{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:38:40Z","timestamp":1784342320464,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":114,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372218"],"award-info":[{"award-number":["62372218"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006374","name":"National Research Foundation Singapore","doi-asserted-by":"publisher","award":["Industry Alignment Fund ? Pre-positioning (IAF-PP) Funding Initiative"],"award-info":[{"award-number":["Industry Alignment Fund ? Pre-positioning (IAF-PP) Funding Initiative"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006374","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-24-1-0204"],"award-info":[{"award-number":["FA9550-24-1-0204"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690188","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"3898-3912","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission Switches"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-3550-696X","authenticated-orcid":false,"given":"Chuqi","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computing, National University of Singapore, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3471-9504","authenticated-orcid":false,"given":"Jun","family":"Zeng","sequence":"additional","affiliation":[{"name":"Independent Researcher, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4247-5202","authenticated-orcid":false,"given":"Yiming","family":"Zhang","sequence":"additional","affiliation":[{"name":"Southern University of Science and Technology &amp; The Hong Kong Polytechnic University, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4097-3205","authenticated-orcid":false,"given":"Adil","family":"Ahmad","sequence":"additional","affiliation":[{"name":"School of Computing and Augmented Intelligence, Arizona State University, Tempe, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3365-2526","authenticated-orcid":false,"given":"Fengwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Southern University of Science and Technology, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3934-7605","authenticated-orcid":false,"given":"Hai","family":"Jin","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7138-5030","authenticated-orcid":false,"given":"Zhenkai","family":"Liang","sequence":"additional","affiliation":[{"name":"School of Computing, National University of Singapore, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"The apache software foundation \"ab - apache http server benchmark tool\". https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html."},{"key":"e_1_3_2_1_2_1","unstructured":"Aqua tracee \"tracee: Linux runtime security and forensics using ebpf\". https:\/\/github.com\/aquasecurity\/tracee."},{"key":"e_1_3_2_1_3_1","unstructured":"Arm architecture reference manual for a-profile architecture. https:\/\/developer.arm.com\/documentation\/ddi0487\/latest\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Arm corelink tzc-400 trustzone address space controller. https:\/\/developer.arm.com\/documentation\/ddi0504\/c."},{"key":"e_1_3_2_1_5_1","unstructured":"Arm system memory management unit architecture specification smmu architecture version 3. https:\/\/developer.arm.com\/documentation\/ihi0070\/latest\/."},{"key":"e_1_3_2_1_6_1","unstructured":"Confidential computing: Hardware-based trusted execution for applications and data. https:\/\/confidentialcomputing.io\/wp-content\/uploads\/sites\/10\/2023\/03\/CCC_outreach_whitepaper_updated_November_2022.pdf."},{"key":"e_1_3_2_1_7_1","unstructured":"\"d5.3 vmsav8--64 translation table format descriptors\" -- arm architecture reference manual for a-profile architecture. https:\/\/developer.arm.com\/documentation\/ddi0487\/latest\/."},{"key":"e_1_3_2_1_8_1","unstructured":"Different types of logs in siem and their log formats. https:\/\/www.manageengine.com\/log-management\/siem\/collecting-and-analysing-different-log-types.html."},{"key":"e_1_3_2_1_9_1","unstructured":"Dynamically program the kernel for efficient networking observability tracing and security. https:\/\/ebpf.io\/."},{"key":"e_1_3_2_1_10_1","unstructured":"Getting started with intel\u00ae active management technology. https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/guide\/getting-started-with-active-management-technology.html."