{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T13:21:59Z","timestamp":1783948919457,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":101,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,19]],"date-time":"2024-11-19T00:00:00Z","timestamp":1731974400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSERC"},{"DOI":"10.13039\/501100006374","name":"Mitacs","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,11,19]]},"DOI":"10.1145\/3689938.3694781","type":"proceedings-article","created":{"date-parts":[[2024,11,19]],"date-time":"2024-11-19T18:21:37Z","timestamp":1732040497000},"page":"80-94","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["SafeBPF: Hardware-assisted Defense-in-depth for eBPF Kernel Extensions"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3418-4982","authenticated-orcid":false,"given":"Soo Yee","family":"Lim","sequence":"first","affiliation":[{"name":"University of British Columbia, Vancouver, British Columbia, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-5378-1857","authenticated-orcid":false,"given":"Tanya","family":"Prasad","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, British Columbia, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1374-153X","authenticated-orcid":false,"given":"Xueyuan","family":"Han","sequence":"additional","affiliation":[{"name":"Wake Forest University, Winston-Salem, North Carolina, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6876-1306","authenticated-orcid":false,"given":"Thomas","family":"Pasquier","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, British Columbia, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,19]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2021. ghOSt: Fast & Flexible User-Space Delegation of Linux Scheduling. https: \/\/lwn.net\/Articles\/873244\/."},{"key":"e_1_3_2_1_2_1","unstructured":"2022. eBPF Kernel Scheduling with Ghost. https:\/\/lpc.events\/event\/16\/ contributions\/1365\/attachments\/986\/1912\/lpc22-ebpf-kernel-schedulingwith-ghost.pdf."},{"key":"e_1_3_2_1_3_1","volume-title":"Analysis on Kernel Self-Protection: Understanding Security and Performance Implication -- Hardening Hostile Code in eBPF. Online (Accessed: 5th","year":"2024","unstructured":"2024. Analysis on Kernel Self-Protection: Understanding Security and Performance Implication -- Hardening Hostile Code in eBPF. Online (Accessed: 5th September 2024). https:\/\/samsung.github.io\/kspp-study\/bpf.html."},{"key":"e_1_3_2_1_4_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. \/arch\/arm64\/kernel\/cpufeature.c. Online (Accessed: 5th September 2024). https:\/\/elixir.bootlin.com\/linux\/v6.3.8\/source\/arch\/arm64\/kernel\/cpufeature.c."},{"key":"e_1_3_2_1_5_1","volume-title":"5th","author":"Extension A Memory Tagging","year":"2024","unstructured":"2024. Armv8.5-A Memory Tagging Extension. Online (Accessed: 5th September 2024). https:\/\/developer.arm.com\/documentation\/102925\/latest\/."},{"key":"e_1_3_2_1_6_1","volume-title":"bcc: Toolkit and library for efficient BPF-based kernel tracing. Online (Accessed: 5th","year":"2024","unstructured":"2024. bcc: Toolkit and library for efficient BPF-based kernel tracing. Online (Accessed: 5th September 2024). https:\/\/github.com\/iovisor\/bcc."},{"key":"e_1_3_2_1_7_1","volume-title":"bpf: cgroup_sock lsm flavor. Online (Accessed: 5th","year":"2024","unstructured":"2024. bpf: cgroup_sock lsm flavor. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/Articles\/899300\/."},{"key":"e_1_3_2_1_8_1","volume-title":"BPF Compiler Collection (BCC). Online (Accessed: 5th","year":"2024","unstructured":"2024. BPF Compiler Collection (BCC). Online (Accessed: 5th September 2024). https:\/\/github.com\/iovisor\/bcc."},{"key":"e_1_3_2_1_9_1","volume-title":"5th","author":"Exceptions BPF","year":"2024","unstructured":"2024. BPF Exceptions. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/ Articles\/944372\/."},{"key":"e_1_3_2_1_10_1","volume-title":"bpf: introduce BPF_JIT_ALWAYS_ON config. Online (Accessed: 5th","year":"2024","unstructured":"2024. bpf: introduce BPF_JIT_ALWAYS_ON config. Online (Accessed: 5th September 2024). https:\/\/lore.kernel.org\/lkml\/20180109180429.1115005--1-ast@ kernel.org\/."},{"key":"e_1_3_2_1_11_1","volume-title":"BPF Kernel Functions (kfuncs). Online (Accessed: 5th","year":"2024","unstructured":"2024. BPF Kernel Functions (kfuncs). Online (Accessed: 5th September 2024). https:\/\/docs.kernel.org\/bpf\/kfuncs.html."},{"key":"e_1_3_2_1_12_1","volume-title":"BPF token. Online (Accessed: 5th","year":"2024","unstructured":"2024. BPF token. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/ Articles\/936823\/."},{"key":"e_1_3_2_1_13_1","volume-title":"5th","author":"Accessed SOCKOPT.","year":"2024","unstructured":"2024. BPF_PROG_TYPE_CGROUP_SOCKOPT. Online (Accessed: 5th September 2024). https:\/\/docs.kernel.org\/bpf\/prog_cgroup_sockopt.html."},{"key":"e_1_3_2_1_14_1","volume-title":"The challenge of compiling for verified architectures. Online (Accessed: 5th","year":"2024","unstructured":"2024. The challenge of compiling for verified architectures. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/Articles\/946254\/."},{"key":"e_1_3_2_1_15_1","volume-title":"Observability, Security. Online","year":"2024","unstructured":"2024. Cilium: eBPF-based Networking, Observability, Security. Online (Accessed: 5th September 2024). https:\/\/cilium.io\/."},{"key":"e_1_3_2_1_16_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2020--27194. Online (Accessed: 5th September 2024). https:\/\/nvd.nist. gov\/vuln\/detail\/CVE-2020--27194."},{"key":"e_1_3_2_1_17_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2020--8835. Online (Accessed: 5th September 2024). https:\/\/cve.mitre. org\/cgi-bin\/cvename.cgi?name=CVE-2020--8835."},{"key":"e_1_3_2_1_18_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2021--31440. Online (Accessed: 5th September 2024). https:\/\/cve. mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021--31440."},{"key":"e_1_3_2_1_19_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2021--33200. Online (Accessed: 5th September 2024). https:\/\/cve. mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021--33200."},{"key":"e_1_3_2_1_20_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2021--34866. Online (Accessed: 5th September 2024). https:\/\/cve. mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021--34866."},{"key":"e_1_3_2_1_21_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2021--3490. Online (Accessed: 5th September 2024). https:\/\/cve.mitre. org\/cgi-bin\/cvename.cgi?name=CVE-2021--3490."},{"key":"e_1_3_2_1_22_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2021--35039. Online (Accessed: 5th September 2024). https:\/\/cve. mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021--35039."},{"key":"e_1_3_2_1_23_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2021--4204. Online (Accessed: 5th September 2024). https:\/\/cve.mitre. org\/cgi-bin\/cvename.cgi?name=CVE-2021--4204."},{"key":"e_1_3_2_1_24_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2022--23222. Online (Accessed: 5th September 2024). https:\/\/cve. mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022--23222."},{"key":"e_1_3_2_1_25_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. CVE-2023--2163. Online (Accessed: 5th September 2024). https:\/\/nvd.nist. gov\/vuln\/detail\/CVE-2023--2163."},{"key":"e_1_3_2_1_26_1","volume-title":"Falco: Cloud Native Runtime Security. Online (Accessed: 5th","year":"2024","unstructured":"2024. Falco: Cloud Native Runtime Security. Online (Accessed: 5th September 2024). https:\/\/falco.org\/."