{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T02:39:22Z","timestamp":1783564762082,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623198","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"2009-2023","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["KRover: A Symbolic Execution Engine for Dynamic Kernel Analysis"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9991-3390","authenticated-orcid":false,"given":"Pansilu","family":"Pitigalaarachchi","sequence":"first","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3974-590X","authenticated-orcid":false,"given":"Xuhua","family":"Ding","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9978-249X","authenticated-orcid":false,"given":"Haiqing","family":"Qiu","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2389-1881","authenticated-orcid":false,"given":"Haoxin","family":"Tu","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-4894-2672","authenticated-orcid":false,"given":"Jiaqi","family":"Hong","sequence":"additional","affiliation":[{"name":"Independent Researcher, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4336-8548","authenticated-orcid":false,"given":"Lingxiao","family":"Jiang","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2560217.2560219"},{"key":"e_1_3_2_1_2_1","volume-title":"USENIX Annual Technical Conference, FREENIX Track. 41--46","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard. 2005. QEMU, a fast and portable dynamic translator. In USENIX Annual Technical Conference, FREENIX Track. 41--46."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22110-1_37"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). 209--224","author":"Cadar Cristian","year":"2008","unstructured":"Cristian Cadar, Daniel Dunbar, and Dawson Engler. 2008. KLEE: Unassisted and Automatic Generation of High-Coverage Tests for Complex Systems Programs. In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). 209--224."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.31"},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 29th USENIX Security Symposium. 1093--1110","author":"Chen Weiteng","year":"2020","unstructured":"Weiteng Chen, Xiaochen Zou, Guoren Li, and Zhiyun Qian. 2020. KOOBE: Towards Facilitating Exploit Generation of Kernel Out-Of-Bounds Write Vulnerabilities. In Proceedings of the 29th USENIX Security Symposium. 1093--1110."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2110356.2110358"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00024"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P). 588--603","author":"Jiang Zheyue","year":"2023","unstructured":"Zheyue Jiang, Yuan Zhang, Jun Xu, Xinqian Sun, Zhuang Liu, and Min Yang. 2023. AEM: Facilitating Cross-Version Exploitability Assessment of Linux Kernel Vulnerabilities. In Proceedings of the IEEE Symposium on Security and Privacy (S&P). 588--603."},{"key":"e_1_3_2_1_10_1","volume-title":"Retrieved September 8th","author":"The","year":"2023","unstructured":"The kernel development community. 2022. The Kernel Address Sanitizer (KASAN). (2022). Retrieved September 8th, 2023 from https:\/\/docs.kernel.org\/dev-tools\/kasan.html"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24018"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1064978.1065034"},{"key":"e_1_3_2_1_13_1","volume-title":"Retrieved September 8th","author":"Maloy Jon","year":"2023","unstructured":"Jon Maloy. 2023. TIPC Programmer's Guide. (2023). Retrieved September 8th, 2023 from http:\/\/tipc.io\/programming.html"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2889160.2889173"},{"key":"e_1_3_2_1_16_1","volume-title":"Retrieved September 8th","year":"2021","unstructured":"Peter. 2021. Local PoC exploit for CVE-2021-43267. (2021). Retrieved September 8th, 2023 from https:\/\/haxx.in\/files\/blasty-vs-tipc.c"},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the 29th USENIX Security Symposium. 181--198","author":"Poeplau Sebastian","year":"2020","unstructured":"Sebastian Poeplau and Aur\u00e9lien Francillon. 2020. Symbolic execution with SymCC: Don't interpret, compile!. In Proceedings of the 29th USENIX Security Symposium. 181--198."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24118"},{"key":"e_1_3_2_1_19_1","first-page":"2021","volume-title":"Retrieved September 8th","author":"Program CVE","year":"2021","unstructured":"CVE Program. 2021. CVE-2021-43267. (2021). Retrieved September 8th, 2023 from https:\/\/www.cve.org\/CVERecord?id=CVE-2021-43267"},{"key":"e_1_3_2_1_20_1","volume-title":"Retrieved September 8th","author":"Project Dyninst","year":"2021","unstructured":"Dyninst Project. 2021. Dyninst. (2021). Retrieved September 8th, 2023 from https:\/\/github.com\/dyninst\/dyninst\/tree\/v12.0.0"},{"key":"e_1_3_2_1_21_1","volume-title":"Retrieved September 8th","author":"Rover","year":"2023","unstructured":"KRover project. 2023. KRover: extended paper. (2023). Retrieved September 8th, 2023 from https:\/\/github.com\/KRoverSystems\/KRover\/blob\/main\/KRoverFullPaper.pdf"},{"key":"e_1_3_2_1_22_1","volume-title":"Presented as part of the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 279--292.","author":"Renzelmann Matthew J","unstructured":"Matthew J Renzelmann, Asim Kadav, and Michael M Swift. 2012. SymDrive: Testing drivers without devices. In Presented as part of the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 279--292."},{"key":"e_1_3_2_1_23_1","volume-title":"Retrieved September 8th","author":"Research Microsoft","year":"2021","unstructured":"Microsoft Research. 2021. Z3. (2021). Retrieved September 8th, 2023 from https:\/\/github.com\/Z3Prover\/z3\/tree\/z3-4.8.14"},{"key":"e_1_3_2_1_24_1","volume-title":"Symposium on Information and Communications Technology Security. 31--54","author":"Saudel Florent","year":"2015","unstructured":"Florent Saudel and Jonathan Salwan. 2015. Triton: A dynamic symbolic execution framework. In Symposium on Information and Communications Technology Security. 31--54."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"e_1_3_2_1_26_1","first-page":"11","article-title":"Heap Feng Shui in Javascript","volume":"2007","author":"Sotirov Alexander","year":"2007","unstructured":"Alexander Sotirov. 2007. Heap Feng Shui in Javascript. Black Hat Europe, Vol. 2007 (2007), 11--20.","journal-title":"Black Hat Europe"},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 1914--1927","author":"Wang Yan","year":"2018","unstructured":"Yan Wang, Chao Zhang, Xiaobo Xiang, Zixuan Zhao, Wenjie Li, Xiaorui Gong, Bingchang Liu, Kaixiang Chen, and Wei Zou. 2018. Revery: From Proof-of-Concept to Exploitable (One Step towards Automatic Exploit Generation). In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS). 1914--1927."},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 27th USENIX Security Symposium. 781--797","author":"Wu Wei","year":"2018","unstructured":"Wei Wu, Yueqi Chen, Jun Xu, Xinyu Xing, Xiaorui Gong, and Wei Zou. 2018. FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free Vulnerabilities. In Proceedings of the 27th USENIX Security Symposium. 781--797."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 27th USENIX Security Symposium. 745--761","author":"Yun Insu","year":"2020","unstructured":"Insu Yun, Sangho Lee, Meng Xu, Yeongjin Jang, and Taesoo Kim. 2020. QSYM: A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing. In Proceedings of the 27th USENIX Security Symposium. 745--761."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409686"},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the 31st USENIX Security Symposium. 3201--3217","author":"Zou Xiaochen","year":"2022","unstructured":"Xiaochen Zou, Guoren Li, Weiteng Chen, Hang Zhang, and Zhiyun Qian. 2022. SyzScope: Revealing High Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel. In Proceedings of the 31st USENIX Security Symposium. 3201--3217.o"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623198","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623198","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:44:06Z","timestamp":1755740646000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623198"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":31,"alternative-id":["10.1145\/3576915.3623198","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623198","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}