{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T02:24:39Z","timestamp":1769048679757,"version":"3.49.0"},"reference-count":168,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2012,6,1]],"date-time":"2012-06-01T00:00:00Z","timestamp":1338508800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2012,6]]},"abstract":"<jats:p>\n            The lack of memory safety in C\/C++ often leads to vulnerabilities.\n            <jats:italic>Code injection attacks<\/jats:italic>\n            exploit these vulnerabilities to gain control over the execution flow of applications. These attacks have played a key role in many major security incidents. Consequently, a huge body of research on countermeasures exists. We provide a comprehensive and structured survey of vulnerabilities and countermeasures that operate at runtime. These countermeasures make different trade-offs in terms of performance, effectivity, compatibility, etc., making it hard to evaluate and compare countermeasures in a given context. We define a classification and evaluation framework on the basis of which countermeasures can be assessed.\n          <\/jats:p>","DOI":"10.1145\/2187671.2187679","type":"journal-article","created":{"date-parts":[[2012,6,15]],"date-time":"2012-06-15T15:31:37Z","timestamp":1339774297000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":40,"title":["Runtime countermeasures for code injection attacks against C and C++ programs"],"prefix":"10.1145","volume":"44","author":[{"given":"Yves","family":"Younan","sequence":"first","affiliation":[{"name":"Katholieke Universiteit Leuven"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frank","family":"Piessens","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,6,14]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.30"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 18th USENIX Security Symposium.","author":"Akritidis P.","unstructured":"Akritidis , P. , Costa , M. , Castro , M. , and Hand , S . 2009. Baggy bounds checking: An efficient and backwards-compatible defense against out-of-bounds errors . In Proceedings of the 18th USENIX Security Symposium. Akritidis, P., Costa, M., Castro, M., and Hand, S. 2009. Baggy bounds checking: An efficient and backwards-compatible defense against out-of-bounds errors. In Proceedings of the 18th USENIX Security Symposium."},{"key":"e_1_2_1_4_1","unstructured":"Aleph One. 1996. Smashing the stack for fun and profit. Phrack 49.  Aleph One. 1996. Smashing the stack for fun and profit. Phrack 49."},{"key":"e_1_2_1_5_1","first-page":"3","article-title":"Defeating compiler-level buffer overflow protection","volume":"30","author":"Alexander S.","year":"2005","unstructured":"Alexander , S. 2005 . Defeating compiler-level buffer overflow protection . USENIX Mag. 30 , 3 . Alexander, S. 2005. Defeating compiler-level buffer overflow protection. USENIX Mag. 30, 3.","journal-title":"USENIX Mag."},{"key":"e_1_2_1_6_1","unstructured":"anonymous. 2001. Once upon a free(). Phrack 57.  anonymous. 2001. Once upon a free(). Phrack 57."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2009.80"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/178243.178446"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.v36:9"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Baratloo A.","unstructured":"Baratloo , A. , Singh , N. , and Tsai , T . 2000. Transparent runtime defense against stack smashing attacks . In Proceedings of the USENIX Annual Technical Conference. Baratloo, A., Singh, N., and Tsai, T. 2000. Transparent runtime defense against stack smashing attacks. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948147"},{"key":"e_1_2_1_12_1","unstructured":"BBP. 2003. BSD heap smashing. BlackHat.  BBP. 2003. BSD heap smashing. BlackHat."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133981.1134000"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/352600.352624"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 12th USENIX Security Symposium.","author":"Bhatkar S.","unstructured":"Bhatkar , S. , DuVarney , D. C. , and Sekar , R . 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits . In Proceedings of the 12th USENIX Security Symposium. Bhatkar, S., DuVarney, D. C., and Sekar, R. 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In Proceedings of the 12th USENIX Security Symposium."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_1"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Bhatkar S.","year":"2005","unstructured":"Bhatkar , S. , Sekar , R. , and DuVarney , D. C. 2005 . Efficient techniques for comprehensive protection from memory error exploits . In Proceedings of the 14th USENIX Security Symposium. Bhatkar, S., Sekar, R., and DuVarney, D. C. 2005. Efficient techniques for comprehensive protection from memory error exploits. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.4380180902"},{"key":"e_1_2_1_19_1","volume-title":"Compiler security checks in depth","author":"Bray B.","unstructured":"Bray , B. 2002. Compiler security checks in depth . Microsoft Corporation Visual C ++ .NET. Bray, B. 2002. Compiler security checks in depth. Microsoft Corporation Visual C++ .NET."},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the 3rd International Workshop on Information Assurance.","author":"Bruschi D.","unstructured":"Bruschi , D. , Cavallaro , L. , and Lanzi , A . 2007a. Diversified process replicae for defeating memory error exploits . In Proceedings of the 3rd International Workshop on Information Assurance. Bruschi, D., Cavallaro, L., and Lanzi, A. 2007a. Diversified process replicae for defeating memory error exploits. In Proceedings of the 3rd International Workshop on Information Assurance."