{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T05:46:42Z","timestamp":1757310402926,"version":"3.40.3"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031171420"},{"type":"electronic","value":"9783031171437"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-17143-7_6","type":"book-chapter","created":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T04:04:22Z","timestamp":1663905862000},"page":"106-124","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Polymorphic Protocols at\u00a0the\u00a0Example of\u00a0Mitigating Web Bots"],"prefix":"10.1007","author":[{"given":"August","family":"See","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leon","family":"Fritz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mathias","family":"Fischer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,9,24]]},"reference":[{"key":"6_CR1","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1016\/j.jnca.2014.10.009","volume":"48","author":"A Akhunzada","year":"2015","unstructured":"Akhunzada, A., et al.: Man-at-the-end attacks: Analysis, taxonomy, human aspects, motivation and future directions. J. Netw. Comput. Appl. 48, 44\u201357 (2015)","journal-title":"J. Netw. Comput. Appl."},{"key":"6_CR2","doi-asserted-by":"publisher","first-page":"101635","DOI":"10.1016\/j.cose.2019.101635","volume":"88","author":"FH Alqahtani","year":"2020","unstructured":"Alqahtani, F.H., Alsulaiman, F.A.: Is image-based captcha secure against attacks based on machine learning? an experimental study. Comput. Secur. 88, 101635 (2020)","journal-title":"Comput. Secur."},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Amin Azad, B., Starov, O., Laperdrix, P., Nikiforakis, N.: Web runner 2049: evaluating third-party anti-bot services. In: Proceedings of the 17th DIMVA (2020)","DOI":"10.1007\/978-3-030-52683-2_7"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Banescu, S., Collberg, C., Ganesh, V., Newsham, Z., Pretschner, A.: Code obfuscation against symbolic execution attacks. In: Proceedings of the 32nd Annual Conference on Computer Security Applications, pp. 189\u2013200 (2016)","DOI":"10.1145\/2991079.2991114"},{"key":"6_CR5","unstructured":"Banescu, S., Collberg, C., Pretschner, A.: Predicting the resilience of obfuscated code against symbolic execution attacks via machine learning. In: 26th USENIX Security 17, pp. 661\u2013678 (2017)"},{"key":"6_CR6","doi-asserted-by":"crossref","unstructured":"Berdajs, J., Bosni\u0107, Z.: Extending applications using an advanced approach to DLL injection and API hooking. Soft. Pract. Exp. 40(7), 567\u2013584 (2010)","DOI":"10.1002\/spe.973"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Bessi, A., Ferrara, E.: Social bots distort the 2016 us presidential election online discussion. First Monday 21(11\u20137) (2016)","DOI":"10.5210\/fm.v21i11.7090"},{"key":"6_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/978-3-642-29615-4_4","volume-title":"Information Security Technology for Applications","author":"K Boda","year":"2012","unstructured":"Boda, K., F\u00f6ldes, \u00c1.M., Guly\u00e1s, G.G., Imre, S.: User tracking on the web via cross-browser fingerprinting. In: Laud, P. (ed.) NordSec 2011. LNCS, vol. 7161, pp. 31\u201346. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-29615-4_4"},{"key":"6_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/978-3-030-21568-2_8","volume-title":"Applied Cryptography and Network Security","author":"X Cheng","year":"2019","unstructured":"Cheng, X., Lin, Y., Gao, D., Jia, C.: DynOpVm: VM-based software obfuscation with dynamic opcode mapping. In: Deng, R.H., Gauthier-Uma\u00f1a, V., Ochoa, M., Yung, M. (eds.) ACNS 2019. LNCS, vol. 11464, pp. 155\u2013174. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-21568-2_8"},{"key":"6_CR10","unstructured":"Collberg, C.: The Tigress C Obfuscator (2001). https:\/\/tigress.wtf\/about.html"},{"key":"6_CR11","unstructured":"Dyer, K.P., Coull, S.E., Shrimpton, T.: Marionette: a programmable network traffic obfuscation system. In: 24th USENIX Security 15, pp. 367\u2013382 (2015)"},{"issue":"3","key":"6_CR12","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/MSP.2007.71","volume":"5","author":"MN Gagnon","year":"2007","unstructured":"Gagnon, M.N., Taylor, S., Ghosh, A.K.: Software protection through anti-debugging. IEEE Secur. Priv. 5(3), 82\u201384 (2007)","journal-title":"IEEE Secur. Priv."