{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T15:24:13Z","timestamp":1742916253287,"version":"3.40.3"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031355035"},{"type":"electronic","value":"9783031355042"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-35504-2_13","type":"book-chapter","created":{"date-parts":[[2023,6,9]],"date-time":"2023-06-09T08:01:47Z","timestamp":1686297707000},"page":"256-275","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Untangle: Aiding Global Function Pointer Hijacking for\u00a0Post-CET Binary Exploitation"],"prefix":"10.1007","author":[{"given":"Alessandro","family":"Bertani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marco","family":"Bonelli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenzo","family":"Binosi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mario","family":"Polino","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,6,10]]},"reference":[{"key":"13_CR1","unstructured":"angr. https:\/\/angr.io\/"},{"key":"13_CR2","unstructured":"CodeQL. https:\/\/codeql.github.com\/"},{"key":"13_CR3","unstructured":"Debian popularity contest. https:\/\/popcon.debian.org\/main\/index.html"},{"key":"13_CR4","unstructured":"Fine-grained forward CFI on top of intel CET \/ IBT. https:\/\/www.openwall.com\/lists\/kernel-hardening\/2021\/02\/11\/1"},{"key":"13_CR5","unstructured":"Linux standard base specification: Interface definitions for libdl. https:\/\/refspecs.linuxbase.org\/LSB_3.0.0\/LSB-generic\/LSB-generic\/libdlman.html"},{"key":"13_CR6","unstructured":"The LLVM compiler infrastructure. https:\/\/llvm.org\/"},{"key":"13_CR7","unstructured":"PyVEX. https:\/\/github.com\/angr\/pyvex"},{"issue":"1","key":"13_CR8","doi-asserted-by":"publisher","first-page":"4:1","DOI":"10.1145\/1609956.1609960","volume":"13","author":"M Abadi","year":"2009","unstructured":"Abadi, M., Budiu, M., Erlingsson, \u00da., Ligatti, J.: Control-flow integrity principles, implementations, and applications. ACM Trans. Inf. Syst. Secur. 13(1), 4:1-4:40 (2009). https:\/\/doi.org\/10.1145\/1609956.1609960","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"13_CR9","unstructured":"Bhatkar, S., DuVarney, D.C., Sekar, R.: Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In: Proceedings of the 12th USENIX Security Symposium, Washington, D.C., USA, 4\u20138 August 2003. USENIX Association (2003)"},{"key":"13_CR10","doi-asserted-by":"publisher","unstructured":"Bletsch, T.K., Jiang, X., Freeh, V.W.: Mitigating code-reuse attacks with control-flow locking. In: Twenty-Seventh Annual Computer Security Applications Conference, ACSAC 2011, Orlando, FL, USA, 5\u20139 December 2011, pp. 353\u2013362. ACM (2011). https:\/\/doi.org\/10.1145\/2076732.2076783","DOI":"10.1145\/2076732.2076783"},{"key":"13_CR11","doi-asserted-by":"publisher","unstructured":"Bletsch, T.K., Jiang, X., Freeh, V.W., Liang, Z.: Jump-oriented programming: a new class of code-reuse attack. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2011, Hong Kong, China, 22\u201324 March 2011, pp. 30\u201340. ACM (2011). https:\/\/doi.org\/10.1145\/1966913.1966919","DOI":"10.1145\/1966913.1966919"},{"key":"13_CR12","doi-asserted-by":"publisher","unstructured":"Borzacchiello, L., Coppa, E., D\u2019Elia, D.C., Demetrescu, C.: Memory models in symbolic execution: key ideas and new thoughts. Softw. Test. Verification Reliab. 29(8) (2019). https:\/\/doi.org\/10.1002\/stvr.1722","DOI":"10.1002\/stvr.1722"},{"key":"13_CR13","unstructured":"Buchanan, E., Roemer, R., Savage, S., Shacham, H.: Return-oriented programming: Exploitation without code injection. Black Hat 8 (2008)"},{"key":"13_CR14","doi-asserted-by":"publisher","unstructured":"Burow, N., Carr, S.A., Nash, J., Larsen, P., Franz, M., Brunthaler, S., Payer, M.: Control-flow integrity: Precision, security, and performance. ACM Comput. Surv. 50(1), 16:1\u201316:33 (2017). https:\/\/doi.org\/10.1145\/3054924","DOI":"10.1145\/3054924"},{"key":"13_CR15","unstructured":"Carlini, N., Wagner, D.A.: ROP is still dangerous: Breaking modern defenses. In: Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA, 20\u201322 August 2014, pp. 385\u2013399. USENIX Association (2014)"},{"key":"13_CR16","doi-asserted-by":"publisher","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A., Shacham, H., Winandy, M.: Return-oriented programming without returns. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010, Chicago, Illinois, USA, 4\u20138 October 2010. pp. 559\u2013572. ACM (2010). https:\/\/doi.org\/10.1145\/1866307.1866370","DOI":"10.1145\/1866307.1866370"},{"key":"13_CR17","unstructured":"Chen, S., Xu, J., Sezer, E.C.: Non-control-data attacks are realistic threats. In: Proceedings of the 14th USENIX Security Symposium, Baltimore, MD, USA, July 31 - August 5, 2005. USENIX Association (2005)"},{"key":"13_CR18","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Zhou, Z., Yu, M., Ding, X., Deng, R.H.: Ropecker: A generic and practical approach for defending against ROP attacks (2014)","DOI":"10.14722\/ndss.2014.23156"},{"key":"13_CR19","doi-asserted-by":"publisher","unstructured":"Dang, T.H.Y., Maniatis, P., Wagner, D.A.: The performance cost of shadow stacks and stack canaries. In: Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, ASIA CCS 2015, Singapore, 14\u201317 April 2015. pp. 555\u2013566. ACM (2015). https:\/\/doi.org\/10.1145\/2714576.2714635","DOI":"10.1145\/2714576.2714635"},{"key":"13_CR20","doi-asserted-by":"publisher","unstructured":"Davi, L., Sadeghi, A., Winandy, M.: Ropdefender: a detection tool to defend against return-oriented programming attacks. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2011, Hong Kong, China, 22\u201324 March 2011, pp. 40\u201351. ACM (2011). https:\/\/doi.org\/10.1145\/1966913.1966920","DOI":"10.1145\/1966913.1966920"},{"key":"13_CR21","unstructured":"Homescu, A., Stewart, M., Larsen, P., Brunthaler, S., Franz, M.: Microgadgets: Size does matter in turing-complete return-oriented programming. In: 6th USENIX Workshop on Offensive Technologies, WOOT\u201912, 6\u20137 August 2012, Bellevue, WA, USA, Proceedings, pp. 64\u201376. USENIX Association (2012)"},{"key":"13_CR22","unstructured":"Hu, H., Chua, Z.L., Adrian, S., Saxena, P., Liang, Z.: Automatic generation of data-oriented exploits. In: 24th USENIX Security Symposium, USENIX Security 15, Washington, D.C., USA, 12\u201314 August 2015, pp. 177\u2013192. USENIX Association (2015)"},{"key":"13_CR23","doi-asserted-by":"publisher","unstructured":"Hu, H., Shinde, S., Adrian, S., Chua, Z.L., Saxena, P., Liang, Z.: Data-oriented programming: On the expressiveness of non-control data attacks. In: IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, 22\u201326 May 2016, pp. 969\u2013986. IEEE Computer Society (2016). https:\/\/doi.org\/10.1109\/SP.2016.62","DOI":"10.1109\/SP.2016.62"},{"key":"13_CR24","doi-asserted-by":"publisher","unstructured":"Ispoglou, K.K., AlBassam, B., Jaeger, T., Payer, M.: Block oriented programming: Automating data-only attacks. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS 2018, Toronto, ON, Canada, 15\u201319 October 2018, pp. 1868\u20131882. ACM (2018). https:\/\/doi.org\/10.1145\/3243734.3243739","DOI":"10.1145\/3243734.3243739"},{"issue":"7","key":"13_CR25","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1145\/360248.360252","volume":"19","author":"JC King","year":"1976","unstructured":"King, J.C.: Symbolic execution and program testing. Commun. ACM 19(7), 385\u2013394 (1976). https:\/\/doi.org\/10.1145\/360248.360252","journal-title":"Commun. ACM"},{"key":"13_CR26","doi-asserted-by":"publisher","unstructured":"Niu, B., Tan, G.: Modular control-flow integrity. In: ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2014, Edinburgh, United Kingdom - 09\u201311 June 2014, pp. 577\u2013587. ACM (2014). https:\/\/doi.org\/10.1145\/2594291.2594295","DOI":"10.1145\/2594291.2594295"},{"key":"13_CR27","unstructured":"Pappas, V., Polychronakis, M., Keromytis, A.D.: Transparent ROP exploit mitigation using indirect branch tracing. In: Proceedings of the 22th USENIX Security Symposium, Washington, DC, USA, 14\u201316 August 2013, pp. 447\u2013462. USENIX Association (2013)"},{"issue":"6","key":"13_CR28","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1109\/MSP.2012.152","volume":"10","author":"M Prandini","year":"2012","unstructured":"Prandini, M., Ramilli, M.: Return-oriented programming. IEEE Secur. Priv. 10(6), 84\u201387 (2012). https:\/\/doi.org\/10.1109\/MSP.2012.152","journal-title":"IEEE Secur. Priv."},{"key":"13_CR29","doi-asserted-by":"publisher","unstructured":"Roemer, R., Buchanan, E., Shacham, H., Savage, S.: Return-oriented programming: Systems, languages, and applications. ACM Trans. Inf. Syst. Secur. 