{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T15:04:38Z","timestamp":1761663878960,"version":"3.41.0"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2019,2,26]],"date-time":"2019-02-26T00:00:00Z","timestamp":1551139200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"crossref","award":["NRF-2018R1D1A1B07049870"],"award-info":[{"award-number":["NRF-2018R1D1A1B07049870"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100003836","name":"IDEC","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100003836","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Automatic Deep Malware Analysis Technology for Cyber Threat Intelligence","award":["2017-0-00168"],"award-info":[{"award-number":["2017-0-00168"]}]},{"name":"Cloud-based Security Intelligence Technology Development for the Customized Security Service Provisioning","award":["2016-0-00078"],"award-info":[{"award-number":["2016-0-00078"]}]},{"name":"Institute for Information 8 communications Technology Promotion (IITP) grant funded by the Korea government"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2019,5,31]]},"abstract":"<jats:p>\n            Security monitoring has long been considered as a fundamental mechanism to mitigate the damage of a security attack. Recently, intra-level security systems have been proposed that can efficiently and securely monitor system software without any involvement of more privileged entity. Unfortunately, there exists no full intra-level security system that can universally operate at any privilege level on ARM. However, as malware and attacks increase against virtually every level of privileged software including an OS, a hypervisor, and even the highest privileged software armored by TrustZone, we have been motivated to develop an intra-level security system, named\n            <jats:italic>Hilps<\/jats:italic>\n            . Hilps realizes true intra-level scheme in all these levels of privileged software on ARM by elaborately exploiting a new hardware feature of ARM\u2019s latest 64-bit architecture, called TxSZ, that enables elastic adjustment of the accessible virtual address range. Furthermore, Hilps newly supports the sandbox mechanism that provides security tools with individually isolated execution environments, thereby minimizing security threats from untrusted security tools. We have implemented a prototype of Hilps on a real machine. The experimental results demonstrate that Hilps is quite promising for practical use in real deployments.\n          <\/jats:p>","DOI":"10.1145\/3309698","type":"journal-article","created":{"date-parts":[[2019,2,26]],"date-time":"2019-02-26T15:05:33Z","timestamp":1551193533000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Safe and Efficient Implementation of a Security System on ARM using Intra-level Privilege Separation"],"prefix":"10.1145","volume":"22","author":[{"given":"Donghyun","family":"Kwon","sequence":"first","affiliation":[{"name":"Seoul National University, Gwanak-gu, Seoul, The Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hayoon","family":"Yi","sequence":"additional","affiliation":[{"name":"Seoul National University, Gwanak-gu, Seoul, The Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7842-1719","authenticated-orcid":false,"given":"Yeongpil","family":"Cho","sequence":"additional","affiliation":[{"name":"Soongsil University, Dongsak-gu, Seoul, The Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yunheung","family":"Paek","sequence":"additional","affiliation":[{"name":"Seoul National University, Gwanak-gu, Seoul, The Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,2,26]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"CVE Details. 2018. Linux kernel vulnerabilities. Retrieved from http:\/\/www.cvedetails.com\/product\/47\/Linux-Linux-Kernel.html?vendor_id&equals;33.  CVE Details. 2018. Linux kernel vulnerabilities. Retrieved from http:\/\/www.cvedetails.com\/product\/47\/Linux-Linux-Kernel.html?vendor_id&equals;33."},{"key":"e_1_2_1_2_1","unstructured":"LLVM Linux. {n.d.}. Retrieved from http:\/\/llvm.linuxfoundation.org.  LLVM Linux. {n.d.}. Retrieved from http:\/\/llvm.linuxfoundation.org."},{"volume-title":"Xen: Vulnerability statistics.","year":"2018","author":"Details CVE","key":"e_1_2_1_3_1"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1535\/itj.1003.02"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium.","year":"2016","author":"Bhutkar Rohan","key":"e_1_2_1_5_1"},{"key":"e_1_2_1_6_1","unstructured":"ARM. {n.d.}. System Memory Management Unit (SMMU). Retrieved from http:\/\/www.arm.com\/products\/system-ip\/controllers\/system-mmu.php.  ARM. {n.d.}. System Memory Management Unit (SMMU). Retrieved from http:\/\/www.arm.com\/products\/system-ip\/controllers\/system-mmu.php."},{"key":"e_1_2_1_7_1","unstructured":"ARM. 2015. Versatile express Juno r1 development platform. Retrieved from http:\/\/infocenter.arm.com\/help\/index.jsp?topic&equals;\/com.arm.doc.100122_0100_01_en\/bri1412864820181.html.  ARM. 2015. Versatile express Juno r1 development platform. Retrieved from http:\/\/infocenter.arm.com\/help\/index.jsp?topic&equals;\/com.arm.doc.100122_0100_01_en\/bri1412864820181.html."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866313"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046752"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/69605.2085"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2775111"},{"volume-title":"Klein","year":"2005","author":"Becher Michael","key":"e_1_2_1_13_1"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629581"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23024"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541986"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694386"},{"volume-title":"Proceedings of the 7th Symposium on Operating Systems Design and Implementation.","author":"Erlingsson Ulfar","key":"e_1_2_1_19_1"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132782"},{"volume-title":"Proceedings of the 17th IEEE Symposium on Security and Privacy.","author":"Forrest Stephanie","key":"e_1_2_1_21_1"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium.","year":"2003","author":"Garfinkel Tal","key":"e_1_2_1_22_1"},{"volume-title":"Proceedings of the workshop on Mobile Security Technologies (MoST'14)","year":"2014","author":"Ge Xinyang","key":"e_1_2_1_23_1"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1176760.1176793"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1950365.1950398"},{"key":"e_1_2_1_26_1","unstructured":"Intel. 