{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T14:57:16Z","timestamp":1786978636609,"version":"3.56.0"},"publisher-location":"New York, NY","reference-count":38,"publisher":"Springer New York","isbn-type":[{"value":"9781461409762","type":"print"},{"value":"9781461409779","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-1-4614-0977-9_2","type":"book-chapter","created":{"date-parts":[[2011,8,19]],"date-time":"2011-08-19T12:24:22Z","timestamp":1313756662000},"page":"29-48","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":82,"title":["Effectiveness of Moving Target Defenses"],"prefix":"10.1007","author":[{"given":"David","family":"Evans","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anh","family":"Nguyen-Tuong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Knight","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2011,8,5]]},"reference":[{"key":"2_CR1_2","unstructured":"Alexander Peslyak (Solar Designer). Return-to-libc Attack. Bugtraq Mailing List, August 1997."},{"key":"2_CR2_2","doi-asserted-by":"crossref","unstructured":"Emery D. Berger and Benjamin G. Zorn. DieHard: Probabilistic Memory Safety for Unsafe Languages. In ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI), June 2006.","DOI":"10.1145\/1133981.1134000"},{"key":"2_CR3_2","unstructured":"Sandeep Bhatkar, Daniel DuVarney, and R. Sekar. Address Obfuscation: An Efficient Approach to Combat a Broad Range of Memory Error Exploits. In USENIX Security Symposium, 2003."},{"key":"2_CR4_2","doi-asserted-by":"crossref","unstructured":"StephenW. Boyd, Gaurav S. Kc, Michael E. Locasto, Angelos D. Keromytis, and Vassilis Prevelakis. On The General Applicability of Instruction-Set Randomization. IEEE Transactions on Dependable and Secure Computing, 7(3), 2010.","DOI":"10.1109\/TDSC.2008.58"},{"key":"2_CR5_2","unstructured":"Kevin Brown. Balls In Bins with Limited Capacity. \n                  http:\/\/www.mathpages.com\/\n                  \n                 home\/kmath337.htm."},{"key":"2_CR6_2","volume-title":"Apple\u2019s Snow Leopard Is Less Secure Than Windows","author":"BX Chen","year":"2009","unstructured":"Brian X. Chen. Apple\u2019s Snow Leopard Is Less Secure Than Windows, But Safer. Wired, September 2009."},{"key":"2_CR7_2","volume-title":"and Ravishankar K","author":"S Chen","year":"2005","unstructured":"Shuo Chen, Jun Xu, Emre C. Sezer, Prachi Gauriar, and Ravishankar K. Iyer. Non-Control- Data Attacks Are Realistic Threats. In USENIX Security Symposium, 2005."},{"key":"2_CR8_2","unstructured":"Crispin Cowan, Steve Beattie, John Johansen, and PerryWagle. PointGuard: Protecting Pointers from Buffer Overflow Vulnerabilities. In 12th USENIX Security Symposium, 2003."},{"key":"2_CR9_2","unstructured":"Benjamin Cox, David Evans, Adrian Filipi, Jonathan Rowanhill,Wei Hu, Jack Davidson, John Knight, Anh Nguyen-Tuong, and Jason Hiser. N-Variant Systems: A Secretless Framework for Security through Diversity. In USENIX Security Symposium, 2006."},{"key":"2_CR10_2","unstructured":"Cristian Cadar and Periklis Akritidis and Manuel Costa and Jean-Phillipe Martin and Miguel Castro. Data Randomization. Technical Report TR-120-2008, Microsoft Research, 2008."},{"key":"2_CR11_2","unstructured":"Tyler Durden. Bypassing PaX ASLR protection. \n                  http:\/\/www.phrack.com\/issues.html?issue=59\\&id=9\/\n                  \n                , 2009."