{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:03:45Z","timestamp":1782975825969,"version":"3.54.5"},"reference-count":61,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202465"],"award-info":[{"award-number":["62202465"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB2910109"],"award-info":[{"award-number":["2021YFB2910109"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00236","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"4020-4035","source":"Crossref","is-referenced-by-count":0,"title":["NetPanic: the Attack Surface You Can't Syscall"],"prefix":"10.1109","author":[{"given":"Tianshuo","family":"Han","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zong","family":"Cao","sequence":"additional","affiliation":[{"name":"Imperial Global,Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhen","family":"Dong","sequence":"additional","affiliation":[{"name":"Fudan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiapu","family":"Luo","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenyu","family":"Song","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jian","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.240559"},{"key":"ref2","article-title":"A survey of fuzzing open-source operating systems","author":"Hu","year":"2025","journal-title":"arXiv preprint"},{"key":"ref3","article-title":"Syzparam: Introducing runtime parameters into kernel driver fuzzing","author":"Sun","year":"2025","journal-title":"arXiv preprint"},{"key":"ref4","volume-title":"syzkaller: An unsupervised coverage-guided kernel fuzzer","author":"Dmitry","year":"2016"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623146"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179298"},{"key":"ref7","first-page":"71","article-title":"Playing for $\\{\\mathrm{K}(\\mathrm{H})$ eaps $\\}$: Understanding and improving linux kernel exploit reliability","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Zeng"},{"key":"ref8","first-page":"6825","article-title":"Pspray: Timing {Side-Channel} based linux kernel heap exploitation technique","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Lee"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560585"},{"key":"ref10","first-page":"781","article-title":"{FUZE}: Towards facilitating exploit generation for kernel {Use-After-Free} vulnerabilities","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Wu"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623220"},{"key":"ref12","article-title":"When good kernel defenses go bad: Reliable and stable kernel exploits via defenseamplified tlb side-channel leaks","volume-title":"34rd USENIX Security Symposium: USENIX Security 2024. USENIX Association","author":"Maar"},{"key":"ref13","first-page":"167","article-title":"{kAFL}:{Hardware-Assisted} feedback fuzzing for {OS} kernels","volume-title":"26th USENIX security symposium (USENIX Security 17)","author":"Schumilo"},{"key":"ref14","volume-title":"External network fuzzing for linux kernel","author":"Konovalov","year":"2023"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519591"},{"key":"ref17","first-page":"489","article-title":"{TCPFuzz}: Detecting memory and semantic bugs in {TCP} stacks with fuzzing","volume-title":"2021 USENIX Annual Technical Conference (USENIX ATC 21)","author":"Zou"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2022.23008"},{"key":"ref19","volume-title":"Linux kernel security bugs","year":"2024"},{"key":"ref20","volume-title":"Kcov: code coverage for fuzzing","author":"Kagstrom","year":"2025"},{"key":"ref21","volume-title":"Kernel address sanitizer (kasan)","author":"Andrey Konovalov","year":"2025"},{"key":"ref22","volume-title":"Syzlang: the eclarative description of syscall interfaces to manipulate programs by syzkaller","author":"Vyukov","year":"2025"},{"key":"ref23","volume-title":"Universal tun\/tap device driver","year":"2025"},{"key":"ref24","volume-title":"Syzbot: the system continuously fuzzes main linux kernel branches and automatically reports found bugs to kernel mailing lists","author":"Vyukov","year":"2025"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833683"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484564"},{"key":"ref27","first-page":"729","article-title":"MoonShine: Optimizing OS fuzzer seed selection with trace distillation","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Pailoor"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483547"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575731"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359662"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00035"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1587\/transinf.2021NGP0005"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00078"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00024"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3696788"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10233-3"},{"key":"ref37","volume-title":"Scapy: Packet crafting for Python","author":"Biondi","year":"2003"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1868447.1868466"},{"key":"ref39","volume-title":"Network subsystem in the linux kernel","year":"2025"},{"key":"ref40","volume-title":"Mannual of nfs in the linux kernel","year":"2025"},{"key":"ref41","volume-title":"Device drivers for ethernet and ethernet-based virtual function devices","year":"2025"},{"key":"ref42","volume-title":"the internet protocol","year":"1981"},{"key":"ref43","volume-title":"Specification of the transmission control protocol (tcp)","year":"1981"},{"key":"ref44","volume-title":"the file transfer protocol","year":"1985"},{"key":"ref45","volume-title":"Specification of the secure shell (ssh) transport layer protocol","year":"2006"},{"key":"ref46","volume-title":"Mannual of socket and its related system calls in the linux","year":"2025"},{"key":"ref47","volume-title":"The internal architecture of syzkaller","author":"Dmitry","year":"2024"},{"key":"ref48","volume-title":"Specification of the internet protocol, version 6 (ipv6)","year":"2017"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560602"},{"key":"ref50","volume-title":"The rust programing language","year":"2006"},{"key":"ref51","volume-title":"The namespace feature of the linux kernel","year":"2025"},{"key":"ref52","author":"Konovalov","year":"2025","journal-title":"The recent patch to tap device that allows bypassing of the dereference machanisms in the network stacks"},{"key":"ref53","volume-title":"Understanding Linux network internals","author":"Benvenuti","year":"2006"},{"key":"ref54","volume-title":"Wireshark the a network traffic analyzer","author":"Thacker","year":"2025"},{"key":"ref55","volume-title":"low overhead in packet dissection","author":"Anders Broman","year":"2025"},{"key":"ref56","volume-title":"The address mapping tools that convert addresses into file names and line numbers","year":"2006"},{"key":"ref57","volume-title":"American Fuzzy Lop","author":"Zalewski","year":"2014"},{"key":"ref58","volume-title":"Google kctf","year":"2025"},{"key":"ref59","volume-title":"Windows equivalent of the linux networking namespace: the network compartments","year":"2014"},{"key":"ref60","volume-title":"Windows equivalent of the linux tap device: Windows tap device driver","year":"2014"},{"key":"ref61","volume-title":"Deflaking stretagy of syzkaller","author":"Dmitry","year":"2024"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573628.pdf?arnumber=11573628","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:36:39Z","timestamp":1782970599000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573628\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00236","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}