{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T15:40:43Z","timestamp":1767109243613},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2019,3,29]],"date-time":"2019-03-29T00:00:00Z","timestamp":1553817600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1186\/s42400-019-0028-9","type":"journal-article","created":{"date-parts":[[2019,3,29]],"date-time":"2019-03-29T13:02:59Z","timestamp":1553864579000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["From proof-of-concept to exploitable"],"prefix":"10.1186","volume":"2","author":[{"given":"Yan","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinyu","family":"Xing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaorui","family":"Gong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Zou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,3,29]]},"reference":[{"key":"28_CR1","unstructured":"!exploitable Crash Analyzer (2018). \n                    http:\/\/msecdbg.codeplex.com\/\n                    \n                  . Accessed 1 May 2018."},{"key":"28_CR2","doi-asserted-by":"crossref","unstructured":"Alhuzali, A, Eshete B, Gjomemo R, Venkatakrishnan V (2016) Chainsaw: Chained automated workflow-based exploit generation In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 641\u2013652.. ACM.","DOI":"10.1145\/2976749.2978380"},{"key":"28_CR3","unstructured":"Andersen, S, Abella V (2004) Data Execution Prevention: Changes to Functionality in Microsoft Windows XP Service Pack 2, Part 3: Memory Protection Technologies. \n                    http:\/\/technet.microsoft.com\/en-us\/library\/bb457155.aspx\n                    \n                  ."},{"key":"28_CR4","unstructured":"Anonymous (2018) Demo exploit. \n                    https:\/\/www.dropbox.com\/s\/xk7bijxd66650ee\/demo.tar.gz?dl=0\n                    \n                  ."},{"key":"28_CR5","unstructured":"Argyroudis, P (2012) The Linux kernel memory allocators from an exploitation perspective. \n                    https:\/\/argp.github.io\/2012\/01\/03\/linux-kernel-heap-exploitation\/\n                    \n                  ."},{"key":"28_CR6","unstructured":"Avgerinos, T, Cha SK, Lim B, Hao T, Brumley D (2011) Aeg: Automatic exploit generation In: Network and Distributed System Security Symposium."},{"issue":"2","key":"28_CR7","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1145\/2560217.2560219","volume":"57","author":"T Avgerinos","year":"2014","unstructured":"Avgerinos, T, Cha SK, Rebert A, Schwartz EJ, Woo M, Brumley D (2014) Automatic exploit generation. Communications of the ACM 57(2):74\u201384.","journal-title":"Communications of the ACM"},{"key":"28_CR8","unstructured":"Azad, B (2016) Mac OS X Privilege Escalation via Use-After-Free: CVE-2016-1828. \n                    https:\/\/bazad.github.io\/2016\/05\/mac-os-x-use-after-free\/#use-after-free\n                    \n                  ."},{"key":"28_CR9","doi-asserted-by":"crossref","unstructured":"B\u00f6hme, M, Pham V-T, Nguyen M-D, Roychoudhury A (2017) Directed greybox fuzzing In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2329\u20132344.. ACM.","DOI":"10.1145\/3133956.3134020"},{"key":"28_CR10","doi-asserted-by":"crossref","unstructured":"B\u00f6hme, M, Pham V-T, Roychoudhury A (2016) Coverage-based greybox fuzzing as markov chain In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 1032\u20131043.. ACM.","DOI":"10.1145\/2976749.2978428"},{"key":"28_CR11","doi-asserted-by":"crossref","unstructured":"Brumley, D, Poosankam P, Song D, Zheng J (2008) Automatic patch-based exploit generation is possible: Techniques and implications In: Proceedings of the 29th IEEE Symposium on Security & Privacy, Oakland.","DOI":"10.1109\/SP.2008.17"},{"key":"28_CR12","doi-asserted-by":"crossref","unstructured":"Cha, SK, Avgerinos T, Rebert A, Brumley D (2012) Unleashing mayhem on binary code In: Security and Privacy (SP), 2012 IEEE Symposium On, 380\u2013394.. IEEE.","DOI":"10.1109\/SP.2012.31"},{"key":"28_CR13","unstructured":"CTF TIME (2018). \n                    https:\/\/ctftime.org\n                    \n                  . Online: accessed 01-May-2018."},{"key":"28_CR14","unstructured":"Database, NV (2017) CVE-2017-7374 Detail. \n                    https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-7374\n                    \n                  ."},{"key":"28_CR15","unstructured":"Dullien, T, Flake H (2011) Exploitation and state machines. Proc Infiltrate."