{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T19:23:10Z","timestamp":1781724190286,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":126,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,4,23]],"date-time":"2017-04-23T00:00:00Z","timestamp":1492905600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,4,23]]},"DOI":"10.1145\/3064176.3064216","type":"proceedings-article","created":{"date-parts":[[2017,4,17]],"date-time":"2017-04-17T12:27:04Z","timestamp":1492432024000},"page":"420-436","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":42,"title":["kR^X"],"prefix":"10.1145","author":[{"given":"Marios","family":"Pomonis","sequence":"first","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Theofilos","family":"Petsios","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[{"name":"Stony Brook University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vasileios P.","family":"Kemerlis","sequence":"additional","affiliation":[{"name":"Brown University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2017,4,23]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"CVE-2010-3437 September 2010.  CVE-2010-3437 September 2010."},{"key":"e_1_3_2_1_2_1","volume-title":"July","author":"Analysis","year":"2011","unstructured":"Analysis of jailbreakme v3 font exploit. https:\/\/goo.gl\/RGsgzc , July 2011 . Analysis of jailbreakme v3 font exploit. https:\/\/goo.gl\/RGsgzc, July 2011."},{"key":"e_1_3_2_1_3_1","unstructured":"CVE-2013-2094 February 2013.  CVE-2013-2094 February 2013."},{"key":"e_1_3_2_1_4_1","unstructured":"CVE-2013-6282 October 2013.  CVE-2013-6282 October 2013."},{"key":"e_1_3_2_1_5_1","unstructured":"CVE-2015-3036 April 2015.  CVE-2015-3036 April 2015."},{"key":"e_1_3_2_1_6_1","unstructured":"CVE-2015-3290 April 2015.  CVE-2015-3290 April 2015."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_2_1_8_1","volume-title":"June","author":"Bittau Andrea","year":"2013","unstructured":"Andrea Bittau . Linux Kernel &lt; 3.8.9 (x86_64) 'perf_swevent_init' Privilege Escalation . https:\/\/www.exploit-db.com\/exploits\/26131\/ , June 2013 . Andrea Bittau. Linux Kernel &lt; 3.8.9 (x86_64) 'perf_swevent_init' Privilege Escalation. https:\/\/www.exploit-db.com\/exploits\/26131\/, June 2013."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_3_2_1_10_1","first-page":"433","volume-title":"Proc. of USENIX Sec","author":"Backes M.","year":"2014","unstructured":"M. Backes and S. N\u00fcrnberger . Oxymoron: Making Fine-Grained Memory Randomization Practical by Allowing Code Sharing . In Proc. of USENIX Sec , pages 433 -- 447 , 2014 . M. Backes and S. N\u00fcrnberger. Oxymoron: Making Fine-Grained Memory Randomization Practical by Allowing Code Sharing. In Proc. of USENIX Sec, pages 433--447, 2014."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660378"},{"key":"e_1_3_2_1_12_1","first-page":"423","volume-title":"Yassour. The Turtles Project: Design and Implementation of Nested Virtualization. In Proc. of USENIX OSDI","author":"Ben-Yehuda M.","year":"2010","unstructured":"M. Ben-Yehuda , M. D. Day , Z. Dubitzky , M. Factor , N. Har'El , A. Gordon , A. Liguori , O. Wasserman , and B.- A. Yassour. The Turtles Project: Design and Implementation of Nested Virtualization. In Proc. of USENIX OSDI , pages 423 -- 436 , 2010 . M. Ben-Yehuda, M. D. Day, Z. Dubitzky, M. Factor, N. Har'El, A. Gordon, A. Liguori, O. Wasserman, and B.-A. Yassour. The Turtles Project: Design and Implementation of Nested Virtualization. In Proc. of USENIX OSDI, pages 423--436, 2010."},{"key":"e_1_3_2_1_13_1","first-page":"255","volume-title":"Proc. of USENIX Sec","author":"Bhatkar S.","year":"2005","unstructured":"S. Bhatkar , R. Sekar , and D. C. DuVarney . Efficient Techniques for Comprehensive Protection from Memory Error Exploits . In Proc. of USENIX Sec , pages 255 -- 270 , 2005 . S. Bhatkar, R. Sekar, and D. C. DuVarney. Efficient Techniques for Comprehensive Protection from Memory Error Exploits. In Proc. of USENIX Sec, pages 255--270, 2005."