{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T08:26:11Z","timestamp":1783153571622,"version":"3.54.6"},"reference-count":175,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2008,12,1]],"date-time":"2008-12-01T00:00:00Z","timestamp":1228089600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Comput. Syst."],"published-print":{"date-parts":[[2008,12]]},"abstract":"<jats:p>Worm containment must be automatic because worms can spread too fast for humans to respond. Recent work proposed network-level techniques to automate worm containment; these techniques have limitations because there is no information about the vulnerabilities exploited by worms at the network level. We propose Vigilante, a new end-to-end architecture to contain worms automatically that addresses these limitations.<\/jats:p>\n          <jats:p>\n            In Vigilante, hosts detect worms by instrumenting vulnerable programs to analyze infection attempts. We introduce\n            <jats:italic>dynamic data-flow analysis<\/jats:italic>\n            : a broad-coverage host-based algorithm that can detect unknown worms by tracking the flow of data from network messages and disallowing unsafe uses of this data. We also show how to integrate other host-based detection mechanisms into the Vigilante architecture. Upon detection, hosts generate\n            <jats:italic>self-certifying alerts<\/jats:italic>\n            (SCAs), a new type of security alert that can be inexpensively verified by any vulnerable host. Using SCAs, hosts can cooperate to contain an outbreak, without having to trust each other. Vigilante broadcasts SCAs over an overlay network that propagates alerts rapidly and resiliently. Hosts receiving an SCA protect themselves by generating filters with\n            <jats:italic>vulnerability condition slicing<\/jats:italic>\n            : an algorithm that performs dynamic analysis of the vulnerable program to identify control-flow conditions that lead to successful attacks. These filters block the worm attack and all its polymorphic mutations that follow the execution path identified by the SCA.\n          <\/jats:p>\n          <jats:p>Our results show that Vigilante can contain fast-spreading worms that exploit unknown vulnerabilities, and that Vigilante's filters introduce a negligible performance overhead. Vigilante does not require any changes to hardware, compilers, operating systems, or the source code of vulnerable programs; therefore, it can be used to protect current software binaries.<\/jats:p>","DOI":"10.1145\/1455258.1455259","type":"journal-article","created":{"date-parts":[[2008,12,17]],"date-time":"2008-12-17T13:25:20Z","timestamp":1229520320000},"page":"1-68","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["Vigilante"],"prefix":"10.1145","volume":"26","author":[{"given":"Manuel","family":"Costa","sequence":"first","affiliation":[{"name":"University of Cambridge and Microsoft Research, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jon","family":"Crowcroft","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Miguel","family":"Castro","sequence":"additional","affiliation":[{"name":"Microsoft Research, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antony","family":"Rowstron","sequence":"additional","affiliation":[{"name":"Microsoft Research, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lidong","family":"Zhou","sequence":"additional","affiliation":[{"name":"Microsoft Research, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lintao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Microsoft Research, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul","family":"Barham","sequence":"additional","affiliation":[{"name":"Microsoft Research, Cambridge, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2008,12,19]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_2_1_2_1","unstructured":"Akamai. 2000. Press release: Akamai helps mcafee.com support flash crowds from iloveyou virus.  Akamai. 2000. Press release: Akamai helps mcafee.com support flash crowds from iloveyou virus."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062520"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.106"},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the USENIX Technical Conference.","author":"Baratloo A.","unstructured":"Baratloo , A. , Singh , N. , and Tsai , T . 2000. Transparent runtime defense against stack smashing attacks . In Proceedings of the USENIX Technical Conference. Baratloo, A., Singh, N., and Tsai, T. 2000. Transparent runtime defense against stack smashing attacks. In Proceedings of the USENIX Technical Conference."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948147"},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of 14th USENIX Security Symposium.","author":"Bethencourt J.","unstructured":"Bethencourt , J. , Franklin , J. , and Vernon , M . 2005. Mapping Internet sensors with probe response attacks . In Proceedings of 14th USENIX Security Symposium. Bethencourt, J., Franklin, J., and Vernon, M. 2005. Mapping Internet sensors with probe response attacks. In Proceedings of 14th USENIX Security Symposium."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134760.1220164"},{"key":"e_1_2_1_11_1","volume-title":"Proceedings of 12th USENIX Security Symposium.","author":"Bhatkar S.","unstructured":"Bhatkar , S. , DuVarney , D. C. , and Sekar , R . 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits . In Proceedings of 12th USENIX Security Symposium. Bhatkar, S., DuVarney, D. C., and Sekar, R. 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In Proceedings of 12th USENIX Security Symposium."},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of 14th USENIX Security Symposium.","author":"Bhatkar S.","year":"2005","unstructured":"Bhatkar , S. , Sekar , R. , and DuVarney , D. C. 2005 . Efficient techniques for comprehensive protection from memory error exploits . In Proceedings of 14th USENIX Security Symposium. Bhatkar, S., Sekar, R., and DuVarney, D. C. 2005. Efficient techniques for comprehensive protection from memory error exploits. In Proceedings of 14th USENIX Security Symposium."},{"key":"e_1_2_1_14_1","unstructured":"blexim. 2002. Basic integer overflows. Phrack 60.  blexim. 2002. Basic integer overflows. Phrack 60."},{"key":"e_1_2_1_15_1","unstructured":"Bochs. 2006. Bochs ia-32 emulator. http:\/\/bochs.sourceforge.net.  Bochs. 2006. Bochs ia-32 emulator. http:\/\/bochs.sourceforge.net."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/800027.808445"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 4th ACM Workshop on Feedback-Directed and Dynamic Optimization.","author":"Bruening D.","unstructured":"Bruening , D. , Duesterwald , E. , and Amarasinghe , S . 