{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,27]],"date-time":"2026-08-27T23:30:39Z","timestamp":1787873439597,"version":"build-2784847793"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_15","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"256-266","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["SigIL: A Signature-Based Approach of\u00a0Malware Detection on\u00a0Intermediate Language"],"prefix":"10.1007","author":[{"given":"Giancarlo","family":"Fortino","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4929-2289","authenticated-orcid":false,"given":"Claudia","family":"Greco","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antonella","family":"Guzzo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0562-7462","authenticated-orcid":false,"given":"Michele","family":"Ianni","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Alam, S., Horspool, R.N., Traore, I.: Mail: Malware analysis intermediate language: a step towards automating and optimizing malware detection. In: Proceedings of the 6th International Conference on Security of Information and Networks, pp. 233\u2013240 (2013)","DOI":"10.1145\/2523514.2527006"},{"key":"15_CR2","unstructured":"Alvarez, V.M.: Yara. https:\/\/virustotal.github.io\/yara\/"},{"key":"15_CR3","unstructured":"Bonfante, G., Kaczmarek, M., Marion, J.Y.: Control flow graphs as malware signatures. In: International workshop on the Theory of Computer Viruses (2007)"},{"issue":"2","key":"15_CR4","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1109\/MSP.2007.31","volume":"5","author":"D Bruschi","year":"2007","unstructured":"Bruschi, D., Martignoni, L., Monga, M.: Code normalization for self-mutating malware. IEEE Secur. Privacy 5(2), 46\u201354 (2007)","journal-title":"IEEE Secur. Privacy"},{"key":"15_CR5","doi-asserted-by":"publisher","unstructured":"Cesare, S., Xiang, Y.: Malware variant detection using similarity search over sets of control flow graphs. In: 2011IEEE 10th International Conference on Trust, Security and Privacy in Computing and Communications, pp. 181\u2013189 (2011). https:\/\/doi.org\/10.1109\/TrustCom.2011.26","DOI":"10.1109\/TrustCom.2011.26"},{"key":"15_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102779","volume":"120","author":"R Chaganti","year":"2022","unstructured":"Chaganti, R., Ravi, V., Pham, T.D.: Deep learning based cross architecture internet of things malware detection and classification. Comput. Secur. 120, 102779 (2022)","journal-title":"Comput. Secur."},{"key":"15_CR7","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S.: Static analysis of executables to detect malicious patterns. WISCONSIN UNIV-MADISON DEPT OF COMPUTER SCIENCES, Tech. rep. (2006)","DOI":"10.21236\/ADA449067"},{"key":"15_CR8","unstructured":"Driller, M.: Metamorphism in practice. 29A Mag. 1(6) (2002)"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Greco, C., Ianni, M., Guzzo, A., Fortino, G.: Explaining binary obfuscation. In: 2023 IEEE International Conference on Cyber Security and Resilience (CSR), pp. 22\u201327. IEEE (2023)","DOI":"10.1109\/CSR57506.2023.10224825"},{"key":"15_CR10","doi-asserted-by":"publisher","unstructured":"Guzzo, A., Ianni, M., Pugliese, A., Sacc\u00e0, D.: Modeling and efficiently detecting security-critical sequences of actions. Futur. Gener. Comput. Syst. (2020). https:\/\/doi.org\/10.1016\/j.future.2020.06.054. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167739X19331528","DOI":"10.1016\/j.future.2020.06.054"},{"key":"15_CR11","doi-asserted-by":"publisher","unstructured":"Ianni, M., Masciari, E.: A compact encoding of security logs for high performance activity detection. In: 29th Euromicro International Conference on Parallel, Distributed and Network-Based Processing, PDP 2021, Valladolid, Spain, March 10\u201312, 2021, pp. 240\u2013244. IEEE (2021). https:\/\/doi.org\/10.1109\/PDP52278.2021.00045. https:\/\/doi.org\/10.1109\/PDP52278.2021.00045","DOI":"10.1109\/PDP52278.2021.00045"},{"key":"15_CR12","doi-asserted-by":"publisher","unstructured":"Ianni, M., Masciari, E.: Scout: Security by computing outliers on activity logs. Comput. Secur. 132, 103355 (2023). https:\/\/doi.org\/10.1016\/j.cose.2023.103355. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404823002651","DOI":"10.1016\/j.cose.2023.103355"},{"key":"15_CR13","unstructured":"Julus, L.: Metamorphism. 