15(1), 2:1\u20132:34 (2012). https:\/\/doi.org\/10.1145\/2133375.2133377","DOI":"10.1145\/2133375.2133377"},{"issue":"2","key":"13_CR30","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/s11416-017-0299-1","volume":"14","author":"AA Sadeghi","year":"2017","unstructured":"Sadeghi, A.A., Niksefat, S., Rostamipour, M.: Pure-Call Oriented Programming (PCOP): chaining the gadgets using call instructions. J. Comput. Virology Hacking Techniques 14(2), 139\u2013156 (2017). https:\/\/doi.org\/10.1007\/s11416-017-0299-1","journal-title":"J. Comput. Virology Hacking Techniques"},{"key":"13_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1007\/978-3-319-11379-1_5","volume-title":"Research in Attacks, Intrusions and Defenses","author":"F Schuster","year":"2014","unstructured":"Schuster, F., et al.: Evaluating the effectiveness of current anti-ROP defenses. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) RAID 2014. LNCS, vol. 8688, pp. 88\u2013108. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_5"},{"key":"13_CR32","doi-asserted-by":"publisher","unstructured":"Shacham, H., Page, M., Pfaff, B., Goh, E., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM Conference on Computer and Communications Security, CCS 2004, Washington, DC, USA, 25\u201329 October 2004, pp. 298\u2013307. ACM (2004). https:\/\/doi.org\/10.1145\/1030083.1030124","DOI":"10.1145\/1030083.1030124"},{"key":"13_CR33","doi-asserted-by":"publisher","unstructured":"Shanbhogue, V., Gupta, D., Sahita, R.: Security analysis of processor instruction set architecture for enforcing control-flow integrity. In: Proceedings of the 8th International Workshop on Hardware and Architectural Support for Security and Privacy, HASP@ISCA 2019, 23 June 2019, pp. 8:1\u20138:11. ACM (2019). https:\/\/doi.org\/10.1145\/3337167.3337175","DOI":"10.1145\/3337167.3337175"},{"key":"13_CR34","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y., Wang, R., Hauser, C., Kruegel, C., Vigna, G.: Firmalice - automatic detection of authentication bypass vulnerabilities in binary firmware (2015)","DOI":"10.14722\/ndss.2015.23294"},{"key":"13_CR35","doi-asserted-by":"publisher","unstructured":"Shoshitaishvili, Y., et al.: SOK: (state of) the art of war: offensive techniques in binary analysis. In: IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, 22\u201326 May 2016, pp. 138\u2013157. IEEE Computer Society (2016). https:\/\/doi.org\/10.1109\/SP.2016.17","DOI":"10.1109\/SP.2016.17"},{"key":"13_CR36","doi-asserted-by":"publisher","unstructured":"Szekeres, L., Payer, M., Wei, T., Song, D.: SOK: eternal war in memory. In: 2013 IEEE Symposium on Security and Privacy, SP 2013, Berkeley, CA, USA, 19\u201322 May 2013, pp. 48\u201362. IEEE Computer Society (2013). https:\/\/doi.org\/10.1109\/SP.2013.13","DOI":"10.1109\/SP.2013.13"},{"key":"13_CR37","doi-asserted-by":"publisher","unstructured":"Wang, F., Shoshitaishvili, Y.: ANGR - the next generation of binary analysis. In: IEEE Cybersecurity Development, SecDev 2017, Cambridge, MA, USA, 24\u201326 September 2017, pp. 8\u20139. IEEE Computer Society (2017). https:\/\/doi.org\/10.1109\/SecDev.2017.14","DOI":"10.1109\/SecDev.2017.14"},{"key":"13_CR38","doi-asserted-by":"publisher","unstructured":"Yamaguchi, F., Golde, N., Arp, D., Rieck, K.: Modeling and discovering vulnerabilities with code property graphs. In: 2014 IEEE Symposium on Security and Privacy, SP 2014, Berkeley, CA, USA, 18\u201321 May 2014, pp. 590\u2013604. IEEE Computer Society (2014). https:\/\/doi.org\/10.1109\/SP.2014.44","DOI":"10.1109\/SP.2014.44"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-35504-2_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,4]],"date-time":"2023-07-04T23:04:26Z","timestamp":1688511866000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-35504-2_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031355035","9783031355042"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-35504-2_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"10 June 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hamburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 July 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva2023.de\/org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"hotcrp.com","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"43","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"12","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}