{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T17:17:12Z","timestamp":1778692632730,"version":"3.51.4"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:00:00Z","timestamp":1778630400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:00:00Z","timestamp":1778630400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100012542","name":"Sichuan Province Science and Technology Support Program","doi-asserted-by":"publisher","award":["2022YFG0171"],"award-info":[{"award-number":["2022YFG0171"]}],"id":[{"id":"10.13039\/100012542","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Exploiting trusted legitimate programs for attacks is a covert technique in the field of cyber confrontation. The behavior of legitimate programs when exploited by attackers is almost indistinguishable from their normal operation, making this type of attack difficult to detect by antivirus software. The attack technique that exploits legitimate Windows kernel drivers has a stronger impact because it runs in higher privilege. Although some existing symbolic execution-based frameworks can identify such vulnerabilities, issues like path explosion and incomplete analysis of sensitive instructions still lead to analysis failures or false positives. In this paper, we present BYOVD Detector, a symbolic execution-based framework for detecting vulnerable Windows kernel drivers. BYOVD Detector uses hooks to skip functions unrelated to dispatch routine setup during driver initialization and further determines whether the results of read instructions can be returned to user programs during analysis. We evaluate BYOVD Detector on public datasets of vulnerable drivers and compare it with other symbolic execution-based frameworks. The results show that BYOVD Detector mitigates the path explosion problem, improves the success rate of finding dispatch routine by 7.2%, and reduces false positive rates by 42.9% and 40.0% when analyzing vulnerabilities in reading MSR and I\/O port instructions, respectively.<\/jats:p>","DOI":"10.1186\/s42400-025-00434-w","type":"journal-article","created":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T03:20:25Z","timestamp":1778642425000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Finding vulnerable drivers with hooking and reading result verification"],"prefix":"10.1186","volume":"9","author":[{"given":"Liang","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoyu","family":"Gao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuling","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"434_CR1","doi-asserted-by":"publisher","unstructured":"Barr-Smith F, Ugarte-Pedrero X, Graziano M, Spolaor R, Martinovic I (2021) Survivalism: Systematic analysis of windows malware living-off-the-land. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 1557\u20131574 . https:\/\/doi.org\/10.1109\/SP40001.2021.00047","DOI":"10.1109\/SP40001.2021.00047"},{"key":"434_CR2","unstructured":"Chen J, Han W, Yin M, Zeng H, Song C, Lee B, Yin H, Shin I (2022) Symsan: Time and space efficient concolic execution via dynamic data-flow analysis. In: 31st USENIX Security Symposium"},{"key":"434_CR3","unstructured":"CISA, NSA, FBI, DOE, EPA, TSA, ACSC, CCCS, NCSC-UK, NCSC-NZ: Identifying and Mitigating Living Off the Land Techniques (2024). https:\/\/www.cisa.gov\/resources-tools\/resources\/identifying-and-mitigating-living-land-techniques Accessed 2025-01-05"},{"key":"434_CR4","unstructured":"CrowdStrike: CrowdStrike 2025 Global Threat Report (2025). https:\/\/www.crowdstrike.com\/explore\/2025-global-threat-report Accessed 2025-03-14"},{"key":"434_CR5","unstructured":"Economou NA, Nissim EE (2015) Windows SMEP bypass: U=S. Ekoparty"},{"key":"434_CR6","unstructured":"ESET: LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group (2018). https:\/\/www.eset.com\/me\/whitepapers\/lojax-first-uefi-rootkit-found-in-the-wild-courtesy-of-the-sednit-group\/ Accessed 2024-03-12"},{"key":"434_CR7","unstructured":"Fewer S (2020) CVE-2020-16854 - Microsoft Windows Kernel Last Branch Record Information Disclosure Vulnerability . https:\/\/blog.relyze.com\/2020\/09\/cve-2020-16854-microsoft-windows-kernel.html Accessed 2025-06-08"},{"key":"434_CR8","doi-asserted-by":"publisher","unstructured":"Gupta R, Dresel LP, Spahn N, Vigna G, Kruegel C, Kim T (2022) Popkorn: Popping windows kernel drivers at scale. In: Proceedings of the 38th Annual Computer Security Applications Conference. ACSAC \u201922, pp. 854\u2013868. Association for Computing Machinery, New York, NY, USA . https:\/\/doi.org\/10.1145\/3564625.3564631","DOI":"10.1145\/3564625.3564631"},{"key":"434_CR9","unstructured":"gmh5225, namazso: physmem_drivers: A collection of various vulnerable (mostly physical memory exposing) drivers (2022). https:\/\/github.com\/namazso\/physmem_drivers Accessed 2024-03-12"},{"key":"434_CR10","unstructured":"Haruyama T (2022) Detect Me If You Can - Anti-Firmware Forensics. Recon 2022"},{"key":"434_CR11","unstructured":"Haruyama T (2023) Hunting Vulnerable Kernel Drivers . https:\/\/blogs.vmware.com\/security\/2023\/10\/hunting-vulnerable-kernel-drivers.html Accessed 2024-12-05"},{"key":"434_CR12","unstructured":"Hromcov\u00e1 Z, Cherepanov A (2020) InvisiMole: The hidden part of the story . https:\/\/web-assets.esetstatic.com\/wls\/2020\/06\/ESET_InvisiMole.pdf Accessed 2025-01-05"},{"key":"434_CR13","unstructured":"Haag M, Hernandez JE, Bencherchali N (2024) Living Off The Land Drivers . https:\/\/www.loldrivers.io\/ Accessed 2024-12-05"},{"key":"434_CR14","unstructured":"Hurd C (2020) TALOS-2020-1114 . https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2020-1114 Accessed 2024-03-12"},{"key":"434_CR15","unstructured":"IDontCode: MSREXEC - Elevate Arbitrary WRMSR to Kernel Execution (2021). https:\/\/blog.back.engineering\/22\/03\/2021\/ Accessed 2025-06-08"},{"issue":"7","key":"434_CR16","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1145\/360248.360252","volume":"19","author":"JC King","year":"1976","unstructured":"King JC (1976) Symbolic execution and program testing. Commun ACM 19(7):385\u2013394","journal-title":"Commun ACM"},{"key":"434_CR17","unstructured":"Lin C-Y (2023) Enhanced Vulnerability Hunting in WDM Drivers with Symbolic Execution and Taint Analysis. CODE BLUE"},{"key":"434_CR18","doi-asserted-by":"crossref","unstructured":"Li Z, Wang J, Sun M, Lui JC (2021) Mirchecker: detecting bugs in rust programs via static analysis. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 2183\u20132196","DOI":"10.1145\/3460120.3484541"},{"key":"434_CR19","unstructured":"Mattos E, Homewood R (2022) Yours Truly, Signed AV Driver: Weaponizing an Antivirus Driver . https:\/\/www.aon.com\/cyber-solutions\/aon_cyber_labs\/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver\/ Accessed 2024-03-12"},{"key":"434_CR20","unstructured":"Microsoft: Static Driver Verifier (2021). https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/devtest\/static-driver-verifier Accessed 2024-03-12"},{"key":"434_CR21","unstructured":"Microsoft: Writing Dispatch Routines (2021). https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/kernel\/writing-dispatch-routines Accessed 2025-03-20"},{"key":"434_CR22","unstructured":"Microsoft: Driver Verifier (2023). https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/devtest\/driver-verifier Accessed 2024-03-12"},{"key":"434_CR23","unstructured":"Microsoft: Microsoft recommended driver block rules (2024). https:\/\/learn.microsoft.com\/en-us\/windows\/security\/application-security\/application-control\/windows-defender-application-control\/design\/microsoft-recommended-driver-block-rules Accessed 2024-03-12"},{"key":"434_CR24","unstructured":"Michael J, Shkatov M (2019) Get off the kernel if you can\u2019t drive. DEFCON"},{"key":"434_CR25","doi-asserted-by":"publisher","unstructured":"Ning R, Bu W, Yang J, Duan S (2023) A survey of detection methods research on living-off-the-land techniques. In: 2023 IEEE International Conference on Sensors, Electronics and Computer Engineering (ICSECE), pp. 159\u2013164 . https:\/\/doi.org\/10.1109\/ICSECE58870.2023.10263445","DOI":"10.1109\/ICSECE58870.2023.10263445"},{"key":"434_CR26","doi-asserted-by":"publisher","unstructured":"Ongun T, Stokes JW, Or JB, Tian K, Tajaddodianfar F, Neil J, Seifert C, Oprea A, Platt JC (2021) Living-off-the-land command detection using active learning. In: Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses. RAID \u201921, pp. 442\u2013455. Association for Computing Machinery, New York, NY, USA . https:\/\/doi.org\/10.1145\/3471621.3471858","DOI":"10.1145\/3471621.3471858"},{"key":"434_CR27","unstructured":"Poeplau S, Francillon A (2020) Symbolic execution with $$\\{$$SymCC$$\\}$$: Don\u2019t interpret, compile! In: 29th USENIX Security Symposium (USENIX Security 20), pp. 181\u2013198"},{"key":"434_CR28","doi-asserted-by":"crossref","unstructured":"Poeplau S, Francillon A (2021) Symqemu: Compilation-based symbolic execution for binaries. In: Ndss 2021, Network and Distributed System Security Symposium . Internet Society","DOI":"10.14722\/ndss.2021.24118"},{"key":"434_CR29","unstructured":"Ren Y (2025) Stratified Sampling Labelled Dataset for Windows Kernel Driver Binary . https:\/\/gitee.com\/li502\/driver_dataset Accessed 2025-01-03"},{"key":"434_CR30","doi-asserted-by":"publisher","unstructured":"Sen K (2007) Concolic testing. In: Proceedings of the 22nd IEEE\/ACM International Conference on Automated Software Engineering. ASE \u201907, pp. 571\u2013572. Association for Computing Machinery, New York, NY, USA . https:\/\/doi.org\/10.1145\/1321631.1321746","DOI":"10.1145\/1321631.1321746"},{"key":"434_CR31","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili Y, Wang R, Salls C, Stephens N, Polino M, Dutcher A, Grosen J, Feng S, Hauser C, Kruegel C, Vigna G (2016) SoK: (State of) The Art of War: Offensive Techniques in Binary Analysis. In: IEEE Symposium on Security and Privacy","DOI":"10.1109\/SP.2016.17"},{"key":"434_CR32","unstructured":"Warns R, Harrison T (2019) Device Driver Debauchery and MSR Madness. INFILTRATE"},{"key":"434_CR33","doi-asserted-by":"publisher","unstructured":"Wang Q, Hassan W, Li D, Jee K, Yu X, Zou K, Rhee J, Chen Z, Cheng W, Gunter CA, Chen H (2020) You are what you do: Hunting stealthy malware via data provenance analysis. In: Network and Distributed System Security Symposium . https:\/\/doi.org\/10.14722\/ndss.2020.24167","DOI":"10.14722\/ndss.2020.24167"},{"key":"434_CR34","unstructured":"Yun I, Lee S, Xu M, Jang Y, Kim T (2018) $$\\{$$QSYM$$\\}$$: A practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 745\u2013761"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00434-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00434-w","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00434-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T16:49:03Z","timestamp":1778690943000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00434-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,13]]},"references-count":34,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["434"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00434-w","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,13]]},"assertion":[{"value":"8 January 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 June 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no Conflict of interest to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"166"}}