SGX-Bomb: Locking down the processor via Rowhammer attack

Y Jang, J Lee, S Lee, T Kim - Proceedings of the 2nd Workshop on …, 2017 - dl.acm.org
Intel Software Guard Extensions (SGX) provides a strongly isolated memory space, known
as an enclave, for a user process, ensuring confidentiality and integrity against software and …

Theseus: an experiment in operating system structure and state management

K Boos, N Liyanage, R Ijaz, L Zhong - 14th USENIX Symposium on …, 2020 - usenix.org
This paper describes an operating system (OS) called Theseus. Theseus is the result of
multi-year experimentation to redesign and improve OS modularity by reducing the states …

Adaptive android kernel live patching

Y Chen, Y Zhang, Z Wang, L Xia, C Bao… - 26th USENIX Security …, 2017 - usenix.org
Android kernel vulnerabilities pose a serious threat to user security and privacy. They allow
attackers to take full control over victim devices, install malicious and unwanted apps, and …

Runtime software patching: Taxonomy, survey and future directions

C Islam, V Prokhorenko, MA Babar - Journal of Systems and Software, 2023 - Elsevier
Runtime software patching aims to minimize or eliminate service downtime, user
interruptions and potential data losses while deploying a patch. Due to modern software …

Mitigating vulnerability windows with hypervisor transplant

TD Ngoc, B Teabe, A Tchana, G Muller… - Proceedings of the …, 2021 - dl.acm.org
The vulnerability window of a hypervisor regarding a given security flaw is the time between
the identification of the flaw and the integration of a correction/patch in the running …

Rewind & Discard: Improving software resilience using isolated domains

M Gülmez, T Nyman, C Baumann… - 2023 53rd Annual …, 2023 - ieeexplore.ieee.org
Well-known defenses exist to detect and mitigate common faults and memory safety
vulnerabilities in software. Yet, many of these mitigations do not address the challenge of …

Reboot-oriented IoT: Life cycle management in trusted execution environment for disposable IoT devices

K Suzaki, A Tsukamoto, A Green… - Proceedings of the 36th …, 2020 - dl.acm.org
Many IoT devices are geographically distributed without human administrators, which are
maintained by a remote server to enforce security updates, ideally through machine-to …

KShot: Live kernel patching with SMM and SGX

L Zhou, F Zhang, J Liao, Z Ning, J Xiao… - 2020 50th Annual …, 2020 - ieeexplore.ieee.org
Live kernel patching is an increasingly common trend in operating system distributions,
enabling dynamic updates to include new features or to fix vulnerabilities without having to …

Virtual machine preserving host updates for zero day patching in public cloud

M Russinovich, N Govindaraju… - Proceedings of the …, 2021 - dl.acm.org
Host software updates are critical to ensure the security, reliability and compliance of public
clouds. Many updates require a virtualization component restart or operating system reboot …

An Empirical Study of Automation in Software Security Patch Management

N Dissanayake, A Jayatilaka, M Zahedi… - Proceedings of the 37th …, 2022 - dl.acm.org
Several studies have shown that automated support for different activities of the security
patch management process has great potential for reducing delays in installing security …