{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:54:43Z","timestamp":1771700083597,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":53,"publisher":"ACM","license":[{"start":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T00:00:00Z","timestamp":1131321600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2005,11,7]]},"DOI":"10.1145\/1102120.1102152","type":"proceedings-article","created":{"date-parts":[[2006,2,6]],"date-time":"2006-02-06T15:52:40Z","timestamp":1139241160000},"page":"235-248","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":99,"title":["On deriving unknown vulnerabilities from zero-day polymorphic and metamorphic worm exploits"],"prefix":"10.1145","author":[{"given":"Jedidiah R.","family":"Crandall","sequence":"first","affiliation":[{"name":"Univ. of Calif., Davis, Davis, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhendong","family":"Su","sequence":"additional","affiliation":[{"name":"Univ. of Calif., Davis, Davis, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S. Felix","family":"Wu","sequence":"additional","affiliation":[{"name":"Univ. of Calif., Davis, Davis, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frederic T.","family":"Chong","sequence":"additional","affiliation":[{"name":"Dept. Comp. Sci. Univ. of Calif., Santa Barbara, Santa Barbara, CA 93106"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"20th IFIP International Information Security Conference.","author":"Akritidis P.","unstructured":"P. Akritidis , E. P. Markatos , M. Polychronakis , and K. Anagnostakis . Stride: Polymorphic sled detection through instruction sequence analysis . In 20th IFIP International Information Security Conference. P. Akritidis, E. P. Markatos, M. Polychronakis, and K. Anagnostakis. Stride: Polymorphic sled detection through instruction sequence analysis. In 20th IFIP International Information Security Conference."},{"key":"e_1_3_2_1_2_1","unstructured":"Barnaby Jack. Remote Windows Kernel Exploitation-Step Into the Ring 0.  Barnaby Jack. Remote Windows Kernel Exploitation-Step Into the Ring 0."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948147"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/11537328_2"},{"key":"e_1_3_2_1_5_1","volume-title":"USENIX Security Symposium 2005","author":"Chen S.","year":"2005","unstructured":"S. Chen , J. Xu , and E. C. Sezer . Non-control-hijacking attacks are realistic threats . In USENIX Security Symposium 2005 , 2005 . S. Chen, J. Xu, and E. C. Sezer. Non-control-hijacking attacks are realistic threats. In USENIX Security Symposium 2005, 2005."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_15"},{"key":"e_1_3_2_1_7_1","volume-title":"Static analysis of executables to detect malicious patterns","author":"Christodorescu M.","year":"2003","unstructured":"M. Christodorescu and S. Jha . Static analysis of executables to detect malicious patterns , 2003 . M. Christodorescu and S. Jha. Static analysis of executables to detect malicious patterns, 2003."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.20"},{"key":"e_1_3_2_1_9_1","first-page":"240","volume-title":"7th DoD\/NBS Computer Security Conference Proceedings","author":"Cohen F.","year":"1984","unstructured":"F. Cohen . Computer viruses: theory and experiments . In 7th DoD\/NBS Computer Security Conference Proceedings , pages 240 -- 263 , September 1984 . F. Cohen. Computer viruses: theory and experiments. In 7th DoD\/NBS Computer Security Conference Proceedings, pages 240--263, September 1984."},{"key":"e_1_3_2_1_10_1","unstructured":"M. Costa J. Crowcroft M. Castro and A. Rowstron. Can we contain internet worms? In HotNets III.  M. Costa J. Crowcroft M. Castro and A. Rowstron. Can we contain internet worms? In HotNets III."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095824"},{"key":"e_1_3_2_1_12_1","volume-title":"Workshop on Architectural Support for Security and Anti-Virus","author":"Crandall J. R.","year":"2004","unstructured":"J. R. Crandall and F. T. Chong . A Security Assessment of the Minos Architecture . In Workshop on Architectural Support for Security and Anti-Virus , Oct. 2004 . J. R. Crandall and F. T. Chong. A Security Assessment of the Minos Architecture. In Workshop on Architectural Support for Security and Anti-Virus, Oct. 2004."