{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T12:03:33Z","timestamp":1784289813390,"version":"3.55.0"},"reference-count":136,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2012,6,1]],"date-time":"2012-06-01T00:00:00Z","timestamp":1338508800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2012,6]]},"abstract":"<jats:p>Programs are implemented in a variety of languages and contain serious vulnerabilities which might be exploited to cause security breaches. These vulnerabilities have been exploited in real life and caused damages to related stakeholders such as program users. As many security vulnerabilities belong to program code, many techniques have been applied to mitigate these vulnerabilities before program deployment. Unfortunately, there is no comprehensive comparative analysis of different vulnerability mitigation works. As a result, there exists an obscure mapping between the techniques, the addressed vulnerabilities, and the limitations of different approaches. This article attempts to address these issues. The work extensively compares and contrasts the existing program security vulnerability mitigation techniques, namely testing, static analysis, and hybrid analysis. We also discuss three other approaches employed to mitigate the most common program security vulnerabilities: secure programming, program transformation, and patching. The survey provides a comprehensive understanding of the current program security vulnerability mitigation approaches and challenges as well as their key characteristics and limitations. Moreover, our discussion highlights the open issues and future research directions in the area of program security vulnerability mitigation.<\/jats:p>","DOI":"10.1145\/2187671.2187673","type":"journal-article","created":{"date-parts":[[2012,6,15]],"date-time":"2012-06-15T15:31:37Z","timestamp":1339774297000},"page":"1-46","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":98,"title":["Mitigating program security vulnerabilities"],"prefix":"10.1145","volume":"44","author":[{"given":"Hossain","family":"Shahriar","sequence":"first","affiliation":[{"name":"Queen's University, Kingston, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammad","family":"Zulkernine","sequence":"additional","affiliation":[{"name":"Queen's University, Kingston, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,6,14]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2006.55"},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 31st IEEE Conference on Local Computer Networks. 1008--1015","author":"Allen W."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. 143","author":"Ashcraft K."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/178243.178446"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315250"},{"key":"e_1_2_1_6_1","volume-title":"Proceedings of the International Performance, Computing and Communications Conference. 449--458","author":"Bertino E."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1083200.1083208"},{"key":"e_1_2_1_8_1","unstructured":"Burns J. 2005. Cross site request forgery: An introduction to a common Web application weakness. White paper Information Security Partners LLC.  Burns J. 2005. Cross site request forgery: An introduction to a common Web application weakness. White paper Information Security Partners LLC."},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation. 11","author":"Castro M."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180445"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1255329.1255344"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.111"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294265"},{"key":"e_1_2_1_14_1","unstructured":"CVE. 2010. Common vulnerabilities and exposures. http:\/\/cve.mitre.org.  CVE. 2010. Common vulnerabilities and exposures. http:\/\/cve.mitre.org."},{"key":"e_1_2_1_15_1","unstructured":"CWE. 2009. Common weakness enumeration. CWE\/SANS top 25 most dangerous programming errors. http:\/\/cwe.mitre.org\/top25.  CWE. 2009. Common weakness enumeration. CWE\/SANS top 25 most dangerous programming errors. http:\/\/cwe.mitre.org\/top25."},{"key":"e_1_2_1_16_1","unstructured":"CWE. 2010. CWE-352: Cross-Site request forgery (CSRF). http:\/\/cwe.mitre.org\/data\/definitions\/352.html.  CWE. 2010. CWE-352: Cross-Site request forgery (CSRF). http:\/\/cwe.mitre.org\/data\/definitions\/352.html."},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 10th Working Conference on Reverse Engineering (WCRE'03)","author":"Dahn C."},{"key":"e_1_2_1_18_1","unstructured":"Dekok A. 2007. Pscan (1.2-8) format string security checker for C files. http:\/\/packages.debian.org\/etch\/pscan.  Dekok A. 2007. Pscan (1.2-8) format string security checker for C files. http:\/\/packages.debian.org\/etch\/pscan."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/C-M.1978.218136"},{"key":"e_1_2_1_20_1","unstructured":"DOM. 1998. Document object model (DOM) level 1 specification version 1.0. http:\/\/www.w3.org.  