{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T16:11:03Z","timestamp":1784823063203,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,30]],"date-time":"2024-07-30T00:00:00Z","timestamp":1722297600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7,30]]},"DOI":"10.1145\/3664476.3671410","type":"proceedings-article","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T12:35:50Z","timestamp":1721910950000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["SOVEREIGN - Towards a Holistic Approach to Critical Infrastructure Protection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1200-1508","authenticated-orcid":false,"given":"Georg","family":"Becker","sequence":"first","affiliation":[{"name":"DCSO GmbH, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1116-6973","authenticated-orcid":false,"given":"Thomas","family":"Eisenbarth","sequence":"additional","affiliation":[{"name":"Universit\u00e4t zu L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-4595-3604","authenticated-orcid":false,"given":"Hannes","family":"Federrath","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6254-8288","authenticated-orcid":false,"given":"Mathias","family":"Fischer","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-6243-1623","authenticated-orcid":false,"given":"Nils","family":"Loose","sequence":"additional","affiliation":[{"name":"Universit\u00e4t zu L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9415-3969","authenticated-orcid":false,"given":"Simon","family":"Ott","sequence":"additional","affiliation":[{"name":"Fraunhofer AISEC, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4836-1775","authenticated-orcid":false,"given":"Joana","family":"Pecholt","sequence":"additional","affiliation":[{"name":"Fraunhofer AISEC, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7311-8742","authenticated-orcid":false,"given":"Stephan","family":"Marwedel","sequence":"additional","affiliation":[{"name":"Airbus Commercial Aircraft, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6948-9858","authenticated-orcid":false,"given":"Dominik","family":"Meyer","sequence":"additional","affiliation":[{"name":"Helmut Schmidt Universit\u00e4t, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6819-3738","authenticated-orcid":false,"given":"Jan","family":"Stijohann","sequence":"additional","affiliation":[{"name":"Langlauf Security Automation, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6702-1514","authenticated-orcid":false,"given":"Anum","family":"Talpur","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-4483-1679","authenticated-orcid":false,"given":"Matthias","family":"Vallentin","sequence":"additional","affiliation":[{"name":"Tenzir GmbH, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,7,30]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"AMD. 2020. SEV-SNP: Strengthening VM Isolation with Integrity Protection and more. White Paper."},{"key":"e_1_3_2_1_2_1","volume-title":"12th USENIX Symposium on Operating Systems Design and Implementation. 689\u2013703","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O\u2019keeffe, Mark\u00a0L Stillwell, 2016. SCONE: Secure linux containers with intel SGX. In 12th USENIX Symposium on Operating Systems Design and Implementation. 689\u2013703."},{"key":"e_1_3_2_1_3_1","unstructured":"Pradipta Banerjee Christophe de Dinechin Ariel Adam Jochen Schroder and Martin Tessun. 2022. What is the Confidential Containers project?https:\/\/www.redhat.com\/en\/blog\/what-confidential-containers-project"},{"key":"e_1_3_2_1_4_1","volume-title":"Trusted Container Extensions for Container-based Confidential Computing. arXiv preprint arXiv:2205.05747","author":"Brasser Ferdinand","year":"2022","unstructured":"Ferdinand Brasser, Patrick Jauernig, Frederik Pustelnik, Ahmad-Reza Sadeghi, and Emmanuel Stapf. 2022. Trusted Container Extensions for Container-based Confidential Computing. arXiv preprint arXiv:2205.05747 (2022)."},{"key":"e_1_3_2_1_5_1","unstructured":"Pascal Brueckner Amr Osman Mathias Fischer and Thorsten Strufe. 2019. Sandnet: Towards High Quality of Deception in Container-based Microservice Architectures. In International Conference on Communications (ICC) - Communications and Information Systems Security Symposium (CISS). IEEE."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3054924"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00076"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3087402"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3436877"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2019.100055"},{"key":"e_1_3_2_1_11_1","unstructured":"EUROCAE WG-72. 2018. ED-203A \u2013 Airworthiness Security Methods and Considerations. Technical Report. European Organization for Civil Aviation Equipment (EUROCAE)."},{"key":"e_1_3_2_1_12_1","volume-title":"Unicorn: Runtime provenance-based detector for advanced persistent threats. arXiv preprint arXiv:2001.01525","author":"Han Xueyuan","year":"2020","unstructured":"Xueyuan Han, Thomas Pasquier, Adam Bates, James Mickens, and Margo Seltzer. 2020. Unicorn: Runtime provenance-based detector for advanced persistent threats. arXiv preprint arXiv:2001.01525 (2020)."},{"key":"e_1_3_2_1_13_1","volume-title":"Nodoze: Combatting threat alert fatigue with automated provenance triage. In network and distributed systems security symposium.","author":"Hassan Wajih\u00a0Ul","year":"2019","unstructured":"Wajih\u00a0Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen, Kangkook Jee, Zhichun Li, and Adam Bates. 2019. Nodoze: Combatting threat alert fatigue with automated provenance triage. In network and distributed systems security symposium."},{"key":"e_1_3_2_1_14_1","volume-title":"22nd USENIX Security Symposium. 