{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:21:20Z","timestamp":1750306880813,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,12,3]],"date-time":"2012-12-03T00:00:00Z","timestamp":1354492800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["905442"],"award-info":[{"award-number":["905442"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,12,3]]},"DOI":"10.1145\/2420950.2420992","type":"proceedings-article","created":{"date-parts":[[2012,12,19]],"date-time":"2012-12-19T14:12:22Z","timestamp":1355926342000},"page":"279-288","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["CodeShield"],"prefix":"10.1145","author":[{"given":"Christopher","family":"Gates","sequence":"first","affiliation":[{"name":"Purdue University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jing","family":"Chen","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert","family":"Proctor","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,12,3]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/1052676.1052683"},{"key":"e_1_3_2_1_2_1","unstructured":"BIT9. Bit9 parity suite: Adaptive application whitelisting. http:\/\/www.bit9.com\/products\/bit9-parity-suite.php.  BIT9. Bit9 parity suite: Adaptive application whitelisting. http:\/\/www.bit9.com\/products\/bit9-parity-suite.php."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280691"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455821"},{"key":"e_1_3_2_1_5_1","unstructured":"M. Corporation. Kernel data and filtering support for vista sp1 \/ windows server 2008. MSDN.  M. Corporation. Kernel data and filtering support for vista sp1 \/ windows server 2008. MSDN ."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/1387649.1387650"},{"key":"e_1_3_2_1_7_1","volume-title":"Conference on Email and Anti-Spam","author":"Erickson D.","year":"2008","unstructured":"D. Erickson , M. Casado , and N. McKeown . The effectiveness of whitelisting: a user-study . In Conference on Email and Anti-Spam , 2008 . D. Erickson, M. Casado, and N. McKeown. The effectiveness of whitelisting: a user-study. In Conference on Email and Anti-Spam, 2008."},{"key":"e_1_3_2_1_8_1","volume-title":"Engineering windows","author":"Fathi B.","year":"2008","unstructured":"B. Fathi . Engineering windows 7, October 2008 . MSDN blog on User Account Control . B. Fathi. Engineering windows 7, October 2008. MSDN blog on User Account Control."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2005.12.004"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046742"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/191177.191183"},{"key":"e_1_3_2_1_12_1","volume-title":"Third quarter","author":"Labs M.","year":"2011","unstructured":"M. Labs . Mcafee threats report : Third quarter 2011 , Nov. 2011. White paper from McAfee . M. Labs. Mcafee threats report: Third quarter 2011, Nov. 2011. White paper from McAfee."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2011.367"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866356"},{"key":"e_1_3_2_1_15_1","unstructured":"McAfee. Application control. http:\/\/www.mcafee.com\/us\/products\/application-control.aspx.  McAfee. Application control. http:\/\/www.mcafee.com\/us\/products\/application-control.aspx."},{"key":"e_1_3_2_1_16_1","unstructured":"Microsoft. Applocker. http:\/\/technet.microsoft.com\/en-us\/library\/dd548340.  Microsoft. Applocker. http:\/\/technet.microsoft.com\/en-us\/library\/dd548340."},{"key":"e_1_3_2_1_17_1","first-page":"73","volume-title":"Proceedings of the 13th USENIX Security Symposium (Security 2004","author":"Miretskiy Y.","year":"2004","unstructured":"Y. Miretskiy , A. Das , C. P. Wright , and E. Zadok . AVFS: An on-access anti-virus file system . In Proceedings of the 13th USENIX Security Symposium (Security 2004 ), pages 73 -- 88 , San Diego, CA , August 2004 . USENIX Association. Y. Miretskiy, A. Das, C. P. Wright, and E. Zadok. AVFS: An on-access anti-virus file system. In Proceedings of the 13th USENIX Security Symposium (Security 2004), pages 73--88, San Diego, CA, August 2004. USENIX Association."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837112"},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of the 17th USENIX Security Symposium","author":"Oberheide J.","year":"2008","unstructured":"J. Oberheide , E. Cooke , and F. Jahanian . CloudAV: N-Version Antivirus in the Network Cloud . In Proceedings of the 17th USENIX Security Symposium , San Jose, CA , July 2008 . J. Oberheide, E. Cooke, and F. Jahanian. CloudAV: N-Version Antivirus in the Network Cloud. In Proceedings of the 17th USENIX Security Symposium, San Jose, CA, July 2008."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866898.1866907"},{"key":"e_1_3_2_1_21_1","first-page":"3","volume-title":"Whitelisting for Endpoint Defense","author":"Shein R.","year":"2011","unstructured":"R. Shein . Chapter 1 : Whitelisting for Endpoint Defense , pages 3 -- 14 . Auerbach Publications , 2011 . R. Shein. Chapter 1: Whitelisting for Endpoint Defense, pages 3--14. Auerbach Publications, 2011."},{"key":"e_1_3_2_1_22_1","volume-title":"Information Security Management Handbook","author":"Shein R.","year":"2011","unstructured":"R. Shein , H. F. Tipton , and M. Krause . Information Security Management Handbook , Sixth Edition, Volume 5 . Auerbach Publications , 2011 . R. Shein, H. F. Tipton, and M. Krause. Information Security Management Handbook, Sixth Edition, Volume 5. Auerbach Publications, 2011."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280692"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2010.187"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753382"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPSD.2008.4562720"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837125"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966987"},{"key":"e_1_3_2_1_29_1","first-page":"1","volume-title":"Proceedings of the 2nd USENIX workshop on Hot topics in security","author":"Wurster G.","year":"2007","unstructured":"G. Wurster and P. C. van Oorschot . Self-signed executables: restricting replacement of program binaries by malware . In Proceedings of the 2nd USENIX workshop on Hot topics in security , pages 8: 1 -- 8 :5, Berkeley, CA, USA , 2007 . USENIX Association. G. Wurster and P. C. van Oorschot. Self-signed executables: restricting replacement of program binaries by malware. In Proceedings of the 2nd USENIX workshop on Hot topics in security, pages 8:1--8:5, Berkeley, CA, USA, 2007. USENIX Association."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1060745.1060817"}],"event":{"name":"ACSAC '12: Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Orlando Florida USA","acronym":"ACSAC '12"},"container-title":["Proceedings of the 28th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420992","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2420950.2420992","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:18:33Z","timestamp":1750234713000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420992"}},"subtitle":["towards personalized application whitelisting"],"short-title":[],"issued":{"date-parts":[[2012,12,3]]},"references-count":30,"alternative-id":["10.1145\/2420950.2420992","10.1145\/2420950"],"URL":"https:\/\/doi.org\/10.1145\/2420950.2420992","relation":{},"subject":[],"published":{"date-parts":[[2012,12,3]]},"assertion":[{"value":"2012-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}