{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T15:56:02Z","timestamp":1780502162091,"version":"3.54.1"},"publisher-location":"Cham","reference-count":40,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030870485","type":"print"},{"value":"9783030870492","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-87049-2_25","type":"book-chapter","created":{"date-parts":[[2022,3,3]],"date-time":"2022-03-03T05:04:20Z","timestamp":1646283860000},"page":"685-710","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Malware Forensics: Legacy Solutions, Recent Advances, and\u00a0Future Challenges"],"prefix":"10.1007","author":[{"given":"Farid","family":"Na\u00eft-Abdesselam","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Asim","family":"Darwaish","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chafiq","family":"Titouna","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,3,3]]},"reference":[{"key":"25_CR1","doi-asserted-by":"publisher","unstructured":"Ye, Y., Li, T., Zhu, S., Zhuang, W., Tas, E., Gupta, U., Abdulhayoglu, M. (2011). Combining file content and file relations for cloud based malware detection, pp. 222\u2013230. https:\/\/doi.org\/10.1145\/2020408.2020448","DOI":"10.1145\/2020408.2020448"},{"key":"25_CR2","unstructured":"Hardy, W., Chen, L., Hou, S., Ye, Y., Li, X.: DL4MD: a deep learning framework for intelligent malware detection. In: Proceedings of the International Conference on Data Mining (DMIN), p. 61. The Steering Committee of the World Congress in Computer Science, Computer Engineering and Applied Computing (WorldComp) (2016)"},{"key":"25_CR3","doi-asserted-by":"crossref","unstructured":"Alam, M.S., Vuong, S.T.: Random forest classification for detecting android malware. In: 2013 IEEE International Conference on Green Computing and Communications and IEEE Internet of Things and IEEE Cyber, Physical and Social Computing, pp. 663\u2013669. IEEE (2013)","DOI":"10.1109\/GreenCom-iThings-CPSCom.2013.122"},{"issue":"11","key":"25_CR4","doi-asserted-by":"publisher","first-page":"3353","DOI":"10.1007\/s00521-017-2914-y","volume":"30","author":"HJ Zhu","year":"2018","unstructured":"Zhu, H.J., Jiang, T.H., Ma, B., You, Z.H., Shi, W.L., Cheng, L.: HEMD: a highly efficient random forest-based malware detection framework for Android. Neural Comput. Appl. 30(11), 3353\u20133361 (2018)","journal-title":"Neural Comput. Appl."},{"key":"25_CR5","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., Hubner, M., Gascon, H., Rieck, K., Siemens, C.E.R.T.: Drebin: effective and explainable detection of android malware in your pocket. In: NDSS, vol. 14, pp. 23\u201326 (2014)","DOI":"10.14722\/ndss.2014.23247"},{"key":"25_CR6","doi-asserted-by":"publisher","unstructured":"Sung, A., Xu, J., Chavez, P., Mukkamala, S.: Static analyzer of vicious executables (SAVE). In: Proceedings\u2014Annual Computer Security Applications Conference, ACSAC, pp. 326\u2013334 (2005). https:\/\/doi.org\/10.1109\/CSAC.2004.37","DOI":"10.1109\/CSAC.2004.37"},{"key":"25_CR7","unstructured":"Christodorescu, M., Jha, S.: Static analysis of executables to detect malicious patterns. In: Proceedings of the 12th Conference on USENIX Security Symposium\u2014Volume 12 (SSYM\u201903). USENIX Association, USA (2003)"},{"key":"25_CR8","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1145\/1007512.1007518","volume":"29","author":"M Christodorescu","year":"2004","unstructured":"Christodorescu, M., Jha, S.: Testing malware detectors. ACM