{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,12]],"date-time":"2025-06-12T04:03:37Z","timestamp":1749701017494,"version":"3.41.0"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319475592"},{"type":"electronic","value":"9783319475608"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-47560-8_10","type":"book-chapter","created":{"date-parts":[[2016,10,8]],"date-time":"2016-10-08T00:59:42Z","timestamp":1475888382000},"page":"152-168","source":"Crossref","is-referenced-by-count":5,"title":["A Survey on Internal Interfaces Used by Exploits and Implications on Interface Diversification"],"prefix":"10.1007","author":[{"given":"Sampsa","family":"Rauti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Samuel","family":"Lauren","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joni","family":"Uitto","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shohreh","family":"Hosseinzadeh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jukka","family":"Ruohonen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sami","family":"Hyrynsalmi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ville","family":"Lepp\u00e4nen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,10,9]]},"reference":[{"issue":"2","key":"10_CR1","doi-asserted-by":"crossref","first-page":"8:1","DOI":"10.1145\/2240276.2240279","volume":"15","author":"M Abadi","year":"2012","unstructured":"Abadi, M., Plotkin, G.D.: On protection by layout randomization. ACM Trans. Inf. Syst. Secur. 15(2), 8:1\u20138:29 (2012)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"10_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-642-18178-8_18","volume-title":"Information Security","author":"E Athanasopoulos","year":"2011","unstructured":"Athanasopoulos, E., Krithinakis, A., Markatos, E.P.: An architecture for enforcing JavaScript randomization in Web2.0 applications. In: Burmester, M., Tsudik, G., Magliveras, S., Ili\u0107, I. (eds.) ISC 2010. LNCS, vol. 6531, pp. 203\u2013209. Springer, Heidelberg (2011). doi: 10.1007\/978-3-642-18178-8_18"},{"key":"10_CR3","unstructured":"Athanasopoulos, E., Pappas, V., Krithinakis, A., Ligouras, S., Markatos, E.P., Karagiannis, T.: xJS: practical XSS prevention for web application development. In: Proceedings of the 2010 USENIX conference on Web application development, WebApps 2010, pp. 1\u201312. USENIX Association (2010)"},{"issue":"1","key":"10_CR4","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1145\/1053283.1053286","volume":"8","author":"EG Barrantes","year":"2005","unstructured":"Barrantes, E.G., Ackley, D.H., Forrest, S., Stefanovi\u0107, D.: Randomized instruction set emulation. ACM Trans. Inf. Syst. Secur. 8(1), 3\u201340 (2005)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"issue":"3","key":"10_CR5","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1109\/TDSC.2008.58","volume":"7","author":"SW Boyd","year":"2010","unstructured":"Boyd, S.W., Kc, G.S., Locasto, M.E., Prevelakis, V., Keromytis, A.D.: On the general applicability of instruction-set randomization. IEEE Trans. Dependable Secure Comput. 7(3), 255\u2013270 (2010)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/978-3-540-24852-1_21","volume-title":"Applied Cryptography and Network Security","author":"SW Boyd","year":"2004","unstructured":"Boyd, S.W., Keromytis, A.D.: SQLrand: preventing SQL injection attacks. In: Jakobsson, M., Yung, M., Zhou, J. (eds.) ACNS 2004. LNCS, vol. 3089, pp. 292\u2013302. Springer, Heidelberg (2004). doi: 10.1007\/978-3-540-24852-1_21"},{"key":"10_CR7","unstructured":"Chew, M., Song, D.: Mitigating buffer overflows by operating system randomization. Technical report, CMU (2002)"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Chongkyung, K., Jinsuk, J., Bookholt, C., Xu, J., Peng, N.: Address space layout permutation (ASLP): towards fine-grained randomization of commodity software. In: 2006 Computer Security Applications Conference, ACSAC 2006, pp. 339\u2013348, December 2006","DOI":"10.1109\/ACSAC.2006.9"},{"issue":"6","key":"10_CR9","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1016\/0167-4048(93)90054-9","volume":"12","author":"FB Cohen","year":"1993","unstructured":"Cohen, F.B.: Operating system protection through program evolution. Comput. Secur. 