{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T14:06:29Z","timestamp":1773669989226,"version":"3.50.1"},"reference-count":40,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2012,7,1]],"date-time":"2012-07-01T00:00:00Z","timestamp":1341100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2012,7]]},"abstract":"<jats:p>Layout randomization is a powerful, popular technique for software protection. We present it and study it in programming-language terms. More specifically, we consider layout randomization as part of an implementation for a high-level programming language; the implementation translates this language to a lower-level language in which memory addresses are numbers. We analyze this implementation, by relating low-level attacks against the implementation to contexts in the high-level programming language, and by establishing full abstraction results.<\/jats:p>","DOI":"10.1145\/2240276.2240279","type":"journal-article","created":{"date-parts":[[2012,8,1]],"date-time":"2012-08-01T17:35:16Z","timestamp":1343842516000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":36,"title":["On Protection by Layout Randomization"],"prefix":"10.1145","volume":"15","author":[{"given":"Mart\u00edn","family":"Abadi","sequence":"first","affiliation":[{"name":"Microsoft Research, Silicon Valley"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gordon D.","family":"Plotkin","sequence":"additional","affiliation":[{"name":"Microsoft Research, Silicon Valley"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,7]]},"reference":[{"key":"e_1_2_2_1_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the 25th International Colloquium on Automata, Languages and Programming","author":"Abadi M.","unstructured":"Abadi , M. 1998. Protection in programming-language translations . In Proceedings of the 25th International Colloquium on Automata, Languages and Programming . Lecture Notes in Computer Science , vol. 1443 . Springer , 868--883. Abadi, M. 1998. Protection in programming-language translations. In Proceedings of the 25th International Colloquium on Automata, Languages and Programming. Lecture Notes in Computer Science, vol. 1443. Springer, 868--883."},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/324133.324266"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-007-0203-0"},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_2_2_5_1","first-page":"59","article-title":"Bypassing PaX ASLR protection","volume":"11","author":"Anonymous","year":"2002","unstructured":"Anonymous . 2002 . Bypassing PaX ASLR protection . Phrack 11 , 59 . Anonymous. 2002. Bypassing PaX ASLR protection. Phrack 11, 59.","journal-title":"Phrack"},{"key":"e_1_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653672"},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1053283.1053286"},{"key":"e_1_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cl.2005.05.002"},{"key":"e_1_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133981.1134000"},{"key":"e_1_2_2_10_1","volume-title":"Proceedings of the 12th USENIX Security Symposium.","author":"Bhatkar S.","unstructured":"Bhatkar , S. , DuVarney , D. C. , and Sekar , R . 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits . In Proceedings of the 12th USENIX Security Symposium. Bhatkar, S., DuVarney, D. C., and Sekar, R. 2003. Address obfuscation: An efficient approach to combat a broad range of memory error exploits. In Proceedings of the 12th USENIX Security Symposium."},{"key":"e_1_2_2_11_1","volume-title":"Proceedings of the 14th USENIX Security Symposium.","author":"Bhatkar S.","year":"2005","unstructured":"Bhatkar , S. , Sekar , R. , and DuVarney , D. C. 2005 . Efficient techniques for comprehensive protection from memory error exploits . In Proceedings of the 14th USENIX Security Symposium. Bhatkar, S., Sekar, R., and DuVarney, D. C. 2005. Efficient techniques for comprehensive protection from memory error exploits. In Proceedings of the 14th USENIX Security Symposium."},{"key":"e_1_2_2_12_1","volume-title":"Proceedings of the Usenix Security Symposium. 177--192","author":"Chen S.","unstructured":"Chen , S. , Jun Xu , E. C. S. , Gauriar , P. , and Iyer , R. K . 2005. Non-control-data attacks are realistic threats . In Proceedings of the Usenix Security Symposium. 177--192 . Chen, S., Jun Xu, E. C. S., Gauriar, P., and Iyer, R. K. 2005. Non-control-data attacks are realistic threats. In Proceedings of the Usenix Security Symposium. 177--192."},{"key":"e_1_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455786"},{"key":"e_1_2_2_14_1","volume-title":"Cryptography and Data Security","author":"Denning D. E.","unstructured":"Denning , D. E. 1982. Cryptography and Data Security . Addison-Wesley , Reading, Mass . Denning, D. E. 1982. Cryptography and Data Security. Addison-Wesley, Reading, Mass."},{"key":"e_1_2_2_15_1","unstructured":"Druschel P. and Peterson L. L. 1992. High-performance cross-domain data transfer. Tech. rep. TR 92-11 Department of Computer Science The University of Arizona. Druschel P. and Peterson L. L. 1992. High-performance cross-domain data transfer. Tech. rep. TR 92-11 Department of Computer Science The University of Arizona."},{"key":"e_1_2_2_16_1","volume-title":"Proceedings of the Foundations of Security Analysis and Design IV, FOSAD 2006\/2007 Tutorial Lectures","author":"Erlingsson","unstructured":"Erlingsson , \u00da. 2007. Low-level software security: Attacks and defenses . In Proceedings of the Foundations of Security Analysis and Design IV, FOSAD 2006\/2007 Tutorial Lectures , A. Aldini and R. Gorrieri Eds., Lecture Notes in Computer Science, vol. 4677 . Springer , 92--134. Erlingsson, \u00da. 2007. Low-level software security: Attacks and defenses. In Proceedings of the Foundations of Security Analysis and Design IV, FOSAD 2006\/2007 Tutorial Lectures, A. Aldini and R. Gorrieri Eds., Lecture Notes in Computer Science, vol. 4677. Springer, 92--134."