SIGSOFT Softw. Eng. Notes 29, 34\u201344 (2004). https:\/\/doi.org\/10.1145\/1007512.1007518","journal-title":"ACM SIGSOFT Softw. Eng. Notes"},{"key":"25_CR9","doi-asserted-by":"publisher","unstructured":"Shanmugam, G., Low, R., Stamp, M.: Simple substitution distance and metamorphic detection. J. Comput. Virol. Hacking Tech. 9 (2013). https:\/\/doi.org\/10.1007\/s11416-013-0184-5","DOI":"10.1007\/s11416-013-0184-5"},{"key":"25_CR10","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11416-006-0028-7","volume":"2","author":"W Wong","year":"2006","unstructured":"Wong, W., Stamp, M.: Hunting for metamorphic engines. J. Comput. Virol. 2, 211\u2013229 (2006). https:\/\/doi.org\/10.1007\/s11416-006-0028-7","journal-title":"J. Comput. Virol."},{"key":"25_CR11","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/s11416-011-0153-9","volume":"7","author":"I Sorokin","year":"2011","unstructured":"Sorokin, I.: Comparing files using structural entropy. J. Comput. Virol. 7, 259\u2013265 (2011). https:\/\/doi.org\/10.1007\/s11416-011-0153-9","journal-title":"J. Comput. Virol."},{"key":"25_CR12","doi-asserted-by":"publisher","unstructured":"Baysa, D., Low, R., Stamp, M.: Structural entropy and metamorphic malware. J. Comput. Virol. Hacking Tech. 9 (2013). https:\/\/doi.org\/10.1007\/s11416-013-0185-4","DOI":"10.1007\/s11416-013-0185-4"},{"key":"25_CR13","unstructured":"Sz\u00f6r, P., Ferrie, P.: Hunting for metamorphic. In: Virus Bulletin Conference (2001)"},{"key":"25_CR14","doi-asserted-by":"publisher","unstructured":"Runwal, N., Low, R., Stamp, M.: OpCode graph similarity and metamorphic detection. J. Comput. Virol. 8 (2012). https:\/\/doi.org\/10.1007\/s11416-012-0160-5","DOI":"10.1007\/s11416-012-0160-5"},{"key":"25_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11416-012-0171-2","volume":"9","author":"M Stamp","year":"2013","unstructured":"Stamp, M., Toderici, A.: Chi-squared distance and metamorphic virus detection. J. Comput. Virol. Hacking Tech. 9, 1\u201314 (2013). https:\/\/doi.org\/10.1007\/s11416-012-0171-2","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"25_CR16","doi-asserted-by":"publisher","unstructured":"Zheng, M., Sun, M., Lui, J.C.S.: Droid analytics: a signature based analytic system to collect, extract, analyze and associate Android malware. In: 2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, Melbourne, VIC, 2013, pp. 163\u2013171. https:\/\/doi.org\/10.1109\/TrustCom.2013.25","DOI":"10.1109\/TrustCom.2013.25"},{"issue":"12","key":"25_CR17","doi-asserted-by":"publisher","first-page":"2754","DOI":"10.1109\/TMC.2018.2880731","volume":"18","author":"T Gao","year":"2019","unstructured":"Gao, T., Peng, W., Sisodia, D., Saha, T.K., Li, F., Al Hasan, M.: Android malware detection via graphlet sampling. IEEE Trans. Mob. Comput. 18(12), 2754\u20132767 (2019). https:\/\/doi.org\/10.1109\/TMC.2018.2880731","journal-title":"IEEE Trans. Mob. Comput."},{"key":"25_CR18","doi-asserted-by":"publisher","unstructured":"Wu, D., Mao, C., Wei, T., Lee, H., Wu, K.: DroidMat: Android malware detection through manifest and API calls tracing. In: 2012 Seventh Asia Joint Conference on Information Security, Tokyo, 2012, pp. 62\u201369. https:\/\/doi.org\/10.1109\/AsiaJCIS.2012.18","DOI":"10.1109\/AsiaJCIS.2012.18"},{"key":"25_CR19","doi-asserted-by":"publisher","unstructured":"Peiravian, N., Zhu, X.: Machine learning for android malware detection using permission and API calls. In: 2013 IEEE 25th International Conference on Tools with Artificial Intelligence, Herndon, VA, 2013, pp. 300\u2013305. https:\/\/doi.org\/10.1109\/ICTAI.2013.53","DOI":"10.1109\/ICTAI.2013.53"},{"key":"25_CR20","doi-asserted-by":"publisher","unstructured":"Chan, P.P.K., Song, W.