{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,5,14]],"date-time":"2022-05-14T04:50:38Z","timestamp":1652503838161},"reference-count":37,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"12","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2018,12,1]]},"DOI":"10.1587\/transinf.2018edp7192","type":"journal-article","created":{"date-parts":[[2018,11,30]],"date-time":"2018-11-30T22:27:33Z","timestamp":1543616853000},"page":"3005-3018","source":"Crossref","is-referenced-by-count":4,"title":["Automatic Prevention of Buffer Overflow Vulnerability Using Candidate Code Generation"],"prefix":"10.1587","volume":"E101.D","author":[{"given":"Young-Su","family":"JANG","sequence":"first","affiliation":[{"name":"Korea Polytechnics"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jin-Young","family":"CHOI","sequence":"additional","affiliation":[{"name":"Korea University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"crossref","unstructured":"[1] J. Stark, \u201cProduct lifecycle management,\u201d Product Lifecycle Management, Springer, vol.1, pp.1-29, 2015. 10.1007\/978-3-319-17440-2_1","DOI":"10.1007\/978-3-319-17440-2_1"},{"key":"2","doi-asserted-by":"publisher","unstructured":"[2] C.-C. Huang, F.-Y. Lin, F.Y.-S. Lin, and Y.S. Sun, \u201cA novel approach to evaluate software vulnerability prioritization,\u201d J. Syst. Softw., vol.86, no.11, pp.2822-2840, 2013. 10.1016\/j.jss.2013.06.040","DOI":"10.1016\/j.jss.2013.06.040"},{"key":"3","doi-asserted-by":"crossref","unstructured":"[3] F. Gao, L. Wang, and X. Li, \u201cBovInspector: automatic inspection and repair of buffer overflow vulnerabilities,\u201d Proc. 31st IEEE\/ACM Int. Conf. Automated Software Engineering, pp.786-791, 2016.","DOI":"10.1145\/2970276.2970282"},{"key":"4","doi-asserted-by":"publisher","unstructured":"[4] P. Bisht, P. Madhusudan, and V.N. Venkatakrishnan, \u201cCANDID: Dynamic candidate evaluations for automatic prevention of SQL injection attacks,\u201d ACM Trans. Info. Syst. Security, vol.13, no.2, pp.1-38, 2010. 10.1145\/1698750.1698754","DOI":"10.1145\/1698750.1698754"},{"key":"5","unstructured":"[5] B.V. Deokate and D.B. Hanchate, \u201cSoftware source code plagiarism detection using latent semantic analysis,\u201d Int. J. Sci Res., vol.5, pp.1059-1063, 2006."},{"key":"6","doi-asserted-by":"publisher","unstructured":"[6] H. Shahriar, H.M. Haddad, and I. Vaidya, \u201cBuffer overflow patching for C and C++ programs: rule-based approach,\u201d SIGAPP Appl. Comput. Rev, vol.13, no.2, pp.8-19, 2013. 10.1145\/2505420.2505421","DOI":"10.1145\/2505420.2505421"},{"key":"7","doi-asserted-by":"crossref","unstructured":"[7] Y. Yang, C. Onita, X. Zhang, and J. Dhaliwal, \u201cTESTQUAL: Conceptualizing software testing as a service,\u201d e-Service J., vol.7, no.2, pp.46-65, 2011. 10.2979\/eservicej.7.2.46","DOI":"10.2979\/eservicej.7.2.46"},{"key":"8","doi-asserted-by":"publisher","unstructured":"[8] B.M. Padmanabhuni and H.B.K. Tan, \u201cAuditing buffer overflow vulnerabilities using hybrid static-dynamic analysis,\u201d IET Software, vol.10, no.2, pp.54-61, 2016. 10.1049\/iet-sen.2014.0185","DOI":"10.1049\/iet-sen.2014.0185"},{"key":"9","doi-asserted-by":"publisher","unstructured":"[9] A.E. Elhadi, M.A. Maarof, and B.I. Barry, \u201cImproving the detection of malware behaviour using simplified data dependent API call graph,\u201d Int. J. Sec. Appl., vol.7, no.5, pp.29-42, 2013. 10.14257\/ijsia.2013.7.5.03","DOI":"10.14257\/ijsia.2013.7.5.03"},{"key":"10","doi-asserted-by":"crossref","unstructured":"[10] T. Ye, L. Zhang, L. Wang, and X. Li, \u201cAn empirical study on detecting and fixing buffer overflow bugs,\u201d ICST IEEE Int. Conf., pp.91-101, 2016. 10.1109\/icst.2016.21","DOI":"10.1109\/ICST.2016.21"},{"key":"11","doi-asserted-by":"publisher","unstructured":"[11] H. Brar and P. Kaur, \u201cComparing detection ratio of three static analysis tools,\u201d Int. Journal of Computer Applications, vol.124, no.13, pp.35-40, 2015. 