{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T10:22:36Z","timestamp":1743070956780,"version":"3.40.3"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030389901"},{"type":"electronic","value":"9783030389918"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-38991-8_34","type":"book-chapter","created":{"date-parts":[[2020,1,21]],"date-time":"2020-01-21T20:34:32Z","timestamp":1579638872000},"page":"518-532","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Moving Target Defense Against Injection Attacks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8068-6636","authenticated-orcid":false,"given":"Huan","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1160-5596","authenticated-orcid":false,"given":"Kangfeng","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9096-3617","authenticated-orcid":false,"given":"Xiaodan","family":"Yan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shoushan","family":"Luo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bin","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,1,22]]},"reference":[{"key":"34_CR1","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1016\/j.future.2018.09.042","volume":"92","author":"Y Xu","year":"2019","unstructured":"Xu, Y., Wang, G., Ren, J., Zhang, Y.: An adaptive and configurable protection framework against android privilege escalation threats. Future Gener. Comput. Syst. 92, 210\u2013224 (2019)","journal-title":"Future Gener. Comput. Syst."},{"key":"34_CR2","doi-asserted-by":"crossref","unstructured":"Xu, Y., Ren, J., Wang, G., Zhang, C., Yang, J., Zhang, Y.: A blockchain-basednon-repudiation network computing service scheme for industrial IoT. IEEE Trans. Ind. Inf. (2019)","DOI":"10.1109\/TII.2019.2897133"},{"key":"34_CR3","unstructured":"OWASP Top 10 Application Security Risks. \nhttps:\/\/www.owasp.org\/index.php\/Top_10-2017_Top_10\n\n. Accessed 27 Mar 2018"},{"issue":"2","key":"34_CR4","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1109\/MSP.2006.46","volume":"4","author":"T Holz","year":"2006","unstructured":"Holz, T., Marechal, S., Raynal, F.: New threats and attacks on the world wide web. IEEE Secur. Priv. 4(2), 72\u201375 (2006)","journal-title":"IEEE Secur. Priv."},{"key":"34_CR5","unstructured":"Chong, F., et al.: National cyber leap year summit 2009: Co-chairs report. NITRD Program (2009)"},{"key":"34_CR6","doi-asserted-by":"crossref","unstructured":"Kindy, D.A., Pathan, A.S.K.: A survey on sql injection: vulnerabilities, attacks, and prevention techniques. In: 2011 IEEE 15th International Symposium on Consumer Electronics (ISCE), pp. 468\u2013471. IEEE (2011)","DOI":"10.1109\/ISCE.2011.5973873"},{"key":"34_CR7","unstructured":"Halfond, W.G., et al.: A classification of SQL-injection attacks and countermeasures. In: Proceedings of the IEEE International Symposium on Secure Software Engineering, vol. 1, pp. 13\u201315. IEEE (2006)"},{"key":"34_CR8","unstructured":"Gould, C., Su, Z., Devanbu, P.: JDBC checker: a static analysis tool for SQL\/JDBC applications. In: Proceedings of the 26th International Conference on Software Engineering, pp. 697\u2013698. IEEE (2004)"},{"issue":"3","key":"34_CR9","first-page":"174","volume":"32","author":"WU Chunmei","year":"2006","unstructured":"Chunmei, W.U., Xia, N., Mao, B.: A comparison of static analysis technology for intrusion prevention. Comput. Eng. 32(3), 174\u2013176 (2006)","journal-title":"Comput. Eng."},{"key":"34_CR10","doi-asserted-by":"crossref","unstructured":"Kosuga, Y., Kono, K., Hanaoka, M., Hishiyama, M., Takahama, Y.: Sania: syntactic and semantic analysis for automated testing against SQL injection. In: Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), pp. 107\u2013117. IEEE (2007)","DOI":"10.1109\/ACSAC.2007.20"},{"key":"34_CR11","doi-asserted-by":"crossref","unstructured":"Naderi-Afooshteh, A., Nguyen-Tuong, A., Bagheri-Marzijarani, M., Hiser, J.D., Davidson, J.W.: Joza: hybrid taint inference for defeating web application SQL injection attacks. In: 2015 45th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 172\u2013183. IEEE (2015)","DOI":"10.1109\/DSN.2015.13"},{"key":"34_CR12","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1007\/0-387-25660-1_20","volume-title":"Security and Privacy in the Age of Ubiquitous Computing","author":"A