-K.: Static detection of Android malware by using permissions and API calls. In: 2014 International Conference on Machine Learning and Cybernetics, Lanzhou, 2014, pp. 82\u201387. https:\/\/doi.org\/10.1109\/ICMLC.2014.7009096","DOI":"10.1109\/ICMLC.2014.7009096"},{"key":"25_CR21","doi-asserted-by":"publisher","unstructured":"Liang, S., Du, X.: Permission-combination-based scheme for Android mobile malware detection. In: 2014 IEEE International Conference on Communications (ICC), Sydney, NSW, 2014, pp. 2301\u20132306. https:\/\/doi.org\/10.1109\/ICC.2014.6883666","DOI":"10.1109\/ICC.2014.6883666"},{"key":"25_CR22","doi-asserted-by":"publisher","unstructured":"Wang, Z., Li, K., Hu, Y., Fukuda, A., Kong, W.: Multilevel permission extraction in Android applications for malware detection. In: 2019 International Conference on Computer, Information and Telecommunication Systems (CITS), Beijing, China, 2019, pp. 1\u20135. https:\/\/doi.org\/10.1109\/CITS.2019.8862060","DOI":"10.1109\/CITS.2019.8862060"},{"key":"25_CR23","doi-asserted-by":"publisher","unstructured":"Kapoor, A., Kushwaha, H., Gandotra, E.: Permission based Android malicious application detection using machine learning. In: 2019 International Conference on Signal Processing and Communication (ICSC), Noida, India, 2019, pp. 103\u2013108. https:\/\/doi.org\/10.1109\/ICSC45622.2019.8938236","DOI":"10.1109\/ICSC45622.2019.8938236"},{"key":"25_CR24","doi-asserted-by":"publisher","unstructured":"Saleem, M.S., Mi\u0161i\u0107, J., \u0161i\u0107, V.B.: Examining permission patterns in Android apps using Kernel density estimation. In: 2020 International Conference on Computing, Networking and Communications (ICNC), Big Island, HI, USA, 2020, pp. 719\u2013724. https:\/\/doi.org\/10.1109\/ICNC47757.2020.9049820","DOI":"10.1109\/ICNC47757.2020.9049820"},{"key":"25_CR25","unstructured":"Kolbitsch, C., Comparetti, P., Kruegel, C., Kirda, E., Zhou, X.-y., Wang, X.: Effective and efficient malware detection at the end host. In: USENIX Security Symposium, pp. 351\u2013366 (2009)"},{"key":"25_CR26","doi-asserted-by":"publisher","unstructured":"Burguera, I., Zurutuza, U., Nadjm-Tehrani, S.: Crowdroid: behavior-based malware detection system for Android. In: SPSM \u201911, pp. 15\u201326 (2011). https:\/\/doi.org\/10.1145\/2046614.2046619","DOI":"10.1145\/2046614.2046619"},{"key":"25_CR27","doi-asserted-by":"publisher","unstructured":"Mohaisen, A., Alrawi, O., Mohaisen, M.: AMAL: high-fidelity, behavior-based automated malware analysis and classification. Comput. Secur. (2015). https:\/\/doi.org\/10.1016\/j.cose.2015.04.001","DOI":"10.1016\/j.cose.2015.04.001"},{"key":"25_CR28","doi-asserted-by":"publisher","unstructured":"Nikolopoulos, S., Polenakis, I.: A graph-based model for malware detection and classification using system-call groups. J. Comput. Virol. Hacking Tech. 13 (2016). https:\/\/doi.org\/10.1007\/s11416-016-0267-1","DOI":"10.1007\/s11416-016-0267-1"},{"issue":"1","key":"25_CR29","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/TDSC.2016.2536605","volume":"15","author":"A Saracino","year":"2018","unstructured":"Saracino, A., Sgandurra, D., Dini, G., Martinelli, F.: MADAM: effective and efficient behavior-based Android malware detection and prevention. IEEE Trans. Depend. Secure Comput. 