{"id":"https://openalex.org/W2427560220","doi":"https://doi.org/10.1109/hst.2016.7495577","title":"Hardware-based workload forensics: Process reconstruction via TLB monitoring","display_name":"Hardware-based workload forensics: Process reconstruction via TLB monitoring","publication_year":2016,"publication_date":"2016-05-01","ids":{"openalex":"https://openalex.org/W2427560220","doi":"https://doi.org/10.1109/hst.2016.7495577","mag":"2427560220"},"language":"en","primary_location":{"id":"doi:10.1109/hst.2016.7495577","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hst.2016.7495577","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101464955","display_name":"Liwei Zhou","orcid":null},"institutions":[{"id":"https://openalex.org/I162577319","display_name":"The University of Texas at Dallas","ror":"https://ror.org/049emcs32","country_code":"US","type":"education","lineage":["https://openalex.org/I162577319"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Liwei Zhou","raw_affiliation_strings":["Electrical Engineering Department, The University of Texas at Dallas, Richardson, TX, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Electrical Engineering Department, The University of Texas at Dallas, Richardson, TX, USA","institution_ids":["https://openalex.org/I162577319"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5078818440","display_name":"Yiorgos Makris","orcid":"https://orcid.org/0000-0002-4322-0068"},"institutions":[{"id":"https://openalex.org/I162577319","display_name":"The University of Texas at Dallas","ror":"https://ror.org/049emcs32","country_code":"US","type":"education","lineage":["https://openalex.org/I162577319"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yiorgos Makris","raw_affiliation_strings":["Electrical Engineering Department, The University of Texas at Dallas, Richardson, TX, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Electrical Engineering Department, The University of Texas at Dallas, Richardson, TX, USA","institution_ids":["https://openalex.org/I162577319"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.7666,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.89109127,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"167","last_page":"172"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11005","display_name":"Radiation Effects in Electronics","score":0.9936000108718872,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7906731963157654},{"id":"https://openalex.org/keywords/workload","display_name":"Workload","score":0.7300113439559937},{"id":"https://openalex.org/keywords/translation-lookaside-buffer","display_name":"Translation lookaside buffer","score":0.6642772555351257},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.594591498374939},{"id":"https://openalex.org/keywords/x86","display_name":"x86","score":0.5932086706161499},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.5790627002716064},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5148093104362488},{"id":"https://openalex.org/keywords/hypervisor","display_name":"Hypervisor","score":0.49368032813072205},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.47741758823394775},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4024815559387207},{"id":"https://openalex.org/keywords/computer-hardware","display_name":"Computer hardware","score":0.328055202960968},{"id":"https://openalex.org/keywords/virtualization","display_name":"Virtualization","score":0.21002990007400513},{"id":"https://openalex.org/keywords/physical-address","display_name":"Physical address","score":0.09343907237052917}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7906731963157654},{"id":"https://openalex.org/C2778476105","wikidata":"https://www.wikidata.org/wiki/Q628539","display_name":"Workload","level":2,"score":0.7300113439559937},{"id":"https://openalex.org/C116007543","wikidata":"https://www.wikidata.org/wiki/Q1071403","display_name":"Translation lookaside buffer","level":4,"score":0.6642772555351257},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.594591498374939},{"id":"https://openalex.org/C170723468","wikidata":"https://www.wikidata.org/wiki/Q182933","display_name":"x86","level":3,"score":0.5932086706161499},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5790627002716064},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5148093104362488},{"id":"https://openalex.org/C112904061","wikidata":"https://www.wikidata.org/wiki/Q1077480","display_name":"Hypervisor","level":4,"score":0.49368032813072205},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.47741758823394775},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4024815559387207},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.328055202960968},{"id":"https://openalex.org/C513985346","wikidata":"https://www.wikidata.org/wiki/Q270471","display_name":"Virtualization","level":3,"score":0.21002990007400513},{"id":"https://openalex.org/C41036726","wikidata":"https://www.wikidata.org/wiki/Q844824","display_name":"Physical address","level":3,"score":0.09343907237052917},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C136085584","wikidata":"https://www.wikidata.org/wiki/Q910289","display_name":"Overlay","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/hst.2016.7495577","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hst.2016.7495577","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":20,"referenced_works":["https://openalex.org/W17417926","https://openalex.org/W73598622","https://openalex.org/W1546317334","https://openalex.org/W1686420892","https://openalex.org/W1956767865","https://openalex.org/W1986465830","https://openalex.org/W2002380285","https://openalex.org/W2050082837","https://openalex.org/W2059063827","https://openalex.org/W2093488494","https://openalex.org/W2101177960","https://openalex.org/W2118372007","https://openalex.org/W2125743503","https://openalex.org/W2135162105","https://openalex.org/W2153635508","https://openalex.org/W2166844173","https://openalex.org/W6603043977","https://openalex.org/W6632599652","https://openalex.org/W6637151178","https://openalex.org/W6640826072"],"related_works":["https://openalex.org/W2974258286","https://openalex.org/W2156299749","https://openalex.org/W1518891319","https://openalex.org/W2109152626","https://openalex.org/W1498056603","https://openalex.org/W2159906569","https://openalex.org/W1823640228","https://openalex.org/W2754887144","https://openalex.org/W2323625620","https://openalex.org/W2625932461"],"abstract_inverted_index":{"We":[0],"introduce":[1],"a":[2,103],"hardware-based":[3],"methodology":[4],"for":[5,20],"performing":[6],"workload":[7,53,122,128],"execution":[8],"forensics":[9,54],"in":[10,82,112],"microprocessors.":[11],"More":[12],"specifically,":[13],"we":[14],"discuss":[15],"the":[16,22,26,45,50,58,113,120],"on-chip":[17],"instrumentation":[18],"required":[19],"capturing":[21],"operational":[23],"profile":[24],"of":[25,102,131,138],"Translation":[27],"Lookaside":[28],"Buffer":[29],"(TLB),":[30],"as":[31,33],"well":[32],"an":[34,97,126,134],"off-line":[35],"machine":[36],"learning":[37],"approach":[38,78],"which":[39,100],"uses":[40],"this":[41,77],"information":[42],"to":[43,88],"identify":[44],"executed":[46],"processes":[47],"and":[48,68,84],"reconstruct":[49],"workload.":[51],"Unlike":[52],"methods":[55],"implemented":[56,80,111],"at":[57,133],"operating":[59,109],"system":[60],"(OS)":[61],"and/or":[62],"hypervisor":[63],"level,":[64],"whose":[65],"data":[66],"logging":[67,136],"monitoring":[69],"mechanisms":[70],"may":[71],"be":[72],"compromised":[73],"through":[74],"software":[75],"attacks,":[76],"is":[79,94],"directly":[81],"hardware":[83],"is,":[85],"therefore,":[86],"immune":[87],"such":[89],"attacks.":[90],"The":[91],"proposed":[92],"method":[93],"demonstrated":[95],"on":[96],"experimentation":[98],"platform":[99],"consists":[101],"32-bit":[104],"x86":[105],"architecture":[106],"running":[107],"Linux":[108],"system,":[110],"Simics":[114],"simulation":[115],"environment.":[116],"Experimental":[117],"results":[118],"using":[119],"Mibench":[121],"benchmark":[123],"suite":[124],"reveal":[125],"overall":[127],"identification":[129],"accuracy":[130],"96.97%":[132],"estimated":[135],"rate":[137],"only":[139],"5.17":[140],"KB/sec.":[141]},"counts_by_year":[{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
