{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T14:06:40Z","timestamp":1782828400326,"version":"3.54.5"},"reference-count":72,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000015","name":"U.S. Department of Energy","doi-asserted-by":"publisher","award":["DE-OE0000779"],"award-info":[{"award-number":["DE-OE0000779"]}],"id":[{"id":"10.13039\/100000015","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"publisher","award":["NSF-1663051"],"award-info":[{"award-number":["NSF-1663051"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tifs.2021.3054968","type":"journal-article","created":{"date-parts":[[2021,1,29]],"date-time":"2021-01-29T20:42:26Z","timestamp":1611952946000},"page":"2413-2428","source":"Crossref","is-referenced-by-count":24,"title":["CPS Device-Class Identification via Behavioral Fingerprinting: From Theory to Practice"],"prefix":"10.1109","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7082-8423","authenticated-orcid":false,"given":"Leonardo","family":"Babun","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0159-2522","authenticated-orcid":false,"given":"Hidayet","family":"Aksu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9823-3464","authenticated-orcid":false,"given":"A. Selcuk","family":"Uluagac","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243796"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/1352533.1352543"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCSW.2012.8"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2018.2808455"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2013.6682720"},{"key":"ref33","first-page":"21","article-title":"CDE: Using system call interposition to automatically create portable software packages","author":"guo","year":"2011","journal-title":"Proc USENIXATC"},{"key":"ref32","author":"ross","year":"2001","journal-title":"Probability Models for Computer Science"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3291047"},{"key":"ref30","year":"2016","journal-title":"Main Page&#x2014;KVM"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICC40277.2020.9149285"},{"key":"ref36","first-page":"2219","article-title":"Liveness is not enough: Enhancing fingerprint authentication with Behavioral biometrics to defeat puppet attacks","author":"wu","year":"2020","journal-title":"Proc USENIX"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24412"},{"key":"ref34","author":"faith","year":"0","journal-title":"The Linux man-pages project"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-017-4652-y"},{"key":"ref62","author":"blunden","year":"2013","journal-title":"The Rookit Arsenal Escape and Evasion in the Dark Corners of the System"},{"key":"ref61","first-page":"1","article-title":"Traps and pitfalls: Practical problems in system call interposition based security tools","author":"garfinkel","year":"2003","journal-title":"Proc NDSS"},{"key":"ref63","first-page":"1","article-title":"User-level infrastructure for system call interposition: A platform for intrusion detection and confinement","author":"jain","year":"1999","journal-title":"Proc NDSS"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SECON.2015.7132891"},{"key":"ref64","first-page":"1","article-title":"Detours: Binary interception of Win32 functions","volume":"3","author":"hunt","year":"1999","journal-title":"Proc WINSYM"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.15837\/ijccc.2013.5.329"},{"key":"ref65","first-page":"139","article-title":"Practical and effective sandboxing for non-root users","author":"kim","year":"2013","journal-title":"Proc USENIX ATC"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2003.1199328"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/GCWkshps45667.2019.9024539"},{"key":"ref67","first-page":"115","article-title":"NORT: Runtime anomaly-based monitoring of malicious Behavior for windows","author":"milea","year":"2011","journal-title":"Proc Int'l Conf Runtime Verification"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924295"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23152"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SNAMS.2019.8931716"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2017.1700871"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2017.7996877"},{"key":"ref22","author":"sillgith","year":"2016","journal-title":"Open source library for IEC 61850 Release 0 9"},{"key":"ref21","year":"2010","journal-title":"Tissue Adhesive with Adjunct Wound Closure Device Intended for the Topical Approximation of Skin&#x2014;Guidance for Industry and FDA Staff"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/s41635-017-0013-2"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2016.7860525"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2016.2605689"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/BigData47090.2019.9006483"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/1629911.1630090"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243735"},{"key":"ref59","article-title":"D&#x00CF;oT: A federated self-learning anomaly detection system for IoT","author":"duc nguyen","year":"2018","journal-title":"arXiv 1804 07474"},{"key":"ref58","first-page":"2177","article-title":"IoT SENTINEL: Automated device-type identification for security enforcement in IoT","author":"miettinen","year":"2017","journal-title":"Proc IEEE 37th Int Conf Distrib Comput Syst (ICDCS)"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2865604"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2014.2369033"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2018.3761722"},{"key":"ref54","doi-asserted-by":"crossref","first-page":"383","DOI":"10.1109\/DSN.2010.5544294","article-title":"A passive approach to wireless device fingerprinting","author":"gao","year":"2010","journal-title":"Proc IEEE\/IFIP Int Conf Dependable Syst Netw (DSN)"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3212480.3226099"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339810"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37228-6_7"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3408308.3427606"},{"key":"ref40","author":"security","year":"2020","journal-title":"Layered Security for the Next One Trillion Devices"},{"key":"ref12","year":"2020","journal-title":"MITRE ATT&CK Supply Chain Compromise"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/2751323.2751329"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2476338"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CNS48642.2020.9162311"},{"key":"ref16","article-title":"Detection of counterfeit and compromised devices using system and function call tracing techniques","author":"babun","year":"2018"},{"key":"ref17","article-title":"Method of resource-limited device and device class identification using system and function call tracing techniques, performance, and statistical analysis","author":"babun","year":"2019"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/WETICE.2016.41"},{"key":"ref19","first-page":"1","article-title":"Who&#x2019;s in control of your control system? Device fingerprinting for cyber-physical systems","author":"formby","year":"2016","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref4","first-page":"1687","article-title":"Sensitive information tracking in commodity IoT","author":"celik","year":"2018","journal-title":"Proc USENIX"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359840"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2019.2911511"},{"key":"ref5","first-page":"145","article-title":"Real-time analysis of privacy-(un)aware IoT applications","author":"babun","year":"2021","journal-title":"Proc PETS\/PoPETS"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3355300"},{"key":"ref7","author":"van opstal","year":"2012","journal-title":"Supply chain solutions for smart grid security Building on business best practices"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00072"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2018.8423022"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660300"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660325"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23107"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICCE-Berlin.2015.7391259"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2005.26"},{"key":"ref41","article-title":"Smartphone fingerprinting via motion sensors: Analyzing feasibility at large-scale and studying real usage patterns","author":"das","year":"2016","journal-title":"arXiv 1605 08763"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/2379616.2379618"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2012.6503213"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/10206\/9151439\/9340269-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9151439\/09340269.pdf?arnumber=9340269","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,23]],"date-time":"2024-08-23T06:32:28Z","timestamp":1724394748000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9340269\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":72,"URL":"https:\/\/doi.org\/10.1109\/tifs.2021.3054968","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}