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813691"},{"key":"e_1_3_2_1_15_1","first-page":"87","volume-title":"Proc. of USENIX Summer","author":"Bonwick J.","year":"1994","unstructured":"J. Bonwick . The Slab Allocator: An Object-Caching Kernel Memory Allocator . In Proc. of USENIX Summer , pages 87 -- 98 , 1994 . J. Bonwick. The Slab Allocator: An Object-Caching Kernel Memory Allocator. In Proc. of USENIX Summer, pages 87--98, 1994."},{"key":"e_1_3_2_1_16_1","volume-title":"January","author":"Bovet D. P.","year":"2013","unstructured":"D. P. Bovet . Special sections in Linux binaries. https:\/\/lwn.net\/Articles\/531148\/ , January 2013 . D. P. Bovet. Special sections in Linux binaries. https:\/\/lwn.net\/Articles\/531148\/, January 2013."},{"key":"e_1_3_2_1_17_1","first-page":"842","volume-title":"Understanding the Linux Kernel","author":"Bovet D. P.","year":"2005","unstructured":"D. P. Bovet and M. Cesati . Understanding the Linux Kernel , chapter Modules, pages 842 -- 851 . O'Reilly Media , 3 rd edition, 2005 . D. P. Bovet and M. Cesati. Understanding the Linux Kernel, chapter Modules, pages 842--851. O'Reilly Media, 3rd edition, 2005.","edition":"3"},{"key":"e_1_3_2_1_18_1","volume-title":"March","author":"Spengler Brad","year":"2014","unstructured":"Brad Spengler and Sorbo. Linux perf_swevent_init Privilege Escalation. https:\/\/goo.gl\/eLgE48 , March 2014 . Brad Spengler and Sorbo. Linux perf_swevent_init Privilege Escalation. https:\/\/goo.gl\/eLgE48, March 2014."},{"key":"e_1_3_2_1_19_1","volume-title":"Sadeghi. Leakage-Resilient Layout Randomization for Mobile Devices. In Proc. of NDSS","author":"Braden K.","year":"2016","unstructured":"K. Braden , S. Crane , L. Davi , M. Franz , P. Larsen , C. Liebchen , and A.- R. Sadeghi. Leakage-Resilient Layout Randomization for Mobile Devices. In Proc. of NDSS , 2016 . K. Braden, S. Crane, L. Davi, M. Franz, P. Larsen, C. Liebchen, and A.-R. Sadeghi. Leakage-Resilient Layout Randomization for Mobile Devices. In Proc. of NDSS, 2016."},{"key":"e_1_3_2_1_20_1","first-page":"385","volume-title":"Proc. of USENIX Sec","author":"Carlini N.","year":"2014","unstructured":"N. Carlini and D. Wagner . ROP is Still Dangerous: Breaking Modern Defenses . In Proc. of USENIX Sec , pages 385 -- 399 , 2014 . N. Carlini and D. Wagner. ROP is Still Dangerous: Breaking Modern Defenses. In Proc. of USENIX Sec, pages 385--399, 2014."},{"key":"e_1_3_2_1_21_1","first-page":"161","volume-title":"Proc. of USENIX Sec","author":"Carlini N.","year":"2015","unstructured":"N. Carlini , A. Barresi , M. Payer , D. Wagner , and T. R. Gross . Control-Flow Bending: On the Effectiveness of Control-Flow Integrity . In Proc. of USENIX Sec , pages 161 -- 176 , 2015 . N. Carlini, A. Barresi, M. Payer, D. Wagner, and T. R. Gross. Control-Flow Bending: On the Effectiveness of Control-Flow Integrity. In Proc. of USENIX Sec, pages 161--176, 2015."},{"key":"e_1_3_2_1_22_1","first-page":"147","volume-title":"Proc. of USENIX OSDI","author":"Castro M.","year":"2006","unstructured":"M. Castro , M. Costa , and T. Harris . Securing software by enforcing data-flow integrity . In Proc. of USENIX OSDI , pages 147 -- 160 , 2006 . M. Castro, M. Costa, and T. Harris. Securing software by enforcing data-flow integrity. In Proc. of USENIX OSDI, pages 147--160, 2006."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866370"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813671"},{"key":"e_1_3_2_1_25_1","unstructured":"K. Cook. Kernel Self Protection Project. https:\/\/goo.gl\/KsN0t8.  K. Cook. Kernel Self Protection Project. https:\/\/goo.gl\/KsN0t8."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1463891.1463912"},{"key":"e_1_3_2_1_27_1","volume-title":"May","author":"Corbet J.","year":"2009","unstructured":"J. Corbet . An updated guide to debugfs. https:\/\/lwn.net\/Articles\/334546\/ , May 2009 . J. Corbet. An updated guide to debugfs. https:\/\/lwn.net\/Articles\/334546\/, May 2009."