{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:43:45Z","timestamp":1750308225514,"version":"3.41.0"},"reference-count":21,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2005,3,1]],"date-time":"2005-03-01T00:00:00Z","timestamp":1109635200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGARCH Comput. Archit. News"],"published-print":{"date-parts":[[2005,3]]},"abstract":"<jats:p>\n            Minos is a microarchitecture that implements Biba's low-water-mark integrity policy on individual words of data. Months of testing have revealed a robust system that stops attacks which corrupt control data to hijack program control flow. The low-water-mark policy is orthogonal to the memory model so that it works with existing software and middleware. The key is that Minos tracks the integrity of all data, but protects control flow by checking this integrity when a program uses the data for control transfer. Existing policies, in contrast, need to differentiate between control and non-control data\n            <jats:italic>a priori.<\/jats:italic>\n            Our implementation of Minos for Red Hat Linux 6.2 on a Pentium-based emulator is a usable Linux system on the network. We have demonstrated that Minos protects against a menagerie of real control data attacks, not just buffer overflows. This paper will detail our security assessments of Minos and other hardware and software mechanisms designed to stop the same class of attacks. We conclude that while Minos is substantially more secure than other approaches, existing C programs lack the semantic information necessary to totally secure their control flow. More details about the implementation of Minos are available in [1].\n          <\/jats:p>","DOI":"10.1145\/1055626.1055634","type":"journal-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T19:28:32Z","timestamp":1131391712000},"page":"48-57","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["A security assessment of the minos architecture"],"prefix":"10.1145","volume":"33","author":[{"given":"Jedidiah R.","family":"Crandall","sequence":"first","affiliation":[{"name":"University of California at Davis"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frederic T.","family":"Chong","sequence":"additional","affiliation":[{"name":"University of California at Davis"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,3]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.26"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_2_1_3_1","unstructured":"K. J. Biba \"Integrity Considerations for Secure Computer Systems \" in MITRE Technical Report TR-3153 Apr 1977.  K. J. Biba \"Integrity Considerations for Secure Computer Systems \" in MITRE Technical Report TR-3153 Apr 1977."},{"key":"e_1_2_1_4_1","volume-title":"Low Water-Mark Integrity Protection for COTS Environments","author":"Fraser T.","year":"2000","unstructured":"T. Fraser , \"LOMAC : Low Water-Mark Integrity Protection for COTS Environments ,\" 2000 . T. Fraser, \"LOMAC: Low Water-Mark Integrity Protection for COTS Environments,\" 2000."},{"key":"e_1_2_1_5_1","unstructured":"Intel \"Press Release 12 March 2002.\"  Intel \"Press Release 12 March 2002.\""},{"key":"e_1_2_1_6_1","volume-title":"Computer Architecture: A Quantitative Approach 3rd. ed","author":"Patterson D. A.","year":"2003","unstructured":"D. A. Patterson and J. L. Hennessy , Computer Architecture: A Quantitative Approach 3rd. ed . San Mateo : Morgan Kaufmann , 2003 . D. A. Patterson and J. L. Hennessy, Computer Architecture: A Quantitative Approach 3rd. ed. San Mateo: Morgan Kaufmann, 2003."},{"key":"e_1_2_1_7_1","first-page":"264","volume-title":"Techniques to reduce the soft error rate of a high-performance microprocessor.\" in Proceedings of the 31st annual International Symposium on Computer Architecture","author":"Weaver C.","year":"2004","unstructured":"C. Weaver , J. Emer , and S. S. Mukherjee , \" Techniques to reduce the soft error rate of a high-performance microprocessor.\" in Proceedings of the 31st annual International Symposium on Computer Architecture , p. 264 , IEEE Computer Society , 2004 . C. Weaver, J. Emer, and S. S. Mukherjee, \"Techniques to reduce the soft error rate of a high-performance microprocessor.