{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:44:27Z","timestamp":1772041467278,"version":"3.50.1"},"reference-count":95,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T00:00:00Z","timestamp":1608595200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"crossref","award":["N00014-17-1-2891"],"award-info":[{"award-number":["N00014-17-1-2891"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["D18AP00045"],"award-info":[{"award-number":["D18AP00045"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Science Foundation","award":["CNS-1749895 and CNS-1617902"],"award-info":[{"award-number":["CNS-1749895 and CNS-1617902"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2020,12,31]]},"abstract":"<jats:p>Gaining reliable arbitrary code execution through the exploitation of memory corruption vulnerabilities is becoming increasingly more difficult in the face of modern exploit mitigations. Facing this challenge, adversaries have started shifting their attention to data leakage attacks, which can lead to equally damaging outcomes, such as the disclosure of private keys or other sensitive data.<\/jats:p>\n          <jats:p>\n            In this work, we present a compiler-level defense against data leakage attacks for user-space applications. Our approach strikes a balance between the manual effort required to protect sensitive application data, and the performance overhead of achieving strong data confidentiality. To that end, we require developers to simply annotate those variables holding sensitive data, after which our framework automatically transforms only the\n            <jats:italic>fraction<\/jats:italic>\n            of the entire program code that is related to sensitive data operations. We implemented this approach by extending the LLVM compiler, and used it to protect memory-resident private keys in the MbedTLS server, ssh-agent, and a Libsodium-based file signing program, as well as user passwords for Lighttpd and Memcached. Our results demonstrate the feasibility and practicality of our technique: a modest runtime overhead (e.g., 13% throughput reduction for MbedTLS) that is on par with, or better than, existing state-of-the-art memory safety approaches for selective data protection.\n          <\/jats:p>","DOI":"10.1145\/3419475","type":"journal-article","created":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T22:11:26Z","timestamp":1608675086000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Mitigating Data-only Attacks by Protecting Memory-resident Sensitive Data"],"prefix":"10.1145","volume":"1","author":[{"given":"Tapti","family":"Palit","sequence":"first","affiliation":[{"name":"Stony Brook University, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabian","family":"Monrose","sequence":"additional","affiliation":[{"name":"UNC Chapel Hill, NC"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[{"name":"Stony Brook University, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,12,22]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Grsecurity. 2003. Retrieved from https:\/\/grsecurity.net\/.  Grsecurity. 2003. Retrieved from https:\/\/grsecurity.net\/."},{"key":"e_1_2_1_2_1","volume-title":"CPU2006 Benchmark. 2006","author":"SPEC","year":"2006","unstructured":"SPEC CPU2006 Benchmark. 2006 . Retrieved from http:\/\/www.spec.org\/cpu 2006 . SPEC CPU2006 Benchmark. 2006. Retrieved from http:\/\/www.spec.org\/cpu2006."},{"key":"e_1_2_1_3_1","unstructured":"The Heartbleed Bug. 2014. Retrieved from http:\/\/heartbleed.com\/.  The Heartbleed Bug. 2014. Retrieved from http:\/\/heartbleed.com\/."},{"key":"e_1_2_1_4_1","unstructured":"Control Flow Guard. 2015. Retrieved from https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/mt637065(v&equals;vs.85).aspx.  Control Flow Guard. 2015. Retrieved from https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/mt637065(v&equals;vs.85).aspx."},{"key":"e_1_2_1_5_1","unstructured":"CFL-based Unification-based Alias Analysis. 2016. Retrieved from https:\/\/github.com\/llvm-mirror\/llvm\/blob\/master\/lib\/Analysis\/.  CFL-based Unification-based Alias Analysis. 2016. Retrieved from https:\/\/github.com\/llvm-mirror\/llvm\/blob\/master\/lib\/Analysis\/."},{"key":"e_1_2_1_6_1","unstructured":"2016. Intel Streaming SIMD Extensions Technology. Retrieved from https:\/\/www.intel.com\/content\/www\/us\/en\/support\/articles\/806000005779\/processors.html. 807.  2016. Intel Streaming SIMD Extensions Technology. Retrieved from https:\/\/www.intel.com\/content\/www\/us\/en\/support\/articles\/806000005779\/processors.html. 807."},{"key":"e_1_2_1_7_1","unstructured":"GNU Binutils Gold Linker. 2018. Retrieved from https:\/\/www.gnu.org\/software\/binutils\/.  GNU Binutils Gold Linker. 2018. Retrieved from https:\/\/www.gnu.org\/software\/binutils\/."},{"key":"e_1_2_1_8_1","unstructured":"SSL Library mbed TLS. 2018. Retrieved from https:\/\/tls.mbed.org\/.  SSL Library mbed TLS. 2018. Retrieved from https:\/\/tls.mbed.org\/."},{"key":"e_1_2_1_9_1","unstructured":"The Sodium crypto library (libsodium). 2018. Retrieved from https:\/\/www.gitbook.com\/book\/jedisct1\/libsodium\/details.  The Sodium crypto library (libsodium). 2018. Retrieved from https:\/\/www.gitbook.com\/book\/jedisct1\/libsodium\/details."},{"key":"e_1_2_1_10_1","volume-title":"Intrinsics for Intel\u00ae Advanced Vector Extensions 2","author":"Overview","year":"2019","unstructured":"Overview : Intrinsics for Intel\u00ae Advanced Vector Extensions 2 . 