{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:38:08Z","timestamp":1778632688583,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2005,11,11]],"date-time":"2005-11-11T00:00:00Z","timestamp":1131667200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2005,11,11]]},"DOI":"10.1145\/1103626.1103633","type":"proceedings-article","created":{"date-parts":[[2006,2,6]],"date-time":"2006-02-06T15:52:40Z","timestamp":1139241160000},"page":"30-40","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":62,"title":["Defending against hitlist worms using network address space randomization"],"prefix":"10.1145","author":[{"given":"S.","family":"Antonatos","sequence":"first","affiliation":[{"name":"Institute of Computer Science, Hellas, Heraklion, Crete, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"P.","family":"Akritidis","sequence":"additional","affiliation":[{"name":"Institute of Computer Science, Hellas, Heraklion, Crete, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"E. P.","family":"Markatos","sequence":"additional","affiliation":[{"name":"Institute of Computer Science, Hellas, Heraklion, Crete, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"K. G.","family":"Anagnostakis","sequence":"additional","affiliation":[{"name":"Institute for Infocomm Research, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,11,11]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"D Shield: Distributed Intrusion Detection System. http:\/\/www.dshield.org.]]  D Shield: Distributed Intrusion Detection System. http:\/\/www.dshield.org.]]"},{"key":"e_1_3_2_1_2_1","unstructured":"CERT Advisory CA-2001-19: 'CodeRed' Worm Exploiting Buffer Overflow in IIS Indexing Service DLL. http:\/\/www.cert.org\/advisories\/CA-200119.html July 2001.]]  CERT Advisory CA-2001-19: 'CodeRed' Worm Exploiting Buffer Overflow in IIS Indexing Service DLL. http:\/\/www.cert.org\/advisories\/CA-200119.html July 2001.]]"},{"key":"e_1_3_2_1_3_1","unstructured":"NLANR-PMAT traffic Archive: BellLabs-Itrace. http:\/\/pma.nlanr.net\/Traces\/Traces\/long\/bell\/1 2002.]]  NLANR-PMAT traffic Archive: BellLabs-Itrace. http:\/\/pma.nlanr.net\/Traces\/Traces\/long\/bell\/1 2002.]]"},{"key":"e_1_3_2_1_4_1","unstructured":"NLANR-PMAT taffic archive: Leipzig-Itrace. http:\/\/pma.nlanr.net\/Traces\/Traces\/long\/leip\/1 2002.]]  NLANR-PMAT taffic archive: Leipzig-Itrace. http:\/\/pma.nlanr.net\/Traces\/Traces\/long\/leip\/1 2002.]]"},{"key":"e_1_3_2_1_5_1","unstructured":"DISCO\n  : The Passive IP Discovery Tool. http:\/\/www.altmode.com\/disco\/ 2004.]]  DISCO: The Passive IP Discovery Tool. http:\/\/www.altmode.com\/disco\/ 2004.]]"},{"key":"e_1_3_2_1_6_1","unstructured":"Fingerprinting: The complete documentation. http:\/\/www.l0t3k.org\/security\/docs\/fingerprinting\/ 2004.]]  Fingerprinting: The complete documentation. http:\/\/www.l0t3k.org\/security\/docs\/fingerprinting\/ 2004.]]"},{"key":"e_1_3_2_1_7_1","unstructured":"Fingerprinting: The complete tools box. http:\/\/www.l0t3k.org\/security\/tools\/fingerprinting\/ 2004.]]  Fingerprinting: The complete tools box. http:\/\/www.l0t3k.org\/security\/tools\/fingerprinting\/ 2004.]]"},{"key":"e_1_3_2_1_8_1","volume-title":"Dec.","author":"Uses Net Worm","year":"2004","unstructured":"Net Worm Uses Google to Spread . http:\/\/it.slashdot.org\/it\/04\/12\/21\/2135235.shtml , Dec. 2004 .]] Net Worm Uses Google to Spread. http:\/\/it.slashdot.org\/it\/04\/12\/21\/2135235.shtml, Dec. 2004.]]"},{"key":"e_1_3_2_1_9_1","volume-title":"http:\/\/thc.org\/releases.php","year":"2004","unstructured":"THC-Amap. http:\/\/thc.org\/releases.php , 2004 .]] THC-Amap. http:\/\/thc.org\/releases.php, 2004.]]"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICON.2003.1266224"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1052812.1052823"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 6th IEEE International Symposiumon Object-oriented Real-time Distributed Computing","author":"Atighetchi M.","year":"2003","unstructured":"M. Atighetchi , P. Pal , F. Webber , R. Schantz , and C. Jones . Adaptive use of network-centric mechanisms in cyber-defense .In Proceedings of the 6th IEEE International Symposiumon Object-oriented Real-time Distributed Computing , May 2003 .]] M. Atighetchi, P. Pal, F. Webber, R. Schantz, and C. Jones. Adaptive use of network-centric mechanisms in cyber-defense.In Proceedings of the 6th IEEE International Symposiumon Object-oriented Real-time Distributed Computing, May 2003.]]"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1023720.1023722"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948147"},{"key":"e_1_3_2_1_15_1","first-page":"105","volume-title":"In Proceedings of the 12th USENIX Security Symposium","author":"Bhatkar S.","year":"2003","unstructured":"S. Bhatkar , D. DuVarney , and R. Sekar . Address obfuscation: An efficient approach to combat abroad range of memory error exploits . In In Proceedings of the 12th USENIX Security Symposium , pages 105 -- 120 , Aug. 2003 .]] S. Bhatkar, D. DuVarney, and R. Sekar. Address obfuscation: An efficient approach to combat abroad range of memory error exploits. In In Proceedings of the 12th USENIX Security Symposium, pages 105--120, Aug. 2003.]]"