{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T17:58:24Z","timestamp":1770227904014,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":86,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,3,28]],"date-time":"2022-03-28T00:00:00Z","timestamp":1648425600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"KU Leuven"},{"name":"Flemish Research Programme Cybersecurity"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,3,28]]},"DOI":"10.1145\/3492321.3519560","type":"proceedings-article","created":{"date-parts":[[2022,3,28]],"date-time":"2022-03-28T14:28:18Z","timestamp":1648477698000},"page":"266-282","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":34,"title":["You shall not (by)pass!"],"prefix":"10.1145","author":[{"given":"Alexios","family":"Voulimeneas","sequence":"first","affiliation":[{"name":"KU Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonas","family":"Vinck","sequence":"additional","affiliation":[{"name":"KU Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruben","family":"Mechelinck","sequence":"additional","affiliation":[{"name":"KU Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stijn","family":"Volckaert","sequence":"additional","affiliation":[{"name":"KU Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,3,28]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2016. Close but No Cigar: On the Effectiveness of Intel's CET Against Code Reuse Attacks. https:\/\/grsecurity.net\/effectiveness_of_intel_cet_against_code_reuse_attacks  2016. Close but No Cigar: On the Effectiveness of Intel's CET Against Code Reuse Attacks. https:\/\/grsecurity.net\/effectiveness_of_intel_cet_against_code_reuse_attacks"},{"key":"e_1_3_2_1_2_1","unstructured":"2021. Intel\u00ae 64 and IA-32 Architectures Software Developer's Manual.  2021. Intel \u00ae 64 and IA-32 Architectures Software Developer's Manual."},{"key":"e_1_3_2_1_3_1","unstructured":"2021. Unintended Instructions on x86. Philip Reames - A collection of (public) notes on assorted topics. https:\/\/github.com\/preames\/public-notes\/blob\/master\/unintended-instructions.rst  2021. Unintended Instructions on x86. Philip Reames - A collection of (public) notes on assorted topics. https:\/\/github.com\/preames\/public-notes\/blob\/master\/unintended-instructions.rst"},{"key":"e_1_3_2_1_4_1","unstructured":"Last accessed 2022. Syscall User Dispatch. The kernel development community. https:\/\/www.kernel.org\/doc\/html\/latest\/admin-guide\/syscall-user-dispatch.html  Last accessed 2022. Syscall User Dispatch. The kernel development community. https:\/\/www.kernel.org\/doc\/html\/latest\/admin-guide\/syscall-user-dispatch.html"},{"key":"e_1_3_2_1_5_1","unstructured":"Last accessed 2022. syscall_intercept. System call intercepting library: https:\/\/github.com\/pmem\/syscall_intercept.  Last accessed 2022. syscall_intercept. System call intercepting library: https:\/\/github.com\/pmem\/syscall_intercept."},{"key":"e_1_3_2_1_6_1","volume-title":"Control-Flow Integrity. In ACM Conference on Computer and Communications Security (CCS).","author":"Abadi Mart\u00edn","year":"2005","unstructured":"Mart\u00edn Abadi , Mihai Budiu , Ulfar Erlingsson , and Jay Ligatti . 2005 . Control-Flow Integrity. In ACM Conference on Computer and Communications Security (CCS). Mart\u00edn Abadi, Mihai Budiu, Ulfar Erlingsson, and Jay Ligatti. 2005. Control-Flow Integrity. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_7_1","unstructured":"ARM. 2015. ARM Memory Domains. http:\/\/infocenter.arm.com\/help\/index.jsp?topic=\/com.arm.doc.ddi0211k\/Babjdffh.html.  ARM. 2015. ARM Memory Domains. http:\/\/infocenter.arm.com\/help\/index.jsp?topic=\/com.arm.doc.ddi0211k\/Babjdffh.html."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-021-00644-w"},{"key":"e_1_3_2_1_9_1","volume-title":"Cali: Compiler-Assisted Library Isolation. In ACM Symposium on Information, Computer and Communications Security (ASIACCS).","author":"Bauer Markus","year":"2021","unstructured":"Markus Bauer and Christian Rossow . 2021 . Cali: Compiler-Assisted Library Isolation. In ACM Symposium on Information, Computer and Communications Security (ASIACCS). Markus Bauer and Christian Rossow. 2021. Cali: Compiler-Assisted Library Isolation. In ACM Symposium on Information, Computer and Communications Security (ASIACCS)."