{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T10:05:55Z","timestamp":1773655555049,"version":"3.50.1"},"reference-count":28,"publisher":"Allerton Press","issue":"7","license":[{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Aut. Control Comp. Sci."],"published-print":{"date-parts":[[2020,12]]},"DOI":"10.3103\/s0146411620070111","type":"journal-article","created":{"date-parts":[[2021,2,8]],"date-time":"2021-02-08T12:46:46Z","timestamp":1612788406000},"page":"573-583","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["On Detecting Code Reuse Attacks"],"prefix":"10.3103","volume":"54","author":[{"given":"Y. V.","family":"Kosolapov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1627","published-online":{"date-parts":[[2021,2,8]]},"reference":[{"key":"7274_CR1","doi-asserted-by":"crossref","unstructured":"Shacham, H., The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86), Proceedings of the 14th ACM Conference on Computer and Communications Security, 2007, pp. 552\u2013561.","DOI":"10.1145\/1315245.1315313"},{"key":"7274_CR2","doi-asserted-by":"crossref","unstructured":"Buchanan, E., Roemer, R., Shacham, H., and Savage, S., When good instructions go bad: Generalizing return-oriented programming to RISC, Proceedings of the 15th ACM Conference on Computer and Communications Security, 2008, pp. 27\u201338.","DOI":"10.1145\/1455770.1455776"},{"key":"7274_CR3","unstructured":"http:\/\/ropshell.com. Accessed November 26, 2018."},{"key":"7274_CR4","doi-asserted-by":"publisher","first-page":"379","DOI":"10.4156\/jdcta.vol6.issue14.46","volume":"6","author":"C. Binlin","year":"2012","unstructured":"Binlin, C., Jianming, F., and Zhiyi, Y., Heap spraying attack detection based on sled distance, Int. J. Digital Content Technol. Its Appl., 2012, vol. 6, no. 14, pp. 379\u2013386.","journal-title":"Int. J. Digital Content Technol. Its Appl."},{"key":"7274_CR5","doi-asserted-by":"crossref","unstructured":"Davi, L., Sadeghi, A., and Winandy, M., ROPdefender: A detection tool to defend against return-oriented programming attacks, Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, 2011, pp. 40\u201351.","DOI":"10.1145\/1966913.1966920"},{"key":"7274_CR6","doi-asserted-by":"crossref","unstructured":"Davi, L., Koeberl, P., and Sadeghi, A., Hardware-assisted fine-grained control-flow integrity: Towards efficient protection of embedded systems against software exploitation, Proceedings of the 51st Annual Design Automation Conference, San Francisco, CA, 2014, pp. 1\u20136.","DOI":"10.1145\/2593069.2596656"},{"key":"7274_CR7","doi-asserted-by":"crossref","unstructured":"Ge, X., Talele, N., Payer, M., and Jaeger, T., Fine-grained control-flow integrity for kernel software, IEEE European Symposium on Security and Privacy, 2016, pp. 179\u2013194.","DOI":"10.1109\/EuroSP.2016.24"},{"key":"7274_CR8","doi-asserted-by":"crossref","unstructured":"Usui, T., Ikuse, T., Iwamura, M., and Yada, T., POSTER: Static ROP chain detection based on hidden Markov model considering ROP chain integrity, Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016, pp. 1808\u20131810.","DOI":"10.1145\/2976749.2989040"},{"key":"7274_CR9","unstructured":"Cawan, S.C., Arnold, S.R., Beattie, S.M., and Wagle, P.M., Pointguard: Method and system for protecting programs against pointer corruption attacks, US Patent 7752459B2, 2010."},{"key":"7274_CR10","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Zhou, Z., Miao, Y., Ding, X., and Deng, H.R., ROPecker: A generic and practical approach for defending against ROP attack, Symposium on Network and Distributed System Security (NDSS), 2014, pp. 1\u201314.","DOI":"10.14722\/ndss.2014.23156"},{"key":"7274_CR11","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-642-10772-6_13","volume":"5905","author":"P. Chen","year":"2009","unstructured":"Chen, P., Xiao, H., Shen, X., Yin, X., Mao, B., and Xie, L., DROP: Detecting return-oriented programming malicious code, Lect. Notes Comput. Sci., 2009, vol. 5905, pp. 163\u2013177.","journal-title":"Lect. Notes Comput. Sci."},{"key":"7274_CR12","unstructured":"Control-flow Enforcement Technology Preview, 2017. https:\/\/software.intel.com\/sites\/default\/files\/managed\/4d\/2a\/control-flow-enforcement-technology-preview.pdf. Accessed November 26, 2018."