{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2023,7,26]],"date-time":"2023-07-26T04:56:08Z","timestamp":1690347368148},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2012,9,15]],"date-time":"2012-09-15T00:00:00Z","timestamp":1347667200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Mobile Netw Appl"],"published-print":{"date-parts":[[2013,4]]},"DOI":"10.1007\/s11036-012-0392-0","type":"journal-article","created":{"date-parts":[[2012,9,15]],"date-time":"2012-09-15T05:48:54Z","timestamp":1347688134000},"page":"271-292","source":"Crossref","is-referenced-by-count":13,"title":["ChameleonSoft: Software Behavior Encryption for Moving Target Defense"],"prefix":"10.1007","volume":"18","author":[{"given":"Mohamed","family":"Azab","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohamed","family":"Eltoweissy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2012,9,15]]},"reference":[{"key":"392_CR1","unstructured":"Cohen F (1985) Computer viruses. PhD thesis, University of Southern California"},{"issue":"3","key":"392_CR2","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1162\/artl.1994.1.3.249","volume":"1","author":"EH Spafford","year":"1994","unstructured":"Spafford EH (1994) Computer viruses as artificial life. J Artif Life 1(3):249\u2013265","journal-title":"J Artif Life"},{"key":"392_CR3","first-page":"149","volume":"77","author":"A Avizienis","year":"1977","unstructured":"Avizienis A, Chen L (1977) On the implementation of n-version programming for software fault tolerance during execution. IEEE COMPSAC 77:149\u2013155","journal-title":"IEEE COMPSAC."},{"key":"392_CR4","unstructured":"Wood J, Jackson K (2012) How cephalopods change color. Available: http:\/\/www.thecephalopodpage.org\/cephschool\/"},{"issue":"7","key":"392_CR5","doi-asserted-by":"crossref","first-page":"692","DOI":"10.1109\/32.83905","volume":"17","author":"DE Eckhardt","year":"1991","unstructured":"Eckhardt DE, Caglayan AK, Knight JC, Lee LD, McAllister DF, Vouk MA, Kelly JJP (1991) An experimental evaluation of software redundancy as a strategy for improving reliability. IEEE Trans Software Eng 17(7):692\u2013702","journal-title":"IEEE Trans Software Eng"},{"key":"392_CR6","doi-asserted-by":"crossref","first-page":"220","DOI":"10.1109\/TSE.1975.6312842","volume":"1","author":"B Randell","year":"1975","unstructured":"Randell B (1975) System structure for software fault tolerance. IEEE Trans Software Eng 1:220\u2013232","journal-title":"IEEE Trans Software Eng"},{"issue":"1","key":"392_CR7","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1109\/TSE.1986.6312924","volume":"12","author":"JC Knight","year":"1986","unstructured":"Knight JC, Leveson NG (1986) An experimental evaluation of the assumption of independence in multiversion programming. IEEE Trans Software Eng 12(1):96\u2013109","journal-title":"IEEE Trans Software Eng"},{"issue":"6","key":"392_CR8","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1109\/52.636672","volume":"14","author":"L Hatton","year":"1997","unstructured":"Hatton L (1997) N-version design versus one good version. IEEE Software 14(6):71\u201376","journal-title":"IEEE Software"},{"issue":"6","key":"392_CR9","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1016\/0167-4048(93)90054-9","volume":"12","author":"F Cohen","year":"1993","unstructured":"Cohen F (1993) Operating system protection through program evolution. Comput Secur 12(6):565\u2013584","journal-title":"Comput Secur"},{"key":"392_CR10","volume-title":"A specialization toolkit to increase the diversity of operating systems","author":"C Pu","year":"1996","unstructured":"Pu C, Black A, Cowan C, Walpole J (1996) A specialization toolkit to increase the diversity of operating systems. ICMAS Workshop on Immunity-Based Systems, Nara"},{"key":"392_CR11","unstructured":"Just JE, Cornwell M (2004) Review and analysis of synthetic diversity for breaking monocultures. ACM Workshop on Rapid Malcode (WORM \u201904): 23\u201332"},{"issue":"1","key":"392_CR12","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1145\/1055626.1055632","volume":"33","author":"DA Holland","year":"2005","unstructured":"Holland DA, Lim AT, Seltzer MI (2005) An architecture a day keeps the hacker away. SIGARCH Comput Architect News 33(1):34\u201341","journal-title":"SIGARCH Comput Architect News"},{"key":"392_CR13","unstructured":"Chew M, Song D (2002) Mitigating buffer overflows by operating system randomization. Technical Report CMU-CS-02-197, Department of Computer Science, Carnegie Mellon University"},{"key":"392_CR14","unstructured":"Xu J, Kalbarczyk Z, Iyer RK (2003) Transparent runtime randomization for security. 