},{"key":"e_1_3_2_1_10_1","volume-title":"USENIX Symposium on Operating Systems Design and Implementation (OSDI).","author":"Belay Adam","year":"2012","unstructured":"Adam Belay , Andrea Bittau , Ali Mashtizadeh , David Terei , David Mazi\u00e8res , and Christos Kozyrakis . 2012 . Dune: Safe User-level Access to Privileged CPU Features . In USENIX Symposium on Operating Systems Design and Implementation (OSDI). Adam Belay, Andrea Bittau, Ali Mashtizadeh, David Terei, David Mazi\u00e8res, and Christos Kozyrakis. 2012. Dune: Safe User-level Access to Privileged CPU Features. In USENIX Symposium on Operating Systems Design and Implementation (OSDI)."},{"key":"e_1_3_2_1_11_1","volume-title":"Hacking Blind. In IEEE Symposium on Security and Privacy (S&P).","author":"Bittau Andrea","year":"2014","unstructured":"Andrea Bittau , Adam Belay , Ali Jos\u00e9 Mashtizadeh , David Mazi\u00e8res , and Dan Boneh . 2014 . Hacking Blind. In IEEE Symposium on Security and Privacy (S&P). Andrea Bittau, Adam Belay, Ali Jos\u00e9 Mashtizadeh, David Mazi\u00e8res, and Dan Boneh. 2014. Hacking Blind. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_12_1","volume-title":"USENIX Symposium on Networked Systems Design and Implementation (NSDI).","author":"Bittau Andrea","year":"2008","unstructured":"Andrea Bittau , Petr Marchenko , Mark Handley , and Brad Karp . 2008 . Wedge: Splitting Applications into Reduced-Privilege Compartments . In USENIX Symposium on Networked Systems Design and Implementation (NSDI). Andrea Bittau, Petr Marchenko, Mark Handley, and Brad Karp. 2008. Wedge: Splitting Applications into Reduced-Privilege Compartments. In USENIX Symposium on Networked Systems Design and Implementation (NSDI)."},{"key":"e_1_3_2_1_13_1","volume-title":"USENIX Security Symposium.","author":"Brasser Ferdinand","year":"2017","unstructured":"Ferdinand Brasser , Lucas Davi , David Gens , Christopher Liebchen , and Ahmad-Reza Sadeghi . 2017 . CAn't touch this: Software-only mitigation against Rowhammer attacks targeting kernel memory . In USENIX Security Symposium. Ferdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2017. CAn't touch this: Software-only mitigation against Rowhammer attacks targeting kernel memory. In USENIX Security Symposium."},{"key":"e_1_3_2_1_14_1","volume-title":"Privtrans: Automatically Partitioning Programs for Privilege Separation. In USENIX Security Symposium.","author":"Brumley David","year":"2004","unstructured":"David Brumley and Dawn Song . 2004 . Privtrans: Automatically Partitioning Programs for Privilege Separation. In USENIX Security Symposium. David Brumley and Dawn Song. 2004. Privtrans: Automatically Partitioning Programs for Privilege Separation. In USENIX Security Symposium."},{"key":"e_1_3_2_1_15_1","volume-title":"The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization. arXiv preprint arXiv:2004.04846","author":"Bumjin Im","year":"2021","unstructured":"Im Bumjin , Yang Fangfei , Tsai Chia-Che , LeMay Michael , Vahldiek-Oberwagner Anjo , and Dautenhahn Nathan . 2021 . The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization. arXiv preprint arXiv:2004.04846 (2021). Im Bumjin, Yang Fangfei, Tsai Chia-Che, LeMay Michael, Vahldiek-Oberwagner Anjo, and Dautenhahn Nathan. 2021. The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization. arXiv preprint arXiv:2004.04846 (2021)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3054924"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00076"},{"key":"e_1_3_2_1_18_1","volume-title":"Fast Byte-Granularity Software Fault Isolation. In ACM Symposium on Operating Systems Principles (SOSP).","author":"Castro Miguel","year":"2009","unstructured":"Miguel Castro , Manuel Costa , Jean-Philippe Martin , Marcus Peinado , Periklis Akritidis , Austin Donnelly , Paul Barham , and Richard Black . 2009 . Fast Byte-Granularity Software Fault Isolation. In ACM Symposium on Operating Systems Principles (SOSP). Miguel Castro, Manuel Costa, Jean-Philippe Martin, Marcus Peinado, Periklis Akritidis, Austin Donnelly, Paul Barham, and Richard Black. 2009. Fast Byte-Granularity Software Fault Isolation. In ACM Symposium on Operating Systems Principles (SOSP)."},{"key":"e_1_3_2_1_19_1","volume-title":"SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGX. In USENIX Security Symposium.","author":"Chen Yuan","year":"2022","unstructured":"Yuan Chen , Jiaqi Li , Guorui Xu , Yajin Zhou , Zhi Wang , Cong Wang , and Kui Ren . 