{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T01:36:52Z","timestamp":1766281012292,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,17]],"date-time":"2021-08-17T00:00:00Z","timestamp":1629158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EPSRC","award":["EP\/P009301\/1"],"award-info":[{"award-number":["EP\/P009301\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,8,17]]},"DOI":"10.1145\/3465481.3470116","type":"proceedings-article","created":{"date-parts":[[2021,8,16]],"date-time":"2021-08-16T17:57:21Z","timestamp":1629136641000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["RansomClave: Ransomware Key Management using SGX"],"prefix":"10.1145","author":[{"given":"Alpesh","family":"Bhudia","sequence":"first","affiliation":[{"name":"Royal Holloway, University of London, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"O'Keeffe","sequence":"additional","affiliation":[{"name":"Royal Holloway, University of London, GB"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniele","family":"Sgandurra","sequence":"additional","affiliation":[{"name":"Royal Holloway, University of London, GB"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Darren","family":"Hurley-Smith","sequence":"additional","affiliation":[{"name":"Royal Holloway, University of London, GB"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,8,17]]},"reference":[{"doi-asserted-by":"crossref","unstructured":"B. Al-rimy 2018. Ransomware threat success factors taxonomy and countermeasures: A survey and research directions. Comput & Sec. (2018).","key":"e_1_3_2_1_1_1","DOI":"10.1016\/j.cose.2018.01.001"},{"key":"e_1_3_2_1_2_1","volume-title":"HASP '13","author":"Anati Ittai","year":"2013","unstructured":"Ittai Anati, Shay Gueron, Simon Johnson, and Vincent Scarlata. 2013. Innovative technology for CPU based attestation and sealing. In HASP '13."},{"volume-title":"Mastering Bitcoin: unlocking digital cryptocurrencies. O\u2019Reilly Media","author":"Antonopoulos M","unstructured":"Andreas\u00a0M Antonopoulos. 2014. Mastering Bitcoin: unlocking digital cryptocurrencies. O\u2019Reilly Media, Inc.","key":"e_1_3_2_1_3_1"},{"key":"e_1_3_2_1_4_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. In OSDI '16","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov, Bohdan Trach, Franz Gregor, 2016. SCONE: Secure Linux Containers with Intel SGX. In OSDI '16."},{"volume-title":"Int. Conference on Cyber Security '20","author":"Bajpai P.","unstructured":"P. Bajpai and R. Enbody. 2020. Memory forensics against ransomware. In Int. Conference on Cyber Security '20.","key":"e_1_3_2_1_5_1"},{"doi-asserted-by":"crossref","unstructured":"P. Bajpai A.\u00a0K. Sood and R. Enbody. 2018. A key-management-based taxonomy for ransomware. In APWG eCrime '18.","key":"e_1_3_2_1_6_1","DOI":"10.1109\/ECRIME.2018.8376213"},{"key":"e_1_3_2_1_7_1","volume":"200","author":"Bergeron J.","unstructured":"J. Bergeron, Mourad Debbabi, J. Desharnais, 2009. Static Detection of Malicious Code in Executable Programs. Int. J. of Req. Eng (2009).","journal-title":"J. Desharnais"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_8_1","DOI":"10.1109\/ACCESS.2019.2945839"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_9_1","DOI":"10.4018\/978-1-5225-0864-9.ch012"},{"key":"e_1_3_2_1_10_1","volume-title":"Secure Cloud Micro Services Using Intel SGX. In DAIS '17","author":"Brenner Stefan","year":"2017","unstructured":"Stefan Brenner, Tobias Hundt, Giovanni Mazzeo, 2017. Secure Cloud Micro Services Using Intel SGX. In DAIS '17."