DOM. 1998. Document object model (DOM) level 1 specification version 1.0. http:\/\/www.w3.org."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/781131.781149"},{"key":"e_1_2_1_22_1","unstructured":"Dowd M. McDonald J. and Schuh J. 2007. The Art of Software Security Assessment. Addison-Wesley.   Dowd M. McDonald J. and Schuh J. 2007. The Art of Software Security Assessment. Addison-Wesley."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the International Conference on Dependable Systems and Networks (DSN'00)","author":"Du W."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2008.44"},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the ICSE Workshop on Dynamic Analysis. 24--27","author":"Ernst M.","year":"2003"},{"key":"e_1_2_1_26_1","unstructured":"Erlingsson U. 2007. Low-Level software security: Attacks and defenses. Tech. rep. MSR-TR-07-153 Microsoft Research.  Erlingsson U. 2007. Low-Level software security: Attacks and defenses. Tech. rep. MSR-TR-07-153 Microsoft Research."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.976940"},{"key":"e_1_2_1_28_1","unstructured":"FlawFinder. 2010. http:\/\/www.dwheeler.com\/flawfinder.  FlawFinder. 2010. http:\/\/www.dwheeler.com\/flawfinder."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2007.63"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948155"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1519065.1519083"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1998.674827"},{"key":"e_1_2_1_33_1","unstructured":"Gordon L. A. Loeb M. P. Lucyshyn W. and Richardson R. 2004. Ninth CSI\/FBI computer crime and security survey. Tech. rep. RL32331 Computer Security Institute.  Gordon L. A. Loeb M. P. Lucyshyn W. and Richardson R. 2004. Ninth CSI\/FBI computer crime and security survey. Tech. rep. RL32331 Computer Security Institute."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cor.2007.01.013"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1526709.1526785"},{"key":"e_1_2_1_36_1","unstructured":"Guo P. 2006. A scalable mixed-level approach to dynamic analysis of C and C++ programs. Master of Engineering thesis Massachusetts Institute of Technology. May.  Guo P. 2006. A scalable mixed-level approach to dynamic analysis of C and C++ programs. Master of Engineering thesis Massachusetts Institute of Technology. May."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134319"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1083246.1083250"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1181775.1181797"},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the IEEE International Symposium on Secure Software Engineering.","author":"Halfond W."},{"key":"e_1_2_1_41_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS).","author":"Haugh E."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2007.43"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/379605.379665"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/775152.775174"},{"key":"e_1_2_1_45_1","unstructured":"Huss E. 1997. The C library reference guide release 1. http:\/\/www.acm.uiuc.edu\/webmonkeys\/book\/c_guide\/.  Huss E. 1997. The C library reference guide release 1. http:\/\/www.acm.uiuc.edu\/webmonkeys\/book\/c_guide\/."},{"key":"e_1_2_1_46_1","unstructured":"ISO. 1992. International Standards Organization Information Technology Database Languages SQL 3rd Ed. ISO\/IEC.  ISO. 1992. International Standards Organization Information Technology Database Languages SQL 3 rd Ed. ISO\/IEC."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1244002.1244071"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/638750.638781"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1512762.1512766"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2009.34"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1135777.1135817"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143997.1144271"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1363686.1364201"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the International Conference on Advanced Computing Technologies (ICACT). 1304--1307","author":"Kim H."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"e_1_2_1_58_1","unstructured":"Klein A. 2005. DOM-Based cross site scripting or XSS of the third kind. http:\/\/www.webappsec.org\/projects\/articles\/071105.shtml.  Klein A. 2005. DOM-Based cross site scripting or XSS of the third kind. http:\/\/www.webappsec.org\/projects\/articles\/071105.shtml."},{"key":"e_1_2_1_59_1","first-page":"55","article-title":"The frame pointer overwrite","volume":"9","author":"Klog","year":"1999","journal-title":"Phrack Mag."},{"key":"e_1_2_1_60_1","volume-title":"Proceedings of the Workshop on the Evaluation of Software Defect Detection Tools.","author":"Kratkewicz K."},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/1506216.1506248"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/1328408.1328410"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/1453101.1453137"},{"key":"e_1_2_1_64_1","unstructured":"Leah D. 2000. A memory allocator. http:\/\/g.oswego.edu\/dl\/html\/malloc.html.  