{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,8]],"date-time":"2025-11-08T22:37:20Z","timestamp":1762641440532},"reference-count":62,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2011,11,1]],"date-time":"2011-11-01T00:00:00Z","timestamp":1320105600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Autom. Comput."],"published-print":{"date-parts":[[2011,11]]},"DOI":"10.1007\/s11633-011-0606-0","type":"journal-article","created":{"date-parts":[[2011,12,5]],"date-time":"2011-12-05T08:34:56Z","timestamp":1323074096000},"page":"472-483","source":"Crossref","is-referenced-by-count":9,"title":["Protecting against address space layout randomisation (ASLR) compromises and return-to-libc attacks using network intrusion detection systems"],"prefix":"10.1007","volume":"8","author":[{"given":"David J.","family":"Day","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng-Xu","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2011,12,6]]},"reference":[{"issue":"8","key":"606_CR1","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1145\/1536616.1536634","volume":"52","author":"C. Reis","year":"2009","unstructured":"C. Reis, A. Barth, C. Pizano. Browser security: Lessons from google chrome. Communications of the ACM, vol. 52, no. 8, pp. 45\u201349, 2009.","journal-title":"Communications of the ACM"},{"key":"606_CR2","doi-asserted-by":"crossref","first-page":"298","DOI":"10.1145\/1030083.1030124","volume-title":"Proceedings of the 11th ACM Conference on Computer and Communications Security","author":"H. Shacham","year":"2004","unstructured":"H. Shacham, M. Page, B. Pfaff, E. J. Goh, N. Modadugu, D. Boneh. On the effectiveness of address-space randomization. In Proceedings of the 11th ACM Conference on Computer and Communications Security, ACM, New York, USA, pp. 298\u2013307, 2004."},{"key":"606_CR3","unstructured":"A. Sotirov, M. Dowd. Bypassing Browser Memory Protections, [Online], Available: http:\/\/www.blackhat.com\/ presentations\/bh-usa-08\/SotirovDowd\/bh08-sotirovdowd.pdf , March 8, 2011."},{"key":"606_CR4","doi-asserted-by":"crossref","unstructured":"Z. Liang, R. Seikar. Fast and automated generation of attack signatures: A basis for building self-protecting. In Proceedings of the 21st Annual Computer Security Applications Conference, Tucson, USA, pp. 215\u2013224, 2005.","DOI":"10.1145\/1102120.1102150"},{"key":"606_CR5","volume-title":"Buffer Over-flow Attacks","author":"J. C. Foster","year":"2005","unstructured":"J. C. Foster, V. Osipov, N. Bhall, N. Heinen. Buffer Over-flow Attacks, Burlington, USA: Syngress, 2005."},{"key":"606_CR6","unstructured":"SANS. The Top Cyber Security Risks, [Online], Available: http:\/\/www.sans.org\/top-cyber-security-risks\/#trends , March 9, 2011."},{"key":"606_CR7","unstructured":"TIOBE Software. TIOBE Programming Community Index for September 2008, [Online], Available: http:\/\/www.tiobe.com\/index.php\/content\/paperinfo\/tpci\/ index.html , March 9, 2011."},{"issue":"1","key":"606_CR8","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MS.2002.976936","volume":"19","author":"A. K. Ghosh","year":"2002","unstructured":"A. K. Ghosh, C. Howell, J. A. Whittaker. Building software securely from the ground up. IEEE Software, vol. 19, no. 1, pp. 14\u201316, 2002.","journal-title":"IEEE Software"},{"key":"606_CR9","unstructured":"C. Schmidt, T. Darby. The What, Why, and How of the 1988 Internet Worm, [Online], Available: http:\/\/www.snowplow.org\/tom\/worm\/worm.html , March 9, 2011."},{"key":"606_CR10","unstructured":"C. Cowan. Buffer Overflow Attacks, [Online], Available: http:\/\/www.usenix.org\/publications\/library\/proceedings\/sec98\/full_papers\/cowan\/cowan_html\/node3.html , March 9, 2011."},{"key":"606_CR11","unstructured":"H. Etoh. Evaluation, [Online], Available: http:\/\/www.trl. ibm.com\/projects\/security\/ssp\/node5.html , March 9, 2011."