{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:31:55Z","timestamp":1750221115011,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":61,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,3,13]],"date-time":"2019-03-13T00:00:00Z","timestamp":1552435200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100007297","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-17-1-2513"],"award-info":[{"award-number":["N00014-17-1-2513"]}],"id":[{"id":"10.13039\/100007297","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1801601, CNS-1513783"],"award-info":[{"award-number":["CNS-1801601, CNS-1513783"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,3,13]]},"DOI":"10.1145\/3292006.3300028","type":"proceedings-article","created":{"date-parts":[[2019,3,21]],"date-time":"2019-03-21T12:22:04Z","timestamp":1553170924000},"page":"209-220","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["PoLPer"],"prefix":"10.1145","author":[{"given":"Yuseok","family":"Jeon","sequence":"first","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junghwan","family":"Rhee","sequence":"additional","affiliation":[{"name":"NEC Laboratories America, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chung Hwan","family":"Kim","sequence":"additional","affiliation":[{"name":"NEC Laboratories America, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhichun","family":"Li","sequence":"additional","affiliation":[{"name":"NEC Laboratories America, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mathias","family":"Payer","sequence":"additional","affiliation":[{"name":"EPFL &amp; Purdue University, Lausanne, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Byoungyoung","family":"Lee","sequence":"additional","affiliation":[{"name":"Seoul National &amp; Purdue University, Seoul, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhenyu","family":"Wu","sequence":"additional","affiliation":[{"name":"NEC Laboratories America, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,3,13]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Online; accessed 22-Sept-2018. Bypassing non-executable memory ASLR and stack canaries on x86--64 Linux. https:\/\/www.antoniobarresi.com\/security\/ exploitdev\/2014\/05\/03\/64bitexploitation\/.  Online; accessed 22-Sept-2018. Bypassing non-executable memory ASLR and stack canaries on x86--64 Linux. https:\/\/www.antoniobarresi.com\/security\/ exploitdev\/2014\/05\/03\/64bitexploitation\/."},{"key":"e_1_3_2_1_2_1","unstructured":"Online; accessed 22-Sept-2018. Defeating DEP with ROP. https:\/\/samsclass.info\/ 127\/proj\/rop.htm.  Online; accessed 22-Sept-2018. Defeating DEP with ROP. https:\/\/samsclass.info\/ 127\/proj\/rop.htm."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314466.1314467"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23421"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Scott Brookes and Stephen Taylor. 2016. Containing a Confused Deputy on x86: A Survey of Privilege Escalation Mitigation Techniques. International Journal of Advanced Computer Science and Applications.  Scott Brookes and Stephen Taylor. 2016. Containing a Confused Deputy on x86: A Survey of Privilege Escalation Mitigation Techniques. International Journal of Advanced Computer Science and Applications.","DOI":"10.14569\/IJACSA.2016.070463"},{"key":"e_1_3_2_1_8_1","unstructured":"Linux capabilities. Online; accessed 23-Sep-2018. http:\/\/man7.org\/linux\/ man-pages\/man7\/capabilities.7.html.  Linux capabilities. Online; accessed 23-Sep-2018. http:\/\/man7.org\/linux\/ man-pages\/man7\/capabilities.7.html."},{"key":"e_1_3_2_1_9_1","volume-title":"Gross","author":"Carlini Nicolas","year":"2015","unstructured":"Nicolas Carlini , Antonio Barresi , Mathias Payer , David Wagner , and Thomas R . Gross . 2015 . Control-flow Bending : On the Effectiveness of Control-flow Integrity. In Proceedings of SEC '15. Nicolas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. 2015. Control-flow Bending: On the Effectiveness of Control-flow Integrity. In Proceedings of SEC'15."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of OSDI'06","author":"Castro Miguel","year":"2006","unstructured":"Miguel Castro , Manuel Costa , and Tim Harris . 2006 . Securing software by enforcing data-flow integrity . In Proceedings of OSDI'06 . Miguel Castro, Manuel Costa, and Tim Harris. 2006. Securing software by enforcing data-flow integrity. In Proceedings of OSDI'06."},{"key":"e_1_3_2_1_11_1","volume-title":"Setuid Demystified. In Proceedings of SEC'02","author":"Chen Hao","year":"2002","unstructured":"Hao Chen , David Wagner , and Drew Dean . 2002 . Setuid Demystified. In Proceedings of SEC'02 . Hao Chen, David Wagner, and Drew Dean. 2002. Setuid Demystified. In Proceedings of SEC'02."