{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T03:46:11Z","timestamp":1772163971142,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","license":[{"start":{"date-parts":[[2005,10,20]],"date-time":"2005-10-20T00:00:00Z","timestamp":1129766400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2005,10,20]]},"DOI":"10.1145\/1095810.1095824","type":"proceedings-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T12:34:39Z","timestamp":1131366879000},"page":"133-147","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":273,"title":["Vigilante"],"prefix":"10.1145","author":[{"given":"Manuel","family":"Costa","sequence":"first","affiliation":[{"name":"University of Cambridge, Cambridge, UK and Microsoft Research Ltd., Cambridge, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jon","family":"Crowcroft","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Miguel","family":"Castro","sequence":"additional","affiliation":[{"name":"Microsoft Research Ltd., Cambridge, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Antony","family":"Rowstron","sequence":"additional","affiliation":[{"name":"Microsoft Research Ltd., Cambridge, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lidong","family":"Zhou","sequence":"additional","affiliation":[{"name":"Microsoft Research Silicon Valley, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lintao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Microsoft Research Silicon Valley, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Barham","sequence":"additional","affiliation":[{"name":"Microsoft Research Ltd., Cambridge, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,10,20]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Pax team. http:\/\/pax.grsecurity.net\/.  Pax team. http:\/\/pax.grsecurity.net\/."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_2_1_3_1","volume-title":"May","author":"Akamai","year":"2000","unstructured":"Akamai . Press release: Akamai helps mcafee.com support flash crowds from iloveyou virus , May 2000 . Akamai. Press release: Akamai helps mcafee.com support flash crowds from iloveyou virus, May 2000."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948147"},{"key":"e_1_3_2_1_5_1","volume-title":"ACM FDD0 (Dec.","author":"Bruening D.","year":"2000","unstructured":"Bruening , D. , Duesterwald , E. , and Amarasinghe , S . Design and implementation of a dynamic optimization framework for Windows . In ACM FDD0 (Dec. 2000 ). Bruening, D., Duesterwald, E., and Amarasinghe, S. Design and implementation of a dynamic optimization framework for Windows. In ACM FDD0 (Dec. 2000)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1060289.1060317"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095820"},{"key":"e_1_3_2_1_8_1","volume-title":"Modelling the spread of active worms","author":"Chen Z.","year":"2003","unstructured":"Chen , Z. , Gao , L. , and Kwiat , K . Modelling the spread of active worms . In IEEE INFOCOM (Apr . 2003 ). Chen, Z., Gao, L., and Kwiat, K. Modelling the spread of active worms. In IEEE INFOCOM (Apr. 2003)."},{"key":"e_1_3_2_1_9_1","volume-title":"Can we contain I nternet worms? In HotNets (Nov","author":"Costa M.","year":"2004","unstructured":"Costa , M. , Crowcroft , J. , Castro , M. , and Rowstron , A . Can we contain I nternet worms? In HotNets (Nov . 2004 ). Costa, M., Crowcroft, J., Castro, M., and Rowstron, A. Can we contain I nternet worms? In HotNets (Nov. 2004)."},{"key":"e_1_3_2_1_10_1","volume-title":"USENIX Security Symposium (Jan.","author":"Cowan C.","year":"1998","unstructured":"Cowan , C. , Pu , C. , Maier , D. , Hinton , H. , Wadpole , J. , Bakke , P. , Beattie , S. , Grier , A. , Wagle , P. , and Zhang , Q . Stackguard: Automatic detection and prevention of buffer-overrun attacks . In USENIX Security Symposium (Jan. 1998 ). Cowan, C., Pu, C., Maier, D., Hinton, H., Wadpole, J., Bakke, P., Beattie, S., Grier, A., Wagle, P., and Zhang, Q. Stackguard: Automatic detection and prevention of buffer-overrun attacks. In USENIX Security Symposium (Jan. 1998)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.26"},{"key":"e_1_3_2_1_12_1","volume-title":"IPTPS (Mar.","author":"Douceur J. R.","year":"2002","unstructured":"Douceur , J. R. The Sybil attack . In IPTPS (Mar. 2002 ). Douceur, J. R. The Sybil attack. In IPTPS (Mar. 2002)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1060289.1060309"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/568522.568525"},{"key":"e_1_3_2_1_15_1","volume-title":"USENIX Annual Technical Conference (Jun.","author":"Fraser K.","year":"2003","unstructured":"Fraser , K. , and Chang , F . Operating System I\/O Speculation: How two invocations are faster than one . In USENIX Annual Technical Conference (Jun. 2003 ). Fraser, K., and Chang, F. Operating System I\/O Speculation: How two invocations are faster than one. In USENIX Annual Technical Conference (Jun. 2003)."