{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T12:35:10Z","timestamp":1740141310845,"version":"3.37.3"},"reference-count":86,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002218","61925206","62132014"],"award-info":[{"award-number":["62002218","61925206","62132014"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2023,7,1]]},"DOI":"10.1109\/tdsc.2022.3193327","type":"journal-article","created":{"date-parts":[[2022,7,22]],"date-time":"2022-07-22T16:37:58Z","timestamp":1658507878000},"page":"3208-3221","source":"Crossref","is-referenced-by-count":0,"title":["Hawkeye: Eliminating Kernel Address Leakage in Normal Data Flows"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8395-1319","authenticated-orcid":false,"given":"Zeyu","family":"Mi","sequence":"first","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhi","family":"Guo","sequence":"additional","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fuqian","family":"Huang","sequence":"additional","affiliation":[{"name":"Optiver, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9720-0361","authenticated-orcid":false,"given":"Haibo","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"article-title":"mach_port_kobject() and the kernel address obfuscation","year":"2014","author":"esser","key":"ref13"},{"year":"2021","key":"ref57","article-title":"Common vulnerabilities and exposures"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978321"},{"year":"2020","key":"ref56","article-title":"Common vulnerabilities and exposures"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00027"},{"article-title":"Intel&#x00AE; xeon&#x00AE; processor D product family technical overview","year":"2015","author":"mulnix","key":"ref59"},{"article-title":"Bypassing windows 7 kernel ASLR","year":"2011","author":"conceil","key":"ref14"},{"article-title":"kptr_restrict for hiding kernel pointers","year":"2010","author":"rosenberg","key":"ref58"},{"year":"2017","key":"ref53","article-title":"Common vulnerabilities and exposures"},{"year":"2018","key":"ref52","article-title":"Common vulnerabilities and exposures"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2021.3130751"},{"year":"2017","key":"ref55","article-title":"Common vulnerabilities and exposures"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303946"},{"year":"2018","key":"ref54","article-title":"Common vulnerabilities and exposures"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978366"},{"key":"ref16","first-page":"1063","article-title":"From IP ID to device ID and KASLR bypass","author":"klein","year":"2019","journal-title":"Proc 28th USENIX Secur Symp"},{"year":"2018","key":"ref19","article-title":"Common vulnerabilities and exposures"},{"year":"2018","key":"ref18","article-title":"Common vulnerabilities and exposures"},{"year":"2018","key":"ref51","article-title":"Common vulnerabilities and exposures"},{"year":"2018","key":"ref50","article-title":"Common vulnerabilities and exposures"},{"year":"2018","key":"ref46","article-title":"Common vulnerabilities and exposures"},{"article-title":"oo7: Low-overhead defense against spectre attacks via binary analysis","year":"2018","author":"wang","key":"ref45"},{"year":"2018","key":"ref48","article-title":"Common vulnerabilities and exposures"},{"article-title":"Lkml: Brian belleville: [PATCH] floppy: Do not copy a kernel pointer to user memory in FDGETPRM ioctl","year":"2018","author":"belleville","key":"ref47"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2846742"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483549"},{"year":"2016","key":"ref41"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134069"},{"key":"ref44","first-page":"255","article-title":"EPTI: Efficient defence against meltdown attack for unpatched VMs","author":"hua","year":"2018","journal-title":"Proc USENIX Annu Tech Conf"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196501"},{"year":"2018","key":"ref49","article-title":"Common vulnerabilities and exposures"},{"article-title":"Kernel address space layout randomization","year":"2013","author":"edge","key":"ref8"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2103799.2103805"},{"article-title":"KASLR feature to randomize each loadable module","year":"2018","author":"edgecombe","key":"ref9"},{"article-title":"The story of a simple and dangerous kernel bug","year":"2009","author":"me","key":"ref4"},{"article-title":"iOS kernel exploitation","year":"2011","author":"esser","key":"ref3"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660331"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"year":"2021","key":"ref82","article-title":"The kernel address sanitizer (KASAN)"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483547"},{"key":"ref40","article-title":"Exploiting uses of uninitialized stack variables in Linux kernels to leak kernel pointers","author":"cho","year":"2020","journal-title":"Proc 14th USENIX Workshop Offensive Technol"},{"year":"2021","key":"ref84"},{"year":"2019","key":"ref83","article-title":"Github - Google\/ktsan: Kernel Thread Sanitizer, a fast data race detector for the Linux kernel"},{"key":"ref80","first-page":"2471","article-title":"Detecting kernel refcount bugs with two-dimensional consistency checking","author":"tan","year":"2021","journal-title":"Proc 30th USENIX Secur