{"id":"https://openalex.org/W2805407300","doi":"https://doi.org/10.1145/3196494.3196514","title":"Use-After-FreeMail","display_name":"Use-After-FreeMail","publication_year":2018,"publication_date":"2018-05-29","ids":{"openalex":"https://openalex.org/W2805407300","doi":"https://doi.org/10.1145/3196494.3196514","mag":"2805407300"},"language":"en","primary_location":{"id":"doi:10.1145/3196494.3196514","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3196494.3196514","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 on Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066874310","display_name":"Daniel Gruss","orcid":"https://orcid.org/0000-0002-7977-3246"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":true,"raw_author_name":"Daniel Gruss","raw_affiliation_strings":["Graz University of Technology, Graz, Austria"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology, Graz, Austria","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070469078","display_name":"Michael Schwarz","orcid":"https://orcid.org/0000-0001-6744-3410"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Michael Schwarz","raw_affiliation_strings":["Graz University of Technology, Graz, Austria"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology, Graz, Austria","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066497367","display_name":"Matthias W\u00fcbbeling","orcid":null},"institutions":[{"id":"https://openalex.org/I135140700","display_name":"University of Bonn","ror":"https://ror.org/041nas322","country_code":"DE","type":"education","lineage":["https://openalex.org/I135140700"]},{"id":"https://openalex.org/I4210166245","display_name":"Fraunhofer Institute for Communication, Information Processing and Ergonomics","ror":"https://ror.org/05nn0gw40","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210166245","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Matthias W\u00fcbbeling","raw_affiliation_strings":["Fraunhofer FKIE &amp;University of Bonn, Bonn, Germany"],"affiliations":[{"raw_affiliation_string":"Fraunhofer FKIE &amp;University of Bonn, Bonn, Germany","institution_ids":["https://openalex.org/I135140700","https://openalex.org/I4210166245"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053703505","display_name":"Simon Guggi","orcid":null},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Simon Guggi","raw_affiliation_strings":["Graz University of Technology, Graz, Austria"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology, Graz, Austria","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076277466","display_name":"Timo Malderle","orcid":null},"institutions":[{"id":"https://openalex.org/I135140700","display_name":"University of Bonn","ror":"https://ror.org/041nas322","country_code":"DE","type":"education","lineage":["https://openalex.org/I135140700"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Timo Malderle","raw_affiliation_strings":["University of Bonn, Bonn, Germany"],"affiliations":[{"raw_affiliation_string":"University of Bonn, Bonn, Germany","institution_ids":["https://openalex.org/I135140700"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009551343","display_name":"Stefan More","orcid":"https://orcid.org/0000-0001-7076-7563"},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Stefan More","raw_affiliation_strings":["Graz University of Technology, Graz, Austria"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology, Graz, Austria","institution_ids":["https://openalex.org/I4092182"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5056935116","display_name":"Moritz Lipp","orcid":null},"institutions":[{"id":"https://openalex.org/I4092182","display_name":"Graz University of Technology","ror":"https://ror.org/00d7xrm67","country_code":"AT","type":"education","lineage":["https://openalex.org/I4092182"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Moritz Lipp","raw_affiliation_strings":["Graz University of Technology, Graz, Austria"],"affiliations":[{"raw_affiliation_string":"Graz University of Technology, Graz, Austria","institution_ids":["https://openalex.org/I4092182"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5066874310"],"corresponding_institution_ids":["https://openalex.org/I4092182"],"apc_list":null,"apc_paid":null,"fwci":1.1847,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.84178858,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"297","last_page":"311"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9962000250816345,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/counterfeit","display_name":"Counterfeit","score":0.8315317630767822},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7337384819984436},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5726861357688904},{"id":"https://openalex.org/keywords/memory-safety","display_name":"Memory