{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T15:08:01Z","timestamp":1784646481890,"version":"3.55.0"},"reference-count":61,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2006,12,23]],"date-time":"2006-12-23T00:00:00Z","timestamp":1166832000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J Comput Virol"],"published-print":{"date-parts":[[2007,2,7]]},"DOI":"10.1007\/s11416-006-0031-z","type":"journal-article","created":{"date-parts":[[2006,12,22]],"date-time":"2006-12-22T10:54:09Z","timestamp":1166784849000},"page":"257-274","source":"Crossref","is-referenced-by-count":20,"title":["Network-level polymorphic shellcode detection using emulation"],"prefix":"10.1007","volume":"2","author":[{"given":"Michalis","family":"Polychronakis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kostas G.","family":"Anagnostakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evangelos P.","family":"Markatos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2006,12,23]]},"reference":[{"key":"31_CR1","unstructured":"sk, History and advances in windows shellcode. Phrack 11(62), (2004)"},{"key":"31_CR2","unstructured":"Kim, H.-A., Karp, B.: Autograph: toward automated, distributed worm signature detection. In: Proceedings of the 13th USENIX Security Symposium, pp. 271\u2013286, (2004)"},{"key":"31_CR3","unstructured":"Singh, S., Estan, C., Varghese, G., Savage, S.: Automated worm fingerprinting. In: Proceedings of the 6th Symposium on Operating Systems Design & Implementation (OSDI), (2004)"},{"key":"31_CR4","doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., Song, D.: Polygraph: automatically Generating signatures for polymorphic worms. In: Proceedings of the IEEE Security & Privacy Symposium, pp. 226\u2013241, (2005)","DOI":"10.1109\/SP.2005.15"},{"key":"31_CR5","unstructured":"Tang, Y., Chen, S.: Defending against internet worms: a signature-based approach. In: Proceedings of the 24th Annual Joint Conference of IEEE Computer and Communication societies (INFOCOM), (2005)"},{"key":"31_CR6","doi-asserted-by":"crossref","unstructured":"Wang, K., Stolfo, S.J.: Anomalous payload-based network intrusion detection. In: Proceedings of the 7th International Symposium on Recent Advanced in Intrusion Detection (RAID), pp. 201\u2013222, (2004)","DOI":"10.1007\/978-3-540-30143-1_11"},{"key":"31_CR7","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Kirda, E., Mutz, D., Robertson, W., Vigna, G.: Polymorphic worm detection using structural information of executables. In: Proceedings of the International Symposium on Recent Advances in Intrusion Detection (RAID), (2005)","DOI":"10.1007\/11663812_11"},{"key":"31_CR8","doi-asserted-by":"crossref","unstructured":"Chinchani, R., Berg, E.V.D.: A fast static analysis approach to detect exploit code inside network flows. In: Proceedings of the International Symposium on Recent Advances in Intrusion Detection (RAID), (2005)","DOI":"10.1007\/11663812_15"},{"key":"31_CR9","unstructured":"Wang, X., Pan, C.-C., Liu, P., Zhu, S.: Sigfree: a signature-free buffer overflow attack blocker. In: Proceedings of the USENIX Security Symposium (2006)"},{"key":"31_CR10","unstructured":"Li, Z., Sanghi, M., Chen, Y., Kao, M.-Y., Chavez, B.: Hamsa: fast signature generation for zero-day polymorphic worms with provable attack resilience. In: Proceedings of the 2006 IEEE Symposium on Security and Privacy, pp. 32\u201347, 2006"},{"key":"31_CR11","unstructured":"Sz\u00f6r, P.: The art of computer virus research and defense. Addison-Wesley Professional, (2005)"},{"key":"31_CR12","unstructured":"Sz\u00f6r, P., Ferrie, P.: Hunting for metamorphic. In: Proceedings of the virus bulletin conference. pp. 123\u2013144, (2001)"},{"key":"31_CR13","unstructured":"Christodorescu, M., Jha, S.: Static analysis of executables to detect malicious patterns. In: Proceedings of the 12th USENIX Security Symposium (Security\u201903), (2003)"},{"key":"31_CR14","unstructured":"Roesch, M.: Snort: lightweight intrusion detection for networks. In: Proceedings of USENIX LISA \u201999, November 1999, (software available from http:\/\/www.snort.org\/)"},{"key":"31_CR15","unstructured":"Paxson, V.: Bro: a system for detecting network intruders in real-time. In: Proceedings of the 7th USENIX Security Symposium, (1998)"},{"issue":"6","key":"31_CR16","first-page":"55","volume":"30","author":"C. Jordan","year":"2005","unstructured":"Jordan C. (2005). Writing detection signatures. USENIX login 30(6): 55\u201361","journal-title":"USENIX login"},{"key":"31_CR17","unstructured":"K2, ADMmutate, http:\/\/www.ktwo.ca\/ADMmutate-0.8.4.tar. gz, (2001)"},{"key":"31_CR18","unstructured":"Detristan, T., Ulenspiegel, T., Malcom, Y., Underduk, M.: Polymorphic shellcode engine using spectrum analysis. Phrack 11(61), (2003)"},{"key":"31_CR19","unstructured":"Rix, Writing IA32 alphanumeric shellcodes. Phrack 11(57), (2001)"},{"key":"31_CR20","unstructured":"Bania, P.: TAPiON, http:\/\/pb.specialised.info\/all\/tapion\/, (2005)"},{"key":"31_CR21","doi-asserted-by":"crossref","unstructured":"Toth, T., Kruegel, C.: Accurate buffer overflow detection via abstract payload execution. In: Proceedings of the 5th Symposium on Recent Advances in Intrusion Detection (RAID), (2002)","DOI":"10.1007\/3-540-36084-0_15"},{"key":"31_CR22","doi-asserted-by":"crossref","unstructured":"Akritidis, P., Markatos, E.P., Polychronakis, M., K.: STRIDE: Polymorphic sled detection through instruction sequence analysis. In: Proceedings of the 20th IFIP International Information Security Conference (IFIP\/SEC), (2005)","DOI":"10.1007\/0-387-25660-1_25"},{"key":"31_CR23","doi-asserted-by":"crossref","unstructured":"Crandall, J.R., Wu, S.F., Chong, F.T.: Experiences using minos as a tool for capturing and analyzing novel worms for unknown vulnerabilities. In: Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), (2005)","DOI":"10.1007\/11506881_3"},{"key":"31_CR24","doi-asserted-by":"crossref","unstructured":"Pasupulati, A., Coit, J., Levitt, K., Wu, S., Li, S., Kuo, J., Fan, K.: Buttercup: on network-based detection of polymorphic buffer overflow vulnerabilities. In: Proceedings of the Network Operations and Management Symposium (NOMS), pp. 235\u2013248, (2004)","DOI":"10.1109\/NOMS.2004.1317662"},{"issue":"4","key":"31_CR25","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/MSP.2004.36","volume":"2","author":"J. Pincus","year":"2004","unstructured":"Pincus J. and Baker B. (2004). Beyond stack smashing: recent advances in exploiting buffer overflows. IEEE Security Privacy 2(4): 20\u201327","journal-title":"IEEE Security Privacy"},{"key":"31_CR26","doi-asserted-by":"crossref","unstructured":"Kreibich, C., Crowcroft, J.: Honeycomb\u2013creating intrusion detection signatures using honeypots. In: Proceedings of the Second Workshop on Hot Topics in Networks (HotNets-II), (2003)","DOI":"10.1145\/972374.972384"},{"key":"31_CR27","unstructured":"Kolesnikov, O., Dagon, D., Lee, W.: Advanced polymorphic worms: evading IDS by blending in with traffic. In: College of Computing, Georgia of Technology, Atlanta, GA 30332, http:\/\/www.cc.gatech.edu\/~ok\/w\/ok_pw.pdf, (2004)"},{"key":"31_CR28","doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., Song, D.: Paragraph: thwarting signature learning by training maliciously. In: Proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection (RAID), (2006)","DOI":"10.1007\/11856214_5"},{"key":"31_CR29","doi-asserted-by":"crossref","unstructured":"Payer, U., Teufl, P., Lamberger, M.: Hybrid engine for polymorphic shellcode detection. In: Proceedings of the conference on detection of intrusions and malware and vulnerability assessment (DIMVA), pp. 19\u201331, (2005)","DOI":"10.1007\/11506881_2"},{"key":"31_CR30","doi-asserted-by":"crossref","unstructured":"Linn, C., Debray, S.: Obfuscation of executable code to improve resistance to static disassembly. In: Proceedings of the 10th ACM conference on Computer and communications security (CCS), pp. 290\u2013299, (2003)","DOI":"10.1145\/948109.948149"},{"key":"31_CR31","unstructured":"Aycock, J., deGraaf, R., Jacobson, M.: Anti-disassembly using cryptographic hash functions. Department of Computer Science, University of Calgary, Technical Report, pp. 793\u2013824, (2005)"},{"key":"31_CR32","doi-asserted-by":"crossref","unstructured":"Venable, M., Chouchane, M.R., Karim, M.E., Lakhotia, A.: Analyzing memory accesses in obfuscated x86 executables. In: Proceedings of the conference on detection of intrusions and malware and vulnerability assessment (DIMVA), (2005)","DOI":"10.1007\/11506881_1"},{"issue":"8","key":"31_CR33","doi-asserted-by":"crossref","first-page":"735","DOI":"10.1109\/TSE.2002.1027797","volume":"28","author":"C.S. Collberg","year":"2002","unstructured":"Collberg C.S. and Thomborson C. (2002). Watermarking, tamper-proffing and obfuscation: tools for software protection. IEEE Trans. Softw. Eng. 28(8): 735\u2013746","journal-title":"IEEE Trans. Softw. Eng."},{"key":"31_CR34","unstructured":"Wang, C., Hill, J., Knight, J., Davidson, J.: Software tamper resistance: Obstructing static analysis of programs. University of Virginia, Technical Report CS-2000\u201312, (2000)"},{"key":"31_CR35","doi-asserted-by":"crossref","unstructured":"Madou, M., Anckaert, B., Moseley, P., Debray, S., Sutter, B.D., Bosschere, K.D.: Software protection through dynamic code mutation. In: Proceedings of the 6th International Workshop on Information Security Applications (WISA), pp. 194\u2013206, (2005)","DOI":"10.1007\/11604938_15"},{"key":"31_CR36","doi-asserted-by":"crossref","unstructured":"Schwarz, B., Debray, S., Andrews, G.: Disassembly of executable code revisited. In: Proceedings of the ninth working conference on reverse engineering (WCRE), (2002)","DOI":"10.1109\/WCRE.2002.1173063"},{"key":"31_CR37","unstructured":"Prasad, M., cker Chiueh, T.: A binary rewriting defense against stack based overflow attacks. In: Proceedings of the USENIX annual technical conference, (2003)"},{"key":"31_CR38","unstructured":"Kruegel, C., Robertson, W., Valeur, F., Vigna, G.: Static disassembly of obfuscated binaries. In: Proceedings of the USENIX security symposium, pp. 255\u2013270, (2004)"},{"issue":"6","key":"31_CR39","doi-asserted-by":"crossref","first-page":"565","DOI":"10.1016\/0167-4048(93)90054-9","volume":"12","author":"F.B. Cohen","year":"1993","unstructured":"Cohen F.B. (1993). Operating system protection through program evolution. Comput. Sec. 12(6): 565\u2013584","journal-title":"Comput. Sec."},{"key":"31_CR40","unstructured":"Metasploit project, http:\/\/www.metasploit.com\/, (2006)"},{"issue":"7","key":"31_CR41","doi-asserted-by":"crossref","first-page":"811","DOI":"10.1002\/spe.4380250706","volume":"25","author":"C. Cifuentes","year":"1995","unstructured":"Cifuentes C. and Gough K.J. (1995). Decompilation of binary programs. Softw. Prac. Exp. 25(7): 811\u2013829","journal-title":"Softw. Prac. Exp."},{"key":"31_CR42","doi-asserted-by":"crossref","unstructured":"Balakrishnan, G., Reps, T.: Analyzing memory accesses in x86 executables. In: Proceedings of the International Conference on Compiler Construction (CC), (2004)","DOI":"10.1007\/978-3-540-24723-4_2"},{"key":"31_CR43","unstructured":"Noir, GetPC code (was: Shellcode from ASCII), http:\/\/www. securityfocus.com\/ archive\/82\/327100\/2006-01-03\/1, June 2003"},{"key":"31_CR44","unstructured":"Ionescu, C.: GetPC code (was: Shellcode from ASCII), http:\/\/ www.securityfocus.com\/archive\/82\/327348\/2006-01-03\/1, July 2003"},{"key":"31_CR45","unstructured":"Wever, B.