{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,4]],"date-time":"2026-04-04T02:54:28Z","timestamp":1775271268008,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,4,2]],"date-time":"2017-04-02T00:00:00Z","timestamp":1491091200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,4,2]]},"DOI":"10.1145\/3052973.3053029","type":"proceedings-article","created":{"date-parts":[[2017,3,31]],"date-time":"2017-03-31T12:22:54Z","timestamp":1490962974000},"page":"167-178","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":30,"title":["PrivWatcher"],"prefix":"10.1145","author":[{"given":"Quan","family":"Chen","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmed M.","family":"Azab","sequence":"additional","affiliation":[{"name":"Samsung Research America, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guruprasad","family":"Ganesh","sequence":"additional","affiliation":[{"name":"Samsung Research America, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Ning","sequence":"additional","affiliation":[{"name":"Samsung Research America, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,4,2]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"ApacheBench. https:\/\/httpd.apache.org\/.  ApacheBench. https:\/\/httpd.apache.org\/."},{"key":"e_1_3_2_1_2_1","unstructured":"CVE-2013--2596. http:\/\/www.cvedetails.com\/cve\/CVE-2013--2596.  CVE-2013--2596. http:\/\/www.cvedetails.com\/cve\/CVE-2013--2596."},{"key":"e_1_3_2_1_3_1","unstructured":"CVE-2013--6282. http:\/\/www.cvedetails.com\/cve\/CVE-2013--6282.  CVE-2013--6282. http:\/\/www.cvedetails.com\/cve\/CVE-2013--6282."},{"key":"e_1_3_2_1_4_1","unstructured":"CVE-2014--3153. http:\/\/www.cvedetails.com\/cve\/CVE-2014--3153.  CVE-2014--3153. http:\/\/www.cvedetails.com\/cve\/CVE-2014--3153."},{"key":"e_1_3_2_1_5_1","unstructured":"CVE-2015--3636. http:\/\/www.cvedetails.com\/cve\/CVE-2015--3636.  CVE-2015--3636. http:\/\/www.cvedetails.com\/cve\/CVE-2015--3636."},{"key":"e_1_3_2_1_6_1","unstructured":"CVE-2016-0728. http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=2016-0728.  CVE-2016-0728. http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=2016-0728."},{"key":"e_1_3_2_1_7_1","unstructured":"iovyroot. https:\/\/github.com\/dosomder\/iovyroot.  iovyroot. https:\/\/github.com\/dosomder\/iovyroot."},{"key":"e_1_3_2_1_8_1","unstructured":"kcbench. https:\/\/github.com\/knurd\/kcbench.  kcbench. https:\/\/github.com\/knurd\/kcbench."},{"key":"e_1_3_2_1_9_1","unstructured":"Kernel address space layout randomization. https:\/\/lwn.net\/Articles\/569635\/.  Kernel address space layout randomization. https:\/\/lwn.net\/Articles\/569635\/."},{"key":"e_1_3_2_1_10_1","unstructured":"KNOXout. http:\/\/www.vsecgroup.com\/single-post\/2016\/09\/16\/KNOXout--Bypassing-Samsung-KNOX.  KNOXout. http:\/\/www.vsecgroup.com\/single-post\/2016\/09\/16\/KNOXout--Bypassing-Samsung-KNOX."},{"key":"e_1_3_2_1_11_1","unstructured":"PingPong Root. http:\/\/pingpongroot.co\/.  PingPong Root. http:\/\/pingpongroot.co\/."},{"key":"e_1_3_2_1_12_1","unstructured":"QuadRooter. https:\/\/media.defcon.org\/DEF%20CON%2024\/DEF%20CON%2024%20presentations\/DEFCON-24-Adam-Donenfeld-Stumping-The-Mobile-Chipset.pdf.  QuadRooter. https:\/\/media.defcon.org\/DEF%20CON%2024\/DEF%20CON%2024%20presentations\/DEFCON-24-Adam-Donenfeld-Stumping-The-Mobile-Chipset.pdf."},{"key":"e_1_3_2_1_13_1","unstructured":"The SLUB allocator. http:\/\/lwn.net\/Articles\/229984.  The SLUB allocator. http:\/\/lwn.net\/Articles\/229984."},{"key":"e_1_3_2_1_14_1","unstructured":"UnixBench. https:\/\/github.com\/kdlucas\/byte-unixbench.  UnixBench. https:\/\/github.com\/kdlucas\/byte-unixbench."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"e_1_3_2_1_17_1","unstructured":"Android. System and kernel security. http:\/\/source.android.com\/devices\/tech\/security\/overview\/kernel-security.html.  Android. System and kernel security. http:\/\/source.android.com\/devices\/tech\/security\/overview\/kernel-security.html."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.50"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866313"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.29"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653729"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/1298455.1298470"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720278"},{"key":"e_1_3_2_1_25_1","volume-title":"Usenix Security","volume":"5","author":"Chen S.","year":"2005","unstructured":"S. Chen , J. Xu , E. C. Sezer , P. Gauriar , and R. K. Iyer . Non-control-data attacks are realistic threats . In Usenix Security , volume 5 , 2005 . S. Chen, J. Xu, E. C. Sezer, P. Gauriar, and R. K. Iyer. Non-control-data attacks are realistic threats. In Usenix Security, volume 5, 2005."