2001. Design and implementation of a dynamic optimization framework for Windows . In Proceedings of the 4th ACM Workshop on Feedback-Directed and Dynamic Optimization. Bruening, D., Duesterwald, E., and Amarasinghe, S. 2001. Design and implementation of a dynamic optimization framework for Windows. In Proceedings of the 4th ACM Workshop on Feedback-Directed and Dynamic Optimization."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.41"},{"key":"e_1_2_1_19_1","first-page":"46","article-title":"Bypassing stackguard and stackshield","volume":"10","author":"Bulba","year":"2000","unstructured":"Bulba and Kil3r. 2000 . Bypassing stackguard and stackshield . Phrack 10 , 46 (May). Bulba and Kil3r. 2000. Bypassing stackguard and stackshield. Phrack 10, 46 (May).","journal-title":"Phrack"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1002\/(SICI)1097-024X(200006)30:7%3C775::AID-SPE309%3E3.0.CO;2-H"},{"key":"e_1_2_1_21_1","volume-title":"The Computer Science and Engineering Handbook","author":"Cardelli L.","unstructured":"Cardelli , L. 2004. Type systems . In The Computer Science and Engineering Handbook . CRC Press . Cardelli, L. 2004. Type systems. In The Computer Science and Engineering Handbook. CRC Press."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation.","author":"Castro M.","unstructured":"Castro , M. , Costa , M. , and Harris , T . 2006. Securing software by enforcing data-flow integrity . In Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation. Castro, M., Costa, M., and Harris, T. 2006. Securing software by enforcing data-flow integrity. In Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the International Conference on Dependable Systems and Networks.","author":"Castro M.","unstructured":"Castro , M. , Costa , M. , and Rowstron , A . 2004. Performance and dependability of structured peer-to-peer overlays . In Proceedings of the International Conference on Dependable Systems and Networks. Castro, M., Costa, M., and Rowstron, A. 2004. Performance and dependability of structured peer-to-peer overlays. In Proceedings of the International Conference on Dependable Systems and Networks."},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation.","author":"Castro M.","unstructured":"Castro , M. , Druschel , P. , Ganesh , A. , Rowstron , A. , and Wallach , D. S . 2002. Security for structured peer-to-peer overlay networks . In Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation. Castro, M., Druschel, P., Ganesh, A., Rowstron, A., and Wallach, D. S. 2002. Security for structured peer-to-peer overlay networks. In Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_25_1","unstructured":"CERT. 2001. Cert advisory ca-2001-26 nimda worm. http:\/\/www.cert.org\/advisories\/ca-2001-26.html.  CERT. 2001. Cert advisory ca-2001-26 nimda worm. http:\/\/www.cert.org\/advisories\/ca-2001-26.html."},{"key":"e_1_2_1_26_1","unstructured":"CERT. 2005. Technical cyber security alerts. http:\/\/www.us-cert.gov.  CERT. 2005. Technical cyber security alerts. http:\/\/www.us-cert.gov."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.36"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of 14th USENIX Security Symposium.","author":"Chen S.","unstructured":"Chen , S. , Xu , J. , Sezer , E. C. , Gauriar , P. , and Iyer , R. K . 2005. Non-Control-Data attacks are realistic threats . In Proceedings of 14th USENIX Security Symposium. Chen, S., Xu, J., Sezer, E. C., Gauriar, P., and Iyer, R. K. 2005. Non-Control-Data attacks are realistic threats. In Proceedings of 14th USENIX Security Symposium."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the 22th IEEE Conference on Computer Communications.","author":"Chen Z.","unstructured":"Chen , Z. , Gao , L. , and Kwiat , K . 2003. Modelling the spread of active worms . In Proceedings of the 22th IEEE Conference on Computer Communications. Chen, Z., Gao, L., and Kwiat, K. 2003. Modelling the spread of active worms. In Proceedings of the 22th IEEE Conference on Computer Communications."},{"key":"e_1_2_1_30_1","unstructured":"Cheswick W. R. Bellovin S. M. and Rubin A. D. 2003. Firewalls and Internet Security: Repelling the Wily Hacker. Addison-Wesley.   Cheswick W. R. Bellovin S. M. and Rubin A. D. 2003. Firewalls and Internet Security: Repelling the Wily Hacker. Addison-Wesley."},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection.","author":"Chinchani R.","unstructured":"Chinchani , R. and van den Berg, E. 2005. A fast static analysis approach to detect exploit code inside network flows . In Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection. Chinchani, R. and van den Berg, E. 2005. A fast static analysis approach to detect exploit code inside network flows. In Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection."},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the 21st International Conference on Distributed Computing Systems.","author":"Chiueh T.","unstructured":"Chiueh , T. and Hsu , F . 2001. RAD: A compile-time solution to buffer overflow attacks . In Proceedings of the 21st International Conference on Distributed Computing Systems. Chiueh, T. and Hsu, F. 2001. RAD: A compile-time solution to buffer overflow attacks. In Proceedings of the 21st International Conference on Distributed Computing Systems."},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of 13th USENIX Security Symposium.","author":"Chow J.","unstructured":"Chow , J. , Pfaff , B. , Garfinkel , T. , Christopher , K. , and Rosenblum , M . 2004. Understanding data lifetime via whole system simulation . In Proceedings of 13th USENIX Security Symposium. Chow, J., Pfaff, B., Garfinkel, T., Christopher, K., and Rosenblum, M. 2004. Understanding data lifetime via whole system simulation. In Proceedings of 13th USENIX Security Symposium."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(87)90122-2"},{"key":"e_1_2_1_35_1","unstructured":"Cormen T. H. Leiserson C. E. and Rivest R. L. 1990. Introduction to Algorithms. MIT Electrical Engineering and Computer Science Series. MIT Press.   Cormen T. H. Leiserson C. E. and Rivest R. L. 1990. Introduction to Algorithms. MIT Electrical Engineering and Computer Science Series. MIT Press."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294274"},{"key":"e_1_2_1_37_1","unstructured":"Costa M. Crowcroft J. Castro M. and Rowstron A. 2004. Can we contain Internet worms&quest; In Proceedings of the 3rd Workshop on Hot Topics in Networks.  Costa M. Crowcroft J. Castro M. and Rowstron A. 2004. Can we contain Internet worms&quest; In Proceedings of the 3rd Workshop on Hot Topics in Networks."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095824"},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Cowan C.","unstructured":"Cowan , C. , Barringer , M. , Beattie , S. , Kroah-Hartman , G. , Frantzen , M. , and Lokier , J . 2001. Formatguard: Automatic protection from printf format string vulnerabilities . In Proceedings of the 10th USENIX Security Symposium. Cowan, C., Barringer, M., Beattie, S., Kroah-Hartman, G., Frantzen, M., and Lokier, J. 2001. Formatguard: Automatic protection from printf format string vulnerabilities. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the 12th USENIX Security Symposium.","author":"Cowan C.","unstructured":"Cowan , C. , Beattie , S. , Johansen , J. , and Wagle , P . 2003. Pointguard: Protecting pointers from buffer overflow vulnerabilities . In Proceedings of the 12th USENIX Security Symposium. Cowan, C., Beattie, S., Johansen, J., and Wagle, P. 2003. Pointguard: Protecting pointers from buffer overflow vulnerabilities. In Proceedings of the 12th USENIX Security Symposium."},{"key":"e_1_2_1_41_1","volume-title":"Proceedings of the 7th USENIX Security Symposium.","author":"Cowan C.","unstructured":"Cowan , C. , Pu , C. , Maier , D. , Hinton , H. , Wadpole , J. , Bakke , P. , Beattie , S. , Grier , A. , Wagle , P. , and Zhang , Q . 1998. Stackguard: Automatic detection and prevention of buffer-overrun attacks . In Proceedings of the 7th USENIX Security Symposium. Cowan, C., Pu, C., Maier, D., Hinton, H., Wadpole, J., Bakke, P., Beattie, S., Grier, A., Wagle, P., and Zhang, Q. 1998. Stackguard: Automatic detection and prevention of buffer-overrun attacks. In Proceedings of the 7th USENIX Security Symposium."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.26"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102152"},{"key":"e_1_2_1_44_1","first-page":"55","article-title":"Win32 buffer overflows","volume":"9","author":"Dark Spyrit","year":"1999","unstructured":"Dark Spyrit . 1999 . Win32 buffer overflows . Phrack 9 , 55 . Dark Spyrit. 1999. Win32 buffer overflows. Phrack 9, 55.","journal-title":"Phrack"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/360933.360975"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.5555\/646334.687813"},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation.","author":"Dunlap G. W.","unstructured":"Dunlap , G. W. , King , S. T. , Cinar , S. , Basrai , M. A. , and Chen , P. M . 2002. Revirt: Enabling intrusion analysis through virtual-machine logging and replay . In Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation. Dunlap, G. W., King, S. T., Cinar, S., Basrai, M. A., and Chen, P. M. 2002. Revirt: Enabling intrusion analysis through virtual-machine logging and replay. In Proceedings of the 5th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_49_1","unstructured":"Durden T. 2002. Bypassing pax aslr protection. Phrack 59 (Jul.).  Durden T. 2002. Bypassing pax aslr protection. Phrack 59 (Jul.)."},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Eichin M. W.","unstructured":"Eichin , M. W. and Rochlis , J. A . 1989. With microscope and tweezers: An analysis of the Internet virus of November 1988 . In Proceedings of the IEEE Symposium on Security and Privacy. Eichin, M. W. and Rochlis, J. A. 1989. With microscope and tweezers: An analysis of the Internet virus of November 1988. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/568522.568525"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/502034.502041"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.976940"},{"key":"e_1_2_1_54_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Feng H.","unstructured":"Feng , H. , Kolesnikov , O. , Fogla , P. , Lee , W. , and Gong , W . 2003. Anomaly detection using system call information . In Proceedings of the IEEE Symposium on Security and Privacy. Feng, H., Kolesnikov, O., Fogla, P., Lee, W., and Gong, W. 2003. Anomaly detection using system call information. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_56_1","volume-title":"An abstract computer model demonstrating directional information flow","author":"Fenton J.","unstructured":"Fenton , J. 1974a. An abstract computer model demonstrating directional information flow . University of Cambridge , Cambridge, UK . Fenton, J. 1974a. An abstract computer model demonstrating directional information flow. University of Cambridge, Cambridge, UK."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/17.2.143"},{"key":"e_1_2_1_58_1","volume-title":"Proceedings of 15th USENIX Security Symposium.","author":"Fogla P.","unstructured":"Fogla , P. , Sharif , M. , Perdisci , R. , Kolesnikov , O. , and Lee , W . 2006. Polymorphic blending attacks . In Proceedings of 15th USENIX Security Symposium. Fogla, P., Sharif, M., Perdisci, R., Kolesnikov, O., and Lee, W. 2006. Polymorphic blending attacks. In Proceedings of 15th USENIX Security Symposium."},{"key":"e_1_2_1_59_1","unstructured":"Forescout. 2006. Wormscout. http:\/\/www.forescout.com\/wormscout.html.  Forescout. 2006. Wormscout. http:\/\/www.forescout.com\/wormscout.html."},{"key":"e_1_2_1_60_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Forrest S.","unstructured":"Forrest , S. , Hofmeyr , S. A. , Somayaji , A. , and Longstaff , T. A . 1996. A sense of self for Unix processes . In Proceedings of the IEEE Symposium on Security and Privacy. Forrest, S., Hofmeyr, S. A., Somayaji, A., and Longstaff, T. A. 1996. A sense of self for Unix processes. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the 6th Workshop on Hot Topics in Operating Systems.","author":"Forrest S.","unstructured":"Forrest , S. , Somayaji , A. , and Ackley , D . 1997. Building diverse computer systems . In Proceedings of the 6th Workshop on Hot Topics in Operating Systems. Forrest, S., Somayaji, A., and Ackley, D. 1997. Building diverse computer systems. In Proceedings of the 6th Workshop on Hot Topics in Operating Systems."},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Fraser K.","unstructured":"Fraser , K. and Chang , F . 2003. Operating System I\/O Speculation: How two invocations are faster than one . In Proceedings of the USENIX Annual Technical Conference. Fraser, K. and Chang, F. 2003. Operating System I\/O Speculation: How two invocations are faster than one. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_63_1","volume-title":"Proceedings of the 25th IEEE Conference on Computer Communications.","author":"Ganesh A.","unstructured":"Ganesh , A. , Gunawardena , D. , Key , P. , Massoulie , L. , and Scott , J . 2006. Efficient quarantining of scanning worms: Optimal detection and coordination . In Proceedings of the 25th IEEE Conference on Computer Communications. Ganesh, A., Gunawardena, D., Key, P., Massoulie, L., and Scott, J. 2006. Efficient quarantining of scanning worms: Optimal detection and coordination. In Proceedings of the 25th IEEE Conference on Computer Communications."},{"key":"e_1_2_1_64_1","volume-title":"Tech. Rep. CS-02-144","author":"Ganger G.","year":"2002","unstructured":"Ganger , G. , Economu , G. , and Bielski , S . 2002 . Self-Securing network interfaces: What , why and how. Tech. Rep. CS-02-144 , Carnegie Mellon University . May. Ganger, G., Economu, G., and Bielski, S. 2002. Self-Securing network interfaces: What, why and how. Tech. Rep. CS-02-144, Carnegie Mellon University. May."