{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T14:56:08Z","timestamp":1780325768452,"version":"3.54.1"},"reference-count":46,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2014,3,27]],"date-time":"2014-03-27T00:00:00Z","timestamp":1395878400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2014,10]]},"DOI":"10.1007\/s10207-014-0233-1","type":"journal-article","created":{"date-parts":[[2014,3,26]],"date-time":"2014-03-26T05:42:46Z","timestamp":1395812566000},"page":"439-452","source":"Crossref","is-referenced-by-count":8,"title":["A defense framework against malware and vulnerability exploits"],"prefix":"10.1007","volume":"13","author":[{"given":"Meng","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anand","family":"Raghunathan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Niraj K.","family":"Jha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2014,3,27]]},"reference":[{"key":"233_CR1","unstructured":"CSI: CSI computer crime and security survey. http:\/\/www.gocsi.com (2010)"},{"key":"233_CR2","unstructured":"Symantec: Security response. http:\/\/www.messagelabs.com\/resources\/mlireports.aspx (2011)"},{"key":"233_CR3","unstructured":"McAfee: Threats predictions. http:\/\/www.mcafee.com\/us\/resources\/reports\/rp-threat-predictions-2011 (2011)"},{"key":"233_CR4","unstructured":"CERT: CERT vulnerability notes database. http:\/\/www.kb.cert.org\/vuls (2011)"},{"key":"233_CR5","unstructured":"CVE: The standard for information security vulnerability names. http:\/\/cve.mitre.org\/ (2011)"},{"key":"233_CR6","unstructured":"Aaraj, N., Raghunathan, A., Jha, N.K.: Virtualization-based framework for malware defense. In: Proceedings of Conference Detection of Intrusions and Malware and Vulnerability, Assessment, pp. 64\u201387 (2008)."},{"key":"233_CR7","unstructured":"Kaspersky Anti-Virus Mobile. http:\/\/usa.kaspersky.com\/products-services\/home-computer-security\/mobile-security (2014)"},{"key":"233_CR8","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S., Song, D., Bryant, R.: Semantics-aware malware detection. In: Proceedings of IEEE Symposium Security and Privacy, pp. 32\u201346 (2005).","DOI":"10.1109\/SP.2005.20"},{"key":"233_CR9","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1007\/s11416-006-0024-y","volume":"2","author":"JA Morales","year":"2006","unstructured":"Morales, J.A., Clarke, P.J., Deng, Y., Kibria, B.M.G.: Testing and evaluating virus detectors for handheld devices. Comput. Virol. 2, 135\u2013147 (2006)","journal-title":"Comput. Virol."},{"key":"233_CR10","unstructured":"Kaspersky: Using heuristic analysis in Kaspersky anti-virus. http:\/\/www.kaspersky.com (2010)"},{"key":"233_CR11","unstructured":"Necula, G.C.: Sandbox technology inside AV scanners. In: Proceedings of Virus Bulletin Conference (2001)."},{"key":"233_CR12","unstructured":"Goldberg, I., Wagner, D., Thomas, R., Brewer, E.A.: A secure environment for untrusted helper applications confining the wily hacker. In: Proceedings of Conference USENIX Security Symposium, pp. 1\u20131 (1996)."},{"key":"233_CR13","unstructured":"Peterson, D.S., Bishop, M., Pandey, R.: A flexible containment mechanism for executing untrusted code. In: Proceedings of USENIX Security Symposium, pp. 207\u2013225 (2002)."},{"key":"233_CR14","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1007\/s11416-008-0086-0","volume":"4","author":"G Jacob","year":"2008","unstructured":"Jacob, G., Debar, H., Filiol, E.: Behavioral detection of malware: from a survey towards an established taxonomy. Comput. Virol. 4, 251\u2013266 (2008)","journal-title":"Comput. Virol."},{"key":"233_CR15","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1007\/s11036-008-0113-x","volume":"14","author":"A-D Schmidt","year":"2009","unstructured":"Schmidt, A.