{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T20:00:17Z","timestamp":1743105617735,"version":"3.40.3"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030868895"},{"type":"electronic","value":"9783030868901"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-86890-1_4","type":"book-chapter","created":{"date-parts":[[2021,9,17]],"date-time":"2021-09-17T00:49:44Z","timestamp":1631839784000},"page":"59-77","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Certified Malware in South Korea: A Localized Study of Breaches of Trust in Code-Signing PKI Ecosystem"],"prefix":"10.1007","author":[{"given":"Bumjun","family":"Kwon","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sanghyun","family":"Hong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuseok","family":"Jeon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Doowon","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,17]]},"reference":[{"unstructured":"What should i do with the annoying ads? (in Korean) https:\/\/www.donga.com\/news\/Economy\/article\/all\/20140914\/66399483\/1. Accessed 03 Sept 2020","key":"4_CR1"},{"unstructured":"N. Korea fakes \u2018code signing\u2019 to spread spyware. KBS world radio. http:\/\/world.kbs.co.kr\/service\/news_view.htm?lang=e&Seq_Code=119375. Accessed 30 Aug 2020","key":"4_CR2"},{"unstructured":"To bypass code-signing checks, malware gang steals lots of certificates. ars technica. https:\/\/arstechnica.com\/information-technology\/2016\/03\/to-bypass-code-signing-checks-malware-gang-steals-lots-of-certificates\/. Accessed 30 Aug 2020","key":"4_CR3"},{"unstructured":"Adobe. Electronic Signature Laws and Regulations - South Korea (2020). https:\/\/helpx.adobe.com\/sign\/using\/legality-south-korea.html","key":"4_CR4"},{"doi-asserted-by":"crossref","unstructured":"Alrawi, O., Mohaisen, A.: Chains of distrust: towards understanding certificates used for signing malicious applications. In: WWW 2016, Republic and Canton of Geneva, Switzerland (2016)","key":"4_CR5","DOI":"10.1145\/2872518.2888610"},{"issue":"3","key":"4_CR6","first-page":"77","volume":"9","author":"S-W Chai","year":"2015","unstructured":"Chai, S.-W., Min, K.-S., Lee, J.-H.: A study of issues about accredited certification methods in Korea. Int. J. Secur. Appl. 9(3), 77\u201384 (2015)","journal-title":"Int. J. Secur. Appl."},{"unstructured":"Code Signing Working Group. Minimum requirements for the issuance and management of publicly-trusted code signing certificates. Technical report (2016)","key":"4_CR7"},{"doi-asserted-by":"crossref","unstructured":"Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., Polk, W.: Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile. RFC 5280. RFC Editor (May 2008). http:\/\/www.rfc-editor.org\/rfc\/rfc5280.txt","key":"4_CR8","DOI":"10.17487\/rfc5280"},{"unstructured":"Durumeric, Z., Wustrow, E., Halderman, J.A.: ZMap: fast internet-wide scanning and its security applications. In: Proceedings of the 22Nd USENIX Conference on Security, SEC 2013, Berkeley, CA, USA, pp. 605\u2013620. USENIX Association (2013)","key":"4_CR9"},{"unstructured":"Falliere, N., O\u2019Murchu, L., Chien, E.: W32.Stuxnet dossier. Symantec Whitepaper (February 2011)","key":"4_CR10"},{"unstructured":"Geater, J.: How to remove Kraddare. https:\/\/www.solvusoft.com\/en\/malware\/potentially-unwanted-application\/kraddare\/","key":"4_CR11"},{"unstructured":"Google: Announcing the first SHA1 collision (February 2017)","key":"4_CR12"},{"doi-asserted-by":"crossref","unstructured":"Kim, D., Kwon, B. J., Dumitras, T.: Certified malware: measuring breaches of trust in the windows code-signing PKI. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017 (2017)","key":"4_CR13","DOI":"10.1145\/3133956.3133958"},{"unstructured":"Kim, D., Kwon, B.J., Koz\u00e1k, K., Gates, C., Dumitras, T.: The broken shield: measuring revocation effectiveness in the windows code-signing PKI. In: 27th USENIX Security Symposium, USENIX Security 2018. USENIX Association (2018)","key":"4_CR14"},{"unstructured":"KLRI: Digital Signature Act, 2017. https:\/\/elaw.klri.re.kr\/eng_service\/lawView.do?hseq=42625&lang=ENG","key":"4_CR15"},{"unstructured":"Kotzias, P., Bilge, L., Caballero, J.: Measuring PUP prevalence and pup distribution through pay-per-install services. In: Proceedings of the USENIX Security Symposium (2016)","key":"4_CR16"},{"doi-asserted-by":"crossref","unstructured":"Kotzias, P., Matic, S., Rivera, R., Caballero, J.: Certified PUP: abuse in authenticode code signing. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS 2015. ACM, New York (2015)","key":"4_CR17","DOI":"10.1145\/2810103.2813665"},{"unstructured":"Koz\u00e1k, K., Kwon, B.J., Kim, D., Gates, C., Dumitra\u015f, T.: Issued for abuse: measuring the underground trade in code signing certificate. In: 17th Annual Workshop on the Economics of Information Security (WEIS) (2018)","key":"4_CR18"},{"doi-asserted-by":"crossref","unstructured":"Kwon, B.J., Srinivas, V., Deshpande, A., Dumitras, T.: Catching worms, trojan horses and pups: unsupervised detection of silent delivery campaigns. In: 24th Annual Network and Distributed System Security Symposium, NDSS 2017 (2017)","key":"4_CR19","DOI":"10.14722\/ndss.2017.23220"},{"unstructured":"Microsoft: Microsoft security advisory: update for deprecation of MD5 hashing algorithm for Microsoft root certificate program, 13 August 2013","key":"4_CR20"},{"unstructured":"Microsoft: Trojan:win32\/delf. https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Trojan:Win32\/Delf","key":"4_CR21"},{"unstructured":"Microsoft: Trojan:win32\/kraddare. https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Trojan:Win32\/Kraddare","key":"4_CR22"},{"unstructured":"Microsoft: Win32\/onescan. https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?name=win32%2Fonescan","key":"4_CR23"},{"unstructured":"Microsoft: Erroneous VeriSign-issued Digital Certificates Pose Spoofing Hazard (2001)","key":"4_CR24"},{"unstructured":"Microsoft: Windows Authenticode portable executable signature format (March 2008). http:\/\/download.microsoft.com\/download\/9\/c\/5\/9c5b2167-8017-4bae-9fde-d599bac8184a\/Authenticode_PE.docx","key":"4_CR25"},{"unstructured":"Morowczynski, M.: SHA-1 deprecation and changing the root CA\u2019s hash algorithm (2018)","key":"4_CR26"},{"unstructured":"Niemela, J.: It\u2019s Signed, therefore it\u2019s Clean, right? (2010)","key":"4_CR27"},{"unstructured":"NLIC: Electronic Financial Transaction Act, 2017. http:\/\/www.law.go.kr\/eng\/engLsSc.do?menuId=1&query=electronic+financial+transactions+act&x=0&y=0#liBgcolor0","key":"4_CR28"},{"doi-asserted-by":"crossref","unstructured":"Park, H.M.: The web accessibility crisis of the Korea\u2019s electronic government: fatal consequences of the digital signature law and public key certificate. In: 2012 45th Hawaii International Conference on System Sciences, pp. 2319\u20132328. IEEE (2012)","key":"4_CR29","DOI":"10.1109\/HICSS.2012.591"},{"key":"4_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1007\/978-3-319-45719-2_11","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"M Sebasti\u00e1n","year":"2016","unstructured":"Sebasti\u00e1n, M., Rivera, R., Kotzias, P., Caballero, J.: AVclass: a tool for massive malware labeling. In: Monrose, F., Dacier, M., Blanc, G., Garcia-Alfaro, J. (eds.) RAID 2016. LNCS, vol. 9854, pp. 230\u2013253. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-45719-2_11"},{"unstructured":"Swiat: Flame malware collision attack explained (June 2012)","key":"4_CR31"},{"unstructured":"Wood, M.: Want my autograph? The use and abuse of digital signatures by malware. In: Virus Bulletin Conference, September 2010, pp. 1\u20138 (September 2010)","key":"4_CR32"},{"doi-asserted-by":"crossref","unstructured":"Yilek, S., Rescorla, E., Shacham, H., Enright, B., Savage, S.: When private keys are public: results from the 2008 Debian OpenSSL vulnerability. In: Proceedings of the 9th ACM SIGCOMM Conference on Internet Measurement, IMC 2009. ACM (2009)","key":"4_CR33","DOI":"10.1145\/1644893.1644896"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-86890-1_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,17]],"date-time":"2021-09-17T00:59:38Z","timestamp":1631840378000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-86890-1_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030868895","9783030868901"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-86890-1_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"17 September 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information and Communications Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Chongqing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icics2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.icics.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"182","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"49","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}