{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T18:29:56Z","timestamp":1780079396748,"version":"3.54.0"},"publisher-location":"New York, NY, USA","reference-count":17,"publisher":"ACM","license":[{"start":{"date-parts":[[2016,10,24]],"date-time":"2016-10-24T00:00:00Z","timestamp":1477267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2016,10,24]]},"DOI":"10.1145\/2976749.2978361","type":"proceedings-article","created":{"date-parts":[[2016,10,25]],"date-time":"2016-10-25T12:46:35Z","timestamp":1477399595000},"page":"779-790","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["An In-Depth Study of More Than Ten Years of Java Exploitation"],"prefix":"10.1145","author":[{"given":"Philipp","family":"Holzinger","sequence":"first","affiliation":[{"name":"Fraunhofer SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stefan","family":"Triller","sequence":"additional","affiliation":[{"name":"Fraunhofer SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alexandre","family":"Bartel","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Darmstadt, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eric","family":"Bodden","sequence":"additional","affiliation":[{"name":"Paderborn University &amp; Fraunhofer IEM, Paderborn, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2016,10,24]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"http:\/\/slightlyrandombrokenthoughts.blogspot.de\/2010\/04\/java-trusted-method-chaining-cve-2010.html. {Online","author":"Java","year":"2016","unstructured":"Java trusted method chaining (cve-2010-0840\/zdi-10-056). http:\/\/slightlyrandombrokenthoughts.blogspot.de\/2010\/04\/java-trusted-method-chaining-cve-2010.html. {Online ; accessed on 22- May - 2016 }. Java trusted method chaining (cve-2010-0840\/zdi-10-056). http:\/\/slightlyrandombrokenthoughts.blogspot.de\/2010\/04\/java-trusted-method-chaining-cve-2010.html. {Online; accessed on 22-May-2016}."},{"key":"e_1_3_2_1_2_1","volume-title":"http:\/\/openjdk.java.net\/projects\/jigsaw\/spec\/sotms\/. {Online","author":"The","year":"2016","unstructured":"The state of the module system. http:\/\/openjdk.java.net\/projects\/jigsaw\/spec\/sotms\/. {Online ; accessed on 22- May - 2016 }. The state of the module system. http:\/\/openjdk.java.net\/projects\/jigsaw\/spec\/sotms\/. {Online; accessed on 22-May-2016}."},{"key":"e_1_3_2_1_3_1","volume-title":"https:\/\/media.blackhat.com\/bh-us-12\/Briefings\/Oh\/BH_US_12_Oh_Recent_Java_Exploitation_Trends_and_Malware_WP.pdf","author":"Recent","year":"2012","unstructured":"Recent java exploitation trends and malware. https:\/\/media.blackhat.com\/bh-us-12\/Briefings\/Oh\/BH_US_12_Oh_Recent_Java_Exploitation_Trends_and_Malware_WP.pdf , 2012 . {Online; accessed on 18-May-2016}. Recent java exploitation trends and malware. https:\/\/media.blackhat.com\/bh-us-12\/Briefings\/Oh\/BH_US_12_Oh_Recent_Java_Exploitation_Trends_and_Malware_WP.pdf, 2012. {Online; accessed on 18-May-2016}."},{"key":"e_1_3_2_1_4_1","volume-title":"Analyzing four widely exploited java vulnerabilities. https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/rpt-java-vulnerabilities.pdf","author":"Brewing","year":"2014","unstructured":"Brewing up trouble : Analyzing four widely exploited java vulnerabilities. https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/rpt-java-vulnerabilities.pdf , 2014 . {Online; accessed on 18-May-2016}. Brewing up trouble: Analyzing four widely exploited java vulnerabilities. https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/rpt-java-vulnerabilities.pdf, 2014. {Online; accessed on 18-May-2016}."},{"key":"e_1_3_2_1_5_1","first-page":"107","volume-title":"NDSS","volume":"3","author":"Abadi Martin","year":"2003","unstructured":"Martin Abadi and C\u00e9dric Fournet . Access control based on execution history . In NDSS , volume 3 , pages 107 -- 121 , 2003 . Martin Abadi and C\u00e9dric Fournet. Access control based on execution history. In NDSS, volume 3, pages 107--121, 2003."