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.26"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_3"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_13"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/844128.844148"},{"key":"e_1_3_2_1_17_1","volume-title":"University of Cambridge","author":"Fenton J.","year":"1973","unstructured":"J. Fenton . Information protection systems. In Ph.D. Thesis , University of Cambridge , 1973 . J. Fenton. Information protection systems. In Ph.D. Thesis, University of Cambridge, 1973."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065036"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_14"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_13"},{"key":"e_1_3_2_1_21_1","first-page":"271","volume-title":"USENIX Security Symposium","author":"Kim H.-A.","year":"2004","unstructured":"H.-A. Kim and B. Karp . Autograph: Toward automated, distributed worm signature detection . In USENIX Security Symposium , pages 271 -- 286 , 2004 . H.-A. Kim and B. Karp. Autograph: Toward automated, distributed worm signature detection. In USENIX Security Symposium, pages 271--286, 2004."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"e_1_3_2_1_23_1","unstructured":"O. Kolesnikov and W. Lee. Advanced polymorphic worms: Evading IDS by blending in with normal traffic.  O. Kolesnikov and W. Lee. Advanced polymorphic worms: Evading IDS by blending in with normal traffic."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972384"},{"key":"e_1_3_2_1_25_1","volume-title":"RAID","author":"Kr\u00fcgel C.","year":"2005","unstructured":"C. Kr\u00fcgel , E. Kirda , D. Mutz , W. Robertson , and G. Vigna . Polymorphic worm detection using structural information of executables . In RAID , 2005 . C. Kr\u00fcgel, E. Kirda, D. Mutz, W. Robertson, and G. Vigna. Polymorphic worm detection using structural information of executables. In RAID, 2005."},{"key":"e_1_3_2_1_26_1","volume-title":"Fuzz revisited: A re-examination of the reliability of UNIX utilities and services. Technical report","author":"Miller B.","year":"1995","unstructured":"B. Miller , D. Koski , C. P. Lee , V. Maganty , R. Murthy , A. Natarajan , and J. Steidl . Fuzz revisited: A re-examination of the reliability of UNIX utilities and services. Technical report , 1995 . B. Miller, D. Koski, C. P. Lee, V. Maganty, R. Murthy, A. Natarajan, and J. Steidl. Fuzz revisited: A re-examination of the reliability of UNIX utilities and services. Technical report, 1995."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05)","author":"Newsome J.","year":"2005","unstructured":"J. Newsome and D. Song . Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software . In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05) , Feb. 2005 . J. Newsome and D. Song. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05), Feb. 2005."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2004.1317662"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_2"},{"key":"e_1_3_2_1_32_1","volume-title":"Secure Networks","author":"Ptacek T. H.","year":"1998","unstructured":"T. H. Ptacek and T. N. Newsham . Insertion, evasion, and denial of service: Eluding network intrusion detection. Technical report , Secure Networks , Inc., Suite 330, 1201 5th Street S.W, Calgary, Alberta, Canada, T2R-0Y6, 1998 . T. H. Ptacek and T. N. Newsham. Insertion, evasion, and denial of service: Eluding network intrusion detection. Technical report, Secure Networks, Inc., Suite 330, 1201 5th Street S.W, Calgary, Alberta, Canada, T2R-0Y6, 1998."},{"key":"e_1_3_2_1_33_1","volume-title":"Virus Bulletin","author":"Raiu C.","year":"2001","unstructured":"C. Raiu . Holding the Bady . In Virus Bulletin , 2001 . C. Raiu. Holding the Bady. In Virus Bulletin, 2001."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.9"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.10"},{"key":"e_1_3_2_1_36_1","volume-title":"Microsoft Windows Internals","author":"Russinovich M. E.","year":"2004","unstructured":"M. E. Russinovich and D. A. Solomon . Microsoft Windows Internals , Fourth Edition. 2004 . M. E. Russinovich and D. A. Solomon. Microsoft Windows Internals, Fourth Edition. 2004."},{"key":"e_1_3_2_1_37_1","volume-title":"OSDI","author":"Singh S.","year":"2004","unstructured":"S. Singh , C. Estan , G. Varghese , and S. Savage . Automated worm fingerprinting . In OSDI , 2004 . S. Singh, C. Estan, G. Varghese, and S. Savage. Automated worm fingerprinting. In OSDI, 2004."