},{"key":"e_1_3_2_1_11_1","volume-title":"FlyClient: Super-Light Clients for Cryptocurrencies. In IEEE Symposium on Security and Privacy (SP) '20","author":"B\u00fcnz B.","year":"2020","unstructured":"B. B\u00fcnz, L. Kiffer, Loi Luu, 2020. FlyClient: Super-Light Clients for Cryptocurrencies. In IEEE Symposium on Security and Privacy (SP) '20."},{"doi-asserted-by":"crossref","unstructured":"E. Cartwright J. Hernandez-Castro and A. Cartwright. 2019. To pay or not: game theoretic models of ransomware. J. of Cybersecurity.(2019).","key":"e_1_3_2_1_12_1","DOI":"10.1093\/cybsec\/tyz009"},{"key":"e_1_3_2_1_13_1","volume-title":"Sgxpectre: Stealing Intel secrets from SGX enclaves via speculative execution","author":"Chen Guoxing","year":"2019","unstructured":"Guoxing Chen, Sanchuan Chen, Yuan Xiao, 2019. Sgxpectre: Stealing Intel secrets from SGX enclaves via speculative execution. In IEEE EuroS&P '19."},{"doi-asserted-by":"crossref","unstructured":"M. Conti A. Gangwal and S. Ruj. 2018. On the economic significance of ransomware campaigns: A Bitcoin transactions perspective. Comput. & Sec. (2018).","key":"e_1_3_2_1_14_1","DOI":"10.1016\/j.cose.2018.08.008"},{"key":"e_1_3_2_1_15_1","volume-title":"Secure processors part II: Intel SGX security analysis and MIT sanctum architecture. Foundations and Trends in Electronic Design Automation","author":"V. Costan","year":"2017","unstructured":"V. Costan 2017. Secure processors part II: Intel SGX security analysis and MIT sanctum architecture. Foundations and Trends in Electronic Design Automation (2017)."},{"unstructured":"V. Costan and S. Devadas. 2016. Intel SGX Explained.Cryptol. ePrint Arch.(2016).","key":"e_1_3_2_1_16_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_17_1","DOI":"10.1145\/3180465.3180467"},{"doi-asserted-by":"crossref","unstructured":"Tooska Dargahi 2019. A Cyber Kill-Chain based taxonomy of crypto-ransomware features. J. Computer Virology and Hacking Techniques(2019).","key":"e_1_3_2_1_18_1","DOI":"10.1007\/s11416-019-00338-7"},{"key":"e_1_3_2_1_19_1","volume-title":"Evaluation of Live Forensic Techniques in Ransomware Attack Mitigation. Forensic Science International: Digital Investigation. 33","author":"Simon Davies","year":"2020","unstructured":"Simon Davies 2020. Evaluation of Live Forensic Techniques in Ransomware Attack Mitigation. Forensic Science International: Digital Investigation. 33 (2020)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_20_1","DOI":"10.1145\/2664243.2664267"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_21_1","DOI":"10.1007\/978-3-319-70500-2_18"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_22_1","DOI":"10.1007\/978-3-642-23644-0_3"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_23_1","DOI":"10.1145\/1506409.1506429"},{"unstructured":"Intel. 2020. Intel SGX for Linux. Retrieved 2020-09-04 from https:\/\/github.com\/intel\/linux-sgx","key":"e_1_3_2_1_24_1"},{"unstructured":"Intel. 2020. Intel SGX Linux Driver. Retrieved 2020-12-15 from https:\/\/github.com\/intel\/linux-sgx-driver","key":"e_1_3_2_1_25_1"},{"volume-title":"Intel Software Guard Extensions","year":"2020","unstructured":"Intel. 2020. Intel Software Guard Extensions (Intel SGX) Data Center Attestation Primitives: ECDSA Quote Library API. (2020).","key":"e_1_3_2_1_26_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_27_1","DOI":"10.14722\/ndss.2019.23060"},{"doi-asserted-by":"crossref","unstructured":"Masoudeh Keshavarzi and Hamid\u00a0Reza Ghaffary. 