{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:31:49Z","timestamp":1783096309544,"version":"3.54.6"},"reference-count":91,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179398","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"2104-2121","source":"Crossref","is-referenced-by-count":11,"title":["SegFuzz: Segmentizing Thread Interleaving to Discover Kernel Concurrency Bugs through Fuzzing"],"prefix":"10.1109","author":[{"given":"Dae R.","family":"Jeong","sequence":"first","affiliation":[{"name":"KAIST,School of Computing"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Byoungyoung","family":"Lee","sequence":"additional","affiliation":[{"name":"Seoul National University,Department of Electrical and Computer Engineering"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Insik","family":"Shin","sequence":"additional","affiliation":[{"name":"KAIST,School of Computing"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Youngjin","family":"Kwon","sequence":"additional","affiliation":[{"name":"KAIST,School of Computing"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115685"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3177156"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985795"},{"key":"ref4","article-title":"Midas: Systematic kernel TOCTTOU protection","volume-title":"Proceedings of the 31st USENIX Security Symposium (Security)","author":"Bhattacharyya"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/1806596.1806626"},{"key":"ref6","volume-title":"Sloc Cloc and Code (scc)","author":"Boyter","year":"2020"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/1736020.1736040"},{"key":"ref8","article-title":"Klee: unassisted and automatic generation of high-coverage tests for complex systems programs","volume-title":"Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Cadar"},{"key":"ref9","doi-asserted-by":"crossref","DOI":"10.1145\/2970276.2970307","article-title":"Radius aware probabilistic testing of deadlocks with guarantees","volume-title":"Proceedings of the 31st IEEE\/ACM International Conference on Automated Software Engineering (ASE)","author":"Cai"},{"key":"ref10","article-title":"MUZZ: Thread-aware grey-box fuzzing for effective bug hunting in multithreaded programs","volume-title":"Proceedings of the 29th USENIX Security Symposium (Security)","author":"Chen"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1950365.1950396"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.32"},{"key":"ref13","article-title":"Effective data-race detection for the kernel","volume-title":"Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Erickson"},{"key":"ref14","article-title":"SKI: Exposing kernel concurrency bugs through systematic schedule exploration","volume-title":"Proceedings of the 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Fonseca"},{"key":"ref15","volume-title":"FNV Hash","author":"Fowler","year":"2022"},{"key":"ref16","volume-title":"net: fix a concurrency bug in l2tp_tunnel_-register()","author":"Gong","year":"2012"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483549"},{"key":"ref18","volume-title":"Syscall description language","year":"2016"},{"key":"ref19","volume-title":"The Go Programming Language","year":"2022"},{"key":"ref20","volume-title":"Syzkaller - kernel fuzzer","year":"2022"},{"key":"ref21","volume-title":"Trace Me if You Can: Bypassing Linux Syscall Tracing","author":"Guo","year":"2022"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134103"},{"key":"ref23","volume-title":"Android Universal Root: Exploiting Mobile GPU \/ Command Queue Drivers","author":"Han","year":"2022"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23312"},{"key":"ref25","article-title":"Directed graph hashing","volume-title":"CoRR","author":"Helbling","year":"2020"},{"key":"ref26","author":"Huang","year":"2022","journal-title":"Understanding concurrency vulnerabilities in linux kernel"},{"key":"ref27","volume-title":"Hardware and Software Breakpoints","year":"2020"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00017"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3552326.3567486"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24296"},{"key":"ref31","volume-title":"Monitoring Surveillance Vendors: A Deep Dive into In-the-Wild Android Full Chains in 2021","author":"Jin","year":"2021"},{"key":"ref32","volume-title":"Android Universal Root: Exploiting Mobile GPU \/ Command Queue Drivers","author":"Jin","year":"2022"},{"key":"ref33","volume-title":"Trinity: Linux system call fuzzer.","author":"Jones","year":"2012"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/368996.369025"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24018"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359662"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"ref38","article-title":"ExpRace: Exploiting kernel races through raising interrupts","volume-title":"Proceedings of the 30th USENIX Security Symposium (Security), Virtual","author":"Lee"},{"key":"ref39","volume-title":"Exploiting