},{"key":"7274_CR13","doi-asserted-by":"crossref","unstructured":"Checkoway, S., Davi, L., Dmitrienko, A., Sadeghi, A.R., Shacham, H., and Winandy, M., Return-oriented programming without returns, Proceedings of the 17th ACM Conference on Computer and Communications Security, 2010, pp. 559\u2013572.","DOI":"10.1145\/1866307.1866370"},{"key":"7274_CR14","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/s11416-017-0299-1","volume":"14","author":"A. Sadeghi","year":"2018","unstructured":"Sadeghi, A., Niksefat, S., and Rostamipour, M., Pure-call oriented programming (PCOP): Chaining the gadgets using call instructions, J. Comput. Virol. Hacking Tech., 2018, vol. 14, no. 2, pp. 139\u2013156.","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"7274_CR15","doi-asserted-by":"crossref","unstructured":"Yao, F., Chen, J., and Venkataramani, G., Jop-alarm: Detecting jump-oriented programming-based anomalies in applications, IEEE 31st International Conference on Computer Design (ICCD), 2013, pp. 467\u2013470.","DOI":"10.1109\/ICCD.2013.6657084"},{"key":"7274_CR16","unstructured":"Goktas, E., Athanasopoulos, E., Polychronakis, M., Bos, H., and Portokalidis, G., Size does matter: Why using gadget-chain length to prevent code-reuse attacks is hard, Proceedings of the 23rd USENIX Security Symposium, 2014, pp. 417\u2013432."},{"key":"7274_CR17","unstructured":"Carlini, N. and Wagner, D., ROP is still dangerous: Breaking modern defenses, SEC'14 Proceedings of the 23rd USENIX Conference on Security Symposium, 2014, pp. 385\u2013399."},{"key":"7274_CR18","volume-title":"Compilers: Principles, Techniques, and Tools","author":"A.V. Aho","year":"1986","unstructured":"Aho, A.V., Sethi, R., and Ullman, J.D., Compilers: Principles, Techniques, and Tools, Pearson Education, Inc., 1986."},{"key":"7274_CR19","doi-asserted-by":"crossref","unstructured":"Kayaalp, M., Schmitt, T., Nomani, J., Ponomarev, D., and Abu-Ghazaleh, N., Scrap: Architecture for signature-based protection from code reuse attacks, Proceedings of IEEE 19th International Symposium on High Performance Computer Architecture (HPCA2013), 2013, pp. 258\u2013269.","DOI":"10.1109\/HPCA.2013.6522324"},{"key":"7274_CR20","unstructured":"https:\/\/sploitfun.wordpress.com\/2015\/05\/08\/bypassing-aslr-part-iii\/. Accessed December 6, 2018."},{"key":"7274_CR21","unstructured":"Katoch, V., Bypassing ASLR\/DEP. https:\/\/www.exploit-db.com\/docs\/english\/17914-bypassing-aslrdep.pdf. Accessed December 6, 2018."},{"key":"7274_CR22","unstructured":"Pappas, V., Polychronakis, M., and Keromytis, A.D., Transparent ROP exploit mitigation using indirect branch tracing, Proc. of the 22nd USENIX Security Symposium, 2013, pp. 447\u2013462."},{"key":"7274_CR23","unstructured":"https:\/\/www.securityfocus.com\/bid\/62780\/info. Accessed December 3, 2018."},{"key":"7274_CR24","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., and Kirda, E., Limits of static analysis for malware detection, Proceedings of Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), 2008, pp. 421\u2013430.","DOI":"10.1109\/ACSAC.2007.21"},{"key":"7274_CR25","doi-asserted-by":"crossref","unstructured":"Hu, H., Shinde, S., Adrian, S., Chua, Z.L., Saxena, P., and Liang, Z., Data-oriented programming: On the expressiveness of non-control data attacks, Security and Privacy (SP) Symposium, 2016, pp. 969\u2013986.","DOI":"10.1109\/SP.2016.62"},{"key":"7274_CR26","doi-asserted-by":"crossref","unstructured":"Ma, H., Lu, K., Ma, X., Zhang, H., Jia, C., and Gao, D., Software watermarking using return-oriented programming, Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, 2015, pp. 369\u2013380.","DOI":"10.1145\/2714576.2714582"},{"key":"7274_CR27","unstructured":"Gao, D., Method for obfuscation of code using return oriented programming, WO Patent 2016126206A1, 2015."},{"key":"7274_CR28","doi-asserted-by":"crossref","unstructured":"Lu, K., Xiong, S., and Gao, D., Ropsteg: Program steganography with return oriented programming, Proceedings of the 4th ACM Conference on Data and Application Security and Privacy, 2014, pp. 265\u2013272.","DOI":"10.1145\/2557547.2557572"}],"container-title":["Automatic Control and Computer Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.3103\/S0146411620070111.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.3103\/S0146411620070111","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.3103\/S0146411620070111.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T22:01:28Z","timestamp":1773612088000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.3103\/S0146411620070111"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12]]},"references-count":28,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["7274"],"URL":"https:\/\/doi.org\/10.3103\/s0146411620070111","relation":{},"ISSN":["0146-4116","1558-108X"],"issn-type":[{"value":"0146-4116","type":"print"},{"value":"1558-108X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,12]]},"assertion":[{"value":"17 December 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2019","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 May 2019","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 February 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no conflicts of interest.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"CONFLICT OF INTEREST"}},{"value":"Yury V. Kosolapov, orcid.org\/0000-0002-1491-524X, PhD.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"ADDITIONAL INFORMATION"}}]}}