{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,29]],"date-time":"2025-08-29T16:40:02Z","timestamp":1756485602376,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,5]],"date-time":"2024-06-05T00:00:00Z","timestamp":1717545600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,5]]},"DOI":"10.1145\/3655693.3655705","type":"proceedings-article","created":{"date-parts":[[2024,6,4]],"date-time":"2024-06-04T18:22:10Z","timestamp":1717525330000},"page":"90-94","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Attack Surface Measurement: A Weird Machines Perspective"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4972-9770","authenticated-orcid":false,"given":"Matthew","family":"Levy","sequence":"first","affiliation":[{"name":"Naval Information Warfare Center Pacific, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-3690-2651","authenticated-orcid":false,"given":"Froylan","family":"Maldonado","sequence":"additional","affiliation":[{"name":"Naval Information Warfare Center Pacific, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,6,5]]},"reference":[{"volume-title":"Modeling and Design of Secure Internet of Things","author":"Anantharaman Prashant","key":"e_1_3_2_1_1_1","unstructured":"Prashant Anantharaman, J\u00a0Peter Brady, Ira\u00a0Ray Jenkins, Vijay\u00a0H Kothari, Michael\u00a0C Millian, Kartik Palani, Kirti\u00a0V Rathore, Jason Reeves, Rebecca Shapiro, Syed\u00a0H Tanveer, 2020. Intent as a secure design primitive. In Modeling and Design of Secure Internet of Things, First Edition, Charles\u00a0A. Kamhoua, Laurent\u00a0L. Njilla, Alexander Kott, and Sachin Shetty (Eds.). John Wiley and Sons, Inc., New York, NY, Chapter\u00a010, 528\u2013562."},{"key":"e_1_3_2_1_2_1","volume-title":"LANGSEC: Language-theoretic Security. https:\/\/www.cs.dartmouth.edu\/\u00a0sergey\/langsec\/. Accessed: 2024-01-10.","author":"Bratus Sergey","year":"2015","unstructured":"Sergey Bratus. 2015. LANGSEC: Language-theoretic Security. https:\/\/www.cs.dartmouth.edu\/\u00a0sergey\/langsec\/. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_3_1","volume-title":"\u201cweird machines","author":"Bratus Sergey","year":"2011","unstructured":"Sergey Bratus, ME Locasto, and ML Patterson. 2011. Exploit programming: From buffer overflows to \u201cweird machines\u201d and theory of computation. SECURITY ;login 36 (2011), 1\u20139. Issue 6."},{"key":"e_1_3_2_1_4_1","volume-title":"Exploitation as code reuse: On the need of formalization. it-Information Technology 59, 2","author":"Bratus Sergey","year":"2017","unstructured":"Sergey Bratus and Anna Shubina. 2017. Exploitation as code reuse: On the need of formalization. it-Information Technology 59, 2 (2017), 93\u2013100."},{"key":"e_1_3_2_1_5_1","unstructured":"MITRE Corporation. 2014. Common Weakness Scoring System (CWSS\u2122). https:\/\/cwe.mitre.org\/cwss\/cwss_v1.0.1.html. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2017.2785299"},{"key":"e_1_3_2_1_7_1","unstructured":"Ahmed\u00a0(0xRick) Hesham. 2019. Buffer Overflow Examples Code execution by shellcode injection - protostar stack5. https:\/\/0xrick.github.io\/binary-exploitation\/bof5\/. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_8_1","unstructured":"Michael Howard. 2003. Fending Off Future Attacks by Reducing Attack Surface. https:\/\/learn.microsoft.com\/en-us\/previous-versions\/ms972812(v=msdn.10)?redirectedfrom=MSDN. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_9_1","unstructured":"Michael Howard Jon Pincus and Jeannette\u00a0M Wing. 2005. Measuring relative attack surfaces. Technical Report. Carnegie Mellon University."},{"key":"e_1_3_2_1_10_1","unstructured":"Inc. IBM\u00a0Systems. 2014. What is an attack surface?https:\/\/www.ibm.com\/topics\/attack-surface. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_11_1","unstructured":"7\u00a0Pernicious Kingdoms. 2006. CWE-242: Use of Inherently Dangerous Function. https:\/\/cwe.mitre.org\/data\/definitions\/242.html. Accessed: 2024-01-10."},{"volume-title":"NDSS","author":"Kurmus Anil","key":"e_1_3_2_1_12_1","unstructured":"Anil Kurmus, Reinhard Tartler, Daniela Dorneanu, Bernhard Heinloth, Valentin Rothberg, Andreas Ruprecht, Wolfgang Schr\u00f6der-Preikschat, Daniel Lohmann, and R\u00fcdiger Kapitza. 2013. Attack Surface Metrics and Automated Compile-Time OS Kernel Tailoring.. In NDSS. NDSS, San Diego, CA, 1\u201318."