{"id":"https://openalex.org/W2006419855","doi":"https://doi.org/10.1145/1217935.1217939","title":"Practical taint-based protection using demand emulation","display_name":"Practical taint-based protection using demand emulation","publication_year":2006,"publication_date":"2006-04-18","ids":{"openalex":"https://openalex.org/W2006419855","doi":"https://doi.org/10.1145/1217935.1217939","mag":"2006419855"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1217935.1217939","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://www.cs.ubc.ca/~andy/papers/taint-eurosys06.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5005883880","display_name":"Alex Ho","orcid":null},"institutions":[{"id":"https://openalex.org/I4210096386","display_name":"Bridge University","ror":"https://ror.org/00cbm0437","country_code":"SS","type":"education","lineage":["https://openalex.org/I4210096386"]},{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB","SS"],"is_corresponding":false,"raw_author_name":"Alex Ho","raw_affiliation_strings":["University of Cambridge, Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge, Cambridge","institution_ids":["https://openalex.org/I4210096386","https://openalex.org/I241749"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068938307","display_name":"Michael Fetterman","orcid":null},"institutions":[{"id":"https://openalex.org/I1343180700","display_name":"Intel (United States)","ror":"https://ror.org/01ek73717","country_code":"US","type":"company","lineage":["https://openalex.org/I1343180700"]},{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB","US"],"is_corresponding":false,"raw_author_name":"Michael Fetterman","raw_affiliation_strings":["University of Cambridge, Cambridge and Intel Research Cambridge, Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge, Cambridge and Intel Research Cambridge, Cambridge","institution_ids":["https://openalex.org/I1343180700","https://openalex.org/I241749"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041925933","display_name":"Christopher J. Clark","orcid":"https://orcid.org/0000-0001-7943-9291"},"institutions":[{"id":"https://openalex.org/I4210096386","display_name":"Bridge University","ror":"https://ror.org/00cbm0437","country_code":"SS","type":"education","lineage":["https://openalex.org/I4210096386"]},{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB","SS"],"is_corresponding":false,"raw_author_name":"Christopher Clark","raw_affiliation_strings":["University of Cambridge, Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge, Cambridge","institution_ids":["https://openalex.org/I4210096386","https://openalex.org/I241749"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002059431","display_name":"Andrew Warfield","orcid":null},"institutions":[{"id":"https://openalex.org/I4210096386","display_name":"Bridge University","ror":"https://ror.org/00cbm0437","country_code":"SS","type":"education","lineage":["https://openalex.org/I4210096386"]},{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB","SS"],"is_corresponding":false,"raw_author_name":"Andrew Warfield","raw_affiliation_strings":["University of Cambridge, Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge, Cambridge","institution_ids":["https://openalex.org/I4210096386","https://openalex.org/I241749"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5087961508","display_name":"Steven Hand","orcid":"https://orcid.org/0000-0002-6357-3629"},"institutions":[{"id":"https://openalex.org/I4210096386","display_name":"Bridge University","ror":"https://ror.org/00cbm0437","country_code":"SS","type":"education","lineage":["https://openalex.org/I4210096386"]},{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB","SS"],"is_corresponding":false,"raw_author_name":"Steven Hand","raw_affiliation_strings":["University of Cambridge, Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge, Cambridge","institution_ids":["https://openalex.org/I4210096386","https://openalex.org/I241749"]}]}],"institution_assertions":[],"countries_distinct_count":3,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":11.052,"has_fulltext":false,"cited_by_count":187,"citation_normalized_percentile":{"value":0.999859,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"29","last_page":"41"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9988,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9903,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/taint-checking","display_name":"Taint checking","score":0.7434517},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4677774},{"id":"https://openalex.org/keywords/rootkit","display_name":"Rootkit","score":0.42268175}],"concepts":[{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.90946615},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.85152924},{"id":"https://openalex.org/C63116202","wikidata":"https://www.wikidata.org/wiki/Q7676227","display_name":"Taint checking","level":3,"score":0.7434517},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.6148639},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5836426},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5660429},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.51809925},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.47195923},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4677774},{"id":"https://openalex.org/C89992363","wikidata":"https://www.wikidata.org/wiki/Q5961558","display_name":"Track (disk