{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T14:01:24Z","timestamp":1762351284054},"reference-count":43,"publisher":"Springer Science and Business Media LLC","license":[{"start":{"date-parts":[[2020,5,4]],"date-time":"2020-05-04T00:00:00Z","timestamp":1588550400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,5,4]],"date-time":"2020-05-04T00:00:00Z","timestamp":1588550400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61272452"],"award-info":[{"award-number":["61272452"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Basic Research Program of China","doi-asserted-by":"publisher","award":["2014CB340601"],"award-info":[{"award-number":["2014CB340601"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Inf Syst Front"],"DOI":"10.1007\/s10796-020-10014-7","type":"journal-article","created":{"date-parts":[[2020,5,4]],"date-time":"2020-05-04T01:02:14Z","timestamp":1588554134000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["HoneyGadget: A Deception Based Approach for Detecting Code Reuse Attacks"],"prefix":"10.1007","author":[{"given":"Xin","family":"Huang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fei","family":"Yan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liqiang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kai","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,5,4]]},"reference":[{"key":"10014_CR1","unstructured":"Abadi, M, Budiu, M, Erlingsson, U, & Ligatti, J. (2005). Control-flow integrity. In Proceedings of the 12th ACM conference on Computer and communications security (pp. 340\u2013353): ACM."},{"key":"10014_CR2","unstructured":"Andersen, S, & Abella, V. (2004). Data execution prevention. changes to functionality in microsoft windows xp service pack 2, part 3: Memory protection technologies."},{"key":"10014_CR3","unstructured":"Araujo, F, Hamlen, K W, Biedermann, S, & Katzenbeisser, S. (2014). From patches to honey-patches: Lightweight attacker misdirection, deception, and disinformation. In Proceedings of the 2014 ACM SIGSAC conference on computer and communications security (pp. 942\u2013953): ACM."},{"issue":"2","key":"10014_CR4","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1145\/2560217.2560219","volume":"57","author":"T Avgerinos","year":"2014","unstructured":"Avgerinos, T, Sang, K C, Rebert, A, Schwartz, E J, Woo, M, & Brumley, D. (2014). Automatic exploit generation. Communications of the Acm, 57(2), 74\u201384.","journal-title":"Communications of the Acm"},{"key":"10014_CR5","unstructured":"Bittau, A, Belay, A, Mashtizadeh, A, Mazi\u00e8res, D., & Boneh, D. (2014). Hacking blind. In 2014 IEEE Symposium on Security and privacy (SP) (pp. 227\u2013242): IEEE."},{"key":"10014_CR6","unstructured":"Bletsch, T, Jiang, X, Freeh, V W, & Liang, Z. (2011). Jump-oriented programming: a new class of code-reuse attack. In Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security (pp. 30\u201340): ACM."},{"key":"10014_CR7","unstructured":"Cadar, C, Dunbar, D, Engler, D R, & et al. (2008). Klee: Unassisted and automatic generation of high-coverage tests for complex systems programs. In OSDI, (Vol. 8 pp. 209\u2013224)."},{"key":"10014_CR8","unstructured":"Carlini, N, & Wagner, D. (2014). Rop is still dangerous: Breaking modern defenses. In USENIX Security Symposium (pp. 385\u2013399)."},{"key":"10014_CR9","unstructured":"Carlini, N, Barresi, A, Payer, M, Wagner, D, & Gross, TR. (2015). Control-flow bending: On the effectiveness of control-flow integrity. In USENIX Security Symposium (pp. 161\u2013176)."},{"key":"10014_CR10","unstructured":"Checkoway, S, Davi, L, Dmitrienko, A, Sadeghi, AR, Shacham, H, & Winandy, M. (2010). Return-oriented programming without returns. In Proceedings of the 17th ACM conference on Computer and communications security (pp. 559\u2013572): ACM."},{"key":"10014_CR11","unstructured":"Chen, Y, Wang, Z, Whalley, D, & Lu, L. (2016). Remix: On-demand live randomization. In Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy (pp. 50\u201361): ACM."},{"key":"10014_CR12","doi-asserted-by":"crossref","unstructured":"Cheng, Y, Zhou, Z, Miao, Y, Ding, X, & Deng, H. (2014). Ropecker: A generic and practical approach for defending against rop attack. Proceedings of the 21th Annual Network and Distributed System Security Symposium (NDSS\u201914).","DOI":"10.14722\/ndss.2014.23156"},{"key":"10014_CR13","unstructured":"Crane, S, Larsen, P, Brunthaler, S, & Franz, M. (2013). Booby trapping software. In Proceedings of the 2013 New Security Paradigms Workshop (pp. 95\u2013106): ACM."