2019 . Retrieved from https:\/\/software.intel.com\/en-us\/cpp-compiler-developer-guide-and-reference-overview-intrinsics-for-intel-advanced-vector-extensions-2-intel-avx2-instructions. Overview: Intrinsics for Intel\u00ae Advanced Vector Extensions 2. 2019. Retrieved from https:\/\/software.intel.com\/en-us\/cpp-compiler-developer-guide-and-reference-overview-intrinsics-for-intel-advanced-vector-extensions-2-intel-avx2-instructions."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the 19th USENIX Security Symposium.","author":"Akritidis Periklis","year":"2010","unstructured":"Periklis Akritidis . 2010 . Cling: A memory allocator to mitigate dangling pointers . In Proceedings of the 19th USENIX Security Symposium. Periklis Akritidis. 2010. Cling: A memory allocator to mitigate dangling pointers. In Proceedings of the 19th USENIX Security Symposium."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the IEEE Symposium on Security 8 Privacy (S8P\u201908)","author":"Akritidis Periklis","year":"2008","unstructured":"Periklis Akritidis , Cristian Cadar , Costin Raiciu , Manuel Costa , and Miguel Castro . 2008 . Preventing memory error exploits with WIT . In Proceedings of the IEEE Symposium on Security 8 Privacy (S8P\u201908) . 263--277. Periklis Akritidis, Cristian Cadar, Costin Raiciu, Manuel Costa, and Miguel Castro. 2008. Preventing memory error exploits with WIT. In Proceedings of the IEEE Symposium on Security 8 Privacy (S8P\u201908). 263--277."},{"key":"e_1_2_1_14_1","volume-title":"Proceedings of the 18th USENIX Security Symposium. 51--66","author":"Akritidis Periklis","year":"2009","unstructured":"Periklis Akritidis , Manuel Costa , Miguel Castro , and Steven Hand . 2009 . Baggy bounds checking: An efficient and backwards-compatible defense against out-of-bounds errors . In Proceedings of the 18th USENIX Security Symposium. 51--66 . Periklis Akritidis, Manuel Costa, Miguel Castro, and Steven Hand. 2009. Baggy bounds checking: An efficient and backwards-compatible defense against out-of-bounds errors. In Proceedings of the 18th USENIX Security Symposium. 51--66."},{"key":"e_1_2_1_16_1","unstructured":"Brad Antoniewicz. 2013. Analysis of a Malware ROP Chain. Retrieved from http:\/\/blog.opensecurityresearch.com\/2013\/10\/analysis-of-malware-rop-chain.html.  Brad Antoniewicz. 2013. Analysis of a Malware ROP Chain. Retrieved from http:\/\/blog.opensecurityresearch.com\/2013\/10\/analysis-of-malware-rop-chain.html."},{"key":"e_1_2_1_17_1","unstructured":"ARM. 2010. ARM TrustZone. Retrieved from https:\/\/developer.arm.com\/ip-products\/security-ip\/trustzone.  ARM. 2010. ARM TrustZone. Retrieved from https:\/\/developer.arm.com\/ip-products\/security-ip\/trustzone."},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation (OSDI\u201916)","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov , Bohdan Trach , Franz Gregor , Thomas Knauth , Andre Martin , Christian Priebe , Joshua Lind , Divya Muthukumaran , Dan O\u2019Keeffe , Mark Stillwell , et\u00a0al. 2016 . SCONE: Secure linux containers with intel SGX . In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation (OSDI\u201916) . 689--703. Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O\u2019Keeffe, Mark Stillwell, et\u00a0al. 2016. SCONE: Secure linux containers with intel SGX. In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation (OSDI\u201916). 689--703."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 16th Workshop on Hot Topics in Operating Systems (HotOS\u201917)","author":"Balasubramanian Abhiram","year":"2017","unstructured":"Abhiram Balasubramanian , Marek S. Baranowski , Anton Burtsev , Aurojit Panda , Zvonimir Rakamari\u0107 , and Leonid Ryzhyk . 2017 . System programming in Rust: Beyond safety . In Proceedings of the 16th Workshop on Hot Topics in Operating Systems (HotOS\u201917) . Abhiram Balasubramanian, Marek S. Baranowski, Anton Burtsev, Aurojit Panda, Zvonimir Rakamari\u0107, and Leonid Ryzhyk. 2017. System programming in Rust: Beyond safety. In Proceedings of the 16th Workshop on Hot Topics in Operating Systems (HotOS\u201917)."},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the International Static Analysis Symposium (SAS\u201916)","author":"Balatsouras George","year":"2016","unstructured":"George Balatsouras and Yannis Smaragdakis . 2016 . Structure-sensitive points-to analysis for C and C++ . In Proceedings of the International Static Analysis Symposium (SAS\u201916) . 84--104. George Balatsouras and Yannis Smaragdakis. 2016. Structure-sensitive points-to analysis for C and C++. In Proceedings of the International Static Analysis Symposium (SAS\u201916). 84--104."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 16th Workshop on Hot Topics in Operating Systems (HotOS\u201917)","author":"Baumann Andrew","year":"2017","unstructured":"Andrew Baumann . 2017 . Hardware is the new software . In Proceedings of the 16th Workshop on Hot Topics in Operating Systems (HotOS\u201917) . Andrew Baumann. 2017. Hardware is the new software. In Proceedings of the 16th Workshop on Hot Topics in Operating Systems (HotOS\u201917)."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201918)","author":"Belleville Brian","year":"2018","unstructured":"Brian Belleville , Joseph Michael Nash , Yeoul Na , Stijn Volckaert , Per Larsen , Michael Franz , Hyungon Moon , Jangseop Shin , Dongil Hwang , Seonhwa Jung , and Yunheung Paek . 2018 . Hardware assisted randomization of data . In Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201918) . Brian Belleville, Joseph Michael Nash, Yeoul Na, Stijn Volckaert, Per Larsen, Michael Franz, Hyungon Moon, Jangseop Shin, Dongil Hwang, Seonhwa Jung, and Yunheung Paek. 2018. Hardware assisted randomization of data. In Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201918)."