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 3rd International Workshop on Information Assurance.","author":"Bruschi D.","unstructured":"Bruschi , D. , Cavallaro , L. , and Lanzi , A . 2007b. An efficient technique for preventing mimicry and impossible paths execution attacks . In Proceedings of the 3rd International Workshop on Information Assurance. Bruschi, D., Cavallaro, L., and Lanzi, A. 2007b. An efficient technique for preventing mimicry and impossible paths execution attacks. In Proceedings of the 3rd International Workshop on Information Assurance."},{"key":"e_1_2_1_22_1","unstructured":"Bulba and Kil3r. 2000. Bypassing stackguard and stackshield. Phrack 56.  Bulba and Kil3r. 2000. Bypassing stackguard and stackshield. Phrack 56."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the 7th Symposium on Operating Systems Design and Implementation.","author":"Castro M.","unstructured":"Castro , M. , Costa , M. , and Harris , T . 2006. Securing software by enforcing data-flow integrity . In Proceedings of the 7th Symposium on Operating Systems Design and Implementation. Castro, M., Costa, M., and Harris, T. 2006. Securing software by enforcing data-flow integrity. In Proceedings of the 7th Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_34"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1255329.1255344"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10772-6_13"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.36"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Chen S.","unstructured":"Chen , S. , Xu , J. , Sezer , E. C. , Gauriar , P. , and Iyer , R. K . 2005. Non-control-data attacks are realistic threats . In Proceedings of the 14th USENIX Security Symposium. Chen, S., Xu, J., Sezer, E. C., Gauriar, P., and Iyer, R. K. 2005. Non-control-data attacks are realistic threats. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the 9th European Symposium on Research in Computer Security.","author":"Chinchani R.","unstructured":"Chinchani , R. , Iyer , A. , Jayaraman , B. , and Upadhyaya , S . 2004. Archerr: Runtime environment driven program safety . In Proceedings of the 9th European Symposium on Research in Computer Security. Chinchani, R., Iyer, A., Jayaraman, B., and Upadhyaya, S. 2004. Archerr: Runtime environment driven program safety. In Proceedings of the 9th European Symposium on Research in Computer Security."},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the 21st International Conference on Distributed Computing Systems.","author":"Chiueh T.","unstructured":"Chiueh , T. and Hsu , F . 2001. RAD: A compile-time solution to buffer overflow attacks . In Proceedings of the 21st International Conference on Distributed Computing Systems. Chiueh, T. and Hsu, F. 2001. RAD: A compile-time solution to buffer overflow attacks. In Proceedings of the 21st International Conference on Distributed Computing Systems."},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of the 16th European Symposium on Programming.","author":"Condit J.","unstructured":"Condit , J. , Harren , M. , Anderson , Z. , Gay , D. , and Necula , G . 2007. Dependent types for low-level programming . In Proceedings of the 16th European Symposium on Programming. Condit, J., Harren, M., Anderson, Z., Gay, D., and Necula, G. 2007. Dependent types for low-level programming. In Proceedings of the 16th European Symposium on Programming."},{"key":"e_1_2_1_32_1","unstructured":"Conover M. 1999. w00w00 on Heap Overflows. http:\/\/www.w00w00.org\/articles.html.  Conover M. 1999. w00w00 on Heap Overflows. http:\/\/www.w00w00.org\/articles.html."},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the Workshop on Architectural Support for Security and Anti-Virus.","author":"Corliss M.","unstructured":"Corliss , M. , Lewis , E. C. , and Roth , A . 2004. Using dise to protect return addresses from attack . In Proceedings of the Workshop on Architectural Support for Security and Anti-Virus. Corliss, M., Lewis, E. C., and Roth, A. 2004. Using dise to protect return addresses from attack. In Proceedings of the Workshop on Architectural Support for Security and Anti-Virus."},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Cowan C.","unstructured":"Cowan , C. , Barringer , M. , Beattie , S. , Kroah-Hartman , G. , Frantzen , M. , and Lokier , J . 2001. FormatGuard: Automatic protection from printf format string vulnerabilities . In Proceedings of the 10th USENIX Security Symposium. Cowan, C., Barringer, M., Beattie, S., Kroah-Hartman, G., Frantzen, M., and Lokier, J. 2001. FormatGuard: Automatic protection from printf format string vulnerabilities. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_35_1","volume-title":"Proceedings of the 12th USENIX Security Symposium.","author":"Cowan C.","unstructured":"Cowan , C. , Beattie , S. , Johansen , J. , and Wagle , P . 2003. PointGuard: Protecting pointers from buffer overflow vulnerabilities . In Proceedings of the 12th USENIX Security Symposium. Cowan, C., Beattie, S., Johansen, J., and Wagle, P. 2003. PointGuard: Protecting pointers from buffer overflow vulnerabilities. In Proceedings of the 12th USENIX Security Symposium."},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the 7th USENIX Security Symposium.","author":"Cowan C.","unstructured":"Cowan , C. , Pu , C. , Maier , D. , Hinton , H. , Walpole , J. , Bakke , P. , Beattie , S. , Grier , A. , Wagle , P. , and Zhang , Q . 