{"id":"https://openalex.org/W2538851513","doi":"https://doi.org/10.1145/2976749.2978398","title":"ProvUSB","display_name":"ProvUSB","publication_year":2016,"publication_date":"2016-10-24","ids":{"openalex":"https://openalex.org/W2538851513","doi":"https://doi.org/10.1145/2976749.2978398","mag":"2538851513"},"language":"en","primary_location":{"id":"doi:10.1145/2976749.2978398","is_oa":true,"landing_page_url":"https://doi.org/10.1145/2976749.2978398","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/2976749.2978398","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/2976749.2978398","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5015662045","display_name":"Dave Tian","orcid":"https://orcid.org/0000-0002-7506-9593"},"institutions":[{"id":"https://openalex.org/I33213144","display_name":"University of Florida","ror":"https://ror.org/02y3ad647","country_code":"US","type":"education","lineage":["https://openalex.org/I33213144"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Dave (Jing) Tian","raw_affiliation_strings":["University of Florida, Gainesville, USA"],"affiliations":[{"raw_affiliation_string":"University of Florida, Gainesville, USA","institution_ids":["https://openalex.org/I33213144"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021649580","display_name":"Adam Bates","orcid":"https://orcid.org/0000-0003-1511-4951"},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Adam Bates","raw_affiliation_strings":["University of Illinois at Urbana-Champaign, Urbana-Champaign, USA"],"affiliations":[{"raw_affiliation_string":"University of Illinois at Urbana-Champaign, Urbana-Champaign, USA","institution_ids":["https://openalex.org/I157725225"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039485542","display_name":"Kevin Butler","orcid":"https://orcid.org/0000-0002-7498-4239"},"institutions":[{"id":"https://openalex.org/I33213144","display_name":"University of Florida","ror":"https://ror.org/02y3ad647","country_code":"US","type":"education","lineage":["https://openalex.org/I33213144"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kevin R.B. Butler","raw_affiliation_strings":["University of Florida, Gainesville, USA"],"affiliations":[{"raw_affiliation_string":"University of Florida, Gainesville, USA","institution_ids":["https://openalex.org/I33213144"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5052356609","display_name":"Raju Rangaswami","orcid":"https://orcid.org/0009-0000-5243-9451"},"institutions":[{"id":"https://openalex.org/I19700959","display_name":"Florida International University","ror":"https://ror.org/02gz6gg07","country_code":"US","type":"education","lineage":["https://openalex.org/I19700959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Raju Rangaswami","raw_affiliation_strings":["Florida International University, Miami, USA"],"affiliations":[{"raw_affiliation_string":"Florida International University, Miami, USA","institution_ids":["https://openalex.org/I19700959"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5015662045"],"corresponding_institution_ids":["https://openalex.org/I33213144"],"apc_list":null,"apc_paid":null,"fwci":4.7251,"has_fulltext":true,"cited_by_count":24,"citation_normalized_percentile":{"value":0.95326058,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"242","last_page":"253"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11181","display_name":"Advanced Data Storage Technologies","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11181","display_name":"Advanced Data Storage Technologies","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/usb","display_name":"USB","score":0.8277261853218079},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.793373703956604},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.534395158290863},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.5154784321784973},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.5093997120857239},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.45215508341789246},{"id":"https://openalex.org/keywords/block","display_name":"Block (permutation group theory)","score":0.4468921422958374},{"id":"https://openalex.org/keywords/throughput","display_name":"Throughput","score":0.4130341112613678}],"concepts":[{"id":"https://openalex.org/C507366226","wikidata":"https://www.wikidata.org/wiki/Q42378","display_name":"USB","level":3,"score":0.8277261853218079},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.793373703956604},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.534395158290863},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5154784321784973},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5093997120857239},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.45215508341789246},{"id":"https://openalex.org/C2777210771","wikidata":"https://www.wikidata.org/wiki/Q4927124","display_name":"Block (permutation group theory)","level":2,"score":0.4468921422958374},{"id":"https://openalex.org/C157764524","wikidata":"https://www.wikidata.org/wiki/Q1383412","display_name":"Throughput","level":3,"score":0.4130341112613678},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C555944384","wikidata":"https://www.wikidata.org/wiki/Q249","display_name":"Wireless","level":2,"score":0.0},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/2976749.2978398","is_oa":true,"landing_page_url":"https://doi.org/10.1145/2976749.2978398","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/2976749.2978398","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/2976749.2978398","is_oa":true,"landing_page_url":"https://doi.org/10.1145/2976749.2978398","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/2976749.2978398","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G3330822602","display_name":null,"funder_award_id":"CNS-1540218","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7255387903","display_name":"CAREER: Securing Critical Infrastructure with Autonomously Secure Storage","funder_award_id":"1540217","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7530652133","display_name":"TC: Small: Protection Mechanisms for Portable Storage","funder_award_id":"1540218","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8823713488","display_name":null,"funder_award_id":"CNS-1563883","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8896692164","display_name":null,"funder_award_id":"1563883","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8905723206","display_name":null,"funder_award_id":"CNS-1540217","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2538851513.pdf","grobid_xml":"https://content.openalex.org/works/W2538851513.grobid-xml"},"referenced_works_count":60,"referenced_works":["https://openalex.org/W168132470","https://openalex.org/W191261481","https://openalex.org/W192671640","https://openalex.org/W1444906800","https://openalex.org/W1504669610","https://openalex.org/W1559528097","https://openalex.org/W1575826986","https://openalex.org/W1582664144","https://openalex.org/W1595506625","https://openalex.org/W1608813708","https://openalex.org/W1629063291","https://openalex.org/W1748095088","https://openalex.org/W1858703999","https://openalex.org/W1972369120","https://openalex.org/W1999067777","https://openalex.org/W2009232481","https://openalex.org/W2012575532","https://openalex.org/W2019866007","https://openalex.org/W2033984447","https://openalex.org/W2047998374","https://openalex.org/W2064856281","https://openalex.org/W2086792733","https://openalex.org/W2096347345","https://openalex.org/W2107722712","https://openalex.org/W2110320325","https://openalex.org/W2125883665","https://openalex.org/W2127766933","https://openalex.org/W2130264549","https://openalex.org/W2130535036","https://openalex.org/W2134296086","https://openalex.org/W2137808089","https://openalex.org/W2140911579","https://openalex.org/W2145154883","https://openalex.org/W2146244799","https://openalex.org/W2148659804","https://openalex.org/W2152841927","https://openalex.org/W2154220454","https://openalex.org/W2162546229","https://openalex.org/W2170646878","https://openalex.org/W2203654293","https://openalex.org/W2397699236","https://openalex.org/W2403314695","https://openalex.org/W2405774495","https://openalex.org/W2579106964","https://openalex.org/W2963034244","https://openalex.org/W2996027056","https://openalex.org/W3128313482","https://openalex.org/W4232342695","https://openalex.org/W4299301436","https://openalex.org/W6607808888","https://openalex.org/W6633462303","https://openalex.org/W6635691487","https://openalex.org/W6636485689","https://openalex.org/W6637581689","https://openalex.org/W6639074551","https://openalex.org/W6672323963","https://openalex.org/W6679341293","https://openalex.org/W6679542189","https://openalex.org/W6722970870","https://openalex.org/W7061560282"],"related_works":["https://openalex.org/W2360288732","https://openalex.org/W2379137242","https://openalex.org/W2758694247","https://openalex.org/W2356928735","https://openalex.org/W2367116219","https://openalex.org/W2382617248","https://openalex.org/W2078379271","https://openalex.org/W2043460294","https://openalex.org/W4210712718","https://openalex.org/W1905398909"],"abstract_inverted_index":{"Defenders":[0],"of":[1,14,26,42,52,57,71,149,177],"enterprise":[2],"networks":[3],"have":[4],"a":[5,39,69,135],"critical":[6,40],"need":[7],"to":[8,62],"quickly":[9],"identify":[10],"the":[11,24,50,55,113,126,175],"root":[12],"causes":[13],"malware":[15,31],"and":[16,33,44,97,110,116,157,180],"data":[17,29,53,58,105],"leakage.":[18],"Increasingly,":[19],"USB":[20,66,101,127,141,181],"storage":[21,161,182],"devices":[22,67],"are":[23],"media":[25],"choice":[27],"for":[28,93,163],"exfiltration,":[30],"propagation,":[32],"even":[34,83],"cyber-warfare.":[35],"We":[36],"observe":[37],"that":[38,132],"aspect":[41],"explaining":[43],"preventing":[45],"such":[46],"attacks":[47],"is":[48,79],"understanding":[49],"provenance":[51,77,95,106,164],"(i.e.,":[54],"lineage":[56],"from":[59],"its":[60],"creation":[61],"current":[63],"state)":[64],"on":[65,99,151],"as":[68],"means":[70],"ensuring":[72],"their":[73],"safe":[74],"usage.":[75],"Unfortunately,":[76],"tracking":[78,98],"not":[80],"offered":[81],"by":[82,107],"sophisticated":[84],"modern":[85],"devices.":[86,102,183],"This":[87],"work":[88],"presents":[89],"ProvUSB,":[90],"an":[91],"architecture":[92],"fine-grained":[94],"collection":[96],"smart":[100],"ProvUSB":[103,133,168],"maintains":[104],"recording":[108],"reads":[109],"writes":[111],"at":[112],"block":[114],"layer":[115],"reliably":[117],"identifying":[118],"hosts":[119],"editing":[120],"those":[121],"blocks":[122],"through":[123],"attestation":[124],"over":[125],"channel.":[128],"Our":[129],"evaluation":[130],"finds":[131],"imposes":[134],"one-time":[136],"850":[137],"ms":[138],"overhead":[139,162],"during":[140,154],"enumeration,":[142],"but":[143],"approaches":[144],"nearly-bare-metal":[145],"runtime":[146],"performance":[147],"(90%":[148],"throughput)":[150],"larger":[152],"files":[153],"normal":[155],"execution,":[156],"less":[158],"than":[159],"0.1%":[160],"in":[165,174],"real-world":[166],"workloads.":[167],"thus":[169],"provides":[170],"essential":[171],"new":[172],"techniques":[173],"defense":[176],"computer":[178],"systems":[179]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":2},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":9},{"year":2018,"cited_by_count":4},{"year":2017,"cited_by_count":3}],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2016-10-28T00:00:00"}