},{"key":"e_1_3_2_1_11_1","unstructured":"Global incident response threat report. https:\/\/www.vmware.com\/content\/dam\/digitalmarketing\/vmware\/en\/pdf\/docs\/vmwcb-report-the-ominous-rise-of-island-hopping-and-counter-incident-response-continues.pdf."},{"key":"e_1_3_2_1_12_1","unstructured":"Hackers are increasingly destroying logs to hide attacks. https:\/\/www.zdnet.com\/article\/hackers-are-increasingly-destroying-logs-to-hide-attacks\/."},{"key":"e_1_3_2_1_13_1","unstructured":"HitchHiker artifact. https:\/\/github.com\/ASTERISC-Release\/HitchHiker."},{"key":"e_1_3_2_1_14_1","unstructured":"How to view kernel messages in linux | dmesg command. https:\/\/www.geeksforgeeks.org\/how-to-use-the-dmesg-command-on-linux\/."},{"key":"e_1_3_2_1_15_1","unstructured":"Indicator removal: Clear linux or mac system logs. https:\/\/attack.mitre.org\/techniques\/T1070\/002\/."},{"key":"e_1_3_2_1_16_1","unstructured":"Interrupt management framework. https:\/\/trustedfirmware-a.readthedocs.io\/en\/latest\/design\/interrupt-framework-design.html."},{"key":"e_1_3_2_1_17_1","unstructured":"Learn the architecture - realm management extension \"impact on translation lookaside buffers and caches\". https:\/\/developer.arm.com\/documentation\/den0126\/0100\/Physical-Addresses."},{"key":"e_1_3_2_1_18_1","unstructured":"libbpf. https:\/\/docs.kernel.org\/bpf\/libbpf\/index.html."},{"key":"e_1_3_2_1_19_1","unstructured":"memcpy_s.c \"arm-trusted-firmware\". https:\/\/github.com\/ARM-software\/arm-trusted-firmware\/blob\/master\/lib\/libc\/memcpy_s.c."},{"key":"e_1_3_2_1_20_1","unstructured":"memtier-benchmark. https:\/\/github.com\/RedisLabs\/memtier_benchmark."},{"key":"e_1_3_2_1_21_1","unstructured":"Observability in security. https:\/\/techblog.cisco.com\/blog\/observability-in-security."},{"key":"e_1_3_2_1_22_1","unstructured":"Op-tee. https:\/\/www.op-tee.org\/."},{"key":"e_1_3_2_1_23_1","unstructured":"Overlayfs ? privilege escalation. https:\/\/systemweakness.com\/cve-2021--3493-overlayfs-privilege-escalation-51ba49c3255c."},{"key":"e_1_3_2_1_24_1","unstructured":"Sata sil24. https:\/\/archive.kernel.org\/oldwiki\/ata.wiki.kernel.org\/index.php\/Sata_sil24.html."},{"key":"e_1_3_2_1_25_1","unstructured":"Secure monitor calling convention. https:\/\/developer.arm.com\/Architectures\/SMCCC."},{"key":"e_1_3_2_1_26_1","unstructured":"Shadow stacks for 64-bit arm systems. https:\/\/lwn.net\/SubscriberLink\/940403\/c4561635ec6d8881\/."},{"key":"e_1_3_2_1_27_1","unstructured":"sysbench \"scriptable database and system performance benchmark\". https:\/\/github.com\/akopytov\/sysbench."},{"key":"e_1_3_2_1_28_1","unstructured":"Uefi specification -- \"runtime services\". https:\/\/uefi.org\/specs\/UEFI\/2.10\/08_Services_Runtime_Services.html."},{"key":"e_1_3_2_1_29_1","unstructured":"Understanding detecting & preventing modern linux rootkits. https:\/\/blog.securityinnovation.com\/modern-linux-rootkits."},{"key":"e_1_3_2_1_30_1","unstructured":"Understanding linux audit. https:\/\/documentation.suse.com\/sles\/12-SP4\/html\/SLES-all\/cha-audit-comp.html."},{"key":"e_1_3_2_1_31_1","unstructured":"Virtualization-based security (vbs). https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/design\/device-experiences\/oem-vbs."},{"key":"e_1_3_2_1_32_1","unstructured":"What is common vulnerability scoring system (cvss). https:\/\/www.sans.org\/blog\/what-is-cvss\/."},{"key":"e_1_3_2_1_33_1","unstructured":"Xen project. https:\/\/xenproject.org\/."},{"key":"e_1_3_2_1_34_1","unstructured":"'pulling back the curtain' -- rootkit detection and removal. https:\/\/securenetworkers.com\/2019\/07\/31\/pulling-back-the-curtain-rootkit-detection-and-removal\/."},{"key":"e_1_3_2_1_35_1","volume-title":"arm confidential compute architecture. https:\/\/www.arm.com\/architecture\/security-features\/arm-confidential-compute-architecture","year":"2021","unstructured":"Arm. arm confidential compute architecture. https:\/\/www.arm.com\/architecture\/security-features\/arm-confidential-compute-architecture, 2021."},{"key":"e_1_3_2_1_36_1","volume-title":"for armv9-a. https:\/\/developer.arm.com\/documentation\/ddi0615\/latest","author":"The","year":"2021","unstructured":"The realm management extension (rme), for armv9-a. https:\/\/developer.arm.com\/documentation\/ddi0615\/latest, 2021."},{"key":"e_1_3_2_1_37_1","volume-title":"https:\/\/git.trustedfirmware.org\/TF-A\/trusted-firmware-a.git","year":"2022","unstructured":"Trusted-firmware-a. https:\/\/git.trustedfirmware.org\/TF-A\/trusted-firmware-a.git, 2022."