},{"key":"28_CR16","doi-asserted-by":"publisher","unstructured":"Gan, S, Zhang C, Qin X, Tu X, Li K, Pei Z, Chen ZCollafl: Path sensitive fuzzing In: 2018 IEEE Symposium on Security and Privacy (SP), vol. 00, 660\u2013677. \n                    https:\/\/doi.org\/10.1109\/SP.2018.00040\n                    \n                  . \n                    https:\/\/doi.ieeecomputersociety.org\/10.1109\/SP.2018.00040\n                    \n                  .","DOI":"10.1109\/SP.2018.00040"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Gruss, D, Maurice C, Fogh A, Lipp M, Mangard S (2016) Prefetch side-channel attacks: Bypassing SMAP and kernel ASLR In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS).. ACM.","DOI":"10.1145\/2976749.2978356"},{"key":"28_CR18","doi-asserted-by":"crossref","unstructured":"He, L, Cai Y, Hu H, Su P, Liang Z, Yang Y, Huang H, Yan J, Jia X, Feng D (2017) Automatically assessing crashes from heap overflows In: Proceedings of the 32nd IEEE\/ACM International Conference on Automated Software Engineering, 274\u2013279.. IEEE Press.","DOI":"10.1109\/ASE.2017.8115640"},{"key":"28_CR19","unstructured":"Heelan, S (2009) Automatic generation of control flow hijacking exploits for software vulnerabilities. PhD thesis, University of Oxford."},{"key":"28_CR20","first-page":"177","volume-title":"USENIX Security Symposium","author":"H Hu","year":"2015","unstructured":"Hu, H, Chua ZL, Adrian S, Saxena P, Liang Z (2015) Automatic generation of data-oriented exploits In: USENIX Security Symposium, 177\u2013192.. USENIX Association, Washington, D.C. \n                    http:\/\/blogs.usenix.org\/conference\/usenixsecurity15\/technical-sessions\/presentation\/hu\n                    \n                  ."},{"key":"28_CR21","doi-asserted-by":"crossref","unstructured":"Huang, S-K, Huang M-H, Huang P-Y, Lai C-W, Lu H-L, Leong W-M (2012) Crax: Software crash analysis for automatic exploit generation by modeling attacks as symbolic continuations In: Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference On, 78\u201387.. IEEE.","DOI":"10.1109\/SERE.2012.20"},{"key":"28_CR22","doi-asserted-by":"crossref","unstructured":"Jang, Y, Lee S, Kim T (2010) Breaking kernel address space layout randomization with intel tsx In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS).","DOI":"10.1145\/2976749.2978321"},{"key":"28_CR23","unstructured":"jndok (2016) Analysis and exploitation of Pegasus Kernel vulnerabilities. \n                    https:\/\/jndok.github.io\/2016\/10\/04\/pegasus-writeup\/\n                    \n                  ."},{"key":"28_CR24","unstructured":"KASAN (2017) The Kernel Address Sanitizer(KASAN). \n                    https:\/\/github.com\/google\/kasan\/wiki\n                    \n                  ."},{"key":"28_CR25","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1109\/ICSE.2009.5070521","volume-title":"ICSE 2009, Proceedings of the 31st International Conference on Software Engineering","author":"A Kie\u017bun","year":"2009","unstructured":"Kie\u017bun, A, Guo PJ, Jayaraman K, Ernst MD (2009) Automatic creation of SQL injection and cross-site scripting attacks In: ICSE 2009, Proceedings of the 31st International Conference on Software Engineering, 199\u2013209.. IEEE Computer Society, Vancouver."},{"key":"28_CR26","unstructured":"Konovalov, A (2017) Exploiting the Linux kernel via packet sockets. \n                    https:\/\/googleprojectzero.blogspot.com\/2017\/05\/exploiting-linux-kernel-via-packet.html\n                    \n                  . Accessed 18 Jan 2018."},{"key":"28_CR27","unstructured":"Nikolenko, V (2016) Linux Kernel ROP - Ropping your way to # (Part 1). \n                    https:\/\/www.trustwave.com\/Resources\/SpiderLabs-Blog\/Linux-Kernel-ROP---Ropping-your-way-to---(Part-1)\/\n                    \n                  ."},{"key":"28_CR28","unstructured":"PaX-Team (2003) PaX ASLR (Address Space Layout Randomization). \n                    http:\/\/pax.grsecurity.net\/docs\/aslr.txt\n                    \n                  ."},{"key":"28_CR29","doi-asserted-by":"crossref","unstructured":"Rawat, S, Jain V, Kumar A, Bos H (2017) VUzzer: Application-aware Evolutionary Fuzzing In: Network and Distributed System Security Symposium.","DOI":"10.14722\/ndss.2017.23404"},{"key":"28_CR30","unstructured":"Rex (2018) Shellphish\u2019s automated exploitation engine. \n                    https:\/\/github.com\/shellphish\/rex\n                    \n                  . Online: accessed 01-May-2018."