Symp"},{"year":"2021","key":"ref35"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409686"},{"year":"2012","key":"ref34","article-title":"OS X mountain lion, core technologies overview"},{"key":"ref78","first-page":"31","article-title":"MLEE: Effective detection of memory leaks on early-exit paths in os kernels","author":"wang","year":"2021","journal-title":"Proc USENIX Annu Tech Conf"},{"article-title":"fs\/proc, core\/debug: Don't expose absolute kernel addresses via wchan","year":"2015","author":"molnar","key":"ref37"},{"article-title":"linux\/kaslr.c at master","year":"2021","author":"torvalds","key":"ref36"},{"year":"2013","key":"ref31","article-title":"Common vulnerabilities and exposures"},{"key":"ref75","first-page":"1205","article-title":"PeX: A permission check analysis framework for Linux kernel","author":"zhang","year":"2019","journal-title":"Proc 28th USENIX Secur Symp"},{"year":"2018","key":"ref30","article-title":"A step-by-step Linux kernel exploitation (part 4\/4)"},{"key":"ref74","first-page":"1629","article-title":"Static detection of unsafe DMA accesses in device drivers","author":"bai","year":"2021","journal-title":"Proc 30th USENIX Secur Symp"},{"year":"2013","key":"ref33","article-title":"Software defense: Mitigating common exploitation techniques"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304065"},{"article-title":"Retpoline: A software construct for preventing branch-target-injection","year":"2018","author":"turner","key":"ref32"},{"key":"ref76","first-page":"587","article-title":"DSAC: Effective static analysis of sleep-in-atomic-context bugs in kernel modules","author":"bai","year":"2018","journal-title":"Proc USENIX Annu Tech Conf"},{"key":"ref2","first-page":"383","article-title":"Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms","author":"hund","year":"2009","journal-title":"Proc 18th USENIX Secur Symp"},{"article-title":"Exploit mitigation improvements in windows 8","year":"2012","author":"johnson","key":"ref1"},{"year":"2018","key":"ref39","article-title":"Common vulnerabilities and exposures"},{"year":"2018","key":"ref38","article-title":"Common vulnerabilities and exposures"},{"article-title":"The checkpatch.pl script","year":"2021","author":"jones","key":"ref71"},{"article-title":"KLEAK: Practical kernel memory disclosure detection","year":"2018","author":"barabosch","key":"ref70"},{"key":"ref73","first-page":"1","article-title":"How double-fetch situations turn into double-fetch vulnerabilities: A study of double fetches in the Linux kernel","author":"wang","year":"2017","journal-title":"Proc 26th USENIX Secur Symp"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3381990"},{"year":"2021","key":"ref24","article-title":"The Linux kernel archives"},{"year":"2021","key":"ref68","article-title":"UndefinedBehaviorSanitizer"},{"article-title":"Hash addresses printed with %p","year":"2017","author":"harding","key":"ref23"},{"article-title":"GCC undefined behavior sanitizer - UBSan","year":"2014","author":"polacek","key":"ref67"},{"year":"2021","key":"ref26","article-title":"Ubuntu to mainline kernel version mapping"},{"year":"2021","key":"ref25","article-title":"DebianStretch - Debian wiki"},{"key":"ref69","first-page":"1007","article-title":"DR. CHECKER: A soundy analysis for Linux kernel drivers","author":"machiry","year":"2017","journal-title":"Proc 26th USENIX Secur Symp"},{"year":"2018","key":"ref20","article-title":"Common vulnerabilities and exposures"},{"article-title":"Printf(9) - FreeBSD kernel developer's manual","year":"2015","author":"project","key":"ref64"},{"article-title":"Chrome OS internals","year":"2014","author":"triplett","key":"ref63"},{"article-title":"Making attacks a little harder","year":"2010","author":"corbet","key":"ref22"},{"year":"2021","key":"ref66","article-title":"KernelMemorySanitizer, a detector of uses of uninitialized memory in the Linux kernel"},{"article-title":"Exploiting a Linux kernel infoleak to bypass Linux kASLR","year":"2016","author":"grassi","key":"ref21"},{"article-title":"11.7. Configuring system logging","year":"2021","author":"zeising","key":"ref65"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2915829"},{"article-title":"Private mail with a Linux kernel developer over the mailing list","year":"2021","author":"authors","key":"ref27"},{"article-title":"Supervisor mode access prevention","year":"2012","author":"corbet","key":"ref29"},{"article-title":"AMD's modern graphics driver in Linux 5.14 exceeds 3.3 million lines of code","year":"2021","author":"larabel","key":"ref60"},{"article-title":"Sparse: A look under the hood","year":"2016","author":"brown","key":"ref62"},{"article-title":"Printk-formats","year":"2021","author":"dunlap","key":"ref61"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10177761\/09837461.pdf?arnumber=9837461","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,1]],"date-time":"2023-08-01T18:35:56Z","timestamp":1690914956000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9837461\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,1]]},"references-count":86,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2022.3193327","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"type":"print","value":"1545-5971"},{"type":"electronic","value":"1941-0018"},{"type":"electronic","value":"2160-9209"}],"subject":[],"published":{"date-parts":[[2023,7,1]]}}}