{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:48:17Z","timestamp":1783007297127,"version":"3.54.5"},"reference-count":43,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/100006190","name":"Research and Development","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006190","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179402","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"2799-2816","source":"Crossref","is-referenced-by-count":2,"title":["TeSec: Accurate Server-side Attack Investigation for Web Applications"],"prefix":"10.1109","author":[{"given":"Ruihua","family":"Wang","sequence":"first","affiliation":[{"name":"Tsinghua University,KLISS, TNList, School of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yihao","family":"Peng","sequence":"additional","affiliation":[{"name":"Tsinghua University,KLISS, TNList, School of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yilun","family":"Sun","sequence":"additional","affiliation":[{"name":"Tsinghua University,KLISS, TNList, School of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuancheng","family":"Zhang","sequence":"additional","affiliation":[{"name":"Tsinghua University,KLISS, TNList, School of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hai","family":"Wan","sequence":"additional","affiliation":[{"name":"Tsinghua University,KLISS, TNList, School of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xibin","family":"Zhao","sequence":"additional","affiliation":[{"name":"Tsinghua University,KLISS, TNList, School of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/360825.360855"},{"key":"ref2","volume-title":"Compilers: principles, techniques, & tools","author":"Aho","year":"2007"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423355"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052640"},{"key":"ref6","article-title":"Trustworthy whole-system provenance for the linux kernel","volume-title":"24th USENIX Security Symposium","author":"Bates"},{"key":"ref7","volume-title":"Express"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3475358"},{"key":"ref10","article-title":"Scaling SPADE to \u201cbig provenance\u201d","volume-title":"8th USENIX Workshop on the Theory and Practice of Provenance, TaPP 2016, Washington, D.C., USA, June 8-9, 2016","author":"Gehani"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35170-9_6"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3391800.3398175"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24046"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23349"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24270"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30232-2_8"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/2504730.2504740"},{"key":"ref18","article-title":"Dependence-preserving data compaction for scalable forensic analysis","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Hossain"},{"key":"ref19","article-title":"{SLEUTH}: Real-time attack scenario reconstruction from {COTS} audit data","volume-title":"26th {USENIX} Security Symposium ({USENIX} Security 17)","author":"Hossain"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s00450-009-0092-6"},{"key":"ref21","author":"Kharche","year":"2015","journal-title":"Preventing sql injection attack using pattern matching algorithm"},{"key":"ref22","article-title":"Intrusion recovery using selective re-execution","volume-title":"9th USENIX Symposium on Operating Systems Design and Implementation","author":"Kim"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"ref24","article-title":"Enriching intrusion alerts through multi-host causality","volume-title":"NDSS","author":"King"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1137\/0206024"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23306"},{"key":"ref27","article-title":"High accuracy attack provenance via binary-based execution partition","volume-title":"NDSS","author":"Lee"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23319"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102282"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818039"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-93420-0_22"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1186\/s40064-015-0805-1"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/375360.375365"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243776"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2015.2489211"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420989"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1201\/9781420036336.ch7"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833632"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24329"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24445"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590309"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.01.002"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/dsn.2003.1209932"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179402.pdf?arnumber=10179402","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:13:52Z","timestamp":1721452432000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179402\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":43,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179402","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}