{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:45:43Z","timestamp":1760060743806,"version":"build-2065373602"},"reference-count":32,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T00:00:00Z","timestamp":1758672000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100010880","name":"State Grid Corporation of China","doi-asserted-by":"publisher","award":["5700202458225A-1-1-ZN"],"award-info":[{"award-number":["5700202458225A-1-1-ZN"]}],"id":[{"id":"10.13039\/501100010880","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Multi-variant execution (MVX) is an active defense technique that can detect unknown attacks by comparing the outputs of redundant program variants. Despite notable progress in MVX techniques in recent years, current approaches for recovery of abnormal variants still face fundamental challenges, including state inconsistency, low recovery efficiency, and service disruption of an MVX system. Therefore, a record\u2013replay-based state recovery approach for variants in MVX systems is proposed in this paper. First, a Syscall Coordinator (SSC), composed of a recording module, a classification module, and a replay module, is designed to enable state recovery of variants. Then, a synchronization and voting algorithm is presented. When an anomaly is identified through voting, the abnormal variant is handed over to the SSC for state recovery, while the Synchronization Queue is updated accordingly. Furthermore, to ensure uninterrupted system service, we introduce a parallel grouped recovery mechanism, which enables the execution of normal variants and the recovery of abnormal variants to run in parallel. Experimental results on SPEC CPU 2006 benchmark and server applications show that the proposed approach achieves low overhead in both the recording and replay phases while maintaining high state recovery accuracy and supports uninterrupted system service.<\/jats:p>","DOI":"10.3390\/info16100826","type":"journal-article","created":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T10:39:42Z","timestamp":1758710382000},"page":"826","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Record\u2013Replay-Based State Recovery Approach for Variants in an MVX System"],"prefix":"10.3390","volume":"16","author":[{"given":"Xu","family":"Zhong","sequence":"first","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinjian","family":"Zhao","sequence":"additional","affiliation":[{"name":"State Grid Jiangsu Electric Power Co., Ltd., Information & Telecommunication Branch, Nanjing 210024, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Grid Laboratory of Power Cyber-Security Protection and Monitoring Technology, China Electric Power Research Institute Co., Ltd., Nanjing 210003, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1967-7743","authenticated-orcid":false,"given":"June","family":"Li","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yifan","family":"Wang","sequence":"additional","affiliation":[{"name":"Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Li","sequence":"additional","affiliation":[{"name":"Purple Mountain Laboratories, Nanjing 211111, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,9,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1287\/isre.2017.0722","article-title":"Software diversity for improved network security: Optimal distribution of software-based shared vulnerabilities","volume":"28","author":"Temizkan","year":"2017","journal-title":"Inf. Syst. Res."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/MS.2020.3045817","article-title":"The diversity crisis in software development","volume":"38","author":"Albusays","year":"2021","journal-title":"IEEE Softw."},{"key":"ref_3","unstructured":"Cox, B., Evans, D., Filipi, A., Rowanhill, J., Hu, W., Davidson, J., Knight, J., Nguyen-Tuong, A., and Hiser, J. (2006, January 31). N-Variant Systems: A Secretless Framework for Security through Diversity. Proceedings of the 15th USENIX Security Symposium, Vancouver, BC, Canada."},{"key":"ref_4","first-page":"77","article-title":"A Survey on Multi-Variant Execution Security Defense Technology","volume":"5","author":"Yao","year":"2020","journal-title":"J. Cyber Secur."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"101677","DOI":"10.1016\/j.cose.2019.101677","article-title":"Cybersecurity for industrial control systems: A survey","volume":"89","author":"Bhamare","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1177\/03063127211048515","article-title":"Systemic failures and organizational risk management in algorithmic trading: Normal accidents and high reliability in financial markets","volume":"52","author":"Min","year":"2022","journal-title":"Soc. Stud. Sci."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1016\/j.infsof.2018.06.005","article-title":"A case study on software vulnerability coordination","volume":"103","author":"Ruohonen","year":"2018","journal-title":"Inf. Softw. Technol."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1360\/SSI-2021-0272","article-title":"Development paradigms of cyberspace endogenous safety and security","volume":"52","author":"Wu","year":"2022","journal-title":"Sci. Sin. Informationis"},{"key":"ref_9","first-page":"2","article-title":"An Attack Feedback Dynamic Scheduling Strategy Based on Endogenous Security","volume":"9","author":"Chen","year":"2023","journal-title":"J. Inf. Secur. Res."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Goktas, E., Kollenda, B., Koppe, P., Bosman, E., Portokalidis, G., Holz, T., Bos, H., and Giuffrida, C. (2018, January 24\u201326). Position-independent code reuse: On the effectiveness of aslr in the absence of information disclosure. Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), London, UK.","DOI":"10.1109\/EuroSP.2018.00024"},{"key":"ref_11","first-page":"275","article-title":"Diversified Compilation Method Based on LLVM","volume":"51","author":"Chen","year":"2025","journal-title":"Comput. Eng."