{"id":"https://openalex.org/W3110850697","doi":"https://doi.org/10.1145/3427228.3427568","title":"Guide Me to Exploit: Assisted ROP Exploit Generation for ActionScript Virtual Machine","display_name":"Guide Me to Exploit: Assisted ROP Exploit Generation for ActionScript Virtual Machine","publication_year":2020,"publication_date":"2020-12-07","ids":{"openalex":"https://openalex.org/W3110850697","doi":"https://doi.org/10.1145/3427228.3427568","mag":"3110850697"},"language":"en","primary_location":{"id":"doi:10.1145/3427228.3427568","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427568","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5077727814","display_name":"Fadi Y\u0131lmaz","orcid":"https://orcid.org/0000-0002-3591-3606"},"institutions":[{"id":"https://openalex.org/I102149020","display_name":"University of North Carolina at Charlotte","ror":"https://ror.org/04dawnj30","country_code":"US","type":"education","lineage":["https://openalex.org/I102149020"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Fadi Yilmaz","raw_affiliation_strings":["University of North Carolina at Charlotte, United States of America"],"affiliations":[{"raw_affiliation_string":"University of North Carolina at Charlotte, United States of America","institution_ids":["https://openalex.org/I102149020"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045593113","display_name":"Meera Sridhar","orcid":"https://orcid.org/0000-0002-7508-5024"},"institutions":[{"id":"https://openalex.org/I102149020","display_name":"University of North Carolina at Charlotte","ror":"https://ror.org/04dawnj30","country_code":"US","type":"education","lineage":["https://openalex.org/I102149020"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Meera Sridhar","raw_affiliation_strings":["University of North Carolina at Charlotte, United States of America"],"affiliations":[{"raw_affiliation_string":"University of North Carolina at Charlotte, United States of America","institution_ids":["https://openalex.org/I102149020"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102016759","display_name":"Wontae Choi","orcid":null},"institutions":[{"id":"https://openalex.org/I1291425158","display_name":"Google (United States)","ror":"https://ror.org/00njsd438","country_code":"US","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210128969"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wontae Choi","raw_affiliation_strings":["Google"],"affiliations":[{"raw_affiliation_string":"Google","institution_ids":["https://openalex.org/I1291425158"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5077727814"],"corresponding_institution_ids":["https://openalex.org/I102149020"],"apc_list":null,"apc_paid":null,"fwci":0.6734,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.70314843,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"386","last_page":"400"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.9341789484024048},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8806408643722534},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.7638337016105652},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.654190182685852},{"id":"https://openalex.org/keywords/symbolic-execution","display_name":"Symbolic execution","score":0.6515153050422668},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.6260913610458374},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5551695823669434},{"id":"https://openalex.org/keywords/implementation","display_name":"Implementation","score":0.5313858389854431},{"id":"https://openalex.org/keywords/parsing","display_name":"Parsing","score":0.49481314420700073},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.463775098323822},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.33404824137687683},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.21416065096855164},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.13142818212509155},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.11580362915992737}],"concepts":[{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.9341789484024048},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8806408643722534},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.7638337016105652},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.654190182685852},{"id":"https://openalex.org/C2779639559","wikidata":"https://www.wikidata.org/wiki/Q7661178","display_name":"Symbolic execution","level":3,"score":0.6515153050422668},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.6260913610458374},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5551695823669434},{"id":"https://openalex.org/C26713055","wikidata":"https://www.wikidata.org/wiki/Q245962","display_name":"Implementation","level":2,"score":0.5313858389854431},{"id":"https://openalex.org/C186644900","wikidata":"https://www.wikidata.org/wiki/Q194152","display_name":"Parsing","level":2,"score":0.49481314420700073},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.463775098323822},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.33404824137687683},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.21416065096855164},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.13142818212509155},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.11580362915992737}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3427228.3427568","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427568","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.47999998927116394}],"awards":[{"id":"https://openalex.org/G408538210","display_name":null,"funder_award_id":"1566321","funder_id":"https://openalex.org/F4320322898","funder_display_name":"Shota