},{"key":"28_CR31","unstructured":"Schwartz, EJ, Avgerinos T, Brumley D (2011) Q: Exploit hardening made easy In: USENIX Security Symposium, 25\u201341.. Usenix."},{"key":"28_CR32","doi-asserted-by":"crossref","unstructured":"Serebryany, K (2016) Continuous fuzzing with libfuzzer and addresssanitizer In: Cybersecurity Development (SecDev), IEEE, 157\u2013157.. IEEE.","DOI":"10.1109\/SecDev.2016.043"},{"key":"28_CR33","unstructured":"Serebryany, K, Bruening D, Potapenko A, Vyukov D (2012) Addresssanitizer: A fast address sanity checker In: the 2012 USENIX Annual Technical Conference, 309\u2013318.. USENIX Association,."},{"key":"28_CR34","unstructured":"Serebryany, K, Stepanov E, Shlyapnikov A, Tsyrklevich V, Vyukov D (2018) Memory tagging and how it improves C\/C++ memory safety. CoRR abs\/1802.09517. \n                    1802.09517\n                    \n                  ."},{"key":"28_CR35","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y, Wang R, Salls C, Stephens N, Polino M, Dutcher A, Grosen J, Feng S, Hauser C, Kruegel C, et al (2016) Sok:(state of) the art of war: Offensive techniques in binary analysis In: Security and Privacy (SP), 2016 IEEE Symposium On, 138\u2013157.. IEEE.","DOI":"10.1109\/SP.2016.17"},{"key":"28_CR36","doi-asserted-by":"crossref","unstructured":"Sotirov, A (2007) Heap feng shui in javascript. Black Hat Eur.","DOI":"10.1215\/00265667-2007-69-7"},{"key":"28_CR37","doi-asserted-by":"crossref","unstructured":"Stephens, N, Grosen J, Salls C, Dutcher A, Wang R, Corbetta J, Shoshitaishvili Y, Kruegel C, Vigna G (2016) Driller: Augmenting fuzzing through selective symbolic execution In: NDSS, 1\u201316.","DOI":"10.14722\/ndss.2016.23368"},{"key":"28_CR38","unstructured":"Swiecki, R (2016) Honggfuzz. Available online a t: \n                    http:\/\/code.google.com\/p\/honggfuzz\n                    \n                  ."},{"key":"28_CR39","unstructured":"Unlink Exploit (2018). \n                    https:\/\/heap-exploitation.dhavalkapil.com\/attacks\/unlink_exploit.html\n                    \n                  . Online: accessed 01-May-2018."},{"key":"28_CR40","unstructured":"Valgrind (2018). \n                    http:\/\/valgrind.org\n                    \n                  . Accessed 1 May 2018."},{"key":"28_CR41","unstructured":"Vanegue, J (2013) The automated exploitation grand challenge In: Presented at H2HC Conference."},{"key":"28_CR42","doi-asserted-by":"crossref","unstructured":"Xu, W, Li J, Shu J, Yang W, Xie T, Zhang Y, Gu D (2015) From collision to exploitation: Unleashing use-after-free vulnerabilities in linux kernel In: Proceedings of the 2015 ACM SIGSAC Conference on Computer and Communications Security (CCS).. ACM.","DOI":"10.1145\/2810103.2813637"},{"key":"28_CR43","unstructured":"Zalewski, M (2018) American Fuzzy Lop. \n                    http:\/\/lcamtuf.coredump.cx\/afl\/\n                    \n                  . Online: accessed 01-May-2018."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-019-0028-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s42400-019-0028-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-019-0028-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,3,28]],"date-time":"2020-03-28T00:04:01Z","timestamp":1585353841000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-019-0028-9"}},"subtitle":["(One step towards automatic exploitability assessment)"],"short-title":[],"issued":{"date-parts":[[2019,3,29]]},"references-count":43,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,12]]}},"alternative-id":["28"],"URL":"https:\/\/doi.org\/10.1186\/s42400-019-0028-9","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,3,29]]},"assertion":[{"value":"5 November 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 February 2019","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 March 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Xiaorui Gong is a senior engineer at School of Cyber Security, University of Chinese Academy of Sciences. His research focuses on software and system security.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Authors\u2019 information"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Publisher\u2019s Note"}}],"article-number":"12"}}