},{"key":"e_1_3_2_1_28_1","volume-title":"October","author":"Corbet J.","year":"2012","unstructured":"J. Corbet . Supervisor mode access prevention. https:\/\/lwn.net\/Articles\/517475\/ , October 2012 . J. Corbet. Supervisor mode access prevention. https:\/\/lwn.net\/Articles\/517475\/, October 2012."},{"key":"e_1_3_2_1_29_1","volume-title":"May","author":"Corbet J.","year":"2014","unstructured":"J. Corbet . BPF : the universal in-kernel virtual machine. https:\/\/lwn.net\/Articles\/599755\/ , May 2014 . J. Corbet. BPF: the universal in-kernel virtual machine. https:\/\/lwn.net\/Articles\/599755\/, May 2014."},{"key":"e_1_3_2_1_30_1","volume-title":"January","author":"Corbet J.","year":"2014","unstructured":"J. Corbet . Supporting Intel MPX in Linux . https:\/\/lwn.net\/Articles\/582712\/ , January 2014 . J. Corbet. Supporting Intel MPX in Linux. https:\/\/lwn.net\/Articles\/582712\/, January 2014."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535813.2535824"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.52"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813682"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.26"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"key":"e_1_3_2_1_36_1","first-page":"401","volume-title":"Proc. of USENIX Sec","author":"Davi L.","year":"2014","unstructured":"L. Davi , A.-R. Sadeghi , D. Lehmann , and F. Monrose . Stitching the Gadgets: On the Ineffectiveness of Coarse-Grained Control-Flow Integrity Protection . In Proc. of USENIX Sec , pages 401 -- 416 , 2014 . L. Davi, A.-R. Sadeghi, D. Lehmann, and F. Monrose. Stitching the Gadgets: On the Ineffectiveness of Coarse-Grained Control-Flow Integrity Protection. In Proc. of USENIX Sec, pages 401--416, 2014."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23262"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2484313.2484351"},{"key":"e_1_3_2_1_39_1","volume-title":"August","author":"Designer S.","year":"1997","unstructured":"S. Designer . Getting around non-executable stack (and fix). http:\/\/seclists.org\/bugtraq\/1997\/Aug\/63 , August 1997 . S. Designer. Getting around non-executable stack (and fix). http:\/\/seclists.org\/bugtraq\/1997\/Aug\/63, August 1997."},{"key":"e_1_3_2_1_40_1","volume-title":"October","author":"Edge J.","year":"2013","unstructured":"J. Edge . Kernel address space layout randomization. https:\/\/lwn.net\/Articles\/569635\/ , October 2013 . J. Edge. Kernel address space layout randomization. https:\/\/lwn.net\/Articles\/569635\/, October 2013."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517349.2522720"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813646"},{"key":"e_1_3_2_1_43_1","first-page":"1","year":"2020","unstructured":"Exploit Database. EBD- 2020 1 , August 2012. Exploit Database. EBD-20201, August 2012.","journal-title":"Exploit Database. EBD-"},{"key":"e_1_3_2_1_44_1","unstructured":"Exploit Database. EBD-31346 February 2014.  Exploit Database. EBD-31346 February 2014."},{"key":"e_1_3_2_1_45_1","unstructured":"Exploit Database. EBD-33516 May 2014.  Exploit Database. EBD-33516 May 2014."},{"key":"e_1_3_2_1_46_1","volume-title":"Intel 386 and AMD x86-64 Options. https:\/\/goo.gl\/38gK86","author":"GCC","unstructured":"GCC online documentation. Intel 386 and AMD x86-64 Options. https:\/\/goo.gl\/38gK86 . GCC online documentation. Intel 386 and AMD x86-64 Options. https:\/\/goo.gl\/38gK86."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.24"},{"key":"e_1_3_2_1_48_1","unstructured":"J. Geffner. VENOM: Virtualized Environment Neglected Operations Manipulation. http:\/\/venom.crowdstrike.com May 2015.  J. Geffner. VENOM: Virtualized Environment Neglected Operations Manipulation. http:\/\/venom.crowdstrike.com May 2015."