{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:56:47Z","timestamp":1783007807765,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":75,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,30]],"date-time":"2020-10-30T00:00:00Z","timestamp":1604016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Natural Science Foundation of China","award":["61772307, 61772308, 61972224 and U1736209"],"award-info":[{"award-number":["61772307, 61772308, 61972224 and U1736209"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,30]]},"DOI":"10.1145\/3372297.3417867","type":"proceedings-article","created":{"date-parts":[[2021,3,4]],"date-time":"2021-03-04T16:22:09Z","timestamp":1614874929000},"page":"1821-1835","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":29,"title":["Finding Cracks in Shields: On the Security of Control Flow Integrity Mechanisms"],"prefix":"10.1145","author":[{"given":"Yuan","family":"Li","sequence":"first","affiliation":[{"name":"BNRist &amp; INSC, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingzhe","family":"Wang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chao","family":"Zhang","sequence":"additional","affiliation":[{"name":"BNRist &amp; INSC, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingman","family":"Chen","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Songtao","family":"Yang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ying","family":"Liu","sequence":"additional","affiliation":[{"name":"BNRist &amp; INSC, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,11,2]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"[n.d.]. Capstone the ultimzte disassembly framework. http:\/\/www.capstoneengine.org\/.  [n.d.]. Capstone the ultimzte disassembly framework. http:\/\/www.capstoneengine.org\/."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134618"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978358"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1993498.1993540"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076783"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.23"},{"key":"e_1_3_2_2_8_1","volume-title":"Rami G\u00f6khan Kici, and Sorin Lerner","author":"Bounov Dimitar","year":"2016"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3054924"},{"key":"e_1_3_2_2_10_1","volume-title":"Prof. of ISOC Network & Distributed System Security Symposium (NDSS). https:\/\/hexhive. epfl. ch\/publications\/-files\/18NDSS.pdf.","author":"Burow Nathan","year":"2018"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-21424-0_12"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"Yueqiang Cheng Zongwei Zhou Yu Miao Xuhua Ding and Robert H Deng. 2014. ROPecker: A generic and practical approach for defending against ROP attack. (2014).  Yueqiang Cheng Zongwei Zhou Yu Miao Xuhua Ding and Robert H Deng. 2014. ROPecker: A generic and practical approach for defending against ROP attack. (2014).","DOI":"10.14722\/ndss.2014.23156"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857722"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.26"},{"key":"e_1_3_2_2_15_1","first-page":"27","article-title":"MoCFI: A Framework to Mitigate Control-Flow Attacks on Smartphones","volume":"26","author":"Davi Lucas","year":"2012","journal-title":"NDSS"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2744847"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2593069.2596656"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"crossref","unstructured":"P de Clercq. 2017. Hardware supported Software and Control Flow Integrity. (2017).  P de Clercq. 2017. Hardware supported Software and Control Flow Integrity. (2017).","DOI":"10.1016\/j.cose.2017.03.013"},{"key":"e_1_3_2_2_19_1","volume-title":"26th {USENIX} Security Symposium ({USENIX} Security 17). 131--148.","author":"Ding Ren"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664249"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3037697.3037716"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.24"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.43"},{"key":"e_1_3_2_2_24_1","volume-title":"RAID 2018, Heraklion, Crete, Greece, September 10--12, 2018, Proceedings","volume":"11050","author":"Grossklags Jens","year":"2018"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029830"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1950365.1950398"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243797"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"crossref","unstructured":"Dongseok Jang Zachary Tatlock and Sorin Lerner. 2014. SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks.. In NDSS.  Dongseok Jang Zachary Tatlock and Sorin Lerner. 2014. SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks.. In NDSS.","DOI":"10.14722\/ndss.2014.23287"},{"key":"e_1_3_2_2_29_1","volume-title":"21st USENIX Security Symposium ({USENIX} Security 12)","author":"Kemerlis Vasileios P","year":"2012"},{"key":"e_1_3_2_2_30_1","volume-title":"Adaptive Call-site Sensitive Control Flow Integrity. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 95--110","author":"Khandaker Mustakimur","year":"2019"},{"key":"e_1_3_2_2_31_1","volume-title":"28th {USENIX} Security Symposium (USENIX Security 19). 195--211.","author":"Khandaker Mustakimur Rahman"},{"key":"e_1_3_2_2_32_1","volume-title":"11th {USENIX} Symposium on Operating Systems Design and Implementation ({OSDI} 14). 