10.5120\/ijca2015905749","DOI":"10.5120\/ijca2015905749"},{"key":"12","unstructured":"[12] Flawfinder-C\/C++ Source Code Analyzer, http:\/\/www.dwheeler.com\/flawfinder\/, 2017."},{"key":"13","doi-asserted-by":"crossref","unstructured":"[13] E. Cilia, R. Pancsa, P. Tompa, T. Lenaerts, and W. Vranken, \u201cFrom protein sequence to dynamics and disorder with DynaMine,\u201d Nat. Commun., vol.4, pp.1-10, 2013.","DOI":"10.1038\/ncomms3741"},{"key":"14","doi-asserted-by":"crossref","unstructured":"[14] P. Godefroid, M.Y. Levin, and D. Molnar, \u201cSAGE: whitebox fuzzing for security testing,\u201d Commun. ACM., vol.10, no.1, pp.40-44, 2012.","DOI":"10.1145\/2093548.2093564"},{"key":"15","unstructured":"[15] I. Haller, A. Slowinska, M. Neugschwandtner, and H. Bos, \u201cDowsing for overflows: A guided fuzzer to find buffer boundary violations,\u201d Proc. 22nd USENIX Conf. Security, pp.49-64, 2013."},{"key":"16","doi-asserted-by":"crossref","unstructured":"[16] Y. Zhang and A. Mesbah, \u201cAssertions are strongly correlated with test suite effectiveness,\u201d Proc. 2015 10th Joint Meeting on Foundations of Software Engineering, pp.214-224, 2015. 10.1145\/2786805.2786858","DOI":"10.1145\/2786805.2786858"},{"key":"17","doi-asserted-by":"publisher","unstructured":"[17] G.C. Necula, J. Condit, M. Harren, S. McPeak, and W. Weimer, \u201cCCured: type-safe retrofitting of legacy software,\u201d ACM Trans. Progr. Lang. Syst., vol.27, no.3, pp.477-526, 2005. 10.1145\/1065887.1065892","DOI":"10.1145\/1065887.1065892"},{"key":"18","doi-asserted-by":"crossref","unstructured":"[18] A. Kiezun, V. Ganes, S. Artzi, P. Guo, P. Hooimeijer, and M. Ernst, \u201cHAMPI: A solver for word equations over strings, regular expressions, and context-free grammars,\u201d ACM T. Softw. Eng. Meth., vol.21, no.4, pp.25-52, 2012.","DOI":"10.1145\/2377656.2377662"},{"key":"19","doi-asserted-by":"publisher","unstructured":"[19] P. Soulier, D. Li, and J.R. Williams, \u201cA survey of language-based approaches to cyber-physical and embedded system development,\u201d Tsinghua Science and Technology, vol.20, no.2, pp.130-141, 2015. 10.1109\/tst.2015.7085626","DOI":"10.1109\/TST.2015.7085626"},{"key":"20","doi-asserted-by":"crossref","unstructured":"[20] J. Wielemaker, T. Schrijvers, M. Triska, and T. Lager, \u201cSWI-Prolog,\u201d Theory and Practice of Logic Programming, pp.67-96, 2012.","DOI":"10.1017\/S1471068411000494"},{"key":"21","doi-asserted-by":"crossref","unstructured":"[21] G. Vidal, \u201cConcolic execution and test case generation in Prolog,\u201d Proc. 24th Int. Sym. on Logic-Based Program Synthesis and Transformation, vol.8981, pp.167-181, 2015. 10.1007\/978-3-319-17822-6_10","DOI":"10.1007\/978-3-319-17822-6_10"},{"key":"22","unstructured":"[22] K. Jothsna and R.V. Krishniah, \u201cA signature-free buffer overflow attack blocker using genetic programming,\u201d Int. J. Emerg. Tech. Adv. Eng., vol.3, no.2, pp.640-647, 2013."},{"key":"23","unstructured":"[23] S.J. Salunkhe and U.L. Kulkarni, \u201cSoftware theft detection for JavaScript programs based on dynamic birthmark extracted from runtime heap graph,\u201d IOSR J. Comput. Eng., vol.17, no.3, pp.34-39, 2015."},{"key":"24","doi-asserted-by":"publisher","unstructured":"[24] D.A. Plaisted, \u201cSource-to-source translation and software engineering,\u201d J. Softw. Eng. Appl., vol.6, no.4, pp.30-40, 2013. 10.4236\/jsea.2013.64a005","DOI":"10.4236\/jsea.2013.64A005"},{"key":"25","doi-asserted-by":"publisher","unstructured":"[25] V. Kuznetsov, J. Kinder, S. Bucur, and G. Candea, \u201cEfficient state merging in symbolic execution,\u201d ACM SIGPLAN Notices, vol.47, no.6, pp.193-204, 2012. 10.1145\/2345156.2254088","DOI":"10.1145\/2345156.2254088"},{"key":"26","doi-asserted-by":"publisher","unstructured":"[26] Y.