{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:48:04Z","timestamp":1783439284986,"version":"3.54.6"},"reference-count":82,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2024,9,27]],"date-time":"2024-09-27T00:00:00Z","timestamp":1727395200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3106400 and 2023QY1202"],"award-info":[{"award-number":["2023YFB3106400 and 2023QY1202"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation (NSF) of China","doi-asserted-by":"crossref","award":["U2336203 and U1836210"],"award-info":[{"award-number":["U2336203 and U1836210"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Key Research and Development Science and Technology of Hainan Province","award":["GHYF2022010"],"award-info":[{"award-number":["GHYF2022010"]}]},{"name":"Beijing NSF","award":["4242031"],"award-info":[{"award-number":["4242031"]}]},{"name":"Beijing NSF","award":["L234033"],"award-info":[{"award-number":["L234033"]}]},{"name":"Netherlands Organization for Scientific Research","award":["VI.Veni.202.212"],"award-info":[{"award-number":["VI.Veni.202.212"]}]},{"name":"U.S. NSF","award":["2238264"],"award-info":[{"award-number":["2238264"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2024,9,30]]},"abstract":"<jats:p>\n            Deeply embedded systems powered by microcontrollers are becoming popular with the emergence of Internet-of-Things (IoT) technology. However, these devices primarily run C\/C\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"LaTeX\" version=\"MathJax\">\\({+}{+}\\)<\/jats:tex-math>\n            <\/jats:inline-formula>\n            code and are susceptible to memory bugs, which can potentially lead to both control data attacks and non-control data attacks. Existing defense mechanisms (such as control-flow integrity (CFI), dataflow integrity (DFI) and write integrity testing (WIT), etc.) consume a massive amount of resources, making them less practical in real products. To make it lightweight, we design a bitmap-based allowlist mechanism to unify the storage of the runtime data for protecting both control data and non-control data. The memory requirements are constant and small, regardless of the number of deployed defense mechanisms. We store the allowlist in the TrustZone to ensure its integrity and confidentiality. Meanwhile, we perform an offline analysis to detect potential collisions and make corresponding adjustments when it happens. We have implemented our idea on an ARM Cortex-M-based development board. Our evaluation results show a substantial reduction in memory consumption when deploying the proposed CFI and DFI mechanisms, without compromising runtime performance. Specifically, our prototype enforces CFI and DFI at a cost of just 2.09% performance overhead and 32.56% memory overhead on average.\n          <\/jats:p>","DOI":"10.1145\/3672460","type":"journal-article","created":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T05:52:18Z","timestamp":1718776338000},"page":"1-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Bitmap-Based Security Monitoring for Deeply Embedded Systems"],"prefix":"10.1145","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4311-9434","authenticated-orcid":false,"given":"Anni","family":"Peng","sequence":"first","affiliation":[{"name":"National Computer Network Intrusion Protection Center, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-7484-1333","authenticated-orcid":false,"given":"Dongliang","family":"Fang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8205-5616","authenticated-orcid":false,"given":"Le","family":"Guan","sequence":"additional","affiliation":[{"name":"University of Georgia, Athens, GA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0312-9913","authenticated-orcid":false,"given":"Erik van der","family":"Kouwe","sequence":"additional","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0085-6429","authenticated-orcid":false,"given":"Yin","family":"Li","sequence":"additional","affiliation":[{"name":"National Computer Network Intrusion Protection Center, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0840-4846","authenticated-orcid":false,"given":"Wenwen","family":"Wang","sequence":"additional","affiliation":[{"name":"University of Georgia, Athens, GA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2745-7521","authenticated-orcid":false,"given":"Limin","family":"Sun","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8306-7195","authenticated-orcid":false,"given":"Yuqing","family":"Zhang","sequence":"additional","affiliation":[{"name":"National Computer Network Intrusion Protection Center, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,9,27]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_3_1_3_2","first-page":"1","article-title":"Ghost in the plc designing an undetectable programmable logic controller rootkit via pin control attack","volume":"2016","author":"Abbasi Ali","year":"2016","unstructured":"Ali Abbasi and Majid Hashemi. 