{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T19:47:04Z","timestamp":1782589624274,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":90,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,3,25]],"date-time":"2023-03-25T00:00:00Z","timestamp":1679702400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-2155235, CNS-2120642, CAREER CNS-2048262"],"award-info":[{"award-number":["CNS-2155235, CNS-2120642, CAREER CNS-2048262"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["HARDEN #N66001-22-9-4017"],"award-info":[{"award-number":["HARDEN #N66001-22-9-4017"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100002418","name":"Intel Corporation","doi-asserted-by":"publisher","award":["Gift"],"award-info":[{"award-number":["Gift"]}],"id":[{"id":"10.13039\/100002418","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006785","name":"Google","doi-asserted-by":"publisher","award":["Gift"],"award-info":[{"award-number":["Gift"]}],"id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012642","name":"Mozilla Foundation","doi-asserted-by":"publisher","award":["Gift"],"award-info":[{"award-number":["Gift"]}],"id":[{"id":"10.13039\/501100012642","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,3,25]]},"DOI":"10.1145\/3582016.3582023","type":"proceedings-article","created":{"date-parts":[[2023,3,20]],"date-time":"2023-03-20T16:59:03Z","timestamp":1679331543000},"page":"266-281","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFI"],"prefix":"10.1145","author":[{"given":"Shravan","family":"Narayan","sequence":"first","affiliation":[{"name":"University of California at San Diego, San Diego, USA \/ University of Texas at Austin, Austin, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tal","family":"Garfinkel","sequence":"additional","affiliation":[{"name":"University of California at San Diego, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammadkazem","family":"Taram","sequence":"additional","affiliation":[{"name":"Purdue University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joey","family":"Rudek","sequence":"additional","affiliation":[{"name":"University of California at San Diego, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Moghimi","sequence":"additional","affiliation":[{"name":"University of California at San Diego, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evan","family":"Johnson","sequence":"additional","affiliation":[{"name":"University of California at San Diego, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chris","family":"Fallin","sequence":"additional","affiliation":[{"name":"Fastly, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anjo","family":"Vahldiek-Oberwagner","sequence":"additional","affiliation":[{"name":"Intel Labs, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"LeMay","sequence":"additional","affiliation":[{"name":"Intel Labs, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ravi","family":"Sahita","sequence":"additional","affiliation":[{"name":"Rivos, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dean","family":"Tullsen","sequence":"additional","affiliation":[{"name":"University of California at San Diego, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Deian","family":"Stefan","sequence":"additional","affiliation":[{"name":"University of California at San Diego, San Diego, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,3,25]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1899928.1899930"},{"key":"e_1_3_2_1_2_1","unstructured":"Akamai. 2015. Serverless Computing with Akamai Edge Workers. https:\/\/www.akamai.com\/products\/serverless-computing-edgeworkers \t\t\t\t  Akamai. 2015. Serverless Computing with Akamai Edge Workers. https:\/\/www.akamai.com\/products\/serverless-computing-edgeworkers"},{"key":"e_1_3_2_1_3_1","unstructured":"Andreas Rossberg (Ed.). 2020. Memory64 Proposal for WebAssembly. https:\/\/github.com\/WebAssembly\/memory64 \t\t\t\t  Andreas Rossberg (Ed.). 2020. Memory64 Proposal for WebAssembly. https:\/\/github.com\/WebAssembly\/memory64"},{"key":"e_1_3_2_1_4_1","unstructured":"Andreas Rossberg (Ed.). 