},{"key":"e_1_2_1_23_1","unstructured":"Eli Bendersky. 2015. Pure-python library for parsing ELF and DWARF. Retrieved from https:\/\/github.com\/eliben\/pyelftools.  Eli Bendersky. 2015. Pure-python library for parsing ELF and DWARF. Retrieved from https:\/\/github.com\/eliben\/pyelftools."},{"key":"e_1_2_1_24_1","unstructured":"James Bennett Yichong Lin and Thoufique Haq. 2013. The Number of the Beast. Retrieved from http:\/\/blog.fireeye.com\/research\/2013\/02\/the-number-of-the-beast.html.  James Bennett Yichong Lin and Thoufique Haq. 2013. The Number of the Beast. Retrieved from http:\/\/blog.fireeye.com\/research\/2013\/02\/the-number-of-the-beast.html."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 27th ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI\u201906)","author":"Emery","unstructured":"Emery D. Berger and Benjamin G. Zorn. 2006. DieHard: Probabilistic memory safety for unsafe languages . In Proceedings of the 27th ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI\u201906) . 158--168. Emery D. Berger and Benjamin G. Zorn. 2006. DieHard: Probabilistic memory safety for unsafe languages. In Proceedings of the 27th ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI\u201906). 158--168."},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the 5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201908)","author":"Bhatkar Sandeep","unstructured":"Sandeep Bhatkar and R. Sekar . 2008. Data space randomization . In Proceedings of the 5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201908) . 1--22. Sandeep Bhatkar and R. Sekar. 2008. Data space randomization. In Proceedings of the 5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201908). 1--22."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2988336.2988350"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Brumley David","year":"2004","unstructured":"David Brumley and Dawn Song . 2004 . Privtrans: Automatically partitioning programs for privilege separation . In Proceedings of the 13th USENIX Security Symposium. David Brumley and Dawn Song. 2004. Privtrans: Automatically partitioning programs for privilege separation. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS\u201917)","author":"Scott","unstructured":"Scott A. Carr and Mathias Payer. 2017. DataShield: Configurable data confidentiality and integrity . In Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS\u201917) . 193--204. Scott A. Carr and Mathias Payer. 2017. DataShield: Configurable data confidentiality and integrity. In Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS\u201917). 193--204."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.5555\/1298455.1298470"},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Chen Shuo","unstructured":"Shuo Chen , Jun Xu , Emre C. Sezer , Prachi Gauriar , and Ravishankar K. Iyer . 2005. Non-control-data attacks are realistic threats . In Proceedings of the 14th USENIX Security Symposium. Shuo Chen, Jun Xu, Emre C. Sezer, Prachi Gauriar, and Ravishankar K. Iyer. 2005. Non-control-data attacks are realistic threats. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_32_1","volume-title":"The Design of Rijndael: AES-the Advanced Encryption Standard","author":"Daemen Joan","unstructured":"Joan Daemen and Vincent Rijmen . 2013. The Design of Rijndael: AES-the Advanced Encryption Standard . Springer Science 8 Business Media. Joan Daemen and Vincent Rijmen. 2013. The Design of Rijndael: AES-the Advanced Encryption Standard. Springer Science 8 Business Media."},{"key":"e_1_2_1_33_1","unstructured":"Jamie Danielson. 2017. ProcessMitigations 1.0.7. Retrieved from https:\/\/www.powershellgallery.com\/packages\/ProcessMitigations\/1.0.7.  Jamie Danielson. 2017. ProcessMitigations 1.0.7. Retrieved from https:\/\/www.powershellgallery.com\/packages\/ProcessMitigations\/1.0.7."},{"key":"e_1_2_1_34_1","volume-title":"Minisign: A dead simple tool to sign files and verify digital signatures.","author":"Denis Frank","year":"2018","unstructured":"Frank Denis . 2018 . Minisign: A dead simple tool to sign files and verify digital signatures. Retrieved from https:\/\/github.com\/jedisct1\/minisign. Frank Denis. 2018. Minisign: A dead simple tool to sign files and verify digital signatures. Retrieved from https:\/\/github.com\/jedisct1\/minisign."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/780732.780743"},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the 7th Symposium on Operating Systems Design and Implementation (OSDI\u201906)","author":"Erlingsson \u00dalfar","unstructured":"\u00dalfar Erlingsson , Mart\u00edn Abadi , Michael Vrable , Mihai Budiu , and George C. Necula . 2006. (XFI): Software guards for system address spaces . In Proceedings of the 7th Symposium on Operating Systems Design and Implementation (OSDI\u201906) . \u00dalfar Erlingsson, Mart\u00edn Abadi, Michael Vrable, Mihai Budiu, and George C. Necula. 2006. (XFI): Software guards for system address spaces. In Proceedings of the 7th Symposium on Operating Systems Design and Implementation (OSDI\u201906)."},{"key":"e_1_2_1_37_1","volume-title":"Proceedings of Black Hat Europe.","author":"Falcon Francisco","year":"2015","unstructured":"Francisco Falcon . 2015 . Exploiting adobe flash player in the era of control flow guard . In Proceedings of Black Hat Europe. Francisco Falcon. 2015. Exploiting adobe flash player in the era of control flow guard. In Proceedings of Black Hat Europe."