{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T14:34:04Z","timestamp":1725460444806},"publisher-location":"Berlin, Heidelberg","reference-count":25,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642380327"},{"type":"electronic","value":"9783642380334"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-38033-4_21","type":"book-chapter","created":{"date-parts":[[2013,5,7]],"date-time":"2013-05-07T00:51:00Z","timestamp":1367887860000},"page":"295-308","source":"Crossref","is-referenced-by-count":0,"title":["VulLocator: Automatically Locating Vulnerable Code in Binary Programs"],"prefix":"10.1007","author":[{"given":"Yingjun","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kai","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yifeng","family":"Lian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"21_CR1","unstructured":"CNN: Cost of \u2018code red\u2019 rising (2001), http:\/\/articles.cnn.com\/2001-08-08\/tech\/code.red.II_1_russ-cooper-code-red-ii-internal-networks?_s=PM:TECH"},{"key":"21_CR2","doi-asserted-by":"crossref","unstructured":"Lin, Z., Jiang, X., Xu, D., Mao, B., Xie, L.: Autopag: towards automated software patch generation with source code root cause identification and repair. In: Proceedings of the 2nd ACM Symposium on Information, Computer and Communications Security, pp. 329\u2013340. ACM (2007)","DOI":"10.1145\/1229285.1267001"},{"key":"21_CR3","doi-asserted-by":"crossref","unstructured":"Chen, K., Lian, Y., Zhang, Y.: Automatically generating patch in binary programs using attribute-based taint analysis. Information and Communications Security, 367\u2013382 (2010)","DOI":"10.1007\/978-3-642-17650-0_26"},{"key":"21_CR4","doi-asserted-by":"crossref","unstructured":"Perkins, J., et al.: Automatically patching errors in deployed software. In: Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles, pp. 87\u2013102. ACM (2009)","DOI":"10.1145\/1629575.1629585"},{"key":"21_CR5","doi-asserted-by":"crossref","unstructured":"Weimer, W., Nguyen, T., Le Goues, C., Forrest, S.: Automatically finding patches using genetic programming. In: Proceedings of the 31st International Conference on Software Engineering, pp. 364\u2013374. IEEE Computer Society (2009)","DOI":"10.1109\/ICSE.2009.5070536"},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Johnson, N., Caballero, J., Chen, K., McCamant, S., Poosankam, P., Reynaud, D., Song, D.: Differential slicing: Identifying causal execution differences for security applications. In: 2011 IEEE Symposium on Security and Privacy (SP), pp. 347\u2013362. IEEE (2011)","DOI":"10.1109\/SP.2011.41"},{"key":"21_CR7","doi-asserted-by":"crossref","unstructured":"Forrest, S., Nguyen, T., Weimer, W., Le Goues, C.: A genetic programming approach to automated software repair. In: Proceedings of the 11th Annual Conference on Genetic and Evolutionary Computation, pp. 947\u2013954. ACM (2009)","DOI":"10.1145\/1569901.1570031"},{"key":"21_CR8","doi-asserted-by":"crossref","unstructured":"Nguyen, T., Weimer, W., Le Goues, C., Forrest, S.: Using execution paths to evolve software patches. In: Proceedings of the IEEE International Conference on Software Testing, Verification, and Validation Workshops, pp. 152\u2013153. IEEE Computer Society (2009)","DOI":"10.1109\/ICSTW.2009.35"},{"key":"21_CR9","unstructured":"Kranakis, E., Haroutunian, E., Shahbazian, E.: The case for self-healing software. Aspects of Network and Information Security\u00a047 (2008)"},{"issue":"6","key":"21_CR10","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MSP.2005.144","volume":"3","author":"S. Sidiroglou","year":"2005","unstructured":"Sidiroglou, S., Keromytis, A.: Countering network worms through automatic patch generation. IEEE Security & Privacy\u00a03(6), 41\u201349 (2005)","journal-title":"IEEE Security & Privacy"},{"key":"21_CR11","doi-asserted-by":"crossref","unstructured":"Chilimbi, T., Liblit, B., Mehra, K., Nori, A., Vaswani, K.: Holmes: Effective statistical debugging via efficient path profiling. In: Proceedings of the IEEE 31st International Conference on Software Engineering, pp. 34\u201344. IEEE Computer Society (2009)","DOI":"10.1109\/ICSE.2009.5070506"},{"issue":"3","key":"21_CR12","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1145\/1272998.1273010","volume":"41","author":"J. Tucek","year":"2007","unstructured":"Tucek, J., Newsome, J., Lu, S., Huang, C., Xanthos, S., Brumley, D., Zhou, Y., Song, D.: Sweeper: A lightweight end-to-end system for defending against fast worms. ACM SIGOPS Operating Systems Review\u00a041(3), 128 (2007)","journal-title":"ACM SIGOPS Operating Systems Review"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Smirnov, A., Chiueh, T.: Automatic patch generation for buffer overflow attacks. In: The Third International Symposium on Information Assurance and Security, pp. 165\u2013170 (2007)","DOI":"10.1109\/ISIAS.2007.4299769"},{"key":"21_CR14","doi-asserted-by":"crossref","unstructured":"Weiser, M.: Program slicing. IEEE Transaction on Software Engineering, 352\u2013357 (1984)","DOI":"10.1109\/TSE.1984.5010248"},{"issue":"3","key":"21_CR15","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1145\/24039.24041","volume":"9","author":"J. Ferrante","year":"1987","unstructured":"Ferrante, J., Ottenstein, K.J., Warren, J.D.: The program dependence graph and its use in optimization. ACM Transactions on Programming Languages and Systems (TOPLAS)\u00a09(3), 319\u2013349 (1987)","journal-title":"ACM Transactions on Programming Languages and Systems (TOPLAS)"},{"key":"21_CR16","unstructured":"Rinard, M., Cadar, C., Dumitran, D., Roy, D., Leu, T., Beebee Jr., W.: Enhancing server availability and security through failure-oblivious computing. In: Proceedings of the 6th Conference on Symposium on Opearting Systems Design & Implementation, vol.\u00a06, p. 21. USENIX Association (2004)"},{"key":"21_CR17","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Proceedings of the 12th Annual Network and Distributed System Security Symposium (2005)"},{"key":"21_CR18","unstructured":"Newsome, J., Brumley, D., Song, D.: Vulnerability-specific execution filtering for exploit prevention on commodity software. In: Proceedings of the 13th Symposium on Network and Distributed System Security (NDSS) (2006)"},{"key":"21_CR19","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1145\/1102120.1102152","volume-title":"Proceedings of the 12th ACM Conference on Computer and Communications Security","author":"J. Crandall","year":"2005","unstructured":"Crandall, J., Su, Z., Wu, S., Chong, F.: On deriving unknown vulnerabilities from zero-day polymorphic and metamorphic worm exploits. In: Proceedings of the 12th ACM Conference on Computer and Communications Security, pp. 235\u2013248. ACM, New York (2005)"},{"key":"21_CR20","doi-asserted-by":"crossref","unstructured":"Costa, M., Crowcroft, J., Castro, M., Rowstron, A., Zhou, L., Zhang, L., Barham, P.: Vigilante: end-to-end containment of internet worms. In: Proceedings of the Twentieth ACM Symposium on Operating Systems Principles, pp. 133\u2013147 (2005)","DOI":"10.1145\/1095809.1095824"},{"key":"21_CR21","doi-asserted-by":"crossref","unstructured":"Portokalidis, G., Slowinska, A., Bos, H.: Argos: an emulator for fingerprinting zero-day attacks for advertised honeypots with automatic signature generation. In: Proceedings of the 2006 EuroSys Conference, pp. 15\u201327 (2006)","DOI":"10.1145\/1217935.1217938"},{"key":"21_CR22","unstructured":"Baratloo, A., Singh, N., Tsai, T.: Transparent run-time defense against stack smashing attacks. In: Proceedings of the USENIX Annual Technical Conference, pp. 251\u2013262 (2000)"},{"key":"21_CR23","doi-asserted-by":"crossref","unstructured":"Kc, G., Keromytis, A., Prevelakis, V.: Countering code-injection attacks with instruction-set randomization. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, pp. 272\u2013280. ACM (2003)","DOI":"10.1145\/948109.948146"},{"key":"21_CR24","doi-asserted-by":"crossref","unstructured":"Luk, C., et al.: Pin: building customized program analysis tools with dynamic instrumentation. In: Proceedings of the 2005 ACM SIGPLAN Conference on Programming Language Design and Implementation, pp. 190\u2013200. ACM (2005)","DOI":"10.1145\/1065010.1065034"},{"key":"21_CR25","unstructured":"Exploit DB: Exploit database (2012), http:\/\/www.exploit-db.com"}],"container-title":["Lecture Notes in Computer Science","Information Security Practice and Experience"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-38033-4_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T14:36:14Z","timestamp":1688222174000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-38033-4_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642380327","9783642380334"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-38033-4_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}