{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:36:15Z","timestamp":1784342175549,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":64,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3488011","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"273-284","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["VIA: Analyzing Device Interfaces of Protected Virtual Machines"],"prefix":"10.1145","author":[{"given":"Felicitas","family":"Hetzelt","sequence":"first","affiliation":[{"name":"TU Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin","family":"Radev","sequence":"additional","affiliation":[{"name":"Fraunhofer AISEC, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Robert","family":"Buhren","sequence":"additional","affiliation":[{"name":"TU Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathias","family":"Morbitzer","sequence":"additional","affiliation":[{"name":"Fraunhofer AISEC, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jean-Pierre","family":"Seifert","sequence":"additional","affiliation":[{"name":"TU Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2021. Github anonymous repository: analysis of discovered bugs in device drivers. https:\/\/github.com\/fuzzsa\/fuzzsa-bugs."},{"key":"e_1_3_2_1_2_1","unstructured":"2021. libFuzzer: a library for coverage-guided fuzz testing.https:\/\/llvm.org\/docs\/LibFuzzer.html. Accessed: 2021-21-01."},{"key":"e_1_3_2_1_3_1","unstructured":"2021. Patch: gve: Add NULL pointer checks when freeing irqs.https:\/\/github.com\/torvalds\/linux\/commit\/e96b491a0ffa35a8a9607c193fa4d894ca9fb32f."},{"key":"e_1_3_2_1_4_1","unstructured":"2021. Patch: gve: Update mgmt_msix_idx if num_ntfy changes. https:\/\/github.com\/torvalds\/linux\/commit\/5218e919c8d06279884aa0baf76778a6817d5b93."},{"key":"e_1_3_2_1_5_1","unstructured":"2021. Patch: swiotlb: Validate bounce size in the sync\/unmap path. https:\/\/lore.kernel.org\/patchwork\/patch\/1364048\/."},{"key":"e_1_3_2_1_6_1","unstructured":"2021. Patch: Untrusted device support for virtio. https:\/\/lists.linuxfoundation.org\/pipermail\/virtualization\/2021-June\/054685.html."},{"key":"e_1_3_2_1_7_1","unstructured":"2021. Patch: virtio-ring: maintain next in extra state for packed virtqueue. https:\/\/lore.kernel.org\/virtualization\/20210421032117.5177-2-jasowang@redhat.com\/."},{"key":"e_1_3_2_1_8_1","unstructured":"2021. Patch: virtio-ring: store DMA metadata in desc_extra for split virtqueue. https:\/\/lore.kernel.org\/patchwork\/patch\/1416241\/."},{"key":"e_1_3_2_1_9_1","unstructured":"2021. Patch: virtio_net: Fix error code in probe(). https:\/\/lkml.org\/lkml\/2020\/12\/28\/1647."},{"key":"e_1_3_2_1_10_1","unstructured":"2021. Patch: virtio_ring: cut and paste bugs in vring_create_virtqueue_packed(). https:\/\/lkml.org\/lkml\/2020\/12\/28\/687."},{"key":"e_1_3_2_1_11_1","unstructured":"2021. Patch: virtio_ring: Fix two use after free bugs. https:\/\/lkml.org\/lkml\/2020\/12\/28\/828."},{"key":"e_1_3_2_1_12_1","unstructured":"2021. Patch: vmxnet3: Remove buf_info from device accessible structures. https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/netdev\/net-next.git\/commit\/drivers\/net\/vmxnet3?id=de1da8bcf40564a2adada2d5d5426e05355f66e8."},{"key":"e_1_3_2_1_13_1","unstructured":"2021. Platform Devices and Drivers. https:\/\/www.kernel.org\/doc\/html\/latest\/driver-api\/driver-model\/platform.html. Accessed: 2021-21-01."},{"key":"e_1_3_2_1_14_1","unstructured":"2021. Virtual I\/O Device (VIRTIO) Version 1.1. https:\/\/docs.oasis-open.org\/virtio\/virtio\/v1.1\/csprd01\/virtio-v1.1-csprd01.html. Accessed: 2021-21-01."},{"key":"e_1_3_2_1_15_1","unstructured":"Al Danial. 2021. Count Lines of Code. https:\/\/github.com\/AlDanial\/cloc. Accessed: 2021-08-06."},{"key":"e_1_3_2_1_16_1","unstructured":"AMD. 2021. SEV-SNP OVMF. https:\/\/github.com\/AMDESE\/ovmf."},{"key":"e_1_3_2_1_17_1","unstructured":"Fran\u00e7ois Amigorena. 2019. Why SMBs Still do not Trust Cloud Storage Providers to Secure their Data. https:\/\/www.infosecurity-magazine.com\/opinions\/smb-trust-cloud-storage-1-1\/. Accessed: 2021-21-01."