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23156"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.26"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"key":"e_1_3_2_1_29_1","first-page":"401","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Davi L.","year":"2014","unstructured":"L. Davi , A.-R. Sadeghi , D. Lehmann , and F. Monrose . Stitching the gadgets: On the ineffectiveness of coarse-grained control-flow integrity protection . In 23rd USENIX Security Symposium (USENIX Security 14) , pages 401 -- 416 , 2014 . L. Davi, A.-R. Sadeghi, D. Lehmann, and F. Monrose. Stitching the gadgets: On the ineffectiveness of coarse-grained control-flow integrity protection. In 23rd USENIX Security Symposium (USENIX Security 14), pages 401--416, 2014."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653730"},{"key":"e_1_3_2_1_31_1","volume-title":"runtime prevention of return-oriented programming attacks","author":"Fratric I.","year":"2012","unstructured":"I. Fratric . ROPGuard : runtime prevention of return-oriented programming attacks ( 2012 ). I. Fratric. ROPGuard: runtime prevention of return-oriented programming attacks (2012)."},{"key":"e_1_3_2_1_32_1","first-page":"179","volume-title":"2016 IEEE European Symposium on","author":"Ge X.","year":"2016","unstructured":"X. Ge , N. Talele , M. Payer , and T. Jaeger . Fine-grained control-flow integrity for kernel software. In Security and Privacy (EuroS&P) , 2016 IEEE European Symposium on , pages 179 -- 194 . IEEE, 2016 . X. Ge, N. Talele, M. Payer, and T. Jaeger. Fine-grained control-flow integrity for kernel software. In Security and Privacy (EuroS&P), 2016 IEEE European Symposium on, pages 179--194. IEEE, 2016."},{"key":"e_1_3_2_1_33_1","volume-title":"Sprobes: Enforcing kernel code integrity on the TrustZone architecture. arXiv preprint arXiv:1410.7747","author":"Ge X.","year":"2014","unstructured":"X. Ge , H. Vijayakumar , and T. Jaeger . Sprobes: Enforcing kernel code integrity on the TrustZone architecture. arXiv preprint arXiv:1410.7747 , 2014 . X. Ge, H. Vijayakumar, and T. Jaeger. Sprobes: Enforcing kernel code integrity on the TrustZone architecture. arXiv preprint arXiv:1410.7747, 2014."},{"key":"e_1_3_2_1_34_1","first-page":"259","volume-title":"USENIX Annual Technical Conference, FREENIX Track","author":"Gr\u00fcnbacher A.","year":"2003","unstructured":"A. Gr\u00fcnbacher . POSIX access control lists on Linux . In USENIX Annual Technical Conference, FREENIX Track , pages 259 -- 272 , 2003 . A. Gr\u00fcnbacher. POSIX access control lists on Linux. In USENIX Annual Technical Conference, FREENIX Track, pages 259--272, 2003."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.62"},{"key":"e_1_3_2_1_36_1","volume-title":"Intel 64 and and IA-32 architectures software developer's manual","unstructured":"Intel. Intel 64 and and IA-32 architectures software developer's manual , Volume 2 . Intel. Intel 64 and and IA-32 architectures software developer's manual, Volume 2."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"key":"e_1_3_2_1_38_1","volume-title":"USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Kuznetsov V.","year":"2014","unstructured":"V. Kuznetsov , L. Szekeres , M. Payer , G. Candea , R. Sekar , and D. Song . Code-pointer integrity . In USENIX Symposium on Operating Systems Design and Implementation (OSDI) , 2014 . V. Kuznetsov, L. Szekeres, M. Payer, G. Candea, R. Sekar, and D. Song. Code-pointer integrity. In USENIX Symposium on Operating Systems Design and Implementation (OSDI), 2014."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.5555\/977395.977673"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755913.1755934"},{"key":"e_1_3_2_1_41_1","volume-title":"Network and Distributed System Security Symposium (NDSS)","author":"Lin Z.","year":"2011","unstructured":"Z. Lin , J. Rhee , X. Zhang , D. Xu , and X. Jiang . SigGraph: Brute force scanning of kernel data structure instances using graph-based signatures . In Network and Distributed System Security Symposium (NDSS) , 2011 . Z. Lin, J. Rhee, X. Zhang, D. Xu, and X. Jiang. SigGraph: Brute force scanning of kernel data structure instances using graph-based signatures. In Network and Distributed System Security Symposium (NDSS), 2011."},{"key":"e_1_3_2_1_42_1","first-page":"243","volume-title":"USENIX Security Symposium","author":"Litty L.","year":"2008","unstructured":"L. Litty , H. A. Lagar-Cavilla , and D. Lie . Hypervisor support for identifying covertly executing binaries . In USENIX Security Symposium , pages 243 -- 258 , 2008 . L. Litty, H. A. Lagar-Cavilla, and D. Lie. Hypervisor support for identifying covertly executing binaries. In USENIX Security Symposium, pages 243--258, 2008."