2022. Multi Memory Proposal for WebAssembly. https:\/\/github.com\/WebAssembly\/multi-memory \t\t\t\t  Andreas Rossberg (Ed.). 2022. Multi Memory Proposal for WebAssembly. https:\/\/github.com\/WebAssembly\/multi-memory"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1993498.1993540"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1810891.1810910"},{"key":"e_1_3_2_1_7_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. OSDI\u201916","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov , Bohdan Trach , Franz Gregor , Thomas Knauth , Andre Martin , Christian Priebe , Joshua Lind , Divya Muthukumaran , Dan O\u2019Keeffe , Mark L. Stillwell , David Goltzsche , David Eyers , R\u00fcdiger Kapitza , Peter Pietzuch , and Christof Fetzer . 2016 . SCONE: Secure Linux Containers with Intel SGX. OSDI\u201916 . USENIX Association , USA. 689\u2013703. isbn:9781931971331 Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O\u2019Keeffe, Mark L. Stillwell, David Goltzsche, David Eyers, R\u00fcdiger Kapitza, Peter Pietzuch, and Christof Fetzer. 2016. SCONE: Secure Linux Containers with Intel SGX. OSDI\u201916. USENIX Association, USA. 689\u2013703. isbn:9781931971331"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI).","author":"Belay Adam","year":"2012","unstructured":"Adam Belay , Andrea Bittau , Ali Jos\u00e9 Mashtizadeh , David Terei , David Mazi\u00e8res , and Christos Kozyrakis . 2012 . Dune: Safe User-level Access to Privileged CPU Features . In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). Adam Belay, Andrea Bittau, Ali Jos\u00e9 Mashtizadeh, David Terei, David Mazi\u00e8res, and Christos Kozyrakis. 2012. Dune: Safe User-level Access to Privileged CPU Features. In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI)."},{"key":"e_1_3_2_1_10_1","unstructured":"2022. Evaluate expat CVE-2022-40674 fix. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1791598 \t\t\t\t  2022. Evaluate expat CVE-2022-40674 fix. https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1791598"},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella , Jo Van Bulck , Michael Schwarz , Moritz Lipp , Benjamin Von Berg , Philipp Ortner , Frank Piessens , Dmitry Evtyushkin , and Daniel Gruss . 2019 . A Systematic Evaluation of Transient Execution Attacks and Defenses . In Proceedings of the USENIX Security Symposium (USENIX Security). Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Benjamin Von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. 2019. A Systematic Evaluation of Transient Execution Attacks and Defenses. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/381792.195579"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.12"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Connor R Joseph","year":"2020","unstructured":"R Joseph Connor , Tyler McDaniel , Jared M Smith , and Max Schuchard . 2020 . PKU Pitfalls: Attacks on PKU-based Memory Isolation Systems . In Proceedings of the USENIX Security Symposium (USENIX Security). R Joseph Connor, Tyler McDaniel, Jared M Smith, and Max Schuchard. 2020. PKU Pitfalls: Attacks on PKU-based Memory Isolation Systems. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_15_1","unstructured":"Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive. \t\t\t\t  Victor Costan and Srinivas Devadas. 2016. Intel SGX explained. Cryptology ePrint Archive."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304042"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/357980.357993"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361070"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217953"},{"key":"e_1_3_2_1_20_1","unstructured":"Adam Foltzer. 2019. The Lifecycle and Performance of a Lucet Instance. https:\/\/www.fastly.com\/blog\/lucet-performance-and-lifecycle Accessed: 2022-08-10 \t\t\t\t  Adam Foltzer. 2019. The Lifecycle and Performance of a Lucet Instance. https:\/\/www.fastly.com\/blog\/lucet-performance-and-lifecycle Accessed: 2022-08-10"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC).","author":"Ford Bryan","year":"2008","unstructured":"Bryan Ford and Russ Cox . 