{"id":"https://openalex.org/W2524202097","doi":"https://doi.org/10.1109/tdsc.2015.2443803","title":"Detecting and Preventing Kernel Rootkit Attacks with Bus Snooping","display_name":"Detecting and Preventing Kernel Rootkit Attacks with Bus Snooping","publication_year":2015,"publication_date":"2015-06-11","ids":{"openalex":"https://openalex.org/W2524202097","doi":"https://doi.org/10.1109/tdsc.2015.2443803","mag":"2524202097"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2015.2443803","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2015.2443803","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5042587361","display_name":"Hyungon Moon","orcid":"https://orcid.org/0000-0002-4513-1034"},"institutions":[{"id":"https://openalex.org/I139264467","display_name":"Seoul National University","ror":"https://ror.org/04h9pn542","country_code":"KR","type":"education","lineage":["https://openalex.org/I139264467"]}],"countries":["KR"],"is_corresponding":true,"raw_author_name":"Hyungon Moon","raw_affiliation_strings":["ISRC, Seoul National University, Gwanak-gu, Seoul, Korea"],"affiliations":[{"raw_affiliation_string":"ISRC, Seoul National University, Gwanak-gu, Seoul, Korea","institution_ids":["https://openalex.org/I139264467"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101660662","display_name":"Hojoon Lee","orcid":"https://orcid.org/0000-0001-5344-6266"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Hojoon Lee","raw_affiliation_strings":["Graduate School of Information Security, Korea Advanced Institute of Technology, Yuseong, Daejeon, Korea"],"affiliations":[{"raw_affiliation_string":"Graduate School of Information Security, Korea Advanced Institute of Technology, Yuseong, Daejeon, Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089647352","display_name":"Ingoo Heo","orcid":null},"institutions":[{"id":"https://openalex.org/I139264467","display_name":"Seoul National University","ror":"https://ror.org/04h9pn542","country_code":"KR","type":"education","lineage":["https://openalex.org/I139264467"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Ingoo Heo","raw_affiliation_strings":["ISRC, Seoul National University, Gwanak-gu, Seoul, Korea"],"affiliations":[{"raw_affiliation_string":"ISRC, Seoul National University, Gwanak-gu, Seoul, Korea","institution_ids":["https://openalex.org/I139264467"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100655396","display_name":"Kihwan Kim","orcid":"https://orcid.org/0000-0003-0257-1707"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Kihwan Kim","raw_affiliation_strings":["Graduate School of Information Security, Korea Advanced Institute of Technology, Yuseong, Daejeon, Korea"],"affiliations":[{"raw_affiliation_string":"Graduate School of Information Security, Korea Advanced Institute of Technology, Yuseong, Daejeon, Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082524666","display_name":"Yunheung Paek","orcid":"https://orcid.org/0000-0002-6412-2926"},"institutions":[{"id":"https://openalex.org/I139264467","display_name":"Seoul National University","ror":"https://ror.org/04h9pn542","country_code":"KR","type":"education","lineage":["https://openalex.org/I139264467"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Yunheung Paek","raw_affiliation_strings":["ISRC, Seoul National University, Gwanak-gu, Seoul, Korea"],"affiliations":[{"raw_affiliation_string":"ISRC, Seoul National University, Gwanak-gu, Seoul, Korea","institution_ids":["https://openalex.org/I139264467"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5111984144","display_name":"Brent Byunghoon Kang","orcid":null},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Brent Byunghoon Kang","raw_affiliation_strings":["Graduate School of Information Security, Korea Advanced Institute of Technology, Yuseong, Daejeon, Korea"],"affiliations":[{"raw_affiliation_string":"Graduate School of Information Security, Korea Advanced Institute of Technology, Yuseong, Daejeon, Korea","institution_ids":["https://openalex.org/I157485424"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5042587361"],"corresponding_institution_ids":["https://openalex.org/I139264467"],"apc_list":null,"apc_paid":null,"fwci":0.8902,"has_fulltext":false,"cited_by_count":11,"citation_normalized_percentile":{"value":0.8465556,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"14","issue":"2","first_page":"145","last_page":"157"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9965999722480774,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9764000177383423,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/snapshot","display_name":"Snapshot (computer storage)","score":0.6823335886001587},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6740703582763672},{"id":"https://openalex.org/keywords/kernel","display_name":"Kernel (algebra)","score":0.43906068801879883},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.35890698432922363},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.09990930557250977},{"id":"https://openalex.org/keywords/discrete-mathematics","display_name":"Discrete mathematics","score":0.07020202279090881}],"concepts":[{"id":"https://openalex.org/C55282118","wikidata":"https://www.wikidata.org/wiki/Q252683","display_name":"Snapshot (computer storage)","level":2,"score":0.6823335886001587},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6740703582763672},{"id":"https://openalex.org/C74193536","wikidata":"https://www.wikidata.org/wiki/Q574844","display_name":"Kernel (algebra)","level":2,"score":0.43906068801879883},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.35890698432922363},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.09990930557250977},{"id":"https://openalex.org/C118615104","wikidata":"https://www.wikidata.org/wiki/Q121416","display_name":"Discrete