{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T09:23:23Z","timestamp":1766136203359,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":38,"publisher":"ACM","license":[{"start":{"date-parts":[[2010,12,6]],"date-time":"2010-12-06T00:00:00Z","timestamp":1291593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["FP7-PEOPLE-2009-IOF"],"award-info":[{"award-number":["FP7-PEOPLE-2009-IOF"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","award":["2.54E+11","JLS\/2009\/CIPS\/AG\/C2-050"],"award-info":[{"award-number":["2.54E+11","JLS\/2009\/CIPS\/AG\/C2-050"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2010,12,6]]},"DOI":"10.1145\/1920261.1920305","type":"proceedings-article","created":{"date-parts":[[2010,12,20]],"date-time":"2010-12-20T16:13:47Z","timestamp":1292861627000},"page":"287-296","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":46,"title":["Comprehensive shellcode detection using runtime heuristics"],"prefix":"10.1145","author":[{"given":"Michalis","family":"Polychronakis","sequence":"first","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kostas G.","family":"Anagnostakis","sequence":"additional","affiliation":[{"name":"Niometrics, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Evangelos P.","family":"Markatos","sequence":"additional","affiliation":[{"name":"FORTH-ICS, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Goodfellas security research team. http:\/\/goodfellas.shellcode.com.ar\/.  Goodfellas security research team. http:\/\/goodfellas.shellcode.com.ar\/."},{"key":"e_1_3_2_1_2_1","unstructured":"The metasploit project. http:\/\/www.metasploit.com\/.  The metasploit project. http:\/\/www.metasploit.com\/."},{"key":"e_1_3_2_1_3_1","unstructured":"milw0rm. http:\/\/milw0rm.com\/shellcode\/win32\/.  milw0rm. http:\/\/milw0rm.com\/shellcode\/win32\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Packet storm. http:\/\/www.packetstormsecurity.org\/.  Packet storm. http:\/\/www.packetstormsecurity.org\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Win32 assembly components Dec. 2002. http:\/\/lsd-pl.net.  Win32 assembly components Dec. 2002. http:\/\/lsd-pl.net."},{"key":"e_1_3_2_1_6_1","unstructured":"Common shellcode naming initiative 2009. http:\/\/nepenthes.carnivore.it\/csni.  Common shellcode naming initiative 2009. http:\/\/nepenthes.carnivore.it\/csni."},{"key":"e_1_3_2_1_7_1","unstructured":"Retrieving kernel32's base address June 2009. http:\/\/www.harmonysecurity.com\/blog\/2009\/06\/retrieving-kernel32s-base-address.html.  Retrieving kernel32's base address June 2009. http:\/\/www.harmonysecurity.com\/blog\/2009\/06\/retrieving-kernel32s-base-address.html."},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of the Asia Pacific Information Technology Security Conference (AusCERT)","author":"Andersson S.","year":"2004","unstructured":"S. Andersson , A. Clark , and G. Mohay . Network-based buffer overflow detection by exploit code analysis . In Proceedings of the Asia Pacific Information Technology Security Conference (AusCERT) , 2004 . S. Andersson, A. Clark, and G. Mohay. Network-based buffer overflow detection by exploit code analysis. In Proceedings of the Asia Pacific Information Technology Security Conference (AusCERT), 2004."},{"key":"e_1_3_2_1_9_1","volume-title":"libemu","author":"Baecher P.","year":"2009","unstructured":"P. Baecher and M. Koetter . libemu , 2009 . http:\/\/libemu.carnivore.it\/. P. Baecher and M. Koetter. libemu, 2009. http:\/\/libemu.carnivore.it\/."},{"key":"e_1_3_2_1_10_1","volume-title":"Evading network-level emulation","author":"Bania P.","year":"2009","unstructured":"P. Bania . Evading network-level emulation , 2009 . http:\/\/piotrbania.com\/all\/articles\/pbania-evading-nemu2009.pdf. P. Bania. Evading network-level emulation, 2009. http:\/\/piotrbania.com\/all\/articles\/pbania-evading-nemu2009.pdf."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.11"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_15"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_10"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_6"},{"key":"e_1_3_2_1_15_1","volume-title":"Wepawet","author":"Ford S.","year":"2009","unstructured":"S. Ford , M. Cova , C. Kruegel , and G. Vigna . Wepawet , 2009 . http:\/\/wepawet.cs.ucsb.edu\/. S. Ford, M. Cova, C. Kruegel, and G. Vigna. Wepawet, 2009. http:\/\/wepawet.cs.ucsb.edu\/."},{"volume-title":"Uninformed","year":"2007","key":"e_1_3_2_1_16_1","unstructured":"I)ruid. Context-keyed payload encoding . Uninformed , 9, Oct. 2007 . I)ruid. Context-keyed payload encoding. Uninformed, 9, Oct. 2007."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_11"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177087"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653725"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_2"},{"key":"e_1_3_2_1_21_1","volume-title":"A crash course on the depths of Win32#8482;structured exception handling","author":"Pietrek M.","year":"1997","unstructured":"M. Pietrek . A crash course on the depths of Win32#8482;structured exception handling , 1997 . http:\/\/www.microsoft.com\/msj\/0197\/exception\/exception.aspx. M. Pietrek. A crash course on the depths of Win32#8482;structured exception handling, 1997. http:\/\/www.microsoft.com\/msj\/0197\/exception\/exception.aspx."