{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T14:40:26Z","timestamp":1775054426516,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":29,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,3,22]],"date-time":"2011-03-22T00:00:00Z","timestamp":1300752000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100002855","name":"Ministry of Science and Technology of the People's Republic of China","doi-asserted-by":"publisher","award":["2009CB320705"],"award-info":[{"award-number":["2009CB320705"]}],"id":[{"id":"10.13039\/501100002855","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002855","name":"Ministry of Science and Technology of the People's Republic of China","doi-asserted-by":"publisher","award":["2007AA01Z448"],"award-info":[{"award-number":["2007AA01Z448"]}],"id":[{"id":"10.13039\/501100002855","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["6.08E+31"],"award-info":[{"award-number":["6.08E+31"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,3,22]]},"DOI":"10.1145\/1966913.1966918","type":"proceedings-article","created":{"date-parts":[[2011,4,7]],"date-time":"2011-04-07T09:36:11Z","timestamp":1302168971000},"page":"20-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["Automatic construction of jump-oriented programming shellcode (on the x86)"],"prefix":"10.1145","author":[{"given":"Ping","family":"Chen","sequence":"first","affiliation":[{"name":"Nanjing University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiao","family":"Xing","sequence":"additional","affiliation":[{"name":"Nanjing University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bing","family":"Mao","sequence":"additional","affiliation":[{"name":"Nanjing University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Li","family":"Xie","sequence":"additional","affiliation":[{"name":"Nanjing University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaobin","family":"Shen","sequence":"additional","affiliation":[{"name":"Yangzhou University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinchun","family":"Yin","sequence":"additional","affiliation":[{"name":"Yangzhou University, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,3,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.41"},{"key":"e_1_3_2_1_2_1","first-page":"229","volume-title":"CA","author":"Roesch M.","year":"1999","unstructured":"M. Roesch , \"Snort - lightweight intrusion detection for networks,\" in Proceedings of the 13th USENIX Conference on System Administration . Berkeley , CA , USA : USENIX Association , 1999 , pp. 229 -- 238 . M. Roesch, \"Snort - lightweight intrusion detection for networks,\" in Proceedings of the 13th USENIX Conference on System Administration. Berkeley, CA, USA: USENIX Association, 1999, pp. 229--238."},{"key":"e_1_3_2_1_3_1","first-page":"271","volume-title":"Autograph: toward automated, distributed worm signature detection,\" in Proceedings of the 13th Conference on USENIX Security Symposium","author":"Kim H.-A.","year":"2004","unstructured":"H.-A. Kim and B. Karp , \" Autograph: toward automated, distributed worm signature detection,\" in Proceedings of the 13th Conference on USENIX Security Symposium . Berkeley, CA, USA : USENIX Association , 2004 , pp. 271 -- 286 . H.-A. Kim and B. Karp, \"Autograph: toward automated, distributed worm signature detection,\" in Proceedings of the 13th Conference on USENIX Security Symposium. Berkeley, CA, USA: USENIX Association, 2004, pp. 271--286."},{"key":"e_1_3_2_1_4_1","unstructured":"\"The pax project \" 2004. {Online}. Available: http:\/\/pax.grsecurity.net\/  \"The pax project \" 2004. {Online}. Available: http:\/\/pax.grsecurity.net\/"},{"key":"e_1_3_2_1_5_1","unstructured":"J. McDonald \"Defeating solaris\/sparc non-executable stack protection \" Bugtraq 1999.  J. McDonald \"Defeating solaris\/sparc non-executable stack protection \" Bugtraq 1999."