{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T10:42:30Z","timestamp":1780915350617,"version":"3.54.1"},"reference-count":26,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,10]]},"DOI":"10.1109\/malware.2011.6112327","type":"proceedings-article","created":{"date-parts":[[2011,12,29]],"date-time":"2011-12-29T16:04:25Z","timestamp":1325174665000},"page":"58-65","source":"Crossref","is-referenced-by-count":23,"title":["ROP payload detection using speculative code execution"],"prefix":"10.1109","author":[{"given":"Michalis","family":"Polychronakis","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"19","year":"0","journal-title":"Getting Around Non-executable Stack (And Fix)"},{"key":"17","article-title":"The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86)","author":"shacham","year":"0","journal-title":"Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS) 2007"},{"key":"18","article-title":"ShellOS: Enabling fast detection and forensic analysis of code injection attacks","author":"snow","year":"0","journal-title":"Proceedings of the 20th USENIX Security Symposium 2011"},{"key":"15","article-title":"Emulation-based detection of non-self-contained polymorphic shellcode","author":"polychronakis","year":"0","journal-title":"Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID) September 2007"},{"key":"16","article-title":"NOZZLE: A defense against heap-spraying code injection attacks","author":"ratanaworabhan","year":"0","journal-title":"Proceedings of the 18th USENIX Security Symposium Aug 2009"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920305"},{"key":"14","article-title":"Network-level polymorphic shellcode detection using emulation","author":"polychronakis","year":"0","journal-title":"Proceedings of the Third Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA) July 2006"},{"key":"11","author":"hensing","year":"2009","journal-title":"Understanding DEP As A Mitigation Technology"},{"key":"12","article-title":"Polymorphic worm detection using structural information of executables","author":"kruegel","year":"0","journal-title":"Proceedings of the International Symposium on Recent Advances in Intrusion Detection (RAID) Sept 2005"},{"key":"21","article-title":"Accurate buffer overflow detection via abstract payload execution","author":"toth","year":"0","journal-title":"Proc International Symposium on Recent Advances in Intrusion Detection (RAID) October 2002"},{"key":"20","author":"sole?","year":"0","journal-title":"Hanging on A ROPe"},{"key":"22","doi-asserted-by":"publisher","DOI":"10.1145\/1972551.1972555"},{"key":"23","article-title":"Sigfree: A signature-free buffer overflow attack blocker","author":"wang","year":"0","journal-title":"Proceedings of USENIX Security Symposium 2006"},{"key":"24","author":"wicherski","year":"0","journal-title":"Libscizzle"},{"key":"25","article-title":"Analyzing network traffic to detect self-decrypting exploit code","author":"zhang","year":"0","journal-title":"Proceedings of the 2nd ACM Symposium on Information Computer and Communications Security (ASIACCS) 2007"},{"key":"26","author":"zovi","year":"2010","journal-title":"Practical Return-oriented Programming"},{"key":"3","year":"0"},{"key":"2","year":"0"},{"key":"10","article-title":"Low-level software security: Attack and defenses","author":"erlingsson","year":"2007","journal-title":"Microsoft Research"},{"key":"1","year":"0"},{"key":"7","year":"0","journal-title":"Corelan ROPdb"},{"key":"6","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866370"},{"key":"5","article-title":"The ROP pack","author":"baumgartner","year":"0","journal-title":"Proceedings of the 20th Virus Bulletin International Conference (VB) 2010"},{"key":"4","author":"bouchier","year":"0"},{"key":"9","article-title":"Defending browsers against drive-by downloads: Mitigating heapspraying code injection attacks","author":"egele","year":"0","journal-title":"Proceedings of the 6th International Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA) 2009"},{"key":"8","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772720"}],"event":{"name":"2011 6th International Conference on Malicious and Unwanted Software (MALWARE)","location":"Fajardo, PR, USA","start":{"date-parts":[[2011,10,18]]},"end":{"date-parts":[[2011,10,19]]}},"container-title":["2011 6th International Conference on Malicious and Unwanted Software"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6104282\/6112317\/06112327.pdf?arnumber=6112327","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,3,21]],"date-time":"2017-03-21T14:09:34Z","timestamp":1490105374000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6112327\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,10]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/malware.2011.6112327","relation":{},"subject":[],"published":{"date-parts":[[2011,10]]}}}