{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T13:05:02Z","timestamp":1782133502148,"version":"3.54.5"},"publisher-location":"New York, NY","reference-count":55,"publisher":"Springer New York","isbn-type":[{"value":"9781461409762","type":"print"},{"value":"9781461409779","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-1-4614-0977-9_3","type":"book-chapter","created":{"date-parts":[[2011,8,19]],"date-time":"2011-08-19T16:24:22Z","timestamp":1313771062000},"page":"49-76","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Global ISR: Toward a Comprehensive Defense Against Unauthorized Code Execution"],"prefix":"10.1007","author":[{"given":"Georgios","family":"Portokalidis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2011,8,5]]},"reference":[{"key":"3_CR1_3","unstructured":"Wagner, D., Foster, J.S., Brewer, E.A., Aiken, A.: A first step towards automated detection of buffer overrun vulnerabilities. In: Proceedings of the Symposium on Network and Distributed System Security (NDSS). (2000) 3\u201317"},{"key":"3_CR2_3","unstructured":"Spafford, E.H.: The Internet worm program: An analysis. Technical Report CSD-TR-823, Purdue University (1988)"},{"key":"3_CR3_3","unstructured":"CERT: Advisory CA-2001-19: \u201cCode Red\u201d worm exploiting buffer overflow in IIS indexing service DLL. http:\/\/www.cert.org\/advisories\/CA-2001-19.html (2001)"},{"key":"3_CR4_3","unstructured":"CERT: Advisory CA-2003-04: MS-SQL Server Worm. http:\/\/www.cert.org\/ advisories\/CA-2003-04.html (2003)"},{"key":"3_CR5_3","doi-asserted-by":"crossref","unstructured":"Moore, D., Shanning, C., Claffy, K.: Code-Red: a case study on the spread and victims of an Internet worm. In: Proceedings of the 2nd Internet Measurement Workshop (IMW). (2002) 273\u2013284","DOI":"10.1145\/637201.637244"},{"key":"3_CR6_3","doi-asserted-by":"crossref","unstructured":"Zou, C.C., Gong, W., Towsley, D.: Code Red worm propagation modeling and analysis. In: Proceedings of the 9th ACM Conference on Computer and Communications Security (CCS). (2002) 138\u2013147","DOI":"10.1145\/586110.586130"},{"key":"3_CR7_3","volume-title":"Conficker C analysis","author":"P Porras","year":"2009","unstructured":"Porras, P., Saidi, H., Yegneswaran, V.: Conficker C analysis. Technical report, SRI International (2009)"},{"key":"3_CR8_3","unstructured":"Falliere, N., Murchu, L.O., Chien, E.: W32.Stuxnet Dossier version 1.2. White paper (2010)"},{"key":"3_CR9_3","unstructured":"Adobe: Security advisory for flash player, adobe reader and acrobat. http:\/\/www.adobe. com\/support\/security\/advisories\/apsa10-01.html (2010)"},{"key":"3_CR10_3","unstructured":"Symantec: Analysis of a zero-day exploit for adobe flash and reader. Symantec Threat Research (2010)"},{"key":"3_CR11_3","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/MSP.2004.36","volume":"2","author":"J Pincus","year":"2004","unstructured":"Pincus, J., Baker, B.: Beyond stack smashing: Recent advances in exploiting buffer overflows. IEEE Security & Privacy Magazine 2 (2004) 20\u201327","journal-title":"IEEE Security & Privacy Magazine"},{"key":"3_CR12_3","unstructured":"Aleph One: Smashing the stack for fun and profit. Phrack 7 (1996)"},{"key":"3_CR13_3","unstructured":"M. Conover and w00w00 Security Team: w00w00 on heap overflows. http:\/\/www. w00w00.org\/files\/articles\/heaptut.txt (2010)"},{"key":"3_CR14_3","unstructured":"Enumeration, C.W.: CWE-416: use after free. http:\/\/cwe.mitre.org\/data\/ definitions\/416.html (2010)"},{"key":"3_CR15_3","unstructured":"PCWorld: