{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T13:04:20Z","timestamp":1780664660587,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":55,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,26]],"date-time":"2026-04-26T00:00:00Z","timestamp":1777161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"National Natural Science Foundation of China","award":["62202462"],"award-info":[{"award-number":["62202462"]}]},{"name":"National Natural Science Foundation of China","award":["62302500"],"award-info":[{"award-number":["62302500"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,27]]},"DOI":"10.1145\/3767295.3803624","type":"proceedings-article","created":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T20:20:04Z","timestamp":1777062004000},"page":"2022-2036","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["LifeFuzz: Lifecycle-Guided Fuzzing for Windows Driver Cross-Handler Vulnerabilities"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-6632-3482","authenticated-orcid":false,"given":"Chendong","family":"Yu","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, CAS, Beijing, China"},{"name":"School of Cyber Security, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4382-0757","authenticated-orcid":false,"given":"Yuekang","family":"Li","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8009-2252","authenticated-orcid":false,"given":"Yang","family":"Xiao","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS, Beijing, China"},{"name":"School of Cyber Security, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4162-0404","authenticated-orcid":false,"given":"Jie","family":"Lu","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0991-4231","authenticated-orcid":false,"given":"Yeting","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS, Beijing, China"},{"name":"School of Cyber Security, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-3830-723X","authenticated-orcid":false,"given":"Defang","family":"Bo","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS, Beijing, China"},{"name":"School of Cyber Security, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-7121-1196","authenticated-orcid":false,"given":"Wei","family":"Huo","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, CAS, Beijing, China"},{"name":"School of Cyber Security, UCAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,26]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"0dayResearchLab. 2024. Recover the Windows Driver's DeviceIoControl Interface and Dependencies for getting higher coverage in Fuzzing Process. https:\/\/github.com\/0dayResearchLab\/angrPT."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00117"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690320"},{"key":"e_1_3_2_1_4_1","unstructured":"Check Point Research. 2024. Breaking Boundaries: Investigating Vulnerable Drivers and Mitigating Risks. https:\/\/research.checkpoint.com\/2024\/breaking-boundaries-investigating-vulnerable-drivers-and-mitigating-risks\/. Accessed: 2025-09-20."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00269"},{"key":"e_1_3_2_1_6_1","unstructured":"Mark Cherp and Eran Shimony. 2022. My Fuzzy Driver. https:\/\/www.rsaconference.com\/Library\/presentation\/USA\/2022\/MyFuzzyDriver."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134069"},{"key":"e_1_3_2_1_8_1","unstructured":"crewAIInc. 2023. Framework for orchestrating role-playing autonomous AI agents. https:\/\/github.com\/crewAIInc\/crewAI."},{"key":"e_1_3_2_1_9_1","unstructured":"Cyberbit. 2022. Exploring MSI\u2122 Afterburner RTCore driver exploitation. https:\/\/www.cyberbit.com\/campaign\/msi-afterburner-rtcore-driver-exploitation\/."},{"key":"e_1_3_2_1_10_1","unstructured":"debasishm89. 2014. About A mutation based user mode (ring3) dumb in-memory Windows Kernel (IOCTL) Fuzze. https:\/\/github.com\/debasishm89\/iofuzz."},{"key":"e_1_3_2_1_11_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Fleischer Marius","year":"2023","unstructured":"Marius Fleischer, Dipanjan Das, Priyanka Bose, Weiheng Bai, Kangjie Lu, Mathias Payer, Christopher Kruegel, and Giovanni Vigna. 2023. {ACTOR}:{Action-Guided} Kernel Fuzzing. In 32nd USENIX Security Symposium (USENIX Security 23). 5003\u20135020."},{"key":"e_1_3_2_1_12_1","unstructured":"Google. 2011. Automating the task of searching vulnerabilities in Windows kernel drivers. https:\/\/code.google.com\/archive\/p\/ioctlfuzzer."},{"key":"e_1_3_2_1_13_1","unstructured":"Google. 