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833683"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179494.1179497"},{"volume-title":"Measuring a system\u2019s attack surface. School of Computer Science","author":"Manadhata Pratyusa","key":"e_1_3_2_1_15_1","unstructured":"Pratyusa Manadhata and Jeannette\u00a0Marie Wing. 2004. Measuring a system\u2019s attack surface. School of Computer Science, Carnegie Mellon University, Pittsburgh, PA, USA."},{"volume-title":"Moving target defense II: Application of game theory and adversarial modeling","author":"Manadhata K","key":"e_1_3_2_1_16_1","unstructured":"Pratyusa\u00a0K Manadhata. 2012. Game theoretic approaches to attack surface shifting. In Moving target defense II: Application of game theory and adversarial modeling. Springer, New York, NY, 1\u201313."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Pratyusa\u00a0K Manadhata Kymie\u00a0MC Tan Roy\u00a0A Maxion and Jeannette\u00a0M Wing. 2007. An approach to measuring a system\u2019s attack surface. Technical Report. Carnegie Mellon University.","DOI":"10.21236\/ADA476977"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"volume-title":"Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats","author":"Manadhata K","key":"e_1_3_2_1_19_1","unstructured":"Pratyusa\u00a0K Manadhata and Jeannette\u00a0M Wing. 2011. A formal model for a system\u2019s attack surface. In Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats. Springer, New York, NY, 1\u201328."},{"key":"e_1_3_2_1_20_1","unstructured":"William Martin. 2023. Show Us the Proof: Formal Methods Can Be Applied at Large Scale. https:\/\/www.darpa.mil\/news-events\/2023-03-27. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1976.233837"},{"volume-title":"An introduction to formal language theory","author":"Moll N","key":"e_1_3_2_1_22_1","unstructured":"Robert\u00a0N Moll, Michael\u00a0A Arbib, and Assaf\u00a0J Kfoury. 2012. An introduction to formal language theory. Springer Science & Business Media, New York, NY."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510210"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2995306.2995311"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"National\u00a0Institute of Standards and Technology. 2020. Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Technical Report NIST Special Publication 800-171 Revision 2. U.S. Department of Commerce Washington D.C.https:\/\/doi.org\/10.6028\/NIST.SP.800-171r2","DOI":"10.6028\/NIST.SP.800-171r2"},{"key":"e_1_3_2_1_26_1","unstructured":"Meredith Patterson and Sergey Bratus. 2011. The Science of Insecurity. https:\/\/www.youtube.com\/watch?v=3kEfedtQVOY. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_27_1","volume-title":"Weird machines as insecure compilation. arXiv preprint arXiv:1911.00157 1, 1","author":"Paykin Jennifer","year":"2019","unstructured":"Jennifer Paykin, Eric Mertens, Mark Tullsen, Luke Maurer, Beno\u00eet Razet, Alexander Bakst, and Scott Moore. 2019. Weird machines as insecure compilation. arXiv preprint arXiv:1911.00157 1, 1 (2019), 1\u201318."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00051"},{"key":"e_1_3_2_1_29_1","unstructured":"Len Sassaman. 2014. LangSec: Recognition Validation and Compositional Correctness for Real World Security. https:\/\/langsec.org\/bof-handout.pdf. Accessed: 2024-01-10."},{"volume-title":"Towards a formal theory of computer insecurity: a language-theoretic approach","author":"Sassaman Len","key":"e_1_3_2_1_30_1","unstructured":"Len Sassaman and Meredith Patterson. 2011. Towards a formal theory of computer insecurity: a language-theoretic approach. http:\/\/www.youtube.com\/watch?v=AqZNebWoqnc. Accessed: 2024-01-10."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2018.07.008"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2014.37"}],"event":{"name":"EICC 2024: European Interdisciplinary Cybersecurity Conference","acronym":"EICC 2024","location":"Xanthi Greece"},"container-title":["European Interdisciplinary Cybersecurity Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3655693.3655705","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3655693.3655705","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,29]],"date-time":"2025-08-29T16:19:25Z","timestamp":1756484365000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3655693.3655705"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,5]]},"references-count":32,"alternative-id":["10.1145\/3655693.3655705","10.1145\/3655693"],"URL":"https:\/\/doi.org\/10.1145\/3655693.3655705","relation":{},"subject":[],"published":{"date-parts":[[2024,6,5]]},"assertion":[{"value":"2024-06-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}