Leah D. 2000. A memory allocator. http:\/\/g.oswego.edu\/dl\/html\/malloc.html."},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the 7th International Conference on Computer and Information Technology. 709--714","author":"Lin J."},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1267001"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2006.11"},{"key":"e_1_2_1_68_1","volume-title":"Proceedings of the 14th USENIX Security Symposium. 18","author":"Livshits V."},{"key":"e_1_2_1_69_1","volume-title":"Proceedings of the 6th International Workshop on Web Site Evolution. 71--80","author":"Lucca G."},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOSM.2008.4659254"},{"key":"e_1_2_1_71_1","unstructured":"Mathur A. 2008. Foundations of Software Testing 1st Ed. Pearson Education.   Mathur A. 2008. Foundations of Software Testing 1 st Ed. Pearson Education."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.5555\/1433006.1433021"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.84"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.v14:2"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWSESS.2009.5068455"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/WSE.2006.9"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2005.136"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250736"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2004.13"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2008.11"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314257.1314260"},{"key":"e_1_2_1_82_1","first-page":"49","article-title":"Smashing the stack for fun and profit","volume":"7","author":"One A.","year":"1996","journal-title":"Phrack Mag."},{"key":"e_1_2_1_83_1","unstructured":"OSVDB. 2010. Open source vulnerability database. http:\/\/osvdb.org.  OSVDB. 2010. Open source vulnerability database. http:\/\/osvdb.org."},{"key":"e_1_2_1_84_1","unstructured":"OWASP. 2010a. OWASP CSRFGuard project. http:\/\/www.owasp.org\/index.php\/CSRFGuard_2.2 _Configuration_Manual.  OWASP. 2010a. OWASP CSRFGuard project. http:\/\/www.owasp.org\/index.php\/CSRFGuard_2.2 _Configuration_Manual."},{"key":"e_1_2_1_85_1","unstructured":"OWASP. 2010b. Range and type error vulnerability. http:\/\/www.owasp.org\/index.php\/Category:Range_and_ Type_Error_Vulnerability.  OWASP. 2010b. Range and type error vulnerability. http:\/\/www.owasp.org\/index.php\/Category:Range_and_ Type_Error_Vulnerability."},{"key":"e_1_2_1_86_1","volume-title":"Proceedings of the 1st International Conference on Communication System Software and Middleware. 1--7.","author":"Pozza D."},{"key":"e_1_2_1_87_1","unstructured":"PAX. 2003. Documentation for the PaX project. http:\/\/pax.grsecurity.net\/docs\/pax.txt.  PAX. 2003. Documentation for the PaX project. http:\/\/pax.grsecurity.net\/docs\/pax.txt."},{"key":"e_1_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1145\/1281480.1281481"},{"key":"e_1_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102166"},{"key":"e_1_2_1_90_1","unstructured":"Robbins T. 2000. Libformat. http:\/\/archives.neohapsis.com\/archives\/linux\/lsap\/2000-q3\/0444.html.  Robbins T. 2000. Libformat. http:\/\/archives.neohapsis.com\/archives\/linux\/lsap\/2000-q3\/0444.html."},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.22"},{"key":"e_1_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218194010004621"},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the 4th International Workshop on Secure Software Engineering. 519--524","author":"Shahriar H."},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/SSIRI-C.2010.28"},{"key":"e_1_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.4018\/jsse.2010070102"},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2009.191"},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWSESS.2009.5068458"},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2008.123"},{"key":"e_1_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2008.8"},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1109\/QSIC.2008.33"},{"key":"e_1_2_1_101_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Shankar U."},{"key":"e_1_2_1_102_1","unstructured":"Silva A. 2005. Format strings. Gotfault Security Community version 2.5. http:\/\/www.milw0rm.com\/papers\/5.  Silva A. 2005. Format strings. Gotfault Security Community version 2.5. http:\/\/www.milw0rm.com\/papers\/5."},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/IAS.2007.23"},{"key":"e_1_2_1_104_1","unstructured":"Sotirov A. 2005. Automatic vulnerability detection using static analysis. MSc thesis The University of Alabama. http:\/\/gcc.vulncheck.org\/sotirov05automatic.pdf.  Sotirov A. 2005. Automatic vulnerability detection using static analysis. MSc thesis The University of Alabama. http:\/\/gcc.vulncheck.org\/sotirov05automatic.pdf."