2008 . Vx32: Lightweight User-level Sandboxing on the x86 . In Proceedings of the USENIX Annual Technical Conference (ATC). Bryan Ford and Russ Cox. 2008. Vx32: Lightweight User-level Sandboxing on the x86. In Proceedings of the USENIX Annual Technical Conference (ATC)."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Frassetto Tommaso","year":"2018","unstructured":"Tommaso Frassetto , Patrick Jauernig , Christopher Liebchen , and Ahmad-Reza Sadeghi . 2018 . IMIX:In-Process Memory Isolation EXtension . In Proceedings of the USENIX Security Symposium (USENIX Security). Tommaso Frassetto, Patrick Jauernig, Christopher Liebchen, and Ahmad-Reza Sadeghi. 2018. IMIX:In-Process Memory Isolation EXtension. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3423211.3425680"},{"key":"e_1_3_2_1_24_1","unstructured":"Google. 2020. SafeSide. https:\/\/github.com\/google\/safeside \t\t\t\t  Google. 2020. SafeSide. https:\/\/github.com\/google\/safeside"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2294"},{"key":"e_1_3_2_1_26_1","unstructured":"W3C Webassembly Community Group. 2023. Component Model design and specification. https:\/\/github.com\/webassembly\/component-model Accessed: 2022-08-20 \t\t\t\t  W3C Webassembly Community Group. 2023. Component Model design and specification. https:\/\/github.com\/webassembly\/component-model Accessed: 2022-08-20"},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC).","author":"Gu Jinyu","year":"2022","unstructured":"Jinyu Gu , Hao Li , Wentai Li , Yubin Xia , and Haibo Chen . 2022 . EPK: Scalable and Efficient Memory Protection Keys . In Proceedings of the USENIX Annual Technical Conference (ATC). Jinyu Gu, Hao Li, Wentai Li, Yubin Xia, and Haibo Chen. 2022. EPK: Scalable and Efficient Memory Protection Keys. In Proceedings of the USENIX Annual Technical Conference (ATC)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3062341.3062363"},{"key":"e_1_3_2_1_29_1","unstructured":"2014. CVE-2014-0160 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-0160 \t\t\t\t  2014. CVE-2014-0160 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2014-0160"},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC). http:\/\/www.usenix.org\/conference\/atc19\/presentation\/hedayati-hodor","author":"Hedayati Mohammad","year":"2019","unstructured":"Mohammad Hedayati , Spyridoula Gravani , Ethan Johnson , John Criswell , Michael L. Scott , Kai Shen , and Mike Marty . 2019 . Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries . In Proceedings of the USENIX Annual Technical Conference (ATC). http:\/\/www.usenix.org\/conference\/atc19\/presentation\/hedayati-hodor Mohammad Hedayati, Spyridoula Gravani, Ethan Johnson, John Criswell, Michael L. Scott, Kai Shen, and Mike Marty. 2019. Hodor: Intra-Process Isolation for High-Throughput Data Plane Libraries. In Proceedings of the USENIX Annual Technical Conference (ATC). http:\/\/www.usenix.org\/conference\/atc19\/presentation\/hedayati-hodor"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2893177"},{"key":"e_1_3_2_1_32_1","volume-title":"Announcing Lucet: Fastly\u2019s native WebAssembly compiler and runtime. https:\/\/www.fastly.com\/blog\/announcing-lucet-fastly-native-webassembly-compiler-runtime","author":"Hickey Pat","year":"2019","unstructured":"Pat Hickey . 2019 . Announcing Lucet: Fastly\u2019s native WebAssembly compiler and runtime. https:\/\/www.fastly.com\/blog\/announcing-lucet-fastly-native-webassembly-compiler-runtime Pat Hickey. 2019. Announcing Lucet: Fastly\u2019s native WebAssembly compiler and runtime. https:\/\/www.fastly.com\/blog\/announcing-lucet-fastly-native-webassembly-compiler-runtime"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978327"},{"key":"e_1_3_2_1_34_1","volume-title":"The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization. https:\/\/doi.org\/10.48550\/ARXIV.2108.03705","author":"Im Bumjin","year":"2021","unstructured":"Bumjin Im , Fangfei Yang , Chia-Che Tsai , Michael LeMay , Anjo Vahldiek-Oberwagner , and Nathan Dautenhahn . 