{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T14:57:46Z","timestamp":1773154666307,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":25,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642333378","type":"print"},{"value":"9783642333385","type":"electronic"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-33338-5_14","type":"book-chapter","created":{"date-parts":[[2012,9,26]],"date-time":"2012-09-26T01:17:07Z","timestamp":1348622227000},"page":"274-293","source":"Crossref","is-referenced-by-count":11,"title":["FlashDetect: ActionScript 3 Malware Detection"],"prefix":"10.1007","author":[{"given":"Timon","family":"Van Overveldt","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"14_CR1","unstructured":"Adobe: Statistics: PC penetration, \n                      http:\/\/www.adobe.com\/products\/flashplatformruntimes\/statistics.edu.html\n                     (accessed on June 15, 2012)"},{"key":"14_CR2","unstructured":"Blazakis, D.: Interpreter exploitation: Pointer inference and JIT spraying (2010), \n                      http:\/\/www.semantiscope.com\/research\/BHDC2010\/BHDC-2010-Paper.pdf\n                     (accessed on June 15, 2012)"},{"key":"14_CR3","doi-asserted-by":"crossref","unstructured":"Cova, M., Kruegel, C., Vigna, G.: Detection and Analysis of Drive-by-Download Attacks and Malicious JavaScript Code. In: Proceedings of the World Wide Web Conference (WWW), Raleigh, NC (April 2010)","DOI":"10.1145\/1772690.1772720"},{"key":"14_CR4","unstructured":"Curtsinger, C., Livshits, B., Zorn, B., Seifert, C.: Zozzle: Low-overhead mostly static JavaScript malware detection. In: Proceedings of the Usenix Security Symposium (August 2011)"},{"key":"14_CR5","unstructured":"DoSWF.com: DoSWF - Flash encryption, \n                      http:\/\/www.doswf.com\/doswf\n                     (accessed on June 15, 2012)"},{"key":"14_CR6","doi-asserted-by":"publisher","first-page":"363","DOI":"10.1109\/ACSAC.2009.41","volume-title":"Proceedings of the 2009 Annual Computer Security Applications Conference, ACSAC 2009","author":"S. Ford","year":"2009","unstructured":"Ford, S., Cova, M., Kruegel, C., Vigna, G.: Analyzing and detecting malicious flash advertisements. In: Proceedings of the 2009 Annual Computer Security Applications Conference, ACSAC 2009, pp. 363\u2013372. IEEE Computer Society, Washington, DC, USA (2009)"},{"key":"14_CR7","unstructured":"Ikinci, A., Holz, T., Freiling, F.: Monkey-spider: Detecting malicious websites with low-interaction honeyclients. In: Proceedings of Sicherheit, Schutz und Zuverl\u00e4ssigkeit (2008)"},{"key":"14_CR8","unstructured":"JavaScript-Source.com: JavaScript obfuscator, \n                      http:\/\/javascript-source.com\n                     (accessed on June 15, 2012)"},{"key":"14_CR9","unstructured":"Joly, N.: Technical Analysis and Advanced Exploitation of Adobe Flash 0-Day, CVE-2011-0609 (2011), \n                      http:\/\/www.vupen.com\/blog\/20110326.Technical_Analysis_and_Win7_Exploitation_Adobe_Flash_0Day_CVE-2011-0609.php\n                     (accessed on June 15, 2012)"},{"key":"14_CR10","unstructured":"Keizer, G.: Attackers exploit latest Flash bug on large scale, says researcher, \n                      http:\/\/www.computerworld.com\/s\/article\/9217758\/Attackers_exploit_latest_Flash_bug_on_large_scale_says_researcher\n                     (accessed on June 15, 2012)"},{"key":"14_CR11","unstructured":"Kindi: secureSWF, \n                      http:\/\/www.kindi.com\n                     (accessed on June 15, 2012)"},{"key":"14_CR12","doi-asserted-by":"crossref","unstructured":"Kolbitsch, C., Livshits, B., Zorn, B., Seifert, C.: Rozzle: De-cloaking internet malware. In: IEEE