{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:41:20Z","timestamp":1755823280068,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,5,13]],"date-time":"2024-05-13T00:00:00Z","timestamp":1715558400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Chinese National Key R&D Program","award":["022YFF0604503"],"award-info":[{"award-number":["022YFF0604503"]}]},{"name":"RIE2020 Industry Alignment Fund"},{"name":"Chinese National Natural Science Foundation","award":["2032010, 62172201"],"award-info":[{"award-number":["2032010, 62172201"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,5,13]]},"DOI":"10.1145\/3589334.3645476","type":"proceedings-article","created":{"date-parts":[[2024,5,8]],"date-time":"2024-05-08T07:08:13Z","timestamp":1715152093000},"page":"1668-1679","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Medusa: Unveil Memory Exhaustion DoS Vulnerabilities in Protocol Implementations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-7032-2681","authenticated-orcid":false,"given":"Zhengjie","family":"Du","sequence":"first","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4382-0757","authenticated-orcid":false,"given":"Yuekang","family":"Li","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8953-0782","authenticated-orcid":false,"given":"Yaowen","family":"Zheng","sequence":"additional","affiliation":[{"name":"Continental-NTU Corporate Lab, Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3260-4530","authenticated-orcid":false,"given":"Xiaohan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5603-1322","authenticated-orcid":false,"given":"Cen","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4978-127X","authenticated-orcid":false,"given":"Yi","family":"Liu","sequence":"additional","affiliation":[{"name":"Continental-NTU Corporate Lab, Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1183-4310","authenticated-orcid":false,"given":"Sheikh Mahbub","family":"Habib","sequence":"additional","affiliation":[{"name":"Continental Automotive Technologies GmbH, Hannover, Frankfurt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5583-4155","authenticated-orcid":false,"given":"Xinghua","family":"Li","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4794-1652","authenticated-orcid":false,"given":"Linzhang","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7066-2144","authenticated-orcid":false,"given":"Bing","family":"Mao","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,5,13]]},"reference":[{"doi-asserted-by":"publisher","key":"e_1_3_2_2_1_1","DOI":"10.1145\/3533767.3534376"},{"key":"e_1_3_2_2_2_1","volume-title":"Medusa: Unveil memory exhaustion dos vulnerabilities in protocol implementations","author":"Anonymous","year":"2023","unstructured":"Anonymous. Medusa: Unveil memory exhaustion dos vulnerabilities in protocol implementations, 2023. URL: https:\/\/sites.google.com\/view\/medusa-dos."},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_3_1","DOI":"10.1016\/j.cose.2021.102352"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_4_1","DOI":"10.1145\/3395363.3402645"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_5_1","DOI":"10.1109\/SP40000.2020.00117"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_6_1","DOI":"10.1109\/ICSE.2019.00083"},{"key":"e_1_3_2_2_7_1","first-page":"3255","volume-title":"31st USENIX Security Symposium (USENIX Security","author":"Ba Jinsheng","year":"2022","unstructured":"Jinsheng Ba, Marcel B\u00f6hme, Zahra Mirzamomen, and Abhik Roychoudhury. Stateful greybox fuzzing. In 31st USENIX Security Symposium (USENIX Security , pages 3255--3272, 2022."},{"unstructured":"Felipe Balabanian. (cve-2017--7651) - mosquitto server shutdown attack 2018. URL: https:\/\/bugs.eclipse.org\/bugs\/show_bug.cgi?id=529754#c0.","key":"e_1_3_2_2_8_1"},{"key":"e_1_3_2_2_9_1","volume-title":"The \/proc filesystem","author":"Bowden Terrehon","year":"2009","unstructured":"Terrehon Bowden, Jorge Nerin, Shen Feng, and Stefani Seibold. The \/proc filesystem, 2009. URL: https:\/\/docs.kernel.org\/filesystems\/proc.html."},{"key":"e_1_3_2_2_10_1","volume-title":"Proceedings of 20th USENIX Security Symposium","author":"Cho Chia Yuan","year":"2011","unstructured":"Chia Yuan Cho, Domagoj Babic, Pongsin Poosankam, Kevin Zhijie Chen, Edward XueJun Wu, and Dawn Song. MACE: Model-inference-assisted concolic exploration for protocol and vulnerability discovery. In Proceedings of 20th USENIX Security Symposium, 2011."