{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T18:59:46Z","timestamp":1726081186192},"publisher-location":"Singapore","reference-count":30,"publisher":"Springer Singapore","isbn-type":[{"type":"print","value":"9789811548246"},{"type":"electronic","value":"9789811548253"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-981-15-4825-3_28","type":"book-chapter","created":{"date-parts":[[2020,4,25]],"date-time":"2020-04-25T04:02:53Z","timestamp":1587787373000},"page":"348-359","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Protecting Computer Systems from Cyber Attacks with Internal Interface Diversification"],"prefix":"10.1007","author":[{"given":"Sampsa","family":"Rauti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,4,26]]},"reference":[{"key":"28_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., Plotkin, G.: On protection by layout randomization. In: 2010 23rd IEEE Computer Security Foundations Symposium, pp. 337\u2013351 (2010)","DOI":"10.1109\/CSF.2010.30"},{"key":"28_CR2","series-title":"Advances in Information Security","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-030-18214-4_9","volume-title":"Industrial Control Systems Security and Resiliency","author":"M Albanese","year":"2019","unstructured":"Albanese, M., Jajodia, S.: Proactive defense through deception. Industrial Control Systems Security and Resiliency. AIS, vol. 75, pp. 169\u2013202. Springer, Cham (2019). \nhttps:\/\/doi.org\/10.1007\/978-3-030-18214-4_9"},{"key":"28_CR3","unstructured":"AVTest: Malware statictics. \nhttps:\/\/www.av-test.org\/en\/ statistics\/malware\/\n\n. Accessed 20 Aug 2019"},{"issue":"3","key":"28_CR4","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1109\/TDSC.2008.58","volume":"7","author":"S Boyd","year":"2008","unstructured":"Boyd, S., Kc, G., Locasto, M., Keromytis, A.: On the general applicability of instruction-set randomization. IEEE Trans. Dependable Secure Comput. 7(3), 255\u2013270 (2008)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"28_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/978-3-540-24852-1_21","volume-title":"Applied Cryptography and Network Security","author":"SW Boyd","year":"2004","unstructured":"Boyd, S.W., Keromytis, A.D.: SQLrand: preventing SQL injection attacks. In: Jakobsson, M., Yung, M., Zhou, J. (eds.) ACNS 2004. LNCS, vol. 3089, pp. 292\u2013302. Springer, Heidelberg (2004). \nhttps:\/\/doi.org\/10.1007\/978-3-540-24852-1_21"},{"key":"28_CR6","unstructured":"Chew, M., Song, D.: Mitigating buffer overflows by operating system randomization. Technical report, CMU (2002)"},{"key":"28_CR7","unstructured":"Chongkyung, K., Jinsuk, J., Bookholt, C., Xu, J., Peng, N.: Address space layout permutation (ASLP): towards fine-grained randomization of commodity software. In: Computer Security Applications Conference. ACSAC 2006, pp. 339\u2013348 (2006)"},{"key":"28_CR8","unstructured":"Cloudflare: Inside the infamous Mirai IoT Botnet: a retrospective analysis. \nhttps:\/\/blog.cloudflare.com\/inside-mirai-the-infamous-iot-botnet-a-retrospective-analysis\/\n\n. Accessed 20 Aug 2019"},{"issue":"6","key":"28_CR9","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1016\/0167-4048(93)90054-9","volume":"12","author":"F Cohen","year":"1993","unstructured":"Cohen, F.: Operating system protection through program evolution. Comput. Secur. 12(6), 565\u2013584 (1993)","journal-title":"Comput. Secur."