{"id":"https://openalex.org/W4252890599","doi":"https://doi.org/10.1109/cgo.2015.7054189","title":"Getting in control of your control flow with control-data isolation","display_name":"Getting in control of your control flow with control-data isolation","publication_year":2015,"publication_date":"2015-02-01","ids":{"openalex":"https://openalex.org/W4252890599","doi":"https://doi.org/10.1109/cgo.2015.7054189"},"language":"en","primary_location":{"id":"doi:10.1109/cgo.2015.7054189","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cgo.2015.7054189","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 IEEE/ACM International Symposium on Code Generation and Optimization (CGO)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056939927","display_name":"William Arthur","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"William Arthur","raw_affiliation_strings":["University of Michigan"],"affiliations":[{"raw_affiliation_string":"University of Michigan","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076718053","display_name":"Ben Mehne","orcid":null},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ben Mehne","raw_affiliation_strings":["University of California - Berkeley"],"affiliations":[{"raw_affiliation_string":"University of California - Berkeley","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027544576","display_name":"Reetuparna Das","orcid":"https://orcid.org/0000-0002-5894-8342"},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Reetuparna Das","raw_affiliation_strings":["University of Michigan"],"affiliations":[{"raw_affiliation_string":"University of Michigan","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5113456715","display_name":"Todd Austin","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan\u2013Ann Arbor","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Todd Austin","raw_affiliation_strings":["University of Michigan"],"affiliations":[{"raw_affiliation_string":"University of Michigan","institution_ids":["https://openalex.org/I27837315"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5056939927"],"corresponding_institution_ids":["https://openalex.org/I27837315"],"apc_list":null,"apc_paid":null,"fwci":1.2943,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":{"value":0.87439223,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"79","last_page":"90"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10478","display_name":"Diamond and Carbon-based Materials Research","score":0.983299970626831,"subfield":{"id":"https://openalex.org/subfields/2505","display_name":"Materials Chemistry"},"field":{"id":"https://openalex.org/fields/25","display_name":"Materials Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8055639266967773},{"id":"https://openalex.org/keywords/control-flow","display_name":"Control flow","score":0.7010861039161682},{"id":"https://openalex.org/keywords/attack-surface","display_name":"Attack surface","score":0.6887522339820862},{"id":"https://openalex.org/keywords/programmer","display_name":"Programmer","score":0.679032564163208},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6743012070655823},{"id":"https://openalex.org/keywords/isolation","display_name":"Isolation (microbiology)","score":0.6597079634666443},{"id":"https://openalex.org/keywords/heap","display_name":"Heap (data structure)","score":0.5029847025871277},{"id":"https://openalex.org/keywords/data-flow-diagram","display_name":"Data flow diagram","score":0.45734095573425293},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4535759687423706},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.43775051832199097},{"id":"https://openalex.org/keywords/data-structure","display_name":"Data structure","score":0.4107050597667694},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.3986409902572632},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.36551862955093384},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.34965288639068604},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.24121630191802979},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.16087159514427185}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8055639266967773},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.7010861039161682},{"id":"https://openalex.org/C2776576444","wikidata":"https://www.wikidata.org/wiki/Q303569","display_name":"Attack surface","level":2,"score":0.6887522339820862},{"id":"https://openalex.org/C2778514511","wikidata":"https://www.wikidata.org/wiki/Q1374194","display_name":"Programmer","level":2,"score":0.679032564163208},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6743012070655823},{"id":"https://openalex.org/C2775941552","wikidata":"https://www.wikidata.org/wiki/Q25212305","display_name":"Isolation (microbiology)","level":2,"score":0.6597079634666443},{"id":"https://openalex.org/C134757568","wikidata":"https://www.wikidata.org/wiki/Q274089","display_name":"Heap (data structure)","level":2,"score":0.5029847025871277},{"id":"https://openalex.org/C489000","wikidata":"https://www.wikidata.org/wiki/Q747385","display_name":"Data flow