{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T17:15:24Z","timestamp":1778346924717,"version":"3.51.4"},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642029172","type":"print"},{"value":"9783642029189","type":"electronic"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-02918-9_6","type":"book-chapter","created":{"date-parts":[[2009,6,26]],"date-time":"2009-06-26T14:15:11Z","timestamp":1246025711000},"page":"88-106","source":"Crossref","is-referenced-by-count":95,"title":["Defending Browsers against Drive-by Downloads: Mitigating Heap-Spraying Code Injection Attacks"],"prefix":"10.1007","author":[{"given":"Manuel","family":"Egele","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peter","family":"Wurzinger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","unstructured":"Bayer, U.: Anubis - analyzing unknown binaries, \n                    \n                      http:\/\/www.anubis.iseclab.org"},{"key":"6_CR2","unstructured":"Capture-HPC Client Honeypot \/ Honeyclient (2009), \n                    \n                      https:\/\/projects.honeynet.org\/capture-hpc"},{"key":"6_CR3","unstructured":"Chenette, S.: ToorConX - the ultimate deobfuscator (2008), \n                    \n                      http:\/\/www.toorcon.org\/tcx\/26_Chenette.pdf"},{"key":"6_CR4","unstructured":"Superbuddy activex control vulnerability (2006), \n                    \n                      http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2006-5820"},{"key":"6_CR5","doi-asserted-by":"crossref","unstructured":"Dagon, D., Gu, G., Lee, C., Lee, W.: A Taxonomy of Botnet Structures. In: Annual Computer Security Applications Conference, ACSAC (2007)","DOI":"10.1109\/ACSAC.2007.44"},{"key":"6_CR6","unstructured":"Dan Goodin (The Register). SQL injection taints BusinessWeek.com, \n                    \n                      http:\/\/www.theregister.co.uk\/2008\/09\/16\/businessweek_hacked\/\n                    \n                    \n                   (last accessed, December 2008)"},{"key":"6_CR7","unstructured":"Daniel, M., Honoroff, J., Miller, C.: Engineering Heap Overflow Exploits with JavaScript. In: 2nd USENIX Workshop on Offensive Technologies, WOOT 2008 (2008)"},{"key":"6_CR8","unstructured":"Dormann, W., Plakosh, D.: Vulnerability detection in activex controls through automated fuzz testing (2008), \n                    \n                      http:\/\/www.cert.org\/archive\/pdf\/dranzer.pdf"},{"key":"6_CR9","unstructured":"Egele, M., Kruegel, C., Kirda, E., Yin, H., Song, D.X.: Dynamic spyware analysis. In: USENIX Annual Technical Conference, pp. 233\u2013246 (2007)"},{"key":"6_CR10","unstructured":"Feinstein, B., Peck, D.: Caffeine monkey: Automated collection, detection and analysis of malicious javascript (2006), \n                    \n                      http:\/\/www.dc414.org\/download\/confs\/defcon15\/Speakers\/Feinstein_and%20_Peck\/Whitepaper\/dc-15-feinstein_and_peck-WP.pdf"},{"key":"6_CR11","unstructured":"M. Foundation. SpiderMonkey (JavaScript-C) Engine, \n                    \n                      http:\/\/www.mozilla.org\/js\/spidermonkey\/"},{"key":"6_CR12","unstructured":"Frei, S., D\u00fcbendorfer, T., Ollmann, G., May, M.: Understanding the web browser threat. Technical Report 288, ETH Zurich, 06 2008 (2008)"},{"key":"6_CR13","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: 10th Annual Network and Distributed System Security Symposium, NDSS 2003 (2003)"},{"key":"6_CR14","unstructured":"Gregg, B.: fetch application data from snoop or tcpdump logs, \n                    \n                      http:\/\/chaosreader.sourceforge.net\/"},{"key":"6_CR15","doi-asserted-by":"crossref","unstructured":"Hallaraker, O., Vigna, G.: Detecting malicious javascript code in mozilla. In: 10th International Conference on Engineering of Complex Computer Systems (ICECCS 2005), pp. 85\u201394 (2005)","DOI":"10.1109\/ICECCS.2005.35"},{"key":"6_CR16","unstructured":"Leyden, J.: Drive-by download attack compromises 500k websites, \n                    \n                      http:\/\/www.channelregister.co.uk\/2008\/05\/13\/zlob_trojan_forum_compromise_attack\/\n                    \n                    \n                   (last accessed, February 2009)"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Kanich, C., Kreibich, C., Levchenko, K., Enright, B., Voelker, G.M., Paxson, V., Savage, S.: Spamalytics: An empirical analysis of spam marketing conversion. In: ACM Conference on Computer and Communications Security (2008)","DOI":"10.1145\/1455770.1455774"},{"key":"6_CR18","unstructured":"Kirda, E., Kruegel, C., Banks, G., Vigna, G., Kemmerer, R.A.: Behavior-based spyware detection. In: USENIX Security (2006)"},{"key":"6_CR19","unstructured":"x86 shellcode detection and emulation, \n                    \n                      http:\/\/libemu.mwcollect.org\/"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Moore, D., Voelker, G., Savage, S.: Inferring