{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T18:01:09Z","timestamp":1773511269341,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":23,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540317784","type":"print"},{"value":"9783540317791","type":"electronic"}],"license":[{"start":{"date-parts":[[2006,1,1]],"date-time":"2006-01-01T00:00:00Z","timestamp":1136073600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11663812_10","type":"book-chapter","created":{"date-parts":[[2006,1,20]],"date-time":"2006-01-20T07:57:08Z","timestamp":1137743828000},"page":"185-206","source":"Crossref","is-referenced-by-count":23,"title":["Environment-Sensitive Intrusion Detection"],"prefix":"10.1007","author":[{"given":"Jonathon T.","family":"Giffin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Dagon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Somesh","family":"Jha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenke","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Barton P.","family":"Miller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Chinchani, R., Iyer, A., Jayaraman, B., Upadhyaya, S.: ARCHERR: Runtime environment driven program safety. In: 9th European Symposium on Research in Computer Security, Sophia Antipolis, France (September 2004)","DOI":"10.1007\/978-3-540-30108-0_24"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Clarke, E.M., Grumberg, O., Jha, S., Lu, Y., Veith, H.: Counterexample-guided abstraction refinement. In: Computer Aided Verification, Chicago, IL (July 2000)","DOI":"10.1007\/10722167_15"},{"key":"10_CR3","doi-asserted-by":"publisher","first-page":"805","DOI":"10.1016\/S1389-1286(98)00017-6","volume":"31","author":"H. Debar","year":"1999","unstructured":"Debar, H., Dacier, M., Wespi, A.: Towards a taxonomy of intrusion-detection systems. Computer Networks\u00a031, 805\u2013822 (1999)","journal-title":"Computer Networks"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Esparza, J., Hansel, D., Rossmanith, P., Schwoon, S.: Efficient algorithms for model checking pushdown systems. In: Computer Aided Verification, Chicago, IL (July 2000)","DOI":"10.1007\/10722167_20"},{"key":"10_CR5","unstructured":"Feng, H.H., Giffin, J.T., Huang, Y., Jha, S., Lee, W., Miller, B.P.: Formalizing sensitivity in static analysis for intrusion detection. In: IEEE Symposium on Security and Privacy, Oakland, CA (May 2004)"},{"key":"10_CR6","unstructured":"Feng, H.H., Kolesnikov, O.M., Fogla, P., Lee, W., Gong, W.: Anomaly detection using call stack information. In: IEEE Symposium on Security and Privacy, Oakland, CA (May 2003)"},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"Fix, L., Schneider, F.B.: Reasoning about programs by exploiting the environment. In: 21st International Colloquium on Automata, Languages, and Programming, Jerusalem, Israel (July 1994)","DOI":"10.1007\/3-540-58201-0_79"},{"key":"10_CR8","unstructured":"Gao, D., Reiter, M.K., Song, D.: On gray-box program tracking for anomaly detection. In: 13th USENIX Security Symposium, San Diego, CA (August 2004)"},{"key":"10_CR9","unstructured":"Giffin, J.T., Jha, S., Miller, B.P.: Detecting manipulated remote call streams. In: 11th USENIX Security Symposium, San Francisco, CA (August 2002)"},{"key":"10_CR10","unstructured":"Giffin, J.T., Jha, S., Miller, B.P.: Efficient context-sensitive intrusion detection. In: 11th Network and Distributed Systems Security Symposium, San Diego, CA (February 2004)"},{"key":"10_CR11","unstructured":"httpd. Solaris manual pages, ch. 8 (February 1997)"},{"key":"10_CR12","volume-title":"The Shellcoder\u2019s Handbook: Discovering and Exploiting Security Holes","author":"J. Koziol","year":"2003","unstructured":"Koziol, J., Litchfield, D., Aitel, D., Anley, C., Eren, S., Mehta, N., Hassell, R.: The Shellcoder\u2019s Handbook: Discovering and Exploiting Security Holes. Wiley, Chichester (2003)"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Mutz, D., Valeur, F., Vigna, G.: On the detection of anomalous system call arguments. In: 8th European Symposium on Research in Computer Security, Gj\u00f8vik, Norway, October 2003, pp. 326\u2013343 (2003)","DOI":"10.1007\/978-3-540-39650-5_19"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Lam, L.-C, Chiueh, T.-C: Automatic extraction of accurate application-specific sandboxing policy. In: Recent Advances in Intrusion Detection, Sophia Antipolis, France (September 2004)","DOI":"10.1007\/978-3-540-30143-1_1"},{"key":"10_CR15","volume-title":"Advanced Compiler Design and Implementation","author":"S.S. Muchnick","year":"1997","unstructured":"Muchnick, S.S.: Advanced Compiler Design and Implementation. Morgan Kaufmann Publishers, San Francisco (1997)"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Sekar, R., Venkatakrishnan, V.N., Basu, S., Bhatkar, S., DuVarney, D.C.: Model-carrying code: A practical approach for safe execution of untrusted applications. In: ACM Symposium on Operating System Principles, Bolton Landing, NY (October 2003)","DOI":"10.1145\/945446.945448"},{"key":"10_CR17","first-page":"189","volume-title":"Program Flow Analysis: Theory and Applications, ch. 7","author":"M. Sharir","year":"1981","unstructured":"Sharir, M., Pnueli, A.: Two approaches to interprocedural data flow analysis. In: Muchnick, S.S., Jones, N.D. (eds.) Program Flow Analysis: Theory and Applications, ch. 7, pp. 189\u2013233. Prentice-Hall, Englewood Cliffs (1981)"},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"Tan, K., McHugh, J., Killourhy, K.: Hiding intrusions: From the abnormal to the normal and beyond. In: 5th International Workshop on Information Hiding, Noordwijkerhout, Netherlands (October 2002)","DOI":"10.1007\/3-540-36415-3_1"},{"key":"10_CR19","unstructured":"U.S. Department of Energy Computer Incident Advisory Capability. M-026: OpenSSH uselogin privilege elevation vulnerability (December 2001)"},{"key":"10_CR20","unstructured":"Wagner, D., Dean, D.: Intrusion detection via static analysis. In: IEEE Symposium on Security and Privacy, Oakland, CA (May 2001)"},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"Wagner, D., Soto, P.: Mimicry attacks on host based intrusion detection systems. In: 9th ACM Conference on Computer and Communications Security, Washington, DC (November 2002)","DOI":"10.1145\/586110.586145"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"Wagner, D.A.: Static Analysis and Computer Security: New Techniques for Software Assurance. PhD dissertation, University of California at Berkeley (Fall 2000)","DOI":"10.1007\/3-540-47764-0_25"},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Yannakakis, M.: Graph-theoretic methods in database theory. In: ACM Symposium on Principles of Database Systems, Nashville, TN (April 1990)","DOI":"10.1145\/298514.298576"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11663812_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T14:16:40Z","timestamp":1558275400000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11663812_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540317784","9783540317791"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/11663812_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006]]}}}