diagram","level":2,"score":0.45734095573425293},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4535759687423706},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.43775051832199097},{"id":"https://openalex.org/C162319229","wikidata":"https://www.wikidata.org/wiki/Q175263","display_name":"Data structure","level":2,"score":0.4107050597667694},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.3986409902572632},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.36551862955093384},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.34965288639068604},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.24121630191802979},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.16087159514427185},{"id":"https://openalex.org/C89423630","wikidata":"https://www.wikidata.org/wiki/Q7193","display_name":"Microbiology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cgo.2015.7054189","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cgo.2015.7054189","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 IEEE/ACM International Symposium on Code Generation and Optimization (CGO)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W1537077670","https://openalex.org/W1816718056","https://openalex.org/W1823377586","https://openalex.org/W1994742583","https://openalex.org/W2004769014","https://openalex.org/W2013137740","https://openalex.org/W2022911909","https://openalex.org/W2051600169","https://openalex.org/W2063551937","https://openalex.org/W2064452120","https://openalex.org/W2074943483","https://openalex.org/W2093760065","https://openalex.org/W2108744354","https://openalex.org/W2110792065","https://openalex.org/W2117115928","https://openalex.org/W2119971343","https://openalex.org/W2121468041","https://openalex.org/W2122403474","https://openalex.org/W2138517425","https://openalex.org/W2142937557","https://openalex.org/W2146431583","https://openalex.org/W2156620605","https://openalex.org/W2158974202","https://openalex.org/W2159059513","https://openalex.org/W2171929398","https://openalex.org/W4246166885","https://openalex.org/W6632150593","https://openalex.org/W6638487575","https://openalex.org/W6638559843","https://openalex.org/W6677520968","https://openalex.org/W6680659772","https://openalex.org/W6681106990","https://openalex.org/W6685102819"],"related_works":["https://openalex.org/W2120421136","https://openalex.org/W2889297400","https://openalex.org/W156668154","https://openalex.org/W2205960273","https://openalex.org/W2095925360","https://openalex.org/W1549956274","https://openalex.org/W4246377515","https://openalex.org/W2052160877","https://openalex.org/W2235158524","https://openalex.org/W4252890599"],"abstract_inverted_index":{"Computer":[0],"security":[1],"has":[2,14],"become":[3],"a":[4,24,46,94,167,203],"central":[5],"focus":[6],"in":[7,149],"the":[8,42,59,74,77,86,106,109,115,171,185,188],"information":[9],"age.":[10],"Though":[11],"enormous":[12],"effort":[13],"been":[15],"expended":[16],"on":[17,41,128],"ensuring":[18],"secure":[19],"computation,":[20],"software":[21,28],"exploitation":[22],"remains":[23],"serious":[25],"threat.":[26],"The":[27],"attack":[29],"surface":[30],"provides":[31,101],"many":[32],"avenues":[33],"for":[34,202],"hijacking;":[35],"however,":[36],"most":[37],"exploits":[38],"ultimately":[39],"rely":[40],"successful":[43],"execution":[44],"of":[45,52,61,76,108,114,174,187,198,206],"control-flow":[47,70,158,176],"attack.":[48],"This":[49],"pervasive":[50],"diversion":[51],"control":[53,62],"flow":[54,63],"is":[55,82],"made":[56],"possible":[57],"by":[58,103,160],"pollution":[60],"structure":[64],"with":[65],"attacker-injected":[66],"runtime":[67,80,119],"data.":[68],"Many":[69],"attacks":[71,139,147,159],"persist":[72],"because":[73],"root":[75,107],"problem":[78,110],"remains:":[79],"data":[81,120],"allowed":[83],"to":[84,105,138],"enter":[85],"program":[87,122],"counter.":[88],"In":[89],"this":[90],"paper,":[91],"we":[92],"propose":[93],"novel":[95],"approach:":[96],"Control-Data":[97],"Isolation.":[98],"Our":[99],"approach":[100],"protection":[102],"going":[104],"and":[111,132,148],"removing":[112],"all":[113],"operations":[116],"that":[117,180],"inject":[118],"into":[121],"control.":[123],"While":[124],"previous":[125],"work":[126,165],"relies":[127],"CFG":[129,190],"edge":[130],"checking":[131],"labeling,":[133],"these":[134],"techniques":[135],"remain":[136],"vulnerable":[137],"such":[140],"as":[141],"heap":[142],"spray,":[143],"read,":[144],"or":[145],"GOT":[146],"some":[150],"cases":[151],"suffer":[152],"high":[153],"overheads.":[154],"Rather":[155],"than":[156,200],"addressing":[157],"layering":[161],"additional":[162],"complexity,":[163],"our":[164],"takes":[166],"subtractive":[168],"approach;":[169],"subtracting":[170],"primary":[172],"cause":[173],"contemporary":[175],"attacks.":[177],"We":[178],"demonstrate":[179],"control-data":[181],"isolation":[182],"can":[183],"assure":[184],"integrity":[186],"programmer's":[189],"at":[191],"runtime,":[192],"while":[193],"incurring":[194],"average":[195],"performance":[196],"overheads":[197],"less":[199],"7%":[201],"wide":[204],"range":[205],"benchmarks.":[207]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2},{"year":2019,"cited_by_count":4},{"year":2017,"cited_by_count":2},{"year":2015,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