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/195792.195795"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31966-5_9"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"B. Croft and J. Gilmore. Bootstrap Protocol(BOOTP). RFC951 http:\/\/www.rfc-editor.org\/ Sept. 1985.]]   B. Croft and J. Gilmore. Bootstrap Protocol(BOOTP). RFC951 http:\/\/www.rfc-editor.org\/ Sept. 1985.]]","DOI":"10.17487\/rfc0951"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"R. Droms. Dynamic Host Configuration Protocol. RFC2131 http:\/\/www.rfc-editor.org\/ Mar. 1997.]]  R. Droms. Dynamic Host Configuration Protocol. RFC2131 http:\/\/www.rfc-editor.org\/ Mar. 1997.]]","DOI":"10.17487\/rfc2131"},{"key":"e_1_3_2_1_20_1","unstructured":"Internet Systems Consortium Inc. Dynamic host configuration protocol(DHCP)reference implementation .http:\/\/www.isc.org\/sw\/dhcp\/.]]  Internet Systems Consortium Inc. Dynamic host configuration protocol(DHCP)reference implementation .http:\/\/www.isc.org\/sw\/dhcp\/.]]"},{"key":"e_1_3_2_1_21_1","first-page":"489","volume-title":"USENIX Winter","author":"Ioannidis J.","year":"1993","unstructured":"J. Ioannidis and G. Q. Maguire Jr . The design and implementation of amobile internet working architecture . In USENIX Winter , pages 489 -- 502 , 1993 .]] J. Ioannidis and G. Q. Maguire Jr. The design and implementation of amobile internet working architecture. In USENIX Winter, pages 489--502, 1993.]]"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2004.1301325"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/505202.505223"},{"key":"e_1_3_2_1_24_1","first-page":"199","volume-title":"In Proceedings of the 2004 USENIX Technical Conference","author":"Kaminsky M.","year":"2004","unstructured":"M. Kaminsky , E. Peterson , D. B. Giffin , K. Fu , D. Mazires , and M. F. Kaashoek . REX: Secure, extensible remote execution . In In Proceedings of the 2004 USENIX Technical Conference , pages 199 -- 212 , June- July 2004 .]] M. Kaminsky, E. Peterson, D. B. Giffin, K. Fu, D. Mazires, and M. F. Kaashoek. REX: Secure, extensible remote execution. In In Proceedings of the 2004 USENIX Technical Conference, pages 199--212, June-July 2004.]]"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028804"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2001.932214"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.18"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2003.1194893"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2004.1317662"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_4"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988742"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE), Workshop on Enterprise Security","author":"Keromytis S. Sidiroglouand A. D.","year":"2003","unstructured":"S. Sidiroglouand A. D. Keromytis . Anetwork worm vaccine architecture . In Proceedings of the IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE), Workshop on Enterprise Security , June 2003 .]] S. Sidiroglouand A. D. Keromytis. Anetwork worm vaccine architecture. In Proceedings of the IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE), Workshop on Enterprise Security, June 2003.]]"},{"key":"e_1_3_2_1_38_1","volume-title":"Proceedings of the 6th Symposiumon Operating Systems Design & Implementation (OSDI)","author":"Singh S.","year":"2004","unstructured":"S. Singh , C. Estan , G. Varghese , and S. Savage . Automated worm finger printing . In Proceedings of the 6th Symposiumon Operating Systems Design & Implementation (OSDI) , Dec. 2004 .]] S. Singh, C. Estan, G. Varghese, and S. Savage. Automated worm finger printing. In Proceedings of the 6th Symposiumon Operating Systems Design & Implementation (OSDI), Dec. 2004.]]"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/345910.345938"},{"key":"e_1_3_2_1_40_1","volume-title":"Containment of Scanning Worms in Enterprise Networks. Journal of Computer Security","author":"Staniford S.","year":"2004","unstructured":"S. Staniford . Containment of Scanning Worms in Enterprise Networks. Journal of Computer Security , 2004 .]] S. Staniford. Containment of Scanning Worms in Enterprise Networks. Journal of Computer Security, 2004.]]"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029624"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720288"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection(RAID)","author":"Kr\u00fcgel T. Tothand C.","year":"2002","unstructured":"T. Tothand C. Kr\u00fcgel . Accurate buffer overflow detection via abstract payload execution . In Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection(RAID) , Oct. 2002 .]] T. Tothand C. Kr\u00fcgel. Accurate buffer overflow detection via abstract payload execution. In Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection(RAID), Oct. 2002.]]"