2016. Ghost in the plc designing an undetectable programmable logic controller rootkit via pin control attack. Black Hat Europe 2016, 1\u201335.","journal-title":"Black Hat Europe"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00013"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978358"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24016"},{"key":"e_1_3_1_8_2","unstructured":"ARM Ltd. 2021. Arm TrustZone Technology. Retrieved from https:\/\/developer.arm.com\/ip-products\/security-ip\/trustzone\/"},{"key":"e_1_3_1_9_2","unstructured":"ARM Ltd. 2023. ARM Cortex-M Programming Guide to Memory Barrier Instructions. Retrieved from https:\/\/documentation-service.arm.com\/static\/5efefb97dbdee951c1cd5aaf"},{"key":"e_1_3_1_10_2","unstructured":"ARM Ltd. 2024. Discovery Kit with STM32L562QE MCU. Retrieved from https:\/\/www.st.com\/en\/evaluation-tools\/stm32l562e-dk.html"},{"key":"e_1_3_1_11_2","unstructured":"Gal Beniamini. 2017. Over The Air: Exploiting Broadcom\u2019s Wi-Fi Stack. Google Project Zero Blog. Retrieved from https:\/\/googleprojectzero.blogspot.com\/2017\/04\/over-air-exploiting-broadcoms-wi-fi_11.html"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/362686.362692"},{"key":"e_1_3_1_13_2","first-page":"340","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS)","author":"Budiu Mihai","year":"2005","unstructured":"Mihai Budiu, Ulfar Erlingsson, and Jay Ligatti. 2005. Control-Flow Integrity. In Proceedings of the ACM Conference on Computer and Communications Security (CCS). 340\u2013353."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3054924"},{"key":"e_1_3_1_15_2","first-page":"161","volume-title":"Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915)","author":"Carlini Nicholas","year":"2015","unstructured":"Nicholas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. 2015. \\(\\{\\) Control-Flow \\(\\}\\) bending: On the effectiveness of \\(\\{\\) Control-Flow \\(\\}\\) integrity. In Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915). 161\u2013176."},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3052983"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.5555\/1298455.1298470"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0304-3975(00)00109-2"},{"key":"e_1_3_1_19_2","volume-title":"Proceedings of the USENIX Security Symposium","volume":"5","author":"Chen Shuo","year":"2005","unstructured":"Shuo Chen, Jun Xu, Emre Can Sezer, Prachi Gauriar, and Ravishankar K. Iyer. 2005. Non-control-data attacks are realistic threats. In Proceedings of the USENIX Security Symposium, Vol. 5."},{"key":"e_1_3_1_20_2","first-page":"65","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918)","author":"Clements Abraham A.","year":"2018","unstructured":"Abraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, and Mathias Payer. 2018. \\(\\{\\) ACES \\(\\}\\) : Automatic compartments for embedded systems. In Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918). 65\u201382."},{"key":"e_1_3_1_21_2","first-page":"1201","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Clements Abraham A.","year":"2020","unstructured":"Abraham A. Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware re-hosting through abstraction layer emulation. In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 1201\u20131218."},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2016.2548561"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/2593069.2596656"},{"key":"e_1_3_1_24_2","first-page":"401","volume-title":"Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914)","author":"Davi Lucas","year":"2014","unstructured":"Lucas Davi, Ahmad-Reza Sadeghi, Daniel Lehmann, and Fabian Monrose. 2014b. Stitching the gadgets: On the ineffectiveness of \\(\\{\\) Coarse-Grained \\(\\}\\) \\(\\{\\) Control-Flow \\(\\}\\) integrity protection. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914). 401\u2013416."},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/CEC.2017.7969631"},{"key":"e_1_3_1_26_2","unstructured":"Majid Derhambakhsh. 2022. PID Controller Library for ARM CortexM (STM32). Retrieved from https:\/\/github.com\/Majid-Derhambakhsh\/PID-Library"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240821"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3061639.3062276"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446740"},{"issue":"6","key":"e_1_3_1_30_2","first-page":"29","article-title":"W32. stuxnet dossier","volume":"5","author":"Falliere Nicolas","year":"2011","unstructured":"Nicolas Falliere, Liam O. Murchu, and Eric Chien. 2011. W32. stuxnet dossier. White paper, Symantec Corporation, Security Response 5, 6 (2011), 29.","journal-title":"White paper, Symantec Corporation, Security Response"},{"key":"e_1_3_1_31_2","unstructured":"FDA. 2017. Cybersecurity Vulnerabilities Identified in Implantable Cardiac Pacemaker."