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23xxx"},{"key":"e_1_3_2_1_19_1","volume-title":"Static Detection of Unsafe DMA Accesses in Device Drivers. In USENIX Security Symposium. USENIX Association. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/bai","author":"Bai Jia-Ju","year":"2021","unstructured":"Jia-Ju Bai, Tuo Li, Kangjie Lu, and Shi-Min Hu. 2021. Static Detection of Unsafe DMA Accesses in Device Drivers. In USENIX Security Symposium. USENIX Association. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/bai"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354216"},{"key":"e_1_3_2_1_21_1","unstructured":"Cfir Cohen. 2019. AMD-SEV: Platform DH key recovery via invalid curve attack: (CVE-2019-9836). https:\/\/seclists.org\/fulldisclosure\/2019\/Jun\/46. Accessed: 2019-22-05."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363225"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2110356.2110358"},{"key":"e_1_3_2_1_24_1","unstructured":"Zhao-Hui Du Zhiwei Ying Zhenke Ma Yufei Mai Phoebe Wang Jesse Liu and Jesse Fang. 2017. Secure Encrypted Virtualization is Unsecure. arxiv:1712.05090\u00a0[cs.CR] https:\/\/arxiv.org\/abs\/1712.05090"},{"key":"e_1_3_2_1_25_1","volume-title":"SI","author":"Dunlap W","year":"2002","unstructured":"George\u00a0W Dunlap, Samuel\u00a0T King, Sukru Cinar, Murtaza\u00a0A Basrai, and Peter\u00a0M Chen. 2002. ReVirt: Enabling intrusion analysis through virtual-machine logging and replay. ACM SIGOPS Operating Systems Review (OSR) 36, SI (2002), 211\u2013224."},{"key":"e_1_3_2_1_26_1","unstructured":"Google. 2019. syzkaller - kernel fuzzer. https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_1_27_1","unstructured":"Google. 2020. Confidential VM and Compute Engine. https:\/\/cloud.google.com\/compute\/confidential-vm\/docs\/about-cvm."},{"key":"e_1_3_2_1_28_1","unstructured":"PCI Special\u00a0Interest Group. 1998. PCI Local Bus Specification. Chapter\u00a06."},{"key":"e_1_3_2_1_29_1","volume-title":"Security Analysis of Encrypted Virtual Machines. In International Conference on Virtual Execution Environments.","author":"Hetzelt Felicitas","year":"2017","unstructured":"Felicitas Hetzelt and Robert Buhren. 2017. Security Analysis of Encrypted Virtual Machines. In International Conference on Virtual Execution Environments."},{"key":"e_1_3_2_1_30_1","unstructured":"Guerney Hunt Richard Boivie Eric Hall Elaine Palmer Dimitrios Pendarakis and Enriquillo Valdez. 2018. Supporting protected computing on IBM Power Architecture. https:\/\/developer.ibm.com\/articles\/l-support-protected-computing\/. Accessed: 2021-21-01."},{"key":"e_1_3_2_1_31_1","volume-title":"Architecture Specification: Intel Trust Domain Extensions (Intel TDX) Module. https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/intel-tdx-module-1eas.pdf Accessed: 2021-15-01.","year":"2020","unstructured":"Intel. 2020. Architecture Specification: Intel Trust Domain Extensions (Intel TDX) Module. https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/intel-tdx-module-1eas.pdf Accessed: 2021-15-01."},{"key":"e_1_3_2_1_32_1","unstructured":"Intel. 2020. Intel Trust Domain Extensions (whitepaper)."},{"key":"e_1_3_2_1_33_1","unstructured":"Intel. 2020. Trust Domain Extensions. https:\/\/github.com\/intel\/tdx."},{"key":"e_1_3_2_1_34_1","unstructured":"Intel. 2020. x86\/tdx: Add device filter support for x86 TDX platform. https:\/\/github.com\/intel\/tdx\/commit\/6789eee52aab8985e49b362379fab73aa3eecde2."},{"key":"e_1_3_2_1_35_1","volume-title":"2011 44th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 272\u2013283","author":"Jin S.","unstructured":"S. Jin, J. Ahn, S. Cha, and J. Huh. 2011. Architectural support for secure virtualization under a vulnerable hypervisor. In 2011 44th Annual IEEE\/ACM International Symposium on Microarchitecture (MICRO). 272\u2013283."},{"key":"e_1_3_2_1_36_1","unstructured":"David Kaplan Jeremy Powell and Tom Woller. 