{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T16:10:04Z","timestamp":1746202204824,"version":"3.40.4"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319063195"},{"type":"electronic","value":"9783319063201"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-06320-1_13","type":"book-chapter","created":{"date-parts":[[2014,4,28]],"date-time":"2014-04-28T00:59:27Z","timestamp":1398646767000},"page":"159-171","source":"Crossref","is-referenced-by-count":2,"title":["SBE \u2212 A Precise Shellcode Detection Engine Based on Emulation and Support Vector Machine"],"prefix":"10.1007","author":[{"given":"Yonggan","family":"Hou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J. W.","family":"Zhuge","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Xin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenya","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"13_CR1","unstructured":"Roesch, M.: Snort-lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration, pp. 229\u2013238 (1999)"},{"key":"13_CR2","doi-asserted-by":"crossref","unstructured":"Akritidis, P., Markatos, E.P., Polychronakis, M., Anagnostakis, K.: Stride: Polymorphic sled detection through instruction sequence analysis. In: Sasaki, R., Qing, S., Okamoto, E., Yoshiura, H. (eds.) Security and Privacy in the Age of Ubiquitous Computing. IFIP AICT, vol.\u00a0181, pp. 375\u2013391. Springer, Heidelberg (2005)","DOI":"10.1007\/0-387-25660-1_25"},{"key":"13_CR3","doi-asserted-by":"crossref","unstructured":"Pasupulati, A., Coit, J., Levitt, K., Wu, S.F., Li, S., Kuo, J., et al.: Buttercup: On network-based detection of polymorphic buffer overflow vulnerabilities. In: Network Operations and Management Symposium, NOMS 2004, pp. 235\u2013248. IEEE\/IFIP (2004)","DOI":"10.1109\/NOMS.2004.1317662"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Zhang, Q., Reeves, D.S., Ning, P., Iyer, S.P.: Analyzing network traffic to detect self-decrypting exploit code. In: Proceedings of the 2nd ACM Sympoium on Information, Computer and Communications Security, pp. 4\u201312 (2007)","DOI":"10.1145\/1229285.1229291"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Emulation-based detection of non-self-contained polymorphic shellcode. In: Recent Advances in Intrusion Detection, pp. 87\u2013106 (2007)","DOI":"10.1007\/978-3-540-74320-0_5"},{"key":"13_CR6","doi-asserted-by":"crossref","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Comprehensive shellcode detection using runtime heuristics. In: Proceedings of the 26th Annual Computer Security Applications Conference, pp. 287\u2013296 (2010)","DOI":"10.1145\/1920261.1920305"},{"key":"13_CR7","doi-asserted-by":"crossref","unstructured":"Song, Y., Locasto, M.E., Stavrou, A., Keromytis, A.D., Stolfo, S.J.: On the infeasibility of modeling polymorphic shellcode. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 541\u2013551 (2007)","DOI":"10.1145\/1315245.1315312"},{"key":"13_CR8","unstructured":"Mason, J., Small, S., Monrose, F., MacManus, G.: English shellcode. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, 2009, pp. 524\u2013533 (2009)"},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1007\/3-540-36084-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"T. T\u00f3th","year":"2002","unstructured":"T\u00f3th, T., Kruegel, C.: Accurate buffer overflow detection via abstract payload execution. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 274\u2013291. Springer, Heidelberg (2002)"},{"key":"13_CR10","unstructured":"Detristan, T., Ulenspiegel, T., Malcom, Y., Underduk, M.: Polymorphic shellcode engine using spectrum analysis (2003) Phrack, ed."},{"key":"13_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/11790754_4","volume-title":"Detection of Intrusions and Malware & Vulnerability Assessment","author":"M. Polychronakis","year":"2006","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Network Level polymorphic shellcode detection using emulation. In: B\u00fcschkes, R., Laskov, P. (eds.) DIMVA 2006. LNCS, vol.\u00a04064, pp. 54\u201373. Springer, Heidelberg (2006)"},{"key":"13_CR12","first-page":"1157","volume":"3","author":"I. Guyon","year":"2003","unstructured":"Guyon, I., Elisseeff, A.: An introduction to variable and feature selection. The Journal of Machine Learning Research\u00a03, 1157\u20131182 (2003)","journal-title":"The Journal of Machine Learning Research"},{"key":"13_CR13","doi-asserted-by":"crossref","unstructured":"Joachims, T.: Making large scale SVM learning practical (1999)","DOI":"10.7551\/mitpress\/1130.003.0015"},{"key":"13_CR14","unstructured":"K2. ADMmutate, http:\/\/www.ktwo.ca\/ADMmutate-0.8.4.tar.gz (2001)"},{"key":"13_CR15","unstructured":"Skape. Implementing a custom x86 encoder. Uninformed, 5 (September 2006)"},{"key":"13_CR16","unstructured":"Metasploit project (2006), http:\/\/www.metasploit.com\/"},{"key":"13_CR17","unstructured":"Bania, P.: TAPiON (2005), http:\/\/pb.specialised.info\/all\/tapion\/"},{"key":"13_CR18","unstructured":"Salwan, J.: Shell-storm, http:\/\/www.shell-storm.org\/"},{"key":"13_CR19","unstructured":"Offensive Security. Exploit DB, http:\/\/www.exploit-db.com\/"},{"key":"13_CR20","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Addison-Wesley Professional (February 2005)"},{"key":"13_CR21","unstructured":"Hedley, J.: Jsoup: Java html parser, ed. (2010)"},{"key":"13_CR22","unstructured":"Feng, H.-A.: \u201cGeneric shellcode detection,\u201d ed: US Patent 8,307,432 (2012)"},{"key":"13_CR23","unstructured":"Khodaverdi, J.: Enhancing the Effectiveness of Shellcode Detection by New Run-time Heuristics. International Journal of Computer Science\u00a03, 02\u201311 (2013)"},{"key":"13_CR24","unstructured":"Baecher, P., Koetter, M.: libemu (2009), http:\/\/libemu.carnivore.it\/"},{"key":"13_CR25","first-page":"27","volume":"2","author":"C.-C. Chang","year":"2011","unstructured":"Chang, C.-C., Lin, C.-J.: LIBSVM: A library for support vector machines. ACM Transactions on Intelligent Systems and Technology (TIST)\u00a02, 27 (2011)","journal-title":"ACM Transactions on Intelligent Systems and Technology (TIST)"},{"key":"13_CR26","first-page":"1871","volume":"9","author":"R.-E. Fan","year":"2008","unstructured":"Fan, R.-E., Chang, K.-W., Hsieh, C.-J., Wang, X.-R., Lin, C.-J.: LIBLINEAR: A library for large linear classification. The Journal of Machine Learning Research\u00a09, 1871\u20131874 (2008)","journal-title":"The Journal of Machine Learning Research"},{"key":"13_CR27","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1023\/A:1015292818897","volume":"15","author":"P. Andrs","year":"2002","unstructured":"Andrs, P.: The equivalence of support vector machine and regularization neural networks. Neural Processing Letters\u00a015, 97\u2013104 (2002)","journal-title":"Neural Processing Letters"}],"container-title":["Lecture Notes in Computer Science","Information Security Practice and Experience"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-06320-1_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T15:35:21Z","timestamp":1746200121000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-06320-1_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319063195","9783319063201"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-06320-1_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}