1998. StackGuard: Automatic adaptive detection and prevention of buffer overflow attacks . In Proceedings of the 7th USENIX Security Symposium. Cowan, C., Pu, C., Maier, D., Hinton, H., Walpole, J., Bakke, P., Beattie, S., Grier, A., Wagle, P., and Zhang, Q. 1998. StackGuard: Automatic adaptive detection and prevention of buffer overflow attacks. In Proceedings of the 7th USENIX Security Symposium."},{"key":"e_1_2_1_37_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Cox B.","unstructured":"Cox , B. , Evans , D. , Filipi , A. , Rowanhill , J. , Hu , W. , Davidson , J. , Knight , J. , Nguyen-Tuong , A. , and Hiser , J . 2006. N-variant systems: A secretless framework for security through diversity . In Proceedings of the 15th USENIX Security Symposium. Cox, B., Evans, D., Filipi, A., Rowanhill, J., Hu, W., Davidson, J., Knight, J., Nguyen-Tuong, A., and Hiser, J. 2006. N-variant systems: A secretless framework for security through diversity. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the 10th Working Conference on Reverse Engineering.","author":"Dahn C.","unstructured":"Dahn , C. and Mancoridis , S . 2003. Using program transformation to secure C programs against buffer overflows . In Proceedings of the 10th Working Conference on Reverse Engineering. Dahn, C. and Mancoridis, S. 2003. Using program transformation to secure C programs against buffer overflows. In Proceedings of the 10th Working Conference on Reverse Engineering."},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 17th USENIX Security symposium.","author":"Dalton M.","unstructured":"Dalton , M. , Kannan , H. , and Kozyrakis , C . 2008. Real-world buffer overflow protection for userspace & kernelspace . In Proceedings of the 17th USENIX Security symposium. Dalton, M., Kannan, H., and Kozyrakis, C. 2008. Real-world buffer overflow protection for userspace & kernelspace. In Proceedings of the 17th USENIX Security symposium."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134309"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2006.31"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133981.1133999"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/780732.780743"},{"key":"e_1_2_1_44_1","unstructured":"Dobrovitski I. 2003. Exploit for CVS double free() for Linux pserver. http:\/\/seclists.org\/bugtraq\/2003\/Feb\/42.  Dobrovitski I. 2003. Exploit for CVS double free() for Linux pserver. http:\/\/seclists.org\/bugtraq\/2003\/Feb\/42."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_6"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/335169.335201"},{"key":"e_1_2_1_47_1","doi-asserted-by":"crossref","unstructured":"Erlingsson U. Younan Y. and Piessens F. 2010. Low-level software security by example. In Handbook of Information and Communication Security. Springer.  Erlingsson U. Younan Y. and Piessens F. 2010. Low-level software security by example. In Handbook of Information and Communication Security. Springer.","DOI":"10.1007\/978-3-642-04117-4_30"},{"key":"e_1_2_1_48_1","unstructured":"Etoh H. and Yoda K. 2000. Protecting from stack-smashing attacks. Tech. rep. IBM Research Divison Tokyo Research Laboratory.  Etoh H. and Yoda K. 2000. Protecting from stack-smashing attacks. Tech. rep. IBM Research Divison Tokyo Research Laboratory."},{"key":"e_1_2_1_49_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Evans D.","unstructured":"Evans , D. and Twyman , A . 1999. Flexible policy-directed code safety . In Proceedings of the IEEE Symposium on Security and Privacy. Evans, D. and Twyman, A. 1999. Flexible policy-directed code safety. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Feng H. H.","unstructured":"Feng , H. H. , Kolesnikov , O. M. , Fogla , P. , Lee , W. , and Gong , W . 2003. Anomaly detection using call stack information . In Proceedings of the IEEE Symposium on Security and Privacy. Feng, H. H., Kolesnikov, O. M., Fogla, P., Lee, W., and Gong, W. 2003. Anomaly detection using call stack information. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the 20th IEEE Symposium on Reliable Distributed Systems.","author":"Fetzer C.","unstructured":"Fetzer , C. and Xiao , Z . 2001. Detecting heap-smashing attacks through fault containment wrappers . In Proceedings of the 20th IEEE Symposium on Reliable Distributed Systems. Fetzer, C. and Xiao, Z. 2001. Detecting heap-smashing attacks through fault containment wrappers. In Proceedings of the 20th IEEE Symposium on Reliable Distributed Systems."},{"key":"e_1_2_1_52_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Forrest S.","unstructured":"Forrest , S. , Hofmeyr , S. A. , Somayaji , A. , and Longstaff , T. A . 1996. A sense of self for Unix processes . In Proceedings of the IEEE Symposium on Security and Privacy. Forrest, S., Hofmeyr, S. A., Somayaji, A., and Longstaff, T. A. 1996. A sense of self for Unix processes. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455775"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655077.1655083"},{"key":"e_1_2_1_55_1","volume-title":"Proceedings of the 10th USENIX Security Symposium.","author":"Frantzen M.","unstructured":"Frantzen , M. and Shuey , M . 2001. StackGhost: Hardware facilitated stack protection . In Proceedings of the 10th USENIX Security Symposium. Frantzen, M. and Shuey, M. 2001. StackGhost: Hardware facilitated stack protection. In Proceedings of the 10th USENIX Security Symposium."},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/1518684.1518686"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11747-3_1"},{"key":"e_1_2_1_58_1","volume-title":"Proceedings of the 6th USENIX Security Symposium.","author":"Goldberg I.","unstructured":"Goldberg , I. , Wagner , D. , Thomas , R. , and Brewer , E. A . 