},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the 29th Annual Computer Security Applications Conference (ACSAC\u201913)","author":"Garmany Behrad","year":"2013","unstructured":"Behrad Garmany and Tilo M\u00fcller . 2013 . PRIME: Private RSA infrastructure for memory-less encryption . In Proceedings of the 29th Annual Computer Security Applications Conference (ACSAC\u201913) . 149--158. Behrad Garmany and Tilo M\u00fcller. 2013. PRIME: Private RSA infrastructure for memory-less encryption. In Proceedings of the 29th Annual Computer Security Applications Conference (ACSAC\u201913). 149--158."},{"key":"e_1_2_1_39_1","unstructured":"Dan Goodin. 2007. Safari zero-day exploit nets $10 000 prize. Retrieved from https:\/\/www.theregister.co.uk\/2007\/04\/20\/pwn-2-own_winner\/.  Dan Goodin. 2007. Safari zero-day exploit nets $10 000 prize. Retrieved from https:\/\/www.theregister.co.uk\/2007\/04\/20\/pwn-2-own_winner\/."},{"key":"e_1_2_1_40_1","unstructured":"Brian Gorenc. 2017. Pwn2Own 2017\u2014An Event for the Ages. Retrieved from http:\/\/blog.trendmicro.com\/pwn2own-2017-event-ages\/.  Brian Gorenc. 2017. Pwn2Own 2017\u2014An Event for the Ages. Retrieved from http:\/\/blog.trendmicro.com\/pwn2own-2017-event-ages\/."},{"key":"e_1_2_1_41_1","volume-title":"Intel\u00ae advanced encryption standard (AES) new instructions set","author":"Gueron Shay","unstructured":"Shay Gueron . 2010. Intel\u00ae advanced encryption standard (AES) new instructions set . Intel Corporation . Shay Gueron. 2010. Intel\u00ae advanced encryption standard (AES) new instructions set. Intel Corporation."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831155"},{"key":"e_1_2_1_43_1","volume-title":"Proceedings of the 37th IEEE Symposium on Security 8 Privacy (S8P\u201916)","author":"Hu Hong","year":"2016","unstructured":"Hong Hu , Shweta Shinde , Sendroiu Adrian , Zheng Leong Chua , Prateek Saxena , and Zhenkai Liang . 2016 . Data-oriented programming: On the expressiveness of non-control data attacks . In Proceedings of the 37th IEEE Symposium on Security 8 Privacy (S8P\u201916) . Hong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua, Prateek Saxena, and Zhenkai Liang. 2016. Data-oriented programming: On the expressiveness of non-control data attacks. In Proceedings of the 37th IEEE Symposium on Security 8 Privacy (S8P\u201916)."},{"key":"e_1_2_1_44_1","unstructured":"Intel. 2015. Software Guard Extensions SDK. Retrieved from https:\/\/software.intel.com\/sites\/default\/files\/managed\/b4\/cf\/Intel-SGX-SDK-Developer-Reference-for-Windows-OS.pdf.  Intel. 2015. Software Guard Extensions SDK. Retrieved from https:\/\/software.intel.com\/sites\/default\/files\/managed\/b4\/cf\/Intel-SGX-SDK-Developer-Reference-for-Windows-OS.pdf."},{"key":"e_1_2_1_45_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC\u201902)","author":"Jim Trevor","year":"2002","unstructured":"Trevor Jim , J. Greg Morrisett , Dan Grossman , Michael W. Hicks , James Cheney , and Yanling Wang . 2002 . Cyclone: A safe dialect of C . In Proceedings of the USENIX Annual Technical Conference (ATC\u201902) . 275--288. Trevor Jim, J. Greg Morrisett, Dan Grossman, Michael W. Hicks, James Cheney, and Yanling Wang. 2002. Cyclone: A safe dialect of C. In Proceedings of the USENIX Annual Technical Conference (ATC\u201902). 275--288."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3062341.3062376"},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 40th IEEE Symposium on Security 8 Privacy (S8P\u201919)","author":"Kocher Paul","year":"2019","unstructured":"Paul Kocher , Jann Horn , Anders Fogh , Daniel Genkin , Daniel Gruss , Werner Haas , Mike Hamburg , Moritz Lipp , Stefan Mangard , Thomas Prescher , Michael Schwarz , and Yuval Yarom . 2019 . Spectre attacks: Exploiting speculative execution . In Proceedings of the 40th IEEE Symposium on Security 8 Privacy (S8P\u201919) . Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2019. Spectre attacks: Exploiting speculative execution. In Proceedings of the 40th IEEE Symposium on Security 8 Privacy (S8P\u201919)."},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the 12th European Conference on Computer Systems (EuroSys\u201917)","author":"Koning Koen","year":"2017","unstructured":"Koen Koning , Xi Chen , Herbert Bos , Cristiano Giuffrida , and Elias Athanasopoulos . 2017 . No need to hide: Protecting safe regions on commodity hardware . In Proceedings of the 12th European Conference on Computer Systems (EuroSys\u201917) . 437--452. Koen Koning, Xi Chen, Herbert Bos, Cristiano Giuffrida, and Elias Athanasopoulos. 2017. No need to hide: Protecting safe regions on commodity hardware. In Proceedings of the 12th European Conference on Computer Systems (EuroSys\u201917). 437--452."},{"key":"e_1_2_1_49_1","unstructured":"Vadim Kotov. 2014. Dissecting the newest IE10 0-day exploit (CVE-2014-0322). Retrieved from http:\/\/labs.bromium.com\/2014\/02\/25\/dissecting-the-newest-ie10-0-day-exploit-cve-2014-0322\/.  Vadim Kotov. 2014. Dissecting the newest IE10 0-day exploit (CVE-2014-0322). Retrieved from http:\/\/labs.bromium.com\/2014\/02\/25\/dissecting-the-newest-ie10-0-day-exploit-cve-2014-0322\/."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/2685048.2685061"},{"key":"e_1_2_1_51_1","unstructured":"MWR Labs. 2013. MWR Labs Pwn2Own 2013 Write-up - Webkit Exploit. Retrieved from https:\/\/labs.mwrinfosecurity.com\/blog\/mwr-labs-pwn2own-2013-write-up-webkit-exploit\/.  MWR Labs. 2013. MWR Labs Pwn2Own 2013 Write-up - Webkit Exploit. Retrieved from https:\/\/labs.mwrinfosecurity.com\/blog\/mwr-labs-pwn2own-2013-write-up-webkit-exploit\/."},{"key":"e_1_2_1_52_1","unstructured":"Michael Larabel. 