},{"key":"e_1_3_2_1_38_1","volume-title":"CCS","author":"Abera Tigist","year":"2016","unstructured":"Tigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg, Thomas Nyman, Andrew Paverd, Ahmad-Reza Sadeghi, and Gene Tsudik. C-flat: Control-flow attestation for embedded systems software. In CCS, 2016."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833745"},{"key":"e_1_3_2_1_40_1","volume-title":"ASPLOS","author":"Ahmad Adil","year":"2024","unstructured":"Adil Ahmad, Botong Ou, and Congyu Liu et al. Veil: A protected services framework for confidential virtual machines. In ASPLOS, 2024."},{"key":"e_1_3_2_1_41_1","volume-title":"OSDI","author":"Ahmad Adil","year":"2023","unstructured":"Adil Ahmad, Alex Schultz, Byoungyoung Lee, and Pedro Fonseca. An extensible orchestration and protection framework for confidential cloud computing. In OSDI, 2023."},{"key":"e_1_3_2_1_42_1","volume-title":"OSDI","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark L. Stillwell, David Goltzsche, Dave Eyers, R\u00fcdiger Kapitza, Peter Pietzuch, and Christof Fetzer. SCONE: Secure linux containers with intel SGX. In OSDI, 2016."},{"key":"e_1_3_2_1_43_1","volume-title":"WWW","author":"Bates Adam","year":"2017","unstructured":"Adam Bates, Wajih Ul Hassan, Kevin Butler, Alin Dobra, Bradley Reaves, Patrick Cable, Thomas Moyer, and Nabil Schear. Transparent web service auditing via network provenance functions. In WWW, 2017."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11379-1_3"},{"key":"e_1_3_2_1_45_1","volume-title":"NDSS","author":"Brasser Ferdinand","year":"2019","unstructured":"Ferdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi, and Emmanuel Stapf. Sanctuary: Arming trustzone with user-space enclaves. In NDSS, 2019."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2906388.2906390"},{"key":"e_1_3_2_1_47_1","volume-title":"USENIX Security","author":"Cerdeira David","year":"2022","unstructured":"David Cerdeira, Jos\u00e9 Martins, Nuno Santos, and Sandro Pinto. ReZone: Disarming TrustZone with TEE privilege reduction. In USENIX Security, 2022."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00061"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451145"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/2103799.2103805"},{"key":"e_1_3_2_1_51_1","volume-title":"OSDI","author":"Chen Jiahao","year":"2023","unstructured":"Jiahao Chen, Dingji Li, Zeyu Mi, et al. Security and performance in the delegated user-level virtualization. In OSDI, 2023."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346281.1346284"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338916"},{"key":"e_1_3_2_1_54_1","volume-title":"Security","author":"Datta Pubali","year":"2022","unstructured":"Pubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates, and William Enck. ALASTOR: Reconstructing the provenance of serverless intrusions. In Security, 2022."},{"key":"e_1_3_2_1_55_1","volume-title":"CCS","author":"Du Min","year":"2017","unstructured":"Min Du, Feifei Li, Guineng Zheng, and Vivek Srikumar. Deeplog: Anomaly detection and diagnosis from system logs through deep learning. In CCS, 2017."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060289.1060309"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2016.7783743"},{"key":"e_1_3_2_1_58_1","volume-title":"OSDI","author":"Feng Erhu","year":"2021","unstructured":"Erhu Feng, Xu Lu, Dong Du, et al. Scalable memory protection in the PENGLAI enclave. In OSDI, 2021."},{"key":"e_1_3_2_1_59_1","volume-title":"NSDI","author":"Fonseca Rodrigo","year":"2007","unstructured":"Rodrigo Fonseca, George Porter, Randy H. Katz, Scott Shenker, and Ion Stoica. X-trace: A pervasive network tracing framework. In NSDI, 2007."},{"key":"e_1_3_2_1_60_1","volume-title":"CCS","author":"Fu Chuanpu","year":"2021","unstructured":"Chuanpu Fu, Qi Li, Meng Shen, and Ke Xu. Realtime robust malicious traffic detection via frequency domain analysis. In CCS, 2021."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545983"},{"key":"e_1_3_2_1_62_1","volume-title":"Security","author":"Gandhi Varun","year":"2023","unstructured":"Varun Gandhi, Sarbartha Banerjee, Aniket Agarwal, Adil Ahmed, Sangho Lee, and Marcus Peinado. Rethinking system audit architectures for high event coverage and synchronous log availability. In Security, 2023."