},{"key":"e_1_3_2_1_16_1","volume-title":"NDSS (Feb.","author":"Garfinkel T.","year":"2003","unstructured":"Garfinkel , T. , and Rosenblum , M . A virtual machine introspection based architecture for intrusion detection . In NDSS (Feb. 2003 ). Garfinkel, T., and Rosenblum, M. A virtual machine introspection based architecture for intrusion detection. In NDSS (Feb. 2003)."},{"key":"e_1_3_2_1_17_1","volume-title":"PAM2001 (Apr.","author":"Georgatos F.","year":"2001","unstructured":"Georgatos , F. , Gruber , F. , Karrenberg , D. , Santcroos , M. , Uijterwaal , H. , and Wilhelm , R . Providing A ctive M easurements as a R egular S ervice for ISP s . In PAM2001 (Apr. 2001 ). http:\/\/www.ripe.net\/ttm. Georgatos, F., Gruber, F., Karrenberg, D., Santcroos, M., Uijterwaal, H., and Wilhelm, R. Providing A ctive M easurements as a R egular S ervice for ISP s. In PAM2001 (Apr. 2001). http:\/\/www.ripe.net\/ttm."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/RISP.1990.63859"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0036144500371907"},{"key":"e_1_3_2_1_20_1","volume-title":"USENIX Windows NT Symposium (July","author":"Hunt G.","year":"1999","unstructured":"Hunt , G. , and Brubacher , D . Detours: Binary interception of W in32 functions . In USENIX Windows NT Symposium (July 1999 ). Hunt, G., and Brubacher, D. Detours: Binary interception of W in32 functions. In USENIX Windows NT Symposium (July 1999)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_3_2_1_22_1","volume-title":"USENIX Security Symposium (Aug.","author":"Kim H.","year":"2004","unstructured":"Kim , H. , and Karp , B . Autograph: Toward automated, distributed worm signature detection . In USENIX Security Symposium (Aug. 2004 ). Kim, H., and Karp, B. Autograph: Toward automated, distributed worm signature detection. In USENIX Security Symposium (Aug. 2004)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720293"},{"key":"e_1_3_2_1_24_1","volume-title":"HotNets (Nov.","author":"Kreibich C.","year":"2003","unstructured":"Kreibich , C. , and Crowcroft , J . Honeycomb - creating intrusion detection signatures using honeypots . In HotNets (Nov. 2003 ). Kreibich, C., and Crowcroft, J. Honeycomb - creating intrusion detection signatures using honeypots. In HotNets (Nov. 2003)."},{"key":"e_1_3_2_1_25_1","unstructured":"Microsoft. Nirvana. http:\/\/www.microsoft.com\/windows\/cse\/bit.mspx.  Microsoft. Nirvana. http:\/\/www.microsoft.com\/windows\/cse\/bit.mspx."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"e_1_3_2_1_27_1","volume-title":"Internet quarantine: Requirements for containing self-propagating code","author":"Moore D.","year":"2003","unstructured":"Moore , D. , Shannon , C. , Voelker , G. , and Savage , S . Internet quarantine: Requirements for containing self-propagating code . In IEEE INFOCOM (Apr . 2003 ). Moore, D., Shannon, C., Voelker, G., and Savage, S. Internet quarantine: Requirements for containing self-propagating code. In IEEE INFOCOM (Apr. 2003)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/503272.503286"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"key":"e_1_3_2_1_30_1","volume-title":"NDSS (Feb.","author":"Newsome J.","year":"2005","unstructured":"Newsome , J. , and Song , D . Dynamic taint analysis: Automatic detection and generation of software exploit attacks . In NDSS (Feb. 2005 ). Newsome, J., and Song, D. Dynamic taint analysis: Automatic detection and generation of software exploit attacks. In NDSS (Feb. 2005)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_32_1","volume-title":"Secure Networks","author":"Ptacek T. H.","year":"1998","unstructured":"Ptacek , T. H. , and Newsham , T. N . Insertion, evasion, and denial of service: Eluding network intrusion detection. Tech. rep ., Secure Networks , Inc , Jan. 1998 . Ptacek, T. H., and Newsham, T. N. Insertion, evasion, and denial of service: Eluding network intrusion detection. Tech. rep., Secure Networks, Inc, Jan. 1998."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/222124.222138"},{"key":"e_1_3_2_1_34_1","volume-title":"OSDI (Dec.","author":"Rinard M.","year":"2004","unstructured":"Rinard , M. , Cadar , C. , Dumitran , D. , Roy , D. M. , Leu , T. , and Jr ., W. S. B. Enhancing server availability and security through failure-oblivious computing . In OSDI (Dec. 2004 ). Rinard, M., Cadar, C., Dumitran, D., Roy, D. M., Leu, T., and Jr., W. S. B. Enhancing server availability and security through failure-oblivious computing. In OSDI (Dec. 2004)."