2022 . SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGX. In USENIX Security Symposium. Yuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou, Zhi Wang, Cong Wang, and Kui Ren. 2022. SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGX. In USENIX Security Symposium."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.12"},{"key":"e_1_3_2_1_21_1","volume-title":"PKU Pitfalls: Attacks on PKU-based Memory Isolation Systems. In USENIX Security Symposium.","author":"Connor R. Joseph","year":"2020","unstructured":"R. Joseph Connor , Tyler McDaniel , Jared M. Smith , and Max Schuchard . 2020 . PKU Pitfalls: Attacks on PKU-based Memory Isolation Systems. In USENIX Security Symposium. R. Joseph Connor, Tyler McDaniel, Jared M. Smith, and Max Schuchard. 2020. PKU Pitfalls: Attacks on PKU-based Memory Isolation Systems. In USENIX Security Symposium."},{"key":"e_1_3_2_1_22_1","unstructured":"Jonathan Corbet. 2015. Intel Memory Protection Keys. https:\/\/lwn.net\/Articles\/643797\/.  Jonathan Corbet. 2015. Intel Memory Protection Keys. https:\/\/lwn.net\/Articles\/643797\/."},{"key":"e_1_3_2_1_23_1","unstructured":"Jan de Mooij. 2015. W^X JIT-code enabled in Firefox. https:\/\/jandemooij.nl\/blog\/wx-jit-code-enabled-in-firefox\/.  Jan de Mooij. 2015. W ^ X JIT-code enabled in Firefox. https:\/\/jandemooij.nl\/blog\/wx-jit-code-enabled-in-firefox\/."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-18467-8_26"},{"key":"e_1_3_2_1_25_1","volume-title":"Pnacl: Portable native client executables. Google White Paper","author":"Donovan Alan","year":"2010","unstructured":"Alan Donovan , Robert Muth , Brad Chen , and David Sehr . 2010 . Pnacl: Portable native client executables. Google White Paper (2010). Alan Donovan, Robert Muth, Brad Chen, and David Sehr. 2010. Pnacl: Portable native client executables. Google White Paper (2010)."},{"key":"e_1_3_2_1_26_1","unstructured":"Ulrich Drepper. 2006. SELinux Memory Protection. https:\/\/akkadia.org\/drepper\/selinux-mem.html.  Ulrich Drepper. 2006. SELinux Memory Protection. https:\/\/akkadia.org\/drepper\/selinux-mem.html."},{"key":"e_1_3_2_1_27_1","volume-title":"The Matter of Heartbleed. In Internet Measurement Conference (IMC).","author":"Durumeric Zakir","unstructured":"Zakir Durumeric , Frank Li , James Kasten , Johanna Amann , Jethro Beekman , Mathias Payer , Nicolas Weaver , David Adrian , Vern Paxson , Michael Bailey , and J. Alex Halderman . 2014 . The Matter of Heartbleed. In Internet Measurement Conference (IMC). Zakir Durumeric, Frank Li, James Kasten, Johanna Amann, Jethro Beekman, Mathias Payer, Nicolas Weaver, David Adrian, Vern Paxson, Michael Bailey, and J. Alex Halderman. 2014. The Matter of Heartbleed. In Internet Measurement Conference (IMC)."},{"key":"e_1_3_2_1_28_1","unstructured":"Marco Elver. 2021. Add support for synchronous signals on perf events. https:\/\/lwn.net\/Articles\/848984\/.  Marco Elver. 2021. Add support for synchronous signals on perf events. https:\/\/lwn.net\/Articles\/848984\/."},{"key":"e_1_3_2_1_29_1","volume-title":"ACM Symposium on Operating Systems Principles (SOSP).","author":"Erlingsson Ulfar","year":"2006","unstructured":"Ulfar Erlingsson , Mart\u00edn Abadi , Michael Vrable , Mihai Budiu , and George C Necula . 2006 . XFI: Software guards for system address spaces . In ACM Symposium on Operating Systems Principles (SOSP). Ulfar Erlingsson, Mart\u00edn Abadi, Michael Vrable, Mihai Budiu, and George C Necula. 2006. XFI: Software guards for system address spaces. In ACM Symposium on Operating Systems Principles (SOSP)."},{"key":"e_1_3_2_1_30_1","volume-title":"USENIX Annual Technical Conference.","author":"Ford Bryan","year":"2008","unstructured":"Bryan Ford and Russ Cox . 2008 . Vx32: Lightweight User-Level Sand-boxing on the X86 . In USENIX Annual Technical Conference. Bryan Ford and Russ Cox. 2008. Vx32: Lightweight User-Level Sand-boxing on the X86. In USENIX Annual Technical Conference."},{"key":"e_1_3_2_1_31_1","volume-title":"IMIX: In-Process Memory Isolation EXtension. In USENIX Security Symposium.","author":"Frassetto Tommaso","year":"2018","unstructured":"Tommaso Frassetto , Patrick Jauernig , Christopher Liebchen , and Ahmad-Reza Sadeghi . 2018 . IMIX: In-Process Memory Isolation EXtension. In USENIX Security Symposium. Tommaso Frassetto, Patrick Jauernig, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2018. IMIX: In-Process Memory Isolation EXtension. In USENIX Security Symposium."