{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:01:30Z","timestamp":1785952890382,"version":"3.56.0"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2016,7,1]],"date-time":"2016-07-01T00:00:00Z","timestamp":1467331200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"name":"Con Edison"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Multi-Scale Comp. Syst."],"published-print":{"date-parts":[[2016,7,1]]},"DOI":"10.1109\/tmscs.2016.2569467","type":"journal-article","created":{"date-parts":[[2016,5,17]],"date-time":"2016-05-17T14:10:19Z","timestamp":1463494219000},"page":"160-173","source":"Crossref","is-referenced-by-count":44,"title":["Malicious Firmware Detection with Hardware Performance Counters"],"prefix":"10.1109","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0390-9909","authenticated-orcid":false,"given":"Xueyang","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Charalambos","family":"Konstantinou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michail","family":"Maniatakos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ramesh","family":"Karri","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Serena","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Patricia","family":"Robison","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul","family":"Stergiou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Steve","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","article-title":"U-Boot","year":"0"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ELEKTRO.2012.6225571"},{"key":"ref33","article-title":"Arndale Board","year":"0"},{"key":"ref32","article-title":"Detours: Binary interception of win32 functions","author":"hunt","year":"0","journal-title":"Proc 3rd Usenix Windows NT Symp"},{"key":"ref31","article-title":"Booting","year":"0"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594295"},{"key":"ref37","article-title":"VxWorks The industry's leading operating system for embedded devices","year":"0"},{"key":"ref36","article-title":"e300 Power Architecture Core Family Reference Manual","year":"0"},{"key":"ref35","article-title":"Cortex-A15 technical reference manual","year":"0"},{"key":"ref34","article-title":"MPC8308RDB Reference Platform","year":"0"},{"key":"ref60","article-title":"Implementing secure remote firmware updates","author":"shade","year":"2011","journal-title":"Proc Embedded Syst Conf"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/2485922.2485970"},{"key":"ref61","article-title":"Method for performing a trusted firmware\/bios update","author":"zimmer","year":"0"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2015.2474374"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046713"},{"key":"ref64","first-page":"1","article-title":"CFIMon: Detecting violation of control flow integrity\n using performance counters","author":"xia","year":"0","journal-title":"Proc IEEE\/IFIP Int Conf Dependable Syst Netw"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74810-6_4"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2015.7056070"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/VLSID.2016.115"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2015.7372617"},{"key":"ref2","year":"0"},{"key":"ref1","author":"holler","year":"2014"},{"key":"ref20","article-title":"Hardware performance counters","year":"0"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/2463209.2488831"},{"key":"ref21","article-title":"Intel 64 and IA-32 Architectures Developer's Manual","year":"0"},{"key":"ref24","article-title":"4th generation of 32-bit PowerPC microprocessors","year":"0"},{"key":"ref23","article-title":"ARM cortex-A53 processor technical reference manual","year":"0"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.36"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315260"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_20"},{"key":"ref51","first-page":"314","article-title":"Scalable hardware monitors to protect network processors\n from data plane attacks","author":"hu","year":"0","journal-title":"Proc IEEE Conf Commun Netw Security"},{"key":"ref59","article-title":"Energy fraud and orchestrated blackouts - Issues with wireless\n metering protocols (wM-Bus)","author":"brunschwiler","year":"2013"},{"key":"ref58","article-title":"Guarding Technology","year":"0"},{"key":"ref57","article-title":"Use of hashing in a secure boot loader","author":"morais","year":"0"},{"key":"ref56","article-title":"Firmware modification analysis in programmable logic controllers","author":"garcia","year":"0"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2011.2174811"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-68979-9_5"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11203-9_13"},{"key":"ref52","first-page":"1","article-title":"System-level security for network processors with\n hardware monitors","author":"hu","year":"0","journal-title":"Proc 51st ACM\/EDAC\/IEEE Design Autom Conf"},{"key":"ref10","article-title":"Developing a trojaned firmware for juniper ScreenOS platforms","year":"0","journal-title":"The Circle of Lost Hackers"},{"key":"ref11","article-title":"Backdoor found in TP-Link routers","year":"0"},{"key":"ref40","first-page":"1","article-title":"Tutorial on single-pole tripping and reclosing","author":"godoy","year":"0","journal-title":"Proc Western Protective Relay Conf"},{"key":"ref12","article-title":"Reversing and exploiting an Apple firmware update","author":"chen","year":"2009","journal-title":"Black Hat USA 2009"},{"key":"ref13","first-page":"1","article-title":"Mouse trap: Exploiting firmware updates in\n usb peripherals","author":"maskiewicz","year":"0","journal-title":"Proc USENIX Workshop Offensive Technol"},{"key":"ref14","article-title":"Hacking MFPs","year":"0"},{"key":"ref15","article-title":"Ooops I hacked My PBX","year":"0"},{"key":"ref16","first-page":"1","article-title":"Comprehensive experimental analyses of automotive attack surfaces","author":"checkoway","year":"0","journal-title":"20th USENIX Security Symp"},{"key":"ref17","first-page":"6","article-title":"Take two software updates and see me in the morning: The case for software\n security evaluations of medical devices","author":"hanna","year":"0","journal-title":"Proc 2nd USENIX Conf Health Security Privacy"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2013.04.004"},{"key":"ref19","article-title":"OProfile, statistical profiler for Linux systems","year":"0"},{"key":"ref4","article-title":"Battery firmware hacking","author":"miller","year":"2011","journal-title":"Black Hat USA 2011"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2010.05.010"},{"key":"ref6","first-page":"95","article-title":"A large-scale analysis of the security of\n embedded firmwares","author":"costin","year":"0","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref5","first-page":"1","article-title":"When firmware\n modifications attack: A case study of embedded exploitation","author":"cui","year":"0","journal-title":"Proc 20th Annu Netw Distrib Syst Security Symp"},{"key":"ref8","article-title":"Reverse engineering a d-link back-door","author":"heffner","year":"2013"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523661"},{"key":"ref49","first-page":"26","article-title":"On-chip control flow integrity check for real time embedded systems","year":"0","journal-title":"Proc 1st IEEE Int Conf Cyber-Phys Syst Netw Appl"},{"key":"ref9","first-page":"1","article-title":"XCS based\n hidden firmware modification on embedded devices","author":"bencsath","year":"0","journal-title":"Proc 19th Int Conf Softw Telecommun Comput Netw"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/1795194.1795210"},{"key":"ref45","article-title":"Libsvm &#x2013; A library for support vector machines","author":"chang","year":"0"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2744869"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046711"},{"key":"ref42","article-title":"Introduction to one-class support vector machines","year":"0"},{"key":"ref41","article-title":"Man in the middle attacks","author":"ornaghi","year":"0"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/S0893-6080(05)80038-3"},{"key":"ref43","article-title":"Kernel methods and support vector machines","author":"shawe-taylor","year":"2009","journal-title":"Lecture notes"}],"container-title":["IEEE Transactions on Multi-Scale Computing Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6687315\/7605563\/07470546.pdf?arnumber=7470546","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T11:39:24Z","timestamp":1641987564000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7470546\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,7,1]]},"references-count":67,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tmscs.2016.2569467","relation":{},"ISSN":["2332-7766"],"issn-type":[{"value":"2332-7766","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,7,1]]}}}