1996. A secure environment for untrusted helper applications . In Proceedings of the 6th USENIX Security Symposium. Goldberg, I., Wagner, D., Thomas, R., and Brewer, E. A. 1996. A secure environment for untrusted helper applications. In Proceedings of the 6th USENIX Security Symposium."},{"key":"e_1_2_1_59_1","first-page":"1","article-title":"Preventing buffer overflows in C++","volume":"29","author":"Grimes R.","year":"2004","unstructured":"Grimes , R. 2004 . Preventing buffer overflows in C++ . Dr Dobb's J. Softw. Tools Prof. Program. 29 , 1 . Grimes, R. 2004. Preventing buffer overflows in C++. Dr Dobb's J. Softw. Tools Prof. Program. 29, 1.","journal-title":"Dr Dobb's J. Softw. Tools Prof. Program."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/1138912.1138926"},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the Winter USENIX Conference.","author":"Hastings R.","unstructured":"Hastings , R. and Joyce , B . 1992. Purify: Fast detection of memory leaks and access errors . In Proceedings of the Winter USENIX Conference. Hastings, R. and Joyce, B. 1992. Purify: Fast detection of memory leaks and access errors. In Proceedings of the Winter USENIX Conference."},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029873.1029883"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00199-4_14"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217939"},{"key":"e_1_2_1_65_1","volume-title":"Writing Secure Code","author":"Howard M.","unstructured":"Howard , M. and LeBlanc , D. 2001. Writing Secure Code . Microsoft Press . Howard, M. and LeBlanc, D. 2001. Writing Secure Code. Microsoft Press."},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134760.1134764"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECURWARE.2008.16"},{"key":"e_1_2_1_68_1","volume-title":"IA-32 Intel Architecture Software Developer's Manual Volume 1: Basic Architecture","author":"Intel Corporation 2001.","unstructured":"Intel Corporation 2001. IA-32 Intel Architecture Software Developer's Manual Volume 1: Basic Architecture . Intel Corporation . Order Nr. 245470. Intel Corporation 2001. IA-32 Intel Architecture Software Developer's Manual Volume 1: Basic Architecture. Intel Corporation. Order Nr. 245470."},{"key":"e_1_2_1_69_1","unstructured":"ISO. 1999. ISO\/IEC 9899:1999: Programming languages -- C. Tech. rep. International Organization for Standards.  ISO. 1999. ISO\/IEC 9899:1999: Programming languages -- C. Tech. rep. International Organization for Standards."},{"key":"e_1_2_1_70_1","volume-title":"Proceedings of the 26th IEEE International Symposium on Reliable Distributed Systems.","author":"Jiang X.","unstructured":"Jiang , X. , Wang , H. J. , Xu , D. , and Wang , Y. M . 2007. Randsys: Thwarting code injection attacks with system service interface randomization . In Proceedings of the 26th IEEE International Symposium on Reliable Distributed Systems. Jiang, X., Wang, H. J., Xu, D., and Wang, Y. M. 2007. Randsys: Thwarting code injection attacks with system service interface randomization. In Proceedings of the 26th IEEE International Symposium on Reliable Distributed Systems."},{"key":"e_1_2_1_71_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Jim T.","unstructured":"Jim , T. , Morrisett , G. , Grossman , D. , Hicks , M. , Cheney , J. , and Wang , Y . 2002. Cyclone: A safe dialect of C . In Proceedings of the USENIX Annual Technical Conference. Jim, T., Morrisett, G., Grossman, D., Hicks, M., Cheney, J., and Wang, Y. 2002. Cyclone: A safe dialect of C. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_72_1","volume-title":"Proceedings of the 3rd International Workshop on Automatic Debugging.","author":"Jones R. W. M.","unstructured":"Jones , R. W. M. and Kelly , P. H. J. 1997. Backwards-compatible bounds checking for arrays and pointers in C programs . In Proceedings of the 3rd International Workshop on Automatic Debugging. Jones, R. W. M. and Kelly, P. H. J. 1997. Backwards-compatible bounds checking for arrays and pointers in C programs. In Proceedings of the 3rd International Workshop on Automatic Debugging."},{"key":"e_1_2_1_73_1","unstructured":"Kaempf M. 2001. Vudo\u2014An object superstitiously believed to embody magical powers. Phrack 57.  Kaempf M. 2001. Vudo\u2014An object superstitiously believed to embody magical powers. Phrack 57."},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.22"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_2_1_76_1","volume-title":"Proceedings of the USENIX Summer Conference.","author":"Kendall S. C.","year":"1983","unstructured":"Kendall , S. C. 1983 . Bcc: Runtime checking for C programs . In Proceedings of the USENIX Summer Conference. Kendall, S. C. 1983. Bcc: Runtime checking for C programs. In Proceedings of the USENIX Summer Conference."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/1168857.1168884"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.9"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1007\/11937807_19"},{"key":"e_1_2_1_80_1","volume-title":"Proceedings of the 11th USENIX Security Symposium.","author":"Kiriansky V.","unstructured":"Kiriansky , V. , Bruening , D. , and Amarasinghe , S . 2002. Secure execution via program shepherding . In Proceedings of the 11th USENIX Security Symposium. Kiriansky, V., Bruening, D., and Amarasinghe, S. 2002. Secure execution via program shepherding. In Proceedings of the 11th USENIX Security Symposium."},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70500-0_28"},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/581630.581678"},{"key":"e_1_2_1_83_1","unstructured":"Krennmair A. 2003. ContraPolice: a libc extension for protecting applications from heap-smashing attacks. http:\/\/synflood.at\/papers\/cp.pdf.  