-S. Jang and J.-Y. Choi, \u201cDetecting SQL injection attacks using query result size,\u201d Comput. Sec., vol.44, pp.104-118, 2014. 10.1016\/j.cose.2014.04.007","DOI":"10.1016\/j.cose.2014.04.007"},{"key":"27","doi-asserted-by":"publisher","unstructured":"[27] E. Ferneley, \u201cCoupling and control flow measures in practice,\u201d J. Syst. Softw., vol.51, no.2, pp.99-109, 2000. 10.1016\/s0164-1212(99)00115-6","DOI":"10.1016\/S0164-1212(99)00115-6"},{"key":"28","doi-asserted-by":"crossref","unstructured":"[28] M. Valera, K. Rathod, and U. Chauhan, \u201cA neoteric web recommender system based on approach of mining frequent sequential pattern from customized web log preprocessing,\u201d Int. J. Comput. Appl., vol.69, no.24, pp.6-21, 2013.","DOI":"10.5120\/12119-8197"},{"key":"29","doi-asserted-by":"crossref","unstructured":"[29] M. Boekhold, I. Karkowski, and H. Corporaal, \u201cTransforming and parallelizing ANSI C programs using pattern recognition,\u201d int. Conf. on High-Performance Computing and Networking, pp.673-682, 2006. 10.1007\/bfb0100628","DOI":"10.1007\/BFb0100628"},{"key":"30","doi-asserted-by":"crossref","unstructured":"[30] D. Gugerli, \u201cThe world as database: on the relation of software development, query methods, and interpretative independence,\u201d Info. Culture, vol.47, no.3, pp.288-311, 2012. 10.7560\/ic47302","DOI":"10.7560\/IC47302"},{"key":"31","doi-asserted-by":"crossref","unstructured":"[31] S. Ransbotham and S. Mitra, \u201cChoice and chance: a conceptual model of paths to information security compromise,\u201d Infor. Syst. Res., vol.20, no.1, pp.121-139, 2009. 10.1287\/isre.1080.0174","DOI":"10.1287\/isre.1080.0174"},{"key":"32","doi-asserted-by":"crossref","unstructured":"[32] M. Chilowicz, E. Duris, and G. Roussel, \u201cSyntax tree fingerprinting for source code similarity detection,\u201d 2009 IEEE 17th Int. Conf. on Program Comprehension, pp.243-247, 2009. 10.1109\/icpc.2009.5090050","DOI":"10.1109\/ICPC.2009.5090050"},{"key":"33","unstructured":"[33] NIST, Juliet test suite for C\/C++ v1.3, https:\/\/samate.nist.gov\/SRD\/testsuite.php, 2017."},{"key":"34","doi-asserted-by":"publisher","unstructured":"[34] A. Nanthaamornphong and J.C. Carver, \u201cTest-driven development in scientific software: a survey,\u201d Softw. Quality J., vol.25, no.2, pp.343-372, 2017. 10.1007\/s11219-015-9292-4","DOI":"10.1007\/s11219-015-9292-4"},{"key":"35","doi-asserted-by":"publisher","unstructured":"[35] D. Port and J. Wilf, \u201cThe value proposition for assurance of JPL systems,\u201d Procedia Comput. Sci., vol.28, pp.398-403, 2014. 10.1016\/j.procs.2014.03.049","DOI":"10.1016\/j.procs.2014.03.049"},{"key":"36","unstructured":"[36] L.A.B. Sanguino and R. Uetz, \u201cSoftware vulnerability analysis using CPE and CVE,\u201d arXiv preprint arXiv, 1705.05347, 2017."},{"key":"37","doi-asserted-by":"publisher","unstructured":"[37] M. Belaoucha, D. Barthou, A. Eliche, and S.-A.-A. Touati, \u201cFADAlib: an open source C++ library for fuzzy array dataflow analysis,\u201d Procedia Comput. Sci., vol.1, no.1, pp.2075-2084, 2010. 10.1016\/j.procs.2010.04.232","DOI":"10.1016\/j.procs.2010.04.232"}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E101.D\/12\/E101.D_2018EDP7192\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T12:40:18Z","timestamp":1573044018000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E101.D\/12\/E101.D_2018EDP7192\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,1]]},"references-count":37,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2018]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2018edp7192","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"value":"0916-8532","type":"print"},{"value":"1745-1361","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,12,1]]}}}