Dangling pointers could be dangerous. http:\/\/www.pcworld.com\/ article\/134982\/dangling\\_pointers\\_could\\_be\\_dangerous.html (2007)"},{"key":"3_CR16_3","unstructured":"Shankar, U., Talwar, K., Foster, J.S., Wagner, D.: Detecting format string vulnerabilities with type qualifiers. In: Proceedings of the 10th USENIX Security Symposium. (2001) 201\u2013216"},{"key":"3_CR17_3","doi-asserted-by":"crossref","unstructured":"Kc, G.S., Keromytis, A.D., Prevelakis, V.: Countering code-injection attacks with instructionset randomization. In: Proceedings of the 10th ACM Conference on Computer and Communications Security (CCS). (2003)","DOI":"10.1145\/948109.948146"},{"key":"3_CR18_3","doi-asserted-by":"crossref","unstructured":"Barrantes, E.G., Ackley, D.H., Forrest, S., Palmer, T.S., Stefanovic, D., Zovi, D.D.: Randomized instruction set emulation to disrupt binary code injection attacks. In: Proceedings of the ACM Conference on Computer and Communications Security. (2003) 281\u2013289","DOI":"10.1145\/948109.948147"},{"key":"3_CR19_3","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1145\/1053283.1053286","volume":"8","author":"E.G. Barrantes","year":"2005","unstructured":"Barrantes, E.G., Ackley, D.H., Forrest, S., Stefanovi\u00b4c, D.: Randomized instruction set emulation. ACM Transactions on Information System Security 8 (2005) 3\u201340","journal-title":"ACM Transactions on Information System Security"},{"key":"3_CR20_3","unstructured":"Sovarel, A.N., Evans, D., Paul, N.: Where\u2019s the FEEB? the effectiveness of instruction set randomization. In: Proceedings of the 14th USENIX Security Symposium. (2005) 145\u2013160"},{"key":"3_CR21_3","unstructured":"Microsoft: Microsoft Portable Executable and Common Object File Format Specification. http:\/\/www.microsoft.com\/whdc\/system\/platform\/firmware\/ PECOFF.mspx (2010)"},{"key":"3_CR22_3","unstructured":"Raghuram, S., Chakrabarti, C.: A programmable processor for cryptography. In: Proceedings of the 2000 IEEE International Symposium on Circuits and Systems (ISCAS). Volume 5. (2000) 685\u2013688"},{"key":"3_CR23_3","unstructured":"Rogers, B., Solihin, Y., Prvulovic, M.: Memory Predecryption: Hiding the Latency Overhead of Memory Encryption. In: Proceedings of the Workshop on Architectural Support for Security and Anti-virus (WASSA). (2004) 22\u201328"},{"key":"3_CR24_3","unstructured":"The Bochs Project: The cross platform IA-32 emulator. http:\/\/bochs.sourceforge. net\/ (2010)"},{"key":"3_CR25_3","doi-asserted-by":"crossref","unstructured":"Prevelakis, V., Keromytis, A.D.: Drop-in Security for Distributed and Portable Computing Elements. Internet Research: Electronic Networking, Applications and Policy 13 (2003)","DOI":"10.1108\/10662240310469763"},{"key":"3_CR26_3","doi-asserted-by":"crossref","unstructured":"Hu, W., Hiser, J., Williams, D., Filipi, A., Davidson, J.W., Evans, D., Knight, J.C., Nguyen- Tuong, A., Rowanhill, J.: Secure and practical defense against code-injection attacks using software dynamic translation. In: Proceedings of the 2nd International Conference on Virtual Execution Environments (VEE). (2006) 2\u201312","DOI":"10.1145\/1134760.1134764"},{"key":"3_CR27_3","doi-asserted-by":"crossref","unstructured":"Luk, C.K., Cohn, R., Muth, R., Patil, H., Klauser, A., Lowney, G., Wallace, S., Reddi, V.J., Hazelwood, K.: Pin: Building customized program analysis tools with dynamic instrumentation. In: Proceedings of Programming Language Design and Implementation (PLDI). (2005) 