2021 . The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization. https:\/\/doi.org\/10.48550\/ARXIV.2108.03705 10.48550\/ARXIV.2108.03705 Bumjin Im, Fangfei Yang, Chia-Che Tsai, Michael LeMay, Anjo Vahldiek-Oberwagner, and Nathan Dautenhahn. 2021. The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization. https:\/\/doi.org\/10.48550\/ARXIV.2108.03705"},{"key":"e_1_3_2_1_35_1","unstructured":"2020. Intel \u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual. \t\t\t\t  2020. Intel \u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual."},{"key":"e_1_3_2_1_36_1","volume-title":"Native Code. In Proceedings of the USENIX Annual Technical Conference (ATC).","author":"Jangda Abhinav","year":"2019","unstructured":"Abhinav Jangda , Bobby Powers , Emery D. Berger , and Arjun Guha . 2019 . Not So Fast: Analyzing the Performance of WebAssembly vs . Native Code. In Proceedings of the USENIX Annual Technical Conference (ATC). Abhinav Jangda, Bobby Powers, Emery D. Berger, and Arjun Guha. 2019. Not So Fast: Analyzing the Performance of WebAssembly vs. Native Code. In Proceedings of the USENIX Annual Technical Conference (ATC)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24078"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3498688"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064217"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243748"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480076"},{"key":"e_1_3_2_1_42_1","volume-title":"Capability-based Computer Systems","author":"Levy Henry M.","unstructured":"Henry M. Levy . 1984. Capability-based Computer Systems . Digital Press . isbn:978-0-932376-22-0 Henry M. Levy. 1984. Capability-based Computer Systems. Digital Press. isbn:978-0-932376-22-0"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI).","author":"Litton James","year":"2016","unstructured":"James Litton , Anjo Vahldiek-Oberwagner , Eslam Elnikety , Deepak Garg , Bobby Bhattacharjee , and Peter Druschel . 2016 . Light-Weight Contexts: An OS Abstraction for Safety and Performance . In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). James Litton, Anjo Vahldiek-Oberwagner, Eslam Elnikety, Deepak Garg, Bobby Bhattacharjee, and Peter Druschel. 2016. Light-Weight Contexts: An OS Abstraction for Safety and Performance. In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI)."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813690"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Loughlin Kevin","year":"2021","unstructured":"Kevin Loughlin , Ian Neal , Jiacheng Ma , Elisa Tsai , Ofir Weisse , Satish Narayanasamy , and Baris Kasikci . 2021 . DOLMA: Securing Speculation with the Principle of Transient Non-Observability . In Proceedings of the USENIX Security Symposium (USENIX Security). Kevin Loughlin, Ian Neal, Jiacheng Ma, Elisa Tsai, Ofir Weisse, Satish Narayanasamy, and Baris Kasikci. 2021. DOLMA: Securing Speculation with the Principle of Transient Non-Observability. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"#cr-split#-e_1_3_2_1_46_1.1","unstructured":"Jason Lowe-Power Abdul Mutaal Ahmad Ayaz Akram Mohammad Alian Rico Amslinger Matteo Andreozzi Adri\u00e0 Armejach Nils Asmussen Brad Beckmann Srikant Bharadwaj Gabe Black Gedare Bloom Bobby R. Bruce Daniel Rodrigues Carvalho Jeronimo Castrillon Lizhong Chen Nicolas Derumigny Stephan Diestelhorst Wendy Elsasser Carlos Escuin Marjan Fariborz Amin Farmahini-Farahani Pouya Fotouhi Ryan Gambord Jayneel Gandhi Dibakar Gope Thomas Grass Anthony Gutierrez Bagus Hanindhito Andreas Hansson and Swapnil Haria. 2020. The gem5 Simulator: Version 20.0+. https:\/\/doi.org\/10.48550\/ARXIV.2007.03152 10.48550\/ARXIV.2007.03152"},{"key":"#cr-split#-e_1_3_2_1_46_1.2","unstructured":"Jason Lowe-Power Abdul Mutaal Ahmad Ayaz Akram Mohammad Alian Rico Amslinger Matteo Andreozzi Adri\u00e0 Armejach Nils Asmussen Brad Beckmann Srikant Bharadwaj Gabe Black Gedare Bloom Bobby R. Bruce Daniel Rodrigues Carvalho Jeronimo Castrillon Lizhong Chen Nicolas Derumigny Stephan Diestelhorst Wendy Elsasser Carlos Escuin Marjan Fariborz Amin Farmahini-Farahani Pouya Fotouhi Ryan Gambord Jayneel Gandhi Dibakar Gope Thomas Grass Anthony Gutierrez Bagus Hanindhito Andreas Hansson and Swapnil Haria. 