2020. I2CE3: A dedicated and separated attack chain for ransomware offenses as the most infamous cyber extortion. Computer Science Review(2020).","key":"e_1_3_2_1_28_1","DOI":"10.1016\/j.cosrev.2020.100233"},{"key":"e_1_3_2_1_29_1","volume-title":"USENIX Security '16","author":"Kharaz Amin","year":"2016","unstructured":"Amin Kharaz, Sajjad Arshad, Collin Mulliner, 2016. UNVEIL: A large-scale, automated approach to detecting ransomware. In USENIX Security '16."},{"key":"e_1_3_2_1_30_1","volume-title":"Int. J. CSNS","author":"Kok SH","year":"2019","unstructured":"SH Kok, Azween Abdullah, NZ Jhanjhi, and Mahadevan Supramaniam. 2019. Ransomware, Threat and Detection Techniques: A Review. Int. J. CSNS (2019)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_31_1","DOI":"10.1145\/3052973.3053035"},{"unstructured":"Xiaoqi Li Peng Jiang Ting Chen 2017. A Survey on the Security of Blockchain Systems. Future Generation Computer Systems(2017).","key":"e_1_3_2_1_32_1"},{"key":"e_1_3_2_1_33_1","volume-title":"Ransomware: Defending against digital extortion. O\u2019Reilly Media","author":"Liska Allan","year":"2016","unstructured":"Allan Liska and Timothy Gallo. 2016. Ransomware: Defending against digital extortion. O\u2019Reilly Media, Inc."},{"volume-title":"You Shall Not Join: A Measurement Study of Cryptocurrency Peer-to-Peer Bootstrapping Techniques. In SIGSAG '19","author":"Loe A.","unstructured":"A. Loe and E. Quaglia. 2019. You Shall Not Join: A Measurement Study of Cryptocurrency Peer-to-Peer Bootstrapping Techniques. In SIGSAG '19.","key":"e_1_3_2_1_34_1"},{"unstructured":"LSDS Group. 2020. SGX-LKL Library. Retrieved 2021-02-18 from https:\/\/github.com\/lsds\/sgx-lkl","key":"e_1_3_2_1_35_1"},{"doi-asserted-by":"crossref","unstructured":"Robert Luo and Qinyu Liao. 2007. Awareness Education as the Key to Ransomware Prevention. Information Systems Security(2007).","key":"e_1_3_2_1_36_1","DOI":"10.1080\/10658980701576412"},{"doi-asserted-by":"crossref","unstructured":"Carsten Maartmann-Moe 2009. The persistence of memory: Forensic identification and extraction of cryptographic keys. Digital Investigation(2009).","key":"e_1_3_2_1_37_1","DOI":"10.1016\/j.diin.2009.06.002"},{"key":"e_1_3_2_1_38_1","volume-title":"The Wolf In SGX Clothing. Bluehat IL","author":"Marschalek Marion","year":"2018","unstructured":"Marion Marschalek. 2018. The Wolf In SGX Clothing. Bluehat IL (2018)."},{"key":"e_1_3_2_1_39_1","volume-title":"Innovative Instructions and Software Model for Isolated Execution. In Int. Workshop on HASP '13","author":"McKeen Frank","year":"2013","unstructured":"Frank McKeen, Ilya Alexandrovich, 2013. Innovative Instructions and Software Model for Isolated Execution. In Int. Workshop on HASP '13."},{"doi-asserted-by":"crossref","unstructured":"Nailah Mims. 2017. The Botnet Problem. In Comput. Info. Sec. Handbook.","key":"e_1_3_2_1_40_1","DOI":"10.1016\/B978-0-12-803843-7.00014-4"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_41_1","DOI":"10.1145\/3214292.3214301"},{"doi-asserted-by":"crossref","unstructured":"Daniel Morato Eduardo Berrueta Eduardo Maga\u00f1a 2018. Ransomware early detection by the analysis of file sharing traffic. J. Netw. Comput. App.(2018).","key":"e_1_3_2_1_42_1","DOI":"10.1016\/j.jnca.2018.09.013"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_43_1","DOI":"10.1145\/3230833.3234691"},{"key":"e_1_3_2_1_44_1","volume-title":"A survey of published attacks on Intel SGX. ArXiv:2006.13598","author":"Nilsson Alexander","year":"2020","unstructured":"Alexander Nilsson, Pegah\u00a0Nikbakht Bideh, and Joakim Brorsson. 