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the 2nd USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET)","author":"Polychronakis M.","year":"2009","unstructured":"M. Polychronakis , K. G. Anagnostakis , and E. P. Markatos . An empirical study of real-world polymorphic code injection attacks . In Proceedings of the 2nd USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET) , April 2009 . M. Polychronakis, K. G. Anagnostakis, and E. P. Markatos. An empirical study of real-world polymorphic code injection attacks. In Proceedings of the 2nd USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET), April 2009."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/11790754_4"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/1776434.1776442"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_5"},{"volume-title":"July","year":"2004","key":"e_1_3_2_1_26_1","unstructured":"sk. History and advances in windows shellcode. Phrack, 11(62) , July 2004 . sk. History and advances in windows shellcode. Phrack, 11(62), July 2004."},{"volume-title":"Understanding windows shellcode","year":"2003","key":"e_1_3_2_1_27_1","unstructured":"Skape. Understanding windows shellcode , 2003 . http:\/\/www.hick.org\/code\/skape\/papers\/win32-shellcode.pdf. Skape. Understanding windows shellcode, 2003. http:\/\/www.hick.org\/code\/skape\/papers\/win32-shellcode.pdf."},{"volume-title":"Safely searching process virtual address space","year":"2004","key":"e_1_3_2_1_28_1","unstructured":"Skape. Safely searching process virtual address space , 2004 . http:\/\/www.hick.org\/code\/skape\/papers\/egghunt-shellcode.pdf. Skape. Safely searching process virtual address space, 2004. http:\/\/www.hick.org\/code\/skape\/papers\/egghunt-shellcode.pdf."},{"key":"e_1_3_2_1_29_1","unstructured":"SkyLined. Finding the base address of kernel32 in Windows 7. http:\/\/skypher.com\/index.php\/2009\/07\/22\/shellcode-finding-kernel32-in-windows-7\/.  SkyLined. Finding the base address of kernel32 in Windows 7. http:\/\/skypher.com\/index.php\/2009\/07\/22\/shellcode-finding-kernel32-in-windows-7\/."},{"key":"e_1_3_2_1_30_1","unstructured":"SkyLined. SEH GetPC (XP SP3) July 2009. http:\/\/skypher.com\/wiki\/index.php\/Hacking\/Shellcode\/Alphanumeric\/ALPHA3\/x86\/ASCII\/Mixedcase\/SEH_GetPC_(XP_sp3).  SkyLined. SEH GetPC (XP SP3) July 2009. http:\/\/skypher.com\/wiki\/index.php\/Hacking\/Shellcode\/Alphanumeric\/ALPHA3\/x86\/ASCII\/Mixedcase\/SEH_GetPC_(XP_sp3)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315312"},{"key":"e_1_3_2_1_32_1","volume-title":"The Art of Computer Virus Research and Defense","author":"Sz\u00f6r P.","year":"2005","unstructured":"P. Sz\u00f6r . The Art of Computer Virus Research and Defense . Addison-Wesley Professional , February 2005 . P. Sz\u00f6r. The Art of Computer Virus Research and Defense. Addison-Wesley Professional, February 2005."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/1754701.1754723"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.37"},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Wang X.","year":"2006","unstructured":"X. Wang , C.-C. Pan , P. Liu , and S. Zhu . Sigfree: A signature-free buffer overflow attack blocker . In Proceedings of the USENIX Security Symposium , Aug. 2006 . X. Wang, C.-C. Pan, P. Liu, and S. Zhu. Sigfree: A signature-free buffer overflow attack blocker. In Proceedings of the USENIX Security Symposium, Aug. 2006."},{"key":"e_1_3_2_1_36_1","unstructured":"B.-J. Wever. SEH Omelet Shellcode 2009. http:\/\/code.google.com\/p\/w32-seh-omelet-shellcode\/.  B.-J. Wever. SEH Omelet Shellcode 2009. http:\/\/code.google.com\/p\/w32-seh-omelet-shellcode\/."},{"key":"e_1_3_2_1_37_1","unstructured":"G. Wicherski. Win32 egg search shellcode 33 bytes. http:\/\/blog.oxff.net\/2009\/02\/win32-egg-search-shellcode-33-bytes.html.  G. Wicherski. Win32 egg search shellcode 33 bytes. http:\/\/blog.oxff.net\/2009\/02\/win32-egg-search-shellcode-33-bytes.html."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1229291"}],"event":{"name":"ACSAC '10: 2010 Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Austin Texas USA","acronym":"ACSAC '10"},"container-title":["Proceedings of the 26th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920305","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1920261.1920305","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:43Z","timestamp":1750244383000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920305"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,12,6]]},"references-count":38,"alternative-id":["10.1145\/1920261.1920305","10.1145\/1920261"],"URL":"https:\/\/doi.org\/10.1145\/1920261.1920305","relation":{},"subject":[],"published":{"date-parts":[[2010,12,6]]},"assertion":[{"value":"2010-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}