-D., Peters, F., Lamour, F., Scheel, C., \u00c7amtepe, S.A., Albayrak, S.: Monitoring smartphones for anomaly detection. Mobile Netw. Appl. 14, 92\u2013106 (2009)","journal-title":"Mobile Netw. Appl."},{"key":"233_CR16","unstructured":"Jacob, G., Debar, H., Filiol, E.: Malware behavioral detection by attribute-automata using abstraction from platform and language. In: Proceedings of International Symposium, Recent Advances in Intrusion Detection, pp. 81\u2013100 (2009)."},{"key":"233_CR17","doi-asserted-by":"crossref","unstructured":"Wang, H., Jha, S., Ganapathy, V.: Netspy: automatic generation of spyware signatures for NIDS. In: Proceedings of Computer Security Applications Conference, pp. 99\u2013108 (2006).","DOI":"10.1109\/ACSAC.2006.34"},{"key":"233_CR18","unstructured":"Bose, A., Hu, X., Shin, K.G., Park, T.: Behavioral detection of malware on mobile handsets. In: Proceedings of International Conference on Mobile Systems, Applications, and Services, pp. 225\u2013238 (2008)."},{"key":"233_CR19","unstructured":"Xie, L., Zhang, X., Seifert, J.-P., Zhu, S.: pBMDS: a behavior-based malware detection system for cellphone devices. In: Proceedings of ACM Conference on Wireless, Network Security, pp. 37\u201348 (2010)."},{"key":"233_CR20","unstructured":"Forrest, S., Hofmeyr, S., Somayaji, T., Longstaff, T.: A sense of self for Unix processes. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 120\u2013128 (1996)."},{"key":"233_CR21","doi-asserted-by":"crossref","unstructured":"Sekar, R., Bendre, M., Dhurjati, D., Bollineni, P.: A fast automaton-based method for detecting anomalous program behaviors. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 144\u2013155 (2001).","DOI":"10.1109\/SECPRI.2001.924295"},{"key":"233_CR22","doi-asserted-by":"crossref","unstructured":"Warrender, C., Forrest, S., Pearlmutter, B.: Detecting intrusions using system calls: Alternative data models. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 133\u2013145 (1999).","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"233_CR23","unstructured":"Baratloo, A., Singh, N., Tsai, T.: Transparent run-time defense against stack smashing attacks. In: Proceedings of USENIX Annual Technical Conference, pp. 251\u2013262 (2000)."},{"key":"233_CR24","unstructured":"Kiriansky, V., Bruening, D., Amarasinghe, S.P.: Secure execution via program shepherding. In: Proceedings of USENIX Security Symposium, pp. 191\u2013206 (2002)."},{"key":"233_CR25","unstructured":"Nethercote, N: Bounds-checking entire programs without recompiling. In: Proceedings of Workshop, Semantics, Program Analysis, and Computing Environments for Memory Management (2004)."},{"key":"233_CR26","doi-asserted-by":"crossref","unstructured":"Cheng, J., Wong, S.H.Y., Yang, H., Lu, S.: SmartSiren: virus detection and alert for smartphones. In: Proceedings of MobiSys, pp. 133\u2013145 (2007).","DOI":"10.1145\/1247660.1247690"},{"key":"233_CR27","unstructured":"Bose, A., Shin, K.G.: Proactive security for mobile messaging networks. In: Proceedings of ACM Workshop on Wireless, Security, pp. 95\u2013104 (2006)."