},{"key":"e_1_3_2_2_11_1","volume-title":"Peach fuzzer: Smartfuzzer that is capable of performing both generation and mutation based fuzzing","author":"Peach","year":"2023","unstructured":"Peach community. Peach fuzzer: Smartfuzzer that is capable of performing both generation and mutation based fuzzing, 2023. URL: https:\/\/peachtech.gitlab.io\/peach-fuzzer-community\/."},{"key":"e_1_3_2_2_12_1","volume-title":"Common vulnerabilities and exposures","author":"MITRE","year":"2023","unstructured":"MITRE corporation. Common vulnerabilities and exposures, 2023. URL: https:\/\/cve.mitre.org\/."},{"unstructured":"CWE. Common weakness enumeration 2023. URL: https:\/\/cwe.mitre.org\/index.html.","key":"e_1_3_2_2_13_1"},{"volume-title":"Use containers to build, share and run your applications","year":"2023","unstructured":"Docker. Use containers to build, share and run your applications, 2023. URL: https:\/\/www.docker.com\/resources\/what-container.","key":"e_1_3_2_2_14_1"},{"volume-title":"An open source mqtt broker","year":"2023","unstructured":"Eclipse. An open source mqtt broker, 2023. URL: https:\/\/mosquitto.org\/.","key":"e_1_3_2_2_15_1"},{"key":"e_1_3_2_2_16_1","volume-title":"Daniele Cono D'Elia, and Davide Balzarotti1. The use of likely invariants as feedback for fuzzers","author":"Andrea","year":"2021","unstructured":"Andrea Fioraldi1, Daniele Cono D'Elia, and Davide Balzarotti1. The use of likely invariants as feedback for fuzzers. 2021."},{"key":"e_1_3_2_2_17_1","volume-title":"Common vulnerability scoring system version 3.1 calculator","author":"FIRST.","year":"2023","unstructured":"FIRST. Common vulnerability scoring system version 3.1 calculator, 2023. URL: https:\/\/www.first.org\/cvss\/calculator\/3.1#CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H\/RL:O."},{"key":"e_1_3_2_2_18_1","volume-title":"Sulley: A pure-python fully automated and unattended fuzzing framework","author":"Fortra LLC","year":"2023","unstructured":"LLC Fortra. Sulley: A pure-python fully automated and unattended fuzzing framework., 2023. URL: https:\/\/github.com\/OpenRCE\/sulley."},{"volume-title":"psutil","year":"2023","unstructured":"giampaolo. psutil, 2023. URL: https:\/\/github.com\/giampaolo\/psutil.","key":"e_1_3_2_2_19_1"},{"doi-asserted-by":"crossref","unstructured":"Serkan G\u00f6nen Mehmet Ali Bariskan G\u00f6k\u00e7e Karacayilmaz Birkan Alhan Ercan Nurcan Yilmaz Harun Artuner and Erhan Sindiren. A novel approach to prevention of hello flood attack in iot usingmachine learning algorithm. El-Cezeri Fen ve M\u00fchendislik Dergisi 2022.","key":"e_1_3_2_2_20_1","DOI":"10.31202\/ecjse.1149925"},{"key":"e_1_3_2_2_21_1","volume-title":"Overview of the linux virtual file system","author":"Gooch Richard","year":"2005","unstructured":"Richard Gooch. Overview of the linux virtual file system, 2005. URL: https:\/\/www.kernel.org\/doc\/html\/latest\/filesystems\/vfs.html."},{"unstructured":"Graphviz. Graphviz 2021. URL: https:\/\/graphviz.org\/.","key":"e_1_3_2_2_22_1"},{"volume-title":"Graphviz online","year":"2023","unstructured":"Graphviz. Graphviz online, 2023. URL: https:\/\/dreampuf.github.io\/ GraphvizOnline\/.","key":"e_1_3_2_2_23_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_24_1","DOI":"10.9734\/ajrcos\/2021\/v9i230218"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_25_1","DOI":"10.1145\/863955.863968"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_26_1","DOI":"10.1007\/978-0-387-35413-2_16"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_27_1","DOI":"10.1109\/ISCC.2010.5546704"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_28_1","DOI":"10.1145\/3243734.3243804"},{"volume-title":"American fuzzy lop (afl) fuzzer","year":"2023","unstructured":"lcamtuf. American fuzzy lop (afl) fuzzer, 2023. URL: https:\/\/lcamtuf.coredump.cx\/afl\/.","key":"e_1_3_2_2_29_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_30_1","DOI":"10.24086\/cuesj.v6n2y2022.pp49-56"},{"key":"e_1_3_2_2_31_1","volume-title":"The mann-whitney u: A test for assessing whether two independent samples come from the same distribution. Tutorials in quantitative Methods for Psychology, 4(1):13--20","author":"Nadim Nachar","year":"2008","unstructured":"Nadim Nachar et al. The mann-whitney u: A test for assessing whether two independent samples come from the same distribution. Tutorials in quantitative Methods for Psychology, 4(1):13--20, 2008."