Krennmair A. 2003. ContraPolice: a libc extension for protecting applications from heap-smashing attacks. http:\/\/synflood.at\/papers\/cp.pdf."},{"key":"e_1_2_1_84_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Kruegel C.","unstructured":"Kruegel , C. , Kirda , E. , Mutz , D. , Robertson , W. , and Vigna , G . 2005. Automating mimicry attacks using static binary analysis . In Proceedings of the 14th USENIX Security Symposium. Kruegel, C., Kirda, E., Mutz, D., Robertson, W., and Vigna, G. 2005. Automating mimicry attacks using static binary analysis. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.25"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2004.1293079"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065027"},{"key":"e_1_2_1_88_1","volume-title":"Proceedings of the 1st International Conference on Security in Pervasive Computing.","author":"Lee R. B.","unstructured":"Lee , R. B. , Karig , D. K. , McGregor , J. P. , and Shi , Z . 2003. Enlisting hardware architecture to thwart malicious code injection . In Proceedings of the 1st International Conference on Security in Pervasive Computing. Lee, R. B., Karig, D. K., McGregor, J. P., and Shi, Z. 2003. Enlisting hardware architecture to thwart malicious code injection. In Proceedings of the 1st International Conference on Security in Pervasive Computing."},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the 11th USENIX Security Symposium.","author":"Lhee K.-S.","unstructured":"Lhee , K.-S. and Chapin , S. J . 2002. Type-assisted dynamic buffer overflow detection . In Proceedings of the 11th USENIX Security Symposium. Lhee, K.-S. and Chapin, S. J. 2002. Type-assisted dynamic buffer overflow detection. In Proceedings of the 11th USENIX Security Symposium."},{"key":"e_1_2_1_90_1","volume-title":"Proceedings of the 23rd Annual Computer Security Applications Conference.","author":"Li W.","unstructured":"Li , W. and Chiueh , T . 2007. Automated format string attack prevention for win32\/x86 binaries . In Proceedings of the 23rd Annual Computer Security Applications Conference. Li, W. and Chiueh, T. 2007. Automated format string attack prevention for win32\/x86 binaries. In Proceedings of the 23rd Annual Computer Security Applications Conference."},{"key":"e_1_2_1_91_1","first-page":"1","article-title":"A system call randomization-based method for countering code-injection attacks","volume":"1","author":"Liang Z.","year":"2009","unstructured":"Liang , Z. , Liang , B. , and Li , L. 2009 . A system call randomization-based method for countering code-injection attacks . Int. J. Inform. Technol. Comp. Sci. 1 , 1 . Liang, Z., Liang, B., and Li, L. 2009. A system call randomization-based method for countering code-injection attacks. Int. J. Inform. Technol. Comp. Sci. 1, 1.","journal-title":"Int. J. Inform. Technol. Comp. Sci."},{"key":"e_1_2_1_92_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Lin C.","unstructured":"Lin , C. , Rajagopalan , M. , Baker , S. , Collberg , C. , Debray , S. , and Hartman , J . 2005. Protecting against unexpected system calls . In Proceedings of the 14th USENIX Security Symposium. Lin, C., Rajagopalan, M., Baker, S., Collberg, C., Debray, S., and Hartman, J. 2005. Protecting against unexpected system calls. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the International Conference on Communications.","author":"Lin Y.-D.","unstructured":"Lin , Y.-D. , Wu , F.-C. , Lai , Y.-C. , Huang , T.-Y. , and Lin , F . 2010. Embedded tainttracker: Lightweight tracking of taint data against buffer overflow attacks . In Proceedings of the International Conference on Communications. Lin, Y.-D., Wu, F.-C., Lai, Y.-C., Huang, T.-Y., and Lin, F. 2010. Embedded tainttracker: Lightweight tracking of taint data against buffer overflow attacks. In Proceedings of the International Conference on Communications."},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02918-9_7"},{"key":"e_1_2_1_95_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"McCamant S.","unstructured":"McCamant , S. and Morrisett , G . 2006. Evaluating SFI for a CISC architecture . In Proceedings of the 15th USENIX Security Symposium. McCamant, S. and Morrisett, G. 2006. Evaluating SFI for a CISC architecture. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_1_96_1","unstructured":"Messier M. and Viega J. 2003. Safe c string library v1.0.2. http:\/\/www.zork.org\/safestr.  Messier M. and Viega J. 2003. Safe c string library v1.0.2. http:\/\/www.zork.org\/safestr."},{"key":"e_1_2_1_97_1","unstructured":"Microsoft. 2003. Buffer overrun in RPC interface could allow code execution. Microsoft Security Bulletin MS03-026.  Microsoft. 2003. Buffer overrun in RPC interface could allow code execution. Microsoft Security Bulletin MS03-026."},{"key":"e_1_2_1_98_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Miller T. C.","unstructured":"Miller , T. C. and de Raadt, T. 1999. strlcpy and strlcat\u2014Consistent, safe string copy and concatenation . In Proceedings of the USENIX Annual Technical Conference. Miller, T. C. and de Raadt, T. 1999. strlcpy and strlcat\u2014Consistent, safe string copy and concatenation. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542504"},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806651.1806657"},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.29"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1145\/503272.503286"},{"key":"e_1_2_1_103_1","volume-title":"Proceedings of the 2nd Workshop on Semantics, Program Analysis, and Computing Environments for Memory Management.","author":"Nethercote N.","unstructured":"Nethercote , N. and Fitzhardinge , J . 