safety","score":0.5584429502487183},{"id":"https://openalex.org/keywords/memory-leak","display_name":"Memory leak","score":0.5009016990661621},{"id":"https://openalex.org/keywords/memory-management","display_name":"Memory management","score":0.4860292077064514},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.46191051602363586},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.44902288913726807},{"id":"https://openalex.org/keywords/buffer-overflow","display_name":"Buffer overflow","score":0.426442414522171},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.36316239833831787},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.3252074122428894},{"id":"https://openalex.org/keywords/semiconductor-memory","display_name":"Semiconductor memory","score":0.13463163375854492},{"id":"https://openalex.org/keywords/history","display_name":"History","score":0.07647472620010376}],"concepts":[{"id":"https://openalex.org/C2779356469","wikidata":"https://www.wikidata.org/wiki/Q502918","display_name":"Counterfeit","level":2,"score":0.8315317630767822},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7337384819984436},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5726861357688904},{"id":"https://openalex.org/C28180684","wikidata":"https://www.wikidata.org/wiki/Q4080983","display_name":"Memory safety","level":3,"score":0.5584429502487183},{"id":"https://openalex.org/C156731835","wikidata":"https://www.wikidata.org/wiki/Q751740","display_name":"Memory leak","level":4,"score":0.5009016990661621},{"id":"https://openalex.org/C176649486","wikidata":"https://www.wikidata.org/wiki/Q2308807","display_name":"Memory management","level":3,"score":0.4860292077064514},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.46191051602363586},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.44902288913726807},{"id":"https://openalex.org/C40842320","wikidata":"https://www.wikidata.org/wiki/Q19423","display_name":"Buffer overflow","level":2,"score":0.426442414522171},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.36316239833831787},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3252074122428894},{"id":"https://openalex.org/C98986596","wikidata":"https://www.wikidata.org/wiki/Q1143031","display_name":"Semiconductor memory","level":2,"score":0.13463163375854492},{"id":"https://openalex.org/C95457728","wikidata":"https://www.wikidata.org/wiki/Q309","display_name":"History","level":0,"score":0.07647472620010376},{"id":"https://openalex.org/C166957645","wikidata":"https://www.wikidata.org/wiki/Q23498","display_name":"Archaeology","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3196494.3196514","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3196494.3196514","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 on Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:fraunhofer.de:N-520350","is_oa":false,"landing_page_url":"http://publica.fraunhofer.de/documents/N-520350.html","pdf_url":null,"source":{"id":"https://openalex.org/S4306400801","display_name":"Publikationsdatenbank der Fraunhofer-Gesellschaft (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Fraunhofer FKIE","raw_type":"Conference Paper"},{"id":"pmh:oai:publica.fraunhofer.de:publica/403713","is_oa":false,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/403713","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.699999988079071,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G5879261213","display_name":null,"funder_award_id":"862235","funder_id":"https://openalex.org/F4320323031","funder_display_name":"\u00d6sterreichische Forschungsf\u00f6rderungsgesellschaft"}],"funders":[{"id":"https://openalex.org/F4320323031","display_name":"\u00d6sterreichische Forschungsf\u00f6rderungsgesellschaft","ror":"https://ror.org/028jc0449"},{"id":"https://openalex.org/F4320323947","display_name":"K\u00e4rntner Wirtschaftsf\u00f6rderungsfonds","ror":"https://ror.org/050f4mc80"},{"id":"https://openalex.org/F4320324794","display_name":"Steirische