},{"key":"e_1_3_2_1_27_1","volume-title":"Fuzzing for eBPF JIT bugs in the Linux kernel. Online (Accessed: 5th","year":"2024","unstructured":"2024. Fuzzing for eBPF JIT bugs in the Linux kernel. Online (Accessed: 5th September 2024). https:\/\/scannell.io\/posts\/ebpf-fuzzing\/."},{"key":"e_1_3_2_1_28_1","volume-title":"Guidance on Microsoft Signed Drivers Being Used Maliciously (Released","year":"2022","unstructured":"2024. Guidance on Microsoft Signed Drivers Being Used Maliciously (Released: 13 Dec 2022 Last updated: 10 Jan 2023). Online (Accessed: 5th September 2024). https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/ADV220005."},{"key":"e_1_3_2_1_29_1","volume-title":"Intel 64 and IA-32 Architectures Software Developer's Manual -- Volume 1: Basic Architecture. Online (Accessed: 5th","year":"2024","unstructured":"2024. Intel 64 and IA-32 Architectures Software Developer's Manual -- Volume 1: Basic Architecture. Online (Accessed: 5th September 2024). https:\/\/cdrdv2. intel.com\/v1\/dl\/getContent\/671436."},{"key":"e_1_3_2_1_30_1","volume-title":"Introducing a new way to buzz for eBPF vulnerabilities. Online (Accessed: 5th","year":"2024","unstructured":"2024. Introducing a new way to buzz for eBPF vulnerabilities. Online (Accessed: 5th September 2024). https:\/\/security.googleblog.com\/2023\/05\/introducingnew-way-to-buzz-for-ebpf.html."},{"key":"e_1_3_2_1_31_1","volume-title":"Katran: A high performance layer 4 load balancer. Online (Accessed: 5th","year":"2024","unstructured":"2024. Katran: A high performance layer 4 load balancer. Online (Accessed: 5th September 2024). https:\/\/github.com\/facebookincubator\/katran."},{"key":"e_1_3_2_1_32_1","volume-title":"Kernel Address Sanitizer (KASAN). Online (Accessed: 5th","year":"2024","unstructured":"2024. Kernel Address Sanitizer (KASAN). Online (Accessed: 5th September 2024). https:\/\/docs.kernel.org\/dev-tools\/kasan.html."},{"key":"e_1_3_2_1_33_1","volume-title":"libbpf-bootstrap: demo BPF applications. Online (Accessed: 5th","year":"2024","unstructured":"2024. libbpf-bootstrap: demo BPF applications. Online (Accessed: 5th September 2024). https:\/\/github.com\/libbpf\/libbpf-bootstrap."},{"key":"e_1_3_2_1_34_1","volume-title":"Linux BPF Samples. Online (Accessed: 5th","year":"2024","unstructured":"2024. Linux BPF Samples. Online (Accessed: 5th September 2024). https: \/\/github.com\/torvalds\/linux\/tree\/master\/samples\/bpf."},{"key":"e_1_3_2_1_35_1","volume-title":"LLVM improvements for BPF verification. Online (Accessed: 5th","year":"2024","unstructured":"2024. LLVM improvements for BPF verification. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/Articles\/974945\/."},{"key":"e_1_3_2_1_36_1","volume-title":"Mitre: Rust CVEs. Online (Accessed: 5th","year":"2024","unstructured":"2024. Mitre: Rust CVEs. Online (Accessed: 5th September 2024). https:\/\/cve. mitre.org\/cgi-bin\/cvekey.cgi?keyword=rust."},{"key":"e_1_3_2_1_37_1","volume-title":"5th","author":"Accessed Online","year":"2024","unstructured":"2024. Netperf. Online (Accessed: 5th September 2024). https:\/\/hewlettpackard. github.io\/netperf\/."},{"key":"e_1_3_2_1_38_1","volume-title":"Add Stray Write Protection. Online (Accessed: 5th","author":"PATCH","year":"2024","unstructured":"2024. [PATCH V10 00\/44] PKS\/PMEM: Add Stray Write Protection. Online (Accessed: 5th September 2024). https:\/\/lore.kernel.org\/lkml\/20220419170649. 1022246--1-ira.weiny@intel.com\/."},{"key":"e_1_3_2_1_39_1","volume-title":"Pixie: Scriptable observability for Kubernetes. Online (Accessed: 5th","year":"2024","unstructured":"2024. Pixie: Scriptable observability for Kubernetes. Online (Accessed: 5th September 2024). https:\/\/px.dev\/."},{"key":"e_1_3_2_1_40_1","volume-title":"PKS: Add Protection Keys Supervisor (PKS) support. Online (Accessed: 5th","year":"2024","unstructured":"2024. PKS: Add Protection Keys Supervisor (PKS) support. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/Articles\/826091\/."},{"key":"e_1_3_2_1_41_1","volume-title":"Runtime detection of CPU features on an ARMv8-A CPU. Online (Accessed: 5th","year":"2024","unstructured":"2024. Runtime detection of CPU features on an ARMv8-A CPU. Online (Accessed: 5th September 2024). https:\/\/community.arm.com\/arm-communityblogs\/b\/operating-systems-blog\/posts\/runtime-detection-of-cpu-features-onan-armv8-a-cpu."},{"key":"e_1_3_2_1_42_1","volume-title":"Security Hardening: Use of eBPF by unprivileged users has been disabled by default. Online (Accessed: 5th","year":"2024","unstructured":"2024. Security Hardening: Use of eBPF by unprivileged users has been disabled by default. Online (Accessed: 5th September 2024). https:\/\/www.suse.com\/ support\/kb\/doc\/?id=000020545."},{"key":"e_1_3_2_1_43_1","volume-title":"Tagged memory support. Online (Accessed: 5th","year":"2024","unstructured":"2024. Tagged memory support. Online (Accessed: 5th September 2024). https: \/\/lowrisc.org\/docs\/tagged-memory-v0.1\/tags\/."},{"key":"e_1_3_2_1_44_1","volume-title":"Tigera: Container security with built-in network security. Online (Accessed: 5th","year":"2024","unstructured":"2024. Tigera: Container security with built-in network security. Online (Accessed: 5th September 2024). https:\/\/www.tigera.io\/."},{"key":"e_1_3_2_1_45_1","volume-title":"Toward better handling of hardware vulnerabilities. Online (Accessed: 5th","year":"2024","unstructured":"2024. Toward better handling of hardware vulnerabilities. Online (Accessed: 5th September 2024). https:\/\/lwn.net\/Articles\/764593\/."},{"key":"e_1_3_2_1_46_1","volume-title":"Unprivileged eBPF disabled by default for Ubuntu 20.04 LTS, 18.04 LTS, 16.04 ESM. Online (Accessed: 5th","year":"2024","unstructured":"2024. Unprivileged eBPF disabled by default for Ubuntu 20.04 LTS, 18.04 LTS, 16.04 ESM. Online (Accessed: 5th September 2024). https:\/\/discourse.ubuntu. com\/t\/27047."},{"key":"e_1_3_2_1_47_1","volume-title":"Using eBPF in Kubernetes. Online (Accessed: 5th","year":"2024","unstructured":"2024. Using eBPF in Kubernetes. Online (Accessed: 5th September 2024). https:\/\/kubernetes.io\/blog\/2017\/12\/using-ebpf-in-kubernetes\/."},{"key":"e_1_3_2_1_48_1","volume-title":"Security Symposium (USENIX Sec'22)","author":"Alexopoulos Nikolaos","year":"2022","unstructured":"Nikolaos Alexopoulos, Manuel Brack, Jan Philipp Wagner, Tim Grube, and Max M\u00fchlh\u00e4user. 2022. How Long Do Vulnerabilities Live in the Code? A LargeScale Empirical Measurement Study on FOSS Vulnerability Lifetimes. In Security Symposium (USENIX Sec'22). USENIX, 359--376."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3412841.3442037"},{"key":"e_1_3_2_1_50_1","unstructured":"Sanjit Bhat and Hovav Shacham. 2022. Formal Verification of the Linux Kernel eBPF Verifier Range Analysis."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543668"},{"key":"e_1_3_2_1_52_1","volume-title":"Annual Technical Conference (ATC'24)","author":"Cao Xuechun","year":"2024","unstructured":"Xuechun Cao, Shaurya Patel, Soo Yee Lim, Xueyuan Han, and Thomas Pasquier. 2024. FetchBPF: Customizable Prefetching Policies in Linux with eBPF. In Annual Technical Conference (ATC'24). USENIX."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629581"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833707"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2103799.2103805"},{"key":"e_1_3_2_1_56_1","volume-title":"Security Symposium (USENIX Sec'20)","author":"Chen Weiteng","year":"2020","unstructured":"Weiteng Chen, Xiaochen Zou, Guoren Li, and Zhiyun Qian. 2020. KOOBE: towards facilitating exploit generation of kernel Out-Of-Bounds write vulnerabilities. In Security Symposium (USENIX Sec'20). USENIX."