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66332-6_11"},{"key":"e_1_3_2_1_33_1","volume-title":"Enclosure: Language-Based Restriction of Untrusted Libraries. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS).","author":"Ghosn Adrien","year":"2021","unstructured":"Adrien Ghosn , Marios Kogias , Mathias Payer , James R. Larus , and Edouard Bugnion . 2021 . Enclosure: Language-Based Restriction of Untrusted Libraries. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS). Adrien Ghosn, Marios Kogias, Mathias Payer, James R. Larus, and Edouard Bugnion. 2021. Enclosure: Language-Based Restriction of Untrusted Libraries. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS)."},{"key":"e_1_3_2_1_34_1","volume-title":"International Symposium on Research in Attacks, Intrusions and Defenses (RAID).","author":"Gravani Spyridoula","unstructured":"Spyridoula Gravani , Mohammad Hedayati , John Criswell , and Michael L. Scott . 2021. IskiOS: Intra-kernel Isolation and Security using Memory Protection Keys . In International Symposium on Research in Attacks, Intrusions and Defenses (RAID). Spyridoula Gravani, Mohammad Hedayati, John Criswell, and Michael L. Scott. 2021. IskiOS: Intra-kernel Isolation and Security using Memory Protection Keys. In International Symposium on Research in Attacks, Intrusions and Defenses (RAID)."},{"key":"e_1_3_2_1_35_1","volume-title":"Clean Application Compartmentalization with SOAAP. In ACM Conference on Computer and Communications Security (CCS).","author":"Gudka Khilan","year":"2015","unstructured":"Khilan Gudka , Robert N.M. Watson , Jonathan Anderson , David Chisnall , Brooks Davis , Ben Laurie , Ilias Marinos , Peter G. Neumann , and Alex Richardson . 2015 . Clean Application Compartmentalization with SOAAP. In ACM Conference on Computer and Communications Security (CCS). Khilan Gudka, Robert N.M. Watson, Jonathan Anderson, David Chisnall, Brooks Davis, Ben Laurie, Ilias Marinos, Peter G. Neumann, and Alex Richardson. 2015. Clean Application Compartmentalization with SOAAP. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_36_1","volume-title":"Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries. In USENIX Annual Technical Conference.","author":"Hedayati Mohammad","year":"2019","unstructured":"Mohammad Hedayati , Spyridoula Gravani , Ethan Johnson , John Criswell , Michael L. Scott , Kai Shen , and Mike Marty . 2019 . Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries. In USENIX Annual Technical Conference. Mohammad Hedayati, Spyridoula Gravani, Ethan Johnson, John Criswell, Michael L. Scott, Kai Shen, and Mike Marty. 2019. Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries. In USENIX Annual Technical Conference."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2694344.2694390"},{"key":"e_1_3_2_1_38_1","volume-title":"Enforcing Least Privilege Memory Views for Multithreaded Applications. In ACM Conference on Computer and Communications Security (CCS).","author":"Ching-Hsiang Hsu Terry","year":"2016","unstructured":"Terry Ching-Hsiang Hsu , Kevin Hoffman , Patrick Eugster , and Mathias Payer . 2016 . Enforcing Least Privilege Memory Views for Multithreaded Applications. In ACM Conference on Computer and Communications Security (CCS). Terry Ching-Hsiang Hsu, Kevin Hoffman, Patrick Eugster, and Mathias Payer. 2016. Enforcing Least Privilege Memory Views for Multithreaded Applications. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_39_1","volume-title":"VIP: Safeguard Value Invariant Property for Thwarting Critical Memory Corruption Attacks. In ACM Conference on Computer and Communications Security (CCS).","author":"Ismail Mohannad","year":"2021","unstructured":"Mohannad Ismail , Jinwoo Yom , Christopher Jelesnianski , Yeongjin Jang , and Changwoo Min . 2021 . VIP: Safeguard Value Invariant Property for Thwarting Critical Memory Corruption Attacks. In ACM Conference on Computer and Communications Security (CCS). Mohannad Ismail, Jinwoo Yom, Christopher Jelesnianski, Yeongjin Jang, and Changwoo Min. 2021. VIP: Safeguard Value Invariant Property for Thwarting Critical Memory Corruption Attacks. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833650"},{"key":"e_1_3_2_1_41_1","volume-title":"USENIX Security Symposium.","author":"Kenjar Zijo","year":"2020","unstructured":"Zijo Kenjar , Tommaso Frassetto , David Gens , Michael Franz , and Ahmad-Reza Sadeghi . 2020 . V0ltpwn: Attacking x86 processor integrity from software . In USENIX Security Symposium. Zijo Kenjar, Tommaso Frassetto, David Gens, Michael Franz, and Ahmad-Reza Sadeghi. 2020. V0ltpwn: Attacking x86 processor integrity from software. In USENIX Security Symposium."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519582"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2016.46"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064217"},{"key":"e_1_3_2_1_46_1","volume-title":"Code-Pointer Integrity. In USENIX Security Symposium.","author":"Kuznetsov Volodymyr","year":"2014","unstructured":"Volodymyr Kuznetsov , Laszlo Szekeres , Mathias Payer , George Candea , R. Sekar , and Dawn Song . 2014 . Code-Pointer Integrity. In USENIX Security Symposium. Volodymyr Kuznetsov, Laszlo Szekeres, Mathias Payer, George Candea, R. Sekar, and Dawn Song. 2014. Code-Pointer Integrity. In USENIX Security Symposium."},{"key":"e_1_3_2_1_47_1","volume-title":"SoK: Automated Software Diversity. In IEEE Symposium on Security and Privacy (S&P).","author":"Larsen Per","year":"2014","unstructured":"Per Larsen , Andrei Homescu , Stefan Brunthaler , and Michael Franz . 2014 . SoK: Automated Software Diversity. In IEEE Symposium on Security and Privacy (S&P). Per Larsen, Andrei Homescu, Stefan Brunthaler, and Michael Franz. 2014. SoK: Automated Software Diversity. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_48_1","volume-title":"FlexOS: Towards Flexible OS Isolation. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS).","author":"Lefeuvre Hugo","year":"2022","unstructured":"Hugo Lefeuvre , Vlad-Andrei B\u0103doiu , Alexander Jung , Stefan Teodorescu , Sebastian Rauch , Felipe Huici , Costin Raiciu , and Pierre Olivier . 2022 . FlexOS: Towards Flexible OS Isolation. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS). Hugo Lefeuvre, Vlad-Andrei B\u0103doiu, Alexander Jung, Stefan Teodorescu, Sebastian Rauch, Felipe Huici, Costin Raiciu, and Pierre Olivier. 2022. FlexOS: Towards Flexible OS Isolation. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS)."},{"key":"e_1_3_2_1_49_1","volume-title":"Fidelity and Stealth in the DRAKVUF Dynamic Malware Analysis System. In Annual Computer Security Applications Conference (ACSAC).","author":"Lengyel Tamas K.","year":"2014","unstructured":"Tamas K. Lengyel , Steve Maresca , Bryan D. Payne , George D. Webster , Sebastian Vogl , and Aggelos Kiayias . 2014 . Scalability , Fidelity and Stealth in the DRAKVUF Dynamic Malware Analysis System. In Annual Computer Security Applications Conference (ACSAC). Tamas K. Lengyel, Steve Maresca, Bryan D. Payne, George D. Webster, Sebastian Vogl, and Aggelos Kiayias. 2014. Scalability, Fidelity and Stealth in the DRAKVUF Dynamic Malware Analysis System. In Annual Computer Security Applications Conference (ACSAC)."},{"key":"e_1_3_2_1_50_1","volume-title":"USENIX Security Symposium.","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Anders Fogh , Jann Horn , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018 . Meltdown: Reading Kernel Memory from User Space . In USENIX Security Symposium. Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, Jann Horn, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown: Reading Kernel Memory from User Space. In USENIX Security Symposium."},{"key":"e_1_3_2_1_51_1","volume-title":"Light-Weight Contexts: An OS Abstraction for Safety and Performance. In USENIX Symposium on Operating Systems Design and Implementation (OSDI).","author":"Litton James","year":"2016","unstructured":"James Litton , Anjo Vahldiek-Oberwagner , Eslam Elnikety , Deepak Garg , Bobby Bhattacharjee , and Peter Druschel . 2016 . Light-Weight Contexts: An OS Abstraction for Safety and Performance. In USENIX Symposium on Operating Systems Design and Implementation (OSDI). James Litton, Anjo Vahldiek-Oberwagner, Eslam Elnikety, Deepak Garg, Bobby Bhattacharjee, and Peter Druschel. 2016. Light-Weight Contexts: An OS Abstraction for Safety and Performance. In USENIX Symposium on Operating Systems Design and Implementation (OSDI)."},{"key":"e_1_3_2_1_52_1","volume-title":"ACM Conference on Computer and Communications Security (CCS).","author":"Liu Shen","year":"2021","unstructured":"Shen Liu , Gang Tan , and Trent Jaeger . 