800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T00:00:00Z","timestamp":1768348800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea (NRF)","doi-asserted-by":"publisher","award":["RS-2023-NR077166"],"award-info":[{"award-number":["RS-2023-NR077166"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100014188","name":"Korean government (MSIT)","doi-asserted-by":"publisher","award":["RS-2023-00227165"],"award-info":[{"award-number":["RS-2023-00227165"]}],"id":[{"id":"10.13039\/501100014188","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,1,14]]},"DOI":"10.1109\/icoin68469.2026.11480507","type":"proceedings-article","created":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T19:45:18Z","timestamp":1777405518000},"page":"965-970","source":"Crossref","is-referenced-by-count":0,"title":["Empirical Study on BMC Firmware Vulnerabilities: Root Causes and Architectural Insights"],"prefix":"10.1109","author":[{"given":"Jihye","family":"Lee","sequence":"first","affiliation":[{"name":"Korea University,Seoul,Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chanhee","family":"Park","sequence":"additional","affiliation":[{"name":"Korea University,Seoul,Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Youngjoo","family":"Shin","sequence":"additional","affiliation":[{"name":"Korea University,Seoul,Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICET61945.2024.10673073"},{"key":"ref2","article-title":"Illuminating the security issues surrounding Lights-Out server management","volume-title":"USENIX Workshop on Offensive Technologies","author":"Bonkoski","year":"2013"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.18178\/wcse.2024.06.050"},{"key":"ref4","volume-title":"Common vulnerabilities and exposures"},{"key":"ref5","volume-title":"Dgx h100\/h200 user guide: Redfish apis support"},{"key":"ref6","volume-title":"Redfish: a more secure alternative to ipmi"},{"key":"ref7","volume-title":"Supermicro server management (redfish\u00ae api)"},{"key":"ref8","volume-title":"Cwe view: Research concepts"},{"key":"ref9","volume-title":"Harden baseboard management controllers","year":"2023"},{"key":"ref10","author":"Gueye","year":"2021","journal-title":"A historical and statistical study of the software vulnerability landscape"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.5120\/ijca2021921718"},{"key":"ref12","first-page":"1508","article-title":"Some analysis of common vulnerabilities and exposures (cve) data from the national vulnerability database (nvd)","volume-title":"Proceedings of the Conference on Information Systems Applied Research","author":"Glyder"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-70881-8_4"},{"key":"ref14","author":"Sheik","year":"2025","journal-title":"Cyber threat observatory for national identity systems quarterly report: Drawing insights from vulnerability patterns in digital identity, government, healthcare, and finance sectors"},{"key":"ref15","volume-title":"Ipmi: Freight train to hell or linda wu & the night of the leeches","author":"Farmer"},{"key":"ref16","volume-title":"Subvert server bmc: How to replace your server\u2019s brain","author":"Gazet"},{"key":"ref17","volume-title":"idrackar, integrated dell remote access controller\u2019s kind approach to the ram","author":"Iooss"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23057"},{"key":"ref19","article-title":"Digging for dark ipmi devices: Advancing bmc detection and evaluating operational security","volume-title":"Traffic Measurement and Analysis Conference","author":"Gasser"}],"event":{"name":"2026 40th International Conference on Information Networking (ICOIN)","location":"Hanoi, Vietnam","start":{"date-parts":[[2026,1,14]]},"end":{"date-parts":[[2026,1,16]]}},"container-title":["2026 40th International Conference on Information Networking (ICOIN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11480424\/11480459\/11480507.pdf?arnumber=11480507","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T06:46:07Z","timestamp":1777445167000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11480507\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,14]]},"references-count":19,"URL":"https:\/\/doi.org\/10.1109\/icoin68469.2026.11480507","relation":{},"subject":[],"published":{"date-parts":[[2026,1,14]]}}}