29A Mag. 1(5) (2000)"},{"key":"15_CR14","first-page":"15","volume":"15","author":"E Konstantinou","year":"2008","unstructured":"Konstantinou, E., Wolthusen, S.: Metamorphic virus: analysis and detection. Royal Holloway Univ. London 15, 15 (2008)","journal-title":"Royal Holloway Univ. London"},{"key":"15_CR15","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1016\/j.diin.2006.06.015","volume":"3","author":"J Kornblum","year":"2006","unstructured":"Kornblum, J.: Identifying almost identical files using context triggered piecewise hashing. Digit. Investig. 3, 91\u201397 (2006)","journal-title":"Digit. Investig."},{"key":"15_CR16","doi-asserted-by":"crossref","unstructured":"Lakhotia, A., Mohammed, M.: Imposing order on program statements to assist anti-virus scanners. In: Proceedings of the 11th Working Conference on Reverse Engineering, 2004, pp. 161\u2013170. IEEE (2004)","DOI":"10.1109\/WCRE.2004.24"},{"key":"15_CR17","doi-asserted-by":"publisher","unstructured":"Lattner, C., Adve, V.: Llvm: a compilation framework for lifelong program analysis & transformation. In: International Symposium on Code Generation and Optimization, 2004. CGO 2004, pp. 75\u201386 (2004). https:\/\/doi.org\/10.1109\/CGO.2004.1281665","DOI":"10.1109\/CGO.2004.1281665"},{"key":"15_CR18","doi-asserted-by":"crossref","unstructured":"Oliver, J., Cheng, C., Chen, Y.: Tlsh-a locality sensitive hash. In: 2013 Fourth Cybercrime and Trustworthy Computing Workshop, pp. 7\u201313. IEEE (2013)","DOI":"10.1109\/CTC.2013.9"},{"key":"15_CR19","unstructured":"Perriot, F.: Defeating polymorphism through code optimization. In: Proc. of the 2003 Virus Bulletin Conference (VB2003), pp. 1\u201318, September 2003"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Phu, T.N., Hoang, L.H., Toan, N.N., Tho, N.D., Binh, N.N.: Cfdvex: A novel feature extraction method for detecting cross-architecture iot malware. In: Proceedings of the 10th International Symposium on Information and Communication Technology, pp. 248\u2013254 (2019)","DOI":"10.1145\/3368926.3369702"},{"key":"15_CR21","unstructured":"Rajaat: Polimorphism. 29A Mag. 1(3) (1999)"},{"key":"15_CR22","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/978-3-642-15506-2_15","volume-title":"Advances in Digital Forensics VI","author":"V Roussev","year":"2010","unstructured":"Roussev, V.: Data fingerprinting with similarity digests. In: Chow, K.-P., Shenoi, S. (eds.) DigitalForensics 2010. IAICT, vol. 337, pp. 207\u2013226. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15506-2_15"},{"key":"15_CR23","doi-asserted-by":"crossref","unstructured":"Saxe, J., Berlin, K.: Deep neural network based malware detection using two dimensional binary program features. In: 2015 10th International Conference on Malicious and Unwanted Software (MALWARE), pp. 11\u201320. IEEE (2015)","DOI":"10.1109\/MALWARE.2015.7413680"},{"key":"15_CR24","unstructured":"Schiffman, M.: A brief history of malware obfuscation: Part 1 of 2. Published online at https:\/\/blogs.cisco.com\/security\/a_brief_history_of_malware_obfuscation_part_1_of_2. Accessed 13 Nov 2018"},{"key":"15_CR25","unstructured":"Schiffman, M.: A brief history of malware obfuscation: Part 2 of 2. Published online at https:\/\/blogs.cisco.com\/security\/a_brief_history_of_malware_obfuscation_part_2_of_2. Accessed 13 Nov 2018"},{"key":"15_CR26","unstructured":"Szor, P., Ferrie, P.: Hunting for metamorphic. In: Virus bulletin conference. Prague (2001)"},{"issue":"3","key":"15_CR27","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11416-006-0028-7","volume":"2","author":"W Wong","year":"2006","unstructured":"Wong, W., Stamp, M.: Hunting for metamorphic engines. J. Comput. Virol. 2(3), 211\u2013229 (2006)","journal-title":"J. Comput. Virol."},{"key":"15_CR28","doi-asserted-by":"crossref","unstructured":"You, I., Yim, K.: Malware obfuscation techniques: A brief survey. In: 2010 International Conference on Broadband, Wireless Computing, Communication and Applications (BWCCA), pp. 297\u2013300. IEEE (2010)","DOI":"10.1109\/BWCCA.2010.85"},{"key":"15_CR29","doi-asserted-by":"crossref","unstructured":"Zhao, B., Han, J., Meng, X.: A malware detection system based on intermediate language. In: 2017 4th International Conference on Systems and Informatics (ICSAI), pp. 824\u2013830. IEEE (2017)","DOI":"10.1109\/ICSAI.2017.8248399"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:05:36Z","timestamp":1710194736000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}