2021 . Ptrsplit: Supporting general pointers in automatic program partitioning . In ACM Conference on Computer and Communications Security (CCS). Shen Liu, Gang Tan, and Trent Jaeger. 2021. Ptrsplit: Supporting general pointers in automatic program partitioning. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_53_1","volume-title":"Thwarting Memory Disclosure with Efficient Hypervisor-Enforced Intra-Domain Isolation. In ACM Conference on Computer and Communications Security (CCS).","author":"Liu Yutao","year":"2015","unstructured":"Yutao Liu , Tianyu Zhou , Kexin Chen , Haibo Chen , and Yubin Xia . 2015 . Thwarting Memory Disclosure with Efficient Hypervisor-Enforced Intra-Domain Isolation. In ACM Conference on Computer and Communications Security (CCS). Yutao Liu, Tianyu Zhou, Kexin Chen, Haibo Chen, and Yubin Xia. 2015. Thwarting Memory Disclosure with Efficient Hypervisor-Enforced Intra-Domain Isolation. In ACM Conference on Computer and Communications Security (CCS)."},{"key":"e_1_3_2_1_54_1","volume-title":"USENIX Security Symposium.","author":"McCamant Stephen","year":"2006","unstructured":"Stephen McCamant and Greg Morrisett . 2006 . Evaluating SFI for a CISC Architecture .. In USENIX Security Symposium. Stephen McCamant and Greg Morrisett. 2006. Evaluating SFI for a CISC Architecture.. In USENIX Security Symposium."},{"key":"e_1_3_2_1_55_1","unstructured":"Daiping liu Mingwei Zhang Ravi Sahita. 2018. eXecutable-Only-Memory-Switch (XOM-Switch). In Black Hat Asia Briefings (Black Hat Asia).  Daiping liu Mingwei Zhang Ravi Sahita. 2018. eXecutable-Only-Memory-Switch (XOM-Switch). In Black Hat Asia Briefings (Black Hat Asia)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_17"},{"key":"e_1_3_2_1_57_1","unstructured":"John Richard Mose. 2006. Virtual Machines and Memory Protections. https:\/\/lwn.net\/Articles\/210272\/.  John Richard Mose. 2006. Virtual Machines and Memory Protections. https:\/\/lwn.net\/Articles\/210272\/."},{"key":"e_1_3_2_1_58_1","volume-title":"USENIX Annual Technical Conference.","author":"Park Soyeon","year":"2019","unstructured":"Soyeon Park , Sangho Lee , Wen Xu , Hyungon Moon , and Taesoo Kim . 2019 . libmpk: Software Abstraction for Intel Memory Protection Keys . In USENIX Annual Technical Conference. Soyeon Park, Sangho Lee, Wen Xu, Hyungon Moon, and Taesoo Kim. 2019. libmpk: Software Abstraction for Intel Memory Protection Keys. In USENIX Annual Technical Conference."},{"key":"e_1_3_2_1_59_1","volume-title":"NoJITsu: Locking Down JavaScript Engines. In Symposium on Network and Distributed System Security (NDSS).","author":"Park Taemin","year":"2020","unstructured":"Taemin Park , Karel Dhondt , David Gens , Yeoul Na , Stijn Volckaert , and Michael Franz . 2020 . NoJITsu: Locking Down JavaScript Engines. In Symposium on Network and Distributed System Security (NDSS). Taemin Park, Karel Dhondt, David Gens, Yeoul Na, Stijn Volckaert, and Michael Franz. 2020. NoJITsu: Locking Down JavaScript Engines. In Symposium on Network and Distributed System Security (NDSS)."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274698"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00041"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471839"},{"key":"e_1_3_2_1_63_1","volume-title":"CubicleOS: A Library OS with Software Componentisation for Practical Isolation. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS).","author":"Sartakov Vasily A.","year":"2021","unstructured":"Vasily A. Sartakov , Llu\u00eds Vilanova , and Peter Pietzuch . 2021 . CubicleOS: A Library OS with Software Componentisation for Practical Isolation. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS). Vasily A. Sartakov, Llu\u00eds Vilanova, and Peter Pietzuch. 2021. CubicleOS: A Library OS with Software Componentisation for Practical Isolation. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS)."},{"key":"e_1_3_2_1_64_1","volume-title":"Jenny: Securing Syscalls for PKU-based Memory Isolation Systems. In USENIX Security Symposium.","author":"Schrammel David","year":"2022","unstructured":"David Schrammel , Samuel Weiser , Richard Sadek , and Stefan Mangard . 2022 . Jenny: Securing Syscalls for PKU-based Memory Isolation Systems. In USENIX Security Symposium. David Schrammel, Samuel Weiser, Richard Sadek, and Stefan Mangard. 