2020. A survey of published attacks on Intel SGX. ArXiv:2006.13598 (2020)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_45_1","DOI":"10.1109\/MIC.2016.90"},{"key":"e_1_3_2_1_46_1","volume-title":"An SGX-Based Key Management Framework for Data Centric Networking. In Int. WISA '19","author":"Park M.","year":"2019","unstructured":"M. Park, J. Kim, Y. Kim, 2019. An SGX-Based Key Management Framework for Data Centric Networking. In Int. WISA '19."},{"unstructured":"No\u00a0More Ransom. 2021. No More Ransom. Retrieved 2021-03-14 from https:\/\/www.nomoreransom.org","key":"e_1_3_2_1_47_1"},{"unstructured":"Phillip Rogaway. 2011. Evaluation of some blockcipher modes of operation. CRYPTREC for the Government of Japan(2011).","key":"e_1_3_2_1_48_1"},{"doi-asserted-by":"crossref","unstructured":"M. Sabt M. Achemlal and A. Bouabdallah. 2015. Trusted Execution Environment: What It is and What It is Not. In 2015 IEEE Trustcom\/BigDataSE\/ISPA.","key":"e_1_3_2_1_49_1","DOI":"10.1109\/Trustcom.2015.357"},{"key":"e_1_3_2_1_50_1","volume-title":"Malware Guard Extension: abusing Intel SGX to conceal cache attacks. Cybersecurity","author":"Schwarz Michael","year":"2020","unstructured":"Michael Schwarz, Samuel Weiser, 2020. Malware Guard Extension: abusing Intel SGX to conceal cache attacks. Cybersecurity (2020)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_51_1","DOI":"10.1007\/978-3-030-22038-9_9"},{"key":"e_1_3_2_1_52_1","volume-title":"Establishing Mutually Trusted Channels for Remote Sensing Devices with Trusted Execution Environments. In ARES '17","author":"Shepherd Carlton","year":"2017","unstructured":"Carlton Shepherd 2017. Establishing Mutually Trusted Channels for Remote Sensing Devices with Trusted Execution Environments. In ARES '17."},{"volume-title":"Cloudcom '17","author":"Silva R.","unstructured":"R. Silva, P. Barbosa, and A. Brito. 2017. DynSGX: A Privacy Preserving Toolset for Dinamically Loading Functions into Intel SGX Enclaves. In Cloudcom '17.","key":"e_1_3_2_1_53_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_54_1","DOI":"10.1145\/2810103.2813608"},{"key":"e_1_3_2_1_55_1","volume-title":"RAPPER: Ransomware Prevention via Performance Counters.","author":"Sinha Sayan","year":"2018","unstructured":"Sayan Sinha, Manaar Alam, Sarani Bhattacharya, 2018. RAPPER: Ransomware Prevention via Performance Counters."},{"key":"e_1_3_2_1_56_1","volume-title":"Forensic Analysis of Ransomware Families Using Static and Dynamic Analysis. In IEEE Security and Privacy Workshops (SPW) '18","author":"Subedi P.","year":"2018","unstructured":"K.\u00a0P. Subedi 2018. Forensic Analysis of Ransomware Families Using Static and Dynamic Analysis. In IEEE Security and Privacy Workshops (SPW) '18."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_57_1","DOI":"10.1109\/ACCESS.2018.2868885"},{"unstructured":"James Wyke and Anand Ajjan. 2015. The current state of ransomware. SOPHOS. A SophosLabs Technical Paper(2015).","key":"e_1_3_2_1_58_1"}],"event":{"acronym":"ARES 2021","name":"ARES 2021: The 16th International Conference on Availability, Reliability and Security","location":"Vienna Austria"},"container-title":["Proceedings of the 16th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3465481.3470116","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3465481.3470116","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:17:42Z","timestamp":1750191462000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3465481.3470116"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,17]]},"references-count":58,"alternative-id":["10.1145\/3465481.3470116","10.1145\/3465481"],"URL":"https:\/\/doi.org\/10.1145\/3465481.3470116","relation":{},"subject":[],"published":{"date-parts":[[2021,8,17]]},"assertion":[{"value":"2021-08-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}