},{"key":"606_CR12","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1145\/310889.310915","volume-title":"Proceedings of the 1998 Workshop on New Security","author":"C. Cowan","year":"1998","unstructured":"C. Cowan, C. Pu, H. Hinton. Death, taxes and imperfect software: Surviving the inevitable. In Proceedings of the 1998 Workshop on New Security, ACM, New York, USA, pp. 54\u201370, 1998."},{"key":"606_CR13","first-page":"119","volume":"2","author":"C. Cowan","year":"2000","unstructured":"C. Cowan, P. Wagle, C. Pu, S. Beattie, J. Walpole. Buffer overflows: Attacks and defenses for the vulnerability of the decade. IEEE Computer Society, vol. 2, pp. 119\u2013129, 2000.","journal-title":"IEEE Computer Society"},{"key":"606_CR14","unstructured":"T. Bradley. Introduction to Intrusion Detection Systems, [Online], Available: http:\/\/netsecurity.about.com\/cs\/ hackertools\/a\/aa030504.htm , March 9, 2011."},{"issue":"4","key":"606_CR15","doi-asserted-by":"crossref","first-page":"406","DOI":"10.1007\/s11633-009-0406-y","volume":"6","author":"S. S. S. Sindhu","year":"2009","unstructured":"S. S. S. Sindhu, S. Geetha, M. Marikannan, A. Kannan. A neuro-genetic based short-term forecasting framework for network intrusion prediction system. International Journal of Automation and Computing, vol. 6, no. 4, pp. 406\u2013414, 2009.","journal-title":"International Journal of Automation and Computing"},{"issue":"4","key":"606_CR16","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1007\/s11416-006-0031-z","volume":"2","author":"M. Polychronakis","year":"2006","unstructured":"M. Polychronakis, K. G. Anagnostakis, E. P. Markatos. Network-level polymorphic shellcode detection using emulation. Journal in Computer Virology, vol. 2, no. 4, pp. 257\u2013274, 2006.","journal-title":"Journal in Computer Virology"},{"key":"606_CR17","doi-asserted-by":"crossref","DOI":"10.4108\/infoscale.2007","volume-title":"Proceedings of the 2nd International Conference on Scalable Information Systems","author":"H. L. Huang","year":"2007","unstructured":"H. L. Huang, T. J. Liu, K. H. Chen, C. R. Dow, L. C. Wu. A polymorphic shellcode detection mechanism in the network. In Proceedings of the 2nd International Conference on Scalable Information Systems, ACM, Suzhou, PRC, 2007."},{"key":"606_CR18","doi-asserted-by":"crossref","unstructured":"R. Lippmann, S. Webster, D. Stetson. The effect of identifying vulnerabilities and patching software on the utility of network intrusion detection. In Proceedings of the 5th International Conference on Recent Advances in Intrusion Detection, ACM, pp. 307\u2013326, 2002.","DOI":"10.1007\/3-540-36084-0_17"},{"key":"606_CR19","unstructured":"Rule Performance Part One: Content Matches, [Online], Available: http:\/\/vrt-blog.snort.org\/2009\/07\/ruleperformance-part-one-content.html , March 10, 2011."},{"key":"606_CR20","unstructured":"Aleph1. Smashing the Stack for Fun and Profit, [Online], Available: http:\/\/www.phrack.org\/issues.html?issue=49&id=14#article , March 9, 2011."},{"key":"606_CR21","unstructured":"L. Haendel. The Function Pointer Tutorials, [Online], Available: http:\/\/www.newty.de\/fpt\/intro.html#what , March 9, 2011."},{"key":"606_CR22","unstructured":"Etoh. Hiroaki. Stack Protection Systems: Propolice, StackGuard, XP SP2, [Online], Available: http:\/\/pacsec.jp\/psj04\/psj04-hiroaki-e.ppt , March 10, 2011."},{"key":"606_CR23","volume-title":"C++ A Beginner\u2019s Guide","author":"H. Schildt","year":"2003","unstructured":"H. Schildt. C++ A Beginner\u2019s Guide, 2nd ed., Maidenhead, UK: McGraw-Hill, 2003.","edition":"2nd ed."},{"key":"606_CR24","unstructured":"C. Sanders. Buffer Overflows, Data Execution Prevention, and You, [Online], Available: http:\/\/www.windowsecurity. com\/articles\/Buffer-Overflows-Data-Execution-Prevention-You.htm , March 9, 2011."},{"key":"606_CR25","volume-title":"New Security Enhancements in Red Hat Enterprise Linux v.3, update 3","author":"A. Ven","year":"2004","unstructured":"A. Ven. New Security Enhancements in Red Hat Enterprise Linux v.3, update 3. Raleigh, North Carolina, USA: Red Hat, 2004, [Online], Available: http:\/\/www.redhat.com\/f\/pdf\/rhel\/WHP0006US Execshield.pdf , March 9, 2011."