},{"key":"e_1_3_2_1_35_1","volume-title":"Snort: Lightweight intrusion detection for networks.In Conference on Systems Administration (Nov","author":"Roesch M.","year":"1999","unstructured":"Roesch , M. Snort: Lightweight intrusion detection for networks.In Conference on Systems Administration (Nov . 1999 ). Roesch, M. Snort: Lightweight intrusion detection for networks.In Conference on Systems Administration (Nov. 1999)."},{"key":"e_1_3_2_1_36_1"},{"key":"e_1_3_2_1_37_1","volume-title":"Usenix Technical Conference (Apr.","author":"Sidiroglou S.","year":"2005","unstructured":"Sidiroglou , S. , Locasto , M. E. , Boyd , S. W. , and Keromytis , A. D . Building a reactive immune system for software services . In Usenix Technical Conference (Apr. 2005 ). Sidiroglou, S., Locasto, M. E., Boyd, S. W., and Keromytis, A. D. Building a reactive immune system for software services. In Usenix Technical Conference (Apr. 2005)."},{"key":"e_1_3_2_1_38_1","volume-title":"OSDI (Dec.","author":"Singh S.","year":"2004","unstructured":"Singh , S. , Estan , C. , Varghese , G. , and Savage , S . Automated worm fingerprinting . In OSDI (Dec. 2004 ). Singh, S., Estan, C., Varghese, G., and Savage, S. Automated worm fingerprinting. In OSDI (Dec. 2004)."},{"key":"e_1_3_2_1_39_1","volume-title":"NDSS (Feb.","author":"Smirnov A.","year":"2005","unstructured":"Smirnov , A. , and cker Chiueh , T. DIRA: Automatic detection, identification, and repair of control-hijacking attacks . In NDSS (Feb. 2005 ). Smirnov, A., and cker Chiueh, T. DIRA: Automatic detection, identification, and repair of control-hijacking attacks. In NDSS (Feb. 2005)."},{"key":"e_1_3_2_1_40_1","unstructured":"SPEC. Specweb99 benchmark. http:\/\/www.spec.org\/osg\/web99.  SPEC. Specweb99 benchmark. http:\/\/www.spec.org\/osg\/web99."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029624"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720288"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_3_2_1_44_1","unstructured":"TPC. Tpc-c online transaction processing benchmark. http:\/\/www.tpc.org\/tpcc\/default.asp.  TPC. Tpc-c online transaction processing benchmark. http:\/\/www.tpc.org\/tpcc\/default.asp."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015489"},{"key":"e_1_3_2_1_46_1","volume-title":"USENIX Security Symposium (Aug.","author":"Weaver N.","year":"2004","unstructured":"Weaver , N. , Staniford , S. , and Paxson , V . Very fast containment of scanning worms . In USENIX Security Symposium (Aug. 2004 ). Weaver, N., Staniford, S., and Paxson, V. Very fast containment of scanning worms. In USENIX Security Symposium (Aug. 2004)."},{"key":"e_1_3_2_1_47_1","volume-title":"NDSS (Feb.","author":"Wilander J.","year":"2003","unstructured":"Wilander , J. , and Kamkar , M . A comparison of publicly available tools for dynamic buffer overflow prevention . In NDSS (Feb. 2003 ). Wilander, J., and Kamkar, M. A comparison of publicly available tools for dynamic buffer overflow prevention. In NDSS (Feb. 2003)."},{"key":"e_1_3_2_1_48_1","volume-title":"Throttling viruses: Restricting propagation to defeat mobile malicious code. ACSAC","author":"Williamnson M. M.","year":"2002","unstructured":"Williamnson , M. M. Throttling viruses: Restricting propagation to defeat mobile malicious code. ACSAC ( 2002 ). Williamnson, M. M. Throttling viruses: Restricting propagation to defeat mobile malicious code. ACSAC (2002)."},{"key":"e_1_3_2_1_49_1","volume-title":"How to model an internetwork","author":"Zegura E.","year":"1996","unstructured":"Zegura , E. , Calvert , K. , and Bhattacharjee , S . How to model an internetwork . In IEEE INFOCOM (Mar . 1996 ). Zegura, E., Calvert, K., and Bhattacharjee, S. How to model an internetwork. In IEEE INFOCOM (Mar. 1996)."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948136"}],"event":{"name":"SOSP05: ACM SIGOPS 20th Symposium on Operating Systems Principles 2005","location":"Brighton United Kingdom","acronym":"SOSP05","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the twentieth ACM symposium on Operating systems principles"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1095810.1095824","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1095810.1095824","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:08:27Z","timestamp":1750248507000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1095810.1095824"}},"subtitle":["end-to-end containment of internet worms"],"short-title":[],"issued":{"date-parts":[[2005,10,20]]},"references-count":50,"alternative-id":["10.1145\/1095810.1095824","10.1145\/1095810"],"URL":"https:\/\/doi.org\/10.1145\/1095810.1095824","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/1095809.1095824","asserted-by":"object"}]},"subject":[],"published":{"date-parts":[[2005,10,20]]},"assertion":[{"value":"2005-10-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}