{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T19:58:10Z","timestamp":1778788690965,"version":"3.51.4"},"publisher-location":"New York, NY","reference-count":39,"publisher":"Springer New York","isbn-type":[{"value":"9781461409762","type":"print"},{"value":"9781461409779","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-1-4614-0977-9_8","type":"book-chapter","created":{"date-parts":[[2011,8,19]],"date-time":"2011-08-19T16:24:22Z","timestamp":1313771062000},"page":"131-151","source":"Crossref","is-referenced-by-count":59,"title":["Introducing Diversity and Uncertainty to Create Moving Attack Surfaces for Web Services"],"prefix":"10.1007","author":[{"given":"Yih","family":"Huang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anup K.","family":"Ghosh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2011,8,5]]},"reference":[{"key":"8_CR1_8","unstructured":"The Top Cyber Security Risks in Year 2009, http:\/\/www.sans.org\/top-cyber-security-risks ."},{"key":"8_CR2_8","doi-asserted-by":"crossref","unstructured":"Yih Huang; Ghosh, A.K.; Bracewell, T.; Mastropietro, B.;, \u201cA security evaluation of a novel resilient web serving architecture: Lessons learned through industry\/academia collaboration,\u201d Dependable Systems and Networks Workshops (DSN-W), International Conference on, June 28 to July 1, 2010.","DOI":"10.1109\/DSNW.2010.5542597"},{"key":"8_CR3_8","doi-asserted-by":"crossref","unstructured":"Yih Huang, Anup K. Ghosh, \u201cAutomating Intrusion Response via Virtualization for Realizing Uninterruptible Web Services,\u201d Eighth IEEE International Symposium on Network Computing and Applications (NCA\u201909), 2009.","DOI":"10.1109\/NCA.2009.37"},{"key":"8_CR4_8","unstructured":"Fielding, R. T. and Taylor, R. N. 2002. \u201cPrincipled design of the modern Web architecture,\u201d ACM Trans. Internet Technology. 2, 2 (May. 2002), 115\u2013150."},{"key":"8_CR5_8","unstructured":"Microsoft WCF Data Service, http:\/\/msdn.microsoft.com\/en-us\/data\/odata.aspx"},{"key":"8_CR6_8","unstructured":"Google Dalvik VM, http:\/\/www.dalvik.com"},{"issue":"1","key":"8_CR7_8","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1145\/1053283.1053286","volume":"8","author":"E. G. Barrantes","year":"2005","unstructured":"E. G. Barrantes, D. H. Ackley, S. Forrest, and D. Stefanovic. \u201cRandomized instruction set emulation,\u201d ACM Trans. Info. & System Security, 8(1):3 40, Feb. 2005.","journal-title":"ACM Trans. Info. & System Security"},{"key":"8_CR8_8","unstructured":"Java Servlet Technologies, http:\/\/www.oracle.com\/technetwork\/java\/index-jsp-135475.html"},{"key":"8_CR9_8","unstructured":"http:\/\/en.wikipedia.org\/wiki\/List of Linux distributions"},{"key":"8_CR10_8","volume-title":"\u201cThe geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86)\u201d, CCS \u201907 Proceedings of the 14th ACM conference on Computer and communications security","author":"H Shacham","year":"2007","unstructured":"Hovav Shacham, \u201cThe geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86),\u201d CCS \u201907 Proceedings of the 14th ACM conference on Computer and communications security. Whistler, BC, October 2007."},{"key":"8_CR11_8","unstructured":"Gaurav S. Kc, Angelos D. Keromytis, and Vassilis Prevelakis. 2003. \u201cCountering codeinjection attacks with instruction-set randomization,\u201d In Proceedings of the 10th ACM conference on Computer and communications security (CCS \u201903). ACM, New York, NY, USA, 272\u2013280."