},{"key":"e_1_2_1_65_1","unstructured":"Georgatos F. Gruber F. Karrenberg D. Santcroos M. Uijterwaal H. and Wilhelm R. 2001. Providing Active Measurements as a Regular Service for ISPs. http:\/\/www.ripe.net\/ttm.  Georgatos F. Gruber F. Karrenberg D. Santcroos M. Uijterwaal H. and Wilhelm R. 2001. Providing Active Measurements as a Regular Service for ISPs. http:\/\/www.ripe.net\/ttm."},{"key":"e_1_2_1_66_1","unstructured":"gera and riq. 2002. Advances in format string exploitation. Phrack 59 (Jul.).  gera and riq. 2002. Advances in format string exploitation. Phrack 59 (Jul.)."},{"key":"e_1_2_1_67_1","volume-title":"Proceedings of the 11th Annual Network and Distributed System Security Symposium.","author":"Giffin J.","unstructured":"Giffin , J. , Jha , S. , and Miller , B. P . 2004. Efficient context-sensitive intrusion detection . In Proceedings of the 11th Annual Network and Distributed System Security Symposium. Giffin, J., Jha, S., and Miller, B. P. 2004. Efficient context-sensitive intrusion detection. In Proceedings of the 11th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1038\/nphys177"},{"key":"e_1_2_1_69_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Heberlein L. T.","unstructured":"Heberlein , L. T. , Dias , G., K, L. , Wood , B. M. J. , and Wolber , D . 1990. A network security monitor . In Proceedings of the IEEE Symposium on Security and Privacy. Heberlein, L. T., Dias, G., K, L., Wood, B. M. J., and Wolber, D. 1990. A network security monitor. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0036144500371907"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217939"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1162\/106365600568257"},{"key":"e_1_2_1_73_1","volume-title":"Workshop on Information Assurance and Security.","author":"Holz T.","unstructured":"Holz , T. and Raynal , F . 2005. Detecting honeypots and other suspicious environments . In Workshop on Information Assurance and Security. Holz, T. and Raynal, F. 2005. Detecting honeypots and other suspicious environments. In Workshop on Information Assurance and Security."},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.14"},{"key":"e_1_2_1_75_1","unstructured":"Hua W. Ohlund J. and Butterklee B. 1999. Unraveling the mysteries of writing a winsock 2 layered service provider. Microsoft Syst. J.  Hua W. Ohlund J. and Butterklee B. 1999. Unraveling the mysteries of writing a winsock 2 layered service provider. Microsoft Syst. J."},{"key":"e_1_2_1_76_1","volume-title":"USENIX Windows NT Symposium.","author":"Hunt G.","unstructured":"Hunt , G. and Brubacher , D . 1999. Detours: Binary interception of Win32 functions . In USENIX Windows NT Symposium. Hunt, G. and Brubacher, D. 1999. Detours: Binary interception of Win32 functions. In USENIX Windows NT Symposium."},{"key":"e_1_2_1_77_1","volume-title":"Instruction set reference.","author":"Intel","unstructured":"Intel . 1999. Intel architecture software developer's manual , vol. 2 : Instruction set reference. Intel. 1999. Intel architecture software developer's manual, vol. 2: Instruction set reference."},{"key":"e_1_2_1_78_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Jim T.","unstructured":"Jim , T. , Morrisett , G. , Grossman , D. , Hicks , M. , Cheney , J. , and Wang , Y . 2002. Cyclone: A safe dialect of C . In Proceedings of the USENIX Annual Technical Conference. Jim, T., Morrisett, G., Grossman, D., Hicks, M., Cheney, J., and Wang, Y. 2002. Cyclone: A safe dialect of C. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_79_1","volume-title":"Proceedings of 13th USENIX Security Symposium.","author":"Johnson R.","unstructured":"Johnson , R. and Wagner , D . 2004. Finding user\/kernel pointer bugs with type inference . In Proceedings of 13th USENIX Security Symposium. Johnson, R. and Wagner, D. 2004. Finding user\/kernel pointer bugs with type inference. In Proceedings of 13th USENIX Security Symposium."},{"key":"e_1_2_1_80_1","volume-title":"Unix Programmer's Manual, 4.2.","author":"Johnson S. C.","unstructured":"Johnson , S. C. 1984. Lint , a C program checker . In Unix Programmer's Manual, 4.2. Berkeley Software Distribution Supplementary Documents . Johnson, S. C. 1984. Lint, a C program checker. In Unix Programmer's Manual, 4.2. Berkeley Software Distribution Supplementary Documents."},{"key":"e_1_2_1_81_1","volume-title":"Proceedings of the International Workshop on Automatic Debugging.","author":"Jones R.","unstructured":"Jones , R. and Kelly , P . 1997. Backwards-Compatible bounds checking for arrays and pointers in C programs . In Proceedings of the International Workshop on Automatic Debugging. Jones, R. and Kelly, P. 1997. Backwards-Compatible bounds checking for arrays and pointers in C programs. In Proceedings of the International Workshop on Automatic Debugging."},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095820"},{"key":"e_1_2_1_83_1","unstructured":"jp. 2003. Advanced doug lea's malloc exploits. Phrack 61 (Sept.).  jp. 2003. Advanced doug lea's malloc exploits. Phrack 61 (Sept.)."},{"key":"e_1_2_1_85_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Jung J.","unstructured":"Jung , J. , Paxson , V. , Berger , A. W. , and Balakrishnan , H . 2004. Fast portscan detection using sequential hypothesis testing . In Proceedings of the IEEE Symposium on Security and Privacy. Jung, J., Paxson, V., Berger, A. W., and Balakrishnan, H. 2004. Fast portscan detection using sequential hypothesis testing. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_2_1_87_1","volume-title":"International Virus Bulletin Conference.","author":"Kephart J. O.","unstructured":"Kephart , J. O. and Arnold , W. C . 1994. Automatic extraction of computer virus signatures . In International Virus Bulletin Conference. Kephart, J. O. and Arnold, W. C. 1994. Automatic extraction of computer virus signatures. In International Virus Bulletin Conference."},{"key":"e_1_2_1_88_1","volume-title":"International Virus Bulletin Conference.","author":"Kephart J. O.","unstructured":"Kephart , J. O. , Sorkin , G. B. , Swimmer , M. , and White , S. R . 1997. Blueprint for a computer immune system . In International Virus Bulletin Conference. Kephart, J. O., Sorkin, G. B., Swimmer, M., and White, S. R. 1997. Blueprint for a computer immune system. In International Virus Bulletin Conference."},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Kephart J. O.","unstructured":"Kephart , J. O. and White , S. R . 1991. Directed-Graph epidemiological models of computer viruses . In Proceedings of the IEEE Symposium on Security and Privacy. Kephart, J. O. and White, S. R. 1991. Directed-Graph epidemiological models of computer viruses. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_90_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Kim H.","unstructured":"Kim , H. and Karp , B . 2004. Autograph: Toward automated, distributed worm signature detection . In Proceedings of the 13th USENIX Security Symposium. Kim, H. and Karp, B. 2004. Autograph: Toward automated, distributed worm signature detection. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"e_1_2_1_92_1","volume-title":"Proceedings of the 11th USENIX Security Symposium.","author":"Kiriansky V.","unstructured":"Kiriansky , V. , Bruening , D. , and Amarasinghe , S. P . 2002. Secure execution via program shepherding . In Proceedings of the 11th USENIX Security Symposium. Kiriansky, V., Bruening, D., and Amarasinghe, S. P. 2002. Secure execution via program shepherding. In Proceedings of the 11th USENIX Security Symposium."},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the 2nd Workshop on Hot Topics in Networks.","author":"Kreibich C.","unstructured":"Kreibich , C. and Crowcroft , J . 2003. Honeycomb Creating intrusion detection signatures using honeypots . In Proceedings of the 2nd Workshop on Hot Topics in Networks. Kreibich, C. and Crowcroft, J. 2003. Honeycomb Creating intrusion detection signatures using honeypots. In Proceedings of the 2nd Workshop on Hot Topics in Networks."},{"key":"e_1_2_1_94_1","volume-title":"Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection.","author":"Kruegel C.","unstructured":"Kruegel , C. , Kirda , E. , Mutz , D. , Robertson , W. , and Vigna , G . 2005. Polymorphic worm detection using structural information of executables . In Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection. Kruegel, C., Kirda, E., Mutz, D., Robertson, W., and Vigna, G. 2005. Polymorphic worm detection using structural information of executables. In Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection."},{"key":"e_1_2_1_95_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Kruegel C.","unstructured":"Kruegel , C. , Kirda , E. , Mutz , D. , Robertsonand , W. , and Vigna , G . 2005. Automating mimicry attacks using static binary analysis . In Proceedings of the 14th USENIX Security Symposium. Kruegel, C., Kirda, E., Mutz, D., Robertsonand, W., and Vigna, G. 2005. Automating mimicry attacks using static binary analysis. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_96_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Larochelle D.","unstructured":"Larochelle , D. and Evans , D . 2001. Statically detecting likely buffer overflow vulnerabilities . In Proceedings of the 10th USENIX Security Symposium. Larochelle, D. and Evans, D. 2001. Statically detecting likely buffer overflow vulnerabilities. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.12"},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102150"},{"key":"e_1_2_1_99_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Livshits V. B.","unstructured":"Livshits , V. B. and Lam , M. S . 2005. Finding security vulnerabilities in java applications using static analysis . In Proceedings of the 14th USENIX Security Symposium. Livshits, V. B. and Lam, M. S. 2005. Finding security vulnerabilities in java applications using static analysis. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_100_1","volume-title":"Proceedings of the 13th Annual Network and Distributed System Security Symposium.","author":"Locasto M.","unstructured":"Locasto , M. , Sidiroglou , S. , and Keromytis , A . 2006. Software self-healling using collaborative application communities . In Proceedings of the 13th Annual Network and Distributed System Security Symposium. Locasto, M., Sidiroglou, S., and Keromytis, A. 2006. Software self-healling using collaborative application communities. In Proceedings of the 13th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_102_1","unstructured":"Mirage. 2006. Mirage networks. http:\/\/www.miragenetworks.com.  Mirage. 2006. Mirage networks. http:\/\/www.miragenetworks.com."},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_2_1_106_1","volume-title":"Proceedings of the 22th IEEE Conference on Computer Communications.","author":"Moore D.","unstructured":"Moore , D. , Shannon , C. , Voelker , G. , and Savage , S . 2003. Internet quarantine: Requirements for containing self-propagating code . In Proceedings of the 22th IEEE Conference on Computer Communications. Moore, D., Shannon, C., Voelker, G., and Savage, S. 2003. Internet quarantine: Requirements for containing self-propagating code. In Proceedings of the 22th IEEE Conference on Computer Communications."},{"key":"e_1_2_1_107_1","volume-title":"Rep. CS2004-0795","author":"Moore D.","unstructured":"Moore , D. , Shannon , C. , Voelker , G. M. , and Savage , S . 2004. Network telescopes: Tech . Rep. CS2004-0795 , University of California at San Diego. July. Moore, D., Shannon, C., Voelker, G. M., and Savage, S. 2004. Network telescopes: Tech. Rep. CS2004-0795, University of California at San Diego. July."},{"key":"e_1_2_1_108_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Moore D.","unstructured":"Moore , D. , Voelker , G. M. , and Savage , S . 2001. Inferring Internet denial of service activity . In Proceedings of the 10th USENIX Security Symposium. Moore, D., Voelker, G. M., and Savage, S. 2001. Inferring Internet denial of service activity. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1145\/292540.292561"},{"key":"e_1_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1145\/238721.238781"},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1145\/503272.503286"},{"key":"e_1_2_1_112_1","unstructured":"nergal. 2001. The advanced return-into-lib(c) exploits: Pax case study. Phrack 58.  nergal. 2001. The advanced return-into-lib(c) exploits: Pax case study. Phrack 58."},{"key":"e_1_2_1_113_1","volume-title":"Proceedings of the 3rd Workshop on Runtime Verification (RV).","author":"Nethercote N.","unstructured":"Nethercote , N. and Seward , J . 2003. Valgrind: A program supervision framework . In Proceedings of the 3rd Workshop on Runtime Verification (RV). Nethercote, N. and Seward, J. 2003. Valgrind: A program supervision framework. In Proceedings of the 3rd Workshop on Runtime Verification (RV)."},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"key":"e_1_2_1_115_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium.","author":"Newsome J.","unstructured":"Newsome , J. and Song , D . 2005. Dynamic taint analysis for automatic detection, analysis and signature generation of exploits on commodity software . In Proceedings of the 12th Annual Network and Distributed System Security Symposium. Newsome, J. and Song, D. 2005. Dynamic taint analysis for automatic detection, analysis and signature generation of exploits on commodity software. In Proceedings of the 12th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_116_1","first-page":"49","article-title":"Smashing the stack for fun and profit","volume":"7","author":"One A.","year":"1996","unstructured":"One , A. 1996 . Smashing the stack for fun and profit . Phrack 7 , 49 (Nov.). One, A. 1996. Smashing the stack for fun and profit. Phrack 7, 49 (Nov.).","journal-title":"Phrack"},{"key":"e_1_2_1_117_1","volume-title":"Proceedings of the IEEE IFIP Network Operations and Management Symposium (NOMS).","author":"Pasupulati A.","unstructured":"Pasupulati , A. , Coit , J. , Levitt , K. , Wu , S. F. , Li , S. H. , Kuo , J. C. , and Fan , K. P . 