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of SEC'05","author":"Chen Shuo","year":"2005","unstructured":"Shuo Chen , Jun Xu , Emre Can Sezer , Prachi Gauriar , and Ravishankar K Iyer . 2005 . Non-Control-Data Attacks Are Realistic Threats . In Proceedings of SEC'05 . Shuo Chen, Jun Xu, Emre Can Sezer, Prachi Gauriar, and Ravishankar K Iyer. 2005. Non-Control-Data Attacks Are Realistic Threats. In Proceedings of SEC'05."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23156"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813671"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714635"},{"key":"e_1_3_2_1_16_1","unstructured":"Shellcodes database for study cases. Online; accessed 23-Sep-2018. http:\/\/ shell-storm.org\/shellcode\/.  Shellcodes database for study cases. Online; accessed 23-Sep-2018. http:\/\/ shell-storm.org\/shellcode\/."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660333"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813646"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/829515.830554"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_4"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813611"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/54289.871709"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978327"},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of SEC'15","author":"Hu Hong","year":"2015","unstructured":"Hong Hu , Zheng Leong Chua , Sendroiu Adrian , Prateek Saxena , and Zhenkai Liang . 2015 . Automatic Generation of Data-Oriented Exploits .. In Proceedings of SEC'15 . Hong Hu, Zheng Leong Chua, Sendroiu Adrian, Prateek Saxena, and Zhenkai Liang. 2015. Automatic Generation of Data-Oriented Exploits.. In Proceedings of SEC'15."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.62"},{"key":"e_1_3_2_1_26_1","unstructured":"Intel. Online; accessed 23-Sep-2018. Control-flow enforcement technology (CET) preview. https:\/\/software.intel.com\/sites\/default\/files\/managed\/4d\/2a\/ control-flow-enforcement-technology-preview.pdf.  Intel. Online; accessed 23-Sep-2018. Control-flow enforcement technology (CET) preview. https:\/\/software.intel.com\/sites\/default\/files\/managed\/4d\/2a\/ control-flow-enforcement-technology-preview.pdf."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243739"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2592798.2592811"},{"key":"e_1_3_2_1_29_1","unstructured":"Jim Keniston. Online; accessed 23-Sep-2018. Kernel Probes. https:\/\/elixir. free-electrons.com\/linux\/v4.0\/source\/Documentation\/kprobes.txt.  Jim Keniston. Online; accessed 23-Sep-2018. Kernel Probes. https:\/\/elixir. free-electrons.com\/linux\/v4.0\/source\/Documentation\/kprobes.txt."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23107"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/191177.191183"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-39650-5_19"},{"key":"e_1_3_2_1_33_1","volume-title":"Code-Pointer Integrity. In Proceedings of OSDI'14","author":"Kuznetsov Volodymyr","year":"2014","unstructured":"Volodymyr Kuznetsov , L\u00e1szl\u00f3 Szekeres , Mathias Payer , George Candea , R Sekar , and Dawn Song . 2014 . Code-Pointer Integrity. In Proceedings of OSDI'14 . Volodymyr Kuznetsov, L\u00e1szl\u00f3 Szekeres, Mathias Payer, George Candea, R Sekar, and Dawn Song. 2014. Code-Pointer Integrity. In Proceedings of OSDI'14."},{"key":"e_1_3_2_1_34_1","unstructured":"Long Le. 2010. Payload Already Inside: Data Reuse for ROP Exploits. (2010).  Long Le. 2010. Payload Already Inside: Data Reuse for ROP Exploits. (2010)."},{"key":"e_1_3_2_1_35_1","unstructured":"LLVM. Online; accessed 23-Sep-2018. The LLVM Compiler Infrastructure Project. http:\/\/llvm.org\/.  LLVM. Online; accessed 23-Sep-2018. The LLVM Compiler Infrastructure Project. http:\/\/llvm.org\/."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978366"},{"key":"e_1_3_2_1_37_1","unstructured":"Microsoft. Online; accessed 23-Sep-2018. Data Execution Prevention (DEP). https: \/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa366553(v=vs.85).aspx.  Microsoft. Online; accessed 23-Sep-2018. Data Execution Prevention (DEP). https: \/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa366553(v=vs.85).aspx."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/1776434.1776436"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516649"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594295"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660281"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"volume-title":"Proceedings of SEC'13","author":"Pappas Vasilis","key":"e_1_3_2_1_43_1","unstructured":"Vasilis Pappas , Michalis Polychronakis , and Angelos D. Keromytis . 2013. Transparent ROP Exploit Mitigation Using Indirect Branch Tracing . In Proceedings of SEC'13 . Vasilis Pappas, Michalis Polychronakis, and Angelos D. Keromytis. 