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015489"},{"key":"e_1_3_2_1_45_1","first-page":"201","volume-title":"Stolfo. Anomalous Payload-based Network Intrusion Detection. In Proceedings of the 7th International Symposiumon Recent Advanced in Intrusion Detection (RAID)","author":"K. Wangand S.","year":"2004","unstructured":"K. Wangand S. J. Stolfo. Anomalous Payload-based Network Intrusion Detection. In Proceedings of the 7th International Symposiumon Recent Advanced in Intrusion Detection (RAID) , pages 201 -- 222 , Sept. 2004 .]] K. Wangand S. J. Stolfo. Anomalous Payload-based Network Intrusion Detection. In Proceedings of the 7th International Symposiumon Recent Advanced in Intrusion Detection (RAID), pages 201--222, Sept. 2004.]]"},{"key":"e_1_3_2_1_46_1","volume-title":"Proc. Third Annual Workshop on Economics and Information Security (WEIS'04)","author":"Weaver N.","year":"2004","unstructured":"N. Weaver and V. Paxson . A worst-caseworm . In Proc. Third Annual Workshop on Economics and Information Security (WEIS'04) , May 2004 .]] N. Weaver and V. Paxson. A worst-caseworm. In Proc. Third Annual Workshop on Economics and Information Security (WEIS'04), May 2004.]]"},{"key":"e_1_3_2_1_47_1","first-page":"29","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Weaver N.","year":"2004","unstructured":"N. Weaver , S. Staniford , and V. Paxson . Very Fast Containment of Scanning Worms . In Proceedings of the 13th USENIX Security Symposium , pages 29 -- 44 , Aug. 2004 .]] N. Weaver, S. Staniford, and V. Paxson. Very Fast Containment of Scanning Worms. In Proceedings of the 13th USENIX Security Symposium, pages 29--44, Aug. 2004.]]"},{"key":"e_1_3_2_1_49_1","first-page":"143","volume-title":"Proceedings of the Network and Distributed System Security Symposium(NDSS)","author":"Wu J.","year":"2004","unstructured":"J. Wu , S. Vangala , L. Gao , and K. Kwiat . An Effective Architecture and Algorithm for Detecting Worms with Various Scan Techniques . In Proceedings of the Network and Distributed System Security Symposium(NDSS) , pages 143 -- 156 , Feb. 2004 .]] J. Wu, S. Vangala, L. Gao, and K. Kwiat. An Effective Architecture and Algorithm for Detecting Worms with Various Scan Techniques. In Proceedings of the Network and Distributed System Security Symposium(NDSS), pages 143--156, Feb. 2004.]]"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1109\/RELDIS.2003.1238076","volume-title":"Proc. 22nd Symp. on Reliable Distributed Systems-SRDS2003","author":"Xu J.","year":"2003","unstructured":"J. Xu , Z. Kalbarczyk , and R. Iyer . Transparent runtime randomization for security. In A. Fantechi, editor , Proc. 22nd Symp. on Reliable Distributed Systems-SRDS2003 , pages 260 -- 269 , Oct. 2003 .]] J. Xu, Z. Kalbarczyk, and R. Iyer. Transparent runtime randomization for security. In A. Fantechi, editor, Proc. 22nd Symp. on Reliable Distributed Systems-SRDS2003, pages 260--269, Oct. 2003.]]"},{"key":"e_1_3_2_1_51_1","volume-title":"In Proc. USENIX","author":"Yarvin C.","year":"1993","unstructured":"C. Yarvin , R. Bukowski , and T. Anderson . Anonymous RPC: Low-latency protection in a 64-bit address space . In In Proc. USENIX Summer 1993 Technical Conference, pages 175- -186, June 1993.]] C. Yarvin, R. Bukowski, and T. Anderson. Anonymous RPC: Low-latency protection in a 64-bit address space. In In Proc. USENIX Summer 1993 Technical Conference, pages 175--186, June 1993.]]"},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium(NDSS)","author":"Yegneswaran V.","year":"2004","unstructured":"V. Yegneswaran , P. Barford , and S. Jha . Global Intrusion Detection in the DOMINO Overlay System . In Proceedings of the Network and Distributed System Security Symposium(NDSS) , Feb. 2004 .]] V. Yegneswaran, P. Barford, and S. Jha. Global Intrusion Detection in the DOMINO Overlay System. In Proceedings of the Network and Distributed System Security Symposium(NDSS), Feb. 2004.]]"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948136"}],"event":{"name":"CCS05: 12th ACM Conference on Computer and Communications Security 2005","location":"Fairfax VA USA","acronym":"CCS05","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the 2005 ACM workshop on Rapid malcode"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1103626.1103633","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1103626.1103633","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:07:52Z","timestamp":1750262872000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1103626.1103633"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,11,11]]},"references-count":51,"alternative-id":["10.1145\/1103626.1103633","10.1145\/1103626"],"URL":"https:\/\/doi.org\/10.1145\/1103626.1103633","relation":{},"subject":[],"published":{"date-parts":[[2005,11,11]]},"assertion":[{"value":"2005-11-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}