12(6), 565\u2013584 (1993)","journal-title":"Comput. Secur."},{"issue":"2","key":"10_CR10","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1109\/MSP.2012.113","volume":"11","author":"B Coppens","year":"2013","unstructured":"Coppens, B., De Sutter, B., De Bosschere, K.: Protecting your software updates. IEEE Secur. Priv. 11(2), 47\u201354 (2013)","journal-title":"IEEE Secur. Priv."},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Forrest, S., Somayaji, A., Ackley, D.: Building diverse computer systems. In: Proceedings of the 6th Workshop on Hot Topics in Operating Systems (HotOS-VI), HOTOS 1997 (1997)","DOI":"10.1109\/HOTOS.1997.595185"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Franz, M.: E unibus pluram: massive-scale software diversity as a defense mechanism. In Proceedings of the 2010 Workshop on New Security Paradigms, NSPW 2010, pp. 7\u201316. ACM (2010)","DOI":"10.1145\/1900546.1900550"},{"key":"10_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/978-3-642-38631-2_22","volume-title":"Network and System Security","author":"A Gupta","year":"2013","unstructured":"Gupta, A., Kerr, S., Kirkpatrick, M.S., Bertino, E.: Marlin: a fine grained randomization approach to defend against ROP attacks. In: Lopez, J., Huang, X., Sandhu, R. (eds.) NSS 2013. LNCS, vol. 7873, pp. 293\u2013306. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-38631-2_22"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Gupta, A., Kirkpatrick, M.S., Bertino, E.: A secure architecture design based on application isolation, code minimization and randomization. In: 2013 IEEE Conference on Communications and Network Security (CNS), pp. 423\u2013429, October 2013","DOI":"10.1109\/CNS.2013.6682756"},{"key":"10_CR15","unstructured":"Hosseinzadeh, S., Rauti, S., Laur\u00e9n, S., M\u00e4kel\u00e4, J.-M., Holvitie, J., Hyrynsalmi, S., Lepp\u00e4nen, V.: Using diversification and obfuscation techniques for software security: a systematic literature review (2016)"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Hovav, S., Page, M., Pfaff, B., Goh, E.-J., Modadugu, N., Boneh, F.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM Conference on Computer and Communications Security, CCS 2004, pp. 298\u2013307. ACM, New York (2004)","DOI":"10.1145\/1030083.1030124"},{"key":"10_CR17","series-title":"Advances in Information Security","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/978-1-4614-0977-9_4","volume-title":"Moving Target Defense","author":"T Jackson","year":"2011","unstructured":"Jackson, T., Salamat, B., Homescu, A., Manivannan, K., Wagner, G., Gal, A., Brunthaler, S., Wimmer, C., Franz, M.: Compiler-generated software diversity. In: Jajodia, S., et al. (eds.) Moving Target Defense. Advances in Information Security, vol. 54, pp. 77\u201398. Springer, New York (2011)"},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, H.J., Xu, D., Wang, Y.-M.: RandSys: Thwarting code injection attacks with system service interface randomization. In IEEE International Symposium on Reliable Distributed Systems, SRDS 2007, pp. 209\u2013218 (2007)","DOI":"10.1109\/SRDS.2007.36"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Kc, G.S., Keromytis, A.D., Prevelakis, V.: Countering code-injection attacks with instruction-set randomization. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, CCS 2003, pp. 272\u2013280. ACM, New York (2003)","DOI":"10.1145\/948109.948146"},{"issue":"1","key":"10_CR20","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/MSP.2009.15","volume":"7","author":"AD Keromytis","year":"2009","unstructured":"Keromytis, A.D.: Randomized instruction sets and runtime environments past research and future directions. IEEE Secur. Priv. 7(1), 18\u201325 (2009)","journal-title":"IEEE Secur. Priv."