},{"key":"e_1_3_1_32_2","first-page":"1237","volume-title":"Proceedings of the USENIX Security Symposium","author":"Feng B.","year":"2020","unstructured":"B. Feng, A. Mera, and L. Lu. 2020. \\(\\{\\) P2IM \\(\\}\\) : Scalable and hardware-independent firmware testing via automatic peripheral interface modeling. In Proceedings of the USENIX Security Symposium. 1237\u20131254."},{"key":"e_1_3_1_33_2","first-page":"911","volume-title":"Proceedings of the 2020 USENIX Annual Technical Conference (USENIX ATC\u201920)","author":"Garbelini Matheus E.","year":"2020","unstructured":"Matheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sun Sumei, and Ernest Kurniawan. 2020. SweynTooth: Unleashing mayhem over bluetooth low energy. In Proceedings of the 2020 USENIX Annual Technical Conference (USENIX ATC\u201920). USENIX Association, 911\u2013925."},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23313"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1490283.1490287"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102424"},{"key":"e_1_3_1_37_2","unstructured":"Andy Greenberg. 2016. Hacker Says He can Hijack a $35K Police Drone a Mile Away. Retrieved from https:\/\/www.wired.com\/2016\/03\/hacker-says-can-hijack-35k-police-drone-mile-away\/"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3371151"},{"key":"e_1_3_1_39_2","unstructured":"Hex Five Security Inc. 2021. The First TEE For RISC-V. Retrieved from https:\/\/hex-five.com\/multizone-security-sdk\/"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.62"},{"key":"e_1_3_1_41_2","unstructured":"Troy Hunt. 2016. Controlling Vehicle Features of Nissan Leafs Across the Globe Via Vulnerable Apis. Retrieved from https:\/\/www.troyhunt.com\/controlling-vehicle-features-of-nissan\/"},{"key":"e_1_3_1_42_2","volume-title":"Root-of-Trust Architectures for Low-End Embedded Systems","author":"Jakkamsetti Sashidhar","year":"2023","unstructured":"Sashidhar Jakkamsetti. 2023. Root-of-Trust Architectures for Low-End Embedded Systems. University of California, Irvine."},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23287"},{"key":"e_1_3_1_44_2","unstructured":"Ori Karliner. 2018. FreeRTOS TCP\/IP Stack Vulnerabilities\u2013The Details. Retrieved from https:\/\/blog.zimperium.com\/freertos-tcpip-stack-vulnerabilities-details\/"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/1358628.1358911"},{"key":"e_1_3_1_46_2","unstructured":"M. Kol and S. Oberman. 2020. 19 Zero-Day Vulnerabilities Amplified by the Supply Chain. JSOF White Paper. Retrieved from https:\/\/www.jsof-tech.com\/disclosures\/ripple20\/"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2004.52"},{"key":"e_1_3_1_48_2","volume-title":"Concept and Implementation of Autosar Compliant Automotive Ethernet Stack on Infineon Aurix Tricore Board","author":"Krishnadas Sreenath","year":"2016","unstructured":"Sreenath Krishnadas. 2016. Concept and Implementation of Autosar Compliant Automotive Ethernet Stack on Infineon Aurix Tricore Board. Master\u2019s thesis, Universit\u00e4tsbibliothek Chemnitz."},{"key":"e_1_3_1_49_2","unstructured":"Keen Security Lab. 2017. New Car Hacking Research: Tesla Motors. Retrieved from https:\/\/keenlab.tencent.com\/en\/2017\/07\/27\/New-Car-Hacking-Research-2017-Remote-Attack-Tesla-Motors-Again\/"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2004.1281665"},{"key":"e_1_3_1_51_2","unstructured":"Lauterbach GmbH. 2022. MIPS Debugger and Trace. Retrieved from https:\/\/www2.lauterbach.com\/pdf\/debugger_mips.pdf"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00083"},{"key":"e_1_3_1_53_2","unstructured":"ARM Ltd. 2021. Armv8-M Architecture Reference Manual. Retrieved from https:\/\/developer.arm.com\/documentation\/ddi0553\/"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813676"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3538275"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66332-6_12"},{"key":"e_1_3_1_58_2","unstructured":"Rapid7. 2016. Multiple Vulnerabilities in Animas Onetouch Ping Insulin Pump. Retrieved from https:\/\/blog.rapid7.com\/2016\/10\/04\/r7-2016-07-multiple-vulnerabilities-in-animas-onetouch-ping-insulin-pump\/"},{"key":"e_1_3_1_59_2","unstructured":"RJMSTM. 2020a. CRC Data. Retrieved from https:\/\/github.com\/STMicroelectronics\/STM32CubeL5\/tree\/master\/Projects\/STM32L562E-DK\/Examples\/CRC\/CRC_Data_Reversing_16bit_CRC\/"},{"key":"e_1_3_1_60_2","unstructured":"RJMSTM. 2020b. CRYP. Retrieved from https:\/\/github.com\/STMicroelectronics\/STM32CubeL5\/tree\/master\/Projects\/STM32L562E-DK\/Examples\/CRYP\/CRYP_AESModes\/"},{"key":"e_1_3_1_61_2","unstructured":"RJMSTM. 2020c. OSPI. Retrieved from https:\/\/github.com\/STMicroelectronics\/STM32CubeL5\/tree\/master\/Projects\/STM32L562E-DK\/Examples\/OCTOSPI\/OSPI_NOR_MemoryMapped\/"},{"key":"e_1_3_1_62_2","unstructured":"RJMSTM. 