2020. The gem5 Simulator: Version 20.0+. https:\/\/doi.org\/10.48550\/ARXIV.2007.03152"},{"key":"e_1_3_2_1_47_1","unstructured":"Martin Maas. 2022. Working Draft of the RISC-V J Extension Specification. https:\/\/github.com\/riscv\/riscv-j-extension \t\t\t\t  Martin Maas. 2022. Working Draft of the RISC-V J Extension Specification. https:\/\/github.com\/riscv\/riscv-j-extension"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132763"},{"key":"e_1_3_2_1_49_1","unstructured":"Jordon Mears. 2019. How we\u2019re bringing Google Earth to the web. https:\/\/web.dev\/earth-webassembly\/ \t\t\t\t  Jordon Mears. 2019. How we\u2019re bringing Google Earth to the web. https:\/\/web.dev\/earth-webassembly\/"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/2254064.2254111"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/850708.850709"},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Narayan Shravan","year":"2020","unstructured":"Shravan Narayan , Craig Disselkoen , Tal Garfinkel , Nathan Froyd , Eric Rahm , Sorin Lerner , Hovav Shacham , and Deian Stefan . 2020 . Retrofitting Fine Grain Isolation in the Firefox Renderer . In Proceedings of the USENIX Security Symposium (USENIX Security). Shravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd, Eric Rahm, Sorin Lerner, Hovav Shacham, and Deian Stefan. 2020. Retrofitting Fine Grain Isolation in the Firefox Renderer. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Narayan Shravan","year":"2021","unstructured":"Shravan Narayan , Craig Disselkoen , Daniel Moghimi , Sunjay Cauligi , Evan Johnson , Zhao Gang , Anjo Vahldiek-Oberwagner , Ravi Sahita , Hovav Shacham , Dean Tullsen , and Deian Stefan . 2021 . Swivel: Hardening WebAssembly against Spectre . In Proceedings of the USENIX Security Symposium (USENIX Security). Shravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi, Evan Johnson, Zhao Gang, Anjo Vahldiek-Oberwagner, Ravi Sahita, Hovav Shacham, Dean Tullsen, and Deian Stefan. 2021. Swivel: Hardening WebAssembly against Spectre. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_54_1","volume-title":"Hardware support for compartmentalisation","author":"Norton Robert M","unstructured":"Robert M Norton . 2016. Hardware support for compartmentalisation . University of Cambridge , Computer Laboratory . Robert M Norton. 2016. Hardware support for compartmentalisation. University of Cambridge, Computer Laboratory."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292040.3219662"},{"key":"e_1_3_2_1_56_1","unstructured":"Warren Pamukoff. 2022. Shopify Functions Unlocks Backend Logic to Help Meet Any Business Need. https:\/\/www.shopify.com\/nz\/partners\/blog\/shopify-functions \t\t\t\t  Warren Pamukoff. 2022. Shopify Functions Unlocks Backend Logic to Help Meet Any Business Need. https:\/\/www.shopify.com\/nz\/partners\/blog\/shopify-functions"},{"key":"e_1_3_2_1_57_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC).","author":"Park Soyeon","year":"2019","unstructured":"Soyeon Park , Sangho Lee , Wen Xu , Hyungon Moon , and Taesoo Kim . 2019 . libmpk: Software Abstraction for Intel Memory Protection Keys (Intel MPK) . In Proceedings of the USENIX Annual Technical Conference (ATC). Soyeon Park, Sangho Lee, Wen Xu, Hyungon Moon, and Taesoo Kim. 2019. libmpk: Software Abstraction for Intel Memory Protection Keys (Intel MPK). In Proceedings of the USENIX Annual Technical Conference (ATC)."},{"key":"e_1_3_2_1_58_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP).","author":"Peng Dinglang","year":"2023","unstructured":"Dinglang Peng , Congyu Liu , Tapti Palit , Pedro Fonseca , Anjo Vahldiek-Oberwagner , and Mona Vij . 2023 . uSWITCH: Fast Kernel Context Isolation with Implicit Context Switches . In Proceedings of the IEEE Symposium on Security and Privacy (SP). Dinglang Peng, Congyu Liu, Tapti Palit, Pedro Fonseca, Anjo Vahldiek-Oberwagner, and Mona Vij. 2023. uSWITCH: Fast Kernel Context Isolation with Implicit Context Switches. In Proceedings of the IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_1_59_1","unstructured":"Istio Project. 