{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,10]],"date-time":"2026-02-10T10:56:39Z","timestamp":1770720999279,"version":"3.49.0"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030624323","type":"print"},{"value":"9783030624330","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-62433-0_8","type":"book-chapter","created":{"date-parts":[[2020,11,6]],"date-time":"2020-11-06T14:02:46Z","timestamp":1604671366000},"page":"125-139","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Software System Exploration Using Library Call Analysis"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6710-5972","authenticated-orcid":false,"given":"Marinos","family":"Tsantekidis","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vassilis","family":"Prevelakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,11,7]]},"reference":[{"key":"8_CR1","doi-asserted-by":"publisher","unstructured":"Abadi, M., Budiu, M., Erlingsson, U., Ligatti, J.: Control-flow integrity. In: Proceedings of the 12th ACM Conference on Computer and Communications Security, CCS 2005, pp. 340\u2013353. ACM, New York (2005). https:\/\/doi.org\/10.1145\/1102120.1102165. http:\/\/doi.acm.org\/10.1145\/1102120.1102165","DOI":"10.1145\/1102120.1102165"},{"key":"8_CR2","unstructured":"Andersen, S., Abella, V.: Data Execution Prevention (2004). https:\/\/technet.microsoft.com\/en-us\/library\/bb457155.aspx"},{"key":"8_CR3","doi-asserted-by":"publisher","unstructured":"Bittau, A., Belay, A., Mashtizadeh, A., Mazi\u00e8res, D., Boneh, D.: Hacking blind. In: 2014 IEEE Symposium on Security and Privacy, pp. 227\u2013242, May 2014. https:\/\/doi.org\/10.1109\/SP.2014.22","DOI":"10.1109\/SP.2014.22"},{"key":"8_CR4","doi-asserted-by":"publisher","unstructured":"Bletsch, T., Jiang, X., Freeh, V.W., Liang, Z.: Jump-oriented programming: a new class of code-reuse attack. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2011, pp. 30\u201340. ACM, New York (2011). https:\/\/doi.org\/10.1145\/1966913.1966919. http:\/\/doi.acm.org\/10.1145\/1966913.1966919","DOI":"10.1145\/1966913.1966919"},{"key":"8_CR5","doi-asserted-by":"publisher","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A.R., Shacham, H., Winandy, M.: Return-oriented programming without returns. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010, pp. 559\u2013572. ACM, New York (2010). https:\/\/doi.org\/10.1145\/1866307.1866370. http:\/\/doi.acm.org\/10.1145\/1866307.1866370","DOI":"10.1145\/1866307.1866370"},{"issue":"7","key":"8_CR6","doi-asserted-by":"publisher","first-page":"2233","DOI":"10.1016\/j.compeleceng.2012.07.005","volume":"39","author":"LH Chen","year":"2013","unstructured":"Chen, L.H., Hsu, F.H., Hwang, Y., Su, M.C., Ku, W.S., Chang, C.H.: Armory: an automatic security testing tool for buffer overflow defect detection. Comput. Electr. Eng. 39(7), 2233\u20132242 (2013). https:\/\/doi.org\/10.1016\/j.compeleceng.2012.07.005","journal-title":"Comput. Electr. Eng."},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Zhou, Z., Miao, Y., Ding, X., Deng, H.R.: ROPecker: a generic and practical approach for defending against ROP attacks. In: Symposium on Network and Distributed System Security (NDSS) (2014)","DOI":"10.14722\/ndss.2014.23156"},{"key":"8_CR8","unstructured":"Common Vulnerabilities and Exposures: CVE-2013-2028, February 2013. https:\/\/www.cvedetails.com\/cve\/CVE-2013-2028\/"},{"key":"8_CR9","unstructured":"Cowan, C., et al.: StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks. In: Proceedings of the 7th Conference on USENIX Security Symposium - Volume 7, SSYM 1998, p. 5. USENIX Association, Berkeley (1998). http:\/\/dl.acm.org\/citation.cfm?id=1267549.1267554"},{"key":"8_CR10","doi-asserted-by":"publisher","unstructured":"Crane, S., Larsen, P., Brunthaler, S., Franz, M.: