{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T19:23:23Z","timestamp":1781724203983,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the Fundamental Research Funds for the Central Universities","award":["2023QN1078"],"award-info":[{"award-number":["2023QN1078"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3670269","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"4584-4597","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Isolate and Detect the Untrusted Driver with a Virtual Box"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3289-0330","authenticated-orcid":false,"given":"YongGang","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, China University of Mining and Technology &amp; Mine Digitization Engineering Research Center of the Ministry of Education, Xuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2823-1794","authenticated-orcid":false,"given":"ShunRong","family":"Jiang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, China University of Mining and Technology &amp; Mine Digitization Engineering Research Center of the Ministry of Education, Xuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5276-7532","authenticated-orcid":false,"given":"Yu","family":"Bao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, China University of Mining and Technology &amp; Mine Digitization Engineering Research Center of the Ministry of Education, Xuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6595-1451","authenticated-orcid":false,"given":"PengPeng","family":"Chen","sequence":"additional","affiliation":[{"name":"The China University of Mining School of Computer Science and Technology, China University of Mining and TechnologyTechnology &amp; Mine Digitization Engineering Research Center of the Ministry of Education, Xuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6207-0299","authenticated-orcid":false,"given":"Yong","family":"Zhou","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, China University of Mining and Technology &amp; Mine Digitization Engineering Research Center of the Ministry of Education, xuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8704-9821","authenticated-orcid":false,"given":"Yeh-Ching","family":"Chung","sequence":"additional","affiliation":[{"name":"Chinese University of Hong Kong, Shenzhen, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 27th USENIX Security Symposium. 1213--1227","author":"Davi L","unstructured":"Davi L et al Biondo A, Conti M. 2018. The Guards Dilemma: Efficient Code-Reuse Attacks Against Intel SGX. In Proceedings of the 27th USENIX Security Symposium. 1213--1227."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.22"},{"key":"e_1_3_2_1_4_1","volume-title":"Pre-built JOP Chains with the JOP ROCKET: Bypassing DEP without ROP. Black Hat Asia","author":"Brizendine Bramwell","year":"2021","unstructured":"Bramwell Brizendine and Austin Babcock. 2021. Pre-built JOP Chains with the JOP ROCKET: Bypassing DEP without ROP. Black Hat Asia (2021)."},{"key":"e_1_3_2_1_5_1","volume-title":"Pruett M.","author":"Bigelow R","year":"2021","unstructured":"Bigelow R et al Brown M D, Pruett M. 2021. Not so fast: understanding and mitigating negative impacts of compiler optimizations on code reuse gadget sets. In Proceedings of the ACM on Programming Languages. 1--30."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 15th ACM Asia Conference on Computer and Communications Security. 481--493","author":"Haubenwallner M","unstructured":"Haubenwallner M et al. Canella C, Schwarz M. 2020. KASLR: Break it, fix it, repeat. In Proceedings of the 15th ACM Asia Conference on Computer and Communications Security. 481--493."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.24"},{"key":"e_1_3_2_1_8_1","first-page":"26","article-title":"ASLR on the Line: Practical Cache Attacks on the MMU","volume":"17","author":"Gras Ben","year":"2017","unstructured":"Ben Gras, Kaveh Razavi, Erik Bosman, Herbert Bos, and Cristiano Giuffrida. 2017. ASLR on the Line: Practical Cache Attacks on the MMU.. In NDSS, Vol. 17. 26.","journal-title":"NDSS"},{"key":"e_1_3_2_1_9_1","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC 20)","author":"Gu Jinyu","year":"2020","unstructured":"Jinyu Gu, Xinyue Wu, Wentai Li, Nian Liu, Zeyu Mi, Yubin Xia, and Haibo Chen. 2020. Harmonizing performance and isolation in microkernels with efficient intra-kernel isolation and communication. In 2020 USENIX Annual Technical Conference (USENIX ATC 20). 401--417."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the 23rd USENIX Security Symposium. 417--432","author":"Polychronakis M","unstructured":"Polychronakis M et al. G\u00f6ktas E, Athanasopoulos E. 2014. Size Does Matter: Why Using Gadget-Chain Length to Prevent Code-Reuse Attacks is Hard. In Proceedings of the 23rd USENIX Security Symposium. 417--432."},{"key":"e_1_3_2_1_11_1","volume-title":"Artificial Intelligence Techniques for Advanced Computing Applications: Proceedings of ICACT","author":"Harini C.","year":"2020","unstructured":"C. Harini and C. Fancy. 2020. A study on the prevention mechanisms for kernel attacks. In Artificial Intelligence Techniques for Advanced Computing Applications: Proceedings of ICACT 2020. Springer, 11--17."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the Seventeenth European Conference on Computer Systems. 149--165","author":"Williams D","year":"2022","unstructured":"Williams D Holmes B, Waterman J. 2022. KASLR in the age of MicroVMs. In Proceedings of the Seventeenth European Conference on Computer Systems. 149--165."},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22)","author":"Detweiler D","unstructured":"Detweiler D et al Huang Y, Narayanan V. 2022. KSplit: Automating Device Driver Isolation. In Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22). 613--631."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3383669.3398280"},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 1709--1723","author":"Gro\u00df S","unstructured":"Gro\u00df S et al. Lekies S, Kotowicz K. 2017. Code-reuse attacks for the web: Breaking cross-site scripting mitigations via script gadgets. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 1709--1723."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2797932"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567967"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2022.10.035"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2020.3022023"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813690"},{"key":"e_1_3_2_1_21_1","unstructured":"Kangjie Lu Wenke Lee Stefan N\u00fcrnberger and Michael Backes. 2016. How to Make ASLR Win the Clone Wars: Runtime Re-Randomization.. In NDSS."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043568"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833675"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSC54232.2022.9888796"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the 2019 USENIX Annual Technical Conference (USENIX ATC 19)","author":"Jacobsen C","unstructured":"Jacobsen C et al Narayanan V, Balasubramanian A. 2019. LXDs: Towards isolation of kernel subsystems. In Proceedings of the 2019 USENIX Annual Technical Conference (USENIX ATC 19). 269--284."},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the 16th ACM SIGPLAN\/SIGOPS international conference on virtual execution environments. 157--171","author":"Tan G","unstructured":"Tan G et al Narayanan V, Huang Y. 2020. Lightweight kernel isolation with virtualization and VM functions. In Proceedings of the 16th ACM SIGPLAN\/SIGOPS international conference on virtual execution environments. 157--171."},{"key":"e_1_3_2_1_27_1","volume-title":"DIMVA 2019, Gothenburg, Sweden, June 19--20, 2019, Proceedings 16","author":"Neugschwandtner Matthias","year":"2019","unstructured":"Matthias Neugschwandtner, Alessandro Sorniotti, and Anil Kurmus. 2019. Memory categorization: Separating attacker-controlled data. In Detection of Intrusions and Malware, and Vulnerability Assessment: 16th International Conference, DIMVA 2019, Gothenburg, Sweden, June 19--20, 2019, Proceedings 16. Springer, 263--287."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503222.3507779"},{"key":"e_1_3_2_1_29_1","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Oikonomopoulos Angelos","year":"2016","unstructured":"Angelos Oikonomopoulos, Elias Athanasopoulos, Herbert Bos, and Cristiano Giuffrida. 2016. Poking holes in information hiding. In 25th USENIX Security Symposium (USENIX Security 16). 121--138."},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of the Twelfth European Conference on Computer Systems. 420--436","year":"2017","unstructured":"et al Pomonis, Marios. 2017. kR ?X: Comprehensive kernel protection against just-in-time code reuse. In Proceedings of the Twelfth European Conference on Computer Systems. 420--436."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17146-8_26"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2022.06.033"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.45"},{"key":"e_1_3_2_1_34_1","unstructured":"Abhinav Srivastava and Jonathon T Giffin. 2011. Efficient Monitoring of Untrusted Kernel-Mode Execution.. In NDSS. Citeseer."},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP). 934--953","author":"G\u00f6ktas E.","unstructured":"G\u00f6ktas E. et al Van Der Veen, V. 2016. A tough call: Mitigating advanced code-reuse attacks at the binary level. In Proceedings of the IEEE Symposium on Security and Privacy (SP). 934--953."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2019.11.008"},{"key":"e_1_3_2_1_37_1","first-page":"1607","article-title":"CRAlert: Hardware-assisted code reuse attack detection","volume":"69","author":"Wang Wenhao","year":"2021","unstructured":"Wenhao Wang, Guangyu Hu, Xiaolin Xu, and Jiliang Zhang. 2021. CRAlert: Hardware-assisted code reuse attack detection. IEEE Transactions on Circuits and Systems II: Express Briefs 69, 3 (2021), 1607--1611.","journal-title":"IEEE Transactions on Circuits and Systems II: Express Briefs"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3050748.3050752"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 16th ACM conference on Computer and communications security. 545--554","author":"Cui W","unstructured":"Cui W et al Wang Z, Jiang X. 2009. Countering kernel rootkits with lightweight hook protection. In Proceedings of the 16th ACM conference on Computer and communications security. 545--554."},{"key":"e_1_3_2_1_40_1","volume-title":"PointerScope: Understanding Pointer Patching for Code Randomization","author":"Xie Mengfei","year":"2022","unstructured":"Mengfei Xie, Yan Lin, Chenke Luo, Guojun Peng, and Jianming Fu. 2022. PointerScope: Understanding Pointer Patching for Code Randomization. IEEE Transactions on Dependable and Secure Computing (2022)."},{"key":"e_1_3_2_1_41_1","volume-title":"ARM pointer authentication based forward-edge and backward-edge control flow integrity for kernels. arXiv preprint arXiv:1912.10666","author":"Yang Yutian","year":"2019","unstructured":"Yutian Yang, Songbo Zhu, Wenbo Shen, Yajin Zhou, Jiadong Sun, and Kui Ren. 2019. ARM pointer authentication based forward-edge and backward-edge control flow integrity for kernels. arXiv preprint arXiv:1912.10666 (2019)."},{"key":"e_1_3_2_1_42_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Yoo Sungbae","year":"2022","unstructured":"Sungbae Yoo, Jinbum Park, Seolheui Kim, Yeji Kim, and Taesoo Kim. 2022. In-Kernel Control-Flow Integrity on Commodity OSes using ARM Pointer Authentication. In 31st USENIX Security Symposium (USENIX Security 22). 89--106."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3494516"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670269","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3670269","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:12:15Z","timestamp":1755843135000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670269"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":43,"alternative-id":["10.1145\/3658644.3670269","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3670269","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}