{"id":"https://openalex.org/W2785618324","doi":"https://doi.org/10.1109/tifs.2018.2797932","title":"Fine-CFI: Fine-Grained Control-Flow Integrity for Operating System Kernels","display_name":"Fine-CFI: Fine-Grained Control-Flow Integrity for Operating System Kernels","publication_year":2018,"publication_date":"2018-01-25","ids":{"openalex":"https://openalex.org/W2785618324","doi":"https://doi.org/10.1109/tifs.2018.2797932","mag":"2785618324"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2018.2797932","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2018.2797932","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102839957","display_name":"Jinku Li","orcid":"https://orcid.org/0000-0003-0709-7434"},"institutions":[{"id":"https://openalex.org/I149594827","display_name":"Xidian University","ror":"https://ror.org/05s92vm98","country_code":"CN","type":"education","lineage":["https://openalex.org/I149594827"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Jinku Li","raw_affiliation_strings":["School of Cyber Engineering, Xidian University, Xi\u2019an, China","School of Cyber Engineering, Xidian University, Xi'an, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Engineering, Xidian University, Xi\u2019an, China","institution_ids":["https://openalex.org/I149594827"]},{"raw_affiliation_string":"School of Cyber Engineering, Xidian University, Xi'an, China","institution_ids":["https://openalex.org/I149594827"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052363258","display_name":"Xiaomeng Tong","orcid":"https://orcid.org/0000-0002-5531-6286"},"institutions":[{"id":"https://openalex.org/I149594827","display_name":"Xidian University","ror":"https://ror.org/05s92vm98","country_code":"CN","type":"education","lineage":["https://openalex.org/I149594827"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaomeng Tong","raw_affiliation_strings":["School of Cyber Engineering, Xidian University, Xi\u2019an, China","School of Cyber Engineering, Xidian University, Xi'an, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Engineering, Xidian University, Xi\u2019an, China","institution_ids":["https://openalex.org/I149594827"]},{"raw_affiliation_string":"School of Cyber Engineering, Xidian University, Xi'an, China","institution_ids":["https://openalex.org/I149594827"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101886601","display_name":"Fengwei Zhang","orcid":"https://orcid.org/0000-0003-3365-2526"},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fengwei Zhang","raw_affiliation_strings":["Department of Computer Science, Wayne State University, Detroit, MI, USA"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University, Detroit, MI, USA","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012016098","display_name":"Jianfeng Ma","orcid":"https://orcid.org/0000-0003-4251-1143"},"institutions":[{"id":"https://openalex.org/I149594827","display_name":"Xidian University","ror":"https://ror.org/05s92vm98","country_code":"CN","type":"education","lineage":["https://openalex.org/I149594827"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianfeng Ma","raw_affiliation_strings":["School of Cyber Engineering, Xidian University, Xi\u2019an, China","School of Cyber Engineering, Xidian University, Xi'an, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Engineering, Xidian University, Xi\u2019an, China","institution_ids":["https://openalex.org/I149594827"]},{"raw_affiliation_string":"School of Cyber Engineering, Xidian University, Xi'an, China","institution_ids":["https://openalex.org/I149594827"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5102839957"],"corresponding_institution_ids":["https://openalex.org/I149594827"],"apc_list":null,"apc_paid":null,"fwci":3.2073,"has_fulltext":false,"cited_by_count":43,"citation_normalized_percentile":{"value":0.93390525,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":"13","issue":"6","first_page":"1535","last_page":"1550"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9896000027656555,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10478","display_name":"Diamond and Carbon-based Materials Research","score":0.9822999835014343,"subfield":{"id":"https://openalex.org/subfields/2505","display_name":"Materials