},{"key":"606_CR26","volume-title":"An Analysis of Address Space Layout Randomization on Windows Vista","author":"O. Whitehouse","year":"2007","unstructured":"O. Whitehouse. An Analysis of Address Space Layout Randomization on Windows Vista. Cupertino: Symantec, 2007, [Online], Available: http:\/\/www.symantec.com\/avcenter\/reference\/Address_Space_Layout_Randomization.pdf , March 9, 2011."},{"key":"606_CR27","volume-title":"Bypassing Windows Vista\u2019s Address Space Layout Randomization","author":"F. Losliweg","year":"2007","unstructured":"F. Losliweg. Bypassing Windows Vista\u2019s Address Space Layout Randomization. Switzerland: skillTube.com, 2007."},{"key":"606_CR28","doi-asserted-by":"crossref","unstructured":"W. Hu, J. Hiser, D. Williams, A. Filipi, J. W. Davidson, D. Evans. Secure and practical defense against code-injection attacks using software dynamic translation. In Proceedings of the 2nd International Conference on Virtual Execution Environments, ACM, pp. 2\u201312, 2006.","DOI":"10.1145\/1134760.1134764"},{"key":"606_CR29","unstructured":"Linux Kernel Patch from the Openwall Project, [Online], Available: http:\/\/www.openwall.com\/linux\/ , March 9, 2011."},{"key":"606_CR30","unstructured":"P. Lacroix, J. Desharnais. Buffer Overflow Vulnerabilities in C and C + +. s.l., Unpublished Report, 2008."},{"key":"606_CR31","unstructured":"GCC steering Committe, [Online], Available: http:\/\/gcc.gnu.org\/releases.html , March 9, 2011."},{"key":"606_CR32","unstructured":"Skape. Preventing the Exploitation of SEH Overwrites, [Online], Available: http:\/\/www.uninformed.org\/?v=5&a=2&t=pdf , March 9, 2011."},{"key":"606_CR33","unstructured":"Security Focus. Oracle 9I Application Server PL\/SQL Apache Module Buffer Overflow Vulnerability, [Online], Available: http:\/\/www.securityfocus.com\/bid\/3726\/discuss , March 9, 2011."},{"key":"606_CR34","volume-title":"Unix Network Programming","author":"R. S. Stevens","year":"2003","unstructured":"R. S. Stevens, B. Fenner, A. M. Rudoff. Unix Network Programming, Boston, USA: Pearson Education, 2003."},{"key":"606_CR35","unstructured":"T. Durden. Defeating PaX ASLR protection Durden, s.l., Phrack, vol. 12, 2002."},{"key":"606_CR36","unstructured":"Workstation 7, Vmware, [Online], Available: http:\/\/www. vmware.com\/workstation , March 9, 2011."},{"key":"606_CR37","unstructured":"Wireshark, [Online], Available: http:\/\/www.wireshark.org\/ , March 9, 2011."},{"key":"606_CR38","unstructured":"Sourcefire, [Online], Available: http:\/\/www.snort.org\/ , March 9, 2011."},{"key":"606_CR39","unstructured":"The Advanced Return-into-lib(c) Exploits, vol. 11, [Online], Available: http:\/\/www.phrack.org\/issues.html?issue=58&id=4 , March 9, 2011."},{"key":"606_CR40","unstructured":"Explotation for Phun and Profit, [Online], Available: http:\/\/dl.packetstormsecurity.net\/papers\/attack\/phun.pdf , March 9, 2011."},{"key":"606_CR41","unstructured":"R. Riel, S, Feng. Documentation for \/proc\/sys\/kernel, [Online], Available: http:\/\/www.kernel.org\/doc\/Documentation\/sysctl\/kernel.txt , March 9, 2011."},{"key":"606_CR42","unstructured":"Documentation for the PaX Project, [Online], Available: http:\/\/pax.grsecurity.net\/docs\/index.html , March 9, 2011."},{"key":"606_CR43","volume-title":"Intrusion Prevention and Active Response: Deploying Network and Host IPS","author":"M. Rash","year":"2005","unstructured":"M. Rash. Intrusion Prevention and Active Response: Deploying Network and Host IPS, Rockland, USA: Syngress, 2005."},{"key":"606_CR44","unstructured":"The GNU Netcat Project, [Online], Available: http:\/\/netcat.sourceforge.net\/ , March 9, 2011."},{"key":"606_CR45","unstructured":"LinuxManPages, [Online], Available: http:\/\/linuxmanpages.com\/ , March 9, 2011."},{"key":"606_CR46","unstructured":"J. R. Moser. Prelink and Address Space Randomization, [Online], Available: http:\/\/lwn.net\/Articles\/190139\/ , March 9, 2011."