{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T12:54:02Z","timestamp":1742993642143,"version":"3.40.3"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030224783"},{"type":"electronic","value":"9783030224790"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-22479-0_17","type":"book-chapter","created":{"date-parts":[[2019,7,3]],"date-time":"2019-07-03T23:02:56Z","timestamp":1562194976000},"page":"317-337","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Wrangling in the Power of Code Pointers with ProxyCFI"],"prefix":"10.1007","author":[{"given":"Misiker Tadesse","family":"Aga","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Colton","family":"Holoday","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Todd","family":"Austin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,6,11]]},"reference":[{"key":"17_CR1","unstructured":"Data execution prevention (2003). Accessed 29 Feb 2018"},{"key":"17_CR2","unstructured":"Linux kernel 2.6.8 (2004). Accessed 29 Feb 2018"},{"key":"17_CR3","unstructured":"Windows ISV software security defenses (2010). Accessed 29 Feb 2018"},{"key":"17_CR4","unstructured":"Control flow guard (windows) - MSDN - Microsoft (2015). https:\/\/msdn.microsoft.com\/en-us\/library\/dn919635.aspx. Accessed 13 Apr 2018"},{"key":"17_CR5","unstructured":"Cve-2017-14493 (2017). https:\/\/www.cvedetails.com\/cve\/CVE-2017-14493\/. Accessed 12 Feb 2018"},{"key":"17_CR6","unstructured":"Intel control-flow enforcement technology (CET) (2017). https:\/\/software.intel.com\/sites\/default\/files\/managed\/4d\/2a\/control-flow-enforcement-technology-preview.pdf. Accessed 13 Apr 2018"},{"key":"17_CR7","unstructured":"Bladeenc: Vulnerability statistics (2018). https:\/\/www.cvedetails.com\/product\/2851\/Bladeenc-Bladeenc.html. Accessed 05 Jan 2018"},{"key":"17_CR8","unstructured":"Cve-2014-2013 (2018). https:\/\/www.cvedetails.com\/cve\/CVE-2014-2013\/. Accessed 13 Apr 2018"},{"key":"17_CR9","unstructured":"Cve-2017-1000437 (2018). https:\/\/www.cvedetails.com\/cve\/CVE-2017-1000437\/. Accessed 05 Jan 2018"},{"key":"17_CR10","doi-asserted-by":"crossref","unstructured":"Abadi, M., Budiu, M., Erlingsson, U., Ligatti, J.: Control-flow integrity. In: Proceedings of the 12th ACM Conference on Computer and Communications Security, pp. 340\u2013353. ACM (2005)","DOI":"10.1145\/1102120.1102165"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"Arthur, W., Mehne, B., Das, R, Austin, T.: Getting in control of your control flow with control-data isolation. In: Proceedings of the 13th Annual IEEE\/ACM International Symposium on Code Generation and Optimization, pp. 79\u201390. IEEE Computer Society (2015)","DOI":"10.1109\/CGO.2015.7054189"},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Bletsch, T., Jiang, X., Freeh, V.W., Liang, Z.: Jump-oriented programming: a new class of code-reuse attack. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, pp. 30\u201340. ACM (2011)","DOI":"10.1145\/1966913.1966919"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"Buchanan, E., Roemer, R., Shacham, H., Savage, S.: When good instructions go bad: generalizing return-oriented programming to RISC. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 27\u201338. ACM (2008)","DOI":"10.1145\/1455770.1455776"},{"key":"17_CR14","unstructured":"Carlini, N., Barresi, A., Payer, M., Wagner, D., Gross, T.R.: Control-flow bending: on the effectiveness of control-flow integrity. In: 24th USENIX Security Symposium (USENIX Security 15), pp. 161\u2013176. USENIX Association, Washington, DC (2015)"},{"issue":"2","key":"17_CR15","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1016\/0096-0551(93)90005-L","volume":"19","author":"KD Cooper","year":"1993","unstructured":"Cooper, K.D., Hall, M.W., Kennedy, K.: A methodology for procedure cloning. Comput. Lang. 19(2), 105\u2013117 (1993)","journal-title":"Comput. Lang."