2022. Jenny: Securing Syscalls for PKU-based Memory Isolation Systems. In USENIX Security Symposium."},{"key":"e_1_3_2_1_65_1","volume-title":"USENIX Security Symposium.","author":"Schrammel David","year":"2020","unstructured":"David Schrammel , Samuel Weiser , Stefan Steinegger , Martin Schwarzl , Michael Schwarz , Stefan Mangard , and Daniel Gruss . 2020 . Donky: Domain Keys - Efficient In-Process Isolation for RISC-V and x86 . In USENIX Security Symposium. David Schrammel, Samuel Weiser, Stefan Steinegger, Martin Schwarzl, Michael Schwarz, Stefan Mangard, and Daniel Gruss. 2020. Donky: Domain Keys - Efficient In-Process Isolation for RISC-V and x86. In USENIX Security Symposium."},{"key":"e_1_3_2_1_66_1","unstructured":"Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM rowhammer bug to gain kernel privileges. In BlackHat USA.  Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM rowhammer bug to gain kernel privileges. In BlackHat USA."},{"key":"e_1_3_2_1_67_1","volume-title":"USENIX Security Symposium.","author":"Sehr David","year":"2010","unstructured":"David Sehr , Robert Muth , Cliff Biffle , Victor Khimenko , Egor Pasko , Karl Schimpf , Bennet Yee , and Brad Chen . 2010 . Adapting Software Fault Isolation to Contemporary CPU Architectures . In USENIX Security Symposium. David Sehr, Robert Muth, Cliff Biffle, Victor Khimenko, Egor Pasko, Karl Schimpf, Bennet Yee, and Brad Chen. 2010. Adapting Software Fault Isolation to Contemporary CPU Architectures. In USENIX Security Symposium."},{"key":"e_1_3_2_1_68_1","volume-title":"Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In IEEE Symposium on Security and Privacy (S&P).","author":"Snow Kevin Z.","year":"2013","unstructured":"Kevin Z. Snow , Fabian Monrose , Lucas Davi , Alexandra Dmitrienko , Christopher Liebchen , and Ahmad-Reza Sadeghi . 2013 . Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In IEEE Symposium on Security and Privacy (S&P). Kevin Z. Snow, Fabian Monrose, Lucas Davi, Alexandra Dmitrienko, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2013. Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_69_1","volume-title":"Efficient Intra-Process Privilege Enforcement of Memory Regions. arXiv preprint arXiv:2108.03705","author":"Tarkhani Zahra","year":"2020","unstructured":"Zahra Tarkhani and Anil Madhavapeddy . 2020. &mu;Tiles : Efficient Intra-Process Privilege Enforcement of Memory Regions. arXiv preprint arXiv:2108.03705 ( 2020 ). Zahra Tarkhani and Anil Madhavapeddy. 2020. &mu;Tiles: Efficient Intra-Process Privilege Enforcement of Memory Regions. arXiv preprint arXiv:2108.03705 (2020)."},{"key":"e_1_3_2_1_70_1","volume-title":"Efficient In-process Isolation with Memory Protection Keys. In USENIX Security Symposium.","author":"Vahldiek-Oberwagner Anjo","year":"2019","unstructured":"Anjo Vahldiek-Oberwagner , Eslam Elnikety , Nuno O Duarte , Peter Druschel , and Deepak Garg . 2019 . ERIM: Secure , Efficient In-process Isolation with Memory Protection Keys. In USENIX Security Symposium. Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O Duarte, Peter Druschel, and Deepak Garg. 2019. ERIM: Secure, Efficient In-process Isolation with Memory Protection Keys. In USENIX Security Symposium."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"e_1_3_2_1_72_1","volume-title":"Automated Application Compartmentalization. In Workshop on Programming Languages and Operating Systems.","author":"Vasilakis Nikos","unstructured":"Nikos Vasilakis , Ben Karel , Nick Roessler , Nathan Dautenhahn , Andr\u00e9 DeHon , and Jonathan M. Smith . 2017. Towards Fine-Grained , Automated Application Compartmentalization. In Workshop on Programming Languages and Operating Systems. Nikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn, Andr\u00e9 DeHon, and Jonathan M. Smith. 2017. Towards Fine-Grained, Automated Application Compartmentalization. In Workshop on Programming Languages and Operating Systems."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23131"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665741"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519558"},{"key":"e_1_3_2_1_76_1","volume-title":"USENIX Annual Technical Conference.","author":"Volckaert Stijn","year":"2016","unstructured":"Stijn Volckaert , Bart Coppens , Alexios Voulimeneas , Andrei Homescu , Per Larsen , Bjorn De Sutter , and Michael Franz . 