Chemistry"},"field":{"id":"https://openalex.org/fields/25","display_name":"Materials Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8732157945632935},{"id":"https://openalex.org/keywords/interrupt","display_name":"Interrupt","score":0.6483217477798462},{"id":"https://openalex.org/keywords/context-switch","display_name":"Context switch","score":0.52424556016922},{"id":"https://openalex.org/keywords/control-flow-graph","display_name":"Control flow graph","score":0.5215240120887756},{"id":"https://openalex.org/keywords/control-flow","display_name":"Control flow","score":0.5121414661407471},{"id":"https://openalex.org/keywords/linux-kernel","display_name":"Linux kernel","score":0.48082077503204346},{"id":"https://openalex.org/keywords/compiler","display_name":"Compiler","score":0.4695380926132202},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.4653196334838867},{"id":"https://openalex.org/keywords/kernel","display_name":"Kernel (algebra)","score":0.4609416723251343},{"id":"https://openalex.org/keywords/rootkit","display_name":"Rootkit","score":0.4589783251285553},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.44205474853515625},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.1555871069431305},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.13827800750732422}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8732157945632935},{"id":"https://openalex.org/C41661131","wikidata":"https://www.wikidata.org/wiki/Q220764","display_name":"Interrupt","level":3,"score":0.6483217477798462},{"id":"https://openalex.org/C53833338","wikidata":"https://www.wikidata.org/wiki/Q1061424","display_name":"Context switch","level":2,"score":0.52424556016922},{"id":"https://openalex.org/C27458966","wikidata":"https://www.wikidata.org/wiki/Q1187693","display_name":"Control flow graph","level":2,"score":0.5215240120887756},{"id":"https://openalex.org/C160191386","wikidata":"https://www.wikidata.org/wiki/Q868299","display_name":"Control flow","level":2,"score":0.5121414661407471},{"id":"https://openalex.org/C553261973","wikidata":"https://www.wikidata.org/wiki/Q14579","display_name":"Linux kernel","level":2,"score":0.48082077503204346},{"id":"https://openalex.org/C169590947","wikidata":"https://www.wikidata.org/wiki/Q47506","display_name":"Compiler","level":2,"score":0.4695380926132202},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.4653196334838867},{"id":"https://openalex.org/C74193536","wikidata":"https://www.wikidata.org/wiki/Q574844","display_name":"Kernel (algebra)","level":2,"score":0.4609416723251343},{"id":"https://openalex.org/C10144332","wikidata":"https://www.wikidata.org/wiki/Q14645","display_name":"Rootkit","level":3,"score":0.4589783251285553},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.44205474853515625},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.1555871069431305},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.13827800750732422},{"id":"https://openalex.org/C173018170","wikidata":"https://www.wikidata.org/wiki/Q165678","display_name":"Microcontroller","level":2,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C114614502","wikidata":"https://www.wikidata.org/wiki/Q76592","display_name":"Combinatorics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2018.2797932","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2018.2797932","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.5699999928474426}],"awards":[{"id":"https://openalex.org/G5356833002","display_name":null,"funder_award_id":"U1405255","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":61,"referenced_works":["https://openalex.org/W1112477","https://openalex.org/W103986934","https://openalex.org/W173413620","https://openalex.org/W1429241971","https://openalex.org/W1535810264","https://openalex.org/W1557252148","https://openalex.org/W1591211019","https://openalex.org/W1631846088","https://openalex.org/W1816718056","https://openalex.org/W1823377586","https://openalex.org/W1964281299","https://openalex.org/W1969501726","https://openalex.org/W1987898580","https://openalex.org/W1993682390","https://openalex.org/W1996931407","https://openalex.org/W2001978806","https://openalex.org/W2012578421","https://openalex.org/W2015083179","https://openalex.org/W2020208333","https://openalex.org/W2022292029","https://openalex.org/W2027963645","https://openalex.org/W2029224396","https://openalex.org/W2042856445","https://openalex.org/W2059969702","https://openalex.org/W2072102701","https://openalex.org/W2074943483","https://openalex.org/W2080313875","https://openalex.org/W2080379526