},{"key":"8_CR12_8","unstructured":"National Institute of Standards, NIST. National vulnerability database, http:\/\/nvd.nist.gov ."},{"key":"8_CR13_8","unstructured":"R. Wojtczuk. \u201cSubverting the Xen hypervisor,\u201d in Black Hat USA, 2008."},{"key":"8_CR14_8","unstructured":"Fabrice Bellard. Qemu, \u201cA fast and portable dynamic translator,\u201d In Proceedings of the USENIX 2005 Annual Technical Conference, FREENIX Track, pages 41\u201346, 2005."},{"key":"8_CR15_8","unstructured":"VMware, Inc. http:\/\/www.vmware.com ."},{"key":"8_CR16_8","volume-title":"\u201cXen and the art of virtualization\u201d, In Proceedings of the nineteenth ACM symposium on Operating systems principles (SOSP \u201903)","author":"P Barham","year":"2003","unstructured":"Paul Barham, Boris Dragovic, Keir Fraser, Steven Hand, Tim Harris, Alex Ho, Rolf Neugebauer, Ian Pratt, and Andrew Warfield. \u201cXen and the art of virtualization,\u201d In Proceedings of the nineteenth ACM symposium on Operating systems principles (SOSP \u201903). New York, NY, USA, 2003."},{"key":"8_CR17_8","unstructured":"OpenVZ lightweigt virtualization, http:\/\/openvz.org ."},{"key":"8_CR18_8","unstructured":"D. Price and A. Tucker. \u201cSolaris zones: Operating system support for consolidating commercial workloads,\u201d In Proceedings of the 18th Usenix LISA Conference., 2004."},{"key":"8_CR19_8","unstructured":"sVirt, http:\/\/selinuxproject.org\/page\/SVirt"},{"key":"8_CR20_8","unstructured":"Virtualbox, http:\/\/www.virtualbox.org\/"},{"key":"8_CR21_8","unstructured":"D. Teigland and H. Mauelshagen. \u201cVolume managers in linux,\u201d In Proceedings of USENIX 2001 Technical Conference, June 2001."},{"key":"8_CR22_8","doi-asserted-by":"crossref","unstructured":"Neiger, Gil; A. Santoni, F. Leung, D. Rodgers, R. Uhlig. \u201cIntel Virtualization Technology: Hardware Support for Efficient Processor Virtualization\u201d. Intel Technology Journal (Intel) 10 (3): 167\u2013178. Available at http:\/\/download.intel.com\/technology\/itj\/2006\/v10i3\/v10-i3 - art01.pdf","DOI":"10.1535\/itj.1003.01"},{"key":"8_CR23_8","unstructured":"AMD Virtualization (AMD-V) Technology, http:\/\/sites.amd.com\/us\/business\/itsolutions\/ virtualization\/Pages\/amd-v.asp"},{"key":"8_CR24_8","unstructured":"Pratyusa K. Manadhata, Jeannette M. Wing, \u201cAn Attack Surface Metric,\u201d IEEE Transactions on Software Engineering, 01 Jun. 2010."},{"key":"8_CR25_8","doi-asserted-by":"crossref","unstructured":"Pratyusa K. Manadhata, Jeannette M. Wing and Mark Flynn, \u201cMeasuring the attack surfaces of two FTP daemons,\u201d Conference on Computer and Communications Security: Proceedings of the 2nd ACM workshop on Quality of protection; 30\u201330 Oct. 2006.","DOI":"10.1145\/1179494.1179497"},{"key":"8_CR26_8","unstructured":"T. Newsham and J. Hoaglan. \u201cWindows Vista Network Attack Surface Analysis: A Broad Overview,\u201d CanSecWest, 2007."},{"key":"8_CR27_8","unstructured":"M. Howard. \u201cFending off future attacks by reducing attack surface,\u201d Available at http:\/\/msdn.microsoft.com\/library\/default.asp?url=\/library\/enus\/ dncode%\/html\/secure02132003.asp, 2003."