{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:URHMBJZYL33MDLXX66D5E5KUCP","short_pith_number":"pith:URHMBJZY","canonical_record":{"source":{"id":"1903.00503","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-01T19:26:35Z","cross_cats_sorted":[],"title_canon_sha256":"8e9e4ba3da9104b4dd8fde4836f1a57d6a5e17308e6c35e8936a7d3c406bf111","abstract_canon_sha256":"906099cb4cc99df726cb4d6b232727d8e4ceb066250026594bae2fc5efc5e2e2"},"schema_version":"1.0"},"canonical_sha256":"a44ec0a7385ef6c1aef7f787d2755413eceffc284d3d4e2019523a74579ea480","source":{"kind":"arxiv","id":"1903.00503","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.00503","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"arxiv_version","alias_value":"1903.00503v1","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.00503","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"pith_short_12","alias_value":"URHMBJZYL33M","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"URHMBJZYL33MDLXX","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"URHMBJZY","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:URHMBJZYL33MDLXX66D5E5KUCP","target":"record","payload":{"canonical_record":{"source":{"id":"1903.00503","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-01T19:26:35Z","cross_cats_sorted":[],"title_canon_sha256":"8e9e4ba3da9104b4dd8fde4836f1a57d6a5e17308e6c35e8936a7d3c406bf111","abstract_canon_sha256":"906099cb4cc99df726cb4d6b232727d8e4ceb066250026594bae2fc5efc5e2e2"},"schema_version":"1.0"},"canonical_sha256":"a44ec0a7385ef6c1aef7f787d2755413eceffc284d3d4e2019523a74579ea480","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:52:14.283087Z","signature_b64":"rgRvq56+xqItIxDLOk9WoE5eyOjVw25vrT87ow1vJXGK7e9fnZuc0Y1JOujpB92Uo7YyoxRHMC/zGAtuT5A3Bw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a44ec0a7385ef6c1aef7f787d2755413eceffc284d3d4e2019523a74579ea480","last_reissued_at":"2026-05-17T23:52:14.282303Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:52:14.282303Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1903.00503","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:52:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6i0+pMl/6jEN4A1J20Sh4BF6vOVpJ3L72qKlBZy5ZEYrfY3+mKvkpdZJUE0sCGDGv+J/HYafZLh/JV+erQcTDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T01:43:20.495354Z"},"content_sha256":"4fcce58393cb55c3174dc3513f2624961a7ca7f433202093610b0247fa0a45ed","schema_version":"1.0","event_id":"sha256:4fcce58393cb55c3174dc3513f2624961a7ca7f433202093610b0247fa0a45ed"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:URHMBJZYL33MDLXX66D5E5KUCP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Automatic Techniques to Systematically Discover New Heap Exploitation Primitives","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dhaval Kapil, Insu Yun, Taesoo Kim","submitted_at":"2019-03-01T19:26:35Z","abstract_excerpt":"Heap exploitation techniques to abuse the metadata of allocators have been widely studied since they are application independent and can be used in restricted environments that corrupt only metadata. Although prior work has found several interesting exploitation techniques, they are ad-hoc and manual, which cannot effectively handle changes or a variety of allocators.\n  In this paper, we present a new naming scheme for heap exploitation techniques that systematically organizes them to discover the unexplored space in finding the techniques and ArcHeap, the tool that finds heap exploitation tec"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.00503","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:52:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"B2nqAkGBTIGpC5w3hjKoK68aEA634YaPjxXn9xMEIH+tJS2LCToWYv/FPplrI1WCwBW4YgTRbi88rg2VImYgDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T01:43:20.495709Z"},"content_sha256":"c4f055cb9450dcc3bfeaaf4d85d3fa645859a00d5209243a52a0eb0723b0d1f5","schema_version":"1.0","event_id":"sha256:c4f055cb9450dcc3bfeaaf4d85d3fa645859a00d5209243a52a0eb0723b0d1f5"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/URHMBJZYL33MDLXX66D5E5KUCP/bundle.json","state_url":"https://pith.