{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:50:33Z","timestamp":1771699833409,"version":"3.50.1"},"publisher-location":"New York, NY","reference-count":72,"publisher":"Springer New York","isbn-type":[{"value":"9781461454151","type":"print"},{"value":"9781461454168","type":"electronic"}],"license":[{"start":{"date-parts":[[2012,8,23]],"date-time":"2012-08-23T00:00:00Z","timestamp":1345680000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2012,8,23]],"date-time":"2012-08-23T00:00:00Z","timestamp":1345680000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-1-4614-5416-8_9","type":"book-chapter","created":{"date-parts":[[2012,9,17]],"date-time":"2012-09-17T22:16:40Z","timestamp":1347920200000},"page":"175-202","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Practical Software Diversification Using In-Place Code Randomization"],"prefix":"10.1007","author":[{"given":"Vasilis","family":"Pappas","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2012,8,23]]},"reference":[{"key":"9_CR1","unstructured":"Adobe CoolType SING Table \u201cuniqueName\u201d Stack Buffer Overflow. http:\/\/www.exploit-db.com\/exploits\/16619\/."},{"key":"9_CR2","unstructured":"Immunity Debugger. http:\/\/www.immunityinc.com\/products-immdbg.shtml."},{"key":"9_CR3","unstructured":"Integard Pro 2.2.0.9026 (Win7 ROP-Code Metasploit Module). http:\/\/www.exploit-db.com\/exploits\/15016\/."},{"key":"9_CR4","unstructured":"MPlayer (r33064 Lite) Buffer Overflow + ROP exploit. http:\/\/www.exploit-db.com\/exploits\/17124\/."},{"key":"9_CR5","unstructured":"\/ORDER (put functions in order). http:\/\/msdn.microsoft.com\/en-us\/library\/00kh39zz.aspx."},{"key":"9_CR6","unstructured":"Profile-guided optimizations. http:\/\/msdn.microsoft.com\/en-us\/library\/e7k32f4k.aspx."},{"key":"9_CR7","unstructured":"Syzygy - profile guided, post-link executable reordering. http:\/\/code.google.com\/p\/sawbuck\/wiki\/SyzygyDesign."},{"key":"9_CR8","unstructured":"White Phosphorus Exploit Pack. http:\/\/www.whitephosphorus.org\/."},{"key":"9_CR9","unstructured":"Wine. http:\/\/www.winehq.org."},{"key":"9_CR10","unstructured":"Intel 64 and IA-32 Architectures Software Developer\u2019s Manual. Volume 2 (2A & 2B): Instruction Set Reference, A-Z. 2011. http:\/\/www.intel.com\/Assets\/PDF\/manual\/325383.pdf."},{"key":"9_CR11","doi-asserted-by":"crossref","unstructured":"M.\u00a0Abadi, M.\u00a0Budiu, U.\u00a0Erlingsson, and J.\u00a0Ligatti. Control-flow integrity. In Proceedings of the 12th ACM conference on Computer and Communications Security (CCS), 2005.","DOI":"10.1145\/1102120.1102165"},{"key":"9_CR12","unstructured":"A.\u00a0V. Aho, M.\u00a0S. Lam, R.\u00a0Sethi, and J.\u00a0D. Ullman. Compilers: Principles, Techniques, and Tools (2nd Edition). Addison-Wesley Longman Publishing Co., Inc., Boston, MA, USA, 2006."},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"E.\u00a0G. Barrantes, D.\u00a0H. Ackley, T.\u00a0S. Palmer, D.\u00a0Stefanovic, and D.\u00a0D. Zovi. Randomized instruction set emulation to disrupt binary code injection attacks. In Proceedings of the 10th ACM conference on Computer and Communications Security (CCS), 2003.","DOI":"10.1145\/948109.948147"},{"key":"9_CR14","unstructured":"K.\u00a0Baumgartner. The ROP pack. In Proceedings of the 20th Virus Bulletin International Conference (VB), 2010."},{"key":"9_CR15","unstructured":"E.\u00a0Bhatkar, D.\u00a0C. Duvarney, and R.