},{"key":"17_CR16","unstructured":"Cowan, C., et al.: Stackguard: automatic adaptive detection and prevention of buffer-overflow attacks. In: USENIX Security Symposium, San Antonio, TX, vol. 98, pp. 63\u201378 (1998)"},{"key":"17_CR17","unstructured":"Cowan, C., Beattie, S., Johansen, J., Wagle, P.: PointGuard TM: protecting pointers from buffer overflow vulnerabilities. In: Proceedings of the 12th Conference on USENIX Security Symposium, vol. 12, pp. 91\u2013104 (2003)"},{"key":"17_CR18","unstructured":"Dai Zovi, D.: Practical return-oriented programming. In: SOURCE Boston (2010)"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Duck, G.J., Yap, R.H.C, Cavallaro, L.: Stack bounds protection with low fat pointers (2017)","DOI":"10.14722\/ndss.2017.23287"},{"key":"17_CR20","doi-asserted-by":"crossref","unstructured":"Evans, I., et al.: Control jujutsu: on the weaknesses of fine-grained control flow integrity. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 901\u2013913. ACM (2015)","DOI":"10.1145\/2810103.2813646"},{"key":"17_CR21","doi-asserted-by":"crossref","unstructured":"Gktas, E., Athanasopoulos, E., Bos, H., Portokalidis, G.: Out of control: overcoming control-flow integrity. In: 2014 IEEE Symposium on Security and Privacy, May, pp. 575\u2013589 (2014)","DOI":"10.1109\/SP.2014.43"},{"key":"17_CR22","unstructured":"G\u00f6kta\u015f, E., Athanasopoulos, E., Polychronakis, M., Bos, H., Portokalidis, G.: Size does matter: why using gadget-chain length to prevent code-reuse attacks is hard. In: Proceedings of the 23rd USENIX Conference on Security Symposium, pp. 417\u2013432. USENIX Association (2014)"},{"key":"17_CR23","unstructured":"Intel: Dynamic libraries (2015). Accessed 29 Feb 2018"},{"key":"17_CR24","unstructured":"Kuznetsov, V., Szekeres, L., Payer, M., Candea, G., Sekar, R., Song, D.: Code-pointer integrity. In: 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2014), pp. 147\u2013163. USENIX Association, Broomfield (2014)"},{"key":"17_CR25","doi-asserted-by":"crossref","unstructured":"Lan, B., Li, Y., Sun, H., Su, C., Liu, Y., Zeng, O.: Loop-oriented programming: a new code reuse attack to bypass modern defenses. In: 2015 IEEE Trustcom\/BigDataSE\/ISPA, vol. 1, pp. 190\u2013197. IEEE (2015)","DOI":"10.1109\/Trustcom.2015.374"},{"key":"17_CR26","unstructured":"Li, J., Wang, Z., Jiang, X., Grace, M., Bahram, S.: Defeating return-oriented rootkits with return-less kernels. In: Proceedings of the 5th European Conference on Computer Systems, pp. 195\u2013208. ACM (2010)"},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Liu, L., Han, J., Gao, D., Jing, J., Zha, D.: Launching return-oriented programming attacks against randomized relocatable executables. In: 2011 IEEE 10th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 37\u201344. IEEE (2011)","DOI":"10.1109\/TrustCom.2011.9"},{"key":"17_CR28","doi-asserted-by":"crossref","unstructured":"Mashtizadeh, A.J., Bittau, A., Boneh, D., Mazi\u00e8res, D.: CCFI: cryptographically enforced control flow integrity. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 941\u2013951. ACM (2015)","DOI":"10.1145\/2810103.2813676"},{"key":"17_CR29","unstructured":"C+ MISRA: Guidelines for the use of the C\/C++ language in critical systems. MIRA Limited, Warwickshire (2012)"},{"key":"17_CR30","doi-asserted-by":"crossref","unstructured":"Mohan, V., Larsen, P., Brunthaler, S., Hamlen, K.W., Franz, M.: Opaque control-flow integrity. In: NDSS, vol. 26, pp. 27\u201330 (2015)","DOI":"10.14722\/ndss.2015.23271"},{"issue":"6","key":"17_CR31","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1145\/1543135.1542504","volume":"44","author":"S Nagarakatte","year":"2009","unstructured":"Nagarakatte, S., Zhao, J., Martin, M.N.K., Zdancewic, S.: SoftBound: highly compatible and complete spatial memory safety for C. ACM SIGPLAN Not. 44(6), 245\u2013258 (2009)","journal-title":"ACM SIGPLAN Not."},{"key":"17_CR32","unstructured":"Prasad, M., Chiueh, T.: A binary rewriting defense against stack based buffer overflow attacks. In: USENIX Annual Technical Conference, General Track, pp. 211\u2013224 (2003)"},{"key":"17_CR33","doi-asserted-by":"crossref","unstructured":"Schuster, F., Tendyck, T., Liebchen, C., Davi, L., Sadeghi, A.