\" in Proceedings of the 31st annual International Symposium on Computer Architecture, p. 264, IEEE Computer Society, 2004."},{"key":"e_1_2_1_8_1","unstructured":"\"Bochs: the Open Source IA-32 Emulation Project (Home Page) http:\/\/bochs.sourceforge.net.\"  \"Bochs: the Open Source IA-32 Emulation Project (Home Page) http:\/\/bochs.sourceforge.net.\""},{"key":"e_1_2_1_9_1","unstructured":"\"Intel Optimization Manual Order Number 242816-003 Section 3.4.\"  \"Intel Optimization Manual Order Number 242816-003 Section 3.4.\""},{"key":"e_1_2_1_10_1","unstructured":"CERT \"Vulnerability Note VU 301156.\"  CERT \"Vulnerability Note VU 301156.\""},{"key":"e_1_2_1_11_1","unstructured":"Nergal \"The advanced return-into-lib(c) exploits: PaX case study Phrack 58.\"  Nergal \"The advanced return-into-lib(c) exploits: PaX case study Phrack 58.\""},{"key":"e_1_2_1_12_1","first-page":"63","author":"Cowan C.","year":"1998","unstructured":"C. Cowan , C. Pu , D. Maier , J. Walpole , P. Bakke , S. Beattie , A. Grier , P. Wagle , Q. Zhang , and H. Hinton , \"StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks,\" in Proc. of the 7th Usenix Security Symposium , pp. 63 -- 78 , Jan 1998 . C. Cowan, C. Pu, D. Maier, J. Walpole, P. Bakke, S. Beattie, A. Grier, P. Wagle, Q. Zhang, and H. Hinton, \"StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks,\" in Proc. of the 7th Usenix Security Symposium, pp. 63--78, Jan 1998.","journal-title":"of the 7th Usenix Security Symposium"},{"key":"e_1_2_1_13_1","unstructured":"D. Litchfield \"Defeating the Stack Based Buffer Overflow Prevention Mechanism of Microsoft Windows 2003 Server (http:\/\/www.packetstormsecurity.com\/papers\/bypass\/defeating-w2k3-stack-protection.pdf).\"  D. Litchfield \"Defeating the Stack Based Buffer Overflow Prevention Mechanism of Microsoft Windows 2003 Server (http:\/\/www.packetstormsecurity.com\/papers\/bypass\/defeating-w2k3-stack-protection.pdf).\""},{"key":"e_1_2_1_14_1","unstructured":"\"Security Focus Vulnerability Notes bugtraq id 1387.\"  \"Security Focus Vulnerability Notes bugtraq id 1387.\""},{"key":"e_1_2_1_15_1","unstructured":"scut \"Exploiting Format String Vulnerabilities.\"  scut \"Exploiting Format String Vulnerabilities.\""},{"key":"e_1_2_1_16_1","unstructured":"jp \"Advanced Doug lea's malloc() exploits Phrack 61.\"  jp \"Advanced Doug lea's malloc() exploits Phrack 61.\""},{"key":"e_1_2_1_17_1","unstructured":"National Security Agency \"Final Evaluation Report International Business Machines Corporation Application System 400.\"  National Security Agency \"Final Evaluation Report International Business Machines Corporation Application System 400.\""},{"key":"e_1_2_1_18_1","unstructured":"B. Babayan \"Security www.elbrus.ru\/mcst\/eng\/ SECURE_INFORMATION_SYSTEM_V5_2e.pdf.\"  B. Babayan \"Security www.elbrus.ru\/mcst\/eng\/ SECURE_INFORMATION_SYSTEM_V5_2e.pdf.\""},{"key":"e_1_2_1_19_1","unstructured":"D. Boutcher \"The Linux Kernel on iSeries.\"  D. Boutcher \"The Linux Kernel on iSeries.\""},{"key":"e_1_2_1_20_1","unstructured":"mechanic \"The basics and an introduction to the IBM AS\/400 www.9x.tc.\"  mechanic \"The basics and an introduction to the IBM AS\/400 www.9x.tc.\""},{"key":"e_1_2_1_21_1","unstructured":"securitytracker.com \"SecurityTracker Alert ID: 1005891.\"  securitytracker.com \"SecurityTracker Alert ID: 1005891.\""}],"container-title":["ACM SIGARCH Computer Architecture News"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1055626.1055634","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1055626.1055634","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:27Z","timestamp":1750264287000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1055626.1055634"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,3]]},"references-count":21,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2005,3]]}},"alternative-id":["10.1145\/1055626.1055634"],"URL":"https:\/\/doi.org\/10.1145\/1055626.1055634","relation":{},"ISSN":["0163-5964"],"issn-type":[{"type":"print","value":"0163-5964"}],"subject":[],"published":{"date-parts":[[2005,3]]},"assertion":[{"value":"2005-03-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}