2004. Buttercup: On network-based detection of polymorphic buffer overflow vulnerabilities . In Proceedings of the IEEE IFIP Network Operations and Management Symposium (NOMS). Pasupulati, A., Coit, J., Levitt, K., Wu, S. F., Li, S. H., Kuo, J. C., and Fan, K. P. 2004. Buttercup: On network-based detection of polymorphic buffer overflow vulnerabilities. In Proceedings of the IEEE IFIP Network Operations and Management Symposium (NOMS)."},{"key":"e_1_2_1_118_1","unstructured":"PAX. 2001. PaX system. http:\/\/pax.grsecurity.net\/.  PAX. 2001. PaX system. http:\/\/pax.grsecurity.net\/."},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.26"},{"key":"e_1_2_1_121_1","unstructured":"PERL. 2006. Perl security manual page. http:\/\/www.perldoc.com.  PERL. 2006. Perl security manual page. http:\/\/www.perldoc.com."},{"key":"e_1_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217938"},{"key":"e_1_2_1_123_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Provos N.","year":"2004","unstructured":"Provos , N. 2004 . A virtual honeypot framework . In Proceedings of the 13th USENIX Security Symposium. Provos, N. 2004. A virtual honeypot framework. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_124_1","unstructured":"Ptacek T. H. and Newsham T. N. 1998. Insertion evasion and denial of service: Eluding network intrusion detection. Tech. Rep. Secure Networks Inc. January.  Ptacek T. H. and Newsham T. N. 1998. Insertion evasion and denial of service: Eluding network intrusion detection. Tech. Rep. Secure Networks Inc. January."},{"key":"e_1_2_1_125_1","unstructured":"QEMU. 2006. Qemu open source processor emulator. http:\/\/fabrice.bellard.free.fr\/qemu\/.  QEMU. 2006. Qemu open source processor emulator. http:\/\/fabrice.bellard.free.fr\/qemu\/."},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095833"},{"key":"e_1_2_1_127_1","doi-asserted-by":"publisher","DOI":"10.1145\/1162666.1162670"},{"key":"e_1_2_1_128_1","volume-title":"Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation.","author":"Rinard M.","year":"2004","unstructured":"Rinard , M. , Cadar , C. , Dumitran , D. , Roy , D. M. , Leu , T. , and Jr ., W. S. B. 2004 . Enhancing server availability and security through failure-oblivious computing . In Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation. Rinard, M., Cadar, C., Dumitran, D., Roy, D. M., Leu, T., and Jr., W. S. B. 2004. Enhancing server availability and security through failure-oblivious computing. In Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_129_1","first-page":"57","article-title":"Writing ia32 alphanumeric shellcodes","volume":"11","year":"2001","unstructured":"rix&commat;hert.org. 2001 . Writing ia32 alphanumeric shellcodes . Phrack 11 , 57 (Aug.). rix&commat;hert.org. 2001. Writing ia32 alphanumeric shellcodes. Phrack 11, 57 (Aug.).","journal-title":"Phrack"},{"key":"e_1_2_1_130_1","volume-title":"Conference on Systems Administration.","author":"Roesch M.","year":"1999","unstructured":"Roesch , M. 1999 . Snort: Lightweight intrusion detection for networks . In Conference on Systems Administration. Roesch, M. 1999. Snort: Lightweight intrusion detection for networks. In Conference on Systems Administration."},{"key":"e_1_2_1_131_1","volume-title":"Proceedings of the 11th Annual Network and Distributed System Security Symposium.","author":"Ruwase O.","unstructured":"Ruwase , O. and Lam , M . 2004. A practical dynamic buffer overflow detector . In Proceedings of the 11th Annual Network and Distributed System Security Symposium. Ruwase, O. and Lam, M. 2004. A practical dynamic buffer overflow detector. In Proceedings of the 11th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_132_1","volume-title":"Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection.","author":"Schechter S.","unstructured":"Schechter , S. , Jung , J. , and Berger , A . 2004. Fast detection of scanning worm infections . In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection. Schechter, S., Jung, J., and Berger, A. 2004. Fast detection of scanning worm infections. In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection."},{"key":"e_1_2_1_133_1","unstructured":"SecurityFocus. 2002. Microsoft jvm class loader buffer overrun vulnerability. http:\/\/www.securityfocus.com\/bid\/6134.  SecurityFocus. 2002. Microsoft jvm class loader buffer overrun vulnerability. http:\/\/www.securityfocus.com\/bid\/6134."},{"key":"e_1_2_1_134_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Sekar R.","unstructured":"Sekar , R. , Bendre , M. , Dhurjati , D. , and Bollineni , P . 2001. A fast automaton-based method for detecting anomalous program behaviors . In Proceedings of the IEEE Symposium on Security and Privacy. Sekar, R., Bendre, M., Dhurjati, D., and Bollineni, P. 2001. A fast automaton-based method for detecting anomalous program behaviors. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_135_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_2_1_136_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Shankar U.","unstructured":"Shankar , U. , Talwar , K. , Foster , J. S. , and Wagner , D . 2001. Detecting format string vulnerabilities with type qualifiers . In Proceedings of the 10th USENIX Security Symposium. Shankar, U., Talwar, K., Foster, J. S., and Wagner, D. 2001. Detecting format string vulnerabilities with type qualifiers. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_137_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.59"},{"key":"e_1_2_1_138_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Shinoda Y.","unstructured":"Shinoda , Y. , Ikai , K. , and Itoh , M . 2005. Vulnerabilities of passive Internet threat monitors . In Proceedings of the 14th USENIX Security Symposium. Shinoda, Y., Ikai, K., and Itoh, M. 2005. Vulnerabilities of passive Internet threat monitors. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_139_1","doi-asserted-by":"publisher","DOI":"10.1145\/358453.358455"},{"key":"e_1_2_1_140_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Sidiroglou S.","unstructured":"Sidiroglou , S. , Locasto , M. E. , Boyd , S. W. , and Keromytis , A. D . 2005. Building a reactive immune system for software services . In Proceedings of the USENIX Annual Technical Conference. Sidiroglou, S., Locasto, M. E., Boyd, S. W., and Keromytis, A. D. 2005. Building a reactive immune system for software services. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_141_1","volume-title":"Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation.","author":"Singh S.","unstructured":"Singh , S. , Estan , C. , Varghese , G. , and Savage , S . 