22nd International Symposium on Reliable Distributed Systems (SRDS\u201903): 260\u2013269"},{"key":"392_CR15","doi-asserted-by":"crossref","unstructured":"LKnight JC, Davidson JW, Evans D, Nguyen-Tuong A, Wang C (2007) Genesis: A Framework for Achieving Software Component Diversity. Technical Report AFRL-IF-RS-TR-2007-9, University of Virginia","DOI":"10.21236\/ADA462289"},{"key":"392_CR16","doi-asserted-by":"crossref","unstructured":"Forrest S, Somayaji A, Ackley D (1997) Building diverse computer systems. 6th Workshop on Hot Topics in Operating Systems (HotOS-VI), pp 67\u201372","DOI":"10.1109\/HOTOS.1997.595185"},{"key":"392_CR17","unstructured":"Salamat B, Jackson T, Gal A, Franz M (2009) Intrusion detection using parallel execution and monitoring of program variants in user-space. Eurosys 2009"},{"key":"392_CR18","unstructured":"Salamat B, Gal A, Franz M (2008) Reverse stack execution in a multi-variant execution environment. Workshop on Compiler and Architectural Techniques for Application Reliability and Security (CATARS\u201908)"},{"key":"392_CR19","doi-asserted-by":"crossref","unstructured":"Salamat B, Gal A, Jackson T, Manivannan K, Wagner G, Franz M (2008) Multi-variant program execution: Using multi-core systems to defuse buffer-overflow vulnerabilities. International Workshop on Multi-Core Computing Systems (MuCoCoS 2008)","DOI":"10.1109\/CISIS.2008.136"},{"key":"392_CR20","doi-asserted-by":"crossref","unstructured":"Jackson T, Salamat B, Wagner G, Wimmer Ch, Franz M (2010) On the effectiveness of multi-variant program execution for vulnerability detection and prevention. International Workshop on Security Measurements and Metrics (MetriSec 2010)","DOI":"10.1145\/1853919.1853929"},{"key":"392_CR21","doi-asserted-by":"crossref","unstructured":"Franz M (2010) E unibus pluram: massive-scale software diversity as a defense mechanism. New Security Paradigms Workshop 2010 (NSPW 2010)","DOI":"10.1145\/1900546.1900550"},{"key":"392_CR22","doi-asserted-by":"crossref","unstructured":"Jackson T, Wimmer Ch, Franz M (2010) Multi-variant program execution for vulnerability detection and analysis. Sixth Annual Cyber Security and Information Intelligence Research Workshop (CSIIRW\u201910)","DOI":"10.1145\/1852666.1852708"},{"key":"392_CR23","doi-asserted-by":"crossref","unstructured":"Salamat B, Jackson T, Wagner G, Wimmer Ch, Franz M (2011) Run-time defense against code injection attacks using replicated execution. IEEE Transactions on Dependable and Secure Computing. IEEE Computer Society, doi: 10.1109\/TDSC.2011.18","DOI":"10.1109\/TDSC.2011.18"},{"key":"392_CR24","unstructured":"Pfleeger CP, Pfleeger SL (2003) Security in computing. Prentice Hall, Third Edition. p 62,ISBN:0-13-035548-8."},{"key":"392_CR25","doi-asserted-by":"crossref","unstructured":"Barrantes E, Ackley D, Palmer T, Stefanovic D, Zovi D (2003) Randomized instruction set emulation to disrupt binary code injection attacks. In Proceedings of the ACM Conference on Computer and Communications Security. ACM Press, pp 281\u2013289","DOI":"10.1145\/948109.948147"},{"key":"392_CR26","doi-asserted-by":"crossref","unstructured":"Kc G, Keromytis A, Prevelakis V (2003) Countering code-injection attacks with instruction-set randomization. In Proceedings of the ACM Conference on Computer and Communications Security, pages 272\u2013280. ACM Press","DOI":"10.1145\/948109.948146"},{"key":"392_CR27","unstructured":"PaX Team (2012) PaX address space layout randomization (ASLR). Available: http:\/\/pax.grsecurity.net\/docs\/aslr.txt"},{"key":"392_CR28","unstructured":"Cox B, Evans D, Filipi A, Rowanhill J, Hu W, Davidson J, Knight J, Nguyen-Tuong A, Hiser J (2006) N-variant systems: a secretless framework for security through diversity. In Proceedings of the 15th USENIX Security Symposium"},{"key":"392_CR29","unstructured":"Cowan C, Pu C, Maier D, Walpole J, Bakke P, Beattie S, Grier A, Wagle P, Zhang Q, Hinton H (1998) StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks. In Proceedings of the 7th USENIX Security Symposium"},{"key":"392_CR30","unstructured":"Avizienis A, Chen L (1977) On the implementation of N-version programming for software fault-tolerance during program execution. International Computer Software and Applications Conference"},{"key":"392_CR31","unstructured":"Chen L, Avizienis A (1978) N-version programming: a fault tolerance approach to reliability of software operation. 