{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T06:56:29Z","timestamp":1758264989495,"version":"3.38.0"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2011,5,22]],"date-time":"2011-05-22T00:00:00Z","timestamp":1306022400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2011,10]]},"DOI":"10.1007\/s10207-011-0132-7","type":"journal-article","created":{"date-parts":[[2011,5,21]],"date-time":"2011-05-21T02:33:01Z","timestamp":1305945181000},"page":"269-283","source":"Crossref","is-referenced-by-count":11,"title":["SAS: semantics aware signature generation for polymorphic worm detection"],"prefix":"10.1007","volume":"10","author":[{"given":"Deguang","family":"Kong","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yoon-Chan","family":"Jhi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tao","family":"Gong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sencun","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongsheng","family":"Xi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2011,5,22]]},"reference":[{"key":"132_CR1","unstructured":"Jempiscodes\u2014a polymorphic shellcode generator. http:\/\/www.shellcode.com.ar\/en\/proyectos.html"},{"key":"132_CR2","unstructured":"Baecher, P., Koetter, M.: Getting around non-executable stack (and fix). http:\/\/www.libemu.carnivore.it\/"},{"key":"132_CR3","unstructured":"Bania, P.: Evading network-level emulation. http:\/\/www.packetstormsecurity.org\/papers\/bypass\/pbania-evading-nemu2009.pdf"},{"key":"132_CR4","doi-asserted-by":"crossref","unstructured":"Borders, K., Prakash, A., Zielinski., M.: Spector: automatically analyzing shell code. In: Proceedings of the 23rd Annual Computer Security Applications Conference, pp. 501\u2013514 (2007)","DOI":"10.1109\/ACSAC.2007.4413015"},{"key":"132_CR5","doi-asserted-by":"crossref","unstructured":"Gu, B., Bai, X., Yang, Z., Adam, C., Xuan, D.: Malicious shellcode detection with virtual memory snapshots. In: Proceedings of IEEE International Conference on Computer Communications (IEEE INFOCOM) (2010)","DOI":"10.1109\/INFCOM.2010.5461950"},{"key":"132_CR6","unstructured":"Brumley, D., Caballero, J., Liang, Z., Newsome, J., Song., D.: Towards automatic discovery of deviations in binary implementations with applications to error detection and fingerprint generation. In: Proceedings of the 16th USENIX Security (2007)"},{"key":"132_CR7","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S., Song, D., Bryant, R.: Semantics-aware malware detection. In: 2005 IEEE Symposium on Security and Privacy (2005)","DOI":"10.1109\/SP.2005.20"},{"key":"132_CR8","doi-asserted-by":"crossref","unstructured":"Chung, S.P., Mok, A.K.: Advanced allergy attacks: Does a corpus really help. In: Recent Advances in Intrusion Detection (RAID), pp. 236\u2013255. Springer, Berlin (2007)","DOI":"10.1007\/978-3-540-74320-0_13"},{"key":"132_CR9","unstructured":"Collberg, C., Thomborson, C., Low., D.: A taxonomy of obfuscating transformations. In: Technical Report 148, University of Auckland (1997)"},{"key":"132_CR10","unstructured":"Detristan, T., Ulenspiegel, T., Malcom, Y., Superbus, M., Underduk, V.: Polymorphic shellcode engine using spectrum analysis. http:\/\/www.phrack.org\/show.php?p=61&a=9"},{"key":"132_CR11","unstructured":"Fogla, P., Sharif, M., Perdisci, R., Kolesnikov, O., Lee, W.: Polymorphic blending attacks. In: Proceedings of The 15th USENIX Security Symposium (2006)"},{"key":"132_CR12","unstructured":"Forsell, M., Lepp\u00e4nen, V.: Mtpa\u2014a processor architecture for mp-socs employing the moving threads paradigm. In: PDPTA, pp. 198\u2013204 (2009)"},{"key":"132_CR13","unstructured":"Gundy, M.V., Balzarotti, D., Vigna, G.: Catch