},{"key":"e_1_3_2_1_38_1","volume-title":"The Art of Computer Virus Research and Defense","author":"Szor P.","year":"2005","unstructured":"P. Szor . The Art of Computer Virus Research and Defense . 2005 . P. Szor. The Art of Computer Virus Research and Defense. 2005."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/366173.366187"},{"key":"e_1_3_2_1_40_1","first-page":"274","volume-title":"RAID","author":"Toth T.","year":"2002","unstructured":"T. Toth and C. Kr\u00fcgel . Accurate buffer overflow detection via abstract payload execution . In RAID , pages 274 -- 291 , 2002 . T. Toth and C. Kr\u00fcgel. Accurate buffer overflow detection via abstract payload execution. In RAID, pages 274--291, 2002."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.31"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030088"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015489"},{"key":"e_1_3_2_1_44_1","volume-title":"USENIX Security Symposium","author":"Yegneswaran V.","year":"2005","unstructured":"V. Yegneswaran , J. T. Giffin , P. Barford , and S. Jha . An architecture for generating semantics-aware signatures . In USENIX Security Symposium , 2005 . V. Yegneswaran, J. T. Giffin, P. Barford, and S. Jha. An architecture for generating semantics-aware signatures. In USENIX Security Symposium, 2005."},{"key":"e_1_3_2_1_45_1","volume-title":"Malicious Cryptography: Exposing Cryptovirology","author":"Young A.","year":"2004","unstructured":"A. Young and M. Yung . Malicious Cryptography: Exposing Cryptovirology . 2004 . A. Young and M. Yung. Malicious Cryptography: Exposing Cryptovirology. 2004."},{"key":"e_1_3_2_1_46_1","unstructured":"bochs: the Open Source IA-32 Emulation Project (Home Page) http:\/\/bochs.sourceforge.net.  bochs: the Open Source IA-32 Emulation Project (Home Page) http:\/\/bochs.sourceforge.net."},{"key":"e_1_3_2_1_47_1","unstructured":"eEye advisory for the DCOM RPC Race Condition (http:\/\/www.eeye.com\/html\/research\/advisories\/ AD20040413B.html).  eEye advisory for the DCOM RPC Race Condition (http:\/\/www.eeye.com\/html\/research\/advisories\/ AD20040413B.html)."},{"key":"e_1_3_2_1_48_1","unstructured":"eEye advisory for the LSASS buffer overflow (http:\/\/www.eeye.com\/html\/research\/advisories\/ AD20040413C.html).  eEye advisory for the LSASS buffer overflow (http:\/\/www.eeye.com\/html\/research\/advisories\/ AD20040413C.html)."},{"key":"e_1_3_2_1_49_1","unstructured":"General William T. Sherman as quoted in B. H. Liddell Hart Strategy second revised edition.  General William T. Sherman as quoted in B. H. Liddell Hart Strategy second revised edition."},{"key":"e_1_3_2_1_50_1","unstructured":"Microsoft advisory MSXX-YYY (http:\/\/www.microsoft.com\/technet\/security\/bulletin\/ MSXX-YYY.mspx).  Microsoft advisory MSXX-YYY (http:\/\/www.microsoft.com\/technet\/security\/bulletin\/ MSXX-YYY.mspx)."},{"key":"e_1_3_2_1_51_1","unstructured":"QEMU (Home Page) http:\/\/fabrice.bellard.free.fr\/qemu\/.  QEMU (Home Page) http:\/\/fabrice.bellard.free.fr\/qemu\/."},{"key":"e_1_3_2_1_52_1","unstructured":"Security Focus Vulnerability Notes (http:\/\/www.securityfocus.com) bid == Bugtraq ID.  Security Focus Vulnerability Notes (http:\/\/www.securityfocus.com) bid == Bugtraq ID."},{"key":"e_1_3_2_1_53_1","volume-title":"The open source network intrusion detection system (http:\/\/www.snort.org)","author":"SNORT","year":"2002","unstructured":"SNORT : The open source network intrusion detection system (http:\/\/www.snort.org) . 2002 . SNORT: The open source network intrusion detection system (http:\/\/www.snort.org). 2002."}],"event":{"name":"CCS05: 12th ACM Conference on Computer and Communications Security 2005","location":"Alexandria VA USA","acronym":"CCS05","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the 12th ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1102120.1102152","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1102120.1102152","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:08:07Z","timestamp":1750262887000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1102120.1102152"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,11,7]]},"references-count":53,"alternative-id":["10.1145\/1102120.1102152","10.1145\/1102120"],"URL":"https:\/\/doi.org\/10.1145\/1102120.1102152","relation":{},"subject":[],"published":{"date-parts":[[2005,11,7]]},"assertion":[{"value":"2005-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}