2016 . Secure and Efficient Application Monitoring and Replication .. In USENIX Annual Technical Conference. Stijn Volckaert, Bart Coppens, Alexios Voulimeneas, Andrei Homescu, Per Larsen, Bjorn De Sutter, and Michael Franz. 2016. Secure and Efficient Application Monitoring and Replication.. In USENIX Annual Technical Conference."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447852.3458714"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_11"},{"key":"e_1_3_2_1_79_1","volume-title":"Efficient Software-Based Fault Isolation. In ACM Symposium on Operating Systems Principles (SOSP).","author":"Wahbe Robert","unstructured":"Robert Wahbe , Steven Lucco , Thomas E. Anderson , and Susan L. Graham . 1993 . Efficient Software-Based Fault Isolation. In ACM Symposium on Operating Systems Principles (SOSP). Robert Wahbe, Steven Lucco, Thomas E. Anderson, and Susan L. Graham. 1993. Efficient Software-Based Fault Isolation. In ACM Symposium on Operating Systems Principles (SOSP)."},{"key":"e_1_3_2_1_80_1","volume-title":"Secure and Efficient In-Process Monitor (and Library) Protection with Intel MPK. In European Workshop on System Security (EuroSec).","author":"Wang Xiaoguang","year":"2020","unstructured":"Xiaoguang Wang , SengMing Yeoh , Pierre Olivier , and Binoy Ravindran . 2020 . Secure and Efficient In-Process Monitor (and Library) Protection with Intel MPK. In European Workshop on System Security (EuroSec). Xiaoguang Wang, SengMing Yeoh, Pierre Olivier, and Binoy Ravindran. 2020. Secure and Efficient In-Process Monitor (and Library) Protection with Intel MPK. In European Workshop on System Security (EuroSec)."},{"key":"e_1_3_2_1_81_1","volume-title":"SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory Isolation. In IEEE Symposium on Security and Privacy (S&P).","author":"Wang Zhe","year":"2020","unstructured":"Zhe Wang , Chenggang Wu , Mengyao Xie , Yinqian Zhang , Kangjie Lu , Xiaofeng Zhang , Yuanming Lai , Yan Kang , and Min Yang . 2020 . SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory Isolation. In IEEE Symposium on Security and Privacy (S&P). Zhe Wang, Chenggang Wu, Mengyao Xie, Yinqian Zhang, Kangjie Lu, Xiaofeng Zhang, Yuanming Lai, Yan Kang, and Min Yang. 2020. SEIMI: Efficient and Secure SMAP-Enabled Intra-process Memory Isolation. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23808-6_34"},{"key":"e_1_3_2_1_83_1","volume-title":"CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization. In IEEE Symposium on Security and Privacy (S&P).","author":"Watson Robert N.M.","year":"2015","unstructured":"Robert N.M. Watson , Jonathan Woodruff , Peter G. Neumann , Simon W. Moore , Jonathan Anderson , David Chisnall , Nirav Dave , Brooks Davis , Khilan Gudka , Ben Laurie , Steven J. Murdoch , Robert Norton , Michael Roe , Stacey Son , and Munraj Vadera . 2015 . CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization. In IEEE Symposium on Security and Privacy (S&P). Robert N.M. Watson, Jonathan Woodruff, Peter G. Neumann, Simon W. Moore, Jonathan Anderson, David Chisnall, Nirav Dave, Brooks Davis, Khilan Gudka, Ben Laurie, Steven J. Murdoch, Robert Norton, Michael Roe, Stacey Son, and Munraj Vadera. 2015. CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization. In IEEE Symposium on Security and Privacy (S&P)."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2013.6693091"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.25"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/2038642.2038687"}],"event":{"name":"EuroSys '22: Seventeenth European Conference on Computer Systems","location":"Rennes France","acronym":"EuroSys '22","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the Seventeenth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3492321.3519560","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3492321.3519560","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:31:07Z","timestamp":1750188667000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3492321.3519560"}},"subtitle":["practical, secure, and fast PKU-based sandboxing"],"short-title":[],"issued":{"date-parts":[[2022,3,28]]},"references-count":86,"alternative-id":["10.1145\/3492321.3519560","10.1145\/3492321"],"URL":"https:\/\/doi.org\/10.1145\/3492321.3519560","relation":{},"subject":[],"published":{"date-parts":[[2022,3,28]]},"assertion":[{"value":"2022-03-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}