me, if you can: Evading network signatures with web-based polymorphic worms. In: Proceedings of the First USENIX Workshop on Offensive Technologies (WOOT) Boston, MA (2007)"},{"key":"132_CR14","doi-asserted-by":"crossref","unstructured":"Gundy, M.V., Chen, H., Su, Z., Vigna, G.: Feature omission vulnerabilities: thwarting signature generation for polymorphic worms. In: Proceeding of Annual Computer Security Applications Conference (ACSAC) (2007)","DOI":"10.1109\/ACSAC.2007.42"},{"key":"132_CR15","doi-asserted-by":"crossref","unstructured":"Kc, G.S., Keromytis, A.D.: e-nexsh: achieving an effectively non-executable stack and heap via system-call policing. In: ACSAC, pp. 286\u2013302 (2005)","DOI":"10.1109\/CSAC.2005.22"},{"key":"132_CR16","unstructured":"Kim, H.A., Karp, B.: Autograph: toward automated, distributed worm signature detection. In: Proceedings of the 13th Usenix Security Symposium (2004)"},{"key":"132_CR17","doi-asserted-by":"crossref","unstructured":"Kreibich, C., Crowcroft., J.: Honeycomb: creating intrusion detection signatures using honeypots. In: Proceedings of the Workshop on Hot Topics in Networks (HotNets) (2003)","DOI":"10.1145\/972374.972384"},{"key":"132_CR18","doi-asserted-by":"crossref","unstructured":"Krugel, C., Kirda, E.: Polymorphic worm detection using structural information of executables. In: 2005 International Symposium on Recent Advances in Intrusion Detecion (2005)","DOI":"10.1007\/11663812_11"},{"key":"132_CR19","unstructured":"Kr\u00fcgel, C., Lippmann, R., Clark, A.: Emulation-based detection of non-self-contained polymorphic shellcode. In: Recent Advances in Intrusion Detection, 10th International Symposium, Lecture Notes in Computer Science, vol. 4637. Springer, Berlin (2007)"},{"key":"132_CR20","unstructured":"Li, Z.: Hamsa code. http:\/\/www.zhichunli.org\/"},{"key":"132_CR21","unstructured":"Li, Z., Sanghi, M., Chen, Y., Kao, M.Y., Chavez, B.: Hamsa: fast signature generation for zero-day polymorphic worms with provable attack resilience. In: IEEE Symposium on Security and Privacy (2006)"},{"key":"132_CR22","unstructured":"Liang, Z., Sekar., R.: Automatic generation of buffer overflow attack signatures: An approach based on program behavior models. In: Proceedings of the Anual Computer Security Applications Conference (2005)"},{"key":"132_CR23","doi-asserted-by":"crossref","unstructured":"Liang, Z., Sekar., R.: Fast and automated generation of attack signatures: A basis for building self-protecting servers. In: Proceedings of the 12th ACM Conference on Computer and Communications Security (2005)","DOI":"10.1145\/1102120.1102150"},{"key":"132_CR24","unstructured":"Macaulay, S.: Admmutate: polymorphic shellcode engine. http:\/\/www.ktwo.ca\/security.html"},{"key":"132_CR25","doi-asserted-by":"crossref","unstructured":"Mason, J., Small, S., Monrose, F., MacManus, G.: English shellcode. In: ACM Conference on Computer and Communications Security. ACM (2009)","DOI":"10.1145\/1653662.1653725"},{"key":"132_CR26","unstructured":"Moore, H.: The metasploit project. http:\/\/www.metasploit.com"},{"key":"132_CR27","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: Proceedings of the 23rd Anual Computer Security Applications Conference (2007)","DOI":"10.1109\/ACSAC.2007.21"},{"key":"132_CR28","unstructured":"Newsome, J., Karp, B., Song, D.: Polygraph: automatic signature generation for polymorphic worms. In: IEEE Symposium on Security and Privacy (2005)"},{"key":"132_CR29","doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., Song, D.: Paragraph: thwarting signature learning by training maliciously. In: Recent Advances in Intrusion Detection (RAID), pp. 81\u2013105. Springer, Berlin (2006)","DOI":"10.1007\/11856214_5"},{"key":"132_CR30","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Proceedings of Network and Distributed System Security Symposium (2005)"},{"key":"132_CR31","unstructured":"Pedro, N.D., Domingos, P., Sumit, M., Verma, S.D.: Adversarial classification. In: 10th ACM SIGKDD Conference On Knowledge Discovery and Data mining, pp. 99\u2013108 (2004)"},{"key":"132_CR32","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Dagon, D., Lee, W.: Misleading worm signature generators using deliberate noise injection. In: Proceedings of The 2006 IEEE Symposium on Security and Privacy (2006)","DOI":"10.1109\/SP.2006.26"},{"issue":"2","key":"132_CR33","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1109\/5.18626","volume":"77","author":"L.R. Rabiner","year":"1999","unstructured":"Rabiner L.R.: A tutorial on hidden markov models and selected applications in speech recognition. Proceedings of the IEEE 77(2), 257\u2013286 (1999)","journal-title":"Proceedings of the IEEE"},{"key":"132_CR34","unstructured":"Ray, E.: Ms-sql worm. http:\/\/www.sans.org\/resources\/malwarefaq\/ms-sql-exploit.php"},{"key":"132_CR35","volume-title":"Earlybird System for Real-Time Detection of Unknown Worms, Technical Report","author":"S. Singh","year":"2003","unstructured":"Singh S., Estan C., Varghese G., Savage S.: Earlybird System for Real-Time Detection of Unknown Worms, Technical Report. University of California at San Diego, San Diego (2003)"},{"key":"132_CR36","unstructured":"Smirnov, A., cker Chiueh, T.: Dira: Automatic detection, identification and repair of control-hijacking attacks. In: NDSS (2005)"},{"key":"132_CR37","doi-asserted-by":"crossref","unstructured":"Song, Y., Locasto, M.E., Stavrou, A., Keromytis, A.D., Stolfo., S.J.: On the infeasibility of modeling polymorphic shellcode. In: Proceedings of the 14th ACM conference on Computer and Communications Security(CCS), pp. 541\u2013551 (2007)","DOI":"10.1145\/1315245.1315312"},{"key":"132_CR38","first-page":"112","volume-title":"The Art of Computer Virus Research and Defense","author":"P. Szor","year":"2005","unstructured":"Szor P.: The Art of Computer Virus Research and Defense, pp. 112\u2013134. Addison Wesley, Upper Saddle River (2005)"},{"key":"132_CR39","unstructured":"Venkataraman, S., Blum, A., Song., D.: Limits of learning-based signature generation with adversaries. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium (2008)"},{"key":"132_CR40","doi-asserted-by":"crossref","unstructured":"Wang, X., Jhi, Y.C., Zhu, S., Liu, P.: Still: exploit code detection via static taint and initialization analyses. In: Proceedings of Anual Computer Security Applications Conference (ACSAC) (2008)","DOI":"10.1109\/ACSAC.2008.37"},{"key":"132_CR41","unstructured":"Wang, X., Pan, C.C., Liu, P., Zhu, S.: Sigfree: a signature-free buffer overflow attack blocker.In: 15th Usenix Security Symposium (2006)"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-011-0132-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-011-0132-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-011-0132-7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,5]],"date-time":"2025-03-05T18:35:59Z","timestamp":1741199759000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-011-0132-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,5,22]]},"references-count":41,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2011,10]]}},"alternative-id":["132"],"URL":"https:\/\/doi.org\/10.1007\/s10207-011-0132-7","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"type":"print","value":"1615-5262"},{"type":"electronic","value":"1615-5270"}],"subject":[],"published":{"date-parts":[[2011,5,22]]}}}