mathematics","level":1,"score":0.07020202279090881}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tdsc.2015.2443803","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2015.2443803","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},{"id":"pmh:oai:scholarworks.unist.ac.kr:201301/24552","is_oa":false,"landing_page_url":"https://ieeexplore.ieee.org/document/7120934/","pdf_url":null,"source":{"id":"https://openalex.org/S4306401118","display_name":"Scholarworks@UNIST (Ulsan National Institute of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I48566637","host_organization_name":"Ulsan National Institute of Science and Technology","host_organization_lineage":["https://openalex.org/I48566637"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"ARTICLE"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.5899999737739563,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G3478701774","display_name":null,"funder_award_id":"2014R1A2A1A10051792","funder_id":"https://openalex.org/F4320322030","funder_display_name":"Ministry of Science, ICT and Future Planning"},{"id":"https://openalex.org/G6717471489","display_name":null,"funder_award_id":"UD140002ED","funder_id":"https://openalex.org/F4320323103","funder_display_name":"Agency for Defense Development"}],"funders":[{"id":"https://openalex.org/F4320322030","display_name":"Ministry of Science, ICT and Future Planning","ror":"https://ror.org/032e49973"},{"id":"https://openalex.org/F4320322120","display_name":"National Research Foundation of Korea","ror":"https://ror.org/013aysd81"},{"id":"https://openalex.org/F4320323103","display_name":"Agency for Defense Development","ror":"https://ror.org/05fhe0r85"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":31,"referenced_works":["https://openalex.org/W94181602","https://openalex.org/W161166442","https://openalex.org/W173413620","https://openalex.org/W1591070193","https://openalex.org/W1641762327","https://openalex.org/W1748095088","https://openalex.org/W1877037860","https://openalex.org/W1976956141","https://openalex.org/W2016915071","https://openalex.org/W2029224396","https://openalex.org/W2054840305","https://openalex.org/W2065085847","https://openalex.org/W2088272026","https://openalex.org/W2101889913","https://openalex.org/W2107247116","https://openalex.org/W2111015674","https://openalex.org/W2124814646","https://openalex.org/W2139949621","https://openalex.org/W2146431583","https://openalex.org/W2151200195","https://openalex.org/W2151849720","https://openalex.org/W2154426165","https://openalex.org/W2158699246","https://openalex.org/W2160146193","https://openalex.org/W2166004296","https://openalex.org/W4206796831","https://openalex.org/W6603860816","https://openalex.org/W6607078713","https://openalex.org/W6637110787","https://openalex.org/W6637581689","https://openalex.org/W6654805914"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2542847180","https://openalex.org/W3034994054","https://openalex.org/W2155226960","https://openalex.org/W2805712290","https://openalex.org/W2909129499","https://openalex.org/W2761598930","https://openalex.org/W2392087771","https://openalex.org/W2553994394","https://openalex.org/W2356600124"],"abstract_inverted_index":{"To":[0],"protect":[1,91],"the":[2,24,28,43,47,50,72,92,102,114,132,144,148,152,159,166],"integrity":[3,17,59],"of":[4,27,49,101,134,139],"operating":[5],"system":[6,30,104,116,141],"kernels,":[7],"we":[8],"present":[9],"<italic":[10,37,51,79,107],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[11,38,52,80,108],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">Vigilare":[12],"system</i>":[13],",":[14],"a":[15,32,69,121],"kernel":[16,58,93,153],"monitor":[18,123,161],"that":[19,83],"is":[20],"architected":[21],"to":[22,113,124,130],"snoop":[23],"bus":[25,118],"traffic":[26],"host":[29,115],"from":[31],"separate":[33],"independent":[34],"hardware.":[35],"This":[36],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">snoop-based":[39],"monitoring</i>":[40,54],"enabled":[41],"by":[42,105],"Vigilare":[44,103,140],"system,":[45],"overcomes":[46],"limitations":[48],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">snapshot-based":[53],"employed":[55],"in":[56,86,128,178],"previous":[57,73],"monitoring":[60,75],"solutions.":[61],"Being":[62],"based":[63],"on":[64],"inspecting":[65],"snapshots":[66],"collected":[67],"over":[68],"certain":[70],"interval,":[71],"hardware-based":[74],"solutions":[76],"cannot":[77,90],"detect":[78,164],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">transient":[81],"attacks</i>":[82],"can":[84],"occur":[85],"between":[87],"snapshots,":[88],"and":[89,120,147,168],"against":[94],"permanent":[95],"damage.":[96],"We":[97],"implemented":[98],"three":[99],"prototypes":[100,138],"adding":[106],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">Snooper</i>":[109],"hardware":[110],"connections":[111],"module":[112],"for":[117],"snooping,":[119],"snapshot-based":[122,160],"be":[125],"comared":[126],"with,":[127],"order":[129],"evaluate":[131],"benefit":[133],"snoop-based":[135],"monitoring.":[136],"The":[137],"detected":[142],"all":[143,165],"transient":[145],"attacks":[146,167],"second":[149],"one":[150],"protected":[151],"with":[154],"negligible":[155],"performance":[156,171],"degradation":[157,172],"while":[158],"could":[162],"not":[163],"induced":[169],"considerable":[170],"as":[173,175],"much":[174],"10":[176],"percent":[177],"our":[179],"tuned":[180],"STREAM":[181],"benchmark":[182],"test.":[183]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2019,"cited_by_count":2},{"year":2018,"cited_by_count":1},{"year":2016,"cited_by_count":1}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