},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_32_1","DOI":"10.1145\/3460319.3469077"},{"volume-title":"Cypher query language","year":"2021","unstructured":"neo4j. Cypher query language, 2021. URL: https:\/\/neo4j.com\/developer\/cypher\/.","key":"e_1_3_2_2_33_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_34_1","DOI":"10.1109\/SP.2018.00056"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_35_1","DOI":"10.1145\/1216370.1216373"},{"key":"e_1_3_2_2_36_1","volume-title":"Boofuzz: A fork and successor of the sulley fuzzing framework","author":"Pereyda Joshua","year":"2023","unstructured":"Joshua Pereyda. Boofuzz: A fork and successor of the sulley fuzzing framework, 2023. URL: https:\/\/github.com\/jtpereyda\/boofuzz."},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_37_1","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"e_1_3_2_2_38_1","volume-title":"Addresssanitizer: A fast address sanity checker","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitry Vyukov. Addresssanitizer: A fast address sanity checker. 2012."},{"issue":"482","key":"e_1_3_2_2_39_1","first-page":"503","article-title":"Denial of service attack detection through machine learning for the iot","volume":"4","author":"Syed Naeem Firdous","year":"2020","unstructured":"Naeem Firdous Syed, Zubair A. Baig, Ahmed Ibrahim, and Craig Valli. Denial of service attack detection through machine learning for the iot. Journal of Information and Telecommunication, 4:482 -- 503, 2020.","journal-title":"Journal of Information and Telecommunication"},{"key":"e_1_3_2_2_40_1","volume-title":"Defensics fuzz testing: Identify defects and zero-day vulnerabilities in services and protocols","author":"Inc. Synopsys.","year":"2023","unstructured":"Inc. Synopsys. Defensics fuzz testing: Identify defects and zero-day vulnerabilities in services and protocols, 2023. URL: https:\/\/www.synopsys.com\/softwareintegrity\/ security-testing\/fuzz-testing.html."},{"issue":"2","key":"e_1_3_2_2_41_1","first-page":"101","article-title":"A critique and improvement of the cl common language effect size statistics of mcgraw and wong","volume":"25","author":"Vargha Andr\u00e1s","year":"2000","unstructured":"Andr\u00e1s Vargha and Harold D. Delaney. A critique and improvement of the cl common language effect size statistics of mcgraw and wong. Journal of Educational and Behavioral Statistics, 25(2):101--132, 2000.","journal-title":"Journal of Educational and Behavioral Statistics"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_42_1","DOI":"10.1145\/3377811.3380396"},{"volume-title":"Denial-of-service attack","year":"2023","unstructured":"Wikipedia. Denial-of-service attack, 2023. URL: https:\/\/en.wikipedia.org\/wiki\/ Denial-of-service_attack.","key":"e_1_3_2_2_43_1"},{"volume-title":"Breadth-first search","year":"2023","unstructured":"Wikipeia. Breadth-first search, 2023. URL: https:\/\/en.wikipedia.org\/wiki\/Breadthfirst_search.","key":"e_1_3_2_2_44_1"},{"volume-title":"Java virtual machine","year":"2023","unstructured":"Wikipeia. Java virtual machine, 2023. URL: https:\/\/en.wikipedia.org\/wiki\/Java_virtual_machine.","key":"e_1_3_2_2_45_1"},{"unstructured":"Wikipeia. Node.js v19.5.0 documentation 2023. URL: https:\/\/nodejs.org\/api\/vm.html.","key":"e_1_3_2_2_46_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_2_47_1","DOI":"10.1109\/ACCESS.2020.2976609"}],"event":{"sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"],"acronym":"WWW '24","name":"WWW '24: The ACM Web Conference 2024","location":"Singapore Singapore"},"container-title":["Proceedings of the ACM Web Conference 2024"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3645476","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3589334.3645476","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:23:03Z","timestamp":1755822183000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3645476"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,13]]},"references-count":47,"alternative-id":["10.1145\/3589334.3645476","10.1145\/3589334"],"URL":"https:\/\/doi.org\/10.1145\/3589334.3645476","relation":{},"subject":[],"published":{"date-parts":[[2024,5,13]]},"assertion":[{"value":"2024-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}