","https://openalex.org/W2099382052","https://openalex.org/W2106412703","https://openalex.org/W2109219878","https://openalex.org/W2110756602","https://openalex.org/W2117798902","https://openalex.org/W2124360577","https://openalex.org/W2131821445","https://openalex.org/W2133592286","https://openalex.org/W2136310957","https://openalex.org/W2138517425","https://openalex.org/W2144006591","https://openalex.org/W2146431583","https://openalex.org/W2148686658","https://openalex.org/W2159216827","https://openalex.org/W2162800072","https://openalex.org/W2172131317","https://openalex.org/W2368550879","https://openalex.org/W2575425722","https://openalex.org/W2612397603","https://openalex.org/W2617655602","https://openalex.org/W6600040955","https://openalex.org/W6607078713","https://openalex.org/W6628351959","https://openalex.org/W6632249059","https://openalex.org/W6636574085","https://openalex.org/W6638487575","https://openalex.org/W6638559843","https://openalex.org/W6678545021","https://openalex.org/W6679916680","https://openalex.org/W6680659772","https://openalex.org/W6682091879","https://openalex.org/W6683671222","https://openalex.org/W7038687428"],"related_works":["https://openalex.org/W2354398839","https://openalex.org/W2025088090","https://openalex.org/W58545800","https://openalex.org/W2171038386","https://openalex.org/W2554074189","https://openalex.org/W4235983615","https://openalex.org/W2138385884","https://openalex.org/W2166895275","https://openalex.org/W2998775986","https://openalex.org/W157564837"],"abstract_inverted_index":{"The":[0],"operating":[1,77],"system":[2,71,78],"kernel":[3,135],"is":[4,221],"often":[5],"the":[6,10,29,85,104,112,116,121,159,174,177,188,195,206,215],"security":[7],"foundation":[8],"for":[9,76,208],"whole":[11],"system.":[12],"To":[13],"prevent":[14],"attacks,":[15],"control-flow":[16,36,199],"integrity":[17],"(CFI)":[18],"has":[19],"been":[20],"proposed":[21],"to":[22,61,111,183],"ensure":[23],"that":[24,72,155,214],"any":[25],"control":[26,113,185],"transfer":[27],"during":[28],"program's":[30],"execution":[31],"never":[32],"deviates":[33],"from":[34,167,176],"its":[35],"graph":[37],"(CFG).":[38],"Existing":[39],"CFI":[40,75,99],"solutions":[41],"either":[42],"work":[43],"in":[44,56,115,148,187],"user":[45],"space":[46],"or":[47,58],"are":[48,59],"coarse-grained;":[49],"thus":[50,129,203],"they":[51],"cannot":[52],"be":[53],"readily":[54],"deployed":[55],"kernels":[57],"vulnerable":[60],"state-of-the-art":[62],"attacks.":[63,137],"In":[64],"this":[65,101,146],"paper,":[66],"we":[67,127],"present":[68],"Fine-CFI,":[69],"a":[70,90,141],"enforces":[73,98],"fine-grained":[74,87],"kernels.":[79],"Unlike":[80],"previous":[81],"systems,":[82],"Fine-CFI":[83,107,156,220],"constructs":[84],"kernel's":[86,117],"CFG":[88],"with":[89,100],"retrofitted":[91],"context-sensitive":[92],"and":[93,134,144,180,191],"field-sensitive":[94],"pointer":[95],"analysis,":[96],"then":[97],"CFG.":[102],"At":[103],"same":[105],"time,":[106],"provides":[108],"comprehensive":[109],"protection":[110],"data":[114,186],"interrupt":[118,189],"context.":[119],"Combining":[120],"above":[122],"two":[123],"kinds":[124],"of":[125,197],"protection,":[126],"can":[128],"defeat":[130],"those":[131],"formidable":[132],"ret2usr":[133],"code-reuse":[136],"We":[138],"have":[139],"developed":[140],"compiler-based":[142],"prototype":[143],"implemented":[145],"technique":[147],"Linux":[149],"3.14":[150],"kernel.":[151],"Our":[152,210],"evaluation":[153,211],"indicates":[154],"prevents":[157],"all":[158,173],"gadgets":[160],"found":[161],"by":[162,201,219],"an":[163],"open-source":[164],"gadget-finding":[165],"tool":[166],"being":[168],"misused,":[169],"as":[170,172],"well":[171],"attacks":[175],"RIPE":[178],"benchmark":[179],"malicious":[181],"attempts":[182],"modify":[184],"context;":[190],"it":[192],"also":[193,212],"reduces":[194],"number":[196],"indirect":[198],"targets":[200],"99.998%,":[202],"largely":[204],"raising":[205],"bar":[207],"attackers.":[209],"shows":[213],"performance":[216],"overhead":[217],"introduced":[218],"less":[222],"than":[223],"10%":[224],"on":[225],"average.":[226]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":7},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":3},{"year":2019,"cited_by_count":10},{"year":2018,"cited_by_count":2}],"updated_date":"2026-03-17T09:09:15.849793","created_date":"2025-10-10T00:00:00"}
