{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T16:05:37Z","timestamp":1787069137494,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,6]],"date-time":"2022-12-06T00:00:00Z","timestamp":1670284800000},"content-version":"vor","delay-in-days":365,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF2110032"],"award-info":[{"award-number":["W911NF2110032"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-21-1-2171"],"award-info":[{"award-number":["N00014-21-1-2171"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Office of Naval Research","award":["N00014-19-1-2371"],"award-info":[{"award-number":["N00014-19-1-2371"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485918","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"675-689","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["SODA: A System for Cyber Deception Orchestration and Automation"],"prefix":"10.1145","author":[{"given":"Md Sajidul Islam","family":"Sajid","sequence":"first","affiliation":[{"name":"University of North Carolina at Charlotte, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinpeng","family":"Wei","sequence":"additional","affiliation":[{"name":"University of North Carolina at Charlotte, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Basel","family":"Abdeen","sequence":"additional","affiliation":[{"name":"University of Texas at Dallas, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ehab","family":"Al-Shaer","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Md Mazharul","family":"Islam","sequence":"additional","affiliation":[{"name":"University of North Carolina at Charlotte, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Walter","family":"Diong","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Latifur","family":"Khan","sequence":"additional","affiliation":[{"name":"University of Texas at Dallas, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Online. Any.run. https:\/\/any.run\/"},{"key":"e_1_3_2_1_2_1","unstructured":"Onlinea. Cuckoo Monitor. https:\/\/github.com\/cuckoosandbox\/monitor"},{"key":"e_1_3_2_1_3_1","unstructured":"Onlineb. Cuckoo Sandbox. https:\/\/cuckoosandbox.org\/"},{"key":"e_1_3_2_1_4_1","unstructured":"Online. Dissecting the Windows Defender Driver - WdFilter (Part 1). https:\/\/www.n4r1b.com\/posts\/2020\/01\/dissecting-the-windows-defender-driver-wdfilter-part-1\/"},{"key":"e_1_3_2_1_5_1","unstructured":"Online. EasyHook - The reinvention of Windows API Hooking. https:\/\/github.com\/EasyHook\/EasyHook"},{"key":"e_1_3_2_1_6_1","unstructured":"Onlinea. Keylogger-Screen-Capture. https:\/\/github.com\/ajayrandhawa\/Keylogger-Screen-Capture"},{"key":"e_1_3_2_1_7_1","unstructured":"Onlineb. Malshare is a free Malware repository providing researchers access to samples malicious feeds and Yara results.https:\/\/malshare.com\/"},{"key":"e_1_3_2_1_8_1","unstructured":"Online. VirusTotal Public vs Premium API. https:\/\/developers.virustotal.com\/v3.0\/reference#public-vs-premium-api"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41284-4_12"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-017-0361-5"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Mitsuaki Akiyama Takeshi Yagi Takeshi Yada Tatsuya Mori and Youki Kadobayashi. 2017. Analyzing the ecosystem of malicious URL redirection through longitudinal observation from honeypots. computers & security 69(2017) 155\u2013173.","DOI":"10.1016\/j.cose.2017.01.003"},{"key":"e_1_3_2_1_12_1","volume-title":"Toward Network Configuration Randomization for Moving Target Defense","author":"Al-Shaer Ehab","unstructured":"Ehab Al-Shaer. 2011. Toward Network Configuration Randomization for Moving Target Defense. Springer New York, 153\u2013159."},{"key":"e_1_3_2_1_13_1","volume-title":"Autonomous Cyber Deception","author":"Al-Shaer Ehab","unstructured":"Ehab Al-Shaer, Jinpeng Wei, W Kevin, and Cliff Wang. 2019. Autonomous Cyber Deception. Springer."},{"key":"e_1_3_2_1_14_1","volume-title":"Forecasting Malware Capabilities From Cyber Attack Memory Images. In 30th USENIX Security Symposium.","author":"Alrawi Omar","year":"2021","unstructured":"Omar Alrawi, Moses Ike, Matthew Pruett, Ranjita\u00a0Pai Kasturi, Srimanta Barua, Taleb Hirani, Brennan Hill, and Brendan Saltaformaggio. 2021. Forecasting Malware Capabilities From Cyber Attack Memory Images. In 30th USENIX Security Symposium."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3289239.3289244"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664285"},{"key":"e_1_3_2_1_17_1","unstructured":"Kostas\u00a0G Anagnostakis Stelios Sidiroglou Periklis Akritidis Konstantinos Xinidis Evangelos Markatos and Angelos\u00a0D Keromytis. 2005. Detecting targeted attacks using shadow honeypots. (2005)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660329"},{"key":"e_1_3_2_1_19_1","volume-title":"O\u2019Reilly Media","author":"Bird Steven","unstructured":"Steven Bird, Ewan Klein, and Edward Loper. 2009. Natural language processing with Python: analyzing text with the natural language toolkit. \u201d O\u2019Reilly Media, Inc.\u201d."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15512-3_7"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5815\/ijcnis.2012.10.07"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994475.2994481"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2018.8433196"},{"key":"e_1_3_2_1_24_1","volume-title":"30th {USENIX} Security Symposium ({USENIX} Security 21).","author":"Ferguson-Walter J","unstructured":"Kimberly\u00a0J Ferguson-Walter, Maxine\u00a0M Major, Chelsea\u00a0K Johnson, and Daniel\u00a0H Muhleman. 2021. Examining the Efficacy of Decoy-based and Psychological Cyber Deception. In 30th {USENIX} Security Symposium ({USENIX} Security 21)."},{"key":"e_1_3_2_1_25_1","unstructured":"Ziya\u00a0Alper Gen\u00e7 Gabriele Lenzini and Daniele Sgandurra. 