Symposium on Security and Privacy (May 2012)","DOI":"10.1109\/SP.2012.48"},{"key":"14_CR13","unstructured":"Li, H.: Understanding and Exploiting Flash ActionScript Vulnerabilities. In: CanSecWest 2011 (2011), \n                      http:\/\/www.fortiguard.com\/sites\/default\/files\/CanSecWest2011_Flash_ActionScript.pdf\n                     (accessed on June 15, 2012)"},{"key":"14_CR14","unstructured":"Liu, B.: Flash mob episode II: Attack of the clones (2009), \n                      http:\/\/blog.fortinet.com\/flash-mob-episode-ii-attack-of-the-clones\/\n                     (accessed on June 15, 2012)"},{"key":"14_CR15","unstructured":"MITRE Corporation: Common Vulnerabilities and Exposures (CVE), \n                      http:\/\/cve.mitre.org\n                     (accessed on June 15, 2012)"},{"key":"14_CR16","first-page":"1","volume-title":"Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, SS 2007","author":"A. Moshchuk","year":"2007","unstructured":"Moshchuk, A., Bragin, T., Deville, D., Gribble, S.D., Levy, H.M.: Spyproxy: execution-based detection of malicious web content. In: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, SS 2007, pp. 3:1\u20133:16. USENIX Association, Berkeley (2007), \n                      http:\/\/dl.acm.org\/citation.cfm?id=1362903.1362906"},{"key":"14_CR17","unstructured":"Moshchuk, E., Bragin, T., Gribble, S.D., Levy, H.M.: A crawler-based study of spyware on the web (2006)"},{"key":"14_CR18","unstructured":"Paget, F.: McAfee Blog: Surrounded by Malicious PDFs, \n                      http:\/\/blogs.mcafee.com\/mcafee-labs\/surrounded-by-malicious-pdfs\n                     (accessed on June 15, 2012)"},{"key":"14_CR19","unstructured":"Alessandro, P., et al.: Lightspark flash player, \n                      http:\/\/lightspark.github.com\n                     (accessed on June 15, 2012)"},{"key":"14_CR20","first-page":"1","volume-title":"Proceedings of the 17th conference on Security Symposium, SS 2008","author":"N. Provos","year":"2008","unstructured":"Provos, N., Mavrommatis, P., Rajab, M.A., Monrose, F.: All your iframes point to us. In: Proceedings of the 17th Conference on Security Symposium, SS 2008, pp. 1\u201315. USENIX Association, Berkeley (2008), \n                      http:\/\/dl.acm.org\/citation.cfm?id=1496711.1496712"},{"key":"14_CR21","unstructured":"Ratanaworabhan, P., Livshits, B., Zorn, B.: Nozzle: A defense against heap-spraying code injection attacks. In: Proceedings of the Usenix Security Symposium (August 2009)"},{"key":"14_CR22","unstructured":"The HoneyNet Project: CaptureHPC, \n                      https:\/\/projects.honeynet.org\/capture-hpc\n                     (accessed on June 15, 2012)"},{"key":"14_CR23","unstructured":"Tung, L.: Flash exploits increase 40 fold in (2011), \n                      http:\/\/www.cso.com.au\/article\/403805\/flash_exploits_increase_40_fold_2011\n                     (accessed on June 15, 2012)"},{"key":"14_CR24","unstructured":"VirusTotal: VirusTotal service, \n                      https:\/\/www.virustotal.com\n                     (accessed on June 15, 2012)"},{"key":"14_CR25","unstructured":"Wang, Y.M., Beck, D., Jiang, X., Roussev, R.: Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities. In: IN NDSS (2006)"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-33338-5_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,9]],"date-time":"2021-08-09T19:07:30Z","timestamp":1628536050000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-642-33338-5_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642333378","9783642333385"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-33338-5_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}