2008. Trusted Execution Technology: Software Development Guide (315168- 005). Retrieved from https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/guides\/intel-txt-software-development-guide.pdf.  Intel. 2008. Trusted Execution Technology: Software Development Guide (315168- 005). Retrieved from https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/guides\/intel-txt-software-development-guide.pdf."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134627"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/2665671.2665726"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.38"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629596"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224075"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043568"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872379"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352592.1352625"},{"volume-title":"Bhavsar","year":"2003","author":"Misra Subhas C.","key":"e_1_2_1_35_1"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/566171.566181"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315260"},{"volume-title":"Proceedings of the Seminar of Advanced Exploitation Techniques (WS\u201907)","author":"Piegdon David R.","key":"e_1_2_1_38_1"},{"key":"e_1_2_1_39_1","unstructured":"Dan Rosenberg. 2014. QSEE trustzone kernel integer overflow. In Black Hat USA. Retrieved from https:\/\/blackhat.com\/docs\/us-14\/materials\/us-14-Rosenberg-Reflections-On-Trusting-TrustZone-WP.pdf.  Dan Rosenberg. 2014. QSEE trustzone kernel integer overflow. In Black Hat USA. Retrieved from https:\/\/blackhat.com\/docs\/us-14\/materials\/us-14-Rosenberg-Reflections-On-Trusting-TrustZone-WP.pdf."},{"key":"e_1_2_1_40_1","unstructured":"Thomas Roth. 2013. Next generation mobile rootkits. In Black Hack Europe. Retrieved from https:\/\/hackinparis.com\/data\/slides\/2013\/Slidesthomasroth.pdf.  Thomas Roth. 2013. Next generation mobile rootkits. In Black Hack Europe. Retrieved from https:\/\/hackinparis.com\/data\/slides\/2013\/Slidesthomasroth.pdf."},{"key":"e_1_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Fred B. Schneider Greg Morrisett and Robert Harper. 2001. A language-based approach to security. In Informatics.   Fred B. Schneider Greg Morrisett and Robert Harper. 2001. A language-based approach to security. In Informatics.","DOI":"10.1007\/3-540-44577-3_6"},{"volume-title":"Proceedings of the 19th USENIX Security Symposium.","year":"2010","author":"Sehr David","key":"e_1_2_1_42_1"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294294"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653720"},{"key":"e_1_2_1_45_1","unstructured":"Di Shen. 2015. Attacking your trusted core: Exploiting trustzone on android. In Black Hat USA. Retrieved from https:\/\/www.blackhat.com\/docs\/us-15\/materials\/us-15-Shen-Attacking-Your-Trusted-Core-Exploiting-Trustzone-On-Android.pdf.  Di Shen. 2015. Attacking your trusted core: Exploiting trustzone on android. In Black Hat USA. Retrieved from https:\/\/www.blackhat.com\/docs\/us-15\/materials\/us-15-Shen-Attacking-Your-Trusted-Core-Exploiting-Trustzone-On-Android.pdf."},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium.","author":"Srivastava Abhinav","key":"e_1_2_1_46_1"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755913.1755935"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/782814.782838"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945466"},{"volume-title":"Proceedings of RECON Canada.","year":"2014","author":"Thomas Josh","key":"e_1_2_1_50_1"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2013.11.032"},{"key":"e_1_2_1_52_1","unstructured":"EFI Unified. 2014. Unified extensible firmware interface specification. Retrieved from https:\/\/uef.org\/specifcations.  EFI Unified. 2014. Unified extensible firmware interface specification. Retrieved from https:\/\/uef.org\/specifcations."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.36"},{"volume-title":"Proceedings of the USENIX Security Symposium. 87--104","year":"2016","author":"Vasudevan Amit","key":"e_1_2_1_54_1"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/173668.168635"},{"volume-title":"Proceedings of the USENIX Annual Technical Conference.","year":"2015","author":"Wang Xiaoguang","key":"e_1_2_1_56_1"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.30"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653728"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium.","year":"2013","author":"Wu Chiachih","key":"e_1_2_1_59_1"},{"volume-title":"Proceedings of the 21st USENIX Security Symposium.","year":"2012","author":"Xu Rubin","key":"e_1_2_1_60_1"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.25"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.53"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3309698","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3309698","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:57:59Z","timestamp":1750208279000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3309698"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,2,26]]},"references-count":61,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2019,5,31]]}},"alternative-id":["10.1145\/3309698"],"URL":"https:\/\/doi.org\/10.1145\/3309698","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"type":"print","value":"2471-2566"},{"type":"electronic","value":"2471-2574"}],"subject":[],"published":{"date-parts":[[2019,2,26]]},"assertion":[{"value":"2017-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-01-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-02-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}