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382214"},{"key":"e_1_3_2_1_50_1","volume-title":"January","author":"Gillespie M.","year":"2015","unstructured":"M. Gillespie . Best Practices for Paravirtualization Enhancements from Intel\u00ae Virtualization Technology : EPT and VT-d. https:\/\/goo.gl\/LLlAZK , January 2015 . M. Gillespie. Best Practices for Paravirtualization Enhancements from Intel\u00ae Virtualization Technology: EPT and VT-d. https:\/\/goo.gl\/LLlAZK, January 2015."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/2699026.2699107"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2016.7860485"},{"key":"e_1_3_2_1_53_1","first-page":"475","volume-title":"Proc. of USENIX Sec","author":"Giuffrida C.","year":"2012","unstructured":"C. Giuffrida , A. Kuijsten , and A. S. Tanenbaum . Enhanced Operating System Security Through Efficient and Finegrained Address Space Randomization . In Proc. of USENIX Sec , pages 475 -- 490 , 2012 . C. Giuffrida, A. Kuijsten, and A. S. Tanenbaum. Enhanced Operating System Security Through Efficient and Finegrained Address Space Randomization. In Proc. of USENIX Sec, pages 475--490, 2012."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.43"},{"key":"e_1_3_2_1_55_1","first-page":"417","volume-title":"Proc. of USENIX Sec","author":"G\u00f6kta\u015f E.","year":"2014","unstructured":"E. G\u00f6kta\u015f , E. Athanasopoulos , M. Polychronakis , H. Bos , and G. Portokalidis . Size Does Matter: Why Using Gadget-Chain Length to Prevent Code-Reuse Attacks is Hard . In Proc. of USENIX Sec , pages 417 -- 432 , 2014 . E. G\u00f6kta\u015f, E. Athanasopoulos, M. Polychronakis, H. Bos, and G. Portokalidis. Size Does Matter: Why Using Gadget-Chain Length to Prevent Code-Reuse Attacks is Hard. In Proc. of USENIX Sec, pages 417--432, 2014."},{"key":"e_1_3_2_1_56_1","volume-title":"May","author":"Hansen D.","year":"2015","unstructured":"D. Hansen . [RFC] x86 : Memory protection keys. https:\/\/lwn.net\/Articles\/643617\/ , May 2015 . D. Hansen. [RFC] x86: Memory protection keys. https:\/\/lwn.net\/Articles\/643617\/, May 2015."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.39"},{"key":"e_1_3_2_1_58_1","first-page":"384","volume-title":"Proc. of USENIX Sec","author":"Hund R.","year":"2009","unstructured":"R. Hund , T. Holz , and F. C. Freiling . Return-Oriented Rootkits: Bypassing Kernel Code Integrity Protection Mechanisms . In Proc. of USENIX Sec , pages 384 -- 398 , 2009 . R. Hund, T. Holz, and F. C. Freiling. Return-Oriented Rootkits: Bypassing Kernel Code Integrity Protection Mechanisms. In Proc. of USENIX Sec, pages 384--398, 2009."},{"key":"e_1_3_2_1_59_1","volume-title":"April","author":"Intel Corporation","year":"2015","unstructured":"Intel Corporation . Intel\u00ae 64 and IA-32 Architectures Software Developer's Manual , April 2015 . Intel Corporation. Intel\u00ae 64 and IA-32 Architectures Software Developer's Manual, April 2015."},{"key":"e_1_3_2_1_60_1","volume-title":"January","author":"Intel Corporation","year":"2016","unstructured":"Intel Corporation . Intel\u00ae Memory Protection Extensions Enabling Guide , January 2016 . Intel Corporation. Intel\u00ae Memory Protection Extensions Enabling Guide, January 2016."},{"key":"e_1_3_2_1_61_1","volume-title":"October","author":"Intel\u00ae OS","year":"2013","unstructured":"Intel\u00ae OS Guard (SMEP). Intel\u00ae Xeon\u00ae Processor E5-2600 V2 Product Family Technical Overview. https:\/\/goo.gl\/mS5Ile , October 2013 . Intel\u00ae OS Guard (SMEP). Intel\u00ae Xeon\u00ae Processor E5-2600 V2 Product Family Technical Overview. https:\/\/goo.gl\/mS5Ile, October 2013."},{"key":"e_1_3_2_1_62_1","first-page":"459","volume-title":"Proc. of USENIX Sec","author":"Kemerlis V. P.","year":"2012","unstructured":"V. P. Kemerlis , G. Portokalidis , and A. D. Keromytis . kGuard: Lightweight Kernel Protection against Return-to-user Attacks . In Proc. of USENIX Sec , pages 459 -- 474 , 2012 . V. P. Kemerlis, G. Portokalidis, and A. D. Keromytis. kGuard: Lightweight Kernel Protection against Return-to-user Attacks. In Proc. of USENIX Sec, pages 459--474, 2012."