},{"key":"e_1_3_2_1_57_1","volume-title":"A QEMU and SystemC-Based Cycle-Accurate ISS for Performance Estimation on SoC Development","author":"Chiang Ming-Chao","year":"2011","unstructured":"Ming-Chao Chiang, Tse-Chen Yeh, and Guo-Fu Tseng. 2011. A QEMU and SystemC-Based Cycle-Accurate ISS for Performance Estimation on SoC Development. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems (2011), 593--606."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/502034.502042"},{"key":"e_1_3_2_1_59_1","volume-title":"Symposium on Operating Systems Design and Implementation (OSDI'06)","author":"Erlingsson Ulfar","year":"2006","unstructured":"Ulfar Erlingsson, Mart\u00edn Abadi, Michael Vrable, Mihai Budiu, and George C Necula. 2006. XFI: Software guards for system address spaces. In Symposium on Operating Systems Design and Implementation (OSDI'06). USENIX, 75--88."},{"key":"e_1_3_2_1_60_1","first-page":"27","article-title":"Microdrivers: A new architecture for device drivers","volume":"134","author":"Ganapathy Vinod","year":"2007","unstructured":"Vinod Ganapathy, Arini Balakrishnan, Michael M Swift, and Somesh Jha. 2007. Microdrivers: A new architecture for device drivers. Network 134 (2007), 27--8.","journal-title":"Network"},{"key":"e_1_3_2_1_61_1","volume-title":"The design and implementation of Microdrivers. ACM SIGARCH Computer Architecture News","author":"Ganapathy Vinod","year":"2008","unstructured":"Vinod Ganapathy, Matthew Renzelmann, Arini Balakrishnan, Michael Swift, and Somesh Jha. 2008. The design and implementation of Microdrivers. ACM SIGARCH Computer Architecture News (2008)."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3314221.3314590"},{"key":"e_1_3_2_1_63_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"He Yi","year":"2023","unstructured":"Yi He, Roland Guo, Yunlong Xing, Xijia Che, Kun Sun, Zhuotao Liu, Ke Xu, and Qi Li. 2023. Cross Container Attacks: The Bewildered {eBPF} on Clouds. In 32nd USENIX Security Symposium (USENIX Security 23). 5971--5988."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3281411.3281443"},{"key":"e_1_3_2_1_65_1","volume-title":"KSplit: Automating Device Driver Isolation. In Symposium on Operating Systems Design and Implementation (OSDI'22)","author":"Huang Yongzhe","year":"2022","unstructured":"Yongzhe Huang, Vikram Narayanan, David Detweiler, Kaiming Huang, Gang Tan, Trent Jaeger, and Anton Burtsev. 2022. KSplit: Automating Device Driver Isolation. In Symposium on Operating Systems Design and Implementation (OSDI'22). USENIX, 613--631."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483542"},{"key":"e_1_3_2_1_67_1","volume-title":"BRF: eBPF Runtime Fuzzer. arXiv preprint arXiv:2305.08782","author":"Hung Hsin-Wei","year":"2023","unstructured":"Hsin-Wei Hung and Ardalan Amiri Sani. 2023. BRF: eBPF Runtime Fuzzer. arXiv preprint arXiv:2305.08782 (2023)."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3593856.3595892"},{"key":"e_1_3_2_1_69_1","volume-title":"EPF: Evil Packet Filter. In Annual Technical Conference (USENIX ATC'23)","author":"Jin Di","year":"2023","unstructured":"Di Jin, Vaggelis Atlidakis, and Vasileios P Kemerlis. 2023. EPF: Evil Packet Filter. In Annual Technical Conference (USENIX ATC'23). USENIX, 735--751."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483548"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064217"},{"key":"e_1_3_2_1_72_1","volume-title":"Phoronix test suite. Online (Accessed: 5th","author":"Larabel Michael","year":"2024","unstructured":"Michael Larabel and Matthew Tippett. 2024. Phoronix test suite. Online (Accessed: 5th September 2024). Phoronix Media (2024). http:\/\/www.phoronix-testsuite.com."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3599691.3603408"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC45041.2023.10278676"},{"key":"e_1_3_2_1_75_1","volume-title":"Color My World: Deterministic Tagging for Memory Safety. arXiv preprint arXiv:2204.03781","author":"Liljestrand Hans","year":"2022","unstructured":"Hans Liljestrand, Carlos Chinea, R\u00e9mi Denis-Courmont, Jan-Erik Ekberg, and N Asokan. 