},{"key":"233_CR28","doi-asserted-by":"crossref","unstructured":"Necula, G.C.: Proof-carrying code. In: Proceedings of ACM Symposium on Principles of Programming Languages, pp. 106\u2013119 (1997).","DOI":"10.1145\/263699.263712"},{"key":"233_CR29","doi-asserted-by":"crossref","unstructured":"Necula, G.C., Lee, P.: The design and implementation of a certifying compiler. In: Proceedings of ACM Conference on Programming Language Design and Implementation, pp. 333\u2013344 (1998).","DOI":"10.1145\/277652.277752"},{"key":"233_CR30","doi-asserted-by":"crossref","unstructured":"Sekar, R., Venkatakrishnan, V., Basu, S., Bhatkar, S., DuVarney, D.C.: Model-carrying code: a practical approach for safe execution of untrusted applications. In: Proceedings of ACM Symposium on Operating Systems Principles, pp. 15\u201328 (2003).","DOI":"10.1145\/1165389.945448"},{"key":"233_CR31","unstructured":"Liang Z., Sekar, R.: Automatic generation of buffer overflow attack signatures: an approach based on program behavior models. In: Proceedings of Computer Security Applications Conference, pp. 215\u2013224 (2005)."},{"key":"233_CR32","doi-asserted-by":"crossref","unstructured":"Luk, C., Cohn, R., Muth, R., Patil, H., Klauser, A., Lowney, G., Wallace, S., Janapa, V., Hazelwood R.K.: Pin: building customized program analysis tools with dynamic instrumentation. In: Proceedings of ACM Conference on Programming Language Design and Implementation, pp. 190\u2013200 (2005).","DOI":"10.1145\/1064978.1065034"},{"key":"233_CR33","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Proceedings of Symposium on Network and Distributed System Security (2005)."},{"key":"233_CR34","unstructured":"Uppuluri, P., Sekar, R.: Experiences with specification-based intrusion detection. In: Proceedings of International Symposium, Recent Advances in Intrusion Detection, pp. 172\u2013189 (2001)."},{"key":"233_CR35","doi-asserted-by":"crossref","unstructured":"Shahriar, H., Zulkernine, M.: Classification of static analysis-based buffer overflow detectors. In: Proceedings of International Conference on Secure Software Integration and Reliability Improvement Companion, pp. 94\u2013101 (2010).","DOI":"10.1109\/SSIRI-C.2010.28"},{"key":"233_CR36","unstructured":"Dill, V.: A decision procedure for bitvectors and arrays. In: Proceedings of International Conference on Computer-Aided Verification, pp. 519\u2013531 (2007)."},{"key":"233_CR37","unstructured":"Cadar, C., Ganesh, V., Pawlowski, P.M., Dill, D.L., Engler, D.R.: Exe: automatically generating inputs of death. In: Proceedings of ACM Conference on Computer and Communications, Security, pp. 322\u2013335 (2006)."},{"key":"233_CR38","unstructured":"Flawfinder, v1. http:\/\/www.dwheeler.com\/flawfinder (2011)"},{"key":"233_CR39","unstructured":"VXHEAVENS. http:\/\/forum.vxheavens.com (2011)"},{"key":"233_CR40","unstructured":"Windows, Linux Virus Collection & Creation Tools. http:\/\/virus-codes.blogspot.com (2011)"},{"key":"233_CR41","unstructured":"The Ultimate Packer for eXecutables. http:\/\/upx.sourceforge.net\/ (2013)"},{"key":"233_CR42","unstructured":"F-PROT. http:\/\/www.f-prot.com (2011)"},{"key":"233_CR43","unstructured":"ClamAV. http:\/\/www.clamav.net (2011)"},{"key":"233_CR44","unstructured":"Avira. http:\/\/www.avira.com (2011)"},{"key":"233_CR45","unstructured":"AVG. http:\/\/www.avg.com (2011)"},{"key":"233_CR46","unstructured":"Bircher, W.L., Law, J., Valluri, M., John, L.K.: Effective use of performance monitoring counters for run-time prediction of power. University of Texas at Austin, Technical, Report, TR-041104-01 (2004)."}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0233-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-014-0233-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0233-1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T04:48:45Z","timestamp":1746161325000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-014-0233-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,3,27]]},"references-count":46,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2014,10]]}},"alternative-id":["233"],"URL":"https:\/\/doi.org\/10.1007\/s10207-014-0233-1","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,3,27]]}}}