\u00a0Sekar. Address obfuscation: an efficient approach to combat a broad range of memory error exploits. In In Proceedings of the 12th USENIX Security Symposium, 2003."},{"key":"9_CR16","unstructured":"S.\u00a0Bhatkar, R.\u00a0Sekar, and D.\u00a0C. DuVarney. Efficient techniques for comprehensive protection from memory error exploits. In Proceedings of the 14th USENIX Security Symposium, August 2005."},{"key":"9_CR17","doi-asserted-by":"crossref","unstructured":"T.\u00a0Bletsch, X.\u00a0Jiang, V.\u00a0Freeh, and Z.\u00a0Liang. Jump-oriented programming: A new class of code-reuse attack. In Proceedings of the 6th Symposium on Information, Computer and Communications Security (ASIACCS), 2011.","DOI":"10.1145\/1966913.1966919"},{"key":"9_CR18","unstructured":"F.\u00a0Bouchez. A Study of Spilling and Coalescing in Register Allocation as Two Separate Phases. PhD thesis, \u00c9cole normale sup\u00e9rieure de Lyon, April 2009."},{"key":"9_CR19","doi-asserted-by":"crossref","unstructured":"E.\u00a0Buchanan, R.\u00a0Roemer, H.\u00a0Shacham, and S.\u00a0Savage. When good instructions go bad: generalizing return-oriented programming to RISC. In Proceedings of the 15th ACM conference on Computer and Communications Security (CCS), 2008.","DOI":"10.1145\/1455770.1455776"},{"key":"9_CR20","doi-asserted-by":"crossref","unstructured":"S.\u00a0Checkoway, L.\u00a0Davi, A.\u00a0Dmitrienko, A.-R. Sadeghi, H.\u00a0Shacham, and M.\u00a0Winandy. Return-oriented programming without returns. In Proceedings of the 17th ACM conference on Computer and Communications Security (CCS), 2010.","DOI":"10.1145\/1866307.1866370"},{"key":"9_CR21","doi-asserted-by":"crossref","unstructured":"S.\u00a0Checkoway, A.\u00a0J. Feldman, B.\u00a0Kantor, J.\u00a0A. Halderman, E.\u00a0W. Felten, and H.\u00a0Shacham. Can DREs provide long-lasting security? the case of return-oriented programming and the AVC advantage. In Proceedings of the 2009 conference on Electronic Voting Technology\/Workshop on Trustworthy Elections (EVT\/WOTE), 2009.","DOI":"10.1145\/1866307.1866370"},{"key":"9_CR22","doi-asserted-by":"crossref","unstructured":"P.\u00a0Chen, H.\u00a0Xiao, X.\u00a0Shen, X.\u00a0Yin, B.\u00a0Mao, and L.\u00a0Xie. DROP: Detecting return-oriented programming malicious code. In Proceedings of the 5th International Conference on Information Systems Security (ICISS), 2009.","DOI":"10.1007\/978-3-642-10772-6_13"},{"key":"9_CR23","doi-asserted-by":"crossref","unstructured":"F.\u00a0B. Cohen. Operating system protection through program evolution. Computers and Security, 12:565\u2013584, Oct. 1993.","DOI":"10.1016\/0167-4048(93)90054-9"},{"key":"9_CR24","unstructured":"Corelan Team. Corelan ROPdb. https:\/\/www.corelan.be\/index.php\/security\/corelan-ropdb\/."},{"key":"9_CR25","unstructured":"Corelan Team. Mona. http:\/\/redmine.corelan.be\/projects\/mona."},{"key":"9_CR26","doi-asserted-by":"crossref","unstructured":"L.\u00a0Davi, A.-R. Sadeghi, and M.\u00a0Winandy. Dynamic integrity measurement and attestation: towards defense against return-oriented programming attacks. In Proceedings of the 2009 ACM workshop on Scalable Trusted Computing (STC), 2009.","DOI":"10.1145\/1655108.1655117"},{"key":"9_CR27","doi-asserted-by":"crossref","unstructured":"L.\u00a0Davi, A.-R. Sadeghi, and M.