},{"issue":"5","key":"8_CR28_8","doi-asserted-by":"publisher","first-page":"483","DOI":"10.1147\/rd.255.0483","volume":"25","author":"RJ Creasy","year":"1981","unstructured":"R. J. Creasy. \u201cThe origin of the VM\/370 time-sharing system,\u201d IBM J. Research and Development, 25(5):483\u2013490, September 1981.","journal-title":"IBM J. Research and Development"},{"key":"8_CR29_8","unstructured":"Microsoft Hyper-V Server, http:\/\/www.microsoft.com\/hyper-v-server\/en\/us\/default.aspx"},{"key":"8_CR30_8","unstructured":"Rinard, M., C. Cadar, D. Dumitran, D. Roy, T. Leu, and J.W. Beebee, \u201cEnhancing server availability and security through failure-oblivious computing,\u201d in Proceedings of the 6th Symposium on OSDI, December 2004."},{"key":"8_CR31_8","unstructured":"Sidiroglou, M.E. Locasto, S.W. Boyd and A. Keromytis, \u201cBuilding a Reactive Immune System for Software Services,\u201d in Proceedings of the USENIX Technical Conference, 2000."},{"key":"8_CR32_8","doi-asserted-by":"crossref","unstructured":"Qin, F., J. Tucek, J. Sundaresan, and Y. Zhou, \u201cRx: treating bugs as allergies\u2014a safe method to survive software failures,\u201d in Proceedings of the 20th ACM Symposium on Operating Systems Principles (SOSP), pp. 235\u2013248, 2005.","DOI":"10.1145\/1095810.1095833"},{"key":"8_CR33_8","doi-asserted-by":"crossref","unstructured":"Sidiroglou, S., O. Laadan, A. Keromytis, \u201cUsing Rescue points to Navigate Software Recovery (Short Paper),\u201d in Proceedings of the IEEE Symposium on Security %26 Privacy, pp. 273\u2013278, May 2007, Oakland, CA.","DOI":"10.1109\/SP.2007.38"},{"key":"8_CR34_8","first-page":"2006","volume":"06","author":"C Kil","year":"2006","unstructured":"Kil, C., Jun, J., Bookholt, C., Xu, J., and Ning, P. 2006. \u201cAddress Space Layout Permutation (ASLP): Towards Fine-Grained Randomization of Commodity Software,\u201d In Proceedings of ACSAC\u201906, 2006.","journal-title":"In Proceedings of ACSAC\u2019"},{"key":"8_CR35_8","doi-asserted-by":"crossref","unstructured":"A. Nguyen-Tuong, D. Evans, J. C. Knight, B. Cox, and J.W. Davidson. \u201cSecurity through redundant data diversity.\u201d In 38th IEEE\/IFPF International Conference on Dependable Systems and Networks (DSN\u201908), Anchorage, Alaska, USA, 2008.","DOI":"10.1109\/DSN.2008.4630087"},{"key":"8_CR36_8","unstructured":"A. Bessani, A. Daidone, I. Gashi, R. Obelheiro, P. Sousa and V. Stankovic. \u201cEnhancing Fault- \/Intrusion Tolerance through Design and Configuration Diversity,\u201d 3rd Workshop on Recent Advances on Intrusion-Tolerant Systems (WRAITS 2009)."},{"key":"8_CR37_8","unstructured":"M. Chew and D. Song. \u201cMitigating Buffer Overflows by Operating System Randomization,\u201d Tech Report CMUCS-02-197. December 2002."},{"key":"8_CR38_8","unstructured":"Yih Huang, David Arsenault, and Arun Sood. \u201cIncorruptible System Self-Cleansing for Intrusion Tolerance,\u201d Performance, Computing, and Communications Conference, IPCCC 2006."},{"key":"8_CR39_8","unstructured":"The Terracotta project, http:\/\/www.terrracotta.org"}],"container-title":["Advances in Information Security","Moving Target Defense"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-0977-9_8.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,18]],"date-time":"2020-11-18T06:18:39Z","timestamp":1605680319000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-1-4614-0977-9_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9781461409762","9781461409779"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-0977-9_8","relation":{},"ISSN":["1568-2633"],"issn-type":[{"value":"1568-2633","type":"print"}],"subject":[],"published":{"date-parts":[[2011]]}}}