},{"key":"e_1_3_2_1_6_1","unstructured":"Nergal \"The advanced return-into-lib(c) exploits (pax case study) \" Phrack Magazine 2001. {Online}. Available: http:\/\/www.phrack.com\/issues.html?issue=58&id=4  Nergal \"The advanced return-into-lib(c) exploits (pax case study) \" Phrack Magazine 2001. {Online}. Available: http:\/\/www.phrack.com\/issues.html?issue=58&id=4"},{"key":"e_1_3_2_1_7_1","unstructured":"S. Krahmer \"X86-64 buffer overflow exploits and the borrowed code chunks exploitation technique \" Phrack Magazine 2005. {Online}. Available: http:\/\/www.suse.de\/krahmer\/no-nx.pdf  S. Krahmer \"X86-64 buffer overflow exploits and the borrowed code chunks exploitation technique \" Phrack Magazine 2005. {Online}. Available: http:\/\/www.suse.de\/krahmer\/no-nx.pdf"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455775"},{"key":"e_1_3_2_1_10_1","volume-title":"Can dres provide long-lasting security?the case of return-oriented programming and the avc advantage,\" in Proceedings of EVT\/WOTE","author":"Checkoway S.","year":"2009","unstructured":"S. Checkoway , A. J. Feldman , B. Kantor , J. A. Halderman , E. W. Felten , and H. Shacham , \" Can dres provide long-lasting security?the case of return-oriented programming and the avc advantage,\" in Proceedings of EVT\/WOTE 2009 .USENIX\/ACCURATE\/IAVoSS, 2009. S. Checkoway, A. J. Feldman, B. Kantor, J. A. Halderman, E. W. Felten, and H. Shacham, \"Can dres provide long-lasting security?the case of return-oriented programming and the avc advantage,\" in Proceedings of EVT\/WOTE 2009.USENIX\/ACCURATE\/IAVoSS, 2009."},{"key":"e_1_3_2_1_11_1","first-page":"383","volume-title":"USA","author":"Hund R.","year":"2009","unstructured":"R. Hund , T. Holz , and F. C. Freiling , \" Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms,\" in Proceedings of 18th USENIX Security Symposium, San Jose, CA , USA , 2009 , pp. 383 -- 398 . R. Hund, T. Holz, and F. C. Freiling, \"Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms,\" in Proceedings of 18th USENIX Security Symposium, San Jose, CA, USA, 2009, pp. 383--398."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455776"},{"key":"e_1_3_2_1_13_1","unstructured":"\"Felix \"fx\" lidner.developments in cisco ios forensics \" CONFidence 2.0. http:\/\/www.recurity-labs.com\/content\/pub\/FX_Router_Exploitation.pdf.  \"Felix \"fx\" lidner.developments in cisco ios forensics \" CONFidence 2.0. http:\/\/www.recurity-labs.com\/content\/pub\/FX_Router_Exploitation.pdf."},{"key":"e_1_3_2_1_14_1","volume-title":"Ruhr-Universitat Bochum","author":"Kornau T.","year":"2010","unstructured":"T. Kornau , \"Return oriented programming for the arm architecture,\" Master's thesis , Ruhr-Universitat Bochum , 2010 . T. Kornau, \"Return oriented programming for the arm architecture,\" Master's thesis, Ruhr-Universitat Bochum, 2010."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655077.1655083"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655108.1655117"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10772-6_13"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755913.1755934"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866370"},{"key":"e_1_3_2_1_23_1","first-page":"230","author":"Turing A. M.","year":"1936","unstructured":"A. M. Turing , \"On computable numbers, with an application to the entscheidungsproblem,\" Proc. London Math. Soc. , pp. 230 -- 265 , 1936 . A. M. Turing, \"On computable numbers, with an application to the entscheidungsproblem,\" Proc. London Math. Soc., pp. 230--265, 1936.","journal-title":"Math. Soc."