{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T06:10:30Z","timestamp":1761977430139,"version":"build-2065373602"},"publisher-location":"Berlin, Heidelberg","reference-count":57,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642412837"},{"type":"electronic","value":"9783642412844"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-41284-4_3","type":"book-chapter","created":{"date-parts":[[2013,10,22]],"date-time":"2013-10-22T17:35:11Z","timestamp":1382463311000},"page":"41-61","source":"Crossref","is-referenced-by-count":3,"title":["Server-Side Code Injection Attacks: A Historical Perspective"],"prefix":"10.1007","author":[{"given":"Jakob","family":"Fritz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Corrado","family":"Leita","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"3_CR1","unstructured":"Symantec: W32.Stuxnet Dossier version 1.4, http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/w32_stuxnet_dossier.pdf (February 2011) (last downloaded October 2012)"},{"key":"3_CR2","unstructured":"Symantec: W32.Duqu The precursor to the next Stuxnet. (November 2011), http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/w32_duqu_the_precursor_to_the_next_stuxnet_research.pdf (last downloaded October 2012)"},{"key":"3_CR3","doi-asserted-by":"crossref","unstructured":"Dacier, M., Pouget, F., Debar, H.: Honeypots: Practical means to validate malicious fault assumptions. In: Proceedings of the 10th IEEE Pacific Rim International Symposium on Dependable Computing, pp. 383\u2013388. IEEE (2004)","DOI":"10.1109\/PRDC.2004.1276594"},{"key":"3_CR4","doi-asserted-by":"crossref","unstructured":"Cooke, E., Bailey, M., Mao, Z., Watson, D., Jahanian, F., McPherson, D.: Toward understanding distributed blackhole placement. In: Proceedings of the 2004 ACM Workshop on Rapid Malcode, pp. 54\u201364. ACM (2004)","DOI":"10.1145\/1029618.1029627"},{"key":"3_CR5","doi-asserted-by":"crossref","unstructured":"Leita, C., Dacier, M.: SGNET: a worldwide deployable framework to support the analysis of malware threat models. In: 7th European Dependable Computing Conference (EDCC 2008) (May 2008)","DOI":"10.1109\/EDCC-7.2008.15"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Song, Y., Locasto, M.E., Stavrou, A., Keromytis, A.D., Stolfo, S.J.: On the infeasibility of modeling polymorphic shellcode. In: Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS), pp. 541\u2013551 (2007)","DOI":"10.1145\/1315245.1315312"},{"key":"3_CR7","doi-asserted-by":"crossref","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS (2007)","DOI":"10.1145\/1315245.1315313"},{"key":"3_CR8","unstructured":"Bennett, J., Lin, Y., Haq, T.: The Number of the Beast (2013), http:\/\/blog.fireeye.com\/research\/2013\/02\/the-number-of-the-beast.html"},{"key":"3_CR9","unstructured":"Roesch, M.: Snort: Lightweight intrusion detection for networks. In: Proceedings of USENIX LISA 1999 (November 1999), software available from http:\/\/www.snort.org\/"},{"key":"3_CR10","unstructured":"Paxson, V.: Bro: A system for detecting network intruders in real-time. In: Proceedings of the 7th USENIX Security Symposium (January 1998)"},{"key":"3_CR11","unstructured":"honeynet.org: Sebek (2012), https:\/\/projects.honeynet.org\/sebek\/"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"Tang, Y., Chen, S.: Defending against internet worms: A signature-based approach. In: Proceedings IEEE 24th Annual Joint Conference of the IEEE Computer and Communications Societies, INFOCOM 2005, vol.\u00a02, pp. 1384\u20131394. IEEE (2005)","DOI":"10.1109\/INFCOM.2005.1498363"},{"key":"3_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"438","DOI":"10.1007\/978-3-540-77048-0_34","volume-title":"Information and Communications Security","author":"J. Zhuge","year":"2007","unstructured":"Zhuge, J., Holz, T., Han, X., Song, C., Zou, W.: Collecting autonomous spreading malware using high-interaction honeypots. In: Qing, S., Imai, H., Wang, G. (eds.) ICICS 2007. LNCS, vol.