147--163.","author":"Kuznetsov Volodymyr"},{"key":"e_1_3_2_2_33_1","volume-title":"VM-CFI: Control-FlowIntegrity for Virtual Machine Kernel Using Intel PT. In International Conference on Computational Science and Its Applications. Springer, 127--137","author":"Kwon Donghyun","year":"2018"},{"key":"e_1_3_2_2_34_1","volume-title":"Jan-Erik Ekberg, and N Asokan.","author":"Liljestrand Hans","year":"2019"},{"key":"e_1_3_2_2_35_1","volume-title":"Proceedings of the 12th ACM Conference on Computer and Communications Security","author":"MartnAbadi MihaiBudiu","year":"2005"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813676"},{"key":"e_1_3_2_2_37_1","first-page":"27","article-title":"Opaque Control-Flow Integrity","volume":"26","author":"Mohan Vishwath","year":"2015","journal-title":"NDSS"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_2"},{"key":"e_1_3_2_2_39_1","volume-title":"Analyzing Control Flow Integrity with LLVM-CFI. arXiv preprint arXiv:1910.01485","author":"Muntean Paul","year":"2019"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594295"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660281"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66332-6_12"},{"key":"e_1_3_2_2_44_1","first-page":"1","article-title":"kBouncer: Efficient and transparent ROP mitigation","volume":"1","author":"Pappas Vasilis","year":"2012","journal-title":"Apr"},{"key":"e_1_3_2_2_45_1","volume-title":"Presented as part of the 22nd USENIX Security Symposium (USENIX Security 13). 447--462.","author":"Pappas Vasilis"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_8"},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523674"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"crossref","unstructured":"Aravind Prakash Xunchao Hu and Heng Yin. 2015. vfGuard: Strict Protection for Virtual Function Calls in COTS C++ Binaries.. In NDSS.  Aravind Prakash Xunchao Hu and Heng Yin. 2015. vfGuard: Strict Protection for Virtual Function Calls in COTS C++ Binaries.. In NDSS.","DOI":"10.14722\/ndss.2015.23297"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2133375.2133377"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991121"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.51"},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"crossref","unstructured":"Chengyu Song Chao Zhang Tielei Wang Wenke Lee and David Melski. 2015. Exploiting and Protecting Dynamic Code Generation.. In NDSS.  Chengyu Song Chao Zhang Tielei Wang Wenke Lee and David Melski. 2015. Exploiting and Protecting Dynamic Code Generation.. In NDSS.","DOI":"10.14722\/ndss.2015.23233"},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950296"},{"key":"e_1_3_2_2_54_1","volume-title":"Exploring control flow guard in windows 10. Available at ht tp:\/\/blog.trendmicro.com\/trendlabssecurityintelligence\/exploring-control-flow-guard-in-windows 10","author":"Tang Jack","year":"2015"},{"key":"e_1_3_2_2_55_1","volume-title":"Rap: Rip rop. In Hackers 2 Hackers Conference (H2HC).","author":"Team X","year":"2015"},{"key":"e_1_3_2_2_56_1","volume-title":"Enforcing Forward-Edge Control- Flow Integrity. In in GCC & LLVM. In 23rd USENIX Security Symposium (USENIX Security 14)","author":"Tice Caroline","year":"2014"},{"key":"e_1_3_2_2_57_1","volume-title":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. ACM, 927--940","author":"der Veen Victor Van","year":"2015"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.60"},{"key":"e_1_3_2_2_59_1","volume-title":"Control-Flow Integrity for Real-Time Embedded Systems. In 31st Euromicro Conference on Real-Time Systems (ECRTS","author":"Walls Robert J","year":"2019"},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818017"},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133986"},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.30"},{"key":"e_1_3_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00023"},{"key":"e_1_3_2_2_64_1","volume-title":"International Conference on Smart Card Research and Advanced Applications. Springer, 161--176","author":"Werner Mario","year":"2015"},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076739"},{"key":"e_1_3_2_2_66_1","volume-title":"IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN","author":"Xia Yubin","year":"2012"},{"key":"e_1_3_2_2_67_1","volume-title":"CRHC-02-05","author":"Xu Jun","year":"2002"},{"key":"e_1_3_2_2_68_1","volume-title":"CONFIRM: Evaluating Compatibility and Relevance of Control-flow Integrity Protections for Modern Software. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Xu Xiaoyang","year":"2019"},{"key":"e_1_3_2_2_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2015.7218424"},{"key":"e_1_3_2_2_70_1","volume-title":"Zhaofeng Chen, and Dawn Song.","author":"Zhang Chao","year":"2015"},{"key":"e_1_3_2_2_71_1","doi-asserted-by":"crossref","unstructured":"Chao Zhang Dawn Song Scott A Carr Mathias Payer Tongxin Li Yu Ding and Chengyu Song. 2016. VTrust: Regaining Trust on Virtual Calls.. In NDSS.  Chao Zhang Dawn Song Scott A Carr Mathias Payer Tongxin Li Yu Ding and Chengyu Song. 2016. VTrust: Regaining Trust on Virtual Calls.. In NDSS.","DOI":"10.14722\/ndss.2016.23164"},{"key":"e_1_3_2_2_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.44"},{"key":"e_1_3_2_2_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3075564.3075570"},{"key":"e_1_3_2_2_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2866164"},{"key":"e_1_3_2_2_75_1","volume-title":"Presented as part of the 22nd USENIX Security Symposium (USENIX Security 13). 337--352.","author":"Zhang Mingwei"}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3417867","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372297.3417867","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:31Z","timestamp":1750197691000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3417867"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,30]]},"references-count":75,"alternative-id":["10.1145\/3372297.3417867","10.1145\/3372297"],"URL":"https:\/\/doi.org\/10.1145\/3372297.3417867","relation":{},"subject":[],"published":{"date-parts":[[2020,10,30]]},"assertion":[{"value":"2020-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}