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985827"},{"key":"e_1_3_2_1_7_1","volume-title":"http:\/\/seclists.org\/bugtraq\/2016\/Apr\/19","author":"Exploration Security","year":"2016","unstructured":"Security Exploration . {se-2012-01} broken security fix in ibm java 7\/8. http:\/\/seclists.org\/bugtraq\/2016\/Apr\/19 , 2016 . {Online; accessed on 17-May-2016}. Security Exploration. {se-2012-01} broken security fix in ibm java 7\/8. http:\/\/seclists.org\/bugtraq\/2016\/Apr\/19, 2016. {Online; accessed on 17-May-2016}."},{"key":"e_1_3_2_1_8_1","volume-title":"http:\/\/seclists.org\/fulldisclosure\/2016\/Apr\/43","author":"Exploration Security","year":"2016","unstructured":"Security Exploration . {se-2012-01} yet another broken security fix in ibm java 7\/8. http:\/\/seclists.org\/fulldisclosure\/2016\/Apr\/43 , 2016 . {Online; accessed on 17-May-2016}. Security Exploration. {se-2012-01} yet another broken security fix in ibm java 7\/8. http:\/\/seclists.org\/fulldisclosure\/2016\/Apr\/43, 2016. {Online; accessed on 17-May-2016}."},{"key":"e_1_3_2_1_9_1","volume-title":"Pearson Education","author":"Gong Li","year":"2003","unstructured":"Li Gong and Gary Ellison . Inside Java (TM) 2 Platform Security : Architecture, API Design, and Implementation . Pearson Education , 2003 . Li Gong and Gary Ellison. Inside Java (TM) 2 Platform Security: Architecture, API Design, and Implementation. Pearson Education, 2003."},{"key":"e_1_3_2_1_10_1","volume-title":"Java under attack -- the evolution of exploits in 2012--2013. https:\/\/securelist.com\/analysis\/publications\/57888\/kaspersky-lab-report-java-under-attack","author":"Labs Kaspersky","year":"2013","unstructured":"Kaspersky Labs . Java under attack -- the evolution of exploits in 2012--2013. https:\/\/securelist.com\/analysis\/publications\/57888\/kaspersky-lab-report-java-under-attack , 2013 . {Online; accessed on 19-May-2016}. Kaspersky Labs. Java under attack -- the evolution of exploits in 2012--2013. https:\/\/securelist.com\/analysis\/publications\/57888\/kaspersky-lab-report-java-under-attack, 2013. {Online; accessed on 19-May-2016}."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2814270.2814313"},{"key":"e_1_3_2_1_12_1","volume-title":"9th USENIX Workshop on Offensive Technologies (WOOT 15)","author":"Peles Or","year":"2015","unstructured":"Or Peles and Roee Hay . One class to rule them all: 0-day deserialization vulnerabilities in android . In 9th USENIX Workshop on Offensive Technologies (WOOT 15) , 2015 . Or Peles and Roee Hay. One class to rule them all: 0-day deserialization vulnerabilities in android. In 9th USENIX Workshop on Offensive Technologies (WOOT 15), 2015."},{"key":"e_1_3_2_1_13_1","volume-title":"4th","author":"Pfleeger CP","year":"2007","unstructured":"CP Pfleeger and SL Pfleeger . Security in computing . 4th , 2007 . CP Pfleeger and SL Pfleeger. Security in computing. 4th, 2007."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.10"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420988"},{"issue":"12","key":"e_1_3_2_1_16_1","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier Bruce","year":"1999","unstructured":"Bruce Schneier . Attack trees . Dr. Dobb's journal , 24 ( 12 ): 21 -- 29 , 1999 . Bruce Schneier. Attack trees. Dr. Dobb's journal, 24(12):21--29, 1999.","journal-title":"Dr. Dobb's journal"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.877869"}],"event":{"name":"CCS'16: 2016 ACM SIGSAC Conference on Computer and Communications Security","location":"Vienna Austria","acronym":"CCS'16","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2976749.2978361","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2976749.2978361","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:40:14Z","timestamp":1750218014000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2976749.2978361"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,10,24]]},"references-count":17,"alternative-id":["10.1145\/2976749.2978361","10.1145\/2976749"],"URL":"https:\/\/doi.org\/10.1145\/2976749.2978361","relation":{},"subject":[],"published":{"date-parts":[[2016,10,24]]},"assertion":[{"value":"2016-10-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}