},{"key":"10014_CR14","unstructured":"Crane, SJ, Volckaert, S, Schuster, F, Liebchen, C, Larsen, P, Davi, L, Sadeghi, AR, Holz, T, De Sutter, B., & Franz, M. (2015). It\u2019s a trap: Table randomization and protection against function-reuse attacks. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (pp. 243\u2013255): ACM."},{"issue":"2","key":"10014_CR15","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/s10796-017-9755-1","volume":"21","author":"RE Crossler","year":"2019","unstructured":"Crossler, R E, B\u00e9langer, F, & Ormond, D. (2019). The quest for complete security: an empirical analysis of users\u2019 multi-layered protection from security threats. Information Systems Frontiers, 21(2), 343\u2013357.","journal-title":"Information Systems Frontiers"},{"key":"10014_CR16","unstructured":"Durumeric, Z, Bailey, M, & Halderman, JA. (2014). An internet-wide view of internet-wide scanning. In USENIX Security Symposium (pp 65\u201378)."},{"key":"10014_CR17","unstructured":"Evans, I, Fingeret, S, Gonzalez, J, Otgonbaatar, U, Tang, T, Shrobe, H, Sidiroglou-Douskos, S, Rinard, M, & Okhravi, H. (2015). Missing the point (er): on the effectiveness of code pointer integrity. In 2015 IEEE Symposium on Security and privacy (SP) (pp. 781\u2013796): IEEE."},{"key":"10014_CR18","unstructured":"G\u00f6ktas, E., Athanasopoulos, E, Bos, H, & Portokalidis, G. (2014). Out of control: Overcoming control-flow integrity. In 2014 IEEE Symposium on Security and privacy (SP) (pp. 575\u2013589): IEEE."},{"key":"10014_CR19","unstructured":"Guide, P. (2011). Intel\u00ae; 64 and ia-32 architectures software developer\u2019s manual. Volume 3B: System programming Guide, Part 2."},{"key":"10014_CR20","unstructured":"Hiser, J, Nguyen-Tuong, A, Co, M, Hall, M, & Davidson, J W. (2012). Ilr: Where\u2019d my gadgets go?. In 2012 IEEE Symposium on Security and privacy (SP) (pp. 571\u2013585): IEEE."},{"key":"10014_CR21","unstructured":"Huang, X, Yan, F, Zhang, L, & Wang, K. (2019). Honeygadget: A deception based rop detection scheme. In International Conference on Science of Cyber Security (pp. 121\u2013135 ): Springer."},{"key":"10014_CR22","doi-asserted-by":"publisher","unstructured":"Junod, P, Rinaldini, J, Wehrli, J, & Michielin, J. (2015). Obfuscator-LLVM \u2013 software protection for the masses. In Wyseur, B (Ed.) Proceedings of the IEEE\/ACM 1st International Workshop on Software Protection, SPRO\u201915. https:\/\/doi.org\/10.1109\/SPRO.2015.10 (pp. 3\u20139). Firenze: IEEE.","DOI":"10.1109\/SPRO.2015.10"},{"key":"10014_CR23","unstructured":"Kemerlis, VP, Portokalidis, G, & Keromytis, AD. (2012). kguard: lightweight kernel protection against return-to-user attacks. In Presented as part of the 21st {USENIX} Security Symposium ({USENIX} Security 12) (pp. 459\u2013474)."},{"key":"10014_CR24","unstructured":"Kil, C, Jun, J, Bookholt, C, Xu, J, & Ning, P. (2006). Address space layout permutation (aslp): Towards fine-grained randomization of commodity software. In Computer Security Applications Conference, 2006. ACSAC\u201906. 22nd Annual (pp. 339\u2013348): IEEE."},{"key":"10014_CR25","unstructured":"Larabel, M, & Tippett, M. (2011). Phoronix test suite. Phoronix Media, [Online] Available: http:\/\/www.phoronix-test-suitecom\/ [Accessed July 2019]."},{"key":"10014_CR26","unstructured":"Le, L. (2010). Payload already inside: datafire-use for rop exploits. USA: Black Hat."},{"key":"10014_CR27","unstructured":"Liu, Y, Shi, P, Wang, X, Chen, H, Zang, B, & Guan, H. (2017). Transparent and efficient cfi enforcement with intel processor trace. In 2017 IEEE International Symposium on High performance computer architecture (HPCA) (pp. 529\u2013540): IEEE."},{"key":"10014_CR28","unstructured":"Ming, J, Xu, D, Wang, L, & Wu, D. (2015). Loop: Logic-oriented opaque predicate detection in obfuscated binary code. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (pp. 757\u2013768): ACM."