{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T15:21:04Z","timestamp":1725808864926},"publisher-location":"Cham","reference-count":32,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319132563"},{"type":"electronic","value":"9783319132570"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-13257-0_25","type":"book-chapter","created":{"date-parts":[[2014,11,3]],"date-time":"2014-11-03T10:43:57Z","timestamp":1415011437000},"page":"413-424","source":"Crossref","is-referenced-by-count":3,"title":["eavesROP: Listening for ROP Payloads in Data Streams"],"prefix":"10.1007","author":[{"given":"Christopher","family":"J\u00e4mthagen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Linus","family":"Karlsson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Stankovski","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Hell","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"25_CR1","unstructured":"One, A.: Smashing the stack for fun and profit, phrack, 49 (1996)"},{"key":"25_CR2","first-page":"30","volume-title":"Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2011","author":"T. Bletsch","year":"2011","unstructured":"Bletsch, T., Jiang, X., Freeh, V.W., Liang, Z.: Jump-oriented programming: A new class of code-reuse attack. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2011, pp. 30\u201340. ACM, New York (2011)"},{"key":"25_CR3","unstructured":"Bracewell, R.: The Fourier Transform and its Applications, 3rd edn. McGraw-Hill Series in Electrical and Computer Engineering. McGraw-Hill Science\/Engineering\/Math. (June 1999)"},{"key":"25_CR4","unstructured":"c0ntex: Bypassing non-executable-stack during exploitation using return-to-libc, \n                    \n                      http:\/\/www.infosecwriters.com\/text_resources\/pdf\/return-to-libc.pdf"},{"key":"25_CR5","unstructured":"Cantoni, L.: BigAnt Server 2.52 SP5 - SEH Stack Overflow ROP-based exploit (ASLR + DEP bypass), \n                    \n                      http:\/\/www.exploit-db.com\/exploits\/22466\/"},{"key":"25_CR6","first-page":"559","volume-title":"Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010","author":"S. Checkoway","year":"2010","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A.R., Shacham, H., Winandy, M.: Return-oriented programming without returns. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010, pp. 559\u2013572. ACM, New York (2010)"},{"key":"25_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-642-10772-6_13","volume-title":"Information Systems Security","author":"P. Chen","year":"2009","unstructured":"Chen, P., Xiao, H., Shen, X., Yin, X., Mao, B., Xie, L.: DROP: Detecting return-oriented programming malicious code. In: Prakash, A., Sen Gupta, I. (eds.) ICISS 2009. LNCS, vol.\u00a05905, pp. 163\u2013177. Springer, Heidelberg (2009)"},{"key":"25_CR8","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Zhou, Z., Miao, Y., Ding, X., Deng, R.: ROPecker: A generic and practical approach for defending against ROP attack. In: NDSS. Research Collection School of Information Systems (2014)","DOI":"10.14722\/ndss.2014.23156"},{"key":"25_CR9","unstructured":"Cormen, T., Leiserson, C., Rivest, R., Stein, C.: Introduction to Algorithms, 3rd edn. MIT Press (2009)"},{"key":"25_CR10","doi-asserted-by":"crossref","unstructured":"Davi, L., Sadeghi, A., Winandy, M.: ROPdefender: A detection tool to defend against return-oriented programming attacks. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2011 (2011)","DOI":"10.1145\/1966913.1966920"},{"key":"25_CR11","unstructured":"Durden, T.: Bypassing PaX ASLR protection, phrack, 59 (2002)"},{"key":"25_CR12","unstructured":"Fratric, I.: Ropguard: Runtime prevention of return-oriented programming attacks (2012)"},{"key":"25_CR13","doi-asserted-by":"crossref","unstructured":"Gupta, A., Kerr, S., Kirkpatrick, M., Bertino, E.: Marlin: Making it harder to fish for gadgets. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, CCS 2012. ACM (2012)","DOI":"10.1145\/2382196.2382310"},{"key":"25_CR14","unstructured":"Hensing, R.: Understanding DEP as a mitigation technology (2009), \n                    \n                      http:\/\/blogs.technet.com\/b\/srd\/archive\/2009\/06\/12\/understanding-dep-as-amitigation-technology-part-1.aspx"},{"key":"25_CR15","doi-asserted-by":"crossref","unstructured":"Hiser, J., Nguyen-Tuong, A., Co, M., Hall, M., Davidson, J.: Ilr: Where\u2019d my gadgets go? In: 2012 IEEE Symposium on Security and Privacy (SP) (2012)","DOI":"10.1109\/SP.2012.39"},{"key":"25_CR16","unstructured":"J\u00e4mthagen, C., Karlsson, L., Stankovski, P., Hell, M.: eavesROP: Listening for ROP payloads in data streams (full version) (2014), \n                    \n                      http:\/\/lup.lub.lu.se\/record\/4586662"},{"key":"25_CR17","doi-asserted-by":"crossref","unstructured":"Li, J., Wang, Z., Jiang, X., Grace, M., Bahram, S.: Defeating return-oriented rootkits with \u201creturn-less\u201d kernels. In: Proceedings of the 5th European Conference on Computer Systems, EuroSys 2010. ACM (2010)","DOI":"10.1145\/1755913.1755934"},{"key":"25_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1007\/978-3-642-23644-0_6","volume-title":"Recent Advances in Intrusion Detection","author":"K. Lu","year":"2011","unstructured":"Lu, K., Zou, D., Wen, W., Gao, D.: Packed, printable, and polymorphic return-oriented programming. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol.\u00a06961, pp. 101\u2013120. Springer, Heidelberg (2011)"},{"key":"25_CR19","doi-asserted-by":"crossref","unstructured":"Onarlioglu, K., Bilge, L., Lanzi, A., Balzarotti, D., Kirda, E.: G-free: Defeating return-oriented programming through gadget-less binaries. In: Proceedings of the 26th Annual Computer Security Applications Conference, ACSAC 2010, pp. 49\u201358. ACM (2010)","DOI":"10.1145\/1920261.1920269"},{"key":"25_CR20","doi-asserted-by":"crossref","unstructured":"Pappas, V., Polychronakis, M., Keromytis, A.: Smashing the gadgets: Hindering return-oriented programming using in-place code randomization. In: IEEE Symposium on Security and Privacy. IEEE Computer Society (2012)","DOI":"10.1109\/SP.2012.41"},{"key":"25_CR21","unstructured":"Pappas, V., Polychronakis, M., Keromytis, A.: Transparent ROP exploit mitigation using indirect branch tracing. Presented as part of the 22nd USENIX Security Symposium (USENIX Security 2013). USENIX (2013)"},{"key":"25_CR22","unstructured":"PaX Team: Address space layout randomization (2003), \n                    \n                      http:\/\/pax.grsecurity.net\/docs\/aslr.txt"},{"key":"25_CR23","doi-asserted-by":"crossref","unstructured":"Polychronakis, M., Keromytis, A.: ROP payload detection using speculative code execution. In: Proceedings of the 2011 6th International Conference on Malicious and Unwanted Software, MALWARE 2011. IEEE Computer Society (2011)","DOI":"10.1109\/MALWARE.2011.6112327"},{"key":"25_CR24","unstructured":"Schwartz, E., Avgerinos, T., Brumley, D.: Q: Exploit hardening made easy. In: Proceedings of USENIX Security 2011 (2011)"},{"key":"25_CR25","unstructured":"Serna, F.J.: CVE-2012-0769, the case of the perfect info leak (2009), \n                    \n                      http:\/\/zhodiac.hispahack.com\/my-stuff\/security\/Flash_ASLR_bypass.pdf"},{"key":"25_CR26","doi-asserted-by":"crossref","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS 2007, pp. 552\u2013561. ACM (2007)","DOI":"10.1145\/1315245.1315313"},{"key":"25_CR27","doi-asserted-by":"crossref","unstructured":"Shacham, H., Page, M., Pfaff, N., Goh, E., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM Conference on Computer and Communications Security, CCS 2004, pp. 298\u2013307. ACM (2004)","DOI":"10.1145\/1030083.1030124"},{"key":"25_CR28","doi-asserted-by":"crossref","unstructured":"Snow, K., Monrose, F., Davi, L., Dmitrienko, A., Liebchen, C., Sadeghi, A.: Just-in-time code reuse: On the effectiveness of fine-grained address space layout randomization. In: 2013 IEEE Symposium on Security and Privacy (SP), pp. 574\u2013588 (May 2013)","DOI":"10.1109\/SP.2013.45"},{"key":"25_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1007\/978-3-642-41284-4_4","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"B. Stancill","year":"2013","unstructured":"Stancill, B., Snow, K.Z., Otterness, N., Monrose, F., Davi, L., Sadeghi, A.-R.: Check my profile: Leveraging static analysis for fast and accurate detection of ROP gadgets. In: Stolfo, S.J., Stavrou, A., Wright, C.V. (eds.) RAID 2013. LNCS, vol.\u00a08145, pp. 62\u201381. Springer, Heidelberg (2013)"},{"key":"25_CR30","unstructured":"Sud0: Audio converter 8.1 0day stack buffer overflow PoC exploit ROP\/WPM, \n                    \n                      http:\/\/www.exploit-db.com\/exploits\/13763\/"},{"key":"25_CR31","unstructured":"Vreugdenhil, P.: Pwn2Own 2010 Windows 7 Internet Explorer 8 exploit (2010), \n                    \n                      http:\/\/vreugdenhilresearch.nl\/Pwn2Own-2010-Windows7-InternetExplorer8.pdf"},{"key":"25_CR32","doi-asserted-by":"crossref","unstructured":"Wartell, R., Mohan, V., Hamlen, K., Lin, Z.: Binary stirring: Self-randomizing instruction addresses of legacy x86 binary code. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, CCS 2012 (2012)","DOI":"10.1145\/2382196.2382216"}],"container-title":["Lecture Notes in Computer Science","Information Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-13257-0_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,28]],"date-time":"2019-05-28T12:57:53Z","timestamp":1559048273000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-13257-0_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319132563","9783319132570"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-13257-0_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}