{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:01:43Z","timestamp":1782975703017,"version":"3.54.5"},"reference-count":92,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00013","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"3930-3948","source":"Crossref","is-referenced-by-count":0,"title":["Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective Tracing"],"prefix":"10.1109","author":[{"given":"Chuqi","family":"Zhang","sequence":"first","affiliation":[{"name":"National University of Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Spencer","family":"Faith","sequence":"additional","affiliation":[{"name":"Arizona State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Feras","family":"Al-Qassas","sequence":"additional","affiliation":[{"name":"Arizona State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Theodorus","family":"Februanto","sequence":"additional","affiliation":[{"name":"Arizona State University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenkai","family":"Liang","sequence":"additional","affiliation":[{"name":"National University of Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Adil","family":"Ahmad","sequence":"additional","affiliation":[{"name":"Arizona State University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Kernel self-protection","year":"2025"},{"key":"ref2","volume-title":"Supervisor mode access prevention","year":"2022"},{"key":"ref3","volume-title":"Cook: Security things in Linux v5.3"},{"key":"ref4","volume-title":"Elena Reshetova. x86\/entry\/64: randomize kernel stack offset upon syscall","year":"2019"},{"key":"ref5","volume-title":"Kcfi support","author":"Tolvanen","year":"2022"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623220"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560585"},{"key":"ref8","volume-title":"RetSpill: KCFI_eval"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00087"},{"key":"ref11","volume-title":"SUSE. Understanding Linux Audit"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134045"},{"key":"ref13","article-title":"Enabling refinable cross-host attack investigation with efficient data flow tagging and tracking","volume-title":"USENIX Security Symposium (USENIX)","author":"Ji","year":"2018"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560570"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484551"},{"key":"ref16","volume-title":"Cve-2021\u201322555 details"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/2815400.2815415"},{"key":"ref18","article-title":"Multik: A framework for orchestrating multiple specialized kernels","author":"Kuo","year":"2019","journal-title":"arXiv preprint"},{"key":"ref19","article-title":"Shard: Fine-Grained Kernel Specialization with Context-Aware Hardening","volume-title":"Proceedings of the 30th USENIX Security Symposium (Security)","author":"Abubakar","year":"2021"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2014.52"},{"key":"ref21","volume-title":"Event tracing for Windows (ETW)","year":"2021"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24065"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417862"},{"key":"ref24","article-title":"Faster yet safer: Logging system via Fixed-Key blockcipher","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Hoang","year":"2022"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833745"},{"key":"ref26","article-title":"Rethinking System Audit Architectures for High Event Coverage and Synchronous Log Availability","volume-title":"Proceedings of the 32nd USENIX Security Symposium (Security)","author":"Gandhi","year":"2023"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690188"},{"key":"ref28","volume-title":"Performance Anomaly Detection with Intel Processor Trace and Intel VTune Profiler"},{"key":"ref29","volume-title":"Tenable Cyber Exposure Study - Application Software Security: Risk Prioritization"},{"key":"ref30","volume-title":"Guide to auditing web servers"},{"key":"ref31","article-title":"KOOBE: Towards facilitating exploit generation of kernel Out-Of-Bounds write vulnerabilities","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Chen","year":"2020"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/sp46215.2023.10179405"},{"key":"ref33","article-title":"Meltdown: Reading kernel memory from user space","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Lipp","year":"2018"},{"key":"ref34","article-title":"One bit flips, one cloud flops: Cross-vm row hammer attacks and privilege escalation","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Xiao","year":"2016"},{"key":"ref35","volume-title":"ftrace - Function Tracer - The Linux Kernel documentation"},{"key":"ref36","article-title":"Reverse debugging of kernel failures in deployed systems","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC 20)","author":"Ge","year":"2020"},{"key":"ref37","article-title":"Auditing frameworks need resource isolation: A systematic study on the super producer threat to system auditing and its mitigation","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Jiang","year":"2023"},{"key":"ref38","article-title":"Where Does It Go? Refining Indirect-Call Targets with Multi-Layer Type Analysis","volume-title":"Proceedings of the 26th ACM Conference on Computer and Communications Security (CCS)","author":"Lu","year":"2019"},{"key":"ref39","volume-title":"System Programming Guide","volume":"3A","year":"2016"},{"key":"ref40","author":"Gao","year":"2024","journal-title":"Retrieval-augmented generation for large language models: A