{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:48:14Z","timestamp":1783007294889,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":29,"publisher":"ACM","license":[{"start":{"date-parts":[[2015,12,7]],"date-time":"2015-12-07T00:00:00Z","timestamp":1449446400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2015,12,7]]},"DOI":"10.1145\/2818000.2818039","type":"proceedings-article","created":{"date-parts":[[2015,12,11]],"date-time":"2015-12-11T17:06:08Z","timestamp":1449853568000},"page":"401-410","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":55,"title":["Accurate, Low Cost and Instrumentation-Free Security Audit Logging for Windows"],"prefix":"10.1145","author":[{"given":"Shiqing","family":"Ma","sequence":"first","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kyu Hyung","family":"Lee","sequence":"additional","affiliation":[{"name":"University of Georgia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chung Hwan","family":"Kim","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junghwan","family":"Rhee","sequence":"additional","affiliation":[{"name":"NEC Laboratories America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongyan","family":"Xu","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,12,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Event tracing for windows (etw). http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa363668(v=vs.85).aspx.  Event tracing for windows (etw). http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa363668(v=vs.85).aspx."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2002.1033782"},{"key":"e_1_3_2_1_3_1","volume-title":"NDSS'14","author":"Arp D.","unstructured":"Arp , D. , Spreitzenbarth , M. , Hubner , M. , Gascon , H. , and Rieck , K . Drebin: Effective and explainable detection of android malware in your pocket . In NDSS'14 . Arp, D., Spreitzenbarth, M., Hubner, M., Gascon, H., and Rieck, K. Drebin: Effective and explainable detection of android malware in your pocket. In NDSS'14."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025151"},{"key":"e_1_3_2_1_5_1","volume-title":"SSYM'04","author":"Chow J.","unstructured":"Chow , J. , Pfaff , B. , Garfinkel , T. , Christopher , K. , and Rosenblum , M . Understanding data lifetime via whole system simulation . SSYM'04 . Chow, J., Pfaff, B., Garfinkel, T., Christopher, K., and Rosenblum, M. Understanding data lifetime via whole system simulation. SSYM'04."},{"key":"e_1_3_2_1_6_1","unstructured":"Egele M. Woo M. Chapman P. and Brumley D. Blanket execution: Dynamic similarity testing for program binaries and components. Usenix Security'14.   Egele M. Woo M. Chapman P. and Brumley D. Blanket execution: Dynamic similarity testing for program binaries and components. Usenix Security'14."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2006.09.013"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095826"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629080.1629082"},{"key":"e_1_3_2_1_10_1","volume-title":"NDSS","author":"Jee K.","year":"2012","unstructured":"Jee , K. , Portokalidis , G. , Kemerlis , V. P. , Ghosh , S. , August , D. I. , and Keromytis , A. D . A general approach for efficiently accelerating software-based dynamic data flow tracking on commodity hardware . In NDSS ( 2012 ). Jee, K., Portokalidis, G., Kemerlis, V. P., Ghosh, S., August, D. I., and Keromytis, A. D. A general approach for efficiently accelerating software-based dynamic data flow tracking on commodity hardware. In NDSS (2012)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2006.69"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2151024.2151042"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2591971.2592008"},{"key":"e_1_3_2_1_14_1","volume-title":"OSDI'10","author":"Kim T.","unstructured":"Kim , T. , Wang , X. , Zeldovich , N. , and Kaashoek , M. F . Intrusion recovery using selective re-execution . OSDI'10 . Kim, T., Wang, X., Zeldovich, N., and Kaashoek, M. F. Intrusion recovery using selective re-execution. OSDI'10."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"e_1_3_2_1_16_1","volume-title":"NDSS","author":"King S. T.","year":"2005","unstructured":"King , S. T. , Mao , Z. M. , Lucchetti , D. G. , and Chen , P. M . Enriching intrusion alerts through multi-host causality . In NDSS ( 2005 ). King, S. T., Mao, Z. M., Lucchetti, D. G., and Chen, P. M. Enriching intrusion alerts through multi-host causality. In NDSS (2005)."