2023. WebAssembly in the Istio Proxy (Envoy). https:\/\/istio.io\/latest\/docs\/concepts\/wasm\/ Accessed: 2022-08-10 \t\t\t\t  Istio Project. 2023. WebAssembly in the Istio Proxy (Envoy). https:\/\/istio.io\/latest\/docs\/concepts\/wasm\/ Accessed: 2022-08-10"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCC-SmartCity-DSS.2017.5"},{"key":"e_1_3_2_1_61_1","unstructured":"RedPanda. 2021. Redpanda Wasm engine architecture. https:\/\/redpanda.com\/blog\/wasm-architecture \t\t\t\t  RedPanda. 2021. Redpanda Wasm engine architecture. https:\/\/redpanda.com\/blog\/wasm-architecture"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361067"},{"key":"e_1_3_2_1_63_1","volume-title":"Proc. IEEE, 63","author":"Saltzer Jerome H","year":"1975","unstructured":"Jerome H Saltzer and Michael D Schroeder . 1975 . The protection of information in computer systems . Proc. IEEE, 63 , 9 (1975). Jerome H Saltzer and Michael D Schroeder. 1975. The protection of information in computer systems. Proc. IEEE, 63, 9 (1975)."},{"key":"e_1_3_2_1_64_1","unstructured":"Dylan Schiemann. 2020. Zoom on Web: WebAssembly SIMD WebTransport and WebCodecs. https:\/\/www.infoq.com\/news\/2020\/08\/zoom-web-chrome-apis\/ \t\t\t\t  Dylan Schiemann. 2020. Zoom on Web: WebAssembly SIMD WebTransport and WebCodecs. https:\/\/www.infoq.com\/news\/2020\/08\/zoom-web-chrome-apis\/"},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Schrammel David","year":"2022","unstructured":"David Schrammel , Samuel Weiser , Richard Sadek , and Stefan Mangard . 2022 . Jenny: Securing Syscalls for PKU-based Memory Isolation Systems . In Proceedings of the USENIX Security Symposium (USENIX Security). David Schrammel, Samuel Weiser, Richard Sadek, and Stefan Mangard. 2022. Jenny: Securing Syscalls for PKU-based Memory Isolation Systems. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_66_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Schrammel David","year":"2020","unstructured":"David Schrammel , Samuel Weiser , Stefan Steinegger , Martin Schwarzl , Michael Schwarz , Stefan Mangard , and Daniel Gruss . 2020 . Donky: Domain Keys\u2013Efficient In-Process Isolation for RISC-V and x86 . In Proceedings of the USENIX Security Symposium (USENIX Security). David Schrammel, Samuel Weiser, Stefan Steinegger, Martin Schwarzl, Michael Schwarz, Stefan Mangard, and Daniel Gruss. 2020. Donky: Domain Keys\u2013Efficient In-Process Isolation for RISC-V and x86. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_67_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS).","author":"Schwarzl Martin","year":"2022","unstructured":"Martin Schwarzl , Pietro Borrello , Andreas Kogler , Kenton Varda , Thomas Schuster , Michael Schwarz , and Daniel Gruss . 2022 . Robust and Scalable Process Isolation Against Spectre in the Cloud . In Proceedings of the European Symposium on Research in Computer Security (ESORICS). Martin Schwarzl, Pietro Borrello, Andreas Kogler, Kenton Varda, Thomas Schuster, Michael Schwarz, and Daniel Gruss. 2022. Robust and Scalable Process Isolation Against Spectre in the Cloud. In Proceedings of the European Symposium on Research in Computer Security (ESORICS)."},{"key":"e_1_3_2_1_68_1","unstructured":"Mark Seaborn. 2013. Sandboxing Libraries in Chrome using SFI: zlib Proof-of-Concept. https:\/\/docs.google.com\/presentation\/d\/1RD3bxsBfTZOIfrlq7HzGMsygPHgb61A1eTdelIYOurs\/ \t\t\t\t  Mark Seaborn. 2013. Sandboxing Libraries in Chrome using SFI: zlib Proof-of-Concept. https:\/\/docs.google.com\/presentation\/d\/1RD3bxsBfTZOIfrlq7HzGMsygPHgb61A1eTdelIYOurs\/"},{"key":"e_1_3_2_1_69_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC).","author":"Shillaker Simon","year":"2020","unstructured":"Simon Shillaker and Peter Pietzuch . 2020 . Faasm: Lightweight isolation for efficient stateful serverless computing . In Proceedings of the USENIX Annual Technical Conference (ATC). Simon Shillaker and Peter Pietzuch. 2020. Faasm: Lightweight isolation for efficient stateful serverless computing. In Proceedings of the USENIX Annual Technical Conference (ATC)."