2004. Bounds-checking entire programs without recompiling . In Proceedings of the 2nd Workshop on Semantics, Program Analysis, and Computing Environments for Memory Management. Nethercote, N. and Fitzhardinge, J. 2004. Bounds-checking entire programs without recompiling. In Proceedings of the 2nd Workshop on Semantics, Program Analysis, and Computing Environments for Memory Management."},{"key":"e_1_2_1_104_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium.","author":"Newsome J.","unstructured":"Newsome , J. and Song , D . 2005. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software . In Proceedings of the 12th Annual Network and Distributed System Security Symposium. Newsome, J. and Song, D. 2005. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In Proceedings of the 12th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_105_1","volume-title":"Proceedings of the International Symposium on Software Security.","author":"Oiwa Y.","unstructured":"Oiwa , Y. , Sekiguchi , T. , Sumii , E. , and Yonezawa , A . 2002. Fail-safe ANSI-C compiler: An approach to making C programs secure: Progress report . In Proceedings of the International Symposium on Software Security. Oiwa, Y., Sekiguchi, T., Sumii, E., and Yonezawa, A. 2002. Fail-safe ANSI-C compiler: An approach to making C programs secure: Progress report. In Proceedings of the International Symposium on Software Security."},{"key":"e_1_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368310.1368334"},{"key":"e_1_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1145\/1289816.1289833"},{"key":"e_1_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.1002\/(SICI)1097-024X(199701)27:1%3C87::AID-SPE78%3E3.0.CO;2-P"},{"key":"e_1_2_1_109_1","unstructured":"Perens B. 1987. Electric fence. http:\/\/perens.com.  Perens B. 1987. Electric fence. http:\/\/perens.com."},{"key":"e_1_2_1_110_1","volume-title":"Proceedings of the 1st International Conference on Communication System Software and Middleware.","author":"Pozza D.","unstructured":"Pozza , D. , Sisto , R. , Durante , L. , and Valenzano , A . 2006. Comparing lexical analysis tools for buffer overflow detection in network software . In Proceedings of the 1st International Conference on Communication System Software and Middleware. Pozza, D., Sisto, R., Durante, L., and Valenzano, A. 2006. Comparing lexical analysis tools for buffer overflow detection in network software. In Proceedings of the 1st International Conference on Communication System Software and Middleware."},{"key":"e_1_2_1_111_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Prasad M.","unstructured":"Prasad , M. and Chiueh , T . 2003. A binary rewriting defense against stack-based overflow attacks . In Proceedings of the USENIX Annual Technical Conference. Prasad, M. and Chiueh, T. 2003. A binary rewriting defense against stack-based overflow attacks. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_112_1","volume-title":"Proceedings of the USENIX Annual Technical Conference.","author":"Prevelakis V.","unstructured":"Prevelakis , V. and Spinellis , D . 2001. Sandboxing applications . In Proceedings of the USENIX Annual Technical Conference. Prevelakis, V. and Spinellis, D. 2001. Sandboxing applications. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_2_1_113_1","volume-title":"Proceedings of the 12th USENIX Security Symposium.","author":"Provos N.","year":"2003","unstructured":"Provos , N. 2003 . Improving host security with system call policies . In Proceedings of the 12th USENIX Security Symposium. Provos, N. 2003. Improving host security with system call policies. In Proceedings of the 12th USENIX Security Symposium."},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2006.29"},{"key":"e_1_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1145\/948187.948201"},{"key":"e_1_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.23"},{"key":"e_1_2_1_117_1","volume-title":"Proceedings of the 18th USENIX Security Symposium.","author":"Ratanaworabhan P.","unstructured":"Ratanaworabhan , P. , Livshits , B. , and Zorn , B . 2009. Nozzle: A defense against heap-spraying code injection attacks . In Proceedings of the 18th USENIX Security Symposium. Ratanaworabhan, P., Livshits, B., and Zorn, B. 2009. Nozzle: A defense against heap-spraying code injection attacks. In Proceedings of the 18th USENIX Security Symposium."},{"key":"e_1_2_1_118_1","volume-title":"Proceedings of the 6th Symposium on Operating Systems Design and Implementation.","author":"Rinard M.","unstructured":"Rinard , M. , Cadar , C. , Dumitran , D. , Roy , D. , Leu , T. , and Beebee , W. S . 2004. Enhancing server availability and security through failure-oblivious computing . In Proceedings of the 6th Symposium on Operating Systems Design and Implementation. Rinard, M., Cadar, C., Dumitran, D., Roy, D., Leu, T., and Beebee, W. S. 2004. Enhancing server availability and security through failure-oblivious computing. In Proceedings of the 6th Symposium on Operating Systems Design and Implementation."},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.2"},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102166"},{"key":"e_1_2_1_121_1","unstructured":"rix. 2000. Smashing C++ VPTRs. Phrack 56.  rix. 2000. Smashing C++ VPTRs. Phrack 56."},{"key":"e_1_2_1_122_1","unstructured":"Robbins T. 2001. Libformat. http:\/\/www.securityfocus.com\/tools\/1818.  Robbins T. 2001. Libformat. http:\/\/www.securityfocus.com\/tools\/1818."},{"key":"e_1_2_1_123_1","volume-title":"Proceedings of the 17th Large Installation Systems Administrators Conference.","author":"Robertson W.","unstructured":"Robertson , W. , Kruegel , C. , Mutz , D. , and Valeur , F . 