2020d. RNG MultiRNG. Retrieved from https:\/\/github.com\/STMicroelectronics\/STM32CubeL5\/tree\/master\/Projects\/STM32L562E-DK\/Examples\/RNG\/RNG_MultiRNG\/"},{"key":"e_1_3_1_63_2","unstructured":"RJMSTM. 2020e. RTC Alarm. Retrieved from https:\/\/github.com\/STMicroelectronics\/STM32CubeL5\/tree\/master\/Projects\/STM32L562E-DK\/Examples\/RTC\/RTC_Alarm\/"},{"key":"e_1_3_1_64_2","unstructured":"RJMSTM. 2020f. STM32CubeL5. Retrieved from https:\/\/github.com\/STMicroelectronics\/STM32CubeL5\/tree\/master\/Projects\/STM32L562E-DK\/"},{"key":"e_1_3_1_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.14"},{"key":"e_1_3_1_66_2","unstructured":"Jonathan Salwan. 2023. ROPgadget Tool. Retrieved from https:\/\/github.com\/JonathanSalwan\/ROPgadget"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.5555\/2001180.2001183"},{"key":"e_1_3_1_68_2","unstructured":"SiFiv Inc. 2022. RISC-V Debug Specification. Retrieved from https:\/\/github.com\/riscv\/riscv-debug-spec\/blob\/master\/riscv-debug-stable.pdf"},{"key":"e_1_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.9"},{"key":"e_1_3_1_70_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2021\/5519891","article-title":"A data-enabled business model for a smart healthcare information service platform in the era of digital transformation","volume":"2021","author":"Su Yu","year":"2021","unstructured":"Yu Su, Fei Hou, Mingde Qi, Wanxuan Li, and Ying Ji. 2021. A data-enabled business model for a smart healthcare information service platform in the era of digital transformation. Journal of Healthcare Engineering 2021, 1\u20139.","journal-title":"Journal of Healthcare Engineering"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00042"},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484788"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_1_74_2","unstructured":"MSRC Team. 2021. BadAlloc\u2013Memory Allocation Vulnerabilities Could Affect Wide Range of IoT and OT Devices in Industrial Medical and Enterprise Networks. Retrieved from https:\/\/msrc-blog.microsoft.com\/2021\/04\/29\/badalloc-memory-allocation-vulnerabili-could-affect-wide-range-of-iot-and-ot-devices-in-industrial-medical-and-enterprise-networks\/"},{"key":"e_1_3_1_75_2","first-page":"941","volume-title":"Proceedings of the 23rd USENIX Security Symposium USENIX Security","author":"Tice Caroline","year":"2014","unstructured":"Caroline Tice, Tom Roeder, Peter Collingbourne, Stephen Checkoway, \u00dalfar Erlingsson, Luis Lozano, and Geoff Pike. 2014. Enforcing forward-edge control-flow integrity in GCC & LLVM. In Proceedings of the 23rd USENIX Security Symposium USENIX Security. 941\u2013955."},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813673"},{"key":"e_1_3_1_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.30"},{"key":"e_1_3_1_78_2","doi-asserted-by":"crossref","unstructured":"Zhilong Wang Haizhou Wang Hong Hu and Peng Liu. 2021. Identifying non-control security-critical data in program binaries with a deep neural model. arXiv:2108.12071. Retrived from https:\/\/arxiv.org\/abs\/2108.12071","DOI":"10.1080\/0305215X.2020.1846031"},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046713"},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.44"},{"key":"e_1_3_1_81_2","first-page":"337","volume-title":"Proceedings of the 22nd USENIX Security Symposium (USENIX Security\u201913)","author":"Zhang Mingwei","year":"2013","unstructured":"Mingwei Zhang and R. Sekar. 2013. Control flow integrity for COTS binaries. In Proceedings of the 22nd USENIX Security Symposium (USENIX Security\u201913). 337\u2013352."},{"key":"e_1_3_1_82_2","first-page":"1219","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920)","author":"Zhou Jie","year":"2020","unstructured":"Jie Zhou, Yufei Du, Zhuojia Shen, Lele Ma, John Criswell, and Robert J. Walls. 2020. Silhouette: Efficient protected shadow stacks for embedded systems. In Proceedings of the 29th USENIX Security Symposium (USENIX Security\u201920). 1219\u20131236."},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519573"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3672460","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3672460","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:58:01Z","timestamp":1750294681000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3672460"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,27]]},"references-count":82,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2024,9,30]]}},"alternative-id":["10.1145\/3672460"],"URL":"https:\/\/doi.org\/10.1145\/3672460","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9,27]]},"assertion":[{"value":"2023-11-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-05-26","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}