},{"key":"e_1_3_2_1_63_1","first-page":"957","volume-title":"Proc. of USENIX Sec","author":"Kemerlis V. P.","year":"2014","unstructured":"V. P. Kemerlis , M. Polychronakis , and A. D. Keromytis . ret2dir: Rethinking Kernel Isolation . In Proc. of USENIX Sec , pages 957 -- 972 , 2014 . V. P. Kemerlis, M. Polychronakis, and A. D. Keromytis. ret2dir: Rethinking Kernel Isolation. In Proc. of USENIX Sec, pages 957--972, 2014."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.9"},{"key":"e_1_3_2_1_65_1","first-page":"203","volume-title":"Files. In Proc. of USENIX Summer","author":"Killian T. J.","year":"1984","unstructured":"T. J. Killian . Processes as Files. In Proc. of USENIX Summer , pages 203 -- 207 , 1984 . T. J. Killian. Processes as Files. In Proc. of USENIX Summer, pages 203--207, 1984."},{"key":"e_1_3_2_1_66_1","volume-title":"July","author":"Kleen A.","year":"2004","unstructured":"A. Kleen . Memory Layout on amd64 Linux. https:\/\/goo.gl\/BtvguP , July 2004 . A. Kleen. Memory Layout on amd64 Linux. https:\/\/goo.gl\/BtvguP, July 2004."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/143365.143508"},{"key":"e_1_3_2_1_68_1","unstructured":"M. Krause. CVE Requests (maybe): Linux kernel: various info leaks some NULL ptr derefs. http:\/\/www.openwall.com\/lists\/oss-security\/2013\/03\/05\/13 March 2013.  M. Krause. CVE Requests (maybe): Linux kernel: various info leaks some NULL ptr derefs. http:\/\/www.openwall.com\/lists\/oss-security\/2013\/03\/05\/13 March 2013."},{"key":"e_1_3_2_1_69_1","first-page":"263","volume-title":"Proc. of OLS","author":"Kroah-Hartman G.","year":"2003","unstructured":"G. Kroah-Hartman . udev -- A Userspace Implementation of devfs . In Proc. of OLS , pages 263 -- 271 , 2003 . G. Kroah-Hartman. udev -- A Userspace Implementation of devfs. In Proc. of OLS, pages 263--271, 2003."},{"key":"e_1_3_2_1_70_1","first-page":"147","volume-title":"Code-Pointer Integrity. In Proc. of USENIX OSDI","author":"Kuznetsov V.","year":"2014","unstructured":"V. Kuznetsov , L. Szekeres , M. Payer , G. Candea , R. Sekar , and D. Song . Code-Pointer Integrity. In Proc. of USENIX OSDI , pages 147 -- 163 , 2014 . V. Kuznetsov, L. Szekeres, M. Payer, G. Candea, R. Sekar, and D. Song. Code-Pointer Integrity. In Proc. of USENIX OSDI, pages 147--163, 2014."},{"key":"e_1_3_2_1_71_1","volume-title":"Hackfest","author":"Larkin M.","year":"2015","unstructured":"M. Larkin . Kernel W^X Improvements In Open BSD. In Hackfest , 2015 . M. Larkin. Kernel W^X Improvements In OpenBSD. In Hackfest, 2015."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.25"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2810121"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755913.1755934"},{"key":"e_1_3_2_1_75_1","volume-title":"July","author":"Liakh S.","year":"2009","unstructured":"S. Liakh . NX protection for kernel data. https:\/\/lwn.net\/Articles\/342266\/ , July 2009 . S. Liakh. NX protection for kernel data. https:\/\/lwn.net\/Articles\/342266\/, July 2009."},{"key":"e_1_3_2_1_76_1","unstructured":"Linux Cross Reference. Linux kernel release 3.19. http:\/\/lxr.free-electrons.com\/source\/arch\/x86\/kernel\/cpu\/perf_event_intel_uncore_snb.c?v=3.19#L565.  Linux Cross Reference. Linux kernel release 3.19. http:\/\/lxr.free-electrons.com\/source\/arch\/x86\/kernel\/cpu\/perf_event_intel_uncore_snb.c?v=3.19#L565."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813690"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813694"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23173"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978366"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"e_1_3_2_1_82_1","unstructured":"M. Matz J. Hubi\u010dka A. Jaeger and M. Mitchell. System V Application Binary Interface. http:\/\/www.x86-64.org\/documentation\/abi.pdf October 2013.  