{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:27:02Z","timestamp":1750220822077,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":20,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,1,19]],"date-time":"2019-01-19T00:00:00Z","timestamp":1547856000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,1,19]]},"DOI":"10.1145\/3309074.3309080","type":"proceedings-article","created":{"date-parts":[[2019,4,12]],"date-time":"2019-04-12T13:29:18Z","timestamp":1555075758000},"page":"273-278","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Identifying HID-based attacks through process event graph using guilt-by-association analysis"],"prefix":"10.1145","author":[{"given":"Chia-Yu","family":"Huang","sequence":"first","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hahn-Ming","family":"Lee","sequence":"additional","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiunn-Chin","family":"Wang","sequence":"additional","affiliation":[{"name":"Jinwen University of Science and Technology, Taipei, Taiwan and National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ching-Hao","family":"Mao","sequence":"additional","affiliation":[{"name":"Institute for Information Industry, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,1,19]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Nissim N. Yahalom R. and Elovici Y. 2017. USB-based attacks. Computers & Security 70 (Sept. 2017) 675--688.  Nissim N. Yahalom R. and Elovici Y. 2017. USB-based attacks. Computers & Security 70 (Sept. 2017) 675--688.","DOI":"10.1016\/j.cose.2017.08.002"},{"volume-title":"Making USB Great Again with USBFILTER. In 25th USENIX Security Symposium (USENIX '16)","year":"2016","author":"Dave","key":"e_1_3_2_1_2_1"},{"volume-title":"USENIX Security Symposium","year":"2016","author":"Angel S.","key":"e_1_3_2_1_3_1"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134050"},{"volume-title":"Curtain: Keep Your Hosts Away from USB Attacks. In Information Security - 20th International Conference (ISC '17), Ho Chi Minh City, Vietnam, November 22--24. 455--171.","year":"2017","author":"Fu J.","key":"e_1_3_2_1_5_1"},{"volume-title":"Unifying Guilt-by-Association Approaches: Theorems and Fast Algorithms. In Machine Learning and Knowledge Discovery in Databases - European Conference (ECML PKDD '11)","author":"Koutra D.","key":"e_1_3_2_1_6_1"},{"key":"e_1_3_2_1_7_1","unstructured":"Rubber Ducky. https:\/\/hakshop.com\/products\/usb-rubber-ducky-deluxe Accessed on: Jun. 30 2018.  Rubber Ducky. https:\/\/hakshop.com\/products\/usb-rubber-ducky-deluxe Accessed on: Jun. 30 2018."},{"key":"e_1_3_2_1_8_1","unstructured":"Crenshaw A. Programmable HID USB Keystroke Dongle: Using the Teensy as a pen testing device. http:\/\/www.irongeek.com\/i.php?page=security\/programmable-hid-usb-keystroke-dongle Accessed on: Jun. 30 2018.  Crenshaw A. Programmable HID USB Keystroke Dongle: Using the Teensy as a pen testing device. http:\/\/www.irongeek.com\/i.php?page=security\/programmable-hid-usb-keystroke-dongle Accessed on: Jun. 30 2018."},{"key":"e_1_3_2_1_9_1","unstructured":"Elkins M. URFUKED (Universal RF USB Keyboard Emulation Device). https:\/\/www.defcon.org\/images\/defcon-18\/dc-18-presentations\/Elkins\/DEFCON-18-Elkins-Universal-RF-Keyboard.pdf Accessed on: Jun. 30 2018.  Elkins M. URFUKED (Universal RF USB Keyboard Emulation Device). https:\/\/www.defcon.org\/images\/defcon-18\/dc-18-presentations\/Elkins\/DEFCON-18-Elkins-Universal-RF-Keyboard.pdf Accessed on: Jun. 30 2018."},{"key":"e_1_3_2_1_10_1","unstructured":"Kamakar S. USBdriveby. http:\/\/samy.pl\/usbdriveby\/ Accessed on: Jun. 30 2018.  Kamakar S. USBdriveby. http:\/\/samy.pl\/usbdriveby\/ Accessed on: Jun. 30 2018."},{"key":"e_1_3_2_1_11_1","unstructured":"Feroz R. EvilDuino. https:\/\/www.slideshare.net\/Rashidferoz1\/evilduino Accessed on: Jun. 30 2018.  Feroz R. EvilDuino. https:\/\/www.slideshare.net\/Rashidferoz1\/evilduino Accessed on: Jun. 30 2018."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920314"},{"key":"e_1_3_2_1_13_1","unstructured":"Kali Nethunter. https:\/\/www.kali.org\/kali-linux-nethunter\/ Accessed on: Jun. 30 2018.  Kali Nethunter. https:\/\/www.kali.org\/kali-linux-nethunter\/ Accessed on: Jun. 30 2018."},{"volume":"201","journal-title":"Lell J.","author":"Nohl K.","key":"e_1_3_2_1_14_1"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978398"},{"volume-title":"TMSUI: A Trust Management Scheme of USB Storage Devices for Industrial Control Systems. In Information and Communications Security - 17th International Conference (ICICS '15)","year":"2015","author":"Yang B.","key":"e_1_3_2_1_16_1"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818040"},{"key":"e_1_3_2_1_18_1","unstructured":"Lumension Endpoint Security. https:\/\/www.ivanti.com\/company\/history\/lumension-security  Lumension Endpoint Security. https:\/\/www.ivanti.com\/company\/history\/lumension-security"},{"key":"e_1_3_2_1_19_1","unstructured":"Kingston Technology Corporation IronKey http:\/\/www.ironkey.com\/en-US\/  Kingston Technology Corporation IronKey http:\/\/www.ironkey.com\/en-US\/"},{"volume-title":"Trustworthy Whole-System Provenance for the Linux Kernel. In 24th USENIX Security Symposium (USENIX '15)","author":"Bates A. M.","key":"e_1_3_2_1_20_1"}],"event":{"name":"ICCSP 2019: 2019 the 3rd International Conference on Cryptography, Security and Privacy","acronym":"ICCSP 2019","location":"Kuala Lumpur Malaysia"},"container-title":["Proceedings of the 3rd International Conference on Cryptography, Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3309074.3309080","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3309074.3309080","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:13:15Z","timestamp":1750201995000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3309074.3309080"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,19]]},"references-count":20,"alternative-id":["10.1145\/3309074.3309080","10.1145\/3309074"],"URL":"https:\/\/doi.org\/10.1145\/3309074.3309080","relation":{},"subject":[],"published":{"date-parts":[[2019,1,19]]},"assertion":[{"value":"2019-01-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}