{"id":"https://openalex.org/W4307208325","doi":"https://doi.org/10.1109/csf54842.2022.9919645","title":"Proving full-system security properties under multiple attacker models on capability machines","display_name":"Proving full-system security properties under multiple attacker models on capability machines","publication_year":2022,"publication_date":"2022-08-01","ids":{"openalex":"https://openalex.org/W4307208325","doi":"https://doi.org/10.1109/csf54842.2022.9919645"},"language":"en","primary_location":{"id":"doi:10.1109/csf54842.2022.9919645","is_oa":false,"landing_page_url":"https://doi.org/10.1109/csf54842.2022.9919645","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE 35th Computer Security Foundations Symposium (CSF)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://lirias.kuleuven.be/handle/20.500.12942/705681","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5064318003","display_name":"Thomas Van Strydonck","orcid":"https://orcid.org/0000-0002-5262-1381"},"institutions":[{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"education","lineage":["https://openalex.org/I99464096"]}],"countries":["BE"],"is_corresponding":true,"raw_author_name":"Thomas Van Strydonck","raw_affiliation_strings":["KU Leuven"],"affiliations":[{"raw_affiliation_string":"KU Leuven","institution_ids":["https://openalex.org/I99464096"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041169923","display_name":"A\u00efna Linn Georges","orcid":"https://orcid.org/0000-0002-5951-4642"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"A\u00efna Linn Georges","raw_affiliation_strings":["Aarhus University"],"affiliations":[{"raw_affiliation_string":"Aarhus University","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043705983","display_name":"Arma\u00ebl Gu\u00e9neau","orcid":"https://orcid.org/0000-0003-3072-4045"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Arma\u00ebl Gueneau","raw_affiliation_strings":["Aarhus University"],"affiliations":[{"raw_affiliation_string":"Aarhus University","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014999933","display_name":"Alix Trieu","orcid":"https://orcid.org/0000-0002-8239-8125"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Alix Trieu","raw_affiliation_strings":["Aarhus University"],"affiliations":[{"raw_affiliation_string":"Aarhus University","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030831735","display_name":"Amin Timany","orcid":"https://orcid.org/0000-0002-2237-851X"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Amin Timany","raw_affiliation_strings":["Aarhus University"],"affiliations":[{"raw_affiliation_string":"Aarhus University","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008329832","display_name":"Frank Piessens","orcid":"https://orcid.org/0000-0001-5438-153X"},"institutions":[{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"education","lineage":["https://openalex.org/I99464096"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Frank Piessens","raw_affiliation_strings":["KU Leuven"],"affiliations":[{"raw_affiliation_string":"KU Leuven","institution_ids":["https://openalex.org/I99464096"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055959064","display_name":"Lars Birkedal","orcid":"https://orcid.org/0000-0003-1320-0098"},"institutions":[{"id":"https://openalex.org/I204337017","display_name":"Aarhus University","ror":"https://ror.org/01aj84f44","country_code":"DK","type":"education","lineage":["https://openalex.org/I204337017"]}],"countries":["DK"],"is_corresponding":false,"raw_author_name":"Lars Birkedal","raw_affiliation_strings":["Aarhus University"],"affiliations":[{"raw_affiliation_string":"Aarhus University","institution_ids":["https://openalex.org/I204337017"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5011654888","display_name":"Dominique Devriese","orcid":"https://orcid.org/0000-0002-3862-6856"},"institutions":[{"id":"https://openalex.org/I99464096","display_name":"KU Leuven","ror":"https://ror.org/05f950310","country_code":"BE","type":"education","lineage":["https://openalex.org/I99464096"]},{"id":"https://openalex.org/I13469542","display_name":"Vrije Universiteit Brussel","ror":"https://ror.org/006e5kg04","country_code":"BE","type":"education","lineage":["https://openalex.org/I13469542"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Dominique Devriese","raw_affiliation_strings":["Vrije Universiteit,KU Leuven,Brussel","KU Leuven, Vrije Universiteit, Brussel"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit,KU Leuven,Brussel","institution_ids":["https://openalex.org/I13469542","https://openalex.org/I99464096"]},{"raw_affiliation_string":"KU Leuven, Vrije Universiteit, Brussel","institution_ids":["https://openalex.org/I13469542","https://openalex.org/I99464096"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5064318003"],"corresponding_institution_ids":["https://openalex.org/I99464096"],"apc_list":null,"apc_paid":null,"fwci":0.9655,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.79849383,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"80","last_page":"95"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10478","display_name":"Diamond