},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWIA.2005.10"},{"key":"e_1_2_1_106_1","unstructured":"Symantec. 2008. Internet security threat report trends for July-September 07. Volume XII. http:\/\/eval.symantec.com\/mktginfo\/enterprise\/white_papers\/b-whitepaper_exec_summary_internet_security_threat_report_xiii_04-2008.en-us.pdf.  Symantec. 2008. Internet security threat report trends for July-September 07. Volume XII. http:\/\/eval.symantec.com\/mktginfo\/enterprise\/white_papers\/b-whitepaper_exec_summary_internet_security_threat_report_xiii_04-2008.en-us.pdf."},{"key":"e_1_2_1_107_1","volume-title":"Proceedings of the 2nd Annual Conference on Privacy, Security and Trust. 155--160","author":"Tal O."},{"key":"e_1_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1109\/ADC.2005.11"},{"key":"e_1_2_1_109_1","unstructured":"Teso Scut\/Team. 2001. Exploiting format string vulnerabilities. http:\/\/doc.bughunter.net\/format-string\/exploit-fs.html.  Teso Scut\/Team. 2001. Exploiting format string vulnerabilities. http:\/\/doc.bughunter.net\/format-string\/exploit-fs.html."},{"key":"e_1_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1145\/1185448.1185570"},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1109\/SESS.2007.12"},{"key":"e_1_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542486"},{"key":"e_1_2_1_113_1","volume-title":"Proceedings of the International Conference on Dependable Systems and Networks. 541","author":"Tsai T."},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1145\/545186.545188"},{"key":"e_1_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030088"},{"key":"e_1_2_1_116_1","volume-title":"Proceedings of the Conference on Software Engineering and Applications (SEA).","author":"Vilela P."},{"key":"e_1_2_1_117_1","unstructured":"W3C. 1999. HTML 4.10 specification. http:\/\/www.w3.org\/TR\/REC-html40.  W3C. 1999. HTML 4.10 specification. http:\/\/www.w3.org\/TR\/REC-html40."},{"key":"e_1_2_1_118_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium.","author":"Wagner D."},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCRE.2005.36"},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368088.1368112"},{"key":"e_1_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250739"},{"key":"e_1_2_1_122_1","volume-title":"Proceedings of the Workshop on Source Code Analysis and Manipulation. 3--13","author":"Weber M."},{"key":"e_1_2_1_123_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASWEC.2006.40"},{"key":"e_1_2_1_124_1","volume-title":"Proceedings of the 10th Network and Distributed System Security Symposium.","author":"Wilander J."},{"key":"e_1_2_1_125_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Xie Y."},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.1145\/940071.940115"},{"key":"e_1_2_1_127_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029894.1029913"},{"key":"e_1_2_1_128_1","doi-asserted-by":"publisher","DOI":"10.1145\/1390630.1390636"},{"key":"e_1_2_1_129_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948153"},{"key":"e_1_2_1_130_1","doi-asserted-by":"publisher","DOI":"10.1145\/949952.940113"},{"key":"e_1_2_1_131_1","unstructured":"Younan Y. Joosen W. Piessens F. and Eynden H. 2005. Security of memory allocators for C and C++. Tech. rep. CW419 Katholieke University Leuven Belgium. http:\/\/www.fort-knox.be\/files\/CW419.pdf.  Younan Y. Joosen W. Piessens F. and Eynden H. 2005. Security of memory allocators for C and C++. Tech. rep. CW419 Katholieke University Leuven Belgium. http:\/\/www.fort-knox.be\/files\/CW419.pdf."},{"key":"e_1_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1145\/1190216.1190252"},{"key":"e_1_2_1_133_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029894.1029911"},{"key":"e_1_2_1_134_1","volume-title":"Proceedings of the International Conference on Apperceiving Computing and Intelligence Analysis. 270--273","author":"Zhang X."},{"key":"e_1_2_1_135_1","doi-asserted-by":"publisher","DOI":"10.1145\/267580.267590"},{"key":"e_1_2_1_136_1","unstructured":"Zuchlinski G. 2003. The anatomy of cross site scripting. http:\/\/www.net-security.org\/dl\/articles\/xss_anatomy.pdf.  Zuchlinski G. 2003. The anatomy of cross site scripting. http:\/\/www.net-security.org\/dl\/articles\/xss_anatomy.pdf."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2187671.2187673","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2187671.2187673","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:06:33Z","timestamp":1750241193000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2187671.2187673"}},"subtitle":["Approaches and challenges"],"short-title":[],"issued":{"date-parts":[[2012,6]]},"references-count":136,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,6]]}},"alternative-id":["10.1145\/2187671.2187673"],"URL":"https:\/\/doi.org\/10.1145\/2187671.2187673","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,6]]},"assertion":[{"value":"2009-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-06-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}