2016. The Current Spectre \/ Meltdown Mitigation Overhead Benchmarks On Linux 5.0. Retrieved from https:\/\/www.phoronix.com\/scan.php?page&equals;article&item&equals;&equals;linux50-spectre-meltdown.  Michael Larabel. 2016. The Current Spectre \/ Meltdown Mitigation Overhead Benchmarks On Linux 5.0. Retrieved from https:\/\/www.phoronix.com\/scan.php?page&equals;article&item&equals;&equals;linux50-spectre-meltdown."},{"key":"e_1_2_1_53_1","volume-title":"Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI\u201905)","author":"Lattner Chris","year":"2005","unstructured":"Chris Lattner and Vikram Adve . 2005 . Automatic pool allocation: Improving performance by controlling data structure layout in the heap . In Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI\u201905) . 129--142. Chris Lattner and Vikram Adve. 2005. Automatic pool allocation: Improving performance by controlling data structure layout in the heap. In Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI\u201905). 129--142."},{"key":"e_1_2_1_54_1","volume-title":"Proceedings of the 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915)","author":"Lee Byoungyoung","year":"2015","unstructured":"Byoungyoung Lee , Chengyu Song , Yeongjin Jang , Tielei Wang , Taesoo Kim , Long Lu , and Wenke Lee . 2015 . Preventing use-after-free with dangling pointers nullification . In Proceedings of the 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915) . Byoungyoung Lee, Chengyu Song, Yeongjin Jang, Tielei Wang, Taesoo Kim, Long Lu, and Wenke Lee. 2015. Preventing use-after-free with dangling pointers nullification. In Proceedings of the 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915)."},{"key":"e_1_2_1_55_1","unstructured":"Haifei Li. 2011. Understanding and exploiting flash actionscript vulnerabilities. CanSecWest.  Haifei Li. 2011. Understanding and exploiting flash actionscript vulnerabilities. CanSecWest."},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC\u201917)","author":"Lind Joshua","year":"2017","unstructured":"Joshua Lind , Christian Priebe , Divya Muthukumaran , Dan O\u2019Keeffe , Pierre-Louis Aublin , Florian Kelbert , Tobias Reiher , David Goltzsche , David Eyers , R\u00fcdiger Kapitza , Christof Fetzer , and Peter Pietzuch . 2017 . Glamdring: Automatic application partitioning for Intel SGX . In Proceedings of the USENIX Annual Technical Conference (ATC\u201917) . Joshua Lind, Christian Priebe, Divya Muthukumaran, Dan O\u2019Keeffe, Pierre-Louis Aublin, Florian Kelbert, Tobias Reiher, David Goltzsche, David Eyers, R\u00fcdiger Kapitza, Christof Fetzer, and Peter Pietzuch. 2017. Glamdring: Automatic application partitioning for Intel SGX. In Proceedings of the USENIX Annual Technical Conference (ATC\u201917)."},{"key":"e_1_2_1_57_1","volume-title":"Proceedings of the 27th USENIX Security Symposium.","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Anders Fogh , Jann Horn , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018 . Meltdown: Reading kernel memory from user space . In Proceedings of the 27th USENIX Security Symposium. Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading kernel memory from user space. In Proceedings of the 27th USENIX Security Symposium."},{"key":"e_1_2_1_58_1","volume-title":"Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915)","author":"Liu Yutao","year":"2015","unstructured":"Yutao Liu , Tianyu Zhou , Kexin Chen , Haibo Chen , and Yubin Xia . 2015 . Thwarting memory disclosure with efficient hypervisor-enforced intra-domain isolation . In Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915) . 1607--1619. Yutao Liu, Tianyu Zhou, Kexin Chen, Haibo Chen, and Yubin Xia. 2015. Thwarting memory disclosure with efficient hypervisor-enforced intra-domain isolation. In Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915). 1607--1619."},{"key":"e_1_2_1_59_1","unstructured":"Chris Lomont. 2016. Introduction to Intel Advanced Vector Extensions. Retrieved from https:\/\/software.intel.com\/en-us\/articles\/introduction-to-intel-advanced-vector-extensions.  Chris Lomont. 2016. Introduction to Intel Advanced Vector Extensions. Retrieved from https:\/\/software.intel.com\/en-us\/articles\/introduction-to-intel-advanced-vector-extensions."},{"key":"e_1_2_1_60_1","volume-title":"Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS\u201908)","author":"Lvin Vitaliy B.","unstructured":"Vitaliy B. Lvin , Gene Novark , Emery D. Berger , and Benjamin G. Zorn . 2008. Archipelago: Trading address space for reliability and security . In Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS\u201908) . 115--124. Vitaliy B. Lvin, Gene Novark, Emery D. Berger, and Benjamin G. Zorn. 2008. Archipelago: Trading address space for reliability and security. In Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS\u201908). 115--124."},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915)","author":"Mashtizadeh Ali Jose","year":"2015","unstructured":"Ali Jose Mashtizadeh , Andrea Bittau , Dan Boneh , and David Mazi\u00e8res . 2015 . CCFI: Cryptographically enforced control flow integrity . In Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915) . 941--951. Ali Jose Mashtizadeh, Andrea Bittau, Dan Boneh, and David Mazi\u00e8res. 2015. CCFI: Cryptographically enforced control flow integrity. In Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915). 941--951."},{"key":"e_1_2_1_62_1","volume-title":"Daniel Genkin, Daniel Gruss, Berk Sunar, Frank Piessens, and Yuval Yarom.","author":"Minkin Marina","year":"2019","unstructured":"Marina Minkin , Daniel Moghimi , Moritz Lipp , Michael Schwarz , Jo Van Bulck , Daniel Genkin, Daniel Gruss, Berk Sunar, Frank Piessens, and Yuval Yarom. 