Rustaveli National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320322898","display_name":"Shota Rustaveli National Science Foundation","ror":"https://ror.org/00xc87681"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":89,"referenced_works":["https://openalex.org/W109452506","https://openalex.org/W134490355","https://openalex.org/W157156687","https://openalex.org/W196342399","https://openalex.org/W203252516","https://openalex.org/W1167171564","https://openalex.org/W1243512957","https://openalex.org/W1459231281","https://openalex.org/W1496222301","https://openalex.org/W1531203382","https://openalex.org/W1555154029","https://openalex.org/W1710734607","https://openalex.org/W1963947298","https://openalex.org/W1979693894","https://openalex.org/W1981838014","https://openalex.org/W2001978806","https://openalex.org/W2002934700","https://openalex.org/W2025898372","https://openalex.org/W2043832938","https://openalex.org/W2055098165","https://openalex.org/W2057330156","https://openalex.org/W2057698738","https://openalex.org/W2062278092","https://openalex.org/W2065948900","https://openalex.org/W2069910799","https://openalex.org/W2094771270","https://openalex.org/W2098456636","https://openalex.org/W2099382052","https://openalex.org/W2101512909","https://openalex.org/W2102824839","https://openalex.org/W2104993088","https://openalex.org/W2113864883","https://openalex.org/W2114780348","https://openalex.org/W2123396057","https://openalex.org/W2123436168","https://openalex.org/W2128006558","https://openalex.org/W2128985333","https://openalex.org/W2137530017","https://openalex.org/W2141717815","https://openalex.org/W2153400751","https://openalex.org/W2162800072","https://openalex.org/W2163764145","https://openalex.org/W2200915860","https://openalex.org/W2216041415","https://openalex.org/W2293825325","https://openalex.org/W2491054514","https://openalex.org/W2503165018","https://openalex.org/W2506015293","https://openalex.org/W2517087431","https://openalex.org/W2534610146","https://openalex.org/W2547825552","https://openalex.org/W2574017551","https://openalex.org/W2613534458","https://openalex.org/W2617809069","https://openalex.org/W2626301739","https://openalex.org/W2740643205","https://openalex.org/W2741068848","https://openalex.org/W2743785204","https://openalex.org/W2752340395","https://openalex.org/W2757104921","https://openalex.org/W2765857833","https://openalex.org/W2766540688","https://openalex.org/W2766898821","https://openalex.org/W2777430404","https://openalex.org/W2791018263","https://openalex.org/W2795192879","https://openalex.org/W2796805080","https://openalex.org/W2808957028","https://openalex.org/W2887198767","https://openalex.org/W2889280832","https://openalex.org/W2891921447","https://openalex.org/W2905627582","https://openalex.org/W2914982603","https://openalex.org/W2947182139","https://openalex.org/W2962879711","https://openalex.org/W2964097210","https://openalex.org/W2968370566","https://openalex.org/W2974819274","https://openalex.org/W3008321987","https://openalex.org/W3017160350","https://openalex.org/W3104664063","https://openalex.org/W3106010854","https://openalex.org/W4206109607","https://openalex.org/W4232884709","https://openalex.org/W4238083723","https://openalex.org/W4244700344","https://openalex.org/W4245592134","https://openalex.org/W6604335577","https://openalex.org/W6608003788"],"related_works":["https://openalex.org/W2801797726","https://openalex.org/W2785720764","https://openalex.org/W2186070848","https://openalex.org/W4285245977","https://openalex.org/W3203826058","https://openalex.org/W340065115","https://openalex.org/W2780750120","https://openalex.org/W2284359849","https://openalex.org/W3104446232","https://openalex.org/W4290048282"],"abstract_inverted_index":{"Automatic":[0],"exploit":[1,85],"generation":[2],"(AEG)":[3],"is":[4],"the":[5,9,26,59,67,84,101,105,114,124,130],"challenge":[6],"of":[7,11,39,61,88,107,133,140],"determining":[8],"exploitability":[10],"a":[12,45,49,141],"given":[13],"vulnerability":[14],"by":[15],"exploring":[16],"all":[17],"possible":[18],"execution":[19,40,51,80,121],"paths":[20,135],"that":[21,112],"can":[22],"result":[23],"from":[24],"triggering":[25],"vulnerability.":[27],"Since":[28],"typical":[29],"AEG":[30,72],"implementations":[31,73],"might":[32],"need":[33],"to":[34,53,104,129],"explore":[35],"an":[36],"unbounded":[37],"number":[38,132],"paths,":[41],"they":[42],"usually":[43],"utilize":[44],"fuzz":[46,76,92],"tester":[47],"and":[48,118,147],"symbolic":[50,79,120],"tool":[52],"facilitate":[54],"this":[55],"task.":[56],"However,":[57],"in":[58,136],"case":[60],"language":[62,142],"virtual":[63,143],"machines,":[64],"such":[65],"as":[66],"ActionScript":[68],"Virtual":[69],"Machine":[70],"(AVM),":[71],"cannot":[74,94],"leverage":[75],"testers":[77,93],"or":[78],"tools":[81,122],"for":[82,100],"generating":[83,109],"script,":[86],"because":[87],"two":[89],"reasons:":[90],"(1)":[91],"efficiently":[95],"generate":[96],"grammatically":[97],"correct":[98],"executables":[99,111],"AVM":[102],"due":[103,128],"improbability":[106],"randomly":[108],"highly-structured":[110],"follow":[113],"complex":[115],"grammar":[116],"rules":[117],"(2)":[119],"encounter":[123],"well-known":[125],"program-state-explosion":[126],"problem":[127],"enormous":[131],"control":[134],"early":[137],"processing":[138],"stages":[139],"machine":[144],"(e.g.,":[145],"lexing":[146],"parsing).":[148]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2020,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