},{"key":"e_1_2_2_17_1","volume-title":"Proceedings of the 3rd Working Conference on the Formal Description of Programming Concepts. 193--219","author":"Felleisen M.","unstructured":"Felleisen , M. and Friedman , D. P . 1986. Control operators, the secd-machine, and the lambda-calculus . In Proceedings of the 3rd Working Conference on the Formal Description of Programming Concepts. 193--219 . Felleisen, M. and Friedman, D. P. 1986. Control operators, the secd-machine, and the lambda-calculus. In Proceedings of the 3rd Working Conference on the Formal Description of Programming Concepts. 193--219."},{"key":"e_1_2_2_18_1","volume-title":"Proceedings of the 6th Workshop on Hot Topics in Operating Systems. 67--72","author":"Forrest S.","unstructured":"Forrest , S. , Somayaji , A. , and Ackley , D. H . 1997. Building diverse computer systems . In Proceedings of the 6th Workshop on Hot Topics in Operating Systems. 67--72 . Forrest, S., Somayaji, A., and Ackley, D. H. 1997. Building diverse computer systems. In Proceedings of the 6th Workshop on Hot Topics in Operating Systems. 67--72."},{"key":"e_1_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1328438.1328478"},{"key":"e_1_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653715"},{"key":"e_1_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1020895213317"},{"key":"e_1_2_2_22_1","unstructured":"Howard M. and Thomlinson M. 2007. Windows Vista ISV security. http:\/\/msdn2.microsoft.com\/en-us\/library\/bb430720.aspx. Howard M. and Thomlinson M. 2007. Windows Vista ISV security. http:\/\/msdn2.microsoft.com\/en-us\/library\/bb430720.aspx."},{"key":"e_1_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"e_1_2_2_24_1","volume-title":"Proceedings of the 11th USENIX Security Symposium. 191--206","author":"Kiriansky V.","unstructured":"Kiriansky , V. , Bruening , D. , and Amarasinghe , S . 2002. Secure execution via program shepherding . In Proceedings of the 11th USENIX Security Symposium. 191--206 . Kiriansky, V., Bruening, D., and Amarasinghe, S. 2002. Secure execution via program shepherding. In Proceedings of the 11th USENIX Security Symposium. 191--206."},{"key":"e_1_2_2_26_1","volume-title":"Foundations for Programming Languages","author":"Mitchell J.","unstructured":"Mitchell , J. 1996. Foundations for Programming Languages . MIT Press . Mitchell, J. 1996. Foundations for Programming Languages. MIT Press."},{"key":"e_1_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/77350.77353"},{"key":"e_1_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/0890-5401(91)90052-4"},{"key":"e_1_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/361932.361937"},{"key":"e_1_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/319301.319345"},{"key":"e_1_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866371"},{"key":"e_1_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1409360.1409382"},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352592.1352616"},{"key":"e_1_2_2_34_1","unstructured":"PaX Project. 2004. The PaX project. http:\/\/pax.grsecurity.net\/. PaX Project . 2004. The PaX project. http:\/\/pax.grsecurity.net\/."},{"key":"e_1_2_2_35_1","volume-title":"Types and Programming Languages","author":"Pierce B.","unstructured":"Pierce , B. 2002. Types and Programming Languages . MIT Press . Pierce, B. 2002. Types and Programming Languages. MIT Press."},{"key":"e_1_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2006.15"},{"key":"e_1_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_2_2_38_1","unstructured":"Sotirov A. and Dowd M. 2008. Bypassing browser memory protections: Setting back browser security by 10 years. http:\/\/taossa.com\/archive\/bh08sotirovdowd.pdf. Sotirov A. and Dowd M. 2008. Bypassing browser memory protections: Setting back browser security by 10 years. http:\/\/taossa.com\/archive\/bh08sotirovdowd.pdf."},{"key":"e_1_2_2_39_1","volume-title":"Proceedings of the 14th USENIX Security Symposium. 145--160","author":"Sovarel A. N.","unstructured":"Sovarel , A. N. , Evans , D. , and Paul , N . 2005. Where\u2019s the FEEB? the effectiveness of instruction set randomization . In Proceedings of the 14th USENIX Security Symposium. 145--160 . Sovarel, A. N., Evans, D., and Paul, N. 2005. Where\u2019s the FEEB? the effectiveness of instruction set randomization. In Proceedings of the 14th USENIX Security Symposium. 145--160."},{"key":"e_1_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.5555\/353629.353648"},{"key":"e_1_2_2_41_1","volume-title":"Proceedings of the USENIX Summer Technical Conference. 175--186","author":"Yarvin C.","unstructured":"Yarvin , C. , Bukowski , R. , and Anderson , T . 1993. Anonymous RPC: Low-latency protection in a 64-bit address space . In Proceedings of the USENIX Summer Technical Conference. 175--186 . Yarvin, C., Bukowski, R., and Anderson, T. 1993. Anonymous RPC: Low-latency protection in a 64-bit address space. In Proceedings of the USENIX Summer Technical Conference. 175--186."}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2240276.2240279","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2240276.2240279","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:20:52Z","timestamp":1750238452000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2240276.2240279"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,7]]},"references-count":40,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,7]]}},"alternative-id":["10.1145\/2240276.2240279"],"URL":"https:\/\/doi.org\/10.1145\/2240276.2240279","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,7]]},"assertion":[{"value":"2010-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}