2019 . Fallout : Reading kernel writes From user space. In arXiv preprint arXiv:1905.12701. Marina Minkin, Daniel Moghimi, Moritz Lipp, Michael Schwarz, Jo Van Bulck, Daniel Genkin, Daniel Gruss, Berk Sunar, Frank Piessens, and Yuval Yarom. 2019. Fallout: Reading kernel writes From user space. In arXiv preprint arXiv:1905.12701."},{"key":"e_1_2_1_63_1","unstructured":"Daniel Moghimi. 2014. Subverting without EIP. Retrieved from http:\/\/www.moghimi.org\/subverting-without-eip\/.  Daniel Moghimi. 2014. Subverting without EIP. Retrieved from http:\/\/www.moghimi.org\/subverting-without-eip\/."},{"key":"e_1_2_1_64_1","volume-title":"Proceedings of the 3rd IEEE European Symposium on Security 8 Privacy (Euro S8P\u201918)","author":"Morton Micah","year":"2018","unstructured":"Micah Morton , Jan Werner , Panagiotis Kintis , Kevin Z. Snow , Manos Antonakakis , Michalis Polychronakis , and Fabian Monrose . 2018 . Security risks in asynchronous web servers: When performance optimizations amplify the impact of data-oriented attacks . In Proceedings of the 3rd IEEE European Symposium on Security 8 Privacy (Euro S8P\u201918) . Micah Morton, Jan Werner, Panagiotis Kintis, Kevin Z. Snow, Manos Antonakakis, Michalis Polychronakis, and Fabian Monrose. 2018. Security risks in asynchronous web servers: When performance optimizations amplify the impact of data-oriented attacks. In Proceedings of the 3rd IEEE European Symposium on Security 8 Privacy (Euro S8P\u201918)."},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the 20th USENIX Security Symposium.","author":"M\u00fcller Tilo","year":"2011","unstructured":"Tilo M\u00fcller , Felix C. Freiling , and Andreas Dewald . 2011 . TRESOR runs encryption securely outside RAM . In Proceedings of the 20th USENIX Security Symposium. Tilo M\u00fcller, Felix C. Freiling, and Andreas Dewald. 2011. TRESOR runs encryption securely outside RAM. In Proceedings of the 20th USENIX Security Symposium."},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 1st Summit on Advances in Programming Languages (SNAPL\u201915)","author":"Nagarakatte Santosh","year":"2015","unstructured":"Santosh Nagarakatte , Milo M. K. Martin , and Steve Zdancewic . 2015 . Everything you want to know about pointer-based checking . In Proceedings of the 1st Summit on Advances in Programming Languages (SNAPL\u201915) . 190--208. Santosh Nagarakatte, Milo M. K. Martin, and Steve Zdancewic. 2015. Everything you want to know about pointer-based checking. In Proceedings of the 1st Summit on Advances in Programming Languages (SNAPL\u201915). 190--208."},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542504"},{"key":"e_1_2_1_68_1","volume-title":"Proceedings of the International Symposium on Memory Management (ISMM\u201910)","author":"Nagarakatte Santosh","year":"2010","unstructured":"Santosh Nagarakatte , Jianzhou Zhao , Milo M. K. Martin , and Steve Zdancewic . 2010 . CETS: Compiler enforced temporal safety for C . In Proceedings of the International Symposium on Memory Management (ISMM\u201910) . 31--40. Santosh Nagarakatte, Jianzhou Zhao, Milo M. K. Martin, and Steve Zdancewic. 2010. CETS: Compiler enforced temporal safety for C. In Proceedings of the International Symposium on Memory Management (ISMM\u201910). 31--40."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065887.1065892"},{"key":"e_1_2_1_70_1","volume-title":"Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS\u201910)","author":"Novark Gene","unstructured":"Gene Novark and Emery D. Berger . 2010. DieHarder: Securing the heap . In Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS\u201910) . 573--584. Gene Novark and Emery D. Berger. 2010. DieHarder: Securing the heap. In Proceedings of the 17th ACM Conference on Computer and Communications Security (CCS\u201910). 573--584."},{"key":"e_1_2_1_71_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS\u201917)","author":"Papadopoulos Panagiotis","year":"2017","unstructured":"Panagiotis Papadopoulos , Giorgos Vasiliadis , Giorgos Christou , Evangelos Markatos , and Sotiris Ioannidis . 2017 . No sugar but all the taste! memory encryption without architectural support . In Proceedings of the European Symposium on Research in Computer Security (ESORICS\u201917) . 362--380. Panagiotis Papadopoulos, Giorgos Vasiliadis, Giorgos Christou, Evangelos Markatos, and Sotiris Ioannidis. 2017. No sugar but all the taste! memory encryption without architectural support. In Proceedings of the European Symposium on Research in Computer Security (ESORICS\u201917). 362--380."},{"key":"e_1_2_1_72_1","unstructured":"Andrew Pardoe. 2017. Security Features in Microsoft Visual C++. Retrieved from https:\/\/blogs.msdn.microsoft.com\/vcblog\/2017\/06\/28\/security-features-in-microsoft-visual-c\/.  Andrew Pardoe. 2017. Security Features in Microsoft Visual C++. Retrieved from https:\/\/blogs.msdn.microsoft.com\/vcblog\/2017\/06\/28\/security-features-in-microsoft-visual-c\/."},{"key":"e_1_2_1_73_1","unstructured":"PaX Team. 2003. Address Space Layout Randomization. Retrieved from http:\/\/pax.grsecurity.net\/docs\/aslr.txt.  PaX Team. 2003. Address Space Layout Randomization. Retrieved from http:\/\/pax.grsecurity.net\/docs\/aslr.txt."},{"key":"e_1_2_1_74_1","unstructured":"PaX Team. 2003. Paging Based Non-executable Pages. Retrieved from http:\/\/pax.grsecurity.net\/docs\/pageexec.txt.  PaX Team. 2003. Paging Based Non-executable Pages. Retrieved from http:\/\/pax.grsecurity.net\/docs\/pageexec.txt."