2022. Color My World: Deterministic Tagging for Memory Safety. arXiv preprint arXiv:2204.03781 (2022)."},{"key":"e_1_3_2_1_76_1","volume-title":"Security Symposium (USENIX Sec'19)","author":"Liljestrand Hans","year":"2019","unstructured":"Hans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez, Jan-Erik Ekberg, and N Asokan. 2019. PAC it up: Towards pointer integrity using ARM pointer authentication. In Security Symposium (USENIX Sec'19). USENIX, 177-- 194."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3609021.3609301"},{"key":"e_1_3_2_1_78_1","volume-title":"Secure Namespaced Kernel Audit for Containers. In Symposium on Cloud Computing (SoCC'21)","author":"Lim Soo Yee","year":"2021","unstructured":"Soo Yee Lim, Bogdan Stelea, Xueyuan Han, and Thomas Pasquier. 2021. Secure Namespaced Kernel Audit for Containers. In Symposium on Cloud Computing (SoCC'21). ACM, 518--532."},{"key":"e_1_3_2_1_79_1","volume-title":"MOAT: Towards Safe BPF Kernel Extension. arXiv preprint arXiv:2301.13421","author":"Lu Hongyi","year":"2023","unstructured":"Hongyi Lu, Shuai Wang, Yechang Wu, Wanning He, and Fengwei Zhang. 2023. MOAT: Towards Safe BPF Kernel Extension. arXiv preprint arXiv:2301.13421 (2023)."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043568"},{"key":"e_1_3_2_1_81_1","volume-title":"Preventing Kernel Hacks with HAKC. In Network and Distributed System Security Symposium (NDSS'22)","author":"McKee Derrick","year":"2022","unstructured":"Derrick McKee, Yianni Giannaris, Carolina Ortega Perez, Howard Shrobe, Mathias Payer, Hamed Okhravi, and Nathan Burow. 2022. Preventing Kernel Hacks with HAKC. In Network and Distributed System Security Symposium (NDSS'22). Internet Society."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/3609510.3609822"},{"key":"e_1_3_2_1_83_1","volume-title":"Security Symposium (USENIX Sec'21)","author":"Narayan Shravan","year":"2021","unstructured":"Shravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi, Evan Johnson, Zhao Gang, Anjo Vahldiek-Oberwagner, Ravi Sahita, Hovav Shacham, Dean Tullsen, et al. 2021. Swivel: Hardening WebAssembly against spectre. In Security Symposium (USENIX Sec'21). USENIX, 1433--1450."},{"key":"e_1_3_2_1_84_1","volume-title":"LXDs: Towards Isolation of Kernel Subsystems. In Annual Technical Conference (ATC'19)","author":"Narayanan Vikram","year":"2019","unstructured":"Vikram Narayanan, Abhiram Balasubramanian, Charlie Jacobsen, Sarah Spall, Scott Bauer, Michael Quigley, Aftab Hussain, Abdullah Younis, Junjie Shen, Moinak Bhattacharyya, et al. 2019. LXDs: Towards Isolation of Kernel Subsystems. In Annual Technical Conference (ATC'19). USENIX, 269--284."},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/3381052.3381328"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517349.2522719"},{"key":"e_1_3_2_1_87_1","volume-title":"Application-Informed Kernel Synchronization Primitives. In Symposium on Operating Systems Design and Implementation (OSDI'22)","author":"Park Sujin","year":"2022","unstructured":"Sujin Park, Diyu Zhou, Yuchen Qian, Irina Calciu, Taesoo Kim, and Sanidhya Kashyap. 2022. Application-Informed Kernel Synchronization Primitives. In Symposium on Operating Systems Design and Implementation (OSDI'22). USENIX, 667--682."},{"key":"e_1_3_2_1_88_1","volume-title":"Annual Technical Conference (ATC'09)","author":"Renzelmann Matthew J","year":"2009","unstructured":"Matthew J Renzelmann and Michael M Swift. 2009. Decaf: Moving Device Drivers to a Modern Language.. In Annual Technical Conference (ATC'09). USENIX."