2003. Runtime detection of heap-based overflows . In Proceedings of the 17th Large Installation Systems Administrators Conference. Robertson, W., Kruegel, C., Mutz, D., and Valeur, F. 2003. Runtime detection of heap-based overflows. In Proceedings of the 17th Large Installation Systems Administrators Conference."},{"key":"e_1_2_1_124_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.16"},{"key":"e_1_2_1_125_1","volume-title":"Proceedings of the 11th Annual Network and Distributed System Security Symposium.","author":"Ruwase O.","unstructured":"Ruwase , O. and Lam , M. S . 2004. A practical dynamic buffer overflow detector . In Proceedings of the 11th Annual Network and Distributed System Security Symposium. Ruwase, O. and Lam, M. S. 2004. A practical dynamic buffer overflow detector. In Proceedings of the 11th Annual Network and Distributed System Security Symposium."},{"key":"e_1_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.1145\/1519065.1519071"},{"key":"e_1_2_1_127_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_1_128_1","unstructured":"scut. 2001. Exploiting format string vulnerabilities. http:\/\/crypto.stanford.edu\/cs155\/papers\/formatstring-1.2.pdf.  scut. 2001. Exploiting format string vulnerabilities. http:\/\/crypto.stanford.edu\/cs155\/papers\/formatstring-1.2.pdf."},{"key":"e_1_2_1_129_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Sekar R.","unstructured":"Sekar , R. , Bendre , M. , Dhurjati , D. , and Bollineni , P . 2001. A fast automaton-based method for detecting anomalous program behaviors . In Proceedings of the IEEE Symposium on Security and Privacy. Sekar, R., Bendre, M., Dhurjati, D., and Bollineni, P. 2001. A fast automaton-based method for detecting anomalous program behaviors. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_130_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_2_1_131_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2006.04.010"},{"key":"e_1_2_1_133_1","volume-title":"Proceedings of the 19th Annual Computer Security Applications Conference.","author":"Shao Z.","unstructured":"Shao , Z. , Zhuge , Q. , He , Y. , and Sha , E. H. M. 2003. Defending embedded systems against buffer overflow via hardware\/software . In Proceedings of the 19th Annual Computer Security Applications Conference. Shao, Z., Zhuge, Q., He, Y., and Sha, E. H. M. 2003. Defending embedded systems against buffer overflow via hardware\/software. In Proceedings of the 19th Annual Computer Security Applications Conference."},{"key":"e_1_2_1_134_1","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2006.43"},{"key":"e_1_2_1_135_1","volume-title":"Internet explorer iframe src&name parameter bof remote compromise","author":"SkyLined","unstructured":"SkyLined . 2004. Internet explorer iframe src&name parameter bof remote compromise . Microsoft Corporation . SkyLined. 2004. Internet explorer iframe src&name parameter bof remote compromise. Microsoft Corporation."},{"key":"e_1_2_1_136_1","doi-asserted-by":"publisher","DOI":"10.5555\/1268028.1268041"},{"key":"e_1_2_1_137_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium.","author":"Smirnov A.","unstructured":"Smirnov , A. and Chiueh , T . 2005. Dira: Automatic detection, identification and repair of control-hijacking attacks . In Proceedings of the Network and Distributed System Security Symposium. Smirnov, A. and Chiueh, T. 2005. Dira: Automatic detection, identification and repair of control-hijacking attacks. In Proceedings of the Network and Distributed System Security Symposium."},{"key":"e_1_2_1_138_1","unstructured":"Smith N. P. 1997. Stack smashing vulnerabilities in the unix operating system. http:\/\/reality.sgi.com\/nate\/machines\/security\/stack-smashing\/.  Smith N. P. 1997. Stack smashing vulnerabilities in the unix operating system. http:\/\/reality.sgi.com\/nate\/machines\/security\/stack-smashing\/."},{"key":"e_1_2_1_139_1","unstructured":"Snarskii A. 1997. Freebsd libc stack integrity patch.  Snarskii A. 1997. Freebsd libc stack integrity patch."},{"key":"e_1_2_1_140_1","unstructured":"Snarskii A. 1999. Libparanoia.  Snarskii A. 1999. Libparanoia."},{"key":"e_1_2_1_141_1","unstructured":"Solar Designer. 1997. Non-executable stack patch.  Solar Designer. 1997. Non-executable stack patch."},{"key":"e_1_2_1_142_1","unstructured":"Solar Designer. 2000. JPEG COM marker processing vulnerability in netscape browsers. http:\/\/www. openwall.com\/linux.  Solar Designer. 2000. JPEG COM marker processing vulnerability in netscape browsers. http:\/\/www. openwall.com\/linux."},{"key":"e_1_2_1_143_1","volume-title":"Proceedings of the 14th Conference on USENIX Security Symposium.","author":"Sovarel A. N.","unstructured":"Sovarel , A. N. , Evans , D. , and Paul , N . 2005. Where's the feeb&quest; The effectiveness of instruction set randomization . In Proceedings of the 14th Conference on USENIX Security Symposium. Sovarel, A. N., Evans, D., and Paul, N. 2005. Where's the feeb&quest; The effectiveness of instruction set randomization. In Proceedings of the 14th Conference on USENIX Security Symposium."},{"key":"e_1_2_1_144_1","doi-asserted-by":"publisher","DOI":"10.1145\/63526.63527"},{"key":"e_1_2_1_145_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.4380220403"},{"key":"e_1_2_1_146_1","doi-asserted-by":"publisher","DOI":"10.1145\/1519144.1519145"},{"key":"e_1_2_1_147_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_2_1_148_1","unstructured":"The PaX Team. 2000. Documentation for the PaX project. http:\/\/pax.grsecurity.net\/docs\/.  The PaX Team. 2000. Documentation for the PaX project. http:\/\/pax.grsecurity.net\/docs\/."},{"key":"e_1_2_1_149_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.20"},{"key":"e_1_2_1_150_1","unstructured":"Vendicator. 