{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T06:09:25Z","timestamp":1725516565404},"publisher-location":"Berlin, Heidelberg","reference-count":36,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540699712"},{"type":"electronic","value":"9783540705000"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-70500-0_28","type":"book-chapter","created":{"date-parts":[[2008,8,12]],"date-time":"2008-08-12T16:07:43Z","timestamp":1218557263000},"page":"376-390","source":"Crossref","is-referenced-by-count":3,"title":["FormatShield: A Binary Rewriting Defense against Format String Attacks"],"prefix":"10.1007","author":[{"given":"Pankaj","family":"Kohli","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bezawada","family":"Bruhadeshwar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"28_CR1","unstructured":"PaX. Published on World-Wide Web (2001), http:\/\/pax.grsecurity.net"},{"key":"28_CR2","unstructured":"PaX Team. PaX address space layout randomization (ASLR), http:\/\/pax.grsecurity.net\/docs\/aslr.txt"},{"key":"28_CR3","unstructured":"CVE - Common Vulnerabilities and Exposures, http:\/\/www.cve.mitre.org"},{"key":"28_CR4","unstructured":"Kaempf, M.: Splitvt Format String Vulnerability, http:\/\/www.securityfocus.com\/bid\/2210\/"},{"key":"28_CR5","unstructured":"CWE - Vulnerability Type Distributions in CVE, http:\/\/cve.mitre.org\/docs\/vuln-trends\/index.html"},{"key":"28_CR6","unstructured":"tf8.: Wu-Ftpd Remote Format String Stack Overwrite Vulnerability, http:\/\/www.securityfocus.com\/bid\/1387"},{"key":"28_CR7","unstructured":"De Kok, A.: PScan: A limited problem scanner for C source files, http:\/\/www.striker.ottawa.on.ca\/~aland\/pscan\/"},{"key":"28_CR8","unstructured":"Shankar, U., Talwar, K., Foster, J.S., Wagner, D.: Detecting format string vulnerabilities with type qualifiers. In: Proceedings of the 10th USENIX Security Symposium (Security 2001), Washington, DC (2001)"},{"key":"28_CR9","unstructured":"Jacobowitz, D.: Multiple Linux Vendor rpc.statd Remote Format String Vulnerability, http:\/\/www.securityfocus.com\/bid\/1480"},{"key":"28_CR10","unstructured":"Robbins, T.: Libformat, http:\/\/www.wiretapped.net\/~fyre\/software\/libformat.html"},{"key":"28_CR11","unstructured":"Tool Interface Standard (TIS) Committee: Executable and linking format (ELF) specification, version 1.2 (1995)"},{"key":"28_CR12","unstructured":"CERT Incident Note IN-2000-10, Widespread Exploitation of rpc.statd and wu-ftpd Vulnerabilities (September 15, 2000)"},{"key":"28_CR13","unstructured":"Tsai, T., Singh, N.: Libsafe 2.0: Detection of Format String Vulnerability Exploits, http:\/\/www.research.avayalabs.com\/project\/libsafe\/doc\/whitepaper-20.pdf"},{"key":"28_CR14","unstructured":"Pelat, G.: PFinger Format String Vulnerability, http:\/\/www.securityfocus.com\/bid\/3725"},{"key":"28_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-540-73545-8","volume-title":"Advances in Smalltalk","author":"Z. Lin","year":"2007","unstructured":"Lin, Z., Xia, N., Li, G., Mao, B., Xie, L.: Transparent Run-Time Prevention of Format-String Attacks Via Dynamic Taint and Flexible Validation. In: De Meuter, W. (ed.) ISC 2006. LNCS, vol.\u00a04406, Springer, Heidelberg (2007)"},{"key":"28_CR16","unstructured":"NSI Rwhoisd Remote Format String Vulnerability, http:\/\/www.securityfocus.com\/bid\/3474"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Shacham, H., Page, M., Pfaff, B., Goh, E.-J., Modadugu, N., Boneh, D.: On the effectiveness of address-space randomization. In: Proceedings of the 11th ACM conference on Computer and communications security, Washington DC, USA, October 25-29 (2004)","DOI":"10.1145\/1030083.1030124"},{"key":"28_CR18","unstructured":"Cowan, C., Barringer, M., Beattie, S., Kroah-Hartman, G.: FormatGuard: Automatic protection from printf format string vulnerabilities. In: Proceedings of the 10th USENIX Security Symposium (Security 2001), Washington, DC (2001)"},{"key":"28_CR19","doi-asserted-by":"crossref","unstructured":"Ringenburg, M., Grossman, D.: Preventing Format-String Attacks via Automatic and Efficient Dynamic Checking. In: Proceedings of the 12th ACM Conference on Computer and Communications Security (CCS 2005), Alexandria, Virginia (2005)","DOI":"10.1145\/1102120.1102166"},{"key":"28_CR20","unstructured":"Chen, S., Xu, J., Sezer, E.C., Gauriar, P., Iyer, R.K.: Non-control-data attacks are realistic