{"id":"https://openalex.org/W2593484158","doi":"https://doi.org/10.1109/tdsc.2017.2679710","title":"KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object","display_name":"KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object","publication_year":2017,"publication_date":"2017-03-08","ids":{"openalex":"https://openalex.org/W2593484158","doi":"https://doi.org/10.1109/tdsc.2017.2679710","mag":"2593484158"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2017.2679710","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2017.2679710","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101660662","display_name":"Hojoon Lee","orcid":"https://orcid.org/0000-0001-5344-6266"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":true,"raw_author_name":"Hojoon Lee","raw_affiliation_strings":["Korea Advanced Institute of Technology, Daejeon, South Korea"],"affiliations":[{"raw_affiliation_string":"Korea Advanced Institute of Technology, Daejeon, South Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5042587361","display_name":"Hyungon Moon","orcid":"https://orcid.org/0000-0002-4513-1034"},"institutions":[{"id":"https://openalex.org/I139264467","display_name":"Seoul National University","ror":"https://ror.org/04h9pn542","country_code":"KR","type":"education","lineage":["https://openalex.org/I139264467"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Hyungon Moon","raw_affiliation_strings":["Seoul National University, Seoul, South Korea"],"affiliations":[{"raw_affiliation_string":"Seoul National University, Seoul, South Korea","institution_ids":["https://openalex.org/I139264467"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089647352","display_name":"Ingoo Heo","orcid":null},"institutions":[{"id":"https://openalex.org/I139264467","display_name":"Seoul National University","ror":"https://ror.org/04h9pn542","country_code":"KR","type":"education","lineage":["https://openalex.org/I139264467"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Ingoo Heo","raw_affiliation_strings":["Seoul National University, Seoul, South Korea"],"affiliations":[{"raw_affiliation_string":"Seoul National University, Seoul, South Korea","institution_ids":["https://openalex.org/I139264467"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110641804","display_name":"Daehee Jang","orcid":null},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Daehee Jang","raw_affiliation_strings":["Korea Advanced Institute of Technology, Daejeon, South Korea"],"affiliations":[{"raw_affiliation_string":"Korea Advanced Institute of Technology, Daejeon, South Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091606131","display_name":"Jinsoo Jang","orcid":"https://orcid.org/0000-0003-2070-2408"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Jinsoo Jang","raw_affiliation_strings":["Korea Advanced Institute of Technology, Daejeon, South Korea"],"affiliations":[{"raw_affiliation_string":"Korea Advanced Institute of Technology, Daejeon, South Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100655396","display_name":"Kihwan Kim","orcid":"https://orcid.org/0000-0003-0257-1707"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Kihwan Kim","raw_affiliation_strings":["Korea Advanced Institute of Technology, Daejeon, South Korea"],"affiliations":[{"raw_affiliation_string":"Korea Advanced Institute of Technology, Daejeon, South Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082524666","display_name":"Yunheung Paek","orcid":"https://orcid.org/0000-0002-6412-2926"},"institutions":[{"id":"https://openalex.org/I139264467","display_name":"Seoul National University","ror":"https://ror.org/04h9pn542","country_code":"KR","type":"education","lineage":["https://openalex.org/I139264467"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Yunheung Paek","raw_affiliation_strings":["Seoul National University, Seoul, South Korea"],"affiliations":[{"raw_affiliation_string":"Seoul National University, Seoul, South Korea","institution_ids":["https://openalex.org/I139264467"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046066368","display_name":"Brent Byunghoon Kang","orcid":"https://orcid.org/0000-0001-8984-1006"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Brent Byunghoon Kang","raw_affiliation_strings":["Korea Advanced Institute of Technology, Daejeon, South Korea"],"affiliations":[{"raw_affiliation_string":"Korea Advanced Institute of Technology, Daejeon, South Korea","institution_ids":["https://openalex.org/I157485424"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5101660662"],"corresponding_institution_ids":["https://openalex.org/I157485424"],"apc_list":null,"apc_paid":null,"fwci":1.3652,"has_fulltext":false,"cited_by_count":18,"citation_normalized_percentile":{"value":0.8534012,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"16","issue":"2","first_page":"287","last_page":"300"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9951000213623047,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9919999837875366,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.813167154788971},{"id":"https://openalex.org/keywords/rootkit","display_name":"Rootkit","score":0.7314789295196533},{"id":"https://openalex.org/keywords/kernel","display_name":"Kernel (algebra)","score":0.665580153465271},{"id":"https://openalex.org/keywords/cache","display_name":"Cache","score":0.5265864729881287},{"id":"https://openalex.org/keywords/sysfs","display_name":"sysfs","score":0.5245949625968933},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.48755306005477905},{"id":"https://openalex.org/keywords/linux-kernel","display_name":"Linux kernel","score":0.41045740246772766},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.39180606603622437},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.3400632441043854}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.813167154788971},{"id":"https://openalex.org/C10144332","wikidata":"https://www.wikidata.org/wiki/Q14645","display_name":"Rootkit","level":3,"score":0.7314789295196533},{"id":"https://openalex.org/C74193536","wikidata":"https://www.wikidata.org/wiki/Q574844","display_name":"Kernel (algebra)","level":2,"score":0.665580153465271},{"id":"https://openalex.org/C115537543","wikidata":"https://www.wikidata.org/wiki/Q165596","display_name":"Cache","level":2,"score":0.5265864729881287},{"id":"https://openalex.org/C90307666","wikidata":"https://www.wikidata.org/wiki/Q1932562","display_name":"sysfs","level":3,"score":0.5245949625968933},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.48755306005477905},{"id":"https://openalex.org/C553261973","wikidata":"https://www.wikidata.org/wiki/Q14579","display_name":"Linux kernel","level":2,"score":0.41045740246772766},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.39180606603622437},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3400632441043854},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.0},{"id":"https://openalex.org/C114614502","wikidata":"https://www.wikidata.org/wiki/Q76592","display_name":"Combinatorics","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/tdsc.2017.2679710","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2017.2679710","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},{"id":"pmh:oai:s-space.snu.ac.kr:10371/198280","is_oa":false,"landing_page_url":"https://hdl.handle.net/10371/198280","pdf_url":null,"source":{"id":"https://openalex.org/S4306401345","display_name":"Seoul National University Open Repository (Seoul National University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I139264467","host_organization_name":"Seoul National University","host_organization_lineage":["https://openalex.org/I139264467"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Article"},{"id":"pmh:oai:scholarworks.unist.ac.kr:201301/24551","is_oa":false,"landing_page_url":"https://scholarworks.unist.ac.kr/handle/201301/24551","pdf_url":null,"source":{"id":"https://openalex.org/S4306401118","display_name":"Scholarworks@UNIST (Ulsan National Institute of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I48566637","host_organization_name":"Ulsan National Institute of Science and Technology","host_organization_lineage":["https://openalex.org/I48566637"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"ARTICLE"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.4399999976158142,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G7202330001","display_name":null,"funder_award_id":"2014R1A2A1A10051792","funder_id":"https://openalex.org/F4320322120","funder_display_name":"National Research Foundation of Korea"}],"funders":[{"id":"https://openalex.org/F4320322120","display_name":"National Research Foundation of Korea","ror":"https://ror.org/013aysd81"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W94181602","https://openalex.org/W161166442","https://openalex.org/W1549154409","https://openalex.org/W1557252148","https://openalex.org/W1576624296","https://openalex.org/W2029224396","https://openalex.org/W2036548030","https://openalex.org/W2048997531","https://openalex.org/W2054840305","https://openalex.org/W2057743816","https://openalex.org/W2088272026","https://openalex.org/W2101889913","https://openalex.org/W2109219878","https://openalex.org/W2122097147","https://openalex.org/W2126220112","https://openalex.org/W2133592286","https://openalex.org/W2139949621","https://openalex.org/W2140678915","https://openalex.org/W2140807364","https://openalex.org/W2140920854","https://openalex.org/W2144006591","https://openalex.org/W2146431583","https://openalex.org/W2151200195","https://openalex.org/W2151849720","https://openalex.org/W2158699246","https://openalex.org/W2168760272","https://openalex.org/W2579632738","https://openalex.org/W6603860816","https://openalex.org/W6606620872"],"related_works":["https://openalex.org/W2354398839","https://openalex.org/W2025088090","https://openalex.org/W3163483881","https://openalex.org/W4287547184","https://openalex.org/W2354333148","https://openalex.org/W3117583373","https://openalex.org/W4233102306","https://openalex.org/W2999306385","https://openalex.org/W119923507","https://openalex.org/W2912106162"],"abstract_inverted_index":{"External":[0],"hardware-based":[1,44],"kernel":[2,26,34,52,87,134],"integrity":[3],"monitors":[4,122],"have":[5,17,152],"been":[6,18],"proposed":[7],"to":[8,20,62,81,162],"mitigate":[9],"kernel-level":[10],"malwares.":[11],"However,":[12],"the":[13,22,28,32,38,57,70,117,159,164,176,181,185],"existing":[14],"external":[15,121],"approaches":[16],"limited":[19],"monitoring":[21,49],"static":[23],"regions":[24],"of":[25,102,156,166,172,184],"while":[27],"latest":[29],"rootkits":[30],"manipulate":[31],"dynamic":[33,53,128],"objects.":[35,54],"To":[36],"address":[37],"issue,":[39],"we":[40],"present":[41],"KI-Mon,":[42],"a":[43,100,154],"platform":[45],"that":[46,136,140],"introduces":[47],"event-triggered":[48,168],"techniques":[50],"for":[51,104,120,175],"KI-Mon":[55,157,186],"advances":[56],"bus":[58,72],"traffic":[59,68,80],"snooping":[60],"technique":[61],"not":[63],"only":[64],"detect":[65],"memory":[66],"write":[67],"on":[69,116,158],"host":[71,178],"but":[73,78],"also":[74,98,110],"filter":[75],"out":[76],"all":[77],"meaningful":[79],"generate":[82],"events.":[83],"We":[84,109,131,151],"show":[85],"how":[86],"invariant":[88,106],"verification":[89,107],"software":[90],"can":[91],"be":[92],"developed":[93],"around":[94],"these":[95,138],"events,":[96],"and":[97,114,147,180],"provide":[99],"set":[101],"APIs":[103],"additional":[105],"development.":[108],"report":[111],"our":[112],"findings":[113],"considerations":[115],"unique":[118],"challenges":[119],"\u2013":[123],"such":[124],"as":[125],"cache":[126,148],"coherency,":[127],"object":[129,145],"tracing.":[130],"introduce":[132],"host-side":[133],"changes":[135,142],"alleviate":[137],"issues":[139],"involve":[141],"in":[143,170],"kernel's":[144],"allocation":[146],"policy":[149],"control.":[150],"built":[153],"prototype":[155],"ARM":[160],"architecture":[161],"demonstrate":[163],"efficacy":[165],"KI-Mon's":[167],"mechanism":[169],"terms":[171],"performance":[173],"overhead":[174],"monitored":[177],"system":[179],"processor":[182],"usage":[183],"processor.":[187]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":7},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":1},{"year":2016,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