15(1), 83\u201397 (2018). https:\/\/doi.org\/10.1109\/TDSC.2016.2536605","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"25_CR30","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1016\/j.cogsys.2019.03.007","volume":"56","author":"C Choi","year":"2019","unstructured":"Choi, C., Esposito, C., Lee, M., Choi, J.: Metamorphic malicious code behavior detection using probabilistic inference methods. Cognit. Syst. Res. 56, 142\u2013150 (2019)","journal-title":"Cognit. Syst. Res."},{"key":"25_CR31","doi-asserted-by":"publisher","unstructured":"Song, F., Touili, T.: PoMMaDe: pushdown model-checking for malware detection, pp. 607\u2013610 (2013). https:\/\/doi.org\/10.1145\/2491411.2494599","DOI":"10.1145\/2491411.2494599"},{"key":"25_CR32","doi-asserted-by":"publisher","unstructured":"Chaugule, A., Xu, Z., Zhu, S.: A Specification Based Intrusion Detection Framework for Mobile Phones, pp. 19\u201337 (2011). https:\/\/doi.org\/10.1007\/978-3-642-21554-4_2","DOI":"10.1007\/978-3-642-21554-4_2"},{"key":"25_CR33","doi-asserted-by":"publisher","unstructured":"Song, F., Touili, T.: Model-Checking for Android Malware Detection, pp. 216\u2013235 (2014). https:\/\/doi.org\/10.1007\/978-3-319-12736-1_12","DOI":"10.1007\/978-3-319-12736-1_12"},{"key":"25_CR34","doi-asserted-by":"publisher","unstructured":"Battista, P., Mercaldo, F., Nardone, V., Santone, A., Visaggio, C.A.: Identification of Android malware families with model checking. https:\/\/doi.org\/10.5220\/0005809205420547","DOI":"10.5220\/0005809205420547"},{"issue":"12","key":"25_CR35","doi-asserted-by":"publisher","first-page":"1230","DOI":"10.1109\/TSE.2018.2834344","volume":"45","author":"G Canfora","year":"2019","unstructured":"Canfora, G., Martinelli, F., Mercaldo, F., Nardone, V., Santone, A., Visaggio, C.A.: LEILA: formal tool for identifying mobile malicious behaviour. IEEE Trans. Softw. Eng. 45(12), 1230\u20131252 (2019). https:\/\/doi.org\/10.1109\/TSE.2018.2834344","journal-title":"IEEE Trans. Softw. Eng."},{"key":"25_CR36","unstructured":"IDApro: Available at: https:\/\/www.hex-rays.com\/. Accessed 28 Nov 2020"},{"key":"25_CR37","unstructured":"Debugger, O.: Available at: http:\/\/www.ollydbg.de\/. Accessed 28 Nov 2020"},{"key":"25_CR38","unstructured":"XXD. Available at: https:\/\/linux.die.net\/man\/1\/xxd. Accessed 28 Nov 2020"},{"key":"25_CR39","unstructured":"Miller, P., Hexdump (2000). Available at: https:\/\/man7.org\/linux\/man-pages\/man1\/hexdump.1.html. Accessed 28 Nov 2020"},{"key":"25_CR40","unstructured":"The first computer virus was designed for an apple computer, by a 15 year old. https:\/\/blogs.quickheal.com\/the-first-pc-virus-was-designed-for-an-apple-computer-by-a-15-year-old\/"}],"container-title":["Lecture Notes in Networks and Systems","Advances in Computing, Informatics, Networking and Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-87049-2_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,28]],"date-time":"2022-04-28T12:13:52Z","timestamp":1651148032000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-87049-2_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030870485","9783030870492"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-87049-2_25","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"value":"2367-3370","type":"print"},{"value":"2367-3389","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"3 March 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}