-R., Holz, T.: Counterfeit object-oriented programming: On the difficulty of preventing code reuse attacks in C++ applications. In: 2015 IEEE Symposium on Security and Privacy (SP), pp. 745\u2013762. IEEE (2015)","DOI":"10.1109\/SP.2015.51"},{"key":"17_CR34","doi-asserted-by":"crossref","unstructured":"Shacham, H., Page, M., Pfaff, B., Goh, E.-J., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM Conference on Computer and Communications Security, pp. 298\u2013307. ACM (2004)","DOI":"10.1145\/1030083.1030124"},{"key":"17_CR35","doi-asserted-by":"crossref","unstructured":"Strackx, R., Younan, Y., Philippaerts, P., Piessens, F., Lachmund, S., Walter, T.: Breaking the memory secrecy assumption. In: Proceedings of the Second European Workshop on System Security, pp. 1\u20138. ACM (2009)","DOI":"10.1145\/1519144.1519145"},{"key":"17_CR36","doi-asserted-by":"crossref","unstructured":"Theodorides, M., Wagner, D.: Breaking active-set backward-edge CFI. In: 2017 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 85\u201389. IEEE (2017)","DOI":"10.1109\/HST.2017.7951803"},{"key":"17_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/978-3-642-23644-0_7","volume-title":"Recent Advances in Intrusion Detection","author":"M Tran","year":"2011","unstructured":"Tran, M., Etheridge, M., Bletsch, T., Jiang, X., Freeh, V., Ning, P.: On the expressiveness of return-into-libc attacks. In: Sommer, R., Balzarotti, D., Maier, Gregor (eds.) RAID 2011. LNCS, vol. 6961, pp. 121\u2013141. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23644-0_7"},{"key":"17_CR38","doi-asserted-by":"crossref","unstructured":"Wagner, D., Soto, P.: Mimicry attacks on host-based intrusion detection systems. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 255\u2013264. ACM (2002)","DOI":"10.1145\/586110.586145"},{"key":"17_CR39","doi-asserted-by":"crossref","unstructured":"Wartell, R., Mohan, V., Hamlen, K.W., Lin, Z.: Binary stirring: self-randomizing instruction addresses of legacy x86 binary code. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 157\u2013168. ACM (2012)","DOI":"10.1145\/2382196.2382216"},{"key":"17_CR40","doi-asserted-by":"crossref","unstructured":"Wilander, J., Nikiforakis, N., Younan, Y., Kamkar, M., Joosen, W.: RIPE: runtime intrusion prevention evaluator. In: Proceedings of the 27th Annual Computer Security Applications Conference, ACSAC. ACM (2011)","DOI":"10.1145\/2076732.2076739"},{"key":"17_CR41","unstructured":"Zhang, C., et al.: Practical control flow integrity and randomization for binary executables. In: 2013 IEEE Symposium on Security and Privacy (SP), pp. 559\u2013573. IEEE (2013)"},{"key":"17_CR42","unstructured":"Zhang, M., Sekar, R.: Control flow integrity for cots binaries. In: USENIX Security Symposium, pp. 337\u2013352 (2013)"}],"container-title":["Lecture Notes in Computer Science","Data and Applications Security and Privacy XXXIII"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-22479-0_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,12]],"date-time":"2024-03-12T16:09:59Z","timestamp":1710259799000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-22479-0_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030224783","9783030224790"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-22479-0_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"11 June 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DBSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP Annual Conference on Data and Applications Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Charleston, SC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 July 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"33","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dbsec2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dbsec2019.cse.sc.edu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"52","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"21","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"40% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}