{"id":"https://openalex.org/W2971156856","doi":"https://doi.org/10.1109/access.2019.2937585","title":"ARG: Automatic ROP Chains Generation","display_name":"ARG: Automatic ROP Chains Generation","publication_year":2019,"publication_date":"2019-01-01","ids":{"openalex":"https://openalex.org/W2971156856","doi":"https://doi.org/10.1109/access.2019.2937585","mag":"2971156856"},"language":"en","primary_location":{"id":"doi:10.1109/access.2019.2937585","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2019.2937585","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/8600701/08813052.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/8600701/08813052.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5001595856","display_name":"Yuan Wei","orcid":"https://orcid.org/0000-0002-7930-2911"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuan Wei","raw_affiliation_strings":["Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-7930-2911","affiliations":[{"raw_affiliation_string":"Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101877453","display_name":"Senlin Luo","orcid":"https://orcid.org/0000-0002-7729-5439"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Senlin Luo","raw_affiliation_strings":["Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112309175","display_name":"Jianwei Zhuge","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156423","display_name":"National Engineering Research Center for Information Technology in Agriculture","ror":"https://ror.org/04c3j3t84","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210156423"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianwei Zhuge","raw_affiliation_strings":["Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China","institution_ids":["https://openalex.org/I4210156423"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100781389","display_name":"Jing Gao","orcid":"https://orcid.org/0000-0002-7139-1227"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jing Gao","raw_affiliation_strings":["Beijing Gehua CATV Network Co., Ltd., Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Beijing Gehua CATV Network Co., Ltd., Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102337092","display_name":"Ennan Zheng","orcid":null},"institutions":[{"id":"https://openalex.org/I67636235","display_name":"University of International Relations","ror":"https://ror.org/04r72en83","country_code":"CN","type":"education","lineage":["https://openalex.org/I67636235"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ennan Zheng","raw_affiliation_strings":["Department of Information Technology, University of International Relations, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Information Technology, University of International Relations, Beijing, China","institution_ids":["https://openalex.org/I67636235"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101964979","display_name":"Bo Li","orcid":"https://orcid.org/0000-0002-9498-6389"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bo Li","raw_affiliation_strings":["Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069772530","display_name":"Limin Pan","orcid":"https://orcid.org/0000-0002-8850-8380"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Limin Pan","raw_affiliation_strings":["Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5001595856"],"corresponding_institution_ids":["https://openalex.org/I125839683"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.6678,"has_fulltext":true,"cited_by_count":6,"citation_normalized_percentile":{"value":0.68995979,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":"7","issue":null,"first_page":"120152","last_page":"120163"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9936000108718872,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.903361976146698},{"id":"https://openalex.org/keywords/gadget","display_name":"Gadget","score":0.8904236555099487},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.7848106622695923},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.46651971340179443},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.44097772240638733},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.42883503437042236},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4213818311691284},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.16662481427192688},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.15061154961585999}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.903361976146698},{"id":"https://openalex.org/C119770614","wikidata":"https://www.wikidata.org/wiki/Q5516347","display_name":"Gadget","level":2,"score":0.8904236555099487},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.7848106622695923},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.46651971340179443},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.44097772240638733},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.42883503437042236},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4213818311691284},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.16662481427192688},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.15061154961585999}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2019.2937585","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2019.2937585","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/8600701/08813052.