},{"key":"10_CR21","unstructured":"Kitchenham, B.: Guidelines for performing systematic literature reviews in software engineering. Technical report EBSE-2007-01, Keele University, School of Computer Science and Mathematics (2007)"},{"issue":"2","key":"10_CR22","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/MSP.2013.129","volume":"12","author":"P Larsen","year":"2014","unstructured":"Larsen, P., Brunthaler, S., Franz, M.: Security through diversity: are we there yet? IEEE Secur. Priv. 12(2), 28\u201335 (2014)","journal-title":"IEEE Secur. Priv."},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Larsen, P., Homescu, A., Brunthaler, S., Franz, M.: SoK: automated software diversity. In: 2014 IEEE Symposium on Security and Privacy (SP), pp. 276\u2013291, May 2014","DOI":"10.1109\/SP.2014.25"},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"Lauren, S., M\u00e4ki, P., Rauti, S., Hosseinzadeh, S., Hyrynsalmi, S., Lepp\u00e4nen, V.: Symbol diversification of Linux binaries. In: Proceedings of World Congress on Internet Security (WorldCIS-2014) (2014)","DOI":"10.1109\/WorldCIS.2014.7028170"},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Liang, Z., Liang, B., Li, L.: A system call randomization based method for countering code injection attacks. In: International Conference on Networks Security, Wireless Communications and Trusted Computing, NSWCTC 2009, pp. 584\u2013587 (2009)","DOI":"10.5815\/ijitcs.2009.01.01"},{"key":"10_CR26","unstructured":"Locasto, M.E., Keromytis, A.D.: PachyRand: SQL randomization for the PostgreSQL JDBC driver. Technical report CUCS-033-05, Columbia University, Computer Science (2005)"},{"key":"10_CR27","series-title":"Advances in Information Security","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1007\/978-1-4614-0977-9_3","volume-title":"Moving Target Defense, Creating Asymmetric Uncertainty for Cyber Threats","author":"G Portokalidis","year":"2011","unstructured":"Portokalidis, G., Keromytis, A.D.: Global ISR: toward a comprehensive defense against unauthorized code execution. In: Jajodia, S., Ghosh, A.K., Swarup, V., Wang, C., Wang, X.S. (eds.) Moving Target Defense, Creating Asymmetric Uncertainty for Cyber Threats. Advances in Information Security, vol. 54, pp. 49\u201376. Springer, New York (2011)"},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"Rauti, S., Lauren, S., Hosseinzadeh, S., M\u00e4kel\u00e4, J.-M., Hyrynsalmi, S., Lepp\u00e4nen, V.: Diversification of system calls in Linux binaries. In: Proceedings of the 6th International Conference on Trustworthy Systems (InTrust 2014) (2014)","DOI":"10.1007\/978-3-319-27998-5_2"},{"key":"10_CR29","doi-asserted-by":"crossref","unstructured":"Rauti, S., Teuhola, J., Lepp\u00e4nen, V.: Diversifying SQL to prevent injection attacks. In: Proceedings of Trustcom\/BigDataSE\/ISPA, pp. 344\u2013351 (2015)","DOI":"10.1109\/Trustcom.2015.393"},{"key":"10_CR30","doi-asserted-by":"crossref","unstructured":"Rodes, B.: Stack layout transformation: towards diversity for securing binary programs. In: 2012 34th International Conference on Software Engineering (ICSE), pp. 1543\u20131546, June 2012","DOI":"10.1109\/ICSE.2012.6227041"},{"key":"10_CR31","unstructured":"Uitto, J., Rauti, S., M\u00e4kel\u00e4, J.-M., Lepp\u00e4nen, V.: Preventing malicious attacks by diversifying Linux shell commands. In: Proceedings of the 14th Symposium on Programming Languages and Software Tools (SPLST 2015), vol. 1525. CEUR Workshop Proceedings (2015)"},{"issue":"1","key":"10_CR32","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/MSP.2009.18","volume":"7","author":"D Williams","year":"2009","unstructured":"Williams, D., Wei, H., Davidson, J.W., Hiser, J.D., Knight, J.C., Nguyen-Tuong, A.: Security through diversity: leveraging virtual machine technology. IEEE Secur. Priv. 7(1), 26\u201333 (2009)","journal-title":"IEEE Secur. Priv."}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-47560-8_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T03:19:25Z","timestamp":1749611965000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-47560-8_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319475592","9783319475608"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-47560-8_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}