8th International Symposium on Fault-Tolerant Computing"},{"key":"392_CR32","unstructured":"Joseph M (1988) Architectural issues in fault- tolerant, secure computing systems. Ph.D. Dissertation. UCLA Department of Computer Science"},{"key":"392_CR33","unstructured":"Linger R, Daly T, Pleszkoch M (2011) Function extraction (FX) research for computation of software behavior: 2010 development and application of semantic reduction theorems for behavior analysis. Research Report for the Air Force Office of Scientific Research Mathematics and Information Science Directorate, 2011"},{"key":"392_CR34","doi-asserted-by":"crossref","unstructured":"Bartholomew R, Burns L, Daly T, Linger R, Prowell S (2007) Function extraction: automated behavior computation for aerospace software verification and certification. Proceedings of 2007 AIAA Aerospace Conference, Monterey, CA, 3: 2145\u20132153.","DOI":"10.2514\/6.2007-2929"},{"key":"392_CR35","unstructured":"Spruijt R (2012) Application virtualization smackdown: head-to-head analysis of Citrix, Endeavors, InstallFree, Microsoft, Spoon, Symantec and VMware. Available: http:\/\/www.brianmadden.com\/blogs\/rubenspruijt\/archive\/2010\/09\/22\/application-virtualization-smackdown-head-to-head-analysis-of-endeavors-citrix-installfree-microsoft-spoon-symantec-and-vmware.aspx"},{"key":"392_CR36","doi-asserted-by":"crossref","unstructured":"Nguyen-Tuong A, Wang A, Hiser J, Knight J, Davidson J (2010) On the effectiveness of the metamorphic shield. The Fourth European Conference on Software Architecture: Companion Volume, ECSA \u201910, pages 170\u2013174, New York, NY, USA, ACM","DOI":"10.1145\/1842752.1842788"},{"key":"392_CR37","doi-asserted-by":"crossref","unstructured":"Buchanan E, Roemer R, Shacham H, Savage S (2008) When good instructions go bad: generalizing return-oriented programming to RISC. 15th ACM Conference on Computer and Communications Security (CCS)","DOI":"10.1145\/1455770.1455776"},{"key":"392_CR38","unstructured":"Peslyak A (1997) Return-to-libc Attack. Bugtraq mailing list"},{"key":"392_CR39","doi-asserted-by":"crossref","unstructured":"Hardy N (1998) The confused deputy (or why capabilities might have been invented). ACM SIGOPS Operating Systems Review 22(4)","DOI":"10.1145\/54289.871709"},{"key":"392_CR40","volume-title":"Cryptographic algorithm metrics","author":"N Jorstad","year":"1997","unstructured":"Jorstad N, Landgrave TS (1997) Cryptographic algorithm metrics. 20th National Information Systems Security Conference, Baltimore"},{"key":"392_CR41","doi-asserted-by":"crossref","unstructured":"Azab M, Hassan R, Eltoweissy M (2011) ChameleonSoft: a moving target defense system. 7th International Conference on Collaborative Computing: Networking, Applications and Worksharing, (CollaborateCom'11)","DOI":"10.4108\/icst.collaboratecom.2011.247115"}],"container-title":["Mobile Networks and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-012-0392-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11036-012-0392-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-012-0392-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,3]],"date-time":"2019-07-03T19:47:04Z","timestamp":1562183224000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11036-012-0392-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,9,15]]},"references-count":41,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2013,4]]}},"alternative-id":["392"],"URL":"https:\/\/doi.org\/10.1007\/s11036-012-0392-0","relation":{},"ISSN":["1383-469X","1572-8153"],"issn-type":[{"value":"1383-469X","type":"print"},{"value":"1572-8153","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,9,15]]}}}