2000. Documentation for Stack Shield.  Vendicator. 2000. Documentation for Stack Shield."},{"key":"e_1_2_1_151_1","volume-title":"Building Secure Software","author":"Viega J.","unstructured":"Viega , J. and McGraw , G. 2002. Building Secure Software . Addison-Wesley . Viega, J. and McGraw, G. 2002. Building Secure Software. Addison-Wesley."},{"key":"e_1_2_1_152_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Wagner D.","unstructured":"Wagner , D. and Dean , D . 2001. Intrusion detection via static analysis . In Proceedings of the IEEE Symposium on Security and Privacy. Wagner, D. and Dean, D. 2001. Intrusion detection via static analysis. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_153_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_2_1_154_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.33"},{"key":"e_1_2_1_155_1","volume-title":"Proceedings of the 7th Nordic Workshop on Secure IT Systems.","author":"Wilander J.","unstructured":"Wilander , J. and Kamkar , M . 2002. A comparison of publicly available tools for static intrusion prevention . In Proceedings of the 7th Nordic Workshop on Secure IT Systems. Wilander, J. and Kamkar, M. 2002. A comparison of publicly available tools for static intrusion prevention. In Proceedings of the 7th Nordic Workshop on Secure IT Systems."},{"key":"e_1_2_1_156_1","unstructured":"Wojtczuk R. 1998. Defeating Solar Designer's non-executable stack patch. http:\/\/insecure.org\/sploits\/non-executable.stack.problems.html.  Wojtczuk R. 1998. Defeating Solar Designer's non-executable stack patch. http:\/\/insecure.org\/sploits\/non-executable.stack.problems.html."},{"key":"e_1_2_1_157_1","volume-title":"Proceedings of the 22nd International Symposium on Reliable Distributed Systems.","author":"Xu J.","unstructured":"Xu , J. , Kalbarczyk , Z. , and Iyer , R. K . 2003. Transparent runtime randomization for security . In Proceedings of the 22nd International Symposium on Reliable Distributed Systems. Xu, J., Kalbarczyk, Z., and Iyer, R. K. 2003. Transparent runtime randomization for security. In Proceedings of the 22nd International Symposium on Reliable Distributed Systems."},{"key":"e_1_2_1_158_1","volume-title":"Proceedings of the 2nd Workshop on Evaluating and Architecting System Dependability.","author":"Xu J.","unstructured":"Xu , J. , Kalbarczyk , Z. , Patel , S. , and Ravishankar , K. I . 2002. Architecture support for defending against buffer overflow attacks . In Proceedings of the 2nd Workshop on Evaluating and Architecting System Dependability. Xu, J., Kalbarczyk, Z., Patel, S., and Ravishankar, K. I. 2002. Architecture support for defending against buffer overflow attacks. In Proceedings of the 2nd Workshop on Evaluating and Architecting System Dependability."},{"key":"e_1_2_1_159_1","volume-title":"Proceedings of the 15th USENIX Security Symposium.","author":"Xu W.","unstructured":"Xu , W. , Bhatkar , S. , and Sekar , R . 2006. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks . In Proceedings of the 15th USENIX Security Symposium. Xu, W., Bhatkar, S., and Sekar, R. 2006. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In Proceedings of the 15th USENIX Security Symposium."},{"key":"e_1_2_1_160_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029894.1029913"},{"key":"e_1_2_1_161_1","doi-asserted-by":"publisher","DOI":"10.1145\/940071.940113"},{"key":"e_1_2_1_164_1","doi-asserted-by":"publisher","DOI":"10.1007\/11935308_27"},{"key":"e_1_2_1_165_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.27"},{"key":"e_1_2_1_166_1","doi-asserted-by":"publisher","DOI":"10.4018\/jsse.2010040104"},{"key":"e_1_2_1_167_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755688.1755707"},{"key":"e_1_2_1_168_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653665"},{"key":"e_1_2_1_169_1","volume-title":"Proceedings of the 2nd IEEE International Information Assurance Workshop.","author":"Zhu G.","unstructured":"Zhu , G. and Tyagi , A . 2004. Protection against indirect overflow attacks on pointers . In Proceedings of the 2nd IEEE International Information Assurance Workshop. Zhu, G. and Tyagi, A. 2004. Protection against indirect overflow attacks on pointers. In Proceedings of the 2nd IEEE International Information Assurance Workshop."},{"key":"e_1_2_1_170_1","volume-title":"Proceedings of the 1st International Conference on E-Business and Telecommunication Networks.","author":"Zuquete A.","year":"2004","unstructured":"Zuquete , A. 2004 . Stackfences: A runtime approach for detecting stack overflows . In Proceedings of the 1st International Conference on E-Business and Telecommunication Networks. Zuquete, A. 2004. Stackfences: A runtime approach for detecting stack overflows. In Proceedings of the 1st International Conference on E-Business and Telecommunication Networks."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2187671.2187679","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2187671.2187679","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:06:33Z","timestamp":1750241193000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2187671.2187679"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,6]]},"references-count":168,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,6]]}},"alternative-id":["10.1145\/2187671.2187679"],"URL":"https:\/\/doi.org\/10.1145\/2187671.2187679","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,6]]},"assertion":[{"value":"2006-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2010-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-06-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}