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3381052.3381326"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1561\/3300000013"},{"key":"e_1_3_2_1_72_1","unstructured":"2022. CHERI Clang\/LLVM and LLD. https:\/\/www.cl.cam.ac.uk\/research\/security\/ctsrd\/cheri\/cheri-llvm.html \t\t\t\t  2022. CHERI Clang\/LLVM and LLD. https:\/\/www.cl.cam.ac.uk\/research\/security\/ctsrd\/cheri\/cheri-llvm.html"},{"key":"e_1_3_2_1_73_1","unstructured":"2022. CheriBSD. https:\/\/github.com\/CTSRD-CHERI\/cheribsd \t\t\t\t  2022. CheriBSD. https:\/\/github.com\/CTSRD-CHERI\/cheribsd"},{"key":"e_1_3_2_1_74_1","unstructured":"2022. Getting started with IBM i. https:\/\/developer.ibm.com\/articles\/i-newtoibmi\/ \t\t\t\t  2022. Getting started with IBM i. https:\/\/developer.ibm.com\/articles\/i-newtoibmi\/"},{"key":"e_1_3_2_1_75_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Vahldiek-Oberwagner Anjo","year":"2019","unstructured":"Anjo Vahldiek-Oberwagner , Eslam Elnikety , Nuno O Duarte , Michael Sammler , Peter Druschel , and Deepak Garg . 2019 . ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK) . In Proceedings of the USENIX Security Symposium (USENIX Security). Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O Duarte, Michael Sammler, Peter Druschel, and Deepak Garg. 2019. ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK). In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_76_1","unstructured":"Kenton Varda. 2018. WebAssembly on Cloudflare Workers. https:\/\/blog.cloudflare.com\/webassembly-on-cloudflare-workers\/ \t\t\t\t  Kenton Varda. 2018. WebAssembly on Cloudflare Workers. https:\/\/blog.cloudflare.com\/webassembly-on-cloudflare-workers\/"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519560"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_3_2_1_79_1","unstructured":"Evan Wallace. 2017. WebAssembly cut Figma\u2019s load time by 3x. https:\/\/www.figma.com\/blog\/webassembly-cut-figmas-load-time-by-3x\/ \t\t\t\t  Evan Wallace. 2017. WebAssembly cut Figma\u2019s load time by 3x. https:\/\/www.figma.com\/blog\/webassembly-cut-figmas-load-time-by-3x\/"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/3380786.3391398"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519553"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/3352460.3358306"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2019.2914037"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665740"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2018.00042"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.25"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2020.2985359"},{"key":"e_1_3_2_1_88_1","unstructured":"2020. WasmBoxC: Simple Easy and Fast VM-less Sandboxing. https:\/\/kripken.github.io\/blog\/wasm\/2020\/07\/27\/ wasmboxc.html \t\t\t\t  2020. WasmBoxC: Simple Easy and Fast VM-less Sandboxing. https:\/\/kripken.github.io\/blog\/wasm\/2020\/07\/27\/ wasmboxc.html"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660344"}],"event":{"name":"ASPLOS '23: 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 3","location":"Vancouver BC Canada","acronym":"ASPLOS '23","sponsor":["SIGARCH ACM Special Interest Group on Computer Architecture","SIGOPS ACM Special Interest Group on Operating Systems","SIGPLAN ACM Special Interest Group on Programming Languages","SIGBED ACM Special Interest Group on Embedded Systems"]},"container-title":["Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 3"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3582016.3582023","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:44Z","timestamp":1750178804000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3582016.3582023"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,25]]},"references-count":90,"alternative-id":["10.1145\/3582016.3582023","10.1145\/3582016"],"URL":"https:\/\/doi.org\/10.1145\/3582016.3582023","relation":{},"subject":[],"published":{"date-parts":[[2023,3,25]]},"assertion":[{"value":"2023-03-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}