{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T18:10:03Z","timestamp":1755886203775,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,4]],"date-time":"2023-12-04T00:00:00Z","timestamp":1701648000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,4]]},"DOI":"10.1145\/3627106.3627197","type":"proceedings-article","created":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T18:13:22Z","timestamp":1701540802000},"page":"677-690","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["RandCompile: Removing Forensic Gadgets from the Linux Kernel to Combat its Analysis"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8474-6253","authenticated-orcid":false,"given":"Fabian","family":"Franzen","sequence":"first","affiliation":[{"name":"Technical University of Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-8267-1146","authenticated-orcid":false,"given":"Andreas Chris","family":"Wilhelmer","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1093-1282","authenticated-orcid":false,"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,12,4]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44647-8_1"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","unstructured":"Sandeep Bhatkar and R. Sekar. 2008. Data Space Randomization. In Detection of Intrusions and Malware and Vulnerability Assessment Diego Zamboni (Ed.). Springer Berlin Heidelberg 1\u201322. https:\/\/doi.org\/10.1007\/978-3-540-70542-0_1","DOI":"10.1007\/978-3-540-70542-0_1"},{"volume-title":"LogicMem - Github Repository. https:\/\/github.com\/bitsecurerlab\/LogicMem. (Online","year":"2023","key":"e_1_3_2_1_3_1","unstructured":"bitsecurerlab. 2022. LogicMem - Github Repository. https:\/\/github.com\/bitsecurerlab\/LogicMem. (Online; accessed 25-May-2023)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484779"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24174-6_4"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-51966-1_6"},{"key":"e_1_3_2_1_7_1","volume-title":"The Tigress C Obfuscator. https:\/\/tigress.wtf\/index.html. (Online","author":"Collberg Christian","year":"2023","unstructured":"Christian Collberg. 2023. The Tigress C Obfuscator. https:\/\/tigress.wtf\/index.html. (Online; accessed 30-September-2023)."},{"key":"e_1_3_2_1_8_1","unstructured":"Manuel Costa Jean-Philippe Martin and Miguel Castro. 2008. Data Randomization. Technical Report MSR-TR-2008-120. 14 pages. https:\/\/www.microsoft.com\/en-us\/research\/publication\/data-randomization\/"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2016.036"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3488017"},{"key":"e_1_3_2_1_11_1","volume-title":"Secure encrypted virtualization is unsecure. arXiv preprint arXiv:1712.05090","author":"Du Zhao-Hui","year":"2017","unstructured":"Zhao-Hui Du, Zhiwei Ying, Zhenke Ma, Yufei Mai, Phoebe Wang, Jesse Liu, and Jesse Fang. 2017. Secure encrypted virtualization is unsecure. arXiv preprint arXiv:1712.05090 (2017)."},{"key":"e_1_3_2_1_12_1","volume-title":"https:\/\/www.volatilityfoundation.org\/. (Online","author":"Foundation Volatility","year":"2023","unstructured":"Volatility Foundation. 2023. Volatility Framework. https:\/\/www.volatilityfoundation.org\/. (Online; accessed 25-May-2023)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545980"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70936-7_11"},{"key":"e_1_3_2_1_15_1","volume-title":"https:\/\/github.com\/google\/rekall. (Online","author":"Forensics Rekall","year":"2023","unstructured":"Google. 2023. Rekall Forensics. https:\/\/github.com\/google\/rekall. (Online; accessed 25-May-2023)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93411-2_4"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484753"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPRO.2015.10"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2013.129"},{"key":"e_1_3_2_1_20_1","volume-title":"28th USENIX Security Symposium (USENIX Security). USENIX Association, 1257\u20131272","author":"Li Mengyuan","year":"2019","unstructured":"Mengyuan Li, Yinqian Zhang, Zhiqiang Lin, and Yan Solihin. 2019. Exploiting unprotected I\/O operations in AMD\u2019s secure encrypted virtualization. In 28th USENIX Security Symposium (USENIX Security). USENIX Association, 1257\u20131272. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/li-mengyuan"},{"key":"e_1_3_2_1_21_1","unstructured":"GNU Libc. 2013. Pointer Encryption. https:\/\/sourceware.org\/glibc\/wiki\/PointerEncryption."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_7"},{"key":"e_1_3_2_1_23_1","unstructured":"H.\u00a0J. Lu Michael Matz Milind Girkar Jan Hubi\u010dka Andreas Jaeger and Mark Mitchell. 2022. System V Application Binary Interface AMD64 Architecture Processor Supplement (With LP64 and ILP32 Programming Models) Version 1.0. https:\/\/gitlab.com\/x86-psABIs\/x86-64-ABI\/-\/jobs\/artifacts\/master\/raw\/x86-64-ABI\/abi.pdf?job=build"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW54247.2022.9833891"},{"key":"e_1_3_2_1_25_1","volume-title":"Writing kernel exploits. Presentation Slides","author":"McAllister Keegan","year":"2014","unstructured":"Keegan McAllister. 2012. Writing kernel exploits. Presentation Slides. Georgia Institute of Technology. https:\/\/tc.gtisc.gatech.edu\/bss\/2014\/r\/kernel-exploits.pdf"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00063"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23398"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485471"},{"key":"e_1_3_2_1_29_1","volume-title":"Writing a Linux Kernel Remote","author":"Page Samuel","year":"2022","unstructured":"Samuel Page. 2022. Writing a Linux Kernel Remote in 2022. https:\/\/blog.immunityinc.com\/p\/writing-a-linux-kernel-remote-in-2022\/. (Online; accessed 30-September-2023)."},{"key":"e_1_3_2_1_30_1","volume-title":"https:\/\/libvmi.com\/. (Online","author":"Project VMI","year":"2023","unstructured":"LibVMI Project. 2015. LibVMI. https:\/\/libvmi.com\/. (Online; accessed 25-May-2023)."},{"volume-title":"PANDA\u2019s OS-specific introspection plugins. https:\/\/github.com\/panda-re\/panda\/tree\/dev\/panda\/plugins\/osi. (Online","year":"2023","key":"e_1_3_2_1_31_1","unstructured":"Panda.re Project. 2023. PANDA\u2019s OS-specific introspection plugins. https:\/\/github.com\/panda-re\/panda\/tree\/dev\/panda\/plugins\/osi. (Online; accessed 25-May-2023)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24324"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/PCCC.2013.6742768"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2018.04.015"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00064"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC.2016.46"}],"event":{"name":"ACSAC '23: Annual Computer Security Applications Conference","acronym":"ACSAC '23","location":"Austin TX USA"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627197","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627106.3627197","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:36:36Z","timestamp":1755884196000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627197"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,4]]},"references-count":36,"alternative-id":["10.1145\/3627106.3627197","10.1145\/3627106"],"URL":"https:\/\/doi.org\/10.1145\/3627106.3627197","relation":{},"subject":[],"published":{"date-parts":[[2023,12,4]]},"assertion":[{"value":"2023-12-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}