\u00a04861, pp. 438\u2013451. Springer, Heidelberg (2007)"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Vrable, M., Ma, J., Chen, J., Moore, D., Vandekieft, E., Snoeren, A.C., Voelker, G.M., Savage, S.: Scalability, fidelity, and containment in the potemkin virtual honeyfarm. In: Proceedings of the Twentieth ACM Symposium on Operating Systems Principles (SOSP), pp. 148\u2013162 (2005)","DOI":"10.1145\/1095809.1095825"},{"key":"3_CR15","unstructured":"Jiang, X., Xu, D.: Collapsar: A vm-based architecture for network attack detention center. In: Proceedings of the 13th USENIX Security Symposium (2004)"},{"key":"3_CR16","series-title":"Dagon, D., Qin, X., Gu, G., Lee, W., Grizzard, J., Levine, J., Owen, H","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-540-30143-1_3","volume-title":"Recent Advances in Intrusion Detection","author":"D. Dagon","year":"2004","unstructured":"Dagon, D., Qin, X., Gu, G., Lee, W., Grizzard, J., Levine, J., Owen, H.: HoneyStat: Local worm detection using honeypots. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. Dagon, D., Qin, X., Gu, G., Lee, W., Grizzard, J., Levine, J., Owen, H, vol.\u00a03224, pp. 39\u201358. Springer, Heidelberg (2004)"},{"issue":"4","key":"3_CR17","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1218063.1217938","volume":"40","author":"G. Portokalidis","year":"2006","unstructured":"Portokalidis, G., Slowinska, A., Bos, H.: Argos: an emulator for fingerprinting zero-day attacks for advertised honeypots with automatic signature generation. SIGOPS Oper. Syst. Rev.\u00a040(4), 15\u201327 (2006)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"3_CR18","unstructured":"Anagnostakis, K.G., Sidiroglou, S., Akritidis, P., Xinidis, K., Markatos, E.P., Keromytis, A.D.: Detecting Targeted Attacks Using Shadow Honeypots. In: Proceedings of the 14th USENIX Security Symposium, pp. 129\u2013144 (August 2005)"},{"key":"3_CR19","unstructured":"Provos, N.: Honeyd: a virtual honeypot daemon. In: 10th DFN-CERT Workshop, Hamburg, Germany, vol.\u00a02 (2003)"},{"key":"3_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/11856214_9","volume-title":"Recent Advances in Intrusion Detection","author":"P. Baecher","year":"2006","unstructured":"Baecher, P., Koetter, M., Holz, T., Dornseif, M., Freiling, F.C.: The nepenthes platform: An efficient approach to collect malware. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 165\u2013184. Springer, Heidelberg (2006)"},{"key":"3_CR21","unstructured":"Amun: Python honeypot (2009), http:\/\/amunhoney.sourceforge.net\/"},{"key":"3_CR22","unstructured":"Dionaea: catches bugs (2012), http:\/\/dionaea.carnivore.it\/"},{"key":"3_CR23","unstructured":"Baecher, P., Koetter, M.: libemu (2009), http:\/\/libemu.carnivore.it\/"},{"key":"3_CR24","unstructured":"Kreibich, C., Weaver, N., Kanich, C., Cui, W., Paxson, V.: [GQ]: Practical Containment for Measuring Modern Malware Systems. In: Proceedings of the ACM Internet Measurement Conference (IMC), Berlin, Germany (November 2011)"},{"key":"3_CR25","unstructured":"Leita, C.: SGNET: automated protocol learning for the observation of malicious threats. PhD thesis, University of Nice-Sophia Antipolis (December 2008)"},{"key":"3_CR26","unstructured":"K2: ADMmutate (2001), http:\/\/www.ktwo.ca\/ADMmutate-0.8.4.tar.gz"},{"key":"3_CR27","unstructured":"Detristan, T., Ulenspiegel, T., Malcom, Y., Underduk, M.: Polymorphic shellcode engine using spectrum analysis. Phrack\u00a011(61) (August 2003)"},{"key":"3_CR28","unstructured":"Obscou: Building ia32 \u2019unicode-proof\u2019 shellcodes. Phrack 11(61) (August 2003)"},{"key":"3_CR29","unstructured":"Rix: Writing IA32 alphanumeric shellcodes. Phrack 11(57) (August 2001)"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Mason, J., Small, S., Monrose, F., MacManus, G.: English shellcode. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, CCS (2009)","DOI":"10.1145\/1653662.1653725"},{"key":"3_CR31","doi-asserted-by":"crossref","unstructured":"Kreibich, C., Crowcroft, J.: Honeycomb \u2013 creating intrusion detection signatures using honeypots. In: Proceedings of the Second Workshop on Hot Topics in Networks (HotNets-II) (November 2003)","DOI":"10.1145\/972374.972384"},{"key":"3_CR32","unstructured":"Kim, H.A., Karp, B.: Autograph: Toward automated, distributed worm signature detection. In: Proceedings of the 13th USENIX Security Symposium, pp. 271\u2013286 (2004)"},{"key":"3_CR33","unstructured":"Singh, S., Estan, C., Varghese, G., Savage, S.: Automated worm fingerprinting. In: Proceedings of the 6th Symposium on Operating Systems Design & Implementation, OSDI (December 2004)"},{"key":"3_CR34","unstructured":"Kolesnikov, O., Dagon, D., Lee, W.: Advanced polymorphic worms: Evading IDS by blending in with normal traffic (2004), http:\/\/www.cc.gatech.edu\/~ok\/w\/ok_pw.pdf"},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., Song, D.: Polygraph: Automatically Generating Signatures for Polymorphic Worms. In: Proceedings of the IEEE Symposium on Security & Privacy, pp. 226\u2013241 ( May 2005)","DOI":"10.1109\/SP.2005.15"},{"key":"3_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2004","unstructured":"Wang, K., Stolfo, S.J.: Anomalous payload-based network intrusion detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 203\u2013222. Springer, Heidelberg (2004)"},{"key":"3_CR37","unstructured":"Li, Z., Sanghi, M., Chen, Y., Kao, M.Y., Chavez, B.: Hamsa: Fast signature generation for zero-day polymorphic worms with provable attack resilience. In: Proceedings of the IEEE Symposium on Security & Privacy, pp. 32\u201347 (2006)"},{"key":"3_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1007\/11856214_5","volume-title":"Recent Advances in Intrusion Detection","author":"J. Newsome","year":"2006","unstructured":"Newsome, J., Karp, B., Song, D.: Paragraph: Thwarting signature learning by training maliciously. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 81\u2013105. Springer, Heidelberg (2006)"},{"key":"3_CR39","unstructured":"Fogla, P., Sharif, M., Perdisci, R., Kolesnikov, O., Lee, W.: Polymorphic blending attacks. In: Proceedings of the 15th USENIX Security Symposium (2006)"},{"key":"3_CR40","doi-asserted-by":"crossref","unstructured":"Wang, H.J., Guo, C., Simon, D.R., Zugenmaier, A.: Shield: Vulnerability-driven network filters for preventing known vulnerability exploits. In: Proceedings of the ACM SIGCOMM Conference, pp. 193\u2013204 (August 2004)","DOI":"10.1145\/1030194.1015489"},{"key":"3_CR41","doi-asserted-by":"crossref","unstructured":"Brumley, D., Newsome, J., Song, D., Wang, H., Jha, S.: Towards automatic generation of vulnerability-based signatures. In: Proceedings of the IEEE Symposium on Security and Privacy (2006)","DOI":"10.21236\/ADA462599"},{"key":"3_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1007\/3-540-36084-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"T. T\u00f3th","year":"2002","unstructured":"T\u00f3th, T., Kruegel, C.: Accurate Buffer Overflow Detection via Abstract Payload Execution. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 274\u2013291. Springer, Heidelberg (2002)"},{"key":"3_CR43","series-title":"IFIP AICT","first-page":"375","volume-title":"Information Security Conference","author":"P. Akritidis","year":"2005","unstructured":"Akritidis, P., Markatos, E.P., Polychronakis, M., Anagnostakis, K.: STRIDE: Polymorphic sled detection through instruction sequence analysis. In: Sasaki, R., Qing, S., Okamoto, E., Yoshiura, H. (eds.) Information Security Conference. IFIP AICT, vol.\u00a0181, pp. 375\u2013391. Springer, Boston (2005)"},{"key":"3_CR44","unstructured":"Andersson, S., Clark, A., Mohay, G.: Network-based buffer overflow detection by exploit code analysis. In: Proceedings of the Asia Pacific Information Technology Security Conference, AusCERT (2004)"},{"key":"3_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11663812_11","volume-title":"Recent Advances in Intrusion Detection","author":"C. Kruegel","year":"2006","unstructured":"Kruegel, C., Kirda, E., Mutz, D., Robertson, W., Vigna, G.: Polymorphic worm detection using structural information of executables. In: Valdes, A., Zamboni, D. (eds.) RAID 2005. LNCS, vol.