and Carbon-based Materials Research","score":0.9833999872207642,"subfield":{"id":"https://openalex.org/subfields/2505","display_name":"Materials Chemistry"},"field":{"id":"https://openalex.org/fields/25","display_name":"Materials Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9797999858856201,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8621327877044678},{"id":"https://openalex.org/keywords/trusted-computing-base","display_name":"Trusted computing base","score":0.8339397311210632},{"id":"https://openalex.org/keywords/trusted-computing","display_name":"Trusted Computing","score":0.5047682523727417},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4921666979789734},{"id":"https://openalex.org/keywords/modular-design","display_name":"Modular design","score":0.4858645796775818},{"id":"https://openalex.org/keywords/code-reuse","display_name":"Code reuse","score":0.47367554903030396},{"id":"https://openalex.org/keywords/computer-security-model","display_name":"Computer security model","score":0.4632967412471771},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.42854586243629456},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.38776662945747375},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.3345966339111328},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.23769500851631165},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2167297899723053},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.14411425590515137},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.1075732409954071}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8621327877044678},{"id":"https://openalex.org/C147346212","wikidata":"https://www.wikidata.org/wiki/Q5492632","display_name":"Trusted computing base","level":4,"score":0.8339397311210632},{"id":"https://openalex.org/C2776831232","wikidata":"https://www.wikidata.org/wiki/Q966812","display_name":"Trusted Computing","level":2,"score":0.5047682523727417},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4921666979789734},{"id":"https://openalex.org/C101468663","wikidata":"https://www.wikidata.org/wiki/Q1620158","display_name":"Modular design","level":2,"score":0.4858645796775818},{"id":"https://openalex.org/C2778583558","wikidata":"https://www.wikidata.org/wiki/Q771245","display_name":"Code reuse","level":3,"score":0.47367554903030396},{"id":"https://openalex.org/C121822524","wikidata":"https://www.wikidata.org/wiki/Q5157582","display_name":"Computer security model","level":2,"score":0.4632967412471771},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.42854586243629456},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.38776662945747375},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.3345966339111328},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.23769500851631165},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2167297899723053},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.14411425590515137},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.1075732409954071},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/csf54842.2022.9919645","is_oa":false,"landing_page_url":"https://doi.org/10.1109/csf54842.2022.9919645","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE 35th Computer Security Foundations Symposium (CSF)","raw_type":"proceedings-article"},{"id":"pmh:oai:lirias2repo.kuleuven.be:20.500.12942/705681","is_oa":true,"landing_page_url":"https://lirias.kuleuven.be/handle/20.500.12942/705681","pdf_url":null,"source":{"id":"https://openalex.org/S4306401954","display_name":"Lirias (KU Leuven)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I99464096","host_organization_name":"KU Leuven","host_organization_lineage":["https://openalex.org/I99464096"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":"IEEE Computer Security Foundations Symposium (CSF), Haifa, Israel, 7-10 August 2022","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:oai:pure.atira.dk:publications/da4c3112-bdf7-4de0-b1f7-5a9fbbee8fd1","is_oa":false,"landing_page_url":"https://pure.au.dk/portal/en/publications/da4c3112-bdf7-4de0-b1f7-5a9fbbee8fd1","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Strydonck, T V, Georges, A L, Gu\u00e9neau, A, Trieu, A, Timany, A, Piessens, F, Birkedal, L & Devriese, D 2022, Proving full-system security properties under multiple attacker models on capability machines. in Proceedings - 2022 IEEE 35th Computer Security Foundations Symposium, CSF 2022. IEEE, pp. 80-95, 35th IEEE Computer Security Foundations Symposium, CSF 2022, Haifa, Israel, 07/08/2022. https://doi.org/10.1109/CSF54842.2022.9919645","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"pmh:oai:lirias2repo.kuleuven.be:20.500.12942/705681","is_oa":true,"landing_page_url":"https://lirias.kuleuven.be/handle/20.500.12942/705681","pdf_url":null,"source":{"id":"https://openalex.org/S4306401954","display_name":"Lirias (KU Leuven)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I99464096","host_organization_name":"KU Leuven","host_organization_lineage":["https://openalex.org/I99464096"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":"IEEE Computer Security Foundations Symposium (CSF), Haifa, Israel, 7-10 August 2022","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.75}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":41,"referenced_works":["https://openalex.org/W170959631","https://openalex.org/W1502344315","https://openalex.org/W1520961854","https://openalex.org/W1545681762","https://openalex.org/W1893312510","https://openalex.org/W1904738922","https://openalex.org/W1970040300","https://openalex.org/W2037671236","https://openalex.org/W2049962807","https://openalex.org/W2076409494","https://openalex.org/W2106869436","https://openalex.org/W2107002931","https://openalex.org/W2109642047","https://openalex.org/W2141253292","https://openalex.org/W2143801419","https://openalex.org/W2152178634","https://openalex.org/W2157514610","https://openalex.org/W2162598060","https://openalex.org/W2164399967","https://openalex.org/W2361817505","https://openalex.org/W2412857152","https://openalex.org/W2610782608","https://openalex.org/W2739746516","https://openalex.org/W2761120147","https://openalex.org/W2781213257","https://openalex.org/W2900137615","https://openalex.org/W2901454403","https://openalex.org/W2910968003","https://openalex.org/W2963888572","https://openalex.org/W2966793605","https://openalex.org/W2994621632","https://openalex.org/W3113614934","https://openalex.org/W3151508267","https://openalex.org/W3210362897","https://openalex.org/W4249110288","https://openalex.org/W4412285215","https://openalex.org/W6632796942","https://openalex.org/W6676000179","https://openalex.org/W6712237015","https://openalex.org/W6881502031","https://openalex.org/W7075356097"],"related_works":["https://openalex.org/W2358352283","https://openalex.org/W143066512","https://openalex.org/W2116177289","https://openalex.org/W2168214592","https://openalex.org/W4224230903","https://openalex.org/W2356797718","https://openalex.org/W2382159354","https://openalex.org/W2025014554","https://openalex.org/W1512075125","https://openalex.org/W2974256982"],"abstract_inverted_index":{"Assembly-level":[0],"protection":[1,44,51],"mechanisms":[2,52],"(virtual":[3],"mem-ory,":[4],"trusted":[5,40,157,221],"execution":[6],"environments,":[7],"virtualization)":[8],"make":[9],"it":[10],"possible":[11],"to":[12,172,218],"guarantee":[13],"security":[14,78,85,125,206],"properties":[15,79,207],"of":[16,23,63,76,87,98,139,156,165],"a":[17,33,95,103,123,160,219],"full":[18,89,203],"system":[19,90],"in":[20,67,159,176],"the":[21,73,88,119,137,166,177,185,214,226],"presence":[22],"arbitrary":[24,61],"attacker":[25,82,105,181],"provided":[26],"code.":[27,132],"However,":[28],"they":[29],"typically":[30],"only":[31],"support":[32,60,196],"single":[34],"trust":[35,99,120],"boundary:":[36],"code":[37,117],"is":[38,112,115,134],"either":[39],"or":[41],"untrusted,":[42],"and":[43,57,114,200],"cannot":[45],"be":[46,92,128,151],"nested.":[47],"Capability":[48],"machines":[49],"provide":[50],"that":[53,58],"are":[54],"more":[55],"fine-grained":[56],"do":[59],"nesting":[62],"protection.":[64],"We":[65,183],"show":[66],"this":[68,71],"paper":[69],"how":[70],"enables":[72],"formal":[74],"verification":[75,108,155,216],"full-system":[77],"under":[80,94,102,229],"multiple":[81],"models:":[83],"differ-ent":[84],"objectives":[86],"can":[91,127,150],"verified":[93],"different":[96,104,180],"choice":[97],"boundary":[100,121],"(i.e.":[101],"model).":[106],"The":[107],"approach":[109,186],"we":[110,201],"propose":[111],"modular,":[113],"robust:":[116],"outside":[118],"for":[122,142,179,197,225],"given":[124],"objective":[126],"arbitrary,":[129],"unverified":[130],"attacker-provided":[131],"It":[133],"based":[135],"on":[136],"use":[138],"universal":[140],"contracts":[141,148],"untrusted":[143],"adversarial":[144],"code:":[145],"sound,":[146],"conservative":[147],"which":[149],"combined":[152],"with":[153,195],"manual":[154,215],"components":[158],"compositional":[161],"program":[162,167],"logic.":[163],"Compositionality":[164],"logic":[168],"also":[169],"allows":[170],"us":[171],"reuse":[173],"common":[174],"parts":[175],"analyses":[178],"models.":[182],"instantiate":[184],"concretely":[187],"by":[188],"extending":[189],"an":[190],"existing":[191],"capability":[192],"machine":[193],"model":[194],"memory-mapped":[198],"1/0":[199],"obtain":[202],"system,":[204],"machine-verified":[205],"about":[208],"external":[209],"effect":[210],"traces":[211],"while":[212],"limiting":[213],"effort":[217],"small":[220],"computing":[222],"base":[223],"relevant":[224],"specific":[227],"property":[228],"study.":[230]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":1}],"updated_date":"2026-03-13T16:22:10.518609","created_date":"2022-10-30T00:00:00"}
