{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T18:01:59Z","timestamp":1768413719243,"version":"3.49.0"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030302146","type":"print"},{"value":"9783030302153","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-30215-3_18","type":"book-chapter","created":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T23:02:43Z","timestamp":1567378963000},"page":"360-380","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["An Analysis of Malware Trends in Enterprise Networks"],"prefix":"10.1007","author":[{"given":"Abbas","family":"Acar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Long","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"A. Selcuk","family":"Uluagac","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,9,2]]},"reference":[{"key":"18_CR1","unstructured":"2017 Q2 quarterly threat report. \n                      https:\/\/www.esentire.com\/resources\/knowledge\/2017-q2-quarterly-threat-report\/\n                      \n                    . Accessed 28 Sept 2018"},{"key":"18_CR2","unstructured":"2017 state of malware. \n                      https:\/\/www.malwarebytes.com\/pdf\/white-papers\/CTNT-Q4-17.pdf?aliId=91372483\n                      \n                    . Accessed 25 Sept 2018"},{"key":"18_CR3","unstructured":"Combating a spate of java malware with machine learning in real-time. \n                      https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/2017\/04\/20\/combating-a-wave-of-java-malware-with-machine-learning-in-real-time\/\n                      \n                    . Accessed 17 Sept 2018"},{"key":"18_CR4","unstructured":"CVE details. The ultimate security vulnerbility datasource. \n                      https:\/\/www.cvedetails.com\/\n                      \n                    . Accessed 20 Sept 2018"},{"key":"18_CR5","unstructured":"Data Breach Investigations Report (DBIR). \n                      https:\/\/www.verizonenterprise.com\/resources\/reports\/rp_DBIR_2018_Report_en_xg.pdf\n                      \n                    . Accessed 20 Sept 2018"},{"key":"18_CR6","unstructured":"ENISA threat landscape report 2017. \n                      https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-report-2017\/at_download\/fullReport\n                      \n                    . Accessed 23 Sept 2018"},{"key":"18_CR7","unstructured":"Fireeye warns \u2018massive\u2019 locky ransomware campaign hits America. \n                      https:\/\/blog.knowbe4.com\/fireeye-warns-massive-locky-ransomware-campaign-hits-america\n                      \n                    . Accessed 25 Sept 2018"},{"key":"18_CR8","unstructured":"Microsoft security intelligence report volume 20\u2014July through December 2015. \n                      http:\/\/download.microsoft.com\/download\/E\/8\/B\/E8B5CEE5-9FF6-4419-B7BF-698D2604E2B2\/Microsoft_Security_Intelligence_Report_Volume_20_English.pdf\n                      \n                    . Accessed 23 Sept 2018"},{"key":"18_CR9","unstructured":"More cyber-attacks occur on weekends than a weekday, study reveals. \n                      http:\/\/www.eweek.com\/security\/more-cyber-attacks-occur-on-weekends-than-a-weekday-study-reveals\n                      \n                    . Accessed 28 Sept 2018"},{"key":"18_CR10","unstructured":"New feature in office 2016 can block macros and help prevent infection. \n                      https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/2016\/03\/22\/new-feature-in-office-2016-can-block-macros-and-help-prevent-infection\/\n                      \n                    . Accessed 17 Sept 2018"},{"key":"18_CR11","unstructured":"Symantec 2017 internet security threat report. \n                      https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/reports\/istr-22-2017-en.pdf\n                      \n                    . Accessed 25 Sept 2018"},{"key":"18_CR12","unstructured":"Symantec 2017 internet security threat report. \n                      https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/reports\/istr-23-2018-en.pdf\n                      \n                    . Accessed 16 Oct 2018"},{"key":"18_CR13","unstructured":"What is wannacry ransomware and why is it attacking global computers?. \n                      https:\/\/www.theguardian.com\/technology\/2017\/may\/12\/nhs-ransomware-cyber-attack-what-is-wanacrypt0r-20\n                      \n                    . Accessed 25 Sept 2018"},{"key":"18_CR14","unstructured":"Bayer, U., Comparetti, P.M., Hlauschek, C., Kruegel, C., Kirda, E.: Scalable, behavior-based malware clustering. In: NDSS, vol. 9, pp. 8\u201311. Citeseer (2009)"},{"key":"18_CR15","doi-asserted-by":"crossref","unstructured":"Hu, X., Chiueh, T.C., Shin, K.G.: Large-scale malware indexing using function-call graphs. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, pp. 611\u2013620. ACM (2009)","DOI":"10.1145\/1653662.1653736"},{"key":"18_CR16","doi-asserted-by":"crossref","unstructured":"Invernizzi, L., et al.: Nazca: detecting malware distribution in large-scale networks. In: NDSS, vol. 14, pp. 23\u201326 (2014)","DOI":"10.14722\/ndss.2014.23269"},{"key":"18_CR17","doi-asserted-by":"crossref","unstructured":"Kotzias, P., Bilge, L., Vervier, P.A., Caballero, J.: Mind your own business: a longitudinal study of threats and vulnerabilities in enterprises. In: NDSS (2019)","DOI":"10.14722\/ndss.2019.23522"},{"key":"18_CR18","unstructured":"Le Blond, S., Uritesc, A., Gilbert, C., Chua, Z.L., Saxena, P., Kirda, E.: A look at targeted attacks through the lense of an NGO. In: USENIX Security Symposium, pp. 543\u2013558 (2014)"},{"key":"18_CR19","doi-asserted-by":"publisher","unstructured":"Li, Z., Oprea, A.: Operational security log analytics for enterprise breach detection. In: 2016 IEEE Cybersecurity Development (SecDev), pp. 15\u201322, November 2016. \n                      https:\/\/doi.org\/10.1109\/SecDev.2016.015","DOI":"10.1109\/SecDev.2016.015"},{"key":"18_CR20","doi-asserted-by":"publisher","unstructured":"Oprea, A., Li, Z., Yen, T., Chin, S.H., Alrwais, S.: Detection of early-stage enterprise infection by mining large-scale log data. In: 2015 45th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 45\u201356, June 2015. \n                      https:\/\/doi.org\/10.1109\/DSN.2015.14","DOI":"10.1109\/DSN.2015.14"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Lanzi, A., Lee, W.: McBoost: boosting scalability in malware collection and analysis using statistical classification of executables. In: 2008 Annual Computer Security Applications Conference (ACSAC), pp. 301\u2013310. IEEE (2008)","DOI":"10.1109\/ACSAC.2008.22"},{"key":"18_CR22","doi-asserted-by":"crossref","unstructured":"Tamersoy, A., Roundy, K., Chau, D.H.: Guilt by association: large scale malware detection by mining file-relation graphs. In: Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1524\u20131533. ACM (2014)","DOI":"10.1145\/2623330.2623342"},{"key":"18_CR23","doi-asserted-by":"publisher","unstructured":"Yen, T.F., Heorhiadi, V., Oprea, A., Reiter, M.K., Juels, A.: An epidemiological study of malware encounters in a large enterprise. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS 2014, pp. 1117\u20131130. ACM, New York (2014). \n                      https:\/\/doi.org\/10.1145\/2660267.2660330","DOI":"10.1145\/2660267.2660330"},{"key":"18_CR24","doi-asserted-by":"publisher","unstructured":"Yen, T.F., et al.: Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks. In: Proceedings of the 29th Annual Computer Security Applications Conference, ACSAC 2013, pp. 199\u2013208, ACM, New York (2013). \n                      https:\/\/doi.org\/10.1145\/2523649.2523670","DOI":"10.1145\/2523649.2523670"}],"container-title":["Lecture Notes in Computer Science","Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-30215-3_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T23:31:37Z","timestamp":1567380697000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-30215-3_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030302146","9783030302153"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-30215-3_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"2 September 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ISC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"New York City, NY","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 September 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"isw2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/isc2019.cs.stonybrook.edu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"86","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"23","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5-7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}