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"129032","DOI":"10.1109\/ACCESS.2021.3111735","article-title":"An optimal seed scheduling strategy algorithm applied to cyberspace mimic defense","volume":"9","author":"Chen","year":"2021","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"188760","DOI":"10.1109\/ACCESS.2020.3031323","article-title":"Conditional Probability Voting Algorithm Based on Heterogeneity of Mimic Defense System","volume":"8","author":"Wei","year":"2020","journal-title":"IEEE Access"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Salamat, B., Jackson, T., Gal, A., and Franz, M. (2009, January 1\u20133). Orchestra: Intrusion detection using parallel execution and monitoring of program variants in user-space. Proceedings of the 4th ACM European Conference on Computer Systems, Nuremberg, Germany.","DOI":"10.1145\/1519065.1519071"},{"key":"ref_15","unstructured":"Volckaert, S., Coppens, B., Voulimeneas, A., Homescu, A., Larsen, P., De Sutter, B., and Franz, M. (2017, January 12\u201314). Secure and efficient application monitoring and replication. Proceedings of the 2016 USENIX Annual Technical Conference (USENIX ATC 16), Santa Clara, CA, USA."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Volckaert, S., Coppens, B., De Sutter, B., De Bosschere, K., Larsen, P., and Franz, M. (2017, January 23\u201326). Taming parallelism in a multi-variant execution environment. Proceedings of the Twelfth European Conference on Computer Systems, Belgrade, Serbia.","DOI":"10.1145\/3064176.3064178"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"339","DOI":"10.1145\/2786763.2694390","article-title":"Varan the unbelievable: An efficient n-version execution framework","volume":"43","author":"Hosek","year":"2015","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Koning, K., Bos, H., and Giuffrida, C. (July, January 28). Secure and efficient multi-variant execution using hardware-assisted process virtualization. Proceedings of the 2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), Toulouse, France.","DOI":"10.1109\/DSN.2016.46"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Yeoh, S., Wang, X., Jang, J.-W., and Ravindran, B. (2024, January 2\u20136). sMVX: Multi-Variant Execution on Selected Code Paths. Proceedings of the 25th International Middleware Conference, Hong Kong, China.","DOI":"10.1145\/3652892.3654794"},{"key":"ref_20","first-page":"44","article-title":"MVX-CFI: A practical active defense framework for software security","volume":"5","author":"Yao","year":"2020","journal-title":"J. Cyber Secur."},{"key":"ref_21","first-page":"37","article-title":"Method against process control-flow hijacking based on mimic defense","volume":"42","author":"Pan","year":"2021","journal-title":"J. Commun."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1641","DOI":"10.1145\/3689769","article-title":"Jmvx: Fast Multi-threaded Multi-version Execution and Record-Replay for Managed Languages","volume":"8","author":"Schwartz","year":"2024","journal-title":"Proc. ACM Program. Lang."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Cao, J., Arya, K., Garg, R., Matott, S., Panda, D.K., Subramoni, H., Vienne, J., and Cooperman, G. (2016, January 13\u201316). System-level scalable checkpoint-restart for petascale computing. Proceedings of the 2016 IEEE 22nd International Conference on Parallel and Distributed Systems (ICPADS), Wuhan, China.","DOI":"10.1109\/ICPADS.2016.0125"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"2603","DOI":"10.1134\/S1995080220120355","article-title":"Checkpointing Tools in a Supercomputer Center","volume":"41","author":"Savin","year":"2020","journal-title":"Lobachevskii J. Math."},{"key":"ref_25","unstructured":"CRIU. Available online: https:\/\/criu.org\/Main_Page."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"693","DOI":"10.1145\/3093336.3037751","article-title":"Towards practical default-on multi-core record\/replay","volume":"52","author":"Mashtizadeh","year":"2017","journal-title":"ACM SIGPLAN Not."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Laadan, O., Viennot, N., and Nieh, J. (2010, January 14\u201318). Transparent, lightweight application execution replay on commodity multiprocessor operating systems. Proceedings of the 2010 ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems, New York, NY, USA.","DOI":"10.1145\/1811039.1811057"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Lidbury, C., and Donaldson, A.F. (2019, January 22\u201326). Sparse record and replay with controlled scheduling. Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation, Phoenix, AZ, USA.","DOI":"10.1145\/3314221.3314635"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"160","DOI":"10.1109\/TDSC.2018.2878234","article-title":"Stopping memory disclosures via diversification and replicated execution","volume":"18","author":"Lu","year":"2018","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"437","DOI":"10.1109\/TDSC.2015.2411254","article-title":"Cloning your Gadgets:Complete ROP Attack Immunity with Multi-Variant Execution","volume":"13","author":"Volckaert","year":"2016","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_31","unstructured":"Matthew, M., and David, B. (2010, January 8\u201310). TACHYON: Tandem execution for efficient live patch testing. Proceedings of the 21st USENIX Conference on Security Symposium (Security\u201912), Bellevue, WA, USA."},{"key":"ref_32","unstructured":"Zhou, D., and Tamir, Y. (2021). Hycor: Fault-tolerant replicated containers based on checkpoint and replay. arXiv."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/16\/10\/826\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:48:45Z","timestamp":1760035725000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/16\/10\/826"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,24]]},"references-count":32,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2025,10]]}},"alternative-id":["info16100826"],"URL":"https:\/\/doi.org\/10.3390\/info16100826","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2025,9,24]]}}}