\u00a0Winandy. ROPdefender: A practical protection tool to protect against return-oriented programming. In Proceedings of the 6th Symposium on Information, Computer and Communications Security (ASIACCS), 2011.","DOI":"10.1145\/1966913.1966920"},{"key":"9_CR28","unstructured":"S.\u00a0Designer. Getting around non-executable stack (and fix). http:\/\/seclists.org\/bugtraq\/1997\/Aug\/63."},{"key":"9_CR29","unstructured":"T.\u00a0Dullien, T.\u00a0Kornau, and R.-P. Weinmann. A framework for automated architecture-independent gadget search. In Proceedings of the 4th USENIX Workshop on Offensive Technologies (WOOT), 2010."},{"key":"9_CR30","doi-asserted-by":"crossref","unstructured":"R.\u00a0El-Khalil and A.\u00a0D. Keromytis. Hydan: Hiding information in program binaries. In Proceedings of the International Conference on Information and Communications Security, (ICICS), 2004.","DOI":"10.1007\/978-3-540-30191-2_15"},{"key":"9_CR31","unstructured":"\u00da.\u00a0Erlingsson. Low-level software security: Attack and defenses. Technical Report MSR-TR-07-153, Microsoft Research, 2007. http:\/\/research.microsoft.com\/pubs\/64363\/tr-2007-153.pdf."},{"key":"9_CR32","unstructured":"A.\u00a0Fog. Calling conventions for different C++ compilers and operating systems. http:\/\/agner.org\/optimize\/calling_conventions.pdf."},{"key":"9_CR33","unstructured":"S.\u00a0Forrest, A.\u00a0Somayaji, and D.\u00a0Ackley. Building diverse computer systems. In Proceedings of the 6th Workshop on Hot Topics in Operating Systems (HotOS-VI), 1997."},{"key":"9_CR34","doi-asserted-by":"crossref","unstructured":"G.\u00a0Fresi Roglia, L.\u00a0Martignoni, R.\u00a0Paleari, and D.\u00a0Bruschi. Surgically returning to randomized lib(c). In Proceedings of the 25th Annual Computer Security Applications Conference (ACSAC), 2009.","DOI":"10.1109\/ACSAC.2009.16"},{"key":"9_CR35","unstructured":"I.\u00a0Guilfanov. Jump tables. http:\/\/www.hexblog.com\/?p=68."},{"key":"9_CR36","unstructured":"I.\u00a0Guilfanov. Decompilers and beyond. Black Hat USA, 2008."},{"key":"9_CR37","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1145\/1127577.1127590","volume":"33","author":"L. C. Harris","year":"2005","unstructured":"L.\u00a0C. Harris and B.\u00a0P. Miller. Practical analysis of stripped binary code. SIGARCH Comput. Archit. News, 33:63\u201368, December 2005.","journal-title":"SIGARCH Comput. Archit. News"},{"key":"9_CR38","unstructured":"Hex-Rays. IDA Pro Disassembler. http:\/\/www.hex-rays.com\/idapro\/."},{"key":"9_CR39","doi-asserted-by":"crossref","unstructured":"X.\u00a0Hu, T.-c. Chiueh, and K.\u00a0G. Shin. Large-scale malware indexing using function-call graphs. In Proceedings of the 16th ACM conference on Computer and Communications Security (CCS), 2009.","DOI":"10.1145\/1653662.1653736"},{"key":"9_CR40","unstructured":"R.\u00a0Hund, T.\u00a0Holz, and F.\u00a0C. Freiling. Return-oriented rootkits: bypassing kernel code integrity protection mechanisms. In Proceedings of the 18th USENIX Security Symposium, 2009."},{"key":"9_CR41","unstructured":"R.\u00a0Johnson. A castle made of sand: Adobe Reader X sandbox. CanSecWest, 2011."},{"key":"9_CR42","unstructured":"G.\u00a0S. Kc, A.\u00a0D. Keromytis, and V.\u00a0Prevelakis. Countering code-injection attacks with instruction-set randomization. In Proceedings of the 10th ACM conference on Computer and Communications Security (CCS), 2003."},{"key":"9_CR43","doi-asserted-by":"crossref","unstructured":"C.\u00a0Kil, J.\u00a0Jun, C.\u00a0Bookholt, J.\u00a0Xu, and P.