{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:48:58Z","timestamp":1776782938700,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":29,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Fundation","doi-asserted-by":"publisher","award":["CNS-1408880"],"award-info":[{"award-number":["CNS-1408880"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Fundation","doi-asserted-by":"publisher","award":["CNS-1526319"],"award-info":[{"award-number":["CNS-1526319"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Fundation","doi-asserted-by":"publisher","award":["CNS-1801534"],"award-info":[{"award-number":["CNS-1801534"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Fundation","doi-asserted-by":"publisher","award":["CCF-1723571"],"award-info":[{"award-number":["CCF-1723571"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Fundation","doi-asserted-by":"publisher","award":["CNS-1816282"],"award-info":[{"award-number":["CNS-1816282"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Fundation","doi-asserted-by":"publisher","award":["CNS-1408826"],"award-info":[{"award-number":["CNS-1408826"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Intel Inc."}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3354218","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"1023-1040","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["Program-mandering"],"prefix":"10.1145","author":[{"given":"Shen","family":"Liu","sequence":"first","affiliation":[{"name":"Pennsylvania State University, University Park, PA, USA"}]},{"given":"Dongrui","family":"Zeng","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, University Park, PA, USA"}]},{"given":"Yongzhe","family":"Huang","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, University Park, PA, USA"}]},{"given":"Frank","family":"Capobianco","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, University Park, PA, USA"}]},{"given":"Stephen","family":"McCamant","sequence":"additional","affiliation":[{"name":"University of Minnesota, Twin Cities, MN, USA"}]},{"given":"Trent","family":"Jaeger","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, University Park, PA, USA"}]},{"given":"Gang","family":"Tan","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, University Park, PA, USA"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"David M. Beazley. 1997. SWIG Users Manual: Version 1.1.  David M. Beazley. 1997. SWIG Users Manual: Version 1.1."},{"key":"e_1_3_2_2_2_1","volume-title":"Proceedings of the 5th USENIX Symposium on Networked Systems Design and Implementation. 309--322","author":"Bittau Andrea","year":"2008"},{"key":"e_1_3_2_2_3_1","volume-title":"Privtrans: Automatically Partitioning Programs for Privilege Separation. In 13th Usenix Security Symposium. 57--72","author":"Brumley David","year":"2004"},{"key":"e_1_3_2_2_4_1","volume-title":"Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security. 193--204","author":"Scott"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294265"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/1370628.1370629"},{"key":"e_1_3_2_2_7_1","volume-title":"IEEE Symposium on Security and Privacy (S&P). 184--195","author":"Clark David D."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40203-6_5"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/24039.24041"},{"key":"e_1_3_2_2_10_1","volume-title":"Security Policies and Security Models. In IEEE Symposium on Security and Privacy (S&P). 11--20","author":"Joseph"},{"key":"e_1_3_2_2_11_1","volume-title":"Clean Application Compartmentalization with SOAAP. In 22nd ACM Conference on Computer and Communications Security (CCS). 1016--1031","author":"Gudka Khilan","year":"2015"},{"key":"e_1_3_2_2_12_1","volume-title":"USENIX Annual Technical Conference, FREENIX track. 273--284","author":"Kilpatrick Douglas","year":"2003"},{"key":"e_1_3_2_2_13_1","volume-title":"Glamdring: Automatic Application Partitioning for Intel SGX. In USENIX Annual Technical Conference (ATC). 285--298","author":"Lind Joshua"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134066"},{"key":"e_1_3_2_2_15_1","volume-title":"Thwarting Memory Disclosure with Efficient Hypervisor-enforced Intra-domain Isolation. In 22nd ACM Conference on Computer and Communications Security (CCS). 1607--1619","author":"Liu Yutao","year":"2015"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"e_1_3_2_2_17_1","volume-title":"ACM Conference on Programming Language Design and Implementation (PLDI). 193--205","author":"McCamant Stephen"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/363516.363526"},{"key":"e_1_3_2_2_19_1","volume-title":"12th Usenix Security Symposium. 231--242","author":"Provos Niels","year":"2003"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884817"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_3_2_2_22_1","volume-title":"Toward Automated Information-Flow Integrity Verification for Security-Critical Applications. In Network and Distributed System Security Symposium (NDSS). 267--280","author":"Shankar Umesh","year":"2006"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/LICS.2015.13"},{"key":"e_1_3_2_2_24_1","volume-title":"Enforcing Kernel Security Invariants with Data Flow Integrity. In Network and Distributed System Security Symposium (NDSS).","author":"Song Chengyu","year":"2016"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1561\/3300000013"},{"key":"e_1_3_2_2_26_1","volume-title":"Efficient Software-Based Fault Isolation. In ACM SIGOPS Symposium on Operating Systems Principles (SOSP). ACM Press","author":"Wahbe R."},{"key":"e_1_3_2_2_27_1","volume-title":"International Conference on Automated Software Engineering (ASE). 323--333","author":"Yongzheng Wu Yang Liu","year":"2013"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/566340.566343"},{"key":"e_1_3_2_2_29_1","volume-title":"IEEE Symposium on Security and Privacy (S&P). 236--250","author":"Zheng Lantian","year":"2003"}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354218","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3354218","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3354218","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:24:03Z","timestamp":1750202643000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354218"}},"subtitle":["Quantitative Privilege Separation"],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":29,"alternative-id":["10.1145\/3319535.3354218","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3354218","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}