},{"key":"28_CR10","series-title":"Risk, Systems and Decisions","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1007\/978-3-319-77492-3_10","volume-title":"Cyber Resilience of Systems and Networks","author":"N Evans","year":"2019","unstructured":"Evans, N., Horsthemke, W.: Active defense techniques. In: Kott, A., Linkov, I. (eds.) Cyber Resilience of Systems and Networks. RSD, pp. 221\u2013246. Springer, Cham (2019). \nhttps:\/\/doi.org\/10.1007\/978-3-319-77492-3_10"},{"key":"28_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/978-3-642-38631-2_22","volume-title":"Network and System Security","author":"A Gupta","year":"2013","unstructured":"Gupta, A., Kerr, S., Kirkpatrick, M.S., Bertino, E.: Marlin: a fine grained randomization approach to defend against ROP attacks. In: Lopez, J., Huang, X., Sandhu, R. (eds.) NSS 2013. LNCS, vol. 7873, pp. 293\u2013306. Springer, Heidelberg (2013). \nhttps:\/\/doi.org\/10.1007\/978-3-642-38631-2_22"},{"key":"28_CR12","unstructured":"Imperva: Breaking down Mirai: an IoT DDoS botnet analysis. \nhttps:\/\/www.imperva.com\/blog\/malware-analysis-mirai-ddos-botnet\/\n\n. Accessed 20 Aug 2019"},{"key":"28_CR13","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, H.J., Xu, D., Wang, Y.: RandSys: thwarting code injection attacks with system service interface randomization. In: 26th IEEE International Symposium on Reliable Distributed Systems. SRDS 2007, pp. 209\u2013218 (2007)","DOI":"10.1109\/SRDS.2007.36"},{"key":"28_CR14","doi-asserted-by":"crossref","unstructured":"Kambourakis, G., Kolias, C., Stavrou, A.: The Mirai botnet and the IoT zombie armies. In: MILCOM 2017\u20132017 IEEE Military Communications Conference (MILCOM), pp. 267\u2013272 (2017)","DOI":"10.1109\/MILCOM.2017.8170867"},{"key":"28_CR15","doi-asserted-by":"crossref","unstructured":"Kc, G., Keromytis, A., Prevelakis, V.: Countering code-injection attacks with instruction-set randomization. In: Proceedings of the 10th ACM Conference on Computer and Communications Security. CCS 2003, New York, NY, USA, pp. 272\u2013280. (2003)","DOI":"10.1145\/948109.948146"},{"key":"28_CR16","doi-asserted-by":"crossref","unstructured":"Kim, J., Jang, D., Jeong, Y., Kang, B.B.: Polar: Per-allocation object layout randomization. In: 2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 505\u2013516. IEEE (2019)","DOI":"10.1109\/DSN.2019.00058"},{"issue":"2","key":"28_CR17","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1109\/MSP.2013.129","volume":"12","author":"P Larsen","year":"2014","unstructured":"Larsen, P., Brunthaler, S., Franz, M.: Security through diversity: are we there yet? IEEE Secur. Priv. 12(2), 28\u201335 (2014)","journal-title":"IEEE Secur. Priv."},{"key":"28_CR18","doi-asserted-by":"crossref","unstructured":"Larsen, P., Homescu, A., Brunthaler, S., Franz, M.: SoK: automated software diversity. In: 2014 IEEE Symposium on Security and Privacy (SP), pp. 276\u2013291 (2014)","DOI":"10.1109\/SP.2014.25"},{"key":"28_CR19","unstructured":"Liang, Z., Liang, B., Li, L.: A system call randomization based method for countering code injection attacks. In: International Conference on Networks Security, Wireless Communications and Trusted Computing. NSWCTC 2009, pp. 584\u2013587 (2009)"},{"key":"28_CR20","unstructured":"Locasto, M., Keromytis, A.: PachyRand: SQL Randomization for the PostgreSQL JDBC Driver. Technical report CUCS-033-05. Columbia University, Computer Science (2005)"},{"key":"28_CR21","unstructured":"Mirai source code: \nhttps:\/\/github.com\/jgamblin\/Mirai-Source-Code\n\n. Accessed 20 Aug 2019"},{"key":"28_CR22","series-title":"Advances in Information Security","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1007\/978-1-4614-0977-9_3","volume-title":"Moving Target Defense","author":"G Portokalidis","year":"2011","unstructured":"Portokalidis, G., Keromytis, A.D.: Global ISR toward a comprehensive defense against unauthorized code execution. In: Jajodia, S., Ghosh, A., Swarup, V., Wang, C., Wang, X. (eds.) Moving Target Defense. Advances in Information Security, vol. 54, pp. 49\u201376. Springer, New York (2011). \nhttps:\/\/doi.org\/10.1007\/978-1-4614-0977-9_3"},{"key":"28_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1007\/978-3-319-27998-5_2","volume-title":"Trusted Systems","author":"S Rauti","year":"2015","unstructured":"Rauti, S., Laur\u00e9n, S., Hosseinzadeh, S., M\u00e4kel\u00e4, J.