\u00a03858, pp. 207\u2013226. Springer, Heidelberg (2006)"},{"key":"3_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/11506881_2","volume-title":"Intrusion and Malware Detection and Vulnerability Assessment","author":"U. Payer","year":"2005","unstructured":"Payer, U., Teufl, P., Lamberger, M.: Hybrid engine for polymorphic shellcode detection. In: Julisch, K., Kruegel, C. (eds.) DIMVA 2005. LNCS, vol.\u00a03548, pp. 19\u201331. Springer, Heidelberg (2005)"},{"key":"3_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1007\/11663812_15","volume-title":"Recent Advances in Intrusion Detection","author":"R. Chinchani","year":"2006","unstructured":"Chinchani, R., van den Berg, E.: A fast static analysis approach to detect exploit code inside network flows. In: Valdes, A., Zamboni, D. (eds.) RAID 2005. LNCS, vol.\u00a03858, pp. 284\u2013308. Springer, Heidelberg (2006)"},{"key":"3_CR48","unstructured":"Wang, X., Pan, C.C., Liu, P., Zhu, S.: Sigfree: A signature-free buffer overflow attack blocker. In: Proceedings of the USENIX Security Symposium (August 2006)"},{"key":"3_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/11790754_4","volume-title":"Detection of Intrusions and Malware & Vulnerability Assessment","author":"M. Polychronakis","year":"2006","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Network\u2013level polymorphic shellcode detection using emulation. In: B\u00fcschkes, R., Laskov, P. (eds.) DIMVA 2006. LNCS, vol.\u00a04064, pp. 54\u201373. Springer, Heidelberg (2006)"},{"key":"3_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-3-540-74320-0_5","volume-title":"Recent Advances in Intrusion Detection","author":"M. Polychronakis","year":"2007","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Emulation-based detection of non-self-contained polymorphic shellcode. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol.\u00a04637, pp. 87\u2013106. Springer, Heidelberg (2007)"},{"key":"3_CR51","doi-asserted-by":"crossref","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: Comprehensive shellcode detection using runtime heuristics. In: Proceedings of the 26th Annual Computer Security Applications Conference (ACSAC) (December 2010)","DOI":"10.1145\/1920261.1920305"},{"key":"3_CR52","unstructured":"Snow, K.Z., Krishnan, S., Monrose, F., Provos, N.: ShellOS: Enabling fast detection and forensic analysis of code injection attacks. In: Proceedings of the 20th USENIX Security Symposium (2011)"},{"key":"3_CR53","unstructured":"Leita, C., Mermoud, K., Dacier, M.: Scriptgen: an automated script generation tool for honeyd. In: 21st Annual Computer Security Applications Conference (December 2005)"},{"key":"3_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/11856214_10","volume-title":"Recent Advances in Intrusion Detection","author":"C. Leita","year":"2006","unstructured":"Leita, C., Dacier, M., Massicotte, F.: Automatic handling of protocol dependencies and reaction to 0-day attacks with scriptGen based honeypots. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 185\u2013205. Springer, Heidelberg (2006)"},{"key":"3_CR55","unstructured":"Polychronakis, M., Anagnostakis, K.G., Markatos, E.P.: An empirical study of real-world polymorphic code injection attacks. In: Proceedings of the 2nd USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET) (April 2009)"},{"key":"3_CR56","doi-asserted-by":"crossref","unstructured":"Polychronakis, M., Keromytis, A.D.: ROP payload detection using speculative code execution. In: Proceedings of the 6th International Conference on Malicious and Unwanted Software (MALWARE), pp. 58\u201365 (October 2011)","DOI":"10.1109\/MALWARE.2011.6112327"},{"key":"3_CR57","unstructured":"Patton, S., Yurcik, W., Doss, D.: An achilles heel in signature-based ids: Squealing false positives in snort. In: Proceedings of RAID 2001 (2001)"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-41284-4_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T17:53:26Z","timestamp":1746035606000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-41284-4_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642412837","9783642412844"],"references-count":57,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-41284-4_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}