},{"key":"606_CR47","unstructured":"C. Cowan, P. Wagle, P. Calton. Buffer Overflows: Attacks and Defenses for the Vulnerability of the Decade, [Online], Available: http:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.147.3917&rep=rep1&type=pdf , March 9, 2011."},{"key":"606_CR48","unstructured":"Mozilla wiki, [Online], Available: https:\/\/wiki.mozilla.org\/Gecko:Home_Page , March 9, 2011."},{"key":"606_CR49","unstructured":"Stack Smash Protection, [Online], Available: http:\/\/dsbd._alioth.debian.org\/www\/?page=ssp , March 9, 2011."},{"key":"606_CR50","unstructured":"Sourcefire Vulnerabilty Research Team, [Online], Available: http:\/\/www.sourcefire.com\/resources\/sourcefire-vrtwhite-paper , March 9, 2011."},{"key":"606_CR51","unstructured":"Writing Detection Signatures, [Online], Available: http:\/\/www.usenix.org\/publications\/login\/2005-12\/pdfs\/jordan.pdf , March 9, 2011."},{"key":"606_CR52","unstructured":"The Snort Project. Snort Users Manual. Snort Users Manual. s.l.: Snort, 2009."},{"key":"606_CR53","unstructured":"IEEE Computer Society, Part 3: Carrier sense multiple access with Collision Detection (CSMA\/CD) Access Method and Physical Layer Specifications, [Online], Available: http:\/\/ieeexplore.ieee.org\/stamp\/stamp.jsp?arnumber=01576509 , March 9, 2011."},{"key":"606_CR54","unstructured":"PCRE \u2014 Perl Compatible Regular Expressions, [Online], Available: http:\/\/www.pcre.org\/pcre.txt , March 9, 2011."},{"key":"606_CR55","unstructured":"S. Friedl. Mapping UNIX pipe descriptors to stdin and stdout in C, [Online], Available: http:\/\/unixwiz.net\/techtips\/remap-pipe-fds.html , March 9, 2011."},{"key":"606_CR56","unstructured":"S. J. Leffler. An Advanced 4.4BSD Interprocess Communication Tutorial, [Online], Available: http:\/\/docs.freebsd.org\/44doc\/psd\/21.ipc\/paper.pdf , March 9, 2011."},{"key":"606_CR57","unstructured":"J. J. Goyvaerts. Learn, Create, Understand, Test, Use and Save Regular Expressions with RegexBuddy, [Online], Available: http:\/\/www.regexbuddy.com\/ , March 9, 2011."},{"key":"606_CR58","unstructured":"Basic Analysis and Security Engine, [Online], Available: http:\/\/base.secureideas.net , March 9, 2011."},{"key":"606_CR59","unstructured":"The NTLM Authentication Protocol and Security Support Provider, [Online], Available: http:\/\/davenport.sourceforge.net\/ntlm.html#ntlmhttpAuthentication , March 9, 2011."},{"key":"606_CR60","unstructured":"Vulnerability Note VU#878603, [Online], Available: http:\/\/www.kb.cert.org\/vuls\/id\/878603 , March 9, 2011."},{"key":"606_CR61","volume-title":"Snort IDS and IPS Toolkit","author":"B. Caswell","year":"2007","unstructured":"B. Caswell, J. Beale, A. Baker. Snort IDS and IPS Toolkit, Burlington, USA: Syngress, 2007."},{"issue":"1","key":"606_CR62","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1007\/s11633-008-0032-0","volume":"5","author":"W. Wilson","year":"2008","unstructured":"W. Wilson, P. Birkin, U. Aickelin. The motif tracking algorithm. International Journal of Automation and Computing, vol. 5, no. 1, pp. 32\u201344, 2008.","journal-title":"International Journal of Automation and Computing"}],"container-title":["International Journal of Automation and Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11633-011-0606-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11633-011-0606-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11633-011-0606-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,20]],"date-time":"2019-06-20T08:59:30Z","timestamp":1561021170000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11633-011-0606-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,11]]},"references-count":62,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2011,11]]}},"alternative-id":["606"],"URL":"https:\/\/doi.org\/10.1007\/s11633-011-0606-0","relation":{},"ISSN":["1476-8186","1751-8520"],"issn-type":[{"value":"1476-8186","type":"print"},{"value":"1751-8520","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,11]]}}}