\u00a0Ning. Address space layout permutation (ASLP): Towards fine-grained randomization of commodity software. In Proceedings of the 22nd Annual Computer Security Applications Conference (ACSAC), 2006.","DOI":"10.1109\/ACSAC.2006.9"},{"key":"9_CR44","unstructured":"S.\u00a0Krahmer. x86-64 buffer overflow exploits and the borrowed code chunks exploitation technique. http:\/\/www.suse.de\/~krahmer\/no-nx.pdf."},{"key":"9_CR45","unstructured":"C.\u00a0Kruegel, W.\u00a0Robertson, F.\u00a0Valeur, and G.\u00a0Vigna. Static disassembly of obfuscated binaries. In Proceedings of the 13th USENIX Security Symposium, 2004."},{"key":"9_CR46","unstructured":"H.\u00a0Li. Understanding and exploiting Flash ActionScript vulnerabilities. CanSecWest, 2011."},{"key":"9_CR47","unstructured":"J.\u00a0Li, Z.\u00a0Wang, X.\u00a0Jiang, M.\u00a0Grace, and S.\u00a0Bahram. Defeating return-oriented rootkits with \u201creturn-less\u201d kernels. In Proceedings of the 5th European conference on Computer Systems (EuroSys), 2010."},{"key":"9_CR48","unstructured":"Microsoft. Enhanced Mitigation Experience Toolkit v2.1. http:\/\/www.microsoft.com\/download\/en\/details.aspx?id=1677."},{"key":"9_CR49","unstructured":"M.\u00a0Miller, T.\u00a0Burrell, and M.\u00a0Howard. Mitigating software vulnerabilities, July 2011. http:\/\/www.microsoft.com\/download\/en\/details.aspx?displaylang=en&id=26788."},{"key":"9_CR50","unstructured":"S.\u00a0S. Muchnick. Advanced compiler design and implementation. Morgan Kaufmann Publishers Inc., San Francisco, CA, USA, 1997."},{"key":"9_CR51","unstructured":"S.\u00a0Nanda, W.\u00a0Li, L.-C. Lam, and T.-c. Chiueh. Bird: Binary interpretation using runtime disassembly. In Proceedings of the International Symposium on Code Generation and Optimization (CGO), 2006."},{"key":"9_CR52","unstructured":"Nergal. The advanced return-into-lib(c) exploits: PaX case study. Phrack, 11(58), Dec. 2001."},{"key":"9_CR53","unstructured":"T.\u00a0Newsham. Non-exec stack, 2000. http:\/\/seclists.org\/bugtraq\/2000\/May\/90."},{"key":"9_CR54","doi-asserted-by":"crossref","unstructured":"K.\u00a0Onarlioglu, L.\u00a0Bilge, A.\u00a0Lanzi, D.\u00a0Balzarotti, and E.\u00a0Kirda. G-Free: defeating return-oriented programming through gadget-less binaries. In Proceedings of the 26th Annual Computer Security Applications Conference (ACSAC), 2010.","DOI":"10.1145\/1920261.1920269"},{"key":"9_CR55","doi-asserted-by":"crossref","unstructured":"V.\u00a0Pappas, M.\u00a0Polychronakis, and A.\u00a0D. Keromytis. Smashing the gadgets: Hindering return-oriented programming using in-place code randomization. In Proceedings of the 33rd IEEE Symposium on Security & Privacy (S&P), May 2012.","DOI":"10.1109\/SP.2012.41"},{"key":"9_CR56","unstructured":"M.\u00a0Parkour. An overview of exploit packs (update 9) April 5 2011. http:\/\/contagiodump.blogspot.com\/2010\/06\/overview-of-exploit-packs-update.html."},{"key":"9_CR57","unstructured":"M.\u00a0Pietrek. An in-depth look into the Win32 portable executable file format, part 2. http:\/\/msdn.microsoft.com\/en-us\/magazine\/cc301808.aspx."},{"key":"9_CR58","doi-asserted-by":"crossref","unstructured":"P.\u00a0Saxena, R.\u00a0Sekar, and V.\u00a0Puranik. Efficient fine-grained binary instrumentation with applications to taint-tracking. In Proceedings of the 6th annual IEEE\/ACM international symposium on Code Generation and Optimization (CGO), 2008.","DOI":"10.1145\/1356058.1356069"},{"key":"9_CR59","unstructured":"E.