{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T17:58:35Z","timestamp":1725559115833},"publisher-location":"Berlin, Heidelberg","reference-count":14,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540253389"},{"type":"electronic","value":"9783540319573"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2005]]},"DOI":"10.1007\/978-3-540-31957-3_111","type":"book-chapter","created":{"date-parts":[[2010,7,7]],"date-time":"2010-07-07T21:26:19Z","timestamp":1278537979000},"page":"980-988","source":"Crossref","is-referenced-by-count":1,"title":["Detecting the Deviations of Privileged Process Execution"],"prefix":"10.1007","author":[{"given":"Purui","family":"Su","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dequan","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haipeng","family":"Qu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dengguo","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"111_CR1","unstructured":"Thomas, E.: Attack class: Buffer overflows, Hello World (1999)"},{"key":"111_CR2","unstructured":"Klog: The Frame Pointer Overwrite. Phrack Magazine\u00a055 (1999)"},{"key":"111_CR3","doi-asserted-by":"crossref","unstructured":"Anonymous: Runtime Process Infection. Phrack Magazine, 59 (2002)","DOI":"10.1093\/ajhp\/59.4.336"},{"key":"111_CR4","unstructured":"Blexim: Basic Integer Overflows. Phrack Magazine\u00a060 (2002)"},{"key":"111_CR5","doi-asserted-by":"crossref","unstructured":"Hofmeyr, S.A., Forrest, S., Somayaji, A.: Intrusion Detection using Sequences of System calls. Journal of Computer Security\u00a06 (1998)","DOI":"10.3233\/JCS-980109"},{"key":"111_CR6","doi-asserted-by":"crossref","unstructured":"Okazaki, Y., Sato, I.: A New Intrusion Detection Method based on Process Profiling. In: Proceedings of the 2002 Symposium on Applications and the Internet, SAINT 2002 (2002)","DOI":"10.1109\/SAINT.2002.994455"},{"key":"111_CR7","unstructured":"Liao, L., Vemuri, V.R.: Use of Text Categorization Techniques for Intrusion Detection. In: Proceedings of the 11th USENIX Security Symposium (2002)"},{"key":"111_CR8","doi-asserted-by":"crossref","unstructured":"Eskin, E., Lee, W., Stolfo, S.J.: Modeling System Calls for Intrusion Detection with Dynamic Window Sizes. In: Proceedings of DISCEXII (June 2001)","DOI":"10.1109\/DISCEX.2001.932213"},{"key":"111_CR9","doi-asserted-by":"crossref","unstructured":"Warrender, C., Forrest, S., Pearlmutter, B.: Detecting intrusions using system calls: Alternative data models. In: Proceedings IEEE Symposium on Security and Privacy, pp. 133\u2013145 (1999)","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"111_CR10","unstructured":"Sekar, R., Bendre, M., Dhurjati, D., Bollineni, P.: A Fast Automation-Based Method for Detecting Anomalous Program Behaviors. In: IEEE Symposium on Security and Privacy (2001)"},{"key":"111_CR11","unstructured":"Tinnagonsutibout, C., Watanapongse, P.: A Novel Approach to Process-based Intrusion Detection System Using Read-sequence Finite State Automata with Inbound Byte Profiler. In: ICEP 2003 (January 2003)"},{"key":"111_CR12","doi-asserted-by":"crossref","unstructured":"Ko, C.: Logic Induction of Valid Behavior Specifications for Intrusion Detection. In: IEEE Symposium on Security and Privacy, Berkeley, California (2000)","DOI":"10.1109\/SECPRI.2000.848452"},{"key":"111_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1007\/3-540-39945-3_8","volume-title":"Recent Advances in Intrusion Detection","author":"A. Wepsi","year":"2000","unstructured":"Wepsi, A., Dacier, M., Debar, H.: Intrusion Detection Using Variable-Length Audit Trail Patterns. In: Debar, H., M\u00e9, L., Wu, S.F. (eds.) RAID 2000. LNCS, vol.\u00a01907, pp. 110\u2013129. Springer, Heidelberg (2000)"},{"key":"111_CR14","doi-asserted-by":"crossref","unstructured":"Wagner, D., Dean, D.: Intrusion Detection via Static Analysis. In: IEEE Symposium on Security and Privacy, Oakland, CA (2001)","DOI":"10.1109\/SECPRI.2001.924296"}],"container-title":["Lecture Notes in Computer Science","Networking - ICN 2005"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-31957-3_111.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T04:31:11Z","timestamp":1605760271000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-31957-3_111"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005]]},"ISBN":["9783540253389","9783540319573"],"references-count":14,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-31957-3_111","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2005]]}}}