},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/1290520.1290524"},{"key":"e_1_2_1_76_1","volume-title":"Proceedings of the 12th USENIX Security Symposium.","author":"Provos Niels","year":"2003","unstructured":"Niels Provos , Markus Friedl , and Peter Honeyman . 2003 . Preventing privilege escalation . In Proceedings of the 12th USENIX Security Symposium. Niels Provos, Markus Friedl, and Peter Honeyman. 2003. Preventing privilege escalation. In Proceedings of the 12th USENIX Security Symposium."},{"key":"e_1_2_1_77_1","volume-title":"Proceedings of the 2nd IEEE European Symposium on Security 8 Privacy (Euro S8P\u201917)","author":"Rogowski Roman","year":"2017","unstructured":"Roman Rogowski , Micah Morton , Forrest Li , Kevin Z. Snow , Fabian Monrose , and Michalis Polychronakis . 2017 . Revisiting browser security in the modern era: New data-only attacks and defenses . In Proceedings of the 2nd IEEE European Symposium on Security 8 Privacy (Euro S8P\u201917) . Roman Rogowski, Micah Morton, Forrest Li, Kevin Z. Snow, Fabian Monrose, and Michalis Polychronakis. 2017. Revisiting browser security in the modern era: New data-only attacks and defenses. In Proceedings of the 2nd IEEE European Symposium on Security 8 Privacy (Euro S8P\u201917)."},{"key":"e_1_2_1_78_1","volume-title":"Proceedings of the 11th Network and Distributed System Security Symposium (NDSS\u201904)","author":"Ruwase Olatunji","unstructured":"Olatunji Ruwase and Monica S. Lam . 2004. A practical dynamic buffer overflow detector . In Proceedings of the 11th Network and Distributed System Security Symposium (NDSS\u201904) . 159--169. Olatunji Ruwase and Monica S. Lam. 2004. A practical dynamic buffer overflow detector. In Proceedings of the 11th Network and Distributed System Security Symposium (NDSS\u201904). 159--169."},{"key":"e_1_2_1_79_1","volume-title":"Proceedings of the 36th IEEE Symposium on Security 8 Privacy (S8P\u201915)","author":"Schuster Felix","year":"2015","unstructured":"Felix Schuster , Manuel Costa , C\u00e9dric Fournet , Christos Gkantsidis , Marcus Peinado , Gloria Mainar-Ruiz , and Mark Russinovich . 2015 . VC3: Trustworthy data analytics in the cloud using SGX . In Proceedings of the 36th IEEE Symposium on Security 8 Privacy (S8P\u201915) . IEEE, 38--54. Felix Schuster, Manuel Costa, C\u00e9dric Fournet, Christos Gkantsidis, Marcus Peinado, Gloria Mainar-Ruiz, and Mark Russinovich. 2015. VC3: Trustworthy data analytics in the cloud using SGX. In Proceedings of the 36th IEEE Symposium on Security 8 Privacy (S8P\u201915). IEEE, 38--54."},{"key":"e_1_2_1_80_1","volume-title":"Proceedings of the 27th Annual Network and Distributed System Security Symposium (NDSS\u201920)","author":"Schwarz Michael","year":"2020","unstructured":"Michael Schwarz , Moritz Lipp , Claudio Canella , Robert Schilling , Florian Kargl , and Daniel Gruss . 2020 . ConTExT: A generic approach for mitigating spectre . In Proceedings of the 27th Annual Network and Distributed System Security Symposium (NDSS\u201920) . Michael Schwarz, Moritz Lipp, Claudio Canella, Robert Schilling, Florian Kargl, and Daniel Gruss. 2020. ConTExT: A generic approach for mitigating spectre. In Proceedings of the 27th Annual Network and Distributed System Security Symposium (NDSS\u201920)."},{"key":"e_1_2_1_81_1","unstructured":"Fermin J. Serna. 2012. CVE-2012-0769 the case of the perfect info leak. Retrieved from http:\/\/zhodiac.hispahack.com\/my-stuff\/security\/Flash_ASLR_bypass.pdf.  Fermin J. Serna. 2012. CVE-2012-0769 the case of the perfect info leak. Retrieved from http:\/\/zhodiac.hispahack.com\/my-stuff\/security\/Flash_ASLR_bypass.pdf."},{"key":"e_1_2_1_82_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S8P\u201916)","author":"Song C.","unstructured":"C. Song , H. Moon , M. Alam , I. Yun , B. Lee , T. Kim , W. Lee , and Y. Paek . 2016. HDFI: Hardware-assisted data-flow isolation . In Proceedings of the IEEE Symposium on Security and Privacy (S8P\u201916) . C. Song, H. Moon, M. Alam, I. Yun, B. Lee, T. Kim, W. Lee, and Y. Paek. 2016. HDFI: Hardware-assisted data-flow isolation. In Proceedings of the IEEE Symposium on Security and Privacy (S8P\u201916)."},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/237721.237727"},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"e_1_2_1_85_1","volume-title":"Proceedings of Black Hat Asia.","author":"Sun Bing","year":"2017","unstructured":"Bing Sun , Chong Xu , and Stanley Zhu . 2017 . The power of data-oriented attacks: Bypassing memory mitigation using data-only exploitation . In Proceedings of Black Hat Asia. Bing Sun, Chong Xu, and Stanley Zhu. 2017. The power of data-oriented attacks: Bypassing memory mitigation using data-only exploitation. In Proceedings of Black Hat Asia."},{"key":"e_1_2_1_86_1","volume-title":"Proceedings of the 34th IEEE Symposium on Security and Privacy (S8P\u201913)","author":"Szekeres Laszlo","year":"2013","unstructured":"Laszlo Szekeres , Mathias Payer , Tao Wei , and Dawn Song . 2013 . SoK: Eternal war in memory . In Proceedings of the 34th IEEE Symposium on Security and Privacy (S8P\u201913) . 48--62. Laszlo Szekeres, Mathias Payer, Tao Wei, and Dawn Song. 2013. SoK: Eternal war in memory. In Proceedings of the 34th IEEE Symposium on Security and Privacy (S8P\u201913). 48--62."},{"key":"e_1_2_1_87_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC\u201917)","author":"Tsai Chia-Che","year":"2017","unstructured":"Chia-Che Tsai , Donald E. Porter , and Mona Vij . 