81\u201396","author":"Jang Jiyong","year":"2013","unstructured":"Jiyong Jang, Maverick Woo, and David Brumley. 2013. Towards automatic software lineage inference. In 22nd USENIX Security Symposium. 81\u201396."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292577"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.25"},{"key":"e_1_3_2_1_17_1","volume-title":"VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In 25th Annual Network and Distributed System Security Symposium, NDSS. The Internet Society.","author":"Li Zhen","year":"2018","unstructured":"Zhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin, Sujuan Wang, Zhijun Deng, and Yuyi Zhong. 2018. VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In 25th Annual Network and Distributed System Security Symposium, NDSS. The Internet Society."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/IECON48115.2021.9589730"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"MITRE. 2023. CWE Top 25 Most Dangerous Software Weaknesses. https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html","DOI":"10.1001\/jama.2023.9319"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3193111.3193112"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542504"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806651.1806657"},{"key":"e_1_3_2_1_24_1","volume-title":"d.]. NIST SOFTWARE ASSURANCE REFERENCE DATASET. Retrieved Feburary 1","author":"NIST.","year":"2024","unstructured":"NIST. [n. d.]. NIST SOFTWARE ASSURANCE REFERENCE DATASET. Retrieved Feburary 1, 2024 from https:\/\/samate.nist.gov\/SARD"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.500-297"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3600160.3600171"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3564648"},{"key":"e_1_3_2_1_29_1","volume-title":"28th USENIX Security Symposium. 479\u2013496","author":"Quiring Erwin","year":"2019","unstructured":"Erwin Quiring, Alwin Maier, and Konrad Rieck. 2019. Misleading authorship attribution of source code using adversarial learning. In 28th USENIX Security Symposium. 479\u2013496."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2020.9099920"},{"key":"e_1_3_2_1_31_1","volume-title":"Automated Vulnerability Detection in Source Code Using Deep Representation Learning. In 17th IEEE International Conference on Machine Learning and Applications, ICMLA. 757\u2013762","author":"Russell L.","year":"2018","unstructured":"Rebecca\u00a0L. Russell, Louis\u00a0Y. Kim, Lei\u00a0H. Hamilton, Tomo Lazovich, Jacob Harer, Onur Ozdemir, Paul\u00a0M. Ellingwood, and Marc\u00a0W. McConley. 2018. Automated Vulnerability Detection in Source Code Using Deep Representation Learning. In 17th IEEE International Conference on Machine Learning and Applications, ICMLA. 757\u2013762."},{"key":"e_1_3_2_1_32_1","volume-title":"SoK: Attestation in confidential computing. ResearchGate pre-print","author":"Sardar M","year":"2023","unstructured":"M Sardar, Thomas Fossati, and Simon Frost. 2023. SoK: Attestation in confidential computing. ResearchGate pre-print (2023)."},{"key":"e_1_3_2_1_33_1","unstructured":"Konstantin Serebryany Derek Bruening Alexander Potapenko and Dmitriy Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In USENIX annual technical conference. 309\u2013318."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_14"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-020-00048-4"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00010"},{"key":"e_1_3_2_1_38_1","unstructured":"National Telecommunications and Information Administration. 2021. Software Bill of Materials. https:\/\/www.ntia.gov\/page\/software-bill-materials"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2716260"},{"key":"e_1_3_2_1_40_1","volume-title":"Techniques for cyber attack attribution","author":"Wheeler A","unstructured":"David\u00a0A Wheeler and Gregory\u00a0N Larsen. 2003. Techniques for cyber attack attribution. Institute for Defense Analysis (2003), 2."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474374.3486918"},{"key":"e_1_3_2_1_42_1","volume-title":"Constructing APT attack scenarios based on intrusion kill chain and fuzzy clustering. Security and Communication Networks","author":"Zhang Ru","year":"2017","unstructured":"Ru Zhang, Yanyu Huo, Jianyi Liu, Fangyu Weng, 2017. Constructing APT attack scenarios based on intrusion kill chain and fuzzy clustering. Security and Communication Networks (2017)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338931"},{"key":"e_1_3_2_1_44_1","volume-title":"Annual Conference on Neural Information Processing Systems, NeurIPS. 10197\u201310207","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jing\u00a0Kai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks. In Annual Conference on Neural Information Processing Systems, NeurIPS. 10197\u201310207."}],"event":{"name":"ARES 2024: The 19th International Conference on Availability, Reliability and Security","location":"Vienna Austria","acronym":"ARES 2024"},"container-title":["Proceedings of the 19th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3671410","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664476.3671410","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T16:52:22Z","timestamp":1755881542000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664476.3671410"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,30]]},"references-count":44,"alternative-id":["10.1145\/3664476.3671410","10.1145\/3664476"],"URL":"https:\/\/doi.org\/10.1145\/3664476.3671410","relation":{},"subject":[],"published":{"date-parts":[[2024,7,30]]},"assertion":[{"value":"2024-07-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}