Wirtschaftsf\u00f6rderungsgesellschaft","ror":"https://ror.org/05x217f96"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":44,"referenced_works":["https://openalex.org/W57130263","https://openalex.org/W800118843","https://openalex.org/W1483030074","https://openalex.org/W1545087491","https://openalex.org/W1546563748","https://openalex.org/W1559551728","https://openalex.org/W1560502112","https://openalex.org/W1600184236","https://openalex.org/W1878544538","https://openalex.org/W1967504361","https://openalex.org/W1984471991","https://openalex.org/W1984816986","https://openalex.org/W1997394198","https://openalex.org/W2006809639","https://openalex.org/W2008648042","https://openalex.org/W2027116318","https://openalex.org/W2059278087","https://openalex.org/W2071565225","https://openalex.org/W2073342447","https://openalex.org/W2081036380","https://openalex.org/W2086176948","https://openalex.org/W2094257886","https://openalex.org/W2094619820","https://openalex.org/W2101041844","https://openalex.org/W2104587081","https://openalex.org/W2128885617","https://openalex.org/W2134028114","https://openalex.org/W2138386740","https://openalex.org/W2165109377","https://openalex.org/W2169270715","https://openalex.org/W2268969612","https://openalex.org/W2350778671","https://openalex.org/W2396697587","https://openalex.org/W2510523362","https://openalex.org/W2535407856","https://openalex.org/W2591614334","https://openalex.org/W2606752733","https://openalex.org/W2791815824","https://openalex.org/W2889478221","https://openalex.org/W2963647121","https://openalex.org/W3099035940","https://openalex.org/W3168213939","https://openalex.org/W4255520410","https://openalex.org/W4285719527"],"related_works":["https://openalex.org/W1583810348","https://openalex.org/W3033191713","https://openalex.org/W2899326588","https://openalex.org/W3016343721","https://openalex.org/W2182829270","https://openalex.org/W3014574736","https://openalex.org/W4249886898","https://openalex.org/W1607515776","https://openalex.org/W2102012911","https://openalex.org/W2255006515"],"abstract_inverted_index":{"Use-after-free":[0],"is":[1],"a":[2,19,22,176,187],"type":[3],"of":[4,56,75,102,125,179],"vulnerability":[5],"commonly":[6],"present":[7],"in":[8,11,143],"software":[9],"written":[10],"memory-unsafe":[12],"languages":[13],"like":[14],"C":[15],"or":[16,41],"C++,":[17],"where":[18,66],"program":[20],"frees":[21],"memory":[23,34],"buffer":[24],"too":[25],"early.":[26],"By":[27],"placing":[28],"counterfeit":[29],"structures":[30],"at":[31],"the":[32,54,162,171],"freed":[33],"location,":[35],"an":[36,73],"attacker":[37],"can":[38,58,68,140,155],"leak":[39],"information":[40,139],"gain":[42],"execution":[43],"control":[44],"upon":[45],"subsequent":[46],"access.":[47],"In":[48,112,132],"this":[49],"paper,":[50],"we":[51,78,106,121,136,174],"show":[52],"that":[53,100,123],"concept":[55],"use-after-free":[57,168,190],"be":[59,69,141,156],"generalized":[60],"to":[61,98,181],"any":[62],"environment":[63],"and":[64,118,149,170,184],"situation":[65],"resources":[67],"silently":[70],"exchanged.":[71],"As":[72],"instance":[74],"our":[76,130],"generalization":[77],"demonstrate":[79],"Use-After-FreeMail":[80,82,144,172],"attacks.":[81,191],"attacks":[83],"gather":[84],"email":[85],"addresses":[86,105],"from":[87],"publicly":[88],"available":[89],"database":[90],"leaks.":[91],"The":[92],"fully":[93],"automated":[94],"quantitative":[95],"analysis":[96],"brought":[97],"light":[99],"33.5%":[101],"all":[103],"free-mail":[104,182],"tested":[107],"are":[108,127],"not":[109],"valid":[110],"anymore.":[111],"two":[113],"user":[114],"studies":[115,135],"with":[116],"100":[117],"31":[119],"participants":[120],"found":[122],"11-19%":[124],"users":[126,185],"affected":[128],"by":[129],"attack.":[131],"qualitative":[133],"case":[134],"investigated":[137],"what":[138],"gained":[142],"attacks,":[145],"e.g.,":[146],"payment":[147],"information,":[148],"how":[150],"far":[151],"currently":[152],"used":[153],"accounts":[154],"compromised":[157],"(identity":[158],"theft).":[159],"Finally,":[160],"drawing":[161],"connection":[163],"between":[164],"mitigations":[165],"against":[166,189],"traditional":[167],"scenarios":[169],"scenario,":[173],"provide":[175],"concise":[177],"list":[178],"recommendations":[180],"providers":[183],"as":[186],"protection":[188]},"counts_by_year":[{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":4}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2018-06-13T00:00:00"}