Booby trapping software. In: Proceedings of the 2013 Workshop on New Security Paradigms Workshop, NSPW 2013, pp. 95\u2013106. ACM, New York (2013). https:\/\/doi.org\/10.1145\/2535813.2535824","DOI":"10.1145\/2535813.2535824"},{"key":"8_CR11","unstructured":"CVE-2016-7054: Chacha20\/poly1305 heap-buffer-overflow (2016). https:\/\/www.openssl.org\/news\/secadv\/20161110.txt"},{"key":"8_CR12","unstructured":"CVE\\_2016\\_7054: Chacha20\/poly1305 heap-buffer-overflow (2016). https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-7054"},{"key":"8_CR13","unstructured":"Designer, S.: Getting around non-executable stack (and fix) (1997). http:\/\/seclists.org\/bugtraq\/1997\/Aug\/63"},{"key":"8_CR14","unstructured":"Fratric, I.: ROPGuard: runtime prevention of return-oriented programming attacks (2012). http:\/\/www.ieee.hr\/_download\/repository\/Ivan_Fratric.pdf"},{"key":"8_CR15","doi-asserted-by":"crossref","unstructured":"Hamad, M., Hammadeh, Z.A.H., Saidi, S., Prevelakis, V., Ernst, R.: Prediction of abnormal temporal behavior in real-time systems. In: The 33rd ACM\/SIGAPP Symposium On Applied Computing (SAC 2018) (2018). https:\/\/dl.acm.org\/citation.cfm?id=3167172","DOI":"10.1145\/3167132.3167172"},{"key":"8_CR16","unstructured":"Hiroaki, E.: ProPolice: GCC extension for protecting applications from stack-smashing attacks, January 2003"},{"key":"8_CR17","doi-asserted-by":"publisher","unstructured":"Lu, S., Seo, M., Lysecky, R.: Timing-based anomaly detection in embedded systems. In: 20th Asia and South Pacific Design Automation Conference, ASP-DAC 2015, January 2015. https:\/\/doi.org\/10.1109\/ASPDAC.2015.7059110","DOI":"10.1109\/ASPDAC.2015.7059110"},{"key":"8_CR18","unstructured":"Pappas, V., Polychronakis, M., Keromytis, A.D.: Transparent ROP exploit mitigation using indirect branch tracing. In: Proceedings of the 22Nd USENIX Conference on Security, SEC 2013, pp. 447\u2013462. USENIX Association, Berkeley (2013). http:\/\/dl.acm.org\/citation.cfm?id=2534766.2534805"},{"key":"8_CR19","unstructured":"PaX, T.: Address Space Layout Randomization (2001). https:\/\/pax.grsecurity.net\/docs\/aslr.txt"},{"issue":"4","key":"8_CR20","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/MSP.2004.36","volume":"2","author":"J Pincus","year":"2004","unstructured":"Pincus, J., Baker, B.: Beyond stack smashing: recent advances in exploiting buffer overruns. IEEE Secur. Privacy 2(4), 20\u201327 (2004). https:\/\/doi.org\/10.1109\/MSP.2004.36","journal-title":"IEEE Secur. Privacy"},{"key":"8_CR21","unstructured":"Prevelakis, V.: Use of HTTP protocol by the TU-BS Sophos Repository. Technical report, TU Braunschweig (2017)"},{"key":"8_CR22","doi-asserted-by":"publisher","unstructured":"Roemer, R., Buchanan, E., Shacham, H., Savage, S.: Return-oriented programming: systems, languages, and applications. ACM Trans. Inf. Syst. Secur. 15(1), 2:1\u20132:34 (2012). https:\/\/doi.org\/10.1145\/2133375.2133377. http:\/\/doi.acm.org\/10.1145\/2133375.2133377","DOI":"10.1145\/2133375.2133377"},{"key":"8_CR23","doi-asserted-by":"publisher","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS 2007, pp. 552\u2013561. ACM, New York (2007). https:\/\/doi.org\/10.1145\/1315245.1315313. http:\/\/doi.acm.org\/10.1145\/1315245.1315313","DOI":"10.1145\/1315245.1315313"},{"key":"8_CR24","doi-asserted-by":"publisher","unstructured":"Shacham, H., Page, M., Pfaff, B., Goh, E.J., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM Conference on Computer and Communications Security, CCS 2004, pp. 298\u2013307. ACM, New York (2004). https:\/\/doi.org\/10.1145\/1030083.1030124. http:\/\/doi.acm.org\/10.1145\/1030083.1030124","DOI":"10.1145\/1030083.1030124"},{"key":"8_CR25","doi-asserted-by":"publisher","unstructured":"Snow, K.Z., Monrose, F., Davi, L., Dmitrienko, A., Liebchen, C., Sadeghi, A.R.: Just-in-time code reuse: on the effectiveness of fine-grained address space layout randomization. In: Proceedings of the 2013 IEEE Symposium on Security and Privacy, SP 2013, pp. 574\u2013588. IEEE Computer Society, Washington, DC (2013). https:\/\/doi.org\/10.1109\/SP.2013.45. http:\/\/dx.doi.org\/10.1109\/SP.2013.45","DOI":"10.1109\/SP.2013.45"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"Tian, D., Xiong, X., Hu, C., Liu, P.: Defeating buffer overflow attacks viavirtualization. Comput. Electr. Eng. 40(6), 1940\u20131950 (2014). http:\/\/dx.doi.org\/10.1016\/j.compeleceng.2013.11.032. http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0045790613003145","DOI":"10.1016\/j.compeleceng.2013.11.032"},{"key":"8_CR27","unstructured":"Tsantekidis, M., Prevelakis, V.: Library-level policy enforcement. In: SECURWARE 2017, The Eleventh International Conference on Emerging Security Information, Systems and Technologies. Rome, Italy (2017). http:\/\/www.thinkmind.org\/index.php?view=article&articleid=securware_2017_2_20_30034"},{"key":"8_CR28","unstructured":"Tsantekidis, M., Prevelakis, V.: Sophos bogus update report. Technical report, TU Braunschweig (2017)"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Tsantekidis, M., Prevelakis, V.: Efficient Monitoring of Library Call Invocation. In: Sixth International Conference on Internet of Things: Systems, Management and Security (IOTSMS). pp. 387\u2013392. Granada, Spain (2019). DOI: 10.1109\/IOTSMS48152.2019.8939203","DOI":"10.1109\/IOTSMS48152.2019.8939203"},{"issue":"4","key":"8_CR30","doi-asserted-by":"publisher","first-page":"437","DOI":"10.1109\/TDSC.2015.2411254","volume":"13","author":"S Volckaert","year":"2016","unstructured":"Volckaert, S., Coppens, B., Sutter, B.D.: Cloning your gadgets: complete rop attack immunity with multi-variant execution. IEEE Trans. Dependable Secure Comput. 13(4), 437\u2013450 (2016). https:\/\/doi.org\/10.1109\/TDSC.2015.2411254","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"8_CR31","unstructured":"Wagle, P., Cowan, C.: Stackguard: simple stack smash protection for GCC. In: Proceedings of the GCC Developers Summit, pp. 243\u2013255 (2003)"},{"key":"8_CR32","unstructured":"i386 WX, O.: (2003). http:\/\/marc.info\/?l=openbsd-misc&m=105056000801065"},{"key":"8_CR33","doi-asserted-by":"publisher","unstructured":"Zeng, Q., Zhao, M., Liu, P.: HeapTherapy: an efficient end-to-end solution against heap buffer overflows. In: 2015 45th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 485\u2013496, June 2015. https:\/\/doi.org\/10.1109\/DSN.2015.54","DOI":"10.1109\/DSN.2015.54"}],"container-title":["Lecture Notes in Computer Science","Model-driven Simulation and Training Environments for Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-62433-0_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T23:03:46Z","timestamp":1762383826000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-62433-0_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030624323","9783030624330"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-62433-0_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"7 November 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"MSTEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on Model-Driven Simulation and Training Environments for Cybersecurity","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Guildford","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 September 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 September 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"mstec2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.threat-arrest.eu\/html\/mstec\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"50% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}