},{"key":"10014_CR29","doi-asserted-by":"crossref","unstructured":"Onarlioglu, K, Bilge, L, Lanzi, A, Balzarotti, D, & Kirda, E. (2010). G-free: defeating return-oriented programming through gadget-less binaries. In Proceedings of the 26th Annual Computer Security Applications Conference (pp. 49\u201358).","DOI":"10.1145\/1920261.1920269"},{"key":"10014_CR30","unstructured":"Pappas, V. (2012). kbouncer: Efficient and transparent rop mitigation."},{"key":"10014_CR31","unstructured":"Pappas, V, Polychronakis, M, & Keromytis, AD. (2013). Transparent rop exploit mitigation using indirect branch tracing. In USENIX Security Symposium (pp. 447\u2013462)."},{"key":"10014_CR32","volume-title":"Defending against return-oriented programming","author":"V Pappas","year":"2015","unstructured":"Pappas, V. (2015). Defending against return-oriented programming. New York: Columbia University."},{"key":"10014_CR33","unstructured":"Riden, J, McGeehan, R, Engert, B, & Mueter, M. (2007). Know your enemy: Web application threats, using honeypots to learn about http-based attacks."},{"key":"10014_CR34","unstructured":"Salwan, J. (2011). Ropgadget\u2013gadgets finder and auto-roper."},{"key":"10014_CR35","unstructured":"Schuster, F, Tendyck, T, Liebchen, C, Davi, L, Sadeghi, A R, & Holz, T. (2015). Counterfeit object-oriented programming: on the difficulty of preventing code reuse attacks in c++ applications. In 2015 IEEE Symposium on Security and privacy (SP) (pp. 745\u2013762): IEEE."},{"key":"10014_CR36","unstructured":"Schwartz, EJ, Avgerinos, T, & Brumley, D. (2011). Q: Exploit hardening made easy. In USENIX Security Symposium (pp. 25\u201341)."},{"key":"10014_CR37","unstructured":"Shacham, H. (2007). The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In Proceedings of the 14th ACM conference on Computer and communications security (pp. 552\u2013561): ACM."},{"key":"10014_CR38","doi-asserted-by":"crossref","unstructured":"Silic, M, & Lowry, P B. (2019). Breaking bad in cyberspace: Understanding why and how black hat hackers manage their nerves to commit their virtual crimes. Information Systems Frontiers, 1\u201313.","DOI":"10.1007\/s10796-019-09949-3"},{"key":"10014_CR39","unstructured":"Snow, K Z, Monrose, F, Davi, L, Dmitrienko, A, Liebchen, C, & Sadeghi, A R. (2013). Just-in-time code reuse: on the effectiveness of fine-grained address space layout randomization. In 2013 IEEE Symposium on Security and privacy (SP) (pp. 574\u2013588): IEEE."},{"issue":"6","key":"10014_CR40","doi-asserted-by":"publisher","first-page":"1353","DOI":"10.1007\/s10796-014-9509-2","volume":"17","author":"A Vishwanath","year":"2015","unstructured":"Vishwanath, A. (2015). Diffusion of deception in social media: Social contagion effects and its antecedents. Information Systems Frontiers, 17(6), 1353\u20131367.","journal-title":"Information Systems Frontiers"},{"key":"10014_CR41","unstructured":"Yan, F, Huang, F, Zhao, L, Peng, H, & Wang, Q. (2016). Baseline is fragile: On the effectiveness of stack pivot defense. In 2016 IEEE 22nd International Conference on Parallel and Distributed Systems (ICPADS) (pp. 406\u2013413): IEEE."},{"key":"10014_CR42","unstructured":"Zhang, C, Wei, T, Chen, Z, Duan, L, Szekeres, L, McCamant, S, Song, D, & Zou, W. (2013a). Practical control flow integrity and randomization for binary executables. In 2013 IEEE Symposium on Security and privacy (SP) (pp. 559\u2013573): IEEE."},{"key":"10014_CR43","unstructured":"Zhang, M, & Sekar, R. (2013b). Control flow integrity for cots binaries. In USENIX Security Symposium (pp. 337\u2013 352)."}],"container-title":["Information Systems Frontiers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-020-10014-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10796-020-10014-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10796-020-10014-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,3]],"date-time":"2021-05-03T23:59:34Z","timestamp":1620086374000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10796-020-10014-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,5,4]]},"references-count":43,"alternative-id":["10014"],"URL":"https:\/\/doi.org\/10.1007\/s10796-020-10014-7","relation":{},"ISSN":["1387-3326","1572-9419"],"issn-type":[{"value":"1387-3326","type":"print"},{"value":"1572-9419","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,5,4]]},"assertion":[{"value":"4 May 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}