M. Matz J. Hubi\u010dka A. Jaeger and M. Mitchell. System V Application Binary Interface. http:\/\/www.x86-64.org\/documentation\/abi.pdf October 2013."},{"key":"e_1_3_2_1_83_1","first-page":"209","volume-title":"Proc. of USENIX Sec","author":"McCamant S.","year":"2006","unstructured":"S. McCamant and G. Morrisett . Evaluating SFI for a CISC Architecture . In Proc. of USENIX Sec , pages 209 -- 224 , 2006 . S. McCamant and G. Morrisett. Evaluating SFI for a CISC Architecture. In Proc. of USENIX Sec, pages 209--224, 2006."},{"key":"e_1_3_2_1_84_1","first-page":"279","volume-title":"Proc. of USENIX ATC","author":"McVoy L.","year":"1996","unstructured":"L. McVoy and C. Staelin . lmbench: Portable Tools for Performance Analysis . In Proc. of USENIX ATC , pages 279 -- 294 , 1996 . L. McVoy and C. Staelin. lmbench: Portable Tools for Performance Analysis. In Proc. of USENIX ATC, pages 279--294, 1996."},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594295"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.41"},{"key":"e_1_3_2_1_88_1","first-page":"447","volume-title":"Proc. of USENIX Sec","author":"Pappas V.","year":"2013","unstructured":"V. Pappas , M. Polychronakis , and A. D. Keromytis . Transparent ROP Exploit Mitigation Using Indirect Branch Tracing . In Proc. of USENIX Sec , pages 447 -- 462 , 2013 . V. Pappas, M. Polychronakis, and A. D. Keromytis. Transparent ROP Exploit Mitigation Using Indirect Branch Tracing. In Proc. of USENIX Sec, pages 447--462, 2013."},{"key":"e_1_3_2_1_89_1","volume-title":"April","author":"Team X","year":"2010","unstructured":"Pa X Team . UDEREF\/amd64. https:\/\/goo.gl\/iPuOVZ , April 2010 . PaX Team. UDEREF\/amd64. https:\/\/goo.gl\/iPuOVZ, April 2010."},{"key":"e_1_3_2_1_90_1","volume-title":"October","author":"Team X","year":"2011","unstructured":"Pa X Team . Better kernels with GCC plugins. https:\/\/lwn.net\/Articles\/461811\/ , October 2011 . PaX Team. Better kernels with GCC plugins. https:\/\/lwn.net\/Articles\/461811\/, October 2011."},{"key":"e_1_3_2_1_91_1","volume-title":"Hackers 2 Hackers Conference (H2HC)","author":"Team X","year":"2015","unstructured":"Pa X Team . RAP: RIP ROP . In Hackers 2 Hackers Conference (H2HC) , 2015 . PaX Team. RAP: RIP ROP. In Hackers 2 Hackers Conference (H2HC), 2015."},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_8"},{"key":"e_1_3_2_1_93_1","first-page":"47","volume-title":"A Guide To Kernel Exploitation: Attacking the Core","author":"Perla E.","year":"2010","unstructured":"E. Perla and M. Oldani . A Guide To Kernel Exploitation: Attacking the Core , chapter Stairway to Successful Kernel Exploitation, pages 47 -- 99 . Elsevier , 2010 . E. Perla and M. Oldani. A Guide To Kernel Exploitation: Attacking the Core, chapter Stairway to Successful Kernel Exploitation, pages 47--99. Elsevier, 2010."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315260"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523674"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/359588.359597"},{"key":"e_1_3_2_1_97_1","unstructured":"PTS. Phoronix Test Suite. http:\/\/www.phoronix-test-suite.com.  PTS. Phoronix Test Suite. http:\/\/www.phoronix-test-suite.com."},{"key":"e_1_3_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.5555\/1433006.1433008"},{"key":"e_1_3_2_1_99_1","volume-title":"December","author":"Rosenberg D.","year":"2010","unstructured":"D. Rosenberg . kptr_restrict for hiding kernel pointers. https:\/\/lwn.net\/Articles\/420403\/ , December 2010 . D. Rosenberg. kptr_restrict for hiding kernel pointers. https:\/\/lwn.net\/Articles\/420403\/, December 2010."},{"key":"e_1_3_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991121"},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.51"},{"key":"e_1_3_2_1_102_1","unstructured":"SecurityFocus. Linux Kernel 'perf_counter_open()' Local Buffer Overflow Vulnerability September 2009.  SecurityFocus. Linux Kernel 'perf_counter_open()' Local Buffer Overflow Vulnerability September 2009."