science/pith/URHMBJZYL33MDLXX66D5E5KUCP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/URHMBJZYL33MDLXX66D5E5KUCP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T01:43:20Z","links":{"resolver":"https://pith.science/pith/URHMBJZYL33MDLXX66D5E5KUCP","bundle":"https://pith.science/pith/URHMBJZYL33MDLXX66D5E5KUCP/bundle.json","state":"https://pith.science/pith/URHMBJZYL33MDLXX66D5E5KUCP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/URHMBJZYL33MDLXX66D5E5KUCP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:URHMBJZYL33MDLXX66D5E5KUCP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"906099cb4cc99df726cb4d6b232727d8e4ceb066250026594bae2fc5efc5e2e2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-01T19:26:35Z","title_canon_sha256":"8e9e4ba3da9104b4dd8fde4836f1a57d6a5e17308e6c35e8936a7d3c406bf111"},"schema_version":"1.0","source":{"id":"1903.00503","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.00503","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"arxiv_version","alias_value":"1903.00503v1","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.00503","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"pith_short_12","alias_value":"URHMBJZYL33M","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"URHMBJZYL33MDLXX","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"URHMBJZY","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:c4f055cb9450dcc3bfeaaf4d85d3fa645859a00d5209243a52a0eb0723b0d1f5","target":"graph","created_at":"2026-05-17T23:52:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Heap exploitation techniques to abuse the metadata of allocators have been widely studied since they are application independent and can be used in restricted environments that corrupt only metadata. Although prior work has found several interesting exploitation techniques, they are ad-hoc and manual, which cannot effectively handle changes or a variety of allocators.\n  In this paper, we present a new naming scheme for heap exploitation techniques that systematically organizes them to discover the unexplored space in finding the techniques and ArcHeap, the tool that finds heap exploitation tec","authors_text":"Dhaval Kapil, Insu Yun, Taesoo Kim","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-01T19:26:35Z","title":"Automatic Techniques to Systematically Discover New Heap Exploitation Primitives"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.00503","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4fcce58393cb55c3174dc3513f2624961a7ca7f433202093610b0247fa0a45ed","target":"record","created_at":"2026-05-17T23:52:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"906099cb4cc99df726cb4d6b232727d8e4ceb066250026594bae2fc5efc5e2e2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-01T19:26:35Z","title_canon_sha256":"8e9e4ba3da9104b4dd8fde4836f1a57d6a5e17308e6c35e8936a7d3c406bf111"},"schema_version":"1.0","source":{"id":"1903.00503","kind":"arxiv","version":1}},"canonical_sha256":"a44ec0a7385ef6c1aef7f787d2755413eceffc284d3d4e2019523a74579ea480","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a44ec0a7385ef6c1aef7f787d2755413eceffc284d3d4e2019523a74579ea480","first_computed_at":"2026-05-17T23:52:14.282303Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:52:14.282303Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"rgRvq56+xqItIxDLOk9WoE5eyOjVw25vrT87ow1vJXGK7e9fnZuc0Y1JOujpB92Uo7YyoxRHMC/zGAtuT5A3Bw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:52:14.283087Z","signed_message":"canonical_sha256_bytes"},"source_id":"1903.00503","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4fcce58393cb55c3174dc3513f2624961a7ca7f433202093610b0247fa0a45ed","sha256:c4f055cb9450dcc3bfeaaf4d85d3fa645859a00d5209243a52a0eb0723b0d1f5"],"state_sha256":"dba9052e125098393135610dbafca547ef1f5bd98b7fff63197b2f4479c3bb4f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"17NkIdXuvYYhWFwhpirRsd44erpi5PT9nfrCSV89rV/OzItMDQu1xASDGYWT28T+hDefWvaRIJaDhyQPiwnxCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T01:43:20.497676Z","bundle_sha256":"5e22992b48dc8c4ce3b63055e277b1840429c438a0459989958f3b2cd5fe9939"}}