{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T13:39:44Z","timestamp":1726061984873},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030346362"},{"type":"electronic","value":"9783030346379"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-34637-9_9","type":"book-chapter","created":{"date-parts":[[2019,12,6]],"date-time":"2019-12-06T00:04:15Z","timestamp":1575590655000},"page":"121-135","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["HoneyGadget: A Deception Based ROP Detection Scheme"],"prefix":"10.1007","author":[{"given":"Xin","family":"Huang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fei","family":"Yan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liqiang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kai","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,12,6]]},"reference":[{"key":"9_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., Budiu, M., Erlingsson, U., Ligatti, J.: Control-flow integrity. In: Proceedings of the 12th ACM Conference on Computer and Communications Security, pp. 340\u2013353. ACM (2005)","DOI":"10.1145\/1102120.1102165"},{"key":"9_CR2","unstructured":"Andersen, S., Abella, V.: Data execution prevention. Changes to functionality in Microsoft Windows XP Service Pack 2, Part 3: memory protection technologies (2004)"},{"key":"9_CR3","doi-asserted-by":"crossref","unstructured":"Araujo, F., Hamlen, K.W., Biedermann, S., Katzenbeisser, S.: From patches to honey-patches: lightweight attacker misdirection, deception, and disinformation. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, pp. 942\u2013953. ACM (2014)","DOI":"10.1145\/2660267.2660329"},{"key":"9_CR4","doi-asserted-by":"crossref","unstructured":"Bittau, A., Belay, A., Mashtizadeh, A., Mazi\u00e8res, D., Boneh, D.: Hacking blind. In: 2014 IEEE Symposium on Security and Privacy (SP), pp. 227\u2013242. IEEE (2014)","DOI":"10.1109\/SP.2014.22"},{"key":"9_CR5","doi-asserted-by":"crossref","unstructured":"Buchanan, E., Roemer, R., Shacham, H., Savage, S.: When good instructions go bad: generalizing return-oriented programming to RISC. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 27\u201338. ACM (2008)","DOI":"10.1145\/1455770.1455776"},{"key":"9_CR6","unstructured":"Carlini, N., Barresi, A., Payer, M., Wagner, D., Gross, T.R.: Control-flow bending: on the effectiveness of control-flow integrity. In: USENIX Security Symposium, pp. 161\u2013176 (2015)"},{"key":"9_CR7","unstructured":"Carlini, N., Wagner, D.: ROP is still dangerous: breaking modern defenses. In: USENIX Security Symposium, pp. 385\u2013399 (2014)"},{"key":"9_CR8","doi-asserted-by":"crossref","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A.R., Shacham, H., Winandy, M.: Return-oriented programming without returns. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, pp. 559\u2013572. ACM (2010)","DOI":"10.1145\/1866307.1866370"},{"key":"9_CR9","doi-asserted-by":"crossref","unstructured":"Chen, Y., Wang, Z., Whalley, D., Lu, L.: Remix: on-demand live randomization. In: Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy, pp. 50\u201361. ACM (2016)","DOI":"10.1145\/2857705.2857726"},{"key":"9_CR10","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Zhou, Z., Miao, Y., Ding, X., Deng, H., et al.: ROPecker: a generic and practical approach for defending against ROP attack (2014)","DOI":"10.14722\/ndss.2014.23156"},{"key":"9_CR11","doi-asserted-by":"crossref","unstructured":"Crane, S., Larsen, P., Brunthaler, S., Franz, M.: Booby trapping software. In: Proceedings of the 2013 New Security Paradigms Workshop, pp. 95\u2013106. ACM (2013)","DOI":"10.1145\/2535813.2535824"},{"key":"9_CR12","doi-asserted-by":"crossref","unstructured":"Crane, S.J., et al.: It\u2019s a trap: table randomization and protection against function-reuse attacks. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. pp. 243\u2013255. ACM (2015)","DOI":"10.1145\/2810103.2813682"},{"key":"9_CR13","unstructured":"Durumeric, Z., Bailey, M., Halderman, J.A.: An internet-wide view of internet-wide scanning. In: USENIX Security Symposium, pp. 65\u201378 (2014)"},{"key":"9_CR14","doi-asserted-by":"crossref","unstructured":"Evans, I., et al.: Missing the point (ER): On the effectiveness of code pointer integrity. In: 2015 IEEE Symposium on Security and Privacy (SP), pp. 781\u2013796. IEEE (2015)","DOI":"10.1109\/SP.2015.53"},{"key":"9_CR15","doi-asserted-by":"crossref","unstructured":"G\u00f6ktas, E., Athanasopoulos, E., Bos, H., Portokalidis, G.: Out of control: overcoming control-flow integrity. In: 2014 IEEE Symposium on Security and Privacy (SP), pp. 575\u2013589. IEEE (2014)","DOI":"10.1109\/SP.2014.43"},{"key":"9_CR16","unstructured":"Guide, P.: Intel\u00ae 64 and ia-32 architectures software developer\u2019s manual. Volume 3B: System programming Guide, Part 2 (2011)"},{"key":"9_CR17","doi-asserted-by":"crossref","unstructured":"Hiser, J., Nguyen-Tuong, A. Co, M., Hall, M., Davidson, J.W.: ILR: where\u2019d my gadgets go? In: 2012 IEEE Symposium on Security and Privacy (SP), pp. 571\u2013585. IEEE (2012)","DOI":"10.1109\/SP.2012.39"},{"key":"9_CR18","unstructured":"Kemerlis, V.P., Portokalidis, G., Keromytis, A.D.: kGuard: lightweight kernel protection against return-to-user attacks. In: Presented as part of the 21st USENIX Security Symposium (USENIX Security 2012), pp. 459\u2013474 (2012)"},{"key":"9_CR19","doi-asserted-by":"crossref","unstructured":"Kil, C., Jun, J., Bookholt, C., Xu, J., Ning, P.: Address space layout permutation (ASLP): towards fine-grained randomization of commodity software. In: 22nd Annual Computer Security Applications Conference, ACSAC 2006, pp. 339\u2013348. IEEE (2006)","DOI":"10.1109\/ACSAC.2006.9"},{"key":"9_CR20","unstructured":"Larabel, M., Tippett, M.: Phoronix test suite. Phoronix Media (2011). \nhttp:\/\/www.phoronix-test-suite.com\/\n\n. Accessed June 2018"},{"key":"9_CR21","unstructured":"Le, L.: Payload already inside: datafire-use for ROP exploits. Black Hat USA (2010)"},{"key":"9_CR22","doi-asserted-by":"crossref","unstructured":"Liu, Y., Shi, P., Wang, X., Chen, H., Zang, B., Guan, H.: Transparent and efficient CFI enforcement with Intel processor trace. In: 2017 IEEE International Symposium on High Performance Computer Architecture (HPCA), pp. 529\u2013540. IEEE (2017)","DOI":"10.1109\/HPCA.2017.18"},{"key":"9_CR23","doi-asserted-by":"crossref","unstructured":"Ming, J., Xu, D., Wang, L., Wu, D.: Loop: logic-oriented opaque predicate detection in obfuscated binary code. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 757\u2013768. ACM (2015)","DOI":"10.1145\/2810103.2813617"},{"key":"9_CR24","unstructured":"Pappas, V.: Defending against return-oriented programming. Columbia University (2015)"},{"key":"9_CR25","unstructured":"Pappas, V.: kBouncer: efficient and transparent ROP mitigation, pp. 1\u20132, 1 April 2012 (2012)"},{"key":"9_CR26","unstructured":"Pappas, V., Polychronakis, M., Keromytis, A.D.: Transparent ROP exploit mitigation using indirect branch tracing. In: USENIX Security Symposium, pp. 447\u2013462 (2013)"},{"key":"9_CR27","unstructured":"Riden, J., McGeehan, R., Engert, B., Mueter, M.: Know your enemy: web application threats, using honeypots to learn about http-based attacks (2007)"},{"key":"9_CR28","unstructured":"Salwan, J.: ROPgadget-Gadgets finder and auto-roper (2011)"},{"key":"9_CR29","unstructured":"Schwartz, E.J., Avgerinos, T., Brumley, D.: Q: Exploit hardening made easy. In: USENIX Security Symposium, pp. 25\u201341 (2011)"},{"key":"9_CR30","doi-asserted-by":"crossref","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the X86). In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 552\u2013561. ACM (2007)","DOI":"10.1145\/1315245.1315313"},{"key":"9_CR31","doi-asserted-by":"crossref","unstructured":"Snow, K.Z., Monrose, F., Davi, L., Dmitrienko, A., Liebchen, C., Sadeghi, A.R.: Just-in-time code reuse: on the effectiveness of fine-grained address space layout randomization. In: 2013 IEEE Symposium on Security and Privacy (SP), pp. 574\u2013588. IEEE (2013)","DOI":"10.1109\/SP.2013.45"},{"key":"9_CR32","unstructured":"Team, K.: KLEE LLVM execution engine. \nhttp:\/\/klee.github.io\/"},{"key":"9_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/978-3-642-23644-0_7","volume-title":"Recent Advances in Intrusion Detection","author":"M Tran","year":"2011","unstructured":"Tran, M., Etheridge, M., Bletsch, T., Jiang, X., Freeh, V., Ning, P.: On the expressiveness of return-into-libc attacks. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol. 6961, pp. 121\u2013141. Springer, Heidelberg (2011). \nhttps:\/\/doi.org\/10.1007\/978-3-642-23644-0_7"},{"key":"9_CR34","unstructured":"Zhang, C., et al.: Practical control flow integrity and randomization for binary executables. In: 2013 IEEE Symposium on Security and Privacy (SP), pp. 559\u2013573. IEEE (2013)"},{"key":"9_CR35","unstructured":"Zhang, M., Sekar, R.: Control flow integrity for COTS binaries. In: USENIX Security Symposium, pp. 337\u2013352 (2013)"}],"container-title":["Lecture Notes in Computer Science","Science of Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-34637-9_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,12,6]],"date-time":"2019-12-06T00:05:08Z","timestamp":1575590708000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-34637-9_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030346362","9783030346379"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-34637-9_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"6 December 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SciSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Science of Cyber Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nanjing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 August 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"scisec2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.sci-cs.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"62","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"32% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}