},{"key":"e_1_3_2_1_103_1","first-page":"1","volume-title":"Proc. of USENIX Sec","author":"Sehr D.","year":"2010","unstructured":"D. Sehr , R. Muth , C. L. Biffle , V. Khimenko , E. Pasko , B. Yee , K. Schimpf , and B. Chen . Adapting Software Fault Isolation to Contemporary CPU Architectures . In Proc. of USENIX Sec , pages 1 -- 11 , 2010 . D. Sehr, R. Muth, C. L. Biffle, V. Khimenko, E. Pasko, B. Yee, K. Schimpf, and B. Chen. Adapting Software Fault Isolation to Contemporary CPU Architectures. In Proc. of USENIX Sec, pages 1--11, 2010."},{"key":"e_1_3_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_105_1","first-page":"574","volume-title":"Sadeghi. Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In Proc. of IEEE S&P","author":"Snow K. Z.","year":"2013","unstructured":"K. Z. Snow , F. Monrose , L. Davi , A. Dmitrienko , C. Liebchen , and A.- R. Sadeghi. Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In Proc. of IEEE S&P , pages 574 -- 588 , 2013 . K. Z. Snow, F. Monrose, L. Davi, A. Dmitrienko, C. Liebchen, and A.-R. Sadeghi. Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In Proc. of IEEE S&P, pages 574--588, 2013."},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.61"},{"key":"e_1_3_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"e_1_3_2_1_108_1","volume-title":"December","author":"Spengler B.","year":"2014","unstructured":"B. Spengler . Enlightenment Linux Kernel Exploitation Framework . https:\/\/goo.gl\/hDymQg , December 2014 . B. Spengler. Enlightenment Linux Kernel Exploitation Framework. https:\/\/goo.gl\/hDymQg, December 2014."},{"key":"e_1_3_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813685"},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1145\/378993.379237"},{"key":"e_1_3_2_1_111_1","first-page":"941","volume-title":"Proc. of USENIX Sec","author":"Tice C.","year":"2014","unstructured":"C. Tice , T. Roeder , P. Collingbourne , S. Checkoway , \u00da. Erlingsson, L. Lozano , and G. Pike . Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM . In Proc. of USENIX Sec , pages 941 -- 955 , 2014 . C. Tice, T. Roeder, P. Collingbourne, S. Checkoway, \u00da. Erlingsson, L. Lozano, and G. Pike. Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In Proc. of USENIX Sec, pages 941--955, 2014."},{"key":"e_1_3_2_1_112_1","volume-title":"November","author":"van de Ven A.","year":"2005","unstructured":"A. van de Ven . Debug option to write-protect rodata : the write protect logic and config option. https:\/\/goo.gl\/shDf0o , November 2005 . A. van de Ven. Debug option to write-protect rodata: the write protect logic and config option. https:\/\/goo.gl\/shDf0o, November 2005."},{"key":"e_1_3_2_1_113_1","volume-title":"July","author":"van de Ven A.","year":"2006","unstructured":"A. van de Ven . Add -fstack-protector support to the kernel. https:\/\/lwn.net\/Articles\/193307\/ , July 2006 . A. van de Ven. Add -fstack-protector support to the kernel. https:\/\/lwn.net\/Articles\/193307\/, July 2006."},{"key":"e_1_3_2_1_114_1","first-page":"813","volume-title":"Proc. of USENIX Sec","author":"Vogl S.","year":"2014","unstructured":"S. Vogl , R. Gawlik , B. Garmany , T. Kittel , J. Pfoh , C. Eckert , and T. Holz . Dynamic Hooks: Hiding Control Flow Changes Within Non-control Data . In Proc. of USENIX Sec , pages 813 -- 828 , 2014 . S. Vogl, R. Gawlik, B. Garmany, T. Kittel, J. Pfoh, C. Eckert, and T. Holz. Dynamic Hooks: Hiding Control Flow Changes Within Non-control Data. In Proc. of USENIX Sec, pages 813--828, 2014."},{"key":"e_1_3_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_3_2_1_116_1","first-page":"347","volume-title":"Proc. of USENIX ATC","author":"Wang X.","year":"2015","unstructured":"X. Wang , Y. Chen , Z. Wang , Y. Qi , and Y. Zhou . SecPod: a Framework for Virtualization-based Security Systems . In Proc. of USENIX ATC , pages 347 -- 360 , 2015 . X. Wang, Y. Chen, Z. Wang, Y. Qi, and Y. Zhou. SecPod: a Framework for Virtualization-based Security Systems. In Proc. of USENIX ATC, pages 347--360, 2015."