Internet Denial of Service Activity. In: Usenix Security Symposium (2001)","DOI":"10.21236\/ADA400003"},{"key":"6_CR21","unstructured":"M.D. Network. ActiveX Controls, \n                    \n                      http:\/\/msdn.microsoft.com\/en-us\/library\/aa751968.aspx"},{"key":"6_CR22","unstructured":"M.D. Network. JScript Windows Script Technologies, \n                    \n                      http:\/\/msdn.microsoft.com\/en-us\/library\/hbxc2t98.aspx"},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Paxson, V.: Bro: A System for Detecting Network Intruders in Real-Time. Computer Networks\u00a031 (1999)","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"6_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1007\/11790754_4","volume-title":"Detection of Intrusions and Malware & Vulnerability Assessment","author":"M. Polychronakis","year":"2006","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Network\u2013level polymorphic shellcode detection using emulation. In: B\u00fcschkes, R., Laskov, P. (eds.) DIMVA 2006. LNCS, vol.\u00a04064, pp. 54\u201373. Springer, Heidelberg (2006)"},{"key":"6_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-3-540-74320-0_5","volume-title":"Recent Advances in Intrusion Detection","author":"M. Polychronakis","year":"2007","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Emulation-based detection of non-self-contained polymorphic shellcode. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol.\u00a04637, pp. 87\u2013106. Springer, Heidelberg (2007)"},{"issue":"4","key":"6_CR26","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/s11416-006-0031-z","volume":"2","author":"M. Polychronakis","year":"2007","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Network-level polymorphic shellcode detection using emulation. Journal in Computer Virology\u00a02(4), 257\u2013274 (2007)","journal-title":"Journal in Computer Virology"},{"key":"6_CR27","unstructured":"Polychronakis, M., Provos, N.: Ghost turns zombie: Exploring the life cycle of web-based malware. In: First USENIX Workshop on Large-Scale Exploits and Emergent Threats (2008)"},{"key":"6_CR28","unstructured":"Provos, N., Mavrommatis, P., Rajab, M.A., Monrose, F.: All your iframes point to us. In: USENIX Security Symposium (2008)"},{"key":"6_CR29","unstructured":"Provos, N., McNamee, D., Mavrommatis, P., Wang, K., Modadugu, N.: The Ghost In The Browser Analysis of Web-based Malware. In: First Workshop on Hot Topics in Understanding Botnets, HotBots 2007 (2007)"},{"key":"6_CR30","unstructured":"Roesch, M.: Snort - Lightweight Intrusion Detection for Networks. In: 13th Systems Administration Conference, LISA (1999)"},{"key":"6_CR31","unstructured":"Secunia PSI study: 28% of all detected applications are insecure (2007), \n                    \n                      http:\/\/secunia.com\/blog\/11\/"},{"key":"6_CR32","unstructured":"Sotirov, A.: Heap Feng Shui in JavaScript, \n                    \n                      http:\/\/www.phreedom.org\/research\/heap-feng-shui\/heap-feng-shui.html\n                    \n                    \n                   (last accessed, November 2008)"},{"key":"6_CR33","unstructured":"Spamcop - the premier service for reporting spam, \n                    \n                      http:\/\/www.spamcop.net\/"},{"key":"6_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1007\/3-540-36084-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"T. T\u00f3th","year":"2002","unstructured":"T\u00f3th, T., Kr\u00fcgel, C.: Accurate buffer overflow detection via abstract payload execution. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 274\u2013291. Springer, Heidelberg (2002)"},{"key":"6_CR35","unstructured":"Vogt, P., Nentwich, F., Jovanovic, N., Kruegel, C., Kirda, E., Vigna, G.: Cross site scripting prevention with dynamic data tainting and static analysis. In: 14th Annual Network and Distributed System Security Symposium, NDSS 2007 (2007)"},{"issue":"2","key":"6_CR36","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C. Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using cwsandbox. IEEE Security and Privacy\u00a05(2), 32\u201339 (2007)","journal-title":"IEEE Security and Privacy"},{"key":"6_CR37","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D.X., Egele, M., Kruegel, C., Kirda, E.: Panorama: capturing system-wide information flow for malware detection and analysis. In: ACM Conference on Computer and Communications Security, pp. 116\u2013127 (2007)","DOI":"10.1145\/1315245.1315261"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-02918-9_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,3,9]],"date-time":"2019-03-09T01:07:11Z","timestamp":1552093631000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-02918-9_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642029172","9783642029189"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-02918-9_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009]]}}}