},{"key":"e_1_3_2_1_17_1","volume-title":"Usernix Security '09","author":"Kolbitsch C.","unstructured":"Kolbitsch , C. , Comparetti , P. M. , Kruegel , C. , Kirda , E. , Zhou , X.-y. , and Wang , X . Effective and efficient malware detection at the end host . Usernix Security '09 . Kolbitsch, C., Comparetti, P. M., Kruegel, C., Kirda, E., Zhou, X.-y., and Wang, X. Effective and efficient malware detection at the end host. Usernix Security '09."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046740"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866314"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516731"},{"key":"e_1_3_2_1_21_1","volume-title":"NDSS","author":"Lee K. H.","year":"2013","unstructured":"Lee , K. H. , Zhang , X. , and Xu , D . High accuracy attack provenance via binary-based execution partition . In NDSS ( 2013 ), Citeseer . Lee, K. H., Zhang, X., and Xu, D. High accuracy attack provenance via binary-based execution partition. In NDSS (2013), Citeseer."},{"key":"e_1_3_2_1_22_1","volume-title":"USENIX'09","author":"Muniswamy-Reddy K.-K.","unstructured":"Muniswamy-Reddy , K.-K. , Braun , U. , Holland , D. A. , Macko , P. , Maclean , D. , Margo , D. , Seltzer , M. , and Smogor , R . Layering in provenance systems . USENIX'09 . Muniswamy-Reddy, K.-K., Braun, U., Holland, D. A., Macko, P., Maclean, D., Margo, D., Seltzer, M., and Smogor, R. Layering in provenance systems. USENIX'09."},{"key":"e_1_3_2_1_23_1","volume-title":"NSDI'12","author":"Nagaraj K.","unstructured":"Nagaraj , K. , Killian , C. , and Neville , J . Structured comparative analysis of systems logs to diagnose performance problems . NSDI'12 . Nagaraj, K., Killian, C., and Neville, J. Structured comparative analysis of systems logs to diagnose performance problems. NSDI'12."},{"key":"e_1_3_2_1_24_1","volume-title":"NDSS","author":"Newsome J.","year":"2005","unstructured":"Newsome , J. , and Song , D. X . Dynamic taint analysis for automatic detection, analysis, and signaturegeneration of exploits on commodity software . In NDSS ( 2005 ). Newsome, J., and Song, D. X. Dynamic taint analysis for automatic detection, analysis, and signaturegeneration of exploits on commodity software. In NDSS (2005)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWIA.2005.9"},{"key":"e_1_3_2_1_26_1","volume-title":"USENIX'09","author":"Tak B. C.","unstructured":"Tak , B. C. , Tang , C. , Zhang , C. , Govindan , S. , Urgaonkar , B. , and Chang , R. N . vpath: precise discovery of request processing paths from black-box observations of thread and network activities . USENIX'09 . Tak, B. C., Tang, C., Zhang, C., Govindan, S., Urgaonkar, B., and Chang, R. N. vpath: precise discovery of request processing paths from black-box observations of thread and network activities. USENIX'09."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629587"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315261"},{"key":"e_1_3_2_1_29_1","volume-title":"DSN'03","author":"Zhu N.","unstructured":"Zhu , N. , and cker Chiueh , T. Design , implementation , and evaluation of repairable file service . DSN'03 . Zhu, N., and cker Chiueh, T. Design, implementation, and evaluation of repairable file service. DSN'03."}],"event":{"name":"ACSAC 2015: 2015 Annual Computer Security Applications Conference","location":"Los Angeles CA USA","acronym":"ACSAC 2015","sponsor":["ACSA Applied Computing Security Assoc"]},"container-title":["Proceedings of the 31st Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2818000.2818039","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2818000.2818039","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T05:43:26Z","timestamp":1750225406000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2818000.2818039"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,12,7]]},"references-count":29,"alternative-id":["10.1145\/2818000.2818039","10.1145\/2818000"],"URL":"https:\/\/doi.org\/10.1145\/2818000.2818039","relation":{},"subject":[],"published":{"date-parts":[[2015,12,7]]},"assertion":[{"value":"2015-12-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}