survey"},{"key":"ref41","article-title":"Exploiting code symmetries for learning program semantics","volume-title":"Proceedings of the 41st International Conference on Machine Learning","author":"Pei","year":"2024"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3676641.3716022"},{"key":"ref43","article-title":"Large language models for code analysis: Do LLMs really do their job","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Fang","year":"2024"},{"key":"ref44","doi-asserted-by":"crossref","DOI":"10.1145\/3691620.3695016","article-title":"Semantic-enhanced indirect call analysis with large language models","volume-title":"Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering","author":"Cheng","year":"2024"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3643795.3648392"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00189"},{"key":"ref47","article-title":"DEEPTYPE: Refining indirect call targets with strong multi-layer type analysis","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Xia","year":"2024"},{"key":"ref48","volume-title":"Linux Virtualization-Based Security (LVBS)"},{"key":"ref49","volume-title":"Intel Jason Chen. Supporting TEE on x86 Client Platforms with pKVM"},{"key":"ref50","article-title":"Hodor: Intra-Process isolation for HighThroughput data plane libraries","volume-title":"2019 USENIX Annual Technical Conference (USENIX ATC 19)","author":"Hedayati","year":"2019"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3582016.3582042"},{"key":"ref52","volume-title":"System V ABI"},{"key":"ref53","article-title":"ARCUS: Symbolic root cause analysis of exploits in production systems","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Yagemann","year":"2021"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.42"},{"key":"ref55","volume-title":"Powerful disassembler library for x86\/amd64","year":"2021"},{"key":"ref56","volume-title":"Ollama: Get up and running w ith large language models"},{"key":"ref57","volume-title":"Qwen3: Think Deeper, Act Faster"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3381052.3381328"},{"key":"ref59","article-title":"An Extensible Orchestration and Protection Framework for Confidential Cloud Computing","volume-title":"Proceedings of the 17th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Ahmad","year":"2023"},{"key":"ref60","volume-title":"Bareflank\/hypervisor"},{"key":"ref61","volume-title":"Microsoft Learn. Virtualization-based security (VBS)","year":"2020"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3037697.3037716"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363217"},{"key":"ref64","volume-title":"Linux test project","year":"2024"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678891"},{"key":"ref66","article-title":"Ninja: Towards transparent tracing and debugging on ARM","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Ning","year":"2017"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534410"},{"key":"ref68","article-title":"BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating Systems","volume-title":"Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Hof"},{"key":"ref69","article-title":"Core slicing: closing the gap between leaky confidential VMs and bare-metal cloud","volume-title":"17th USENIX Symposium on Operating Systems Design and Implementation (OSDI 23)","author":"Zhou","year":"2023"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080209"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446709"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3689031.3717464"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627113"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230328"},{"key":"ref75","volume-title":"Memory protection keys for the kernel"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2775111"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866314"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_32"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"ref82","article-title":"Rept: Reverse debugging of failures in deployed software","volume-title":"USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Cui","year":"2018"},{"key":"ref83","article-title":"Pomp: postmortem program analysis with hardware-enhanced post-crash artifacts","volume-title":"USENIX Security Symposium (USENIX)","author":"Xu","year":"2017"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/2815400.2815412"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132767"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/3453483.3454101"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485363"},{"key":"ref88","article-title":"Nyx: Greybox hypervisor fuzzing using fast snapshots and affine types","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Schumilo","year":"2021"},{"key":"ref89","article-title":"kAFL: Hardware-Assisted feedback fuzzing for OS kernels","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Schumilo","year":"2017"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2017.18"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029830"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243797"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573583.pdf?arnumber=11573583","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:34:05Z","timestamp":1782970445000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573583\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":92,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00013","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}