2013. Transparent ROP Exploit Mitigation Using Indirect Branch Tracing. In Proceedings of SEC'13."},{"key":"e_1_3_2_1_44_1","unstructured":"AppArmor Project. Online; accessed 23-Sep-2018. http:\/\/wiki.apparmor.net\/index. php\/Main_Page.  AppArmor Project. Online; accessed 23-Sep-2018. http:\/\/wiki.apparmor.net\/index. php\/Main_Page."},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of SEC'03","author":"Provos Niels","year":"2003","unstructured":"Niels Provos . 2003 . Improving Host Security with System Call Policies .. In Proceedings of SEC'03 . Niels Provos. 2003. Improving Host Security with System Call Policies.. In Proceedings of SEC'03."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2014.059327"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2133375.2133377"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361067"},{"key":"e_1_3_2_1_49_1","unstructured":"Seccomp. Online; accessed 23-Sep-2018. SECure COMPuting with filters. https: \/\/www.kernel.org\/doc\/Documentation\/prctl\/seccomp_filter.txt.  Seccomp. Online; accessed 23-Sep-2018. SECure COMPuting with filters. https: \/\/www.kernel.org\/doc\/Documentation\/prctl\/seccomp_filter.txt."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132752"},{"key":"e_1_3_2_1_51_1","volume-title":"andWayne Salamon","author":"Smalley Stephen","year":"2001","unstructured":"Stephen Smalley , Chris Vance , andWayne Salamon . 2001 . Implementing SELinux as a Linux security module. NAI Labs Report . Stephen Smalley, Chris Vance, andWayne Salamon. 2001. Implementing SELinux as a Linux security module. NAI Labs Report."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23218"},{"key":"e_1_3_2_1_53_1","unstructured":"PaX Team. Online; accessed 23-Sep-2018. Pax: the Linux kernel patch for least privilege protection. https:\/\/en.wikipedia.org\/wiki\/PaX.  PaX Team. Online; accessed 23-Sep-2018. Pax: the Linux kernel patch for least privilege protection. https:\/\/en.wikipedia.org\/wiki\/PaX."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813673"},{"key":"e_1_3_2_1_55_1","volume-title":"Paladin: Helping Programs Help Themselves with Internal System Call Interposition.","author":"Vaughan Jeffrey A","year":"2010","unstructured":"Jeffrey A Vaughan and Andrew D Hilton . 2010 . Paladin: Helping Programs Help Themselves with Internal System Call Interposition. Jeffrey A Vaughan and Andrew D Hilton. 2010. Paladin: Helping Programs Help Themselves with Internal System Call Interposition."},{"key":"e_1_3_2_1_56_1","volume-title":"Proceedings of SEC'14","author":"Vijayakumar Hayawardh","year":"2014","unstructured":"Hayawardh Vijayakumar , Xinyang Ge , Mathias Payer , and Trent Jaeger . 2014 . JIGSAW: Protecting Resource Access by Inferring Programmer Expectations . In Proceedings of SEC'14 . Hayawardh Vijayakumar, Xinyang Ge, Mathias Payer, and Trent Jaeger. 2014. JIGSAW: Protecting Resource Access by Inferring Programmer Expectations. In Proceedings of SEC'14."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884434"},{"key":"e_1_3_2_1_58_1","unstructured":"M. Zalewski. Online; accessed 23-Sep-2018. American Fuzzy Lop. http:\/\/lcamtuf. coredump.cx\/afl\/.  M. Zalewski. Online; accessed 23-Sep-2018. American Fuzzy Lop. http:\/\/lcamtuf. coredump.cx\/afl\/."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23164"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.44"},{"volume-title":"Proceedings of SEC'13","author":"Zhang Mingwei","key":"e_1_3_2_1_61_1","unstructured":"Mingwei Zhang and R. Sekar . 2013. Control Flow Integrity for COTS Binaries . In Proceedings of SEC'13 . Mingwei Zhang and R. Sekar. 2013. Control Flow Integrity for COTS Binaries. In Proceedings of SEC'13."}],"event":{"name":"CODASPY '19: Ninth ACM Conference on Data and Application Security and Privacy","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Richardson Texas USA","acronym":"CODASPY '19"},"container-title":["Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3292006.3300028","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3292006.3300028","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3292006.3300028","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T01:02:02Z","timestamp":1750208522000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3292006.3300028"}},"subtitle":["Process-Aware Restriction of Over-Privileged Setuid Calls in Legacy Applications"],"short-title":[],"issued":{"date-parts":[[2019,3,13]]},"references-count":61,"alternative-id":["10.1145\/3292006.3300028","10.1145\/3292006"],"URL":"https:\/\/doi.org\/10.1145\/3292006.3300028","relation":{},"subject":[],"published":{"date-parts":[[2019,3,13]]},"assertion":[{"value":"2019-03-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}