{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T13:35:51Z","timestamp":1761917751177},"publisher-location":"Berlin, Heidelberg","reference-count":28,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642054365"},{"type":"electronic","value":"9783642054372"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-05437-2_5","type":"book-chapter","created":{"date-parts":[[2009,10,31]],"date-time":"2009-10-31T10:32:57Z","timestamp":1256985177000},"page":"52-62","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Mitigating Drive-By Download Attacks: Challenges and Open Problems"],"prefix":"10.1007","author":[{"given":"Manuel","family":"Egele","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,11,2]]},"reference":[{"key":"5_CR1","unstructured":"Flash player update available to address security vulnerabilities, \n\nhttp:\/\/www.adobe.com\/support\/security\/bulletins\/apsb09-01.html"},{"key":"5_CR2","unstructured":"Barwinski, M., Irvine, C., Levin, T.: Empirical study of drive-by-download spyware (2006), \n\nhttp:\/\/cisr.nps.navy.mil\/downloads\/06paper_spyware_OnlinePDF.pdf"},{"key":"5_CR3","unstructured":"Superbuddy activex control vulnerability (2006), \n\nhttp:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2006-5820"},{"key":"5_CR4","unstructured":"Buffer overflow in apple quicktime 7.1.3 (2007), \n\nhttp:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-0015"},{"key":"5_CR5","unstructured":"Dan Goodin (The Register). SQL injection taints BusinessWeek.com. (2008), \n\nhttp:\/\/www.theregister.co.uk\/2008\/09\/16\/businessweek_hacked\/\n\n\n (Last accessed, December 2008)"},{"key":"5_CR6","unstructured":"Daniel, M., Honoroff, J., Miller, C.: Engineering Heap Overflow Exploits with JavaScript. In: 2nd USENIX Workshop on Offensive Technologies, WOOT 2008 (2008)"},{"key":"5_CR7","unstructured":"Egele, M., Kirda, E., Kruegel, C.: Defending browsers against drive-by downloads: Mitigating heap-spraying code injection attacks. In: Detection of Intrusions and Malware, and Vulnerability Assessment, 6th International Conference, DIMVA 2009 (to appear, 2009)"},{"key":"5_CR8","unstructured":"Egele, M., Kruegel, C., Kirda, E., Yin, H., Song, D.X.: Dynamic spyware analysis. In: USENIX Annual Technical Conference, pp. 233\u2013246 (2007)"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/11790754_2","volume-title":"Detection of Intrusions and Malware & Vulnerability Assessment","author":"M. Egele","year":"2006","unstructured":"Egele, M., Szydlowski, M., Kirda, E., Kruegel, C.: Using static program analysis to aid intrusion detection. In: B\u00fcschkes, R., Laskov, P. (eds.) DIMVA 2006. LNCS, vol.\u00a04064, pp. 17\u201336. Springer, Heidelberg (2006)"},{"key":"5_CR10","unstructured":"Frei, S., D\u00fcbendorfer, T., Ollmann, G., May, M.: Understanding the web browser threat. Technical Report 288, ETH Zurich (June 2008)"},{"key":"5_CR11","unstructured":"Leyden, J.: Drive-by download attack compromises 500k websites (2009), \n\nhttp:\/\/www.channelregister.co.uk\/2008\/05\/13\/zlob_trojan_forum_compromise_attack\/\n\n\n (Last accessed, February 2009)"},{"key":"5_CR12","unstructured":"Kirda, E., Kruegel, C., Banks, G., Vigna, G., Kemmerer, R.A.: Behavior-based spyware detection. In: USENIX Security (2006)"},{"key":"5_CR13","unstructured":"Exploit Prevention Labs: LinkScanner, \n\nhttp:\/\/linkscanner.explabs.com\/linkscanner\/default.aspx"},{"key":"5_CR14","unstructured":"Microsoft Office Snapshot Viewer ActiveX vulnerability (2008), \n\nhttp:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2008-2463\n\n\n (Last accessed, March 2009)"},{"key":"5_CR15","unstructured":"Microsoft Corporation. Microsoft Security Bulletin MS06-014 - Vulnerability in the Microsoft Data Access Components (MDAC) Function Could Allow Code Execution (2006), \n\nhttp:\/\/www.microsoft.com\/technet\/security\/Bulletin\/MS06-014.mspx\n\n\n (Last accessed, December 2008)"},{"key":"5_CR16","unstructured":"Moshchuk, A., Bragin, T., Gribble, S.D., Levy, H.M.: A crawler-based study of spyware in the web. In: Proceedings of the Network and Distributed System Security Symposium, NDSS 2006, San Diego, California, USA (2006)"},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"Paxson, V.: Bro: A System for Detecting Network Intruders in Real-Time. Computer Networks\u00a031 (1999)","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Emulation-based detection of non-self-contained polymorphic shellcode. In: Recent Advances in Intrusion Detection, 10th International Symposium (RAID), pp. 87\u2013106 (2007)","DOI":"10.1007\/978-3-540-74320-0_5"},{"key":"5_CR19","unstructured":"Polychronakis, M., Provos, N.: Ghost turns zombie: Exploring the life cycle of web-based malware. In: First USENIX Workshop on Large-Scale Exploits and Emergent Threats (2008)"},{"key":"5_CR20","unstructured":"Provos, N., Mavrommatis, P., Rajab, M.A., Monrose, F.: All your iframes point to us. In: USENIX Security Symposium (2008)"},{"key":"5_CR21","unstructured":"Provos, N., McNamee, D., Mavrommatis, P., Wang, K., Modadugu, N.: The Ghost In The Browser Analysis of Web-based Malware. In: First Workshop on Hot Topics in Understanding Botnets, HotBots 2007 (2007)"},{"key":"5_CR22","unstructured":"Robertson, W.K., Vigna, G., Kr\u00fcgel, C., Kemmerer, R.A.: Using generalization and characterization techniques in the anomaly-based detection of web attacks. In: Proceedings of the Network and Distributed System Security Symposium, NDSS 2006, San Diego, California, USA (2006)"},{"key":"5_CR23","unstructured":"Roesch, M.: Snort - Lightweight Intrusion Detection for Networks. In: 13th Systems Administration Conference, LISA (1999)"},{"key":"5_CR24","unstructured":"Sina dloader class activex control \u2019donwloadandinstall\u2019 method arbitrary file download vulnerability, \n\nhttp:\/\/www.securityfocus.com\/bid\/30223\/info"},{"key":"5_CR25","unstructured":"Sotirov, A.: Heap Feng Shui in JavaScript (2008), \n\nhttp:\/\/www.phreedom.org\/research\/heap-feng-shui\/heap-feng-shui.html\n\n\n (Last accessed, November 2008)"},{"key":"5_CR26","unstructured":"Wang, Y.-M., Beck, D., Jiang, X., Roussev, R., Verbowski, C., Chen, S., King, S.T.: Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities. In: NDSS (2006)"},{"issue":"2","key":"5_CR27","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C. Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using cwsandbox. IEEE Security and Privacy\u00a05(2), 32\u201339 (2007)","journal-title":"IEEE Security and Privacy"},{"key":"5_CR28","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D.X., Egele, M., Kruegel, C., Kirda, E.: Panorama: capturing system-wide information flow for malware detection and analysis. In: ACM Conference on Computer and Communications Security, pp. 116\u2013127 (2007)","DOI":"10.1145\/1315245.1315261"}],"container-title":["IFIP Advances in Information and Communication Technology","iNetSec 2009 \u2013 Open Research Problems in Network Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-05437-2_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,3,21]],"date-time":"2020-03-21T15:03:30Z","timestamp":1584803010000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-05437-2_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642054365","9783642054372"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-05437-2_5","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2009]]},"assertion":[{"value":"2 November 2009","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}