threats. In: Proceedings of the 14th conference on USENIX Security Symposium, Baltimore, MD (2005)"},{"key":"28_CR21","unstructured":"Bhatkar, S., DuVarney, D.C., Sekar, R.: Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In: USENIX Security Symposium, Washington, DC (August 2003)"},{"key":"28_CR22","unstructured":"Avijit, K., Gupta, P., Gupta, D.: TIED, LibsafePlus: Tools for Runtime Buffer Overflow Protection. In: Proceedings of the 13th USENIX Security Symposium, San Diego, CA (2004)"},{"key":"28_CR23","unstructured":"Bhatkar, S., Sekar, R., DuVarney, D.C.: Efficient Techniques for Comprehensive Protection from Memory Error Exploits. In: Proceedings of the 14th USENIX Security Symposium, July 31-August 05, p. 17 (2005)"},{"key":"28_CR24","doi-asserted-by":"crossref","unstructured":"Barrantes, E.G., Ackley, D.H., Palmer, T.S., Stefanovic, D., Zovi, D.D.: Randomized Instruction Set Emulation to Disrupt Binary Code Injection Attacks. In: Proceedings of the 10th ACM conference on Computer and communications security, Washington D.C, USA (October 27-30, 2003)","DOI":"10.1145\/948109.948147"},{"key":"28_CR25","doi-asserted-by":"crossref","unstructured":"You, J.H., Seo, S.C., Kim, Y.D., Choi, J.Y., Lee, S.J., Kim, B.K.: Kimchi: A Binary Rewriting Defense Against Format String Attacks. In: WISA 2005 (2005)","DOI":"10.1007\/11604938_14"},{"key":"28_CR26","unstructured":"Cowan, C., Pu, C., Maier, D., Hinton, H., Walpole, J., Bakke, P., Beattie, S., Grier, A., Wagle, P., Zhang, Q.: Stackguard: Automatic adaptive detection and prevention of buffer-overflow attacks. In: Proceedings of the 7th USENIX Security Symposium, San Antonio, TX, pp. 63\u201378 (January 1998)"},{"key":"28_CR27","doi-asserted-by":"crossref","unstructured":"Kc, G.S., Keromytis, A.D., Prevelakis, V.: Countering Code-Injection Attacks with Instruction-Set Randomization. In: Proceedings of the 10th ACM conference on Computer and Communications Security, Washington D.C, USA, October 27-30 (2003)","DOI":"10.1145\/948109.948146"},{"key":"28_CR28","unstructured":"@stake, Inc. tcpflow 0.2.0 format string vulnerability (August 2003), http:\/\/www.securityfocus.com\/advisories\/5686"},{"key":"28_CR29","unstructured":"bind: xlockmore User Supplied Format String Vulnerability, http:\/\/www.securityfocus.com\/bid\/1585"},{"key":"28_CR30","doi-asserted-by":"crossref","unstructured":"Li, W., Chiueh, T.-c.: Automated Format String Attack Prevention for Win32\/X86 Binaries. In: Proceedings of 23rd Annual Computer Security Applications Conference, Florida (December 2007)","DOI":"10.1109\/ACSAC.2007.23"},{"key":"28_CR31","unstructured":"Xiao, Z.: An Automated Approach to Software Reliability and Security. Invited Talk, Department of Computer Science. University of California at Berkeley (2003)"},{"key":"28_CR32","unstructured":"Durden, T.: Bypassing PaX ASLR protection. Phrack Magazine\u00a059(9) (June 2002), http:\/\/www.phrack.org\/phrack\/59\/p59-0x09"},{"key":"28_CR33","unstructured":"Sovarel, N., Evans, D., Paul, N.: Where\u2019s the FEEB? The Effectiveness of Instruction Set Randomization. In: 14th USENIX Security Symposium (August 2005)"},{"key":"28_CR34","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1109\/RELDIS.2003.1238076","volume-title":"Proc. 22nd Symp. on Reliable Distributed Systems \u2013SRDS 2003","author":"J. Xu","year":"2003","unstructured":"Xu, J., Kalbarczyk, Z., Iyer, R.: Transparent Runtime Randomization for Security. In: Fantechi, A. (ed.) Proc. 22nd Symp. on Reliable Distributed Systems \u2013SRDS 2003, pp. 260\u2013269. IEEE Computer Society, Los Alamitos (2003)"},{"key":"28_CR35","unstructured":"Hunt, G., Brubacher, D.: Detours: Binary interception of Win32 functions. In: Proceedings of the 3rd USENIX Windows NT Symposium, Seattle, WA, pp. 135\u2013143 (1999)"},{"key":"28_CR36","unstructured":"Lemos, R.: Internet worm squirms into Linux servers. Special to CNET News.com (January 17, 2001), http:\/\/news.cnet.com\/news\/0-1003-200-4508359.html"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-70500-0_28.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T05:06:43Z","timestamp":1605762403000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-70500-0_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540699712","9783540705000"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-70500-0_28","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[]}}