{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T03:21:02Z","timestamp":1785381662494,"version":"3.55.0"},"reference-count":81,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179314","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"3279-3295","source":"Crossref","is-referenced-by-count":7,"title":["QueryX: Symbolic Query on Decompiled Code for Finding Bugs in COTS Binaries"],"prefix":"10.1109","author":[{"given":"HyungSeok","family":"Han","sequence":"first","affiliation":[{"name":"Theori Inc."}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"JeongOh","family":"Kyea","sequence":"additional","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yonghwi","family":"Jin","sequence":"additional","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinoh","family":"Kang","sequence":"additional","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brian","family":"Pak","sequence":"additional","affiliation":[{"name":"KAIST"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Insu","family":"Yun","sequence":"additional","affiliation":[{"name":"Theori Inc."}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2002.1004368"},{"key":"ref2","article-title":"Effective static analysis of concurrency use-after-free bugs in linux device drivers","volume-title":"Proceedings of the 2019 USENIX Annual Technical Conference (ATC)","author":"Bai"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2660193.2660200"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606558"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872364"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.68"},{"key":"ref7","article-title":"Sys: A static\/symbolic tool for finding good bugs in good (browser) code","volume-title":"Proceedings of the 29th USENIX Security Symposium (Security)","author":"Brown"},{"key":"ref8","article-title":"Sys: A static\/symbolic tool for finding good bugs in good (browser) code","author":"Brown","year":"2020"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22110-1_37"},{"key":"ref10","article-title":"KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs","volume-title":"Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Cadar"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.31"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451152"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3314221.3314601"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3385964"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2016.43"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3338112"},{"key":"ref17","article-title":"How to get Vex-IR for an entire function?","author":"Dutcher","year":"2018"},{"key":"ref18","article-title":"Kernel address space layout randomization","author":"Edge","year":"2013"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.21236\/ada419626"},{"key":"ref20","article-title":"Coda: An end-to-end neural program decompiler","volume-title":"Proceedings of the 2019 Advances in Neural Information Processing Systems","author":"Fu"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23326"},{"key":"ref22","volume-title":"CodeQL","year":"2006"},{"key":"ref23","article-title":"Automated whitebox fuzz testing","volume-title":"Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS)","author":"Godefroid"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/512529.512539"},{"key":"ref25","article-title":"Dowser: a guided fuzzer to find buffer overflow vulnerabilities","volume-title":"Proceedings of the 22th USENIX Security Symposium (Security)","author":"Haller"},{"key":"ref26","article-title":"Precise and scalable detection of use-after-compacting-garbage-collection bugs","volume-title":"Proceedings of the 30th USENIX Security Symposium (Security)","author":"Han"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2015.7054197"},{"key":"ref28","volume-title":"IDA Pro - Hex Rays","year":"2022"},{"key":"ref29","volume-title":"Esprima","author":"Hidayat","year":"2011"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065016"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2019.23051"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330222"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/2837614.2837674"},{"key":"ref34","article-title":"Towards neural decompilation","author":"Katz","year":"2019"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115648"},{"key":"ref36","article-title":"Finding software bugs with the clang static analyzer","author":"Kremenek","year":"2008"},{"key":"ref37","author":"K\u0159oustek","year":"2017","journal-title":"Retdec: An open-source machine-code decompiler"},{"key":"ref38","article-title":"Statically detecting likely buffer overflow vulnerabilities","volume-title":"Proceedings of the 10th USENIX Security Symposium (Security)","author":"Larochelle"},{"key":"ref39","article-title":"Coccinelle: 10 years of automated evolution in the linux kernel","volume-title":"Proceedings of the 2018 USENIX Annual Technical Conference (ATC)","author":"Lawall"},{"key":"ref40","article-title":"Detecting missing-check bugs via semantic- and context-aware criticalness and constraints inferences","volume-title":"Proceedings of the 28th USENIX Security Symposium (Security)","author":"Lu"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3497764"},{"key":"ref43","volume-title":"Windows kernel elevation of privilege vulnerability, CVE-2021-31979","year":"2021"},{"key":"ref44","volume-title":"LOBYTE macro","year":"2022"},{"key":"ref45","volume-title":"CVE-2019-1477","year":"2019"},{"key":"ref46","volume-title":"CVE-2020-1081","year":"2020"},{"key":"ref47","volume-title":"CVE-2021-31979","year":"2021"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78800-3_24"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"ref50","volume-title":"Ghidra","year":"2019"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417256"},{"key":"ref52","article-title":"Under-constrained symbolic execution: Correctness checking for real code","volume-title":"Proceedings of the 24th USENIX Security Symposium (Security)","author":"Ramos"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2018.23008"},{"key":"ref54","article-title":"Native x86 decompilation using Semantics-Preserving structural analysis and iterative Control-Flow structuring","volume-title":"Proceedings of the 22th USENIX Security Symposium (Security)","author":"Schwartz"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23294"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_1"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/178243.178260"},{"key":"ref59","volume-title":"Coverity scan","year":"2006"},{"key":"ref60","article-title":"Autoises: Automatically inferring security specification and detecting violations","volume-title":"Proceedings of the 17th USENIX Security Symposium (Security)","author":"Tan"},{"key":"ref61","volume-title":"Optimization considerations","year":"2022"},{"key":"ref62","volume-title":"Clang static analyzer","year":"2007"},{"key":"ref63","volume-title":"Cppcheck","year":"2007"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180251"},{"key":"ref65","volume-title":"Binary Ninja","year":"2016"},{"key":"ref66","article-title":"How double- fetch situations turn into double-fetch vulnerabilities: A study of double fetches in the linux kernel","volume-title":"Proceedings of the 26th USENIX Security Symposium (Security)","author":"Wang"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243844"},{"key":"ref68","article-title":"Improving integer security for systems with KINT","volume-title":"Proceedings of the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Wang"},{"key":"ref69","article-title":"Understanding and detecting disordered error handling with precise function pairing","volume-title":"Proceedings of the 30th USENIX Security Symposium (Security)","author":"Wu"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1007\/11513988_13"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/1040305.1040334"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00017"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23185"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23185"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.18"},{"key":"ref76","volume-title":"Joern \u2013 the bug hunter\u2019s workbench","author":"Yamaguchi","year":"2014"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516665"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.54"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134620"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180178"},{"key":"ref81","article-title":"APISan: Sanitizing API Usages through Semantic Cross-checking","volume-title":"Proceedings of the 25th USENIX Security Symposium (Security)","author":"Yun"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179314.pdf?arnumber=10179314","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:17:57Z","timestamp":1721452677000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179314\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":81,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179314","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}