{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:48:19Z","timestamp":1783007299127,"version":"3.54.5"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T00:00:00Z","timestamp":1680307200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100017069","name":"SRI International","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100017069","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IIEEE Trans. Software Eng."],"published-print":{"date-parts":[[2023,4,1]]},"DOI":"10.1109\/tse.2022.3231242","type":"journal-article","created":{"date-parts":[[2022,12,22]],"date-time":"2022-12-22T18:38:18Z","timestamp":1671734298000},"page":"2761-2775","source":"Crossref","is-referenced-by-count":2,"title":["autoMPI: Automated Multiple Perspective Attack Investigation With Semantics Aware Execution Partitioning"],"prefix":"10.1109","volume":"49","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7108-3809","authenticated-orcid":false,"given":"Mohannad","family":"Alhanahnah","sequence":"first","affiliation":[{"name":"University of Wisconsin-Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiqing","family":"Ma","sequence":"additional","affiliation":[{"name":"Rutgers University, Piscataway, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ashish","family":"Gehani","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gabriela F.","family":"Ciocarlie","sequence":"additional","affiliation":[{"name":"The University of Texas at San Antonio, San Antonio, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Somesh","family":"Jha","sequence":"additional","affiliation":[{"name":"University of Wisconsin-Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1165389.945467"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"key":"ref3","article-title":"Provenance-aware storage systems","volume-title":"Proc. Annu. Conf. USENIX Annu. Tech. Conf.","author":"Muniswamy-Reddy"},{"key":"ref4","article-title":"Layering in provenance systems","volume-title":"Proc. Conf. USENIX Annu. Tech. Conf.","author":"Muniswamy-Reddy"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/IWIA.2005.9"},{"key":"ref6","article-title":"High accuracy attack provenance via binary-based execution partition","volume-title":"Proc. Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Lee"},{"key":"ref7","first-page":"1111","article-title":"MPI: Multiple perspective attack investigation with semantic aware execution partitioning","volume-title":"Proc. 26th USENIX Secur. Symp.","author":"Ma"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23306"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24270"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24329"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00096"},{"key":"ref12","first-page":"241","article-title":"Kernel-supported cost-effective audit logging for causality tracking","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Ma"},{"key":"ref13","article-title":"Event tracing for windows (ETW)","year":"2021"},{"key":"ref14","article-title":"Windows event log","year":"2020"},{"key":"ref15","article-title":"Vim document: Windows"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"ref17","article-title":"Clang language extensions","year":"2020"},{"key":"ref18","article-title":"Whole program LLVM","author":"Mason","year":"2020"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.21236\/ADA640252"},{"key":"ref20","article-title":"Loom: LLVM instrumentation library","year":"2020"},{"key":"ref21","article-title":"Sloccount","year":"2020"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3315568.3329965"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ASEW.2019.00023"},{"key":"ref24","article-title":"Apache benchmark","year":"2019"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1095809.1095826"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516731"},{"key":"ref27","article-title":"Leaked data","year":"2019"},{"key":"ref28","article-title":"The Sony hack","year":"2019"},{"key":"ref29","first-page":"319","article-title":"Trustworthy whole-system provenance for the linux kernel","volume-title":"Proc. 24th USENIX Secur. Symp.","author":"Bates"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420989"},{"key":"ref31","article-title":"Extensions to the C language family","year":"2019"},{"key":"ref32","article-title":"Extensions to the C++ language"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00024"},{"key":"ref34","article-title":"Test generation using symbolic execution","volume-title":"Proc. IARCS Annu. Conf. Found.s Softw. Technol. Theor. Comput. Sci.","author":"Godefroid"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23282"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2867595"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2977016"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3098977"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/11890850_18"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/dsn.2003.1209932"},{"key":"ref41","first-page":"259","article-title":"Selective versioning in a secure disk system","volume-title":"Proc. 17th Conf. Secur. Symp.","author":"Sundararaman"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978398"},{"key":"ref43","article-title":"Enriching intrusion alerts through multi-host causality","volume-title":"Proc. Netw. Distrib. System Secur. Symp.","author":"King"},{"key":"ref44","first-page":"89","article-title":"Intrusion recovery using selective re-execution","volume-title":"Proc. USENIX Conf. Operating Syst. Des. Implementation","author":"Kim"},{"key":"ref45","first-page":"525","article-title":"Eidetic systems","volume-title":"Proc. 11th USENIX Symp. Operating Syst. Des. Implementation","author":"Devecsery"},{"key":"ref46","article-title":"Dynamic taint analysis for automatic detection, analysis, and signaturegeneration of exploits on commodity software","volume-title":"Proc. Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Newsome"},{"key":"ref47","article-title":"Understanding data lifetime via whole system simulation","volume-title":"Proc. 13th Conf. USENIX Secur. Symp.","author":"Chow"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/2018396.2018419"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2006.69"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/2000791.2000792"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134009"},{"key":"ref52","first-page":"1153","article-title":"Harvesting inconsistent security configurations in custom Android roms via differential analysis","volume-title":"Proc. 25th USENIX Secur. Symp.","author":"Aafer"}],"container-title":["IEEE Transactions on Software Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/32\/10103953\/09996963.pdf?arnumber=9996963","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,2]],"date-time":"2024-03-02T11:58:26Z","timestamp":1709380706000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9996963\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,1]]},"references-count":52,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tse.2022.3231242","relation":{},"ISSN":["0098-5589","1939-3520","2326-3881"],"issn-type":[{"value":"0098-5589","type":"print"},{"value":"1939-3520","type":"electronic"},{"value":"2326-3881","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,1]]}}}