{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2023,9,13]],"date-time":"2023-09-13T19:38:16Z","timestamp":1694633896548},"reference-count":15,"publisher":"Springer Science and Business Media LLC","issue":"11","license":[{"start":{"date-parts":[[2008,10,16]],"date-time":"2008-10-16T00:00:00Z","timestamp":1224115200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sci. China Ser. F-Inf. Sci."],"published-print":{"date-parts":[[2008,11]]},"DOI":"10.1007\/s11432-008-0150-x","type":"journal-article","created":{"date-parts":[[2008,10,15]],"date-time":"2008-10-15T19:21:56Z","timestamp":1224098516000},"page":"1883-1897","source":"Crossref","is-referenced-by-count":1,"title":["Dynamic emulation based modeling and detection of polymorphic shellcode at the network level"],"prefix":"10.1007","volume":"51","author":[{"given":"LanJia","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"HaiXin","family":"Duan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xing","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2008,10,16]]},"reference":[{"key":"150_CR1","first-page":"123","volume-title":"Proceedings of the Virus Bulletin Conference","author":"P. Szor","year":"2001","unstructured":"Szor P, Ferrie P. Hunting for metamorphic. In: Proceedings of the Virus Bulletin Conference. Oxfordshire: Virus Bulletin Ltd, 2001. 123\u2013144"},{"key":"150_CR2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1007\/11506881_2","volume-title":"Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA\u201905)","author":"U. Payer","year":"2005","unstructured":"Payer U, Lamberger M, Teufl P. Hybrid engine for polymorphic shellcode detection. In: Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA\u201905). Berlin: Springer-Verlag, 2005. 19\u201331"},{"key":"150_CR3","first-page":"284","volume-title":"Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection (RAID\u201905)","author":"R. Chinchani","year":"2005","unstructured":"Chinchani R, Berg E. A fast static analysis approach to detect exploit code inside network flows. In: Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection (RAID\u201905). Berlin: Springer-Verlag, 2005. 284\u2013308"},{"key":"150_CR4","volume-title":"Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection (RAID\u201905)","author":"C. Kruegel","year":"2005","unstructured":"Kruegel C, Kirda E, Mutz D, et al. Polymorphic worm detection using structural information of executables. In: Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection (RAID\u201905). Berlin: Springer-Verlag, 2005"},{"key":"150_CR5","volume-title":"Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment","author":"M. Polychronakis","year":"2006","unstructured":"Polychronakis, M, Anagnostakis K G, Markatos E P. Network-level polymorphic shellcode detection using emulation. In: Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment. Berlin: Springer-Verlag, 2006"},{"key":"150_CR6","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1145\/1229285.1229291","volume-title":"Proceedings of the 2nd ACM Symposium on InformAtion, Computer and Communications Security","author":"Q. Zhang","year":"2007","unstructured":"Zhang Q, Reeves D S, Ning P, et al. Analyzing network traffic to detect self-decrypting exploit code. In: Proceedings of the 2nd ACM Symposium on InformAtion, Computer and Communications Security, New York: ACM, 2007. 4\u201312"},{"key":"150_CR7","first-page":"375","volume-title":"Proceedings of the 20th IFIP International Information Security Conference (SEC\u201905)","author":"P. Akritidis","year":"2005","unstructured":"Akritidis P, Markatos E, Polychronakis M, et al. Stride: Polymorphic sled detection through instruction sequence analysis. In: Proceedings of the 20th IFIP International Information Security Conference (SEC\u201905). Boston: Springer, 2005. 375\u2013392"},{"key":"150_CR8","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1007\/3-540-36084-0_15","volume-title":"Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID\u201902)","author":"T. Toth","year":"2002","unstructured":"Toth T, Kruegel C. Accurate buffer overflow detection via abstract payload execution. In: Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID\u201902). Berlin: Springer-Verlag, 2002. 274\u2013291"},{"key":"150_CR9","first-page":"25","volume-title":"Mathematical Methods, Models and Architectures for Computer Network Security Workshop","author":"U. Payer","year":"2005","unstructured":"Payer U, Teufl P, Kraxberger S, et al. Massive data mining for polymorphic code detection. In: Mathematical Methods, Models and Architectures for Computer Network Security Workshop. Berlin: Springer-Verlag, 2005. 25\u201327"},{"key":"150_CR10","volume-title":"Proceedings of Network Operations and Management Symposium 2004","author":"A. Pasupulati","year":"2004","unstructured":"Pasupulati A, Coit J, Levitt K, et al. Buttercup: On network-based detection of polymorphic buffer overflow vulnerabilities. In: Proceedings of Network Operations and Management Symposium 2004. Washington: IEEE Computer Society, 2004"},{"key":"150_CR11","first-page":"32","volume-title":"Proceedings of 2006 IEEE Symposium on Security and Privacy (S&P\u201906)","author":"Z. Li","year":"2006","unstructured":"Li Z, Sanghi M, Chen Y, et al. Hamsa: Fast signature generation for zero-day polymorphic worms with provable attack resilience. In: Proceedings of 2006 IEEE Symposium on Security and Privacy (S&P\u201906). Washington: IEEE Computer Society, 2006. 32\u201347"},{"key":"150_CR12","doi-asserted-by":"crossref","first-page":"226","DOI":"10.1109\/SP.2005.15","volume-title":"Proceedings of 2005 IEEE Symposium on Security and Privacy (S&P\u201905)","author":"J. Newsome","year":"2005","unstructured":"Newsome J, Karp B, Song D. Polygraph: automatically generating signatures for polymorphic worms. In: Proceedings of 2005 IEEE Symposium on Security and Privacy (S&P\u201905). Washington: IEEE Computer Society, 2005. 226\u2013241"},{"key":"150_CR13","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/SP.2005.20","volume-title":"Proceedings of 2005 IEEE Symposium on Security and Privacy (S&P\u201905)","author":"M. Christodorescu","year":"2005","unstructured":"Christodorescu M, Jha S, Seshia S A, et al. Bryant. Semantics-aware malware detection. In: Proceedings of 2005 IEEE Symposium on Security and Privacy (S&P\u201905). Washington: IEEE Computer Society, 2005. 32\u201346"},{"key":"150_CR14","first-page":"169","volume-title":"Proceedings of the 12th USENIX Security Symposium","author":"M. Christodorescu","year":"2003","unstructured":"Christodorescu M, Jha S. Static analysis of executables to detect malicious patterns. In: Proceedings of the 12th USENIX Security Symposium. Berkeley: USENIX Association, 2003. 169\u2013186"},{"key":"150_CR15","unstructured":"Intel Corporation. IA-32 Intel Architecture Software Developer\u2019s Manual, 2006, Volume 2"}],"container-title":["Science in China Series F: Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-008-0150-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11432-008-0150-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-008-0150-x","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,18]],"date-time":"2021-09-18T21:10:06Z","timestamp":1631999406000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11432-008-0150-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,10,16]]},"references-count":15,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2008,11]]}},"alternative-id":["150"],"URL":"https:\/\/doi.org\/10.1007\/s11432-008-0150-x","relation":{},"ISSN":["1009-2757","1862-2836"],"issn-type":[{"value":"1009-2757","type":"print"},{"value":"1862-2836","type":"electronic"}],"subject":[],"published":{"date-parts":[[2008,10,16]]}}}