},{"key":"6_CR13","unstructured":"Gummadi, R., Balakrishnan, H., Maniatis, P., Ratnasamy, S.: Not-a-Bot: improving service availability in the face of botnet attacks. In: NSDI, pp. 307\u2013320 (2009)"},{"key":"6_CR14","unstructured":"Heath, N.: Expedia on how one extra data field can cost \\$12m. https:\/\/www.zdnet.com\/article\/expedia-on-how-one-extra-data-field-can-cost-12m\/ (2010), accessed: 2021-10-18"},{"key":"6_CR15","doi-asserted-by":"crossref","unstructured":"Karuppayah, S., Fischer, M., Rossow, C., M\u00fchlh\u00e4user, M.: On advanced monitoring in resilient and unstructured P2P botnets. In: 2014 IEEE International Conference on Communications (ICC), pp. 871\u2013877. IEEE (2014)","DOI":"10.1109\/ICC.2014.6883429"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Karuppayah, S., Roos, S., Rossow, C., M\u00fchlh\u00e4user, M., Fischer, M.: Zeus Milker: circumventing the P2P Xeus neighbor list restriction mechanism. In: 2015 IEEE 35th International Conference on Distributed Computing Systems, pp. 619\u2013629. IEEE (2015)","DOI":"10.1109\/ICDCS.2015.69"},{"issue":"12","key":"6_CR17","doi-asserted-by":"publisher","first-page":"3250","DOI":"10.1109\/TIT.2004.838101","volume":"50","author":"M Li","year":"2004","unstructured":"Li, M., Chen, X., Li, X., Ma, B., Vit\u00e1nyi, P.M.: The similarity metric. IEEE Trans. Inf. Theory 50(12), 3250\u20133264 (2004)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"Liu, M., Jia, C., Liu, L., Wang, Z.: Extracting sent message formats from executables using backward slicing. In: 2013 Fourth International Conference on Emerging Intelligent Data and Web Technologies, pp. 377\u2013384. IEEE (2013)","DOI":"10.1109\/EIDWT.2013.71"},{"key":"6_CR19","unstructured":"Liu, W.: Introducing reCAPTCHA v3: the new way to stop bots. https:\/\/developers.google.com\/search\/blog\/2018\/10\/introducing-recaptcha-v3-new-way-to (2018). Accessed 20 May 21"},{"key":"6_CR20","unstructured":"Machines, I.: Stop more bots. Start protecting user privacy. https:\/\/www.hcaptcha.com\/ (2018). Accessed 20 May 21"},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"Mohajeri Moghaddam, H., Li, B., Derakhshani, M., Goldberg, I.: Skypemorph: Protocol obfuscation for tor bridges. In: Proceedings of the 2012 ACM conference on Computer and communications security, pp. 97\u2013108 (2012)","DOI":"10.1145\/2382196.2382210"},{"issue":"3","key":"6_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2840724","volume":"48","author":"J Narayan","year":"2015","unstructured":"Narayan, J., Shukla, S.K., Clancy, T.C.: A survey of automatic protocol reverse engineering tools. CSUR 48(3), 1\u201326 (2015)","journal-title":"CSUR"},{"issue":"1","key":"6_CR23","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2522968.2522972","volume":"46","author":"KA Roundy","year":"2013","unstructured":"Roundy, K.A., Miller, B.P.: Binary-code obfuscations in prevalent packer tools. ACM Comput. Surv. (CSUR) 46(1), 1\u201332 (2013)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"6_CR24","doi-asserted-by":"crossref","unstructured":"Sivakorn, S., Polakis, I., Keromytis, A.D.: I am robot: (deep) learning to break semantic image captchas. In: 2016 IEEE EuroS &P, pp. 388\u2013403. IEEE (2016)","DOI":"10.1109\/EuroSP.2016.37"},{"key":"6_CR25","unstructured":"Software, V.: VMProtect Software Protection (2021). https:\/\/vmpsoft.com\/"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Talukder, M., Islam, S., Falcarin, P.: Analysis of obfuscated code with program slicing. In: 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), pp. 1\u20137. IEEE (2019)","DOI":"10.1109\/CyberSecPODS.2019.8885094"},{"key":"6_CR27","unstructured":"Technologies, O.: Oreans Technologies : Software Security Defined (2022). https:\/\/www.oreans.com\/Themida.php. Accessed 07 Dec 21"},{"key":"6_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"200","DOI":"10.1007\/978-3-642-04444-1_13","volume-title":"Computer Security \u2013 ESORICS 2009","author":"Z Wang","year":"2009","unstructured":"Wang, Z., Jiang, X., Cui, W., Wang, X., Grace, M.: ReFormat: automatic reverse engineering of encrypted messages. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol. 5789, pp. 200\u2013215. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-04444-1_13"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-17143-7_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T04:04:56Z","timestamp":1663905896000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-17143-7_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031171420","9783031171437"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-17143-7_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"24 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"562","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"104","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"12","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}