},{"key":"e_1_3_2_1_24_1","unstructured":"milw0rm. {Online}. Available: http:\/\/www.milw0rm.com\/shellcode\/linux\/x86  milw0rm. {Online}. Available: http:\/\/www.milw0rm.com\/shellcode\/linux\/x86"},{"key":"e_1_3_2_1_25_1","unstructured":"\"Implementing linux system calls \" Linux Journal 1999. {Online}. Available: http:\/\/www.linuxjournal.com\/article\/3326  \"Implementing linux system calls \" Linux Journal 1999. {Online}. Available: http:\/\/www.linuxjournal.com\/article\/3326"},{"key":"e_1_3_2_1_26_1","unstructured":"D. Mazzocchio \"Writing shellcode for linux and *bsd \" 2005. {Online}. Available: http:\/\/www.shell-storm.org\/papers\/files\/442.pdf  D. Mazzocchio \"Writing shellcode for linux and *bsd \" 2005. {Online}. Available: http:\/\/www.shell-storm.org\/papers\/files\/442.pdf"},{"key":"e_1_3_2_1_27_1","unstructured":"\"\"linux\/x86 setreuid(geteuid() geteuid()) execve(\"\/bin\/sh\" 0 0)\" \" milw0rm 2009 http:\/\/www.milw0rm.com\/shellcode\/8972.  \"\"linux\/x86 setreuid(geteuid() geteuid()) execve(\"\/bin\/sh\" 0 0)\" \" milw0rm 2009 http:\/\/www.milw0rm.com\/shellcode\/8972."},{"key":"e_1_3_2_1_28_1","unstructured":"\"\"linux\/x86\/ho detector\" \" milw0rm 2008. {Online}. Available: http:\/\/www.milw0rm.com\/shellcode\/7154  \"\"linux\/x86\/ho detector\" \" milw0rm 2008. {Online}. Available: http:\/\/www.milw0rm.com\/shellcode\/7154"},{"key":"e_1_3_2_1_30_1","volume-title":"Binary code extraction and interface identification for security applications,\" Proceedings of the 17th Annual Network and Distributed System Security Symposium","author":"Caballero J.","year":"2010","unstructured":"J. Caballero , N. M. Johnson , S. McCamant , and D. Song , \" Binary code extraction and interface identification for security applications,\" Proceedings of the 17th Annual Network and Distributed System Security Symposium , 2010 . J. Caballero, N. M. Johnson, S. McCamant, and D. Song, \"Binary code extraction and interface identification for security applications,\" Proceedings of the 17th Annual Network and Distributed System Security Symposium, 2010."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.10"},{"key":"e_1_3_2_1_32_1","volume-title":"Reuse-oriented camouflaging trojan: Vulnerability detection and attack construction,\" in Proceedings of the 40th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN-DCCS","author":"Lin Z.","year":"2010","unstructured":"Z. Lin , X. Zhang , and D. Xu , \" Reuse-oriented camouflaging trojan: Vulnerability detection and attack construction,\" in Proceedings of the 40th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN-DCCS 2010 ), Chicago, IL , USA , June 2010. Z. Lin, X. Zhang, and D. Xu, \"Reuse-oriented camouflaging trojan: Vulnerability detection and attack construction,\" in Proceedings of the 40th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN-DCCS 2010), Chicago, IL, USA, June 2010."},{"key":"e_1_3_2_1_33_1","volume-title":"pointer inference and jit spraying,\" BHDC","author":"Blazakis D.","year":"2010","unstructured":"D. Blazakis , \"interpreter exploitation : pointer inference and jit spraying,\" BHDC , 2010 , http:\/\/www.semantiscope.com\/research\/BHDC2010\/BHDC-2010-Paper.pdf. D. Blazakis, \"interpreter exploitation: pointer inference and jit spraying,\" BHDC, 2010, http:\/\/www.semantiscope.com\/research\/BHDC2010\/BHDC-2010-Paper.pdf."}],"event":{"name":"ASIA CCS '11: 6th ACM Symposium on Information, Compuer and Communications Security","location":"Hong Kong China","acronym":"ASIA CCS '11","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1966913.1966918","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1966913.1966918","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:52:25Z","timestamp":1750243945000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1966913.1966918"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,3,22]]},"references-count":29,"alternative-id":["10.1145\/1966913.1966918","10.1145\/1966913"],"URL":"https:\/\/doi.org\/10.1145\/1966913.1966918","relation":{},"subject":[],"published":{"date-parts":[[2011,3,22]]},"assertion":[{"value":"2011-03-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}