\u00a0J. Schwartz, T.\u00a0Avgerinos, and D.\u00a0Brumley. Q: Exploit hardening made easy. In Proceedings of the 20th USENIX Security Symposium, 2011."},{"key":"9_CR60","unstructured":"F.\u00a0J. Serna. CVE-2012-0769: the case of the perfect info leak, Apr. 2012. http:\/\/zhodiac.hispahack.com\/my-stuff\/security\/Flash_ASLR_bypass.pdf."},{"key":"9_CR61","doi-asserted-by":"crossref","unstructured":"H.\u00a0Shacham. The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In Proceedings of the 14th ACM conference on Computer and Communications Security (CCS), 2007.","DOI":"10.1145\/1315245.1315313"},{"key":"9_CR62","doi-asserted-by":"crossref","unstructured":"H.\u00a0Shacham, M.\u00a0Page, B.\u00a0Pfaff, E.-J. Goh, N.\u00a0Modadugu, and D.\u00a0Boneh. On the effectiveness of address-space randomization. In Proceedings of the 11th ACM conference on Computer and Communications Security (CCS), 2004.","DOI":"10.1145\/1030083.1030124"},{"key":"9_CR63","unstructured":"Skape. Locreate: An anagram for relocate. Uninformed, 6, 2007."},{"key":"9_CR64","unstructured":"Skape and Skywing. Bypassing Windows hardware-enforced DEP. Uninformed, 2, Sept. 2005."},{"key":"9_CR65","unstructured":"M.\u00a0Smithson, K.\u00a0Anand, A.\u00a0Kotha, K.\u00a0Elwazeer, N.\u00a0Giles, and R.\u00a0Barua. Binary rewriting without relocation information. Technical report, University of Maryland, 2010. http:\/\/www.ece.umd.edu\/~barua\/without-relocation-technical-report10.pdf."},{"key":"9_CR66","unstructured":"P.\u00a0Sol\u00e9. Defeating DEP, the Immunitiy Debugger way. http:\/\/www.immunitysec.com\/downloads\/DEPLIB.pdf."},{"key":"9_CR67","unstructured":"P.\u00a0Sol\u00e9. Hanging on a ROPe. http:\/\/www.immunitysec.com\/downloads\/DEPLIB20_ekoparty.pdf."},{"key":"9_CR68","unstructured":"P.\u00a0Sz\u00f6r. The Art of Computer Virus Research and Defense. Addison-Wesley Professional, February 2005."},{"issue":"1","key":"9_CR69","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1093\/comjnl\/24.1.83","volume":"24","author":"Y. L. Varol","year":"1981","unstructured":"Y.\u00a0L. Varol and D.\u00a0Rotem. An algorithm to generate all topological sorting arrangements. Comput. J., 24(1):83\u201384, 1981.","journal-title":"Comput. J."},{"key":"9_CR70","unstructured":"P.\u00a0Vreugdenhil. Pwn2Own 2010 Windows 7 Internet Explorer 8 exploit. http:\/\/vreugdenhilresearch.nl\/Pwn2Ownl2010-Windows7-InternetExplorer8.pdf."},{"key":"9_CR71","unstructured":"D.\u00a0A.\u00a0D. Zovi. Mac OS X return-oriented exploitation. RECON, 2010."},{"key":"9_CR72","unstructured":"D.\u00a0A.\u00a0D. Zovi. Practical return-oriented programming. SOURCE Boston, 2010."}],"container-title":["Advances in Information Security","Moving Target Defense II"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-5416-8_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,9]],"date-time":"2023-02-09T09:10:44Z","timestamp":1675933844000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-1-4614-5416-8_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,8,23]]},"ISBN":["9781461454151","9781461454168"],"references-count":72,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-5416-8_9","relation":{},"ISSN":["1568-2633"],"issn-type":[{"value":"1568-2633","type":"print"}],"subject":[],"published":{"date-parts":[[2012,8,23]]},"assertion":[{"value":"23 August 2012","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}