-M., Hyrynsalmi, S., Lepp\u00e4nen, V.: Diversification of system calls in linux binaries. In: Yung, M., Zhu, L., Yang, Y. (eds.) INTRUST 2014. LNCS, vol. 9473, pp. 15\u201335. Springer, Cham (2015). \nhttps:\/\/doi.org\/10.1007\/978-3-319-27998-5_2"},{"key":"28_CR24","doi-asserted-by":"crossref","unstructured":"Rauti, S., Teuhola, J., Lepp\u00e4nen, V.: Diversifying SQL to prevent injection attacks. In: Proceedings of Trustcom\/BigDataSE\/ISPA, pp. 344\u2013351 (2015)","DOI":"10.1109\/Trustcom.2015.393"},{"key":"28_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1007\/978-3-319-47560-8_10","volume-title":"Secure IT Systems","author":"S Rauti","year":"2016","unstructured":"Rauti, S., et al.: A survey on internal interfaces used by exploits and implications on interface diversification. In: Brumley, B.B., R\u00f6ning, J. (eds.) NordSec 2016. LNCS, vol. 10014, pp. 152\u2013168. Springer, Cham (2016). \nhttps:\/\/doi.org\/10.1007\/978-3-319-47560-8_10"},{"key":"28_CR26","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1007\/978-3-319-67071-3_40","volume-title":"International Conference on Applications and Techniques in Cyber Security and Intelligence","author":"R Shetty","year":"2018","unstructured":"Shetty, R., Choo, K.-K.R., Kaufman, R.: Shellshock vulnerability exploitation and mitigation: a demonstration. In: Abawajy, J., Choo, K.-K.R., Islam, R. (eds.) ATCI 2017. AISC, vol. 580, pp. 338\u2013350. Springer, Cham (2018). \nhttps:\/\/doi.org\/10.1007\/978-3-319-67071-3_40"},{"key":"28_CR27","doi-asserted-by":"crossref","unstructured":"Sinha, K., Kemerlis, V.P., Sethumadhavan, S.: Reviving instruction set randomization. In: 2017 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 21\u201328 (2017)","DOI":"10.1109\/HST.2017.7951732"},{"key":"28_CR28","unstructured":"Uitto, J., Rauti, S., M\u00e4kel\u00e4, J.M., Lepp\u00e4nen, V.: Preventing malicious attacks by diversifying Linux shell commands. In: Proceedings of the 14th Symposium on Programming Languages and Software Tools. SPLST 2015, CEUR Workshop Proceedings, vol. 1525 (2015)"},{"issue":"2","key":"28_CR29","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MSP.2018.1870866","volume":"16","author":"C Wang","year":"2018","unstructured":"Wang, C., Lu, Z.: Cyber deception: overview and the road ahead. IEEE Secur. Priv. 16(2), 80\u201385 (2018)","journal-title":"IEEE Secur. Priv."},{"issue":"3","key":"28_CR30","doi-asserted-by":"publisher","first-page":"331","DOI":"10.3233\/JCS-2009-0322","volume":"17","author":"H Xu","year":"2009","unstructured":"Xu, H., Chapin, S.: Address-space layout randomization using code islands. J. Comput. Secur. 17(3), 331\u2013362 (2009)","journal-title":"J. Comput. Secur."}],"container-title":["Communications in Computer and Information Science","Security in Computing and Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-15-4825-3_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,25]],"date-time":"2020-04-25T04:07:22Z","timestamp":1587787642000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-981-15-4825-3_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9789811548246","9789811548253"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-981-15-4825-3_28","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"26 April 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SSCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Security in Computing and Communication","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Trivandrum","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sscc2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.acn-conference.org\/sscc2019\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EDAS","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"61","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"22","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"36% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}