{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T14:31:26Z","timestamp":1782484286375,"version":"3.54.5"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tdsc.2022.3165368","type":"journal-article","created":{"date-parts":[[2022,4,6]],"date-time":"2022-04-06T19:34:28Z","timestamp":1649273668000},"page":"1-1","source":"Crossref","is-referenced-by-count":3,"title":["Automatic Permission Check Analysis for Linux Kernel"],"prefix":"10.1109","author":[{"given":"Jinmeng","family":"Zhou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tong","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenbo","family":"Shen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongyoon","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Changhee","family":"Jung","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed","family":"Azab","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruowen","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peng","family":"Ning","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kui","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/35.312842"},{"key":"ref2","article-title":"capabilities - overview of linux capabilities"},{"issue":"43","key":"ref3","article-title":"Implementing selinux as a linux security module","volume":"1","author":"Smalley","year":"2001","journal-title":"NAI Labs Rep."},{"key":"ref4","article-title":"Apparmor"},{"key":"ref5","article-title":"CAP_SYS_ADMIN: The new root"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23326"},{"key":"ref8","article-title":"Android permission overview"},{"key":"ref9","volume-title":"Advanced Compiler Design Implementation","author":"Muchnick","year":"1997"},{"key":"ref10","article-title":"Trusted computer system evaluation criteria","volume-title":"National Computer Security Center","author":"Qiu","year":"1985"},{"key":"ref11","volume-title":"A Guide to Understanding Discretionary Access Control in Trusted Systems","year":"1987"},{"key":"ref12","article-title":"alse boundaries and arbitrary code execution"},{"key":"ref13","first-page":"6","article-title":"Linux security module framework","volume-title":"Proc. Ottawa Linux Symp.","author":"Wright"},{"key":"ref14","article-title":"Mandatory access control"},{"key":"ref15","first-page":"20","article-title":"Security enhanced (se) android: Bringing flexible mac to android","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Smalley"},{"key":"ref16","article-title":"Virtual file system"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2011.5764696"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2009.9"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/1273442.1250767"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74061-2_17"},{"key":"ref21","article-title":"Locationmanager"},{"key":"ref22","first-page":"379","article-title":"Autoises: Automatically inferring security specification and detecting violations","volume-title":"Proc. USENIX Secur. Symp.","author":"Tan"},{"key":"ref23","first-page":"33","article-title":"Using CQUAL for static analysis of authorization hook placement","volume-title":"Proc. USENIX Secur. Symp.","author":"Zhang"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102164"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-15618-7_14"},{"key":"ref26","article-title":"Towards automated authorization policy enforcement","volume-title":"Proc. 2nd Annu. Secur. Enhanced Linux Symp.","author":"Ganapathy"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586141"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382215"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2004.1281665"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/199448.199461"},{"key":"ref31","first-page":"1205","article-title":"PEX: A permission check analysis framework for linux kernel","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Zhang"},{"key":"ref32","article-title":"capabilities(7) - linux manual page","year":"2022"},{"key":"ref33","article-title":"Whole program LLVM: A wrapper script to build whole-program LLVM bitcode files"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243844"},{"key":"ref35","article-title":"K-miner: Data-flow analysis for the linux kernel"},{"key":"ref36","first-page":"209","article-title":"KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs","volume-title":"Proc. 8th USENIX Conf. Operating Syst. Des. Implementation","author":"Cadar"},{"key":"ref37","article-title":"Re: Leaking path in xfss ioctl interface(missing LSM check) by stephen smalley"},{"key":"ref38","article-title":"timerslack_ns_write"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/1357010.1352618"},{"key":"ref40","article-title":"How double-fetch situations turn into double-fetch vulnerabilities: A study of double fetches in the linux kernel","volume-title":"Proc. USENIX Secur. Symp.","author":"Wang"},{"key":"ref41","article-title":"Sparse"},{"key":"ref42","article-title":"Smatch: Pluggable static analysis for C"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00017"},{"key":"ref44","first-page":"1007","article-title":"DR. CHECKER: A soundy analysis for linux kernel drivers","volume-title":"Proc. 26th USENIX Secur. Symp.","author":"Machiry"},{"key":"ref45","first-page":"163","article-title":"Improving integer security for systems with KINT","volume-title":"Proc. 10th USENIX Conf. Oper. Syst. Des. Implementation","author":"Wang"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978366"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516665"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948153"},{"key":"ref49","first-page":"363","article-title":"APISan: Sanitizing API usages through semantic cross-checking","volume-title":"Proc. USENIX Secur. Symp.","author":"Yun"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/502059.502041"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/2076021.2048146"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/2592798.2592801"},{"key":"ref53","first-page":"973","article-title":"JIGSAW: Protecting resource access by inferring programmer expectations","volume-title":"Proc. USENIX Secur. Symp.","author":"Vijayakumar"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/2815400.2815422"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382222"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23046"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/4358699\/09750908.pdf?arnumber=9750908","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,18]],"date-time":"2024-01-18T00:44:14Z","timestamp":1705538654000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9750908\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/tdsc.2022.3165368","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}