The document introduces 'Buttercup,' a proactive solution to detect polymorphic buffer overflow vulnerabilities in network attacks, particularly against highly evasive polymorphic worms. It describes how traditional signature-based intrusion detection systems (IDS) struggle with these polymorphic attacks and emphasizes the effectiveness of Buttercup in identifying potential return memory address ranges to drop malicious packets with minimal false positives. The evaluation shows that Buttercup can potentially eliminate 100% of worm attack packets while sacrificing only 0.01% of legitimate traffic.