{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,29]],"date-time":"2025-11-29T07:51:59Z","timestamp":1764402719501,"version":"3.40.3"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319406664"},{"type":"electronic","value":"9783319406671"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-40667-1_4","type":"book-chapter","created":{"date-parts":[[2016,6,11]],"date-time":"2016-06-11T11:19:03Z","timestamp":1465643943000},"page":"58-77","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["AVRAND: A Software-Based Defense Against Code Reuse Attacks for AVR Embedded Devices"],"prefix":"10.1007","author":[{"given":"Sergio","family":"Pastrana","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juan","family":"Tapiador","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guillermo","family":"Suarez-Tangil","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pedro","family":"Peris-L\u00f3pez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,6,12]]},"reference":[{"key":"4_CR1","unstructured":"Anderson, W.: Entropy library documentation. Google Code Projects (2012)"},{"key":"4_CR2","unstructured":"Atmel, C.: Avr109: Self programming (2004). atmel.com\/images\/doc1644.pdf"},{"key":"4_CR3","unstructured":"Atmel, C.: Automotive compilation (2012). http:\/\/www.atmel.com\/Images\/atmel_autocompilation_vol9_oct2012.pdf"},{"key":"4_CR4","unstructured":"Backes, M., N\u00fcrnberger, S.: Oxymoron: making fine-grained memory randomization practical by allowing code sharing. In: USENIX Security Symposium (2014)"},{"key":"4_CR5","unstructured":"Bhatkar, S., DuVarney, D.C., Sekar, R.: Address obfuscation: an efficient approach to combat a broad range of memory error exploits. In: USENIX Security (2003)"},{"key":"4_CR6","doi-asserted-by":"crossref","unstructured":"Braden, K., Crane, S., Davi, L., Franz, M., Larsen, P., Liebchen, C., Sadeghi, A.R.: Leakage-resilient layout randomization for mobile devices. In: Network and Distributed Systems Security Symposium (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23364"},{"key":"4_CR7","unstructured":"Carlini, N., Wagner, D.: Rop is still dangerous: breaking modern defenses. In: USENIX Security Symposium (2014)"},{"key":"4_CR8","unstructured":"Cowan, C., Wagle, P., Pu, C., Beattie, S., Walpole, J.: Buffer overflows: attacks and defenses for the vulnerability of the decade. In: DARPA Information Survivability Conference and Exposition, 2000, DISCEX 2000, vol. 2, pp. 119\u2013129. IEEE (2000)"},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Crane, S., Liebchen, C., Homescu, A., Davi, L., Larsen, P., Sadeghi, A.R., Brunthaler, S., Franz, M.: Readactor: practical code randomization resilient to memory disclosure. In: IEEE Symposium on Security and Privacy, S&P, vol. 15 (2015)","DOI":"10.1109\/SP.2015.52"},{"key":"4_CR10","doi-asserted-by":"crossref","unstructured":"Davi, L., Liebchen, C., Sadeghi, A.R., Snow, K.Z., Monrose, F.: Isomeron: code randomization resilient to (just-in-time) return-oriented programming. In: Proceedings of the 22nd Network and Distributed Systems Security Symposium (NDSS) (2015)","DOI":"10.14722\/ndss.2015.23262"},{"key":"4_CR11","unstructured":"Dean, B.S.: Avr downloader\/uploader (2003). http:\/\/www.nongnu.org\/avrdude\/. Accessed Jan 2016"},{"key":"4_CR12","doi-asserted-by":"crossref","unstructured":"Francillon, A., Castelluccia, C.: Code injection attacks on harvard-architecture devices. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 15\u201326. ACM (2008)","DOI":"10.1145\/1455770.1455775"},{"key":"4_CR13","doi-asserted-by":"crossref","unstructured":"Francillon, A., Perito, D., Castelluccia, C.: Defending embedded systems against control flow attacks. In: Proceedings of the First ACM Workshop on Secure Execution of Untrusted Code, pp. 19\u201326. ACM (2009)","DOI":"10.1145\/1655077.1655083"},{"key":"4_CR14","doi-asserted-by":"crossref","unstructured":"Gu, Q., Noorani, R.: Towards self-propagate mal-packets in sensor networks. In: Proceedings of the ACM Conference on Wireless Network Security, pp. 172\u2013182. ACM (2008)","DOI":"10.1145\/1352533.1352563"},{"key":"4_CR15","doi-asserted-by":"crossref","unstructured":"Habibi, J., Gupta, A., Carlsony, S., Panicker, A., Bertino, E.: MAVR: code reuse stealthy attacks and mitigation on unmanned aerial vehicles. In: Distributed Computing Systems (ICDCS), pp. 642\u2013652. IEEE (2015)","DOI":"10.1109\/ICDCS.2015.71"},{"key":"4_CR16","unstructured":"Intel, C.: Hexadecimal object file format specification (1988)"},{"key":"4_CR17","unstructured":"Mohan, V., Hamlen, K.W.: Frankenstein: stitching malware from benign binaries. In: 6th USENIX Workshop on Offensive Technologies. USENIX (2012)"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Mohan, V., Larsen, P., Brunthaler, S., Hamlen, K., Franz, M.: Opaque control-flow integrity. In: Network and Distributed Systems Security Symposium (NDSS) (2015)","DOI":"10.14722\/ndss.2015.23271"},{"key":"4_CR19","unstructured":"GNU Project: Avr libc home page (1999). http:\/\/www.nongnu.org\/avr-libc\/. Accessed Jan 2016"},{"issue":"1","key":"4_CR20","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1145\/2133375.2133377","volume":"15","author":"R Roemer","year":"2012","unstructured":"Roemer, R., Buchanan, E., Shacham, H., Savage, S.: Return-oriented programming: systems, languages, and applications. ACM Trans. Inf. Syst. Secur. (TISSEC) 15(1), 2 (2012)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Sadeghi, A.R., Wachsmann, C., Waidner, M.: Security and privacy challenges in industrial internet of things. In: Annual Design Automation Conference. ACM (2015)","DOI":"10.1145\/2744769.2747942"},{"key":"4_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1007\/978-3-319-11379-1_5","volume-title":"Research in Attacks, Intrusions and Defenses","author":"F Schuster","year":"2014","unstructured":"Schuster, F., Tendyck, T., Pewny, J., Maa\u00df, A., Steegmanns, M., Contag, M., Holz, T.: Evaluating the effectiveness of current Anti-ROP defenses. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) RAID 2014. LNCS, vol. 8688, pp. 88\u2013108. Springer, Heidelberg (2014)"},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Snow, K.Z., Monrose, F., Davi, L., Dmitrienko, A., Liebchen, C., Sadeghi, A.R.: Just-in-time code reuse: on the effectiveness of fine-grained address space layout randomization. In: Security and Privacy (SP), pp. 574\u2013588 (2013)","DOI":"10.1109\/SP.2013.45"},{"key":"4_CR24","doi-asserted-by":"crossref","unstructured":"Szekeres, L., Payer, M., Wei, T., Song, D.: SoK: eternal war in memory. In: 2013 IEEE Symposium on Security and Privacy (SP), pp. 48\u201362. IEEE (2013)","DOI":"10.1109\/SP.2013.13"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"Tang, A., Sethumadhavan, S., Stolfo, S.: Heisenbyte: thwarting memory disclosure attacks using destructive code reads. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 256\u2013267. ACM (2015)","DOI":"10.1145\/2810103.2813685"},{"key":"4_CR26","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4302-4447-9","volume-title":"Practical AVR Microcontrollers: Games, Gadgets, and Home Automation with the Microcontroller Used in the Arduino","author":"A Trevennor","year":"2012","unstructured":"Trevennor, A.: Practical AVR Microcontrollers: Games, Gadgets, and Home Automation with the Microcontroller Used in the Arduino. Apress, USA (2012)"},{"key":"4_CR27","unstructured":"Wojtczuk, R.: The advanced return-into-lib (c) exploits: Pax case study. Phrack Magazine, vol. 0x0b, Issue 0x3a, Phile# 0x04 of 0x0e (2001)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-40667-1_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T10:24:28Z","timestamp":1710325468000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-40667-1_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319406664","9783319406671"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-40667-1_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"12 June 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}