2017 . Graphene-SGX: A practical library OS for unmodified applications on SGX . In Proceedings of the USENIX Annual Technical Conference (ATC\u201917) . Chia-Che Tsai, Donald E. Porter, and Mona Vij. 2017. Graphene-SGX: A practical library OS for unmodified applications on SGX. In Proceedings of the USENIX Annual Technical Conference (ATC\u201917)."},{"key":"e_1_2_1_88_1","volume-title":"Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915)","author":"van der Veen Victor","year":"2015","unstructured":"Victor van der Veen , Dennis Andriesse , Enes G\u00f6kta\u015f , Ben Gras , Lionel Sambuc , Asia Slowinska , Herbert Bos , and Cristiano Giuffrida . 2015 . Practical context-sensitive CFI . In Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915) . 927--940. Victor van der Veen, Dennis Andriesse, Enes G\u00f6kta\u015f, Ben Gras, Lionel Sambuc, Asia Slowinska, Herbert Bos, and Cristiano Giuffrida. 2015. Practical context-sensitive CFI. In Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS\u201915). 927--940."},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the 40th IEEE Symposium on Security 8 Privacy (S8P\u201919)","author":"van Schaik Stephan","year":"2019","unstructured":"Stephan van Schaik , Alyssa Milburn , Sebastian Austerlund , Pietro Frigo , Giorgi Maisuradze , Kaveh Razavi , Herbert Bos , and Cristiano Giuffrida . 2019 . RIDL: Rogue in-flight data load . In Proceedings of the 40th IEEE Symposium on Security 8 Privacy (S8P\u201919) . Stephan van Schaik, Alyssa Milburn, Sebastian Austerlund, Pietro Frigo, Giorgi Maisuradze, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2019. RIDL: Rogue in-flight data load. In Proceedings of the 40th IEEE Symposium on Security 8 Privacy (S8P\u201919)."},{"key":"e_1_2_1_90_1","volume-title":"Proceedings of the 21st ACM Conference on Computer and Communications Security (CCS\u201914)","author":"Vasiliadis Giorgos","year":"2014","unstructured":"Giorgos Vasiliadis , Elias Athanasopoulos , Michalis Polychronakis , and Sotiris Ioannidis . 2014 . PixelVault: Using GPUs for securing cryptographic operations . In Proceedings of the 21st ACM Conference on Computer and Communications Security (CCS\u201914) . 1131--1142. Giorgos Vasiliadis, Elias Athanasopoulos, Michalis Polychronakis, and Sotiris Ioannidis. 2014. PixelVault: Using GPUs for securing cryptographic operations. In Proceedings of the 21st ACM Conference on Computer and Communications Security (CCS\u201914). 1131--1142."},{"key":"e_1_2_1_91_1","volume-title":"Proceedings of the 14th ACM Symposium on Operating Systems Principles (SOSP\u201993)","author":"Wahbe Robert","unstructured":"Robert Wahbe , Steven Lucco , Thomas E. Anderson , and Susan L. Graham . 1993. Efficient software-based fault isolation . In Proceedings of the 14th ACM Symposium on Operating Systems Principles (SOSP\u201993) . 203--216. Robert Wahbe, Steven Lucco, Thomas E. Anderson, and Susan L. Graham. 1993. Efficient software-based fault isolation. In Proceedings of the 14th ACM Symposium on Operating Systems Principles (SOSP\u201993). 203--216."},{"key":"e_1_2_1_92_1","unstructured":"David Weston and Matt Miller. 2016. Windows 10 mitigation improvements. Black Hat USA.  David Weston and Matt Miller. 2016. Windows 10 mitigation improvements. Black Hat USA."},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the ACM International Conference on Virtual Execution Environments (VEE\u201908)","author":"Yang Jisoo","unstructured":"Jisoo Yang and Kang G. Shin . 2008. Using hypervisor to provide data secrecy for user applications on a per-page basis . In Proceedings of the ACM International Conference on Virtual Execution Environments (VEE\u201908) . 71--80. Jisoo Yang and Kang G. Shin. 2008. Using hypervisor to provide data secrecy for user applications on a per-page basis. In Proceedings of the ACM International Conference on Virtual Execution Environments (VEE\u201908). 71--80."},{"key":"e_1_2_1_94_1","volume-title":"Proceedings of the 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915)","author":"Younan Yves","year":"2015","unstructured":"Yves Younan . 2015 . FreeSentry: Protecting against use-after-free vulnerabilities due to dangling pointers . In Proceedings of the 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915) . Yves Younan. 2015. FreeSentry: Protecting against use-after-free vulnerabilities due to dangling pointers. In Proceedings of the 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915)."},{"key":"e_1_2_1_95_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201919)","author":"Yun Min Hong","year":"2019","unstructured":"Min Hong Yun and Lin Zhong . 2019 . Ginseng: Keeping secrets in registers when you distrust the operating system . In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201919) . Min Hong Yun and Lin Zhong. 2019. Ginseng: Keeping secrets in registers when you distrust the operating system. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201919)."},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046713"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3419475","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3419475","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3419475","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:42Z","timestamp":1750197702000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3419475"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,22]]},"references-count":95,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,12,31]]}},"alternative-id":["10.1145\/3419475"],"URL":"https:\/\/doi.org\/10.1145\/3419475","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,12,22]]},"assertion":[{"value":"2020-05-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-12-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}