-J.: Alpha 2, (2004), http:\/\/www.edup.tudelft.nl\/bjwever\/src\/alpha2.c"},{"key":"31_CR46","unstructured":"Perriot, F., Ferrie, P., Sz\u00f6r, P.: Striking similarities. Virus Bull., pp. 4\u20136, (2002)"},{"key":"31_CR47","unstructured":"Obscou, Building IA32 \u2018unicode-proof\u2019 shellcodes. Phrack 11(61), (2003)"},{"key":"31_CR48","doi-asserted-by":"crossref","unstructured":"Tubella, J., Gonz\u00e1lez, A.: Control speculation in multithreaded processors through dynamic loop detection. In: Proceedings of the 4th International Symposium on High- Performance Computer Architecture (HPCA), (1998)","DOI":"10.1109\/HPCA.1998.650542"},{"key":"31_CR49","unstructured":"McCanne, S., Leres, C., Jacobson, V.: Libpcap. http:\/\/www.tcpdump.org\/, (2006)"},{"key":"31_CR50","unstructured":"Wojtczuk, R.: Libnids. http:\/\/libnids.sourceforge.net\/, (2006)"},{"key":"31_CR51","unstructured":"jt, Libdasm. http:\/\/www.klake.org\/~jt\/misc\/libdasm-1.4.tar. gz, (2006)"},{"key":"31_CR52","unstructured":"Apache Chunked Encoding Overflow. http:\/\/www.osvdb.org\/838, (2002)"},{"key":"31_CR53","unstructured":"Microsoft Windows RPC DCOM Interface Overflow, http:\/\/www.osvdb.org\/2100, (2003)"},{"key":"31_CR54","unstructured":"Microsoft Windows LSASS Remote Overflow, http:\/\/www. osvdb.org\/5248, (2004)"},{"issue":"6","key":"31_CR55","doi-asserted-by":"crossref","first-page":"370","DOI":"10.1145\/362248.362270","volume":"16","author":"J.R. Bell","year":"1973","unstructured":"Bell J.R. (1973). Threaded code. Comm. of the ACM. 16(6): 370\u2013372","journal-title":"Comm. of the ACM."},{"key":"31_CR56","unstructured":"Bellard, F.: QEMU, a fast and portable dynamic translator. In: Proceedings of the USENIX Annual Technical Conference, FREENIX Track, pp. 41\u201346, (2005)"},{"key":"31_CR57","unstructured":"Bhatkar, S., DuVarney, D.C., Sekar, R.: Address obfuscation: an efficient approach to combat a broad range of memory error exploits. In: Proceedings of the 12th USENIX Security Symposium, (2003)"},{"key":"31_CR58","unstructured":"Anagnostakis, K., Sidiroglou, S., Akritidis, P., Xinidis, K., Markatos, E., Keromytis, A.D.: Detecting targeted attacks using shadow honeypots. In: Proceedings of the 14th USENIX Security Symposium, pp. 129\u2013144, (2005)"},{"key":"31_CR59","doi-asserted-by":"crossref","unstructured":"Hsu, F.-H., Chiueh, T.-C.: CTCP: a transparent centralized tcp\/ip architecture for network security. In: Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC), pp. 335\u2013344, (2004)","DOI":"10.1109\/CSAC.2004.14"},{"key":"31_CR60","doi-asserted-by":"crossref","unstructured":"Liang, Z. Sekar, R.: Fast and automated generation of attack signatures: a basis for building self-protecting servers. In: Proceedings of the 12th ACM conference on Computer and communications security (CCS), pp. 213\u2013222, (2005)","DOI":"10.1145\/1102120.1102150"},{"key":"31_CR61","doi-asserted-by":"crossref","unstructured":"Dreger, H., Kreibich, C., Paxson, V., Sommer, R.: Enhancing the accuracy of network-based intrusion detection with host-based context. In: Proceedings of the Conference on Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA), (2005)","DOI":"10.1007\/11506881_13"}],"container-title":["Journal in Computer Virology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-006-0031-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-006-0031-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-006-0031-z","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T14:45:41Z","timestamp":1559400341000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-006-0031-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,12,23]]},"references-count":61,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2007,2,7]]}},"alternative-id":["31"],"URL":"https:\/\/doi.org\/10.1007\/s11416-006-0031-z","relation":{},"ISSN":["1772-9890","1772-9904"],"issn-type":[{"value":"1772-9890","type":"print"},{"value":"1772-9904","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006,12,23]]}}}