},{"key":"2_CR12_2","doi-asserted-by":"crossref","unstructured":"Elena Gabriela Barrantes and David Ackley and Stephanie Forrest and Trek Palmer and Darko Stefanovic and Dino Dai Zovi. Intrusion Detection: Randomized Instruction Set Emulation to Disrupt Binary Code Injection Attacks. In 10th ACM Conference on Computer and Communications Security (CCS), 2003.","DOI":"10.1145\/948109.948147"},{"key":"2_CR13_2","doi-asserted-by":"crossref","unstructured":"Elena Gabriela Barrantes and David H. Ackley and Stephanie Forrest and Darko Stefanovic. Randomized Instruction Set Emulation. ACM Transactions on Information and System Security, February 2005.","DOI":"10.1145\/1053283.1053286"},{"key":"2_CR14_2","unstructured":"Gaurav S. Kc and Angelos D. Keromytis and Vassilis Prevelakis. Countering Code-Injection Attacks with Instruction-Set Randomization. In 10th ACM Conference on Computer and Communications Security (CCS), 2003."},{"key":"2_CR15_2","unstructured":"Sudhakar Govindavajhala and Andrew W. Appel. Using Memory Errors to Attack a Virtual Machine. In IEEE Symposium on Security and Privacy (Oakland), 2003."},{"key":"2_CR16_2","doi-asserted-by":"crossref","unstructured":"Norman Hardy. The Confused Deputy (or why capabilities might have been invented). ACM SIGOPS Operating Systems Review, 22(4), October 1988.","DOI":"10.1145\/54289.871709"},{"key":"2_CR17_2","volume-title":"An Architecture A Day Keeps The Hacker Away","author":"D Holland","year":"2004","unstructured":"David Holland, Ada Lim, and Margo Seltzer. An Architecture A Day Keeps The Hacker Away. In Workshop on Architectural Support for Security and Anti-Virus, April 2004."},{"key":"2_CR18_2","unstructured":"Kubuntu Wiki. Supported Position Independent Executables. \n                  https:\/\/wiki.kubuntu\n                  \n                . org\/SecurityTeam\/KnowledgeBase\/BuiltPIE, 2011."},{"key":"2_CR19_2","unstructured":"Microsoft Corporation. Microsoft Security Advisory (961051): Vulnerability in Internet Explorer Could Allow Remote Code Execution. \n                  http:\/\/www.microsoft.com\/\n                  \n                 technet\/security\/advisory\/961051.mspx, December 2008."},{"key":"2_CR20_2","unstructured":"Tilo M\u00a8uller. ASLR Smack and Laugh Reference. Seminar on Advanced Exploitation Techniques, February 2008."},{"key":"2_CR21_2","volume-title":"Adobe PDF Exploits Using Signed Certificates","author":"R Naraine","year":"2010","unstructured":"Ryan Naraine. Adobe PDF Exploits Using Signed Certificates, Bypasses ASLR\/DEP. ZDNet Zero Day, September 2010."},{"key":"2_CR22_2","volume-title":"Security through Redundant Data Diversity","author":"A Nguyen-Tuong","year":"2008","unstructured":"Anh Nguyen-Tuong, David Evans, John C. Knight, Benjamin Cox, and Jack W. Davidson. Security through Redundant Data Diversity. In IEEE\/IFPF International Conference on Dependable Systems and Networks, June 2008."},{"key":"2_CR23_2","doi-asserted-by":"crossref","unstructured":"Anh Nguyen-Tuong, Andrew Wang, Jason D. Hiser, John C. Knight, and Jack W. Davidson. On the effectiveness of the metamorphic shield. In Proceedings of the Fourth European Conference on Software Architecture: Companion Volume, ECSA \u201910, pages 170\u2013174, New York, NY, USA, 2010. ACM.","DOI":"10.1145\/1842752.1842788"},{"key":"2_CR24_2","unstructured":"Pratap V. Prahbu and Yingbo Song and Salvatore J. Stolfo. Smashing the Stack with Hydra: The Many Heads of Advanced Polymorphic Shellcode. Technical Report CUCS-037-09, Columbia University, August 2009."},{"key":"2_CR25_2","unstructured":"Rapid7 LLC. Metasploit. \n                  http:\/\/www.metasploit.com\/\n                  \n                , 2003\u20132011."},{"key":"2_CR26_2","unstructured":"Paruj Ratanaworabhan, Benjamin Livshits, and Benjamin Zorn. Nozzle: A Defense Against Heap-spraying Code Injection Attacks. In USENIX Security Symposium, 2009."},{"key":"2_CR27_2","volume-title":"Reverse Stack Execution in a Multi-Variant Execution Environment","author":"B Salamat","year":"2008","unstructured":"Babak Salamat, Andreas Gal, and Michael Franz. Reverse Stack Execution in a Multi-Variant Execution Environment. In Workshop on Compiler and Architectural Techniques for Application Reliability and Security, June 2008."