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:b26a9aba21b14f0d81c320e49f99ebb8","is_oa":true,"landing_page_url":"https://doaj.org/article/b26a9aba21b14f0d81c320e49f99ebb8","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 7, Pp 120152-120163 (2019)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2019.2937585","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2019.2937585","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/8600701/08813052.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.4399999976158142}],"awards":[],"funders":[{"id":"https://openalex.org/F4320321133","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35"},{"id":"https://openalex.org/F4320329777","display_name":"Beijing National Research Center For Information Science And Technology","ror":null}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2971156856.pdf","grobid_xml":"https://content.openalex.org/works/W2971156856.grobid-xml"},"referenced_works_count":35,"referenced_works":["https://openalex.org/W203252516","https://openalex.org/W229745036","https://openalex.org/W1459231281","https://openalex.org/W1480909796","https://openalex.org/W1481397690","https://openalex.org/W1496222301","https://openalex.org/W1522250664","https://openalex.org/W1992201568","https://openalex.org/W2031641633","https://openalex.org/W2051990174","https://openalex.org/W2089448621","https://openalex.org/W2099382052","https://openalex.org/W2102970979","https://openalex.org/W2107147876","https://openalex.org/W2113864883","https://openalex.org/W2123436168","https://openalex.org/W2162800072","https://openalex.org/W2165597437","https://openalex.org/W2296613870","https://openalex.org/W2512784977","https://openalex.org/W2574017551","https://openalex.org/W2602639380","https://openalex.org/W2611801377","https://openalex.org/W2765363641","https://openalex.org/W2786724047","https://openalex.org/W2792322951","https://openalex.org/W2888875512","https://openalex.org/W6608934814","https://openalex.org/W6628302897","https://openalex.org/W6629841029","https://openalex.org/W6631155369","https://openalex.org/W6675416627","https://openalex.org/W6678302136","https://openalex.org/W6747979171","https://openalex.org/W6753913213"],"related_works":["https://openalex.org/W4252293060","https://openalex.org/W4212943538","https://openalex.org/W2475971442","https://openalex.org/W4312756098","https://openalex.org/W3194202522","https://openalex.org/W4319586723","https://openalex.org/W2206440698","https://openalex.org/W3091274767","https://openalex.org/W4295163867","https://openalex.org/W4312974239"],"abstract_inverted_index":{"Return":[0],"Oriented":[1],"Programming":[2],"(ROP)":[3],"chains":[4,29,45,143,156,166,196],"attack":[5],"has":[6],"been":[7],"widely":[8],"used":[9],"to":[10,73,91,111,140,145,202,216,227,231],"bypass":[11,245],"Data":[12],"Execution":[13],"Prevention":[14],"(DEP)":[15],"and":[16,50,83,137,184,213,251],"Address":[17],"Space":[18],"Layout":[19],"Randomization":[20],"(ASLR)":[21],"protection.":[22],"However,":[23],"the":[24,56,59,75,127,153,161,203],"generation":[25,167],"technology":[26,192],"for":[27,41,80,197,234],"ROP":[28,44,142,155,165,195,211,219],"is":[30,70,114,135,160],"still":[31,47],"in":[32,71,86],"a":[33,87,94,115,131],"state":[34],"of":[35,77,99,109,118,129,199,218],"manual":[36,232],"coding.":[37],"While,":[38],"current":[39],"techniques":[40],"automatically":[42,92,209],"generating":[43],"are":[46,62],"insufficiently":[48],"researched":[49],"have":[51],"few":[52],"successful":[53],"applications.":[54],"On":[55],"other":[57],"hand,":[58],"existing":[60],"methods":[61,100],"based":[63],"on":[64],"using":[65,170],"Intermediate":[66],"Language":[67],"(IL)":[68],"which":[69,159],"order":[72],"translate":[74],"semantics":[76,108],"original":[78,110],"instructions":[79,122],"symbolic":[81],"execution,":[82],"then":[84],"fill":[85],"predefined":[88],"gadget":[89,95,133],"arrangement":[90,134],"construct":[93,141],"list.":[96],"This":[97],"kind":[98],"may":[101,123,138],"bring":[102],"following":[103],"problems:":[104],"(1)":[105],"when":[106],"converting":[107],"IL,":[112],"there":[113],"large":[116],"amount":[117],"overhead":[119],"time,":[120],"critical":[121],"be":[124],"discarded;":[125],"(2)":[126],"process":[128],"populating":[130],"predetermined":[132],"inflexible":[136],"fail":[139],"due":[144],"address":[146],"mismatching.":[147],"In":[148],"this":[149,191],"paper,":[150],"we":[151],"propose":[152],"Automatic":[154],"Generation":[157],"(ARG)":[158],"first":[162],"fully":[163],"automatic":[164],"tool":[168],"without":[169],"IL.":[171],"Tested":[172],"with":[173],"data":[174],"from":[175],"6":[176],"open-source":[177],"international":[178],"Capture":[179],"The":[180],"Flag":[181],"(CTF)":[182],"competitions":[183],"3":[185],"Common":[186],"Vulnerabilities":[187],"&":[188],"Exposures":[189],"(CVE)s,":[190],"successfully":[193],"generated":[194],"all":[198],"them.":[200],"According":[201],"obtained":[204],"results,":[205],"our":[206],"technique":[207],"can":[208,243],"create":[210],"payloads":[212],"reduce":[214],"up":[215],"80%":[217],"exploit":[220,228],"payloads.":[221],"It":[222],"takes":[223],"only":[224],"3-5":[225],"seconds":[226],"successfully,":[229],"compared":[230],"analysis":[233],"at":[235],"least":[236],"60":[237],"minutes,":[238],"as":[239,241],"well":[240],"it":[242],"effectively":[244],"both":[246],"Write":[247],"XOR":[248],"Execute":[249],"(W\u2295X)":[250],"ASLR.":[252]},"counts_by_year":[{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3}],"updated_date":"2026-05-06T08:25:59.206177","created_date":"2025-10-10T00:00:00"}