},{"key":"e_1_3_2_1_89_1","volume-title":"Scalable and Deployable Audit Data Collection System. In Symposium on Security and Privacy (S&P'24)","author":"Sekar R","year":"2024","unstructured":"R Sekar, Hanke Kimm, and Rohit Aich. 2024. eAudit: A Fast, Scalable and Deployable Audit Data Collection System. In Symposium on Security and Privacy (S&P'24). IEEE."},{"key":"e_1_3_2_1_90_1","volume-title":"Automatic Kernel Offload Using BPF. In Workshop on Hot Topics in Operating Systems (HotOS'23)","author":"Shahinfar Farbod","year":"2023","unstructured":"Farbod Shahinfar, Sebastiano Miano, Giuseppe Siracusano, Roberto Bifulco, Aurojit Panda, and Gianni Antichi. 2023. Automatic Kernel Offload Using BPF. In Workshop on Hot Topics in Operating Systems (HotOS'23). ACM, 143--149."},{"key":"e_1_3_2_1_91_1","volume-title":"MiSFIT: Constructing safe extensible systems","author":"Small Christopher","year":"1998","unstructured":"Christopher Small and Margo Seltzer. 1998. MiSFIT: Constructing safe extensible systems. IEEE concurrency 6, 3 (1998), 34--41."},{"key":"e_1_3_2_1_92_1","volume-title":"Security Symposium (USENIX Sec'18)","author":"Sun Yuqiong","year":"2018","unstructured":"Yuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis, Zhongshu Gu, and Trent Jaeger. 2018. Security namespace: making linux security frameworks available to containers. In Security Symposium (USENIX Sec'18). USENIX, 1423-- 1439."},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945466"},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO53902.2022.9741267"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-37709-9_12"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_3_2_1_97_1","volume-title":"Linux Plumbers Conference. Linux Foundation. https:\/\/lpc.events\/event\/11\/contributions\/907\/attachments\/787\/1699\/lpc2021-PKS-22-Sept-2021","author":"Weiny Ira","year":"2024","unstructured":"Ira Weiny and Rick Edgecombe. 2024. Protection Keys, Supervisor (PKS). Online (Accessed: 5th September 2024). In Linux Plumbers Conference. Linux Foundation. https:\/\/lpc.events\/event\/11\/contributions\/907\/attachments\/787\/1699\/lpc2021-PKS-22-Sept-2021.pdf."},{"key":"e_1_3_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095814"},{"key":"e_1_3_2_1_99_1","volume-title":"Conference on File and Storage Technologies (FAST'23)","author":"Yang Zhe","year":"2023","unstructured":"Zhe Yang, Youyou Lu, Xiaojian Liao, Youmin Chen, Junru Li, Siyu He, and Jiwu Shu. 2023. ??-IO: A Unified IO Stack for Computational Storage. In Conference on File and Storage Technologies (FAST'23). USENIX, 347--362."},{"key":"e_1_3_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1145\/3458336.3465290"},{"key":"e_1_3_2_1_101_1","volume-title":"SafeDrive: Safe and Recoverable Extensions Using Language-Based Techniques. In Symposium on Operating Systems Design and Implementation (OSDI'06)","author":"Zhou Feng","year":"2006","unstructured":"Feng Zhou, Jeremy Condit, Zachary Anderson, Ilya Bagrak, Rob Ennals, Matthew Harren, George Necula, and Eric Brewer. 2006. SafeDrive: Safe and Recoverable Extensions Using Language-Based Techniques. In Symposium on Operating Systems Design and Implementation (OSDI'06). USENIX."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on Cloud Computing Security Workshop"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689938.3694781","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689938.3694781","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T18:43:36Z","timestamp":1755974616000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689938.3694781"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,19]]},"references-count":101,"alternative-id":["10.1145\/3689938.3694781","10.1145\/3689938"],"URL":"https:\/\/doi.org\/10.1145\/3689938.3694781","relation":{},"subject":[],"published":{"date-parts":[[2024,11,19]]},"assertion":[{"value":"2024-11-19","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}