2004. Automated worm fingerprinting . In Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation. Singh, S., Estan, C., Varghese, G., and Savage, S. 2004. Automated worm fingerprinting. In Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_142_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium.","author":"Smirnov A.","unstructured":"Smirnov , A. and Chiueh , T . 2005. DIRA: Automatic detection, identification, and repair of control-hijacking attacks . In Proceedings of the 12th Annual Network and Distributed System Security Symposium. Smirnov, A. and Chiueh, T. 2005. DIRA: Automatic detection, identification, and repair of control-hijacking attacks. In Proceedings of the 12th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_143_1","volume-title":"Proceedings of the 9th USENIX Security Symposium.","author":"Somayaji A.","unstructured":"Somayaji , A. and Forrest , S . 2000. Automated response using system-call delays . In Proceedings of the 9th USENIX Security Symposium. Somayaji, A. and Forrest, S. 2000. Automated response using system-call delays. In Proceedings of the 9th USENIX Security Symposium."},{"key":"e_1_2_1_144_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Sovarel N.","unstructured":"Sovarel , N. , Evans , D. , and Paul , N . 2005. Where's the FEEB&quest; The effectiveness of instruction set randomization . In Proceedings of the 14th USENIX Security Symposium. Sovarel, N., Evans, D., and Paul, N. 2005. Where's the FEEB&quest; The effectiveness of instruction set randomization. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_145_1","doi-asserted-by":"publisher","DOI":"10.1145\/63526.63527"},{"key":"e_1_2_1_146_1","unstructured":"SPEC. Specweb99 benchmark. http:\/\/www.spec.org\/osg\/web99.  SPEC. Specweb99 benchmark. http:\/\/www.spec.org\/osg\/web99."},{"key":"e_1_2_1_147_1","article-title":"Containment of scanning worms in enterprise networks","author":"Staniford S.","year":"2004","unstructured":"Staniford , S. 2004 . Containment of scanning worms in enterprise networks . J. Comput. Secur. Staniford, S. 2004. Containment of scanning worms in enterprise networks. J. Comput. Secur.","journal-title":"J. Comput. Secur."},{"key":"e_1_2_1_148_1","doi-asserted-by":"publisher","DOI":"10.5555\/597917.597922"},{"key":"e_1_2_1_149_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029624"},{"key":"e_1_2_1_150_1","volume-title":"Proceedings of the 11th USENIX Security Symposium.","author":"Staniford S.","unstructured":"Staniford , S. , Paxson , V. , and Weaver , N . 2002. How to 0wn the Internet in your spare time . In Proceedings of the 11th USENIX Security Symposium. Staniford, S., Paxson, V., and Weaver, N. 2002. How to 0wn the Internet in your spare time. In Proceedings of the 11th USENIX Security Symposium."},{"key":"e_1_2_1_151_1","volume-title":"Proceedings of the 19th National Information Systems Security Conference.","author":"Staniford-Chen S.","unstructured":"Staniford-Chen , S. , Crawford , R. , Dilger , M. , Frank , J. , Hoagland , J. , Levitt , K. , and Zerkle , D . 1996. GrIDS: A graph-based intrusion detection system for large networks . In Proceedings of the 19th National Information Systems Security Conference. Staniford-Chen, S., Crawford, R., Dilger, M., Frank, J., Hoagland, J., Levitt, K., and Zerkle, D. 1996. GrIDS: A graph-based intrusion detection system for large networks. In Proceedings of the 19th National Information Systems Security Conference."},{"key":"e_1_2_1_152_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_2_1_153_1","volume-title":"the International Virus Bulletin Conference.","author":"Szor P.","unstructured":"Szor , P. and Ferrie , P . 2001. Hunting for metamorphic . In the International Virus Bulletin Conference. Szor, P. and Ferrie, P. 2001. Hunting for metamorphic. In the International Virus Bulletin Conference."},{"key":"e_1_2_1_154_1","volume-title":"Proceedings of the 24th IEEE Conference on Computer Communications.","author":"Tang Y.","unstructured":"Tang , Y. and Chen , S . 2005. Defending against Internet worms: A signature-based approach . In Proceedings of the 24th IEEE Conference on Computer Communications. Tang, Y. and Chen, S. 2005. Defending against Internet worms: A signature-based approach. In Proceedings of the 24th IEEE Conference on Computer Communications."},{"key":"e_1_2_1_155_1","volume-title":"Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection.","author":"Toth T.","unstructured":"Toth , T. and Kruegel , C . 2002a. Accurate buffer overflow detection via abstract payload execution . In Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection. Toth, T. and Kruegel, C. 2002a. Accurate buffer overflow detection via abstract payload execution. In Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection."},{"key":"e_1_2_1_156_1","volume-title":"the IEEE Information Assurance Workshop.","author":"Toth T.","unstructured":"Toth , T. and Kruegel , C . 2002b. Connection-History based anomaly detection . In the IEEE Information Assurance Workshop. Toth, T. and Kruegel, C. 2002b. Connection-History based anomaly detection. In the IEEE Information Assurance Workshop."},{"key":"e_1_2_1_157_1","unstructured":"TPC. 1999. TPC-C online transaction processing benchmark. http:\/\/www.tpc.org\/tpcc\/default.asp.  TPC. 1999. TPC-C online transaction processing benchmark. http:\/\/www.tpc.org\/tpcc\/default.asp."},{"key":"e_1_2_1_158_1","unstructured":"Vendicator. 2001. Stack shield technical info. http:\/\/www.angelfire.com\/sk\/stackshield.  Vendicator. 2001. Stack shield technical info. http:\/\/www.angelfire.com\/sk\/stackshield."},{"key":"e_1_2_1_159_1","volume-title":"Proceedings of the 3rd Workshop on Rapid Malcode.","author":"Vojnovi\u0107 M.","unstructured":"Vojnovi\u0107 , M. and Ganesh , A . 2005. On the race of worms, alerts and patches . In Proceedings of the 3rd Workshop on Rapid Malcode. Vojnovi\u0107, M. and Ganesh, A. 2005. On the race of worms, alerts and patches. In Proceedings of the 3rd Workshop on Rapid Malcode."},{"key":"e_1_2_1_160_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095825"},{"key":"e_1_2_1_161_1","volume-title":"Proceedings of the 7th Annual Network and Distributed System Security Symposium.","author":"Wagner D.","unstructured":"Wagner , D. , Foster , J. S. , Brewer , E. A. , and Aiken , A . 2000. A first step towards automated detection of buffer overrun vulnerabilities . In Proceedings of the 7th Annual Network and Distributed System Security Symposium. Wagner, D., Foster, J. S., Brewer, E. A., and Aiken, A. 2000. A first step towards automated detection of buffer overrun vulnerabilities. In Proceedings of the 7th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_162_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_2_1_163_1","doi-asserted-by":"publisher","DOI":"10.5555\/784591.784730"},{"key":"e_1_2_1_164_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015489"},{"key":"e_1_2_1_165_1","volume-title":"Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection.","author":"Wang K.","unstructured":"Wang , K. , Cretu , G. , and Stolfo , S. J . 