190\u2013200","DOI":"10.1145\/1064978.1065034"},{"key":"3_CR28_3","unstructured":"Hancock, S.: The Perltidy Home Page. http:\/\/perltidy.sourceforge.net\/ (2009)"},{"key":"3_CR29_3","unstructured":"CERT: Vulnerability Note VU#496064. http:\/\/www.kb.cert.org\/vuls\/id\/ 496064 (2002)"},{"key":"3_CR30_3","unstructured":"CERT: Vulnerability Note VU#282403. http:\/\/www.kb.cert.org\/vuls\/id\/ 282403 (2002)"},{"key":"3_CR31_3","unstructured":"Cox, B., Evans, D., Filipi, A., Rowanhill, J., Hu, W., Davidson, J., Knight, J., Nguyen-Tuong, A., Hiser, J.: N-Variant Systems: A Secretless Framework for Security through Diversity. In: Proceedings of the 15th USENIX Security Symposium. (2005) 105\u2013120"},{"key":"3_CR32_3","volume-title":"Vigilante: End-to-end containment of internet worms","author":"M Costa","year":"2005","unstructured":"Costa, M., Crowcroft, J., Castro, M., Rowstron, A.: Vigilante: End-to-end containment of internet worms. In: Proceedings of the ACM Symposium on Systems and Operating Systems Principles (SOSP). (2005)"},{"key":"3_CR33_3","doi-asserted-by":"crossref","unstructured":"Xu, J., Ning, P., Kil, C., Zhai, Y., Bookholt, C.: Automatic Diagnosis and Response to Memory Corruption Vulnerabilities. In: Proceedings of the 12th ACM Conference on Computer and Communications Security (CCS). (2005) 222\u2013234","DOI":"10.1145\/1102120.1102151"},{"key":"3_CR34_3","doi-asserted-by":"crossref","unstructured":"Locasto, M., Wang, K., Keromytis, A., Stolfo, S.: FLIPS: Hybrid Adaptive Intrusion Prevention. In: Proceedings of the Symposium on Recent Advances in Intrusion Detection. (2005) 82\u2013101","DOI":"10.1007\/11663812_5"},{"key":"3_CR35_3","doi-asserted-by":"crossref","unstructured":"Liang, Z., Sekar, R.: Fast and Automated Generation of Attack Signatures: A Basis for Building Self-Protecting Servers. In: Proceedings of the 12th ACM Conference on Computer and Communications Security (CCS). (2005) 213\u2013222","DOI":"10.1145\/1102120.1102150"},{"key":"3_CR36_3","unstructured":"Boyd, S.W., Kc, G.S., Locasto, M.E., Keromytis, A.D., Prevelakis, V.: On the general applicability of instruction-set randomization. IEEE Transactions on Dependable and Secure Computing 99 (2008)"},{"key":"3_CR37_3","unstructured":"Developers, V.: Valgrind user manual \u2013 callgrind. http:\/\/valgrind.org\/docs\/ manual\/cl-manual.html (2010)"},{"key":"3_CR38_3","unstructured":"Bhatkar, S., DuVarney, D.C., Sekar, R.: Address obfuscation: an efficient approach to combat a broad range of memory error exploits. In: Proceedings of the 12th USENIX Security Symposium. (2003) 105\u2013120"},{"key":"3_CR39_3","unstructured":"The PaX Team: Homepage of The Pax Team. http:\/\/pax.grsecurity.net\/ (2010)"},{"key":"3_CR40_3","doi-asserted-by":"crossref","unstructured":"Shacham, H., Page, M., Pfaff, B., Goh, E., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM Conference on Computer and Communications Security (CCS). (2004) 298\u2013307","DOI":"10.1145\/1030083.1030124"},{"key":"3_CR41_3","unstructured":"Bhatkar, S., Sekar, R., DuVarney, D.C.: Efficient techniques for comprehensive protection from memory error exploits. In: Proceedings of the 14th USENIX Security Symposium. (2005) 255\u2013270"},{"key":"3_CR42_3","unstructured":"Durden, T.: Bypassing PaX ASLR protection. Phrack 0x0b (2002)"},{"key":"3_CR43_3","unstructured":"DarkReading: Heap spraying: Attackers\u2019 latest weapon of choice. http: \/\/www.darkreading.com\/security\/vulnerabilities\/showArticle. jhtml?articleID=221901428 (2009)"},{"key":"3_CR44_3","unstructured":"Hardware, E.: CPU-based security: The NX bit. http:\/\/hardware.earthweb.com\/ chips\/article.php\/3358421 (2004)"},{"key":"3_CR45_3","unstructured":"Cowan, C., Beattie, S., Johansen, J., Wagle, P.: PointGuard: Protecting pointers from buffer overflow vulnerabilities. In: Proceedings of the 12th USENIX Security Symposium. (2003) 91\u2013104"},{"key":"3_CR46_3","unstructured":"Cowan, C., Pu, C., Maier, D., Hinton, H., Walpole, J., Bakke, P., Beattie, S., Grier, A., Wagle, P., Zhang, Q.: StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks. In: Proceedings of the 7th USENIX Security Symposium. (1998)"},{"key":"3_CR47_3","unstructured":"Etoh, J.: GCC extension for protecting applications from stack-smashing attacks. http: \/\/www.trl.ibm.com\/projects\/security\/ssp\/ (2000)"},{"key":"3_CR48_3","unstructured":"Bulba, Kil3r: Bypassing StackGuard and StackShield. Phrack 5 (2000)"},{"key":"3_CR49_3","doi-asserted-by":"crossref","unstructured":"Akritidis, P., Cadar, C., Raiciu, C., Costa, M., Castro, M.: Preventing memory error exploits with WIT. In: Proceedings of the 2008 IEEE Symposium on Security and Privacy. (2008) 263\u2013277","DOI":"10.1109\/SP.2008.30"},{"key":"3_CR50_3","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1145\/1065887.1065892","volume":"27","author":"GC Necula","year":"2005","unstructured":"Necula, G.C., Condit, J., Harren, M., McPeak, S., Weimer, W.: CCured: type-safe retrofitting of legacy software. ACM Trans. Program. Lang. Syst. 27 (2005) 477\u2013526","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"3_CR51_3","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Proceedings of the 12th Annual Symposium on Network and Distributed System Security (NDSS). (2005)"},{"key":"3_CR52_3","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1145\/360051.360056","volume":"19","author":"DE Denning","year":"1976","unstructured":"Denning, D.E.: A lattice model of secure information flow. Commun. ACM 19 (1976) 236\u2013 243","journal-title":"Commun. ACM"},{"key":"3_CR53_3","doi-asserted-by":"crossref","unstructured":"Ho, A., Fetterman, M., Clark, C.,Warfield, A., Hand, S.: Practical taint-based protection using demand emulation. In: Proceedings of the 1st ACM EuroSys Conference. (2006) 29\u201341","DOI":"10.1145\/1218063.1217939"},{"key":"3_CR54_3","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: TTAnalyze: A tool for analyzing malware. In: Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR) Annual Conference. (2006)"},{"key":"3_CR55_3","doi-asserted-by":"crossref","unstructured":"Portokalidis, G., Slowinska, A., Bos, H.: Argos: an emulator for fingerprinting zero-day attacks. In: Proceedings of the 1st ACM EuroSys Conference. (2006)","DOI":"10.1145\/1217935.1217938"}],"container-title":["Advances in Information Security","Moving Target Defense"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-0977-9_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,11]],"date-time":"2023-02-11T06:19:12Z","timestamp":1676096352000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-1-4614-0977-9_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9781461409762","9781461409779"],"references-count":55,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-0977-9_3","relation":{},"ISSN":["1568-2633"],"issn-type":[{"value":"1568-2633","type":"print"}],"subject":[],"published":{"date-parts":[[2011]]},"assertion":[{"value":"5 August 2011","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}