{"id":"https://openalex.org/W2167332015","doi":"https://doi.org/10.1109/secpri.2003.1199328","title":"Anomaly detection using call stack information","display_name":"Anomaly detection using call stack information","publication_year":2004,"publication_date":"2004-05-13","ids":{"openalex":"https://openalex.org/W2167332015","doi":"https://doi.org/10.1109/secpri.2003.1199328","mag":"2167332015"},"language":"en","primary_location":{"id":"doi:10.1109/secpri.2003.1199328","is_oa":false,"landing_page_url":"https://doi.org/10.1109/secpri.2003.1199328","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings 19th International Conference on Data Engineering (Cat. No.03CH37405)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://scholarworks.umass.edu/biology_faculty_pubs/330","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055626955","display_name":"H.H. Feng","orcid":null},"institutions":[{"id":"https://openalex.org/I24603500","display_name":"University of Massachusetts Amherst","ror":"https://ror.org/0072zz521","country_code":"US","type":"education","lineage":["https://openalex.org/I24603500"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"H.H. Feng","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of Massachusetts, Amherst, MA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of Massachusetts, Amherst, MA, USA","institution_ids":["https://openalex.org/I24603500"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039874248","display_name":"Oleg Kolesnikov","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"O.M. Kolesnikov","raw_affiliation_strings":["Georgia Institute of Technology, College of Computing Georgia Institute of Technology, Atlanta, GA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology, College of Computing Georgia Institute of Technology, Atlanta, GA, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034137329","display_name":"Prahlad Fogla","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"P. Fogla","raw_affiliation_strings":["Georgia Institute of Technology, College of Computing Georgia Institute of Technology, Atlanta, GA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology, College of Computing Georgia Institute of Technology, Atlanta, GA, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100689739","display_name":"Woonghee Lee","orcid":"https://orcid.org/0000-0003-0856-6415"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"W. Lee","raw_affiliation_strings":["Georgia Institute of Technology, College of Computing Georgia Institute of Technology, Atlanta, GA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology, College of Computing Georgia Institute of Technology, Atlanta, GA, USA","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5110939771","display_name":"Weibo Gong","orcid":null},"institutions":[{"id":"https://openalex.org/I24603500","display_name":"University of Massachusetts Amherst","ror":"https://ror.org/0072zz521","country_code":"US","type":"education","lineage":["https://openalex.org/I24603500"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Weibo Gong","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of Massachusetts, Amherst, MA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of Massachusetts, Amherst, MA, USA","institution_ids":["https://openalex.org/I24603500"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":29.4438,"has_fulltext":false,"cited_by_count":389,"citation_normalized_percentile":{"value":0.9968573,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"62","last_page":"75"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9965999722480774,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8511594533920288},{"id":"https://openalex.org/keywords/call-stack","display_name":"Call stack","score":0.8094351887702942},{"id":"https://openalex.org/keywords/stack","display_name":"Stack (abstract data type)","score":0.7778637409210205},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.7305602431297302},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.5827426314353943},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.5667129755020142},{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.5498339533805847},{"id":"https://openalex.org/keywords/path","display_name":"Path (computing)","score":0.5073146224021912},{"id":"https://openalex.org/keywords/convergence","display_name":"Convergence (economics)","score":0.4903152287006378},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.47191885113716125},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.44392505288124084},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.14984416961669922},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.14340943098068237},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.12014442682266235}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8511594533920288},{"id":"https://openalex.org/C119024030","wikidata":"https://www.wikidata.org/wiki/Q759899","display_name":"Call stack","level":3,"score":0.8094351887702942},{"id":"https://openalex.org/C9395851","wikidata":"https://www.wikidata.org/wiki/Q177929","display_name":"Stack (abstract data type)","level":2,"score":0.7778637409210205},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.7305602431297302},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.5827426314353943},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5667129755020142},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.5498339533805847},{"id":"https://openalex.org/C2777735758","wikidata":"https://www.wikidata.org/wiki/Q817765","display_name":"Path (computing)","level":2,"score":0.5073146224021912},{"id":"https://openalex.org/C2777303404","wikidata":"https://www.wikidata.org/wiki/Q759757","display_name":"Convergence (economics)","level":2,"score":0.4903152287006378},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.47191885113716125},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.44392505288124084},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.14984416961669922},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.14340943098068237},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.12014442682266235},{"id":"https://openalex.org/C50522688","wikidata":"https://www.wikidata.org/wiki/Q189833","display_name":"Economic growth","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0}],"mesh":[],"locations_count":8,"locations":[{"id":"doi:10.1109/secpri.2003.1199328","is_oa":false,"landing_page_url":"https://doi.org/10.1109/secpri.2003.1199328","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings 19th International Conference on Data Engineering (Cat. No.03CH37405)","raw_type":"proceedings-article"},{"id":"pmh:oai:scholarworks.umass.edu:biology_faculty_pubs-1329","is_oa":true,"landing_page_url":"https://scholarworks.umass.edu/biology_faculty_pubs/330","pdf_url":null,"source":{"id":"https://openalex.org/S4306402057","display_name":"Scholarworks (University of Massachusetts Amherst)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I24603500","host_organization_name":"University of Massachusetts Amherst","host_organization_lineage":["https://openalex.org/I24603500"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Biology Department Faculty Publication Series","raw_type":"text"},{"id":"pmh:oai:scholarworks.umass.edu:ece_faculty_pubs-1543","is_oa":false,"landing_page_url":"https://scholarworks.umass.edu/ece_faculty_pubs/544","pdf_url":null,"source":{"id":"https://openalex.org/S4306402057","display_name":"Scholarworks (University of Massachusetts Amherst)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I24603500","host_organization_name":"University of Massachusetts Amherst","host_organization_lineage":["https://openalex.org/I24603500"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Electrical and Computer Engineering Faculty Publication Series","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.1006.5301","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.1006.5301","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.ucf.edu/%7Eczou/securityPaper/vtpath.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.13.6179","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.13.6179","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cc.gatech.edu/~ok/w/ok_idpc.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.135.6989","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.135.6989","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://ise.gmu.edu/~xwangc/teaching/ISA674/IDS-Reading/SP03-callstack-IDS.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.331.9186","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.331.9186","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.uiuc.edu/homes/kingst/spring2007/cs598stk/papers/vtpath.pdf","raw_type":"text"},{"id":"pmh:oai:scholarworks.umass.edu:20.500.14394/21255","is_oa":false,"landing_page_url":"https://hdl.handle.net/20.500.14394/21255","pdf_url":null,"source":{"id":"https://openalex.org/S4306402240","display_name":"ScholarWorks@UMassAmherst (University of Massachusetts Amherst)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I24603500","host_organization_name":"University of Massachusetts Amherst","host_organization_lineage":["https://openalex.org/I24603500"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"published","raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:scholarworks.umass.edu:biology_faculty_pubs-1329","is_oa":true,"landing_page_url":"https://scholarworks.umass.edu/biology_faculty_pubs/330","pdf_url":null,"source":{"id":"https://openalex.org/S4306402057","display_name":"Scholarworks (University of Massachusetts Amherst)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I24603500","host_organization_name":"University of Massachusetts Amherst","host_organization_lineage":["https://openalex.org/I24603500"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Biology Department Faculty Publication Series","raw_type":"text"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.6499999761581421,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":28,"referenced_works":["https://openalex.org/W91862604","https://openalex.org/W1583975142","https://openalex.org/W1587265799","https://openalex.org/W1600911019","https://openalex.org/W1600965014","https://openalex.org/W1655226010","https://openalex.org/W1941427975","https://openalex.org/W2028903194","https://openalex.org/W2106649514","https://openalex.org/W2123886726","https://openalex.org/W2128217000","https://openalex.org/W2129860818","https://openalex.org/W2130523241","https://openalex.org/W2135143063","https://openalex.org/W2143776233","https://openalex.org/W2170973665","https://openalex.org/W2180474751","https://openalex.org/W2479612266","https://openalex.org/W6603716672","https://openalex.org/W6634829514","https://openalex.org/W6635224074","https://openalex.org/W6635828606","https://openalex.org/W6636991409","https://openalex.org/W6678985388","https://openalex.org/W6679563790","https://openalex.org/W6679636476","https://openalex.org/W6681189232","https://openalex.org/W6685510272"],"related_works":["https://openalex.org/W2087972928","https://openalex.org/W3015514077","https://openalex.org/W2779721357","https://openalex.org/W1527172253","https://openalex.org/W11100131","https://openalex.org/W2385758958","https://openalex.org/W1968278738","https://openalex.org/W2183313954","https://openalex.org/W3125263037","https://openalex.org/W1969635302"],"abstract_inverted_index":{"The":[0,53],"call":[1,28,50,63],"stack":[2,29,51],"of":[3,126],"a":[4,9,42,123],"program":[5,73],"execution":[6,69,74],"can":[7,81],"be":[8,87,137],"very":[10],"good":[11],"information":[12,25],"source":[13],"for":[14],"intrusion":[15],"detection.":[16],"There":[17],"is":[18,56,99],"no":[19],"prior":[20],"work":[21],"on":[22,131],"dynamically":[23],"extracting":[24],"from":[26,61],"the":[27,62,105,140],"and":[30,65,95,120,133],"effectively":[31],"using":[32,49],"it":[33],"to":[34,45,57,101],"detect":[35,82],"exploits.":[36],"In":[37],"this":[38],"paper":[39],"we":[40],"propose":[41],"new":[43],"method":[44,80,111],"do":[46],"anomaly":[47],"detection":[48],"information.":[52],"basic":[54],"idea":[55],"extract":[58],"return":[59],"addresses":[60],"stack,":[64],"generate":[66],"an":[67],"abstract":[68],"path":[70],"between":[71],"two":[72],"points.":[75],"Experiments":[76],"show":[77],"that":[78,85],"our":[79,110],"some":[83],"attacks":[84,135],"cannot":[86],"detected":[88],"by":[89,115,139],"other":[90,106,113],"approaches,":[91],"while":[92],"its":[93],"convergence":[94],"false":[96],"positive":[97],"performance":[98],"comparable":[100],"or":[102],"better":[103,124],"than":[104],"approaches.":[107,142],"We":[108],"compare":[109],"with":[112],"approaches":[114],"analyzing":[116],"their":[117,127],"underlying":[118],"principles":[119],"thus":[121],"achieve":[122],"characterization":[125],"performance,":[128],"in":[129],"particular":[130],"what":[132],"why":[134],"will":[136],"missed":[138],"various":[141]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":5},{"year":2021,"cited_by_count":9},{"year":2020,"cited_by_count":16},{"year":2019,"cited_by_count":11},{"year":2018,"cited_by_count":15},{"year":2017,"cited_by_count":15},{"year":2016,"cited_by_count":8},{"year":2015,"cited_by_count":16},{"year":2014,"cited_by_count":14},{"year":2013,"cited_by_count":19},{"year":2012,"cited_by_count":15}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