2016. White Paper AMD Memory Encryption. http:\/\/amd-dev.wpengine.netdna-cdn.com\/wordpress\/media\/2013\/12\/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf."},{"key":"e_1_3_2_1_37_1","unstructured":"Kees Cook. 2017. Linux Kernel Self-Protection. https:\/\/www.usenix.org\/system\/files\/login\/articles\/login_spring17_04_cook.pdf."},{"key":"e_1_3_2_1_38_1","volume-title":"Stateful fuzzing of wireless device drivers in an emulated environment. Black Hat Japan","author":"Keil Sylvester","year":"2007","unstructured":"Sylvester Keil and Clemens Kolbitsch. 2007. Stateful fuzzing of wireless device drivers in an emulated environment. Black Hat Japan (2007)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359662"},{"key":"e_1_3_2_1_40_1","volume-title":"Testing Closed-Source Binary Device Drivers with DDT. In USENIX Annual Technical Conference","author":"Kuznetsov Volodymyr","year":"2010","unstructured":"Volodymyr Kuznetsov, Vitaly Chipounov, and George Candea. 2010. Testing Closed-Source Binary Device Drivers with DDT. In USENIX Annual Technical Conference(Boston, MA) (USENIXATC\u201910). USENIX Association, USA, 12."},{"key":"e_1_3_2_1_41_1","volume-title":"CROSSLINE: Breaking\u201dSecurity-by-Crash\u201dbased Memory Isolation in AMD SEV. arXiv preprint arXiv:2008.00146(2020).","author":"Li Mengyuan","year":"2020","unstructured":"Mengyuan Li, Yinqian Zhang, and Zhiqiang Lin. 2020. CROSSLINE: Breaking\u201dSecurity-by-Crash\u201dbased Memory Isolation in AMD SEV. arXiv preprint arXiv:2008.00146(2020)."},{"key":"e_1_3_2_1_42_1","volume-title":"Secure Encrypted Virtualization. In USENIX Security Symposium.","author":"Li Mengyuan","year":"2019","unstructured":"Mengyuan Li, Yinqian Zhang, Zhiqiang Lin, and Yan Solihin. 2019. Exploiting Unprotected I\/O Operations in AMD\u2019s Secure Encrypted Virtualization. In USENIX Security Symposium."},{"key":"e_1_3_2_1_43_1","unstructured":"LLVM. 2021. Address Sanitizer. https:\/\/clang.llvm.org\/docs\/AddressSanitizer.html. Accessed: 2021-08-06."},{"key":"e_1_3_2_1_44_1","volume-title":"ISOC Network and Distributed System Security Symposium (NDSS).","author":"Markettos Theodore","unstructured":"A.\u00a0Theodore Markettos, Colin Rothwell, Brett\u00a0F. Gutstein, Allison Pearce, Peter\u00a0G. Neumann, Simon\u00a0W. Moore, and Robert N.\u00a0M. Watson. 2019. Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy Peripherals. In ISOC Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292006.3300022"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3193111.3193112"},{"key":"e_1_3_2_1_47_1","first-page":"1","article-title":"BadUSB-On Accessories That Turn Evil","volume":"1","author":"Nohl Karsten","year":"2014","unstructured":"Karsten Nohl and Jakob Lell. 2014. BadUSB-On Accessories That Turn Evil. Black Hat USA 1, 9 (2014), 1\u201322.","journal-title":"Black Hat USA"},{"key":"e_1_3_2_1_48_1","volume-title":"POTUS: Probing Off-The-Shelf USB Drivers with Symbolic Fault Injection. In USENIX Workshop on Offensive Technologies (WOOT). USENIX Association","author":"Patrick-Evans James","year":"2017","unstructured":"James Patrick-Evans, Lorenzo Cavallaro, and Johannes Kinder. 2017. POTUS: Probing Off-The-Shelf USB Drivers with Symbolic Fault Injection. In USENIX Workshop on Offensive Technologies (WOOT). USENIX Association, Vancouver, BC. https:\/\/www.usenix.org\/conference\/woot17\/workshop-program\/presentation\/patrick-evans"},{"key":"e_1_3_2_1_49_1","volume-title":"USENIX Security Symposium. 2559\u20132575","author":"Peng Hui","year":"2020","unstructured":"Hui Peng and Mathias Payer. 2020. USBFuzz: A Framework for Fuzzing {USB} Drivers by Device Emulation. In USENIX Security Symposium. 2559\u20132575."},{"key":"e_1_3_2_1_50_1","volume-title":"Proceedings - 9th RoEduNet IEEE International Conference, RoEduNet 2010","author":"Purdila Octavian","year":"2010","unstructured":"Octavian Purdila, Lucian\u00a0Adrian Grijincu, and Nicolae Tapus. 2010. LKL: The Linux kernel library. Proceedings - 9th RoEduNet IEEE International Conference, RoEduNet 2010 (2010), 328\u2013333."