{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:51:13Z","timestamp":1771699873151,"version":"3.50.1"},"reference-count":39,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,9]]},"DOI":"10.1109\/icnss.2011.6059960","type":"proceedings-article","created":{"date-parts":[[2011,11,1]],"date-time":"2011-11-01T20:59:24Z","timestamp":1320181164000},"page":"57-64","source":"Crossref","is-referenced-by-count":7,"title":["Detecting infection onset with behavior-based policies"],"prefix":"10.1109","author":[{"family":"Kui Xu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Danfeng","family":"Yao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"family":"Qiang Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Crowell","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.25"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11145-7_23"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"ref32","article-title":"Cryptographic provenance verification for the integrity of keystrokes and outbound network traffic","author":"stefan","year":"2010","journal-title":"International Conference on Applied Cryptography and Network Security (ACNS)"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04474-8_17"},{"key":"ref30","article-title":"The design and implementation of tripwire: A file system integrity checker","author":"spafford","year":"1994","journal-title":"2nd ACM Conf on Computer and Communication Security (CCS)"},{"key":"ref37","article-title":"Automated web patrol with Strider HoneyMonkeys: Finding web sites that exploit browser vulnerabilities","author":"wang","year":"2006","journal-title":"Proceedings of the Annual Symposium on Network and Distributed System Security (NDSS)"},{"key":"ref36","article-title":"The multi-principal OS construction of the Gazelle web browser","author":"wang","year":"2009","journal-title":"Proceedings of the 18th USENIX Security Symposium"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294263"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_9"},{"key":"ref10","article-title":"Operating system protection for fine-grained programs","author":"jaeger","year":"1998","journal-title":"Proceedings of the 7th USENIX Security Symposium proceedings"},{"key":"ref11","article-title":"Building systems that flexibly control downloaded executable content","author":"jaeger","year":"1996","journal-title":"Proceedings of the 6th USENIX Security Symposium"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1455526.1455527"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2009.5403020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-007-0078-5"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866356"},{"key":"ref16","year":"0"},{"key":"ref17","year":"0"},{"key":"ref18","first-page":"229","article-title":"Symptoms based detection of bot processes","author":"morales","year":"2010","journal-title":"MMM-ACNS volume 6258 of Lecture Notes in Computer Science"},{"key":"ref19","article-title":"SpyProxy: Execution-based detection of malicious web content","author":"moshchuk","year":"2007","journal-title":"Proceedings of the 16th USENIX Security Symposium"},{"key":"ref28","author":"skape","year":"2004","journal-title":"Remote Library Injection"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772720"},{"key":"ref27","author":"skape","year":"2004","journal-title":"Metasploit's Meterpreter"},{"key":"ref3","article-title":"The new generation of targeted attacks","author":"chien","year":"2010","journal-title":"Keynote in Recent Advances in Intrusion Detection (RAID)"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-05437-2_5"},{"key":"ref29","doi-asserted-by":"crossref","DOI":"10.1145\/1755688.1755705","article-title":"Preventing drive-by download via inter-module communication monitoring","author":"song","year":"2010","journal-title":"Proceedings of the 5th ACM Symposium on Information Computer and Communications Security (ASIACCS)"},{"key":"ref5","article-title":"Most abused infection vector","author":"cruz","year":"2008","journal-title":"Trends in Microbiology"},{"key":"ref8","article-title":"Statistical Models and Causal Inference: A Dialogue with the Social Sciences","author":"freedman","year":"2010"},{"key":"ref7","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-02918-9_6","article-title":"Defending browsers against drive-by downloads: Mitigating heap-spraying code injection attacks","author":"egele","year":"2009","journal-title":"Proc Int'l Conf Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA)"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.06.003"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.19"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1390630.1390654"},{"key":"ref20","year":"0","journal-title":"Microsoft high-risk extensions"},{"key":"ref22","year":"0","journal-title":"Apple QuickTime 7 3 RTSP Response Exploit CVE-2007-6166"},{"key":"ref21","article-title":"The ghost in the browser analysis of web-based malware","author":"provos","year":"2007","journal-title":"HotBots'07 Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/1774088.1774506"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920267"},{"key":"ref26","author":"skape","year":"2003","journal-title":"Understanding Windows Shellcode"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595683"}],"event":{"name":"2011 5th International Conference on Network and System Security (NSS)","location":"Milan, Italy","start":{"date-parts":[[2011,9,6]]},"end":{"date-parts":[[2011,9,8]]}},"container-title":["2011 5th International Conference on Network and System Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6044613\/6059944\/06059960.pdf?arnumber=6059960","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,20]],"date-time":"2017-06-20T08:56:20Z","timestamp":1497948980000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6059960\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,9]]},"references-count":39,"URL":"https:\/\/doi.org\/10.1109\/icnss.2011.6059960","relation":{},"subject":[],"published":{"date-parts":[[2011,9]]}}}