2005. Anomalous payload-based worm detection and signature generation . In Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection. Wang, K., Cretu, G., and Stolfo, S. J. 2005. Anomalous payload-based worm detection and signature generation. In Proceedings of the 8th International Symposium on Recent Advances in Intrusion Detection."},{"key":"e_1_2_1_166_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Wang X.","unstructured":"Wang , X. , Pan , C.-C. , Liu , P. , and Zhu , S . 2006. Sigfree: A signature-free buffer overflow attack blocker . In Proceedings of the 15th USENIX Security Symposium. Wang, X., Pan, C.-C., Liu, P., and Zhu, S. 2006. Sigfree: A signature-free buffer overflow attack blocker. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_1_167_1","doi-asserted-by":"publisher","DOI":"10.1109\/CONECT.2004.1375206"},{"key":"e_1_2_1_168_1","volume-title":"Proceedings of the 13th USENIX Security Symposium.","author":"Weaver N.","unstructured":"Weaver , N. , Staniford , S. , and Paxson , V . 2004. Very fast containment of scanning worms . In Proceedings of the 13th USENIX Security Symposium. Weaver, N., Staniford, S., and Paxson, V. 2004. Very fast containment of scanning worms. In Proceedings of the 13th USENIX Security Symposium."},{"key":"e_1_2_1_169_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1984.5010248"},{"key":"e_1_2_1_170_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium.","author":"Whyte D.","unstructured":"Whyte , D. , Kranakis , E. , and Oorschot , P. C. V. 2005. Dns-Based detection of scanning worms in an enterprise network . In Proceedings of the 12th Annual Network and Distributed System Security Symposium. Whyte, D., Kranakis, E., and Oorschot, P. C. V. 2005. Dns-Based detection of scanning worms in an enterprise network. In Proceedings of the 12th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_171_1","volume-title":"Proceedings of the 10th Annual Network and Distributed System Security Symposium.","author":"Wilander J.","unstructured":"Wilander , J. and Kamkar , M . 2003. A comparison of publicly available tools for dynamic buffer overflow prevention . In Proceedings of the 10th Annual Network and Distributed System Security Symposium. Wilander, J. and Kamkar, M. 2003. A comparison of publicly available tools for dynamic buffer overflow prevention. In Proceedings of the 10th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_172_1","volume-title":"Proceedings of the Annual Computer Security Applications Conference (ACSAC).","author":"Williamnson M. M.","year":"2002","unstructured":"Williamnson , M. M. 2002 . Throttling viruses: Restricting propagation to defeat mobile malicious code . In Proceedings of the Annual Computer Security Applications Conference (ACSAC). Williamnson, M. M. 2002. Throttling viruses: Restricting propagation to defeat mobile malicious code. In Proceedings of the Annual Computer Security Applications Conference (ACSAC)."},{"key":"e_1_2_1_173_1","volume-title":"The Formal Semantics of Programming Languages","author":"Winskel G.","unstructured":"Winskel , G. 1993. The Formal Semantics of Programming Languages . MIT Press . Winskel, G. 1993. The Formal Semantics of Programming Languages. MIT Press."},{"key":"e_1_2_1_174_1","doi-asserted-by":"publisher","DOI":"10.1145\/1040305.1040334"},{"key":"e_1_2_1_175_1","volume-title":"Proceedings of the IEEE Symposium on Reliability in Distributed Software (SRDS).","author":"Xu J.","unstructured":"Xu , J. , Kalbarczyk , Z. , and Iyer , R. K . 2003. Transparent runtime randomization for security . In Proceedings of the IEEE Symposium on Reliability in Distributed Software (SRDS). Xu, J., Kalbarczyk, Z., and Iyer, R. K. 2003. Transparent runtime randomization for security. In Proceedings of the IEEE Symposium on Reliability in Distributed Software (SRDS)."},{"key":"e_1_2_1_176_1","volume-title":"Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation.","author":"Yang J.","unstructured":"Yang , J. , Twohey , P. , Engler , D. , and Musuvathi , M . 2004. Using model checking to find serious file system errors . In Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation. Yang, J., Twohey, P., Engler, D., and Musuvathi, M. 2004. Using model checking to find serious file system errors. In Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_177_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Yegneswaran V.","unstructured":"Yegneswaran , V. , Giffin , J. T. , Barford , P. , and Jha , S . 2005. An architecture for generating semantics aware signatures . In Proceedings of the 14th USENIX Security Symposium. Yegneswaran, V., Giffin, J. T., Barford, P., and Jha, S. 2005. An architecture for generating semantics aware signatures. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_178_1","volume-title":"Proceedings of the Annual Joint Conference of the IEEE Computer Communications Societies (IEEE INFOCOM).","author":"Zegura E.","unstructured":"Zegura , E. , Calvert , K. , and Bhattacharjee , S . 1996. How to model an internetwork . In Proceedings of the Annual Joint Conference of the IEEE Computer Communications Societies (IEEE INFOCOM). Zegura, E., Calvert, K., and Bhattacharjee, S. 1996. How to model an internetwork. In Proceedings of the Annual Joint Conference of the IEEE Computer Communications Societies (IEEE INFOCOM)."},{"key":"e_1_2_1_179_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Zheng L.","unstructured":"Zheng , L. , Chong , S. , Myers , A. C. , and Zdancewic , S . 2003. Using replication and partitioning to build secure distributed systems . In Proceedings of the IEEE Symposium on Security and Privacy. Zheng, L., Chong, S., Myers, A. C., and Zdancewic, S. 2003. Using replication and partitioning to build secure distributed systems. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_180_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948136"}],"container-title":["ACM Transactions on Computer Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1455258.1455259","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1455258.1455259","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:30:00Z","timestamp":1750253400000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1455258.1455259"}},"subtitle":["End-to-end containment of Internet worm epidemics"],"short-title":[],"issued":{"date-parts":[[2008,12]]},"references-count":175,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2008,12]]}},"alternative-id":["10.1145\/1455258.1455259"],"URL":"https:\/\/doi.org\/10.1145\/1455258.1455259","relation":{},"ISSN":["0734-2071","1557-7333"],"issn-type":[{"value":"0734-2071","type":"print"},{"value":"1557-7333","type":"electronic"}],"subject":[],"published":{"date-parts":[[2008,12]]},"assertion":[{"value":"2005-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-12-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}