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519565"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23041"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24046"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24270"},{"key":"e_1_3_2_1_67_1","volume-title":"ACM Comput. Surv.","author":"He Shilin","year":"2021","unstructured":"Shilin He, Pinjia He, Zhuangbin Chen, Tianyi Yang, Yuxin Su, and Michael R. Lyu. A survey on automated log analysis for reliability engineering. ACM Comput. Surv., 2021."},{"key":"e_1_3_2_1_68_1","volume-title":"Security","author":"Hoang Viet Tung","year":"2022","unstructured":"Viet Tung Hoang, Cong Wu, and Xin Yuan. Faster yet safer: Logging system via Fixed-Key blockcipher. In Security, 2022."},{"key":"e_1_3_2_1_69_1","volume-title":"OSDI","author":"Hof Alexander Van't","year":"2022","unstructured":"Alexander Van't Hof and Jason Nieh. BlackBox: A container security monitor for protecting containers on untrusted operating systems. In OSDI, 2022."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451146"},{"key":"e_1_3_2_1_71_1","volume-title":"USENIX Security","author":"Hua Zhichao","year":"2017","unstructured":"Zhichao Hua, Jinyu Gu, Yubin Xia, Haibo Chen, Binyu Zang, and Haibing Guan. vTZ: Virtualizing ARM TrustZone. In USENIX Security, 2017."},{"key":"e_1_3_2_1_72_1","volume-title":"S&P","author":"Inam M.","year":"2023","unstructured":"M. Inam, Y. Chen, A. Goyal, J. Liu, J. Mink, N. Michael, S. Gaur, A. Bates, and W. Ul Hassan. Sok: History is a vast early warning system: Auditing the provenance of system intrusions. In S&P, 2023."},{"key":"e_1_3_2_1_73_1","volume-title":"AsiaCCS","author":"Karande Vishal","year":"2017","unstructured":"Vishal Karande, Erick Bauman, Zhiqiang Lin, and Latifur Khan. Sgx-log: Securing system logs with sgx. In AsiaCCS, 2017."},{"key":"e_1_3_2_1_74_1","unstructured":"Max Kellermann. The dirty pipe vulnerability. https:\/\/dirtypipe.cm4all.com\/."},{"key":"e_1_3_2_1_75_1","volume-title":"SOSP","author":"Samuel","year":"2003","unstructured":"Samuel T. King and Peter M. Chen. Backtracking intrusions. In SOSP, 2003."},{"key":"e_1_3_2_1_76_1","volume-title":"EuroSys","author":"Krahn Robert","year":"2018","unstructured":"Robert Krahn, Bohdan Trach, Anjo Vahldiek-Oberwagner, Thomas Knauth, Pramod Bhatotia, and Christof Fetzer. Pesos: Policy enhanced secure object store. In EuroSys, 2018."},{"key":"e_1_3_2_1_77_1","volume-title":"USENIX Security","author":"Lee Yoochan","year":"2021","unstructured":"Yoochan Lee, Changwoo Min, and Byoungyoung Lee. ExpRace: Exploiting kernel races through raising interrupts. In USENIX Security, 2021."},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-021-10063-9"},{"key":"e_1_3_2_1_79_1","volume-title":"SOSP","author":"Li Dingji","year":"2021","unstructured":"Dingji Li, Zeyu Mi, Yubin Xia, et al. Twinvisor: Hardware-isolated confidential virtual machines for arm. In SOSP, 2021."},{"key":"e_1_3_2_1_80_1","volume-title":"ISCA","author":"Li Mingyu","year":"2021","unstructured":"Mingyu Li, Yubin Xia, and Haibo Chen. Confidential serverless made efficient with plug-in enclaves. In ISCA, 2021."},{"key":"e_1_3_2_1_81_1","volume-title":"OSDI","author":"Li Xupeng","year":"2022","unstructured":"Xupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu, Jason Nieh, Yousuf Sait, and Gareth Stockwell. Design and verification of the arm confidential compute architecture. In OSDI, 2022."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472883.3486976"},{"key":"e_1_3_2_1_83_1","volume-title":"CCS","author":"Lin Zhenpeng","year":"2022","unstructured":"Zhenpeng Lin, Yuhang Wu, and Xinyu Xing. Dirtycred: Escalating privilege in linux kernel. In CCS, 2022."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/3620666.3651387"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"e_1_3_2_1_86_1","volume-title":"ATC","author":"McVoy Larry","year":"1996","unstructured":"Larry McVoy and Carl Staelin. lmbench: Portable tools for performance analysis. In ATC, 1996."},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103119"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24065"},{"key":"e_1_3_2_1_89_1","volume-title":"CCS","author":"Paccagnella Riccardo","year":"2020","unstructured":"Riccardo Paccagnella, Kevin Liao, Dave Tian, and Adam Bates. Logging to the danger zone: Race condition attacks and defenses on system audit frameworks. In CCS, 2020."},{"key":"e_1_3_2_1_90_1","volume-title":"ATC","author":"Park Heejin","year":"2019","unstructured":"Heejin Park, Shuang Zhai, Long Lu, and Felix Xiaozhu Lin. StreamBox-TZ: Secure stream analytics at the edge with TrustZone. In ATC, 2019."