},{"key":"e_1_3_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.30"},{"key":"e_1_3_2_1_118_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382216"},{"key":"e_1_3_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897891"},{"key":"e_1_3_2_1_120_1","first-page":"367","volume-title":"Proc. of USENIX OSDI","author":"Williams-King D.","year":"2016","unstructured":"D. Williams-King , G. Gobieski , K. Williams-King , J. P. Blake , X. Yuan , P. Colp , M. Zheng , V. P. Kemerlis , J. Yang , and W. Aiello . Shuffler: Fast and Deployable Continuous Code Re-Randomization . In Proc. of USENIX OSDI , pages 367 -- 382 , 2016 . D. Williams-King, G. Gobieski, K. Williams-King, J. P. Blake, X. Yuan, P. Colp, M. Zheng, V. P. Kemerlis, J. Yang, and W. Aiello. Shuffler: Fast and Deployable Continuous Code Re-Randomization. In Proc. of USENIX OSDI, pages 367--382, 2016."},{"key":"e_1_3_2_1_121_1","volume-title":"February","author":"Wojtczuk R.","year":"2015","unstructured":"R. Wojtczuk . Exploiting \"BadIRET\" vulnerability (CVE-2014-9322 , Linux kernel privilege escalation). https:\/\/goo.gl\/bSEhBI , February 2015 . R. Wojtczuk. Exploiting \"BadIRET\" vulnerability (CVE-2014-9322, Linux kernel privilege escalation). https:\/\/goo.gl\/bSEhBI, February 2015."},{"key":"e_1_3_2_1_122_1","volume-title":"Proc. of USENIX WOOT","author":"Xu W.","year":"2015","unstructured":"W. Xu and Y. Fu . Own Your Android! Yet Another Universal Root . In Proc. of USENIX WOOT , 2015 . W. Xu and Y. Fu. Own Your Android! Yet Another Universal Root. In Proc. of USENIX WOOT, 2015."},{"key":"e_1_3_2_1_123_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.25"},{"key":"e_1_3_2_1_124_1","volume-title":"May","author":"Disable Supervisor Mode Execution F. Yu.","year":"2011","unstructured":"F. Yu. Enable\/ Disable Supervisor Mode Execution Protection. https:\/\/goo.gl\/utKHno , May 2011 . F. Yu. Enable\/Disable Supervisor Mode Execution Protection. https:\/\/goo.gl\/utKHno, May 2011."},{"key":"e_1_3_2_1_125_1","first-page":"559","volume-title":"Proc. of IEEE S&P","author":"Zhang C.","year":"2013","unstructured":"C. Zhang , T. Wei , Z. Chen , L. Duan , L. Szekeres , S. McCamant , D. Song , and W. Zou . Practical Control Flow Integrity and Randomization for Binary Executables . In Proc. of IEEE S&P , pages 559 -- 573 , 2013 . C. Zhang, T. Wei, Z. Chen, L. Duan, L. Szekeres, S. McCamant, D. Song, and W. Zou. Practical Control Flow Integrity and Randomization for Binary Executables. In Proc. of IEEE S&P, pages 559--573, 2013."},{"key":"e_1_3_2_1_126_1","first-page":"337","volume-title":"Proc. of USENIX Sec","author":"Zhang M.","year":"2013","unstructured":"M. Zhang and R. Sekar . Control Flow Integrity for COTS Binaries . In Proc. of USENIX Sec , pages 337 -- 352 , 2013 . M. Zhang and R. Sekar. Control Flow Integrity for COTS Binaries. In Proc. of USENIX Sec, pages 337--352, 2013."}],"event":{"name":"EuroSys '17: Twelfth EuroSys Conference 2017","location":"Belgrade Serbia","acronym":"EuroSys '17","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the Twelfth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3064176.3064216","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3064176.3064216","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:36:15Z","timestamp":1750217775000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3064176.3064216"}},"subtitle":["Comprehensive Kernel Protection against Just-In-Time Code Reuse"],"short-title":[],"issued":{"date-parts":[[2017,4,23]]},"references-count":126,"alternative-id":["10.1145\/3064176.3064216","10.1145\/3064176"],"URL":"https:\/\/doi.org\/10.1145\/3064176.3064216","relation":{},"subject":[],"published":{"date-parts":[[2017,4,23]]},"assertion":[{"value":"2017-04-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}