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/647478.727796"},{"key":"e_1_3_2_1_44_1","first-page":"1","article-title":"Efficient and transparent ROP mitigation","volume":"1","author":"Pappas V.","year":"2012","unstructured":"V. Pappas . kBouncer : Efficient and transparent ROP mitigation . Apr , 1 : 1 -- 2 , 2012 . V. Pappas. kBouncer: Efficient and transparent ROP mitigation. Apr, 1:1--2, 2012.","journal-title":"Apr"},{"key":"e_1_3_2_1_45_1","first-page":"447","volume-title":"USENIX Security","author":"Pappas V.","year":"2013","unstructured":"V. Pappas , M. Polychronakis , and A. D. Keromytis . Transparent ROP exploit mitigation using indirect branch tracing . In USENIX Security , pages 447 -- 462 , 2013 . V. Pappas, M. Polychronakis, and A. D. Keromytis. Transparent ROP exploit mitigation using indirect branch tracing. In USENIX Security, pages 447--462, 2013."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.24"},{"key":"e_1_3_2_1_47_1","volume-title":"Usenix Security","author":"Petroni N. L.","year":"2006","unstructured":"N. L. Petroni Jr , T. Fraser , A. Walters , and W. A. Arbaugh . An architecture for specification-based detection of semantic integrity violations in kernel dynamic data . In Usenix Security , 2006 . N. L. Petroni Jr, T. Fraser, A. Walters, and W. A. Arbaugh. An architecture for specification-based detection of semantic integrity violations in kernel dynamic data. In Usenix Security, 2006."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315260"},{"key":"e_1_3_2_1_49_1","volume-title":"White paper: An overview of Samsung KNOX","year":"2013","unstructured":"Samsung. White paper: An overview of Samsung KNOX , 2013 . Samsung. White paper: An overview of Samsung KNOX, 2013."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1323293.1294294"},{"issue":"43","key":"e_1_3_2_1_51_1","first-page":"139","article-title":"Implementing SELinux as a Linux security module","volume":"1","author":"Smalley S.","year":"2001","unstructured":"S. Smalley , C. Vance , and W. Salamon . Implementing SELinux as a Linux security module . NAI Labs Report , 1 ( 43 ): 139 , 2001 . S. Smalley, C. Vance, and W. Salamon. Implementing SELinux as a Linux security module. NAI Labs Report, 1(43):139, 2001.","journal-title":"NAI Labs Report"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2421012"},{"key":"e_1_3_2_1_54_1","first-page":"347","volume-title":"Proceedings of the 2015 USENIX Conference on Usenix Annual Technical Conference","author":"Wang X.","year":"2015","unstructured":"X. Wang , Y. Chen , Z. Wang , Y. Qi , and Y. Zhou . SecPod: a framework for virtualization-based security systems . In Proceedings of the 2015 USENIX Conference on Usenix Annual Technical Conference , pages 347 -- 360 . USENIX Association , 2015 . X. Wang, Y. Chen, Z. Wang, Y. Qi, and Y. Zhou. SecPod: a framework for virtualization-based security systems. In Proceedings of the 2015 USENIX Conference on Usenix Annual Technical Conference, pages 347--360. USENIX Association, 2015."},{"key":"e_1_3_2_1_55_1","volume-title":"USENIX Security Symposium","author":"Wright C.","year":"2002","unstructured":"C. Wright , C. Cowan , S. Smalley , J. Morris , and G. Kroah-Hartman . Linux security modules: General security support for the Linux kernel . In USENIX Security Symposium , 2002 . C. Wright, C. Cowan, S. Smalley, J. Morris, and G. Kroah-Hartman. Linux security modules: General security support for the Linux kernel. In USENIX Security Symposium, 2002."},{"key":"e_1_3_2_1_56_1","volume-title":"9th USENIX Workshop on Offensive Technologies (WOOT 15)","author":"Xu W.","year":"2015","unstructured":"W. Xu and Y. Fu . Own your Android! yet another universal root . In 9th USENIX Workshop on Offensive Technologies (WOOT 15) , 2015 . W. Xu and Y. Fu. Own your Android! yet another universal root. In 9th USENIX Workshop on Offensive Technologies (WOOT 15), 2015."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720279"}],"event":{"name":"ASIA CCS '17: ACM Asia Conference on Computer and Communications Security","location":"Abu Dhabi United Arab Emirates","acronym":"ASIA CCS '17","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3052973.3053029","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3052973.3053029","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:36:58Z","timestamp":1750217818000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3052973.3053029"}},"subtitle":["Non-bypassable Monitoring and Protection of Process Credentials from Memory Corruption Attacks"],"short-title":[],"issued":{"date-parts":[[2017,4,2]]},"references-count":57,"alternative-id":["10.1145\/3052973.3053029","10.1145\/3052973"],"URL":"https:\/\/doi.org\/10.1145\/3052973.3053029","relation":{},"subject":[],"published":{"date-parts":[[2017,4,2]]},"assertion":[{"value":"2017-04-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}