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"e_1_3_2_1_92_1","volume-title":"CCS","author":"Pasquier Thomas","year":"2018","unstructured":"Thomas Pasquier, Xueyuan Han, Thomas Moyer, et al. Runtime analysis of whole-system provenance. In CCS, 2018."},{"key":"e_1_3_2_1_93_1","volume-title":"Linux Symposium","author":"Qumranet Avi","year":"2007","unstructured":"Avi Qumranet, Yaniv Qumranet, Dor Qumranet, Uri Qumranet, and Anthony Liguori. Kvm: The linux virtual machine monitor. Linux Symposium, 2007."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541949"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00087"},{"key":"e_1_3_2_1_96_1","volume-title":"ASPLOS","author":"Shen Zhiming","year":"2019","unstructured":"Zhiming Shen, Zhen Sun, Gur-Eyal Sela, et al. X-containers: Breaking down barriers to improve performance and isolation of cloud-native containers. In ASPLOS, 2019."},{"key":"e_1_3_2_1_97_1","volume-title":"WISTP","author":"Shepherd Carlton","year":"2017","unstructured":"Carlton Shepherd, Raja Naeem Akram, and Konstantinos Markantonakis. Em-Log: Tamper-Resistant System Logging for Constrained Devices with TEEs. In WISTP, 2017."},{"key":"e_1_3_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23455"},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23500"},{"key":"e_1_3_2_1_100_1","volume-title":"Acai: Extending arm confidential computing architecture protection from cpus to accelerators","author":"Sridhara Supraja","year":"2023","unstructured":"Supraja Sridhara, Andrin Bertschi, Benedict Schl\u00fcter, Mark Kuhne, Fabio Aliberti, and Shweta Shinde. Acai: Extending arm confidential computing architecture protection from cpus to accelerators, 2023."},{"key":"e_1_3_2_1_101_1","volume-title":"Security","author":"Ujcich Benjamin E.","year":"2021","unstructured":"Benjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates, William H. Sanders, and Hamed Okhravi. Causal analysis for Software-Defined networking attacks. In Security, 2021."},{"key":"e_1_3_2_1_102_1","volume-title":"EuroSys","author":"Vahldiek-Oberwagner Anjo","year":"2015","unstructured":"Anjo Vahldiek-Oberwagner, Eslam Elnikety, Aastha Mehta, Deepak Garg, Peter Druschel, Rodrigo Rodrigues, Johannes Gehrke, and Ansley Post. Guardat: Enforcing data policies at the storage layer. In EuroSys, 2015."},{"key":"e_1_3_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274751"},{"key":"e_1_3_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833604"},{"key":"e_1_3_2_1_105_1","volume-title":"S&P","author":"Xu Zhiqiang","year":"2022","unstructured":"Zhiqiang Xu, Pengcheng Fang, Changlin Liu, et al. Depcomm: Graph summarization on system audit logs for attack investigation. In S&P, 2022."},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24445"},{"key":"e_1_3_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541968"},{"key":"e_1_3_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833669"},{"key":"e_1_3_2_1_109_1","volume-title":"CCS","author":"Zeng Jun","year":"2022","unstructured":"Jun Zeng, Chuqi Zhang, and Zhenkai Liang. Palantir: Optimizing attack provenance with hardware-enhanced system observability. In CCS, 2022."},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2409.04484"},{"key":"e_1_3_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338931"},{"key":"e_1_3_2_1_112_1","first-page":"23","author":"Zhang Yiming","year":"2023","unstructured":"Yiming Zhang, Yuxin Hu, Zhenyu Ning, Fengwei Zhang, et al. SHELTER: Extending arm CCA with isolation in user space. In USENIX Security 23, 2023.","journal-title":"USENIX Security"},{"key":"e_1_3_2_1_113_1","volume-title":"USENIX Security","author":"Zhao Shixuan","year":"2023","unstructured":"Shixuan Zhao, Pinshen Xu, Guoxing Chen, et al. Reusable enclaves for confidential serverless computing. In USENIX Security, 2023."},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043584"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690188","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690188","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:56:22Z","timestamp":1755842182000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690188"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":114,"alternative-id":["10.1145\/3658644.3690188","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690188","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}