{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T15:16:59Z","timestamp":1766157419109},"publisher-location":"Berlin, Heidelberg","reference-count":26,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540266136"},{"type":"electronic","value":"9783540316459"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2005]]},"DOI":"10.1007\/11506881_3","type":"book-chapter","created":{"date-parts":[[2010,7,14]],"date-time":"2010-07-14T20:30:33Z","timestamp":1279139433000},"page":"32-50","source":"Crossref","is-referenced-by-count":31,"title":["Experiences Using Minos as a Tool for Capturing and Analyzing Novel Worms for Unknown Vulnerabilities"],"prefix":"10.1007","author":[{"given":"Jedidiah R.","family":"Crandall","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S. Felix","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frederic T.","family":"Chong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"3_CR1","unstructured":"Crandall, J.R., Chong, F.T.: Minos: Control data attack prevention orthogonal to memory model. In: The 37th International Symposium on Microarchitecture (2004)"},{"key":"3_CR2","unstructured":"Bochs: The Open Source IA-32 Emulation Project, Home Page (2005), \n                    \n                      http:\/\/bochs.sourceforge.net"},{"key":"3_CR3","unstructured":"Biba, K.J.: Integrity considerations for secure computer systems. In: MITRE Technical Report TR-3153 (1977)"},{"key":"3_CR4","unstructured":"Crandall, J.R., Chong, F.T.: A security assessment of the minos architecture. In: Workshop on Architectural Support for Security and Anti-Virus (2004)"},{"key":"3_CR5","unstructured":"von Clausewitz, C.: On War (1832)"},{"key":"3_CR6","unstructured":"dark spyrit: Win32 Buffer Overflows (Location, Exploitation, and Prevention), Phrack 55 (1999)"},{"key":"3_CR7","unstructured":"Kolesnikov, O., Lee, W.: Advanced polymorphic worms: Evading ids by blending in with normal traffic (2004)"},{"key":"3_CR8","unstructured":"Litchfield, D.: Defeating the stack based buffer overflow prevention mechanism of microsoft windows 2003 server at black hat asia 2003 (2003), \n                    \n                      http:\/\/www.blackhat.com\/presentations\/bh-asia-03\/bh-asia-03-litchfield.pdf"},{"key":"3_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1007\/3-540-36084-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"T. Toth","year":"2002","unstructured":"Toth, T., Kr\u00fcgel, C.: Accurate buffer overflow detection via abstract payload execution. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 274\u2013291. Springer, Heidelberg (2002)"},{"key":"3_CR10","unstructured":"CLET team: Polymorphic Shellcode Engine Using Spectrum Analysis, Phrack 61 (2003)"},{"key":"3_CR11","unstructured":"ktwo: ADMmutate (2003), \n                    \n                      http:\/\/www.ktwo.ca"},{"key":"3_CR12","unstructured":"Phantasmal Phantasmagoria: White Paper on Polymorphic Evasion (2004), Available at \n                    \n                      http:\/\/www.addict3d.org"},{"key":"3_CR13","unstructured":"SANS Institute: SANS Intrusion Detection FAQ: What is polymorphism and what can it do? (2005)"},{"key":"3_CR14","unstructured":"sk: History and Advances in Windows Shellcode, Phrack 62 (2004)"},{"key":"3_CR15","unstructured":"Singh, S., Estan, C., Varghese, G., Savage, S.: Automated worm fingerprinting. In: OSDI (2004)"},{"key":"3_CR16","unstructured":"Nergal: The advanced return-into-lib(c) exploits: PaX case study. Phrack 58 (2001)"},{"key":"3_CR17","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1145\/1029618.1029631","volume-title":"WORM 2004: Proceedings of the 2004 ACM workshop on Rapid malcode","author":"F. Castaneda","year":"2004","unstructured":"Castaneda, F., Sezer, E.C., Xu, J.: WORM vs. WORM: preliminary study of an active counter-attack mechanism. In: WORM 2004: Proceedings of the 2004 ACM workshop on Rapid malcode, pp. 83\u201393. ACM Press, New York (2004)"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Pasupulati, A., Coit, J., Levitt, K., Wu, S., Li, S., Kuo, R., Fan, K.: Buttercup: On network-based detection of polymorphic buffer overflow vulnerabilities. In: 9th IEEE\/IFIP Network Operation and Management Symposium (2004)","DOI":"10.1109\/NOMS.2004.1317662"},{"key":"3_CR19","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1145\/1015467.1015489","volume-title":"SIGCOMM 2004: Proceedings of the 2004 conference on Applications, technologies, architectures, and protocols for computer communications","author":"H.J. Wang","year":"2004","unstructured":"Wang, H.J., Guo, C., Simon, D.R., Zugenmaier, A.: Shield: vulnerability-driven network filters for preventing known vulnerability exploits. In: SIGCOMM 2004: Proceedings of the 2004 conference on Applications, technologies, architectures, and protocols for computer communications, pp. 193\u2013204. ACM Press, New York (2004)"},{"key":"3_CR20","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Proceedings of the 12th Annual Network and Distributed System Security Symposium (2005)"},{"key":"3_CR21","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1109\/MSECP.2003.1193207","volume":"1","author":"L. Spitzner","year":"2003","unstructured":"Spitzner, L.: The honeynet project: Trapping the hackers. IEEE Security and Privacy\u00a01, 15\u201323 (2003)","journal-title":"IEEE Security and Privacy"},{"key":"3_CR22","unstructured":"The Eurecom Honeypot Project: (Home Page) (2005), \n                    \n                      http:\/\/www.eurecom.fr\/~pouget\/projects.htm"},{"key":"3_CR23","unstructured":"Staniford, S., Paxson, V., Weaver, N.: How to own the internet in your spare time. In: Proceedings of the USENIX Security Symposium, pp. 149\u2013167 (2002)"},{"key":"3_CR24","doi-asserted-by":"crossref","unstructured":"Suh, G.E., Lee, J., Devadas, S.: Secure program execution via dynamic information flow tracking. In: Proceedings of ASPLOS-XI (2004)","DOI":"10.1145\/1024393.1024404"},{"key":"3_CR25","unstructured":"Sidiroglou, S., Keromytis, A.: Countering network worms through automatic patch generation (2003)"},{"key":"3_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-540-30143-1_3","volume-title":"Recent Advances in Intrusion Detection","author":"D. Dagon","year":"2004","unstructured":"Dagon, D., Qin, X., Gu, G., Lee, W., Grizzard, J.B., Levine, J.G., Owen, H.L.: Honeystat: Local worm detection using honeypots. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 39\u201358. Springer, Heidelberg (2004)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11506881_3.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,27]],"date-time":"2021-04-27T06:44:18Z","timestamp":1619505858000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11506881_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005]]},"ISBN":["9783540266136","9783540316459"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/11506881_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2005]]}}}