2015. Syzkaller: an unsupervised coverage-guided kernel fuzzer. https:\/\/github.com\/google\/syzkaller."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3564631"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179298"},{"key":"e_1_3_2_1_16_1","unstructured":"Hex-Rays. 2025. The interactive disassembler pro is a computer software disassembler which generates assembly language code from machine-executable code. https:\/\/hex-rays.com\/ida-home\/."},{"key":"e_1_3_2_1_17_1","volume-title":"USENIX Security Symposium. 2921\u20132938","author":"Jang Jisoo","year":"2023","unstructured":"Jisoo Jang, Minsuk Kang, and Dokyung Song. 2023. ReUSB: Replay-Guided USB Driver Fuzzing.. In USENIX Security Symposium. 2921\u20132938."},{"key":"e_1_3_2_1_18_1","unstructured":"k0keoyo. 2017. A kernel driver fuzzer based on ioctlbf. https:\/\/github.com\/k0keoyo\/kDriver-Fuzzer."},{"key":"e_1_3_2_1_19_1","volume-title":"Yeongjin Jang, Insik Shin, and Byoungyoung Lee.","author":"Kim Kyungtae","year":"2020","unstructured":"Kyungtae Kim, Dae R Jeong, Chung Hwan Kim, Yeongjin Jang, Insik Shin, and Byoungyoung Lee. 2020. HFL: Hybrid Fuzzing on the Linux Kernel.. In NDSS."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_3_2_1_21_1","unstructured":"koutto. 2017. Windows Kernel Drivers fuzzer. https:\/\/github.com\/koutto\/ioctlbf."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471863"},{"key":"e_1_3_2_1_23_1","unstructured":"MSDN. 2020. Windows Filtering Platform. https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/fwp\/windows-filtering-platform-start-page."},{"key":"e_1_3_2_1_24_1","unstructured":"MSDN. 2022. DeviceIoControl function (ioapiset.h). https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/ioapiset\/nf-ioapiset-deviceiocontrol."},{"key":"e_1_3_2_1_25_1","unstructured":"MSDN. 2022. InterlockedCompareExchange. https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/winnt\/nf-winnt-interlockedcompareexchange."},{"key":"e_1_3_2_1_26_1","unstructured":"MSDN. 2022. IofCompleteRequest function (wdm.h). https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/ddi\/wdm\/nf-wdm-iocompleterequest."},{"key":"e_1_3_2_1_27_1","unstructured":"MSDN. 2023. IRP_MJ_DEVICE_CONTROL. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/kernel\/irp-mj-device-control."},{"key":"e_1_3_2_1_28_1","unstructured":"MSDN. 2024. Introduction to WDM. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/kernel\/introduction-to-wdm."},{"key":"e_1_3_2_1_29_1","unstructured":"MSDN. 2024. I\/O request packets. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/gettingstarted\/i-o-request-packets."},{"key":"e_1_3_2_1_30_1","unstructured":"MSDN. 2024. NDIS driver. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/network\/ndis-drivers."},{"key":"e_1_3_2_1_31_1","unstructured":"MSDN. 2024. What is a Driver. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/gettingstarted\/what-is-a-driver-."},{"key":"e_1_3_2_1_32_1","unstructured":"MSDN. 2024. Windows Driver Frameworks. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/wdf."},{"key":"e_1_3_2_1_33_1","unstructured":"MSDN. 2024. WPP Software Tracing. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/devtest\/wpp-software-tracing."},{"key":"e_1_3_2_1_34_1","unstructured":"MSDN. 2025. Windows kernel-mode I\/O manager. https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/kernel\/windows-kernel-mode-i-o-manager."},{"key":"e_1_3_2_1_35_1","first-page":"1","article-title":"StateAFL: Greybox fuzzing for stateful network servers","volume":"27","author":"Natella Roberto","year":"2021","unstructured":"Roberto Natella. 2021. StateAFL: Greybox fuzzing for stateful network servers. Empirical Software Engineering 27 (2021), 1\u201331. https:\/\/api.semanticscholar.org\/CorpusID:238743978","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_1_36_1","unstructured":"National Institute of Standards and Technology. 2019. CVE-2019-16098 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-16098. National Vulnerability Database."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360600"},{"key":"e_1_3_2_1_38_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Pailoor Shankara","year":"2018","unstructured":"Shankara Pailoor, Andrew Aday, and Suman Jana. 2018. {MoonShine}: Optimizing {OS} fuzzer seed selection with trace distillation. In 27th USENIX Security Symposium (USENIX Security 18). 729\u2013743."},{"key":"e_1_3_2_1_39_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Peng Hui","year":"2020","unstructured":"Hui Peng and Mathias Payer. 