Nguyen-Tuong","year":"2005","unstructured":"Nguyen-Tuong, A., Guarnieri, S., Greene, D., Shirley, J., Evans, D.: Automatically hardening web applications using precise tainting. In: Sasaki, R., Qing, S., Okamoto, E., Yoshiura, H. (eds.) SEC 2005. IAICT, vol. 181, pp. 295\u2013307. Springer, Boston, MA (2005). \nhttps:\/\/doi.org\/10.1007\/0-387-25660-1_20"},{"issue":"1\u20132","key":"34_CR13","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1016\/j.mcm.2011.01.050","volume":"55","author":"I Lee","year":"2012","unstructured":"Lee, I., Jeong, S., Yeo, S., Moon, J.: A novel method for SQL injection attack detection based on removing SQL query attribute values. Math. Comput. Modell. 55(1\u20132), 58\u201368 (2012)","journal-title":"Math. Comput. Modell."},{"key":"34_CR14","doi-asserted-by":"crossref","unstructured":"Chen, Z., Guo, M., et al.: Research on SQL injection detection technology based on SVM. In: MATEC Web of Conferences. vol. 173, p. 01004. EDP Sciences (2018)","DOI":"10.1051\/matecconf\/201817301004"},{"issue":"4","key":"34_CR15","doi-asserted-by":"publisher","first-page":"5279","DOI":"10.1007\/s11277-016-3741-7","volume":"96","author":"TY Wu","year":"2017","unstructured":"Wu, T.Y., Chen, C.M., Sun, X., Liu, S., Lin, J.C.W.: A countermeasure to SQL injection attack for cloud environment. Wireless Pers. Commun. 96(4), 5279\u20135293 (2017)","journal-title":"Wireless Pers. Commun."},{"issue":"5","key":"34_CR16","first-page":"4182","volume":"68","author":"Q Li","year":"2019","unstructured":"Li, Q., Wang, F., Wang, J., Li, W.: LSTM-based SQL injection detection method for intelligent transportation system. IEEE Trans. Veh. Technol. 68(5), 4182\u20134191 (2019)","journal-title":"IEEE Trans. Veh. Technol."},{"key":"34_CR17","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1016\/j.jss.2017.11.001","volume":"137","author":"R Yan","year":"2018","unstructured":"Yan, R., Xiao, X., Hu, G., Peng, S., Jiang, Y.: New deep learning method to detect code injection attacks on hybrid applications. J. Syst. Softw. 137, 67\u201377 (2018)","journal-title":"J. Syst. Softw."},{"key":"34_CR18","doi-asserted-by":"crossref","unstructured":"Hou, B., Shi, Y., Qian, K., Tao, L.: Towards analyzing mongodb nosql security and designing injection defense solution. In: 2017 IEEE 3rd International Conference on Big Data Security on Cloud (bigdatasecurity), IEEE International Conference on High Performance and Smart Computing (HPSC), and IEEE International Conference on Intelligent Data and Security (IDS), pp. 90\u201395. IEEE (2017)","DOI":"10.1109\/BigDataSecurity.2017.29"},{"issue":"3","key":"34_CR19","first-page":"01","volume":"3","author":"P Patil","year":"2017","unstructured":"Patil, P., Gaikwad, A., Badekar, R., Urade, A., Hirve, R.: Analysis and diminution of NoSQL injection attacks. IJRDO - J. Comput. Sci. Eng. 3(3), 01\u201307 (2017). ISSN 2456\u20131843, \nhttps:\/\/www.ijrdo.org\/index.php\/cse\/article\/view\/481","journal-title":"IJRDO - J. Comput. Sci. Eng."},{"key":"34_CR20","doi-asserted-by":"crossref","unstructured":"Algarni, A., Alsolami, F., Eassa, F., Alsubhi, K., Jambi, K., Khemakhem, M.: An open tool architecture for security testing of NoSQL-based applications. In: 2017 IEEE\/ACS 14th International Conference on Computer Systems and Applications (AICCSA), pp. 220\u2013225. IEEE (2017)","DOI":"10.1109\/AICCSA.2017.44"},{"issue":"2","key":"34_CR21","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/MSP.2016.36","volume":"14","author":"A Ron","year":"2016","unstructured":"Ron, A., Shulman-Peleg, A., Puzanov, A.: Analysis and mitigation of NoSQL injections. IEEE Secur. Priv. 14(2), 30\u201339 (2016)","journal-title":"IEEE Secur. Priv."},{"key":"34_CR22","doi-asserted-by":"crossref","unstructured":"Hou, B., Qian, K., Li, L., Shi, Y., Tao, L., Liu, J.: Mongodb NoSQL injection analysis and detection. In: 2016 IEEE 3rd International Conference on Cyber Security and Cloud Computing (CSCloud), pp. 75\u201378. IEEE (2016)","DOI":"10.1109\/CSCloud.2016.57"},{"key":"34_CR23","doi-asserted-by":"crossref","unstructured":"Son, S., McKinley, K.S., Shmatikov, V.: Diglossia: detecting code injection attacks with precision and efficiency. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, pp. 1181\u20131192. ACM (2013)","DOI":"10.1145\/2508859.2516696"},{"issue":"11","key":"34_CR24","first-page":"614","volume":"8","author":"AM Eassa","year":"2017","unstructured":"Eassa, A.M., Al-Tarawneh, O.H., El-Bakry, H.M., Salama, A.S.: NoSQL racket: a testing tool for detecting NoSQL injection attacks in web applicationss. Int. J. Adv. Comput. Sci. Appl 8(11), 614\u2013622 (2017)","journal-title":"Int. J. Adv. Comput. Sci. Appl"},{"issue":"6","key":"34_CR25","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1134\/S036176881901002X","volume":"44","author":"AM Eassa","year":"2018","unstructured":"Eassa, A.M., Elhoseny, M., El-Bakry, H.M., Salama, A.S.: NoSQL injection attack detection in web applications using restful service. Program. Comput. Softw. 44(6), 435\u2013444 (2018)","journal-title":"Program. Comput. Softw."},{"key":"34_CR26","doi-asserted-by":"crossref","unstructured":"Appelt, D., Nguyen, C.D., Briand, L.C., Alshahwan, N.: Automated testing for SQL injection vulnerabilities: an input mutation approach. In: Proceedings of the 2014 International Symposium on Software Testing and Analysis. pp. 259\u2013269. ACM (2014)","DOI":"10.1145\/2610384.2610403"},{"key":"34_CR27","doi-asserted-by":"crossref","unstructured":"Taguinod, M., Doup\u00e9, A., Zhao, Z., Ahn, G.J.: Toward a moving target defense for web applications. In: 2015 IEEE International Conference on Information Reuse and Integration, pp. 510\u2013517. IEEE (2015)","DOI":"10.1109\/IRI.2015.84"},{"key":"34_CR28","doi-asserted-by":"crossref","unstructured":"Vikram, S., Yang, C., Gu, G.: Nomad: towards non-intrusive moving-target defense against web bots. In: 2013 IEEE Conference on Communications and Network Security (CNS), pp. 55\u201363. IEEE (2013)","DOI":"10.1109\/CNS.2013.6682692"},{"issue":"1","key":"34_CR29","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1109\/MSP.2009.15","volume":"7","author":"AD Keromytis","year":"2009","unstructured":"Keromytis, A.D.: Randomized instruction sets and runtime environments past research and future directions. IEEE Secur. Priv. 7(1), 18\u201325 (2009)","journal-title":"IEEE Secur. Priv."},{"key":"34_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/978-3-540-24852-1_21","volume-title":"Applied Cryptography and Network Security","author":"SW Boyd","year":"2004","unstructured":"Boyd, S.W., Keromytis, A.D.: SQLrand: preventing SQL injection attacks. In: Jakobsson, M., Yung, M., Zhou, J. (eds.) ACNS 2004. LNCS, vol. 3089, pp. 292\u2013302. Springer, Heidelberg (2004). \nhttps:\/\/doi.org\/10.1007\/978-3-540-24852-1_21"},{"issue":"1","key":"34_CR31","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/MS.2014.150","volume":"32","author":"S Allier","year":"2014","unstructured":"Allier, S., Barais, O., Baudry, B., Bourcier, J., Daubert, E., Fleurey, F., Monperrus, M., Song, H., Tricoire, M.: Multitier diversification in web-based software applications. IEEE Softw. 32(1), 83\u201390 (2014)","journal-title":"IEEE Softw."},{"key":"34_CR32","doi-asserted-by":"crossref","unstructured":"Zhang, H., Zheng, K., Wang, X., Luo, S., Wu, B.: Efficient strategy selection for moving target defense under multiple attacks. IEEE Access (2019)","DOI":"10.1109\/ACCESS.2019.2918319"}],"container-title":["Lecture Notes in Computer Science","Algorithms and Architectures for Parallel Processing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-38991-8_34","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,1,22]],"date-time":"2020-01-22T00:52:39Z","timestamp":1579654359000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-38991-8_34"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030389901","9783030389918"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-38991-8_34","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"22 January 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICA3PP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Algorithms and Architectures for Parallel Processing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Melbourne, VIC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ica3pp2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/nsclab.org\/ica3pp2019\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"251","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"73","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5.8","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}