{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T23:05:00Z","timestamp":1782774300194,"version":"3.54.5"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031175503","type":"print"},{"value":"9783031175510","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-17551-0_21","type":"book-chapter","created":{"date-parts":[[2022,9,29]],"date-time":"2022-09-29T13:25:48Z","timestamp":1664457948000},"page":"315-330","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Malware Detection Using Automated Generation of\u00a0Yara Rules on\u00a0Dynamic Features"],"prefix":"10.1007","author":[{"given":"Qin","family":"Si","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hui","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ying","family":"Tong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jian","family":"Liang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lei","family":"Cui","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiyu","family":"Hao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,30]]},"reference":[{"key":"21_CR1","unstructured":"Sonicwall2022-cyber-threat-report. https:\/\/www.sonicwall.com\/2022-cyber-threat-report"},{"key":"21_CR2","doi-asserted-by":"crossref","unstructured":"Ahmed, F., Hameed, H., Shafiq, M.Z., Farooq, M.: Using spatio-temporal information in API calls with machine learning algorithms for malware detection. In: The 2nd ACM Workshop on Security and Artificial Intelligence, pp. 55\u201362 (2009)","DOI":"10.1145\/1654988.1655003"},{"key":"21_CR3","unstructured":"Alvarez, V.M.: yara documentation4.2.0 (2022)"},{"key":"21_CR4","unstructured":"Ashraf, A., Aziz, A., Zahoora, U., Rajarajan, M., Khan, A.: Ransomware analysis using feature engineering and deep neural networks. arXiv preprint arXiv:1910.00286 (2019)"},{"key":"21_CR5","unstructured":"Brengel, M., Rossow, C.: $$\\{$$YARIX$$\\}$$: Scalable $$\\{$$YARA-based$$\\}$$ malware intelligence. In: 30th USENIX Security Symposium, pp. 3541\u20133558 (2021)"},{"key":"21_CR6","unstructured":"Clark, C.: Yaragenerator. XenoSec (2013)"},{"key":"21_CR7","doi-asserted-by":"crossref","unstructured":"Eskandari, M., Khorshidpur, Z., Hashemi, S.: To incorporate sequential dynamic features in malware detection engines. In: 2012 European Intelligence and Security Informatics Conference, pp. 46\u201352. IEEE (2012)","DOI":"10.1109\/EISIC.2012.57"},{"issue":"1","key":"21_CR8","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/s11277-014-2136-x","volume":"81","author":"S Gupta","year":"2015","unstructured":"Gupta, S., Kumar, P.: An immediate system call sequence based approach for detecting malicious program executions in cloud environment. Wireless Pers. Commun. 81(1), 405\u2013425 (2015)","journal-title":"Wireless Pers. Commun."},{"key":"21_CR9","unstructured":"InQuest: awesome-yara (2016). https:\/\/github.com\/InQuest\/awesome-yara"},{"key":"21_CR10","doi-asserted-by":"crossref","unstructured":"Jaramillo, L.E.S.: Detecting malware capabilities with Foss: lessons learned through a real-life incident. In: 2018 13th Iberian Conference on Information Systems and Technologies (CISTI), pp. 1\u20136. IEEE (2018)","DOI":"10.23919\/CISTI.2018.8399238"},{"key":"21_CR11","doi-asserted-by":"crossref","unstructured":"Naik, N., Jenkins, P., Cooke, R., Gillett, J., Jin, Y.: Evaluating automatically generated yara rules and enhancing their effectiveness. In: 2020 IEEE Symposium Series on Computational Intelligence (SSCI), pp. 1146\u20131153. IEEE (2020)","DOI":"10.1109\/SSCI47803.2020.9308179"},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Park, Y., Reeves, D., Mulukutla, V., Sundaravel, B.: Fast malware classification by automated behavioral graph matching. In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research, pp. 1\u20134 (2010)","DOI":"10.1145\/1852666.1852716"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Qiao, Y., Yang, Y., Ji, L., He, J.: Analyzing malware by abstracting the frequent itemsets in api call sequences. In: 2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, pp. 265\u2013270. IEEE (2013)","DOI":"10.1109\/TrustCom.2013.36"},{"key":"21_CR14","doi-asserted-by":"crossref","unstructured":"Raff, E., Zak, R., et al.: Automatic Yara rule generation using biclustering. In: The 13th ACM Workshop on Artificial Intelligence and Security, pp. 71\u201382 (2020)","DOI":"10.1145\/3411508.3421372"},{"key":"21_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"108","DOI":"10.1007\/978-3-540-70542-0_6","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"K Rieck","year":"2008","unstructured":"Rieck, K., Holz, T., Willems, C., D\u00fcssel, P., Laskov, P.: Learning and classification of malware behavior. In: Zamboni, D. (ed.) DIMVA 2008. LNCS, vol. 5137, pp. 108\u2013125. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-70542-0_6"},{"key":"21_CR16","doi-asserted-by":"crossref","unstructured":"Saxe, J., Mentis, D., Greamo, C.: Visualization of shared system call sequence relationships in large malware corpora. In: Proceedings of the Ninth International Symposium on Visualization for Cyber Security, pp. 33\u201340 (2012)","DOI":"10.1145\/2379690.2379695"},{"key":"21_CR17","unstructured":"Saxe, J.: Yaraml (2020). https:\/\/github.com\/sophos-ai\/yaraml_rules\/"},{"key":"21_CR18","unstructured":"Schultz, M.G., Eskin, E., Zadok, F., Stolfo, S.J.: Data mining methods for detection of new malicious executables. In: Proceedings 2001 IEEE Symposium on Security and Privacy. S &P 2001, pp. 38\u201349. IEEE (2000)"},{"key":"21_CR19","unstructured":"Tandon, G., Chan, P.K.: Learning useful system call attributes for anomaly detection. In: FLAIRS Conference, pp. 405\u2013411 (2005)"},{"issue":"6","key":"21_CR20","doi-asserted-by":"publisher","first-page":"14","DOI":"10.4304\/jsw.2.6.14-21","volume":"2","author":"SM Varghese","year":"2007","unstructured":"Varghese, S.M., Jacob, K.P.: Anomaly detection using system call sequence sets. J. Softw. 2(6), 14\u201321 (2007)","journal-title":"J. Softw."},{"issue":"3","key":"21_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3073559","volume":"50","author":"Y Ye","year":"2017","unstructured":"Ye, Y., Li, T., Adjeroh, D., Iyengar, S.S.: A survey on malware detection using data mining techniques. ACM Comput. Surv. (CSUR) 50(3), 1\u201340 (2017)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"21_CR22","doi-asserted-by":"crossref","unstructured":"Ye, Y., Wang, D., Li, T., Ye, D.: IMDS: intelligent malware detection system. In: Proceedings of the 13th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1043\u20131047 (2007)","DOI":"10.1145\/1281192.1281308"},{"key":"21_CR23","doi-asserted-by":"crossref","unstructured":"Zhang, X., et al.: Enhancing state-of-the-art classifiers with API semantics to detect evolved android malware. In: The 2020 ACM SIGSAC Conference on Computer and Communications Security, pp. 757\u2013770 (2020)","DOI":"10.1145\/3372297.3417291"}],"container-title":["Lecture Notes in Computer Science","Science of Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-17551-0_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,29]],"date-time":"2022-09-29T13:29:18Z","timestamp":1664458158000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-17551-0_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031175503","9783031175510"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-17551-0_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"30 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SciSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Science of Cyber Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Matsue","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"scisec2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.scisec.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"50% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3 Posters","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}