2020. {USBFuzz}: A framework for fuzzing {USB} drivers by device emulation. In 29th USENIX Security Symposium (USENIX Security 20). 2559\u20132575."},{"key":"e_1_3_2_1_40_1","volume-title":"AFLNET: A Greybox Fuzzer for Network Protocols. 2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST) (2020","author":"Pham Van-Thuan","year":"2020","unstructured":"Van-Thuan Pham, Marcel B\u00f6hme, and Abhik Roychoudhury. 2020. AFLNET: A Greybox Fuzzer for Network Protocols. 2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST) (2020), 460\u2013465. https:\/\/api.semanticscholar.org\/CorpusID:220881956"},{"key":"e_1_3_2_1_41_1","unstructured":"Picus Security. 2022. BlackByte Ransomware Bypasses EDR Products via RTCore64.sys Abuse. https:\/\/www.picussecurity.com\/resource\/blog\/blackbyte-ransomware-bypasses-edr-products-via-rtcore64.sys-abuse."},{"key":"e_1_3_2_1_42_1","unstructured":"Sangjun. 2024. 1-Click-Fuzz: Systematically Fuzzing the Windows Kernel Driver with Symbolic Execution. https:\/\/github.com\/0dayResearchLab\/msFuzz."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00137"},{"key":"e_1_3_2_1_44_1","volume-title":"26th USENIX security symposium (USENIX Security 17). 167\u2013182.","author":"Schumilo Sergej","unstructured":"Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. {kAFL}:{Hardware-Assisted} feedback fuzzing for {OS} kernels. In 26th USENIX security symposium (USENIX Security 17). 167\u2013182."},{"key":"e_1_3_2_1_45_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Shen Zekun","year":"2022","unstructured":"Zekun Shen, Ritik Roongta, and Brendan Dolan-Gavitt. 2022. Drifuzz: Harvesting bugs in device drivers from golden seeds. In 31st USENIX Security Symposium (USENIX Security 22). 1275\u20131290."},{"key":"e_1_3_2_1_46_1","unstructured":"Linshuang Li ShiJie Xu Jianyang Song. 2022. The Next Generation of Windows Exploitation Attacking the Common Log File System. https:\/\/www.blackhat.com\/asia-22\/briefings\/schedule."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23176"},{"key":"e_1_3_2_1_48_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Song Dokyung","year":"2020","unstructured":"Dokyung Song, Felicitas Hetzelt, Jonghwan Kim, Brent Byunghoon Kang, Jean-Pierre Seifert, and Michael Franz. 2020. Agamotto: Accelerating kernel driver fuzzing with lightweight virtual machine checkpoints. In 29th USENIX Security Symposium (USENIX Security 20). 2541\u20132557."},{"key":"e_1_3_2_1_49_1","unstructured":"Sophos. 2022. Remove All The Callbacks - BlackByte Ransomware Returns. https:\/\/news.sophos.com\/en-us\/2022\/10\/04\/blackbyte-ransomware-returns\/."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477132.3483547"},{"key":"e_1_3_2_1_51_1","volume-title":"Angr-the next generation of binary analysis. In 2017 IEEE Cybersecurity Development (SecDev)","author":"Wang Fish","unstructured":"Fish Wang and Yan Shoshitaishvili. 2017. Angr-the next generation of binary analysis. In 2017 IEEE Cybersecurity Development (SecDev). IEEE, 8\u20139."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23131"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00051"},{"key":"e_1_3_2_1_54_1","unstructured":"zeze zeze. 2023. A tool that is used to hunt vulnerabilities in x64 WDM drivers. https:\/\/github.com\/zeze-zeze\/ioctlance."},{"key":"e_1_3_2_1_55_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Zhao Bodong","year":"2022","unstructured":"Bodong Zhao, Zheming Li, Shisong Qin, Zheyu Ma, Ming Yuan, Wenyu Zhu, Zhihong Tian, and Chao Zhang. 2022. {StateFuzz}: System {Call-Based} {State-Aware} linux driver fuzzing. In 31st USENIX Security Symposium (USENIX Security 22). 3273\u20133289."}],"event":{"name":"EUROSYS '26: 21st European Conference on Computer Systems","location":"McEwan Hall\/The University of Edinburgh Edinburgh Scotland UK","acronym":"EUROSYS '26","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 21st European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3767295.3803624","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T12:10:29Z","timestamp":1780661429000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3767295.3803624"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,26]]},"references-count":55,"alternative-id":["10.1145\/3767295.3803624","10.1145\/3767295"],"URL":"https:\/\/doi.org\/10.1145\/3767295.3803624","relation":{},"subject":[],"published":{"date-parts":[[2026,4,26]]},"assertion":[{"value":"2026-04-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}