Kernel Races through Taming Thread Interleaving","author":"Lee","year":"2022"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3314221.3314635"},{"key":"ref41","volume-title":"The Kernel Address Sanitizer (KASAN)","year":"2022"},{"key":"ref42","volume-title":"The kernel concurrency sanitizer (kcsan)","year":"2022"},{"key":"ref43","volume-title":"Explanation of the Linux-Kernel Memory Consistency Model","year":"2022"},{"key":"ref44","volume-title":"Runtime locking correctness validator","year":"2022"},{"key":"ref45","volume-title":"The Undefined Behavior Sanitizer - UBSAN","year":"2022"},{"key":"ref46","volume-title":"Linux Watchdog Support","year":"2022"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23387"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2560012"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1346281.1346323"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542491"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48184-2_32"},{"key":"ref52","volume-title":"Cve-2016-8655","year":"2016"},{"key":"ref53","volume-title":"Cve-2017-15649","year":"2016"},{"key":"ref54","volume-title":"Cve-2017-17712","year":"2016"},{"key":"ref55","volume-title":"Cve-2017-2636","year":"2017"},{"key":"ref56","volume-title":"Cve-2017-7533","year":"2017"},{"key":"ref57","volume-title":"Cve-2018-12232","year":"2018"},{"key":"ref58","volume-title":"Cve-2019-11486","year":"2019"},{"key":"ref59","volume-title":"Cve-2019-1999","year":"2019"},{"key":"ref60","volume-title":"Cve-2019-2025","year":"2019"},{"key":"ref61","volume-title":"Cve-2019-6974","year":"2019"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3428298"},{"key":"ref63","article-title":"Finding and reproducing heisenbugs in concurrent programs","volume-title":"Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Musuvathi"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/2254064.2254128"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/781498.781528"},{"key":"ref67","volume-title":"An introduction to statistical methods and data analysis.","author":"Ott","year":"2015"},{"key":"ref68","article-title":"MoonShine: Optimizing OS fuzzer seed selection with trace distillation","volume-title":"Proceedings of the 27th USENIX Security Symposium (Security)","author":"Pailoor"},{"key":"ref69","volume-title":"The LLVM Compiler Infrastructure","author":"Project","year":"2021"},{"key":"ref70","article-title":"kAFL:Hardware-Assisted feedback fuzzing for OS kernels","volume-title":"Proceedings of the 26th USENIX Security Symposium (Security)","author":"Schumilo"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196508"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/1791194.1791203"},{"key":"ref73","article-title":"Address-Sanitizer: A fast address sanity checker","volume-title":"Proceedings of the 2012 USENIX Annual Technical Conference (ATC)","author":"Serebryany"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23176"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483547"},{"key":"ref76","article-title":"KSG: Augmenting kernel fuzzing with system call specification generation","volume-title":"Proceedings of the 2022 USENIX Annual Technical Conference (ATC)","author":"Sun"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238224"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/2555243.2555260"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043590"},{"key":"ref80","article-title":"SyzVegas: Beating kernel fuzzing odds with reinforcement learning","volume-title":"Proceedings of the 30th USENIX Security Symposium (Security), Virtual","author":"Wang"},{"key":"ref81","article-title":"How double-fetch situations turn into double-fetch vulnerabilities: A study of double fetches in the linux kernel","volume-title":"Proceedings of the 26th USENIX Security Symposium (Security)","author":"Wang"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.4345"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-016-6383-8"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243844"},{"key":"ref85","volume-title":"SLOCCount","author":"Wheeler","year":"2020"},{"key":"ref86","article-title":"FUZE: Towards facilitating exploit generation for kernel Use-After-Free vulnerabilities","volume-title":"Proceedings of the 27th USENIX Security Symposium (Security)","author":"Wu"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00017"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00078"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00035"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872384"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/3037697.3037708"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179398.pdf?arnumber=10179398","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:15:27Z","timestamp":1721452527000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179398\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":91,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179398","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}