},{"key":"e_1_3_2_1_51_1","volume-title":"Exploiting Interfaces of Secure Encrypted Virtual Machines. In ACM Reversing and Offensive-oriented Trends Symposium (ROOTS). 1\u201312","author":"Radev Martin","year":"2020","unstructured":"Martin Radev and Mathias Morbitzer. 2020. Exploiting Interfaces of Secure Encrypted Virtual Machines. In ACM Reversing and Offensive-oriented Trends Symposium (ROOTS). 1\u201312."},{"key":"e_1_3_2_1_52_1","volume-title":"USENIX Symposium on Operating System Design and Implementation (OSDI)","author":"Renzelmann J.","year":"2012","unstructured":"Matthew\u00a0J. Renzelmann, Asim Kadav, and Michael\u00a0M. Swift. 2012. SymDrive: Testing Drivers without Devices. In USENIX Symposium on Operating System Design and Implementation (OSDI) (Hollywood, CA, USA) (OSDI\u201912). USENIX Association, USA, 279\u2013292."},{"key":"e_1_3_2_1_53_1","volume-title":"Fine Grained Dataflow Tracking with Proximal Gradients. In USENIX Security Symposium.","author":"Ryan Gabriel","year":"2021","unstructured":"Gabriel Ryan, Abhishek Shah, Dongdong She, Koustubha Bhat, and Suman Jana. 2021. Fine Grained Dataflow Tracking with Proximal Gradients. In USENIX Security Symposium."},{"key":"e_1_3_2_1_54_1","volume-title":"Don\u2019t trust your USB! How to find bugs in USB device drivers. Blackhat Europe","author":"Schumilo Sergej","year":"2014","unstructured":"Sergej Schumilo, Ralf Spenneberg, and Hendrik Schwartke. 2014. Don\u2019t trust your USB! How to find bugs in USB device drivers. Blackhat Europe (2014)."},{"key":"e_1_3_2_1_55_1","unstructured":"AMD SEV-SNP. 2020. Strengthening VM isolation with integrity protection and more. White Paper January(2020)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23176"},{"key":"e_1_3_2_1_57_1","volume-title":"Agamotto: Accelerating Kernel Driver Fuzzing with Lightweight Virtual Machine Checkpoints. In USENIX Security Symposium. USENIX Association, 2541\u20132557","author":"Song Dokyung","year":"2020","unstructured":"Dokyung Song, Felicitas Hetzelt, Jonghwan Kim, Brent\u00a0ByungHoon Kang, Jean-Pierre Seifert, and Michael Franz. 2020. Agamotto: Accelerating Kernel Driver Fuzzing with Lightweight Virtual Machine Checkpoints. In USENIX Security Symposium. USENIX Association, 2541\u20132557. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/song"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2248487.2151022"},{"key":"e_1_3_2_1_59_1","volume-title":"USENIX Workshop on Offensive Technologies (WOOT). USENIX Association","author":"van Tonder Rijnard","year":"2014","unstructured":"Rijnard van Tonder and Herman Engelbrecht. 2014. Lowering the USB Fuzzing Barrier by Transparent Two-Way Emulation. In USENIX Workshop on Offensive Technologies (WOOT). USENIX Association, San Diego, CA. https:\/\/www.usenix.org\/conference\/woot14\/workshop-program\/presentation\/van-tonder"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329820"},{"key":"e_1_3_2_1_61_1","volume-title":"SEVurity: No Security Without Integrity - Breaking Integrity-Free Memory Encryption with Minimal Assumptions. In IEEE Symposium on Security and Privacy (S&P).","author":"Wilke Luca","year":"2020","unstructured":"Luca Wilke, Jan Wichelmann, Mathias Morbitzer, and Thomas Eisenbarth. 2020. SEVurity: No Security Without Integrity - Breaking Integrity-Free Memory Encryption with Minimal Assumptions. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2013.6522323"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00035"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043576"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488011","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3488011","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:18:26Z","timestamp":1755890306000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488011"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":64,"alternative-id":["10.1145\/3485832.3488011","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3488011","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}