2019. On Deception-Based Protection Against Cryptographic Ransomware. In DIMVA."},{"key":"e_1_3_2_1_26_1","volume-title":"Active deception framework: an extensible development environment for adaptive cyber deception. In 2020 IEEE Secure Development (SecDev)","author":"Islam Md\u00a0Mazharul","unstructured":"Md\u00a0Mazharul Islam and Ehab Al-Shaer. 2020. Active deception framework: an extensible development environment for adaptive cyber deception. In 2020 IEEE Secure Development (SecDev). IEEE, 41\u201348."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338468.3356830"},{"key":"e_1_3_2_1_28_1","volume-title":"CHIMERA: Autonomous Planning and Orchestration for Malware Deception. In 2021 IEEE Conference on Communications and Network Security (CNS). IEEE.","author":"Islam Md\u00a0Mazharul","year":"2021","unstructured":"Md\u00a0Mazharul Islam, Ashutosh Dutta, Md\u00a0Sajidul\u00a0Islam Sajid, Ehab Al-Shaer, Jinpeng Wei, and Sadegh Farhang. 2021. CHIMERA: Autonomous Planning and Orchestration for Malware Deception. In 2021 IEEE Conference on Communications and Network Security (CNS). IEEE."},{"key":"e_1_3_2_1_29_1","volume-title":"Moving Target Defense II: Application of Game Theory and Adversarial Modeling","author":"Jajodia Sushil","unstructured":"Sushil Jajodia, Anup\u00a0K. Ghosh, V.\u00a0S. Subrahmanian, Vipin Swarup, Cliff Wang, and X.\u00a0Sean Wang. 2012. Moving Target Defense II: Application of Game Theory and Adversarial Modeling. Springer."},{"key":"e_1_3_2_1_30_1","volume-title":"Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats","author":"Jajodia Sushil","unstructured":"Sushil Jajodia, Anup\u00a0K. Ghosh, Vipin Swarup, Cliff Wang, and X.\u00a0Sean Wang. 2011. Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats (1st ed.). Springer Publishing Company, Incorporated.","edition":"1"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCSIT.2010.5565196"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076790"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/1855768.1855790"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26362-5_28"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2017.8228653"},{"key":"e_1_3_2_1_36_1","unstructured":"Tomas Mikolov Kai Chen Greg Corrado and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space. arXiv preprint arXiv:1301.3781(2013)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCC.2016.14"},{"key":"e_1_3_2_1_38_1","volume-title":"HoneyBug: Personalized Cyber Deception for Web Applications. In 53rd Hawaii International Conference on System Sciences, HICSS 2020","author":"Niakanlahiji Amirreza","year":"2020","unstructured":"Amirreza Niakanlahiji, Jafar\u00a0Haadi Jafarian, Bei-Tseng Chu, and Ehab Al-Shaer. 2020. HoneyBug: Personalized Cyber Deception for Web Applications. In 53rd Hawaii International Conference on System Sciences, HICSS 2020, Maui, Hawaii, USA, January 7-10, 2020. ScholarSpace, 1\u201310. http:\/\/hdl.handle.net\/10125\/63972"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37228-6_20"},{"key":"e_1_3_2_1_40_1","unstructured":"popescuadi. 2017. Ransomware - Simple C++ ransomware prove the concept.https:\/\/github.com\/popescuadi\/Ransomware."},{"key":"e_1_3_2_1_41_1","volume-title":"USENIX Security Symposium, Vol.\u00a0173","author":"Provos Niels","year":"2004","unstructured":"Niels Provos 2004. A Virtual Honeypot Framework.. In USENIX Security Symposium, Vol.\u00a0173. 1\u201314."},{"key":"e_1_3_2_1_42_1","unstructured":"Niels Provos and Thorsten Holz. 2007. Virtual honeypots: from botnet tracking to intrusion detection. Pearson Education."},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the 14th IEEE International Conference on Malicious and Unwanted Software.","author":"Rrushi J","year":"2019","unstructured":"J Rrushi. 2019. Honeypot evader: Activity-guided propagation versus counter-evasion via decoy os activity. In Proceedings of the 14th IEEE International Conference on Malicious and Unwanted Software."},{"key":"e_1_3_2_1_44_1","volume-title":"DodgeTron: Towards Autonomous Cyber Deception Using Dynamic Hybrid Analysis of Malware. In 2020 IEEE Conference on Communications and Network Security (CNS). IEEE, 1\u20139.","author":"Sajid Sajidul\u00a0Islam","year":"2020","unstructured":"Md\u00a0Sajidul\u00a0Islam Sajid, Jinpeng Wei, Md\u00a0Rabbi Alam, Ehsan Aghaei, and Ehab Al-Shaer. 2020. DodgeTron: Towards Autonomous Cyber Deception Using Dynamic Hybrid Analysis of Malware. In 2020 IEEE Conference on Communications and Network Security (CNS). IEEE, 1\u20139."},{"key":"e_1_3_2_1_45_1","volume-title":"12th {USENIX} Workshop on Offensive Technologies ({WOOT} 18).","author":"Vetterl Alexander","unstructured":"Alexander Vetterl and Richard Clayton. 2018. Bitter harvest: Systematically fingerprinting low-and medium-interaction honeypots at internet scale. In 12th {USENIX} Workshop on Offensive Technologies ({WOOT} 18)."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/IAW.2004.1437806"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00027"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Mikhail Zolotukhin and Timo H\u00e4m\u00e4l\u00e4inen. 2014. Detection of zero-day malware based on the analysis of opcode sequences. In CCNC.","DOI":"10.1109\/CCNC.2014.6866599"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485918","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485918","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485918","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:16:37Z","timestamp":1755890197000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485918"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":48,"alternative-id":["10.1145\/3485832.3485918","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485918","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}