},{"key":"2_CR28_2","doi-asserted-by":"crossref","unstructured":"Babak Salamat, Todd Jackson, Andreas Gal, and Michael Franz. Orchestra: Intrusion Detection using Parallel Execution and Monitoring of Program Variants in User-Space. In ACM European Conference on Computer Systems (EuroSys), 2009.","DOI":"10.1145\/1519065.1519071"},{"key":"2_CR29_2","doi-asserted-by":"crossref","unstructured":"Hovav Shacham, Matthew Page, Ben Pfaff, Eu-Jin Goh, Nagendra Modadugu, and Dan Boneh. On the effectiveness of address-space randomization. In ACM Conference on Computer and Communications Security (CCS), CCS \u201904, pages 298\u2013307, New York, NY, USA, 2004. ACM.","DOI":"10.1145\/1030083.1030124"},{"key":"2_CR30_2","unstructured":"Alexander Sotirov. Heap Feng Shui in JavaScript. \n                  http:\/\/www.blackhat\n                  \n                . com\/presentations\/bh-europe-07\/Sotirov\/Presentation\/ bh-eu-07-sotirov-apr19.pdf, 2007."},{"key":"2_CR31_2","unstructured":"Ana Nora Sovarel, David Evans, and Nathanael Paul. Where\u2019s the feeb? the effectiveness of instruction set randomization. In 14th USENIX Security Symposium, Berkeley, CA, USA, 2005. USENIX Association."},{"key":"2_CR32_2","unstructured":"Stephanie Forrest and Anil Somayaji and David Ackley. Building Diverse Computer Systems. In Hot Topics in Operating Systems, 1997."},{"key":"2_CR33_2","unstructured":"Stephen W. Boyd and Angelos D. Keromytis. SQLrand: Preventing SQL Injection Attacks. In Applied Cryptography and Network Security (ACNS), 2004."},{"key":"2_CR34_2","volume-title":"and Thomas Walter","author":"R Strackx","year":"2009","unstructured":"Raoul Strackx, Yves Younan, Pieter Philippaerts, Frank Piessens, Sven Lachmund, and Thomas Walter. Breaking the Memory Secrecy Assumption. In Second European Workshop on System Security, 2009."},{"key":"2_CR35_2","unstructured":"PaX Team. PaX Homepage. \n                  http:\/\/pax.grsecurity.net\/\n                  \n                , 2000."},{"key":"2_CR36_2","doi-asserted-by":"crossref","unstructured":"Wei Hu and Jason Hiser and DanWilliams and Adrian Filipi and JackW. Davidson and David Evans and John C. Knight and Anh Nguyen-Tuong and Jonathan Rowanhill. Secure and Practical Defense Against Code-injection Attacks Using Software Dynamic Translation. In Second International Conference on Virtual Execution Environments, 2006.","DOI":"10.1145\/1134760.1134764"},{"key":"2_CR37_2","doi-asserted-by":"crossref","unstructured":"Yoav Weiss and Elena Gabriela Barrantes. Known\/Chosen Key Attacks against Software Instruction Set Randomization. In Annual Computer Security Applications Conference (ACSAC), 2006.","DOI":"10.1109\/ACSAC.2006.33"},{"key":"2_CR38_2","unstructured":"Berend-Jan \u201cSkyLined\u201d Wever. MS Internet Explorer (IFRAME Tag) Buffer Overflow Exploit. \n                  http:\/\/www.exploit-db.com\/exploits\/612\/\n                  \n                , 2004."}],"container-title":["Advances in Information Security","Moving Target Defense"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-0977-9_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,21]],"date-time":"2019-05-21T15:46:33Z","timestamp":1558453593000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-1-4614-0977-9_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9781461409762","9781461409779"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-0977-9_2","relation":{},"ISSN":["1568-2633"],"issn-type":[{"value":"1568-2633","type":"print"}],"subject":[],"published":{"date-parts":[[2011]]},"assertion":[{"value":"5 August 2011","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}