drive)","level":2,"score":0.42965347},{"id":"https://openalex.org/C10144332","wikidata":"https://www.wikidata.org/wiki/Q14645","display_name":"Rootkit","level":3,"score":0.42268175},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.32571617},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.21064293},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C50522688","wikidata":"https://www.wikidata.org/wiki/Q189833","display_name":"Economic growth","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1217935.1217939","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.86.8484","pdf_url":"http://www.cs.ubc.ca/~andy/papers/taint-eurosys06.pdf","source":{"id":"https://openalex.org/S4306400349","display_name":"CiteSeer X (The Pennsylvania State University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I130769515","host_organization_name":"Pennsylvania State University","host_organization_lineage":["https://openalex.org/I130769515"],"host_organization_lineage_names":["Pennsylvania State University"],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.86.8484","pdf_url":"http://www.cs.ubc.ca/~andy/papers/taint-eurosys06.pdf","source":{"id":"https://openalex.org/S4306400349","display_name":"CiteSeer X (The Pennsylvania State University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I130769515","host_organization_name":"Pennsylvania State University","host_organization_lineage":["https://openalex.org/I130769515"],"host_organization_lineage_names":["Pennsylvania State University"],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"display_name":"Peace, justice, and strong institutions","score":0.41,"id":"https://metadata.un.org/sdg/16"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":33,"referenced_works":["https://openalex.org/W146660932","https://openalex.org/W1499057083","https://openalex.org/W1499241274","https://openalex.org/W1508196346","https://openalex.org/W1511560695","https://openalex.org/W1522250664","https://openalex.org/W192953227","https://openalex.org/W1997269120","https://openalex.org/W2006816934","https://openalex.org/W2066583243","https://openalex.org/W2089821795","https://openalex.org/W2098809490","https://openalex.org/W2100666033","https://openalex.org/W2100673955","https://openalex.org/W2102970979","https://openalex.org/W2103919170","https://openalex.org/W2107089133","https://openalex.org/W2117115928","https://openalex.org/W2120230074","https://openalex.org/W2121542813","https://openalex.org/W2131726714","https://openalex.org/W2133217855","https://openalex.org/W2148613020","https://openalex.org/W2154766204","https://openalex.org/W2161433768","https://openalex.org/W2162568437","https://openalex.org/W2165100126","https://openalex.org/W2168264487","https://openalex.org/W2914982603","https://openalex.org/W4231945399","https://openalex.org/W4235021791","https://openalex.org/W4244704438","https://openalex.org/W4254762831"],"related_works":["https://openalex.org/W4384155508","https://openalex.org/W3202286589","https://openalex.org/W2923974490","https://openalex.org/W2379630539","https://openalex.org/W2147794177","https://openalex.org/W2135398928","https://openalex.org/W2034507087","https://openalex.org/W1994747466","https://openalex.org/W1858426298","https://openalex.org/W125046873"],"abstract_inverted_index":{"Many":[0],"software":[1],"attacks":[2],"are":[3,87],"based":[4],"on":[5],"injecting":[6],"malicious":[7],"code":[8],"into":[9],"a":[10,19,35,75],"target":[11],"host.":[12],"This":[13],"paper":[14],"demonstrates":[15,69],"the":[16,29,54,70,114,118,136],"use":[17],"of":[18],"well-known":[20],"technique,":[21,85],"data":[22,26,51,109,133,163],"tainting,":[23],"to":[24,38,45,72,89,124],"track":[25,49],"received":[27,134],"from":[28,135,151],"network":[30,137],"as":[31,102],"it":[32,144],"propagates":[33],"through":[34],"system":[36,55,77],"and":[37,80,121,128,148],"prevent":[39],"its":[40],"execution.":[41,82],"Unlike":[42],"past":[43],"approaches":[44],"taint":[46,126,162],"tracking,":[47],"which":[48],"tainted":[50,108],"by":[52,113],"running":[53,76],"completely":[56],"in":[57,63,99],"an":[58],"emulator":[59],"or":[60],"simulator,":[61],"resulting":[62],"considerable":[64],"execution":[65],"overhead,":[66],"our":[67],"work":[68],"ability":[71],"dynamically":[73],"switch":[74],"between":[78],"virtualized":[79],"emulated":[81],"Using":[83],"this":[84],"we":[86,130],"able":[88],"explore":[90],"hardware":[91],"support":[92,125],"for":[93,158],"taint-based":[94],"protection":[95],"that":[96,132],"is":[97,104,110,145,164],"deployable":[98],"real-world":[100],"situations,":[101],"emulation":[103],"only":[105],"used":[106],"when":[107],"being":[111],"processed":[112],"CPU.":[115],"By":[116],"modifying":[117],"CPU,":[119],"memory,":[120],"I/O":[122],"devices":[123],"tracking":[127],"protection,":[129],"guarantee":[131],"may":[138],"not":[139],"be":[140],"executed,":[141],"even":[142],"if":[143],"written":[146],"to,":[147],"later":[149],"read":[150],"disk.":[152],"We":[153],"demonstrate":[154],"near":[155],"native":[156],"speeds":[157],"workloads":[159],"where":[160],"little":[161],"present.":[165]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2006419855","counts_by_year":[{"year":2024,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":7},{"year":2018,"cited_by_count":2},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":13},{"year":2015,"cited_by_count":9},{"year":2014,"cited_by_count":10},{"year":2013,"cited_by_count":10},{"year":2012,"cited_by_count":25}],"updated_date":"2024-12-11T06:01:56.493821","created_date":"2016-06-24"}