{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T13:07:13Z","timestamp":1772716033347,"version":"3.50.1"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319600796","type":"print"},{"value":"9783319600802","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-60080-2_21","type":"book-chapter","created":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T14:40:06Z","timestamp":1496328006000},"page":"288-305","source":"Crossref","is-referenced-by-count":15,"title":["Malware Triage Based on Static Features and Public APT Reports"],"prefix":"10.1007","author":[{"given":"Giuseppe","family":"Laurenza","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leonardo","family":"Aniello","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Riccardo","family":"Lazzeretti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roberto","family":"Baldoni","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,6,2]]},"reference":[{"key":"21_CR1","unstructured":"IOC parser. https:\/\/github.com\/armbues\/ioc_parser\/ . Accessed 17 Mar 2017"},{"key":"21_CR2","unstructured":"MongoDB. https:\/\/www.mongodb.com\/ . Accessed 13 Mar 2017"},{"key":"21_CR3","unstructured":"PEFrame. https:\/\/github.com\/guelfoweb\/peframe\/ . Accessed 17 Mar 2017"},{"issue":"1","key":"21_CR4","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1023\/A:1010933404324","volume":"45","author":"L Breiman","year":"2001","unstructured":"Breiman, L.: Random forests. Mach. Learn. 45(1), 5\u201332 (2001)","journal-title":"Mach. Learn."},{"key":"21_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-662-44885-4_5","volume-title":"Communications and Multimedia Security","author":"P Chen","year":"2014","unstructured":"Chen, P., Desmet, L., Huygens, C.: A study on advanced persistent threats. In: Decker, B., Z\u00faquete, A. (eds.) CMS 2014. LNCS, vol. 8735, pp. 63\u201372. Springer, Heidelberg (2014). doi: 10.1007\/978-3-662-44885-4_5"},{"key":"21_CR6","unstructured":"CNN: Nearly 1 million new malware threats released every day (2014). http:\/\/money.cnn.com\/2015\/04\/14\/technology\/security\/cyber- attack-hacks-security\/"},{"key":"21_CR7","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-015-0261-z","volume":"13","author":"A Damodaran","year":"2015","unstructured":"Damodaran, A., Di Troia, F., Visaggio, C.A., Austin, T.H., Stamp, M.: A comparison of static, dynamic, and hybrid analysis for malware detection. J. Comput. Virol. Hacking Tech. 13, 1\u201312 (2015)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"21_CR8","unstructured":"Fireeye: FireEye labs obfuscated string solver. https:\/\/github.com\/fireeye\/flare-floss\/ . Accessed 17 Mar 2017"},{"issue":"2","key":"21_CR9","doi-asserted-by":"crossref","first-page":"646","DOI":"10.1016\/j.jnca.2012.10.004","volume":"36","author":"R Islam","year":"2013","unstructured":"Islam, R., Tian, R., Batten, L.M., Versteeg, S.: Classification of malware based on integrated static and dynamic features. J. Netw. Comput. Appl. 36(2), 646\u2013656 (2013)","journal-title":"J. Netw. Comput. Appl."},{"key":"21_CR10","doi-asserted-by":"crossref","unstructured":"Jang, J., Brumley, D., Venkataraman, S.: BitShred: Fast, scalable malware triage. Technical report CMU-Cylab-10-022, Cylab, Carnegie Mellon University, Pittsburgh, PA (2010)","DOI":"10.1145\/2046707.2046742"},{"key":"21_CR11","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1007\/978-3-642-35264-5_21","volume-title":"Computer Applications for Security, Control and System Engineering","author":"I Jeun","year":"2012","unstructured":"Jeun, I., Lee, Y., Won, D.: A practical study on advanced persistent threats. In: Kim, T., Stoica, A., Fang, W., Vasilakos, T., Villalba, J.G., Arnett, K.P., Khan, M.K., Kang, B.-H. (eds.) SecTech 2012. CCIS, vol. 339, pp. 144\u2013152. Springer, Heidelberg (2012). doi: 10.1007\/978-3-642-35264-5_21"},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Khodamoradi, P., Fazlali, M., Mardukhi, F., Nosrati, M.: Heuristic metamorphic malware detection based on statistics of assembly instructions using classification algorithms. In: 2015 18th CSI International Symposium on Computer Architecture and Digital Systems (CADS), pp. 1\u20136. IEEE (2015)","DOI":"10.1109\/CADS.2015.7377792"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Kirat, D., Nataraj, L., Vigna, G., Manjunath, B.: SigMal: a static signal processing based malware triage. In: Proceedings of the 29th Annual Computer Security Applications Conference. pp. 89\u201398. ACM (2013)","DOI":"10.1145\/2523649.2523682"},{"issue":"3","key":"21_CR14","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1007\/s11416-013-0178-3","volume":"9","author":"A Lakhotia","year":"2013","unstructured":"Lakhotia, A., Walenstein, A., Miles, C., Singh, A.: VILO: a rapid learning nearest-neighbor classifier for malware triage. J. Comput. Virol. Hacking Tech. 9(3), 109\u2013123 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"21_CR15","doi-asserted-by":"crossref","unstructured":"Laurenza, G., Ucci, D., Aniello, L., Baldoni, R.: An architecture for semi-automatic collaborative malware analysis for CIs. In: 2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks Workshop, pp. 137\u2013142. IEEE (2016)","DOI":"10.1109\/DSN-W.2016.40"},{"key":"21_CR16","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1016\/j.comnet.2016.05.018","volume":"109","author":"M Marchetti","year":"2016","unstructured":"Marchetti, M., Pierazzi, F., Colajanni, M., Guido, A.: Analysis of high volumes of network traffic for advanced persistent threat detection. Comput. Netw. 109, 127\u2013141 (2016)","journal-title":"Comput. Netw."},{"key":"21_CR17","unstructured":"Trend Micro: IXESHE: an APT campaign. Trend Micro Incorporated Research Paper (2012)"},{"key":"21_CR18","unstructured":"MITRE: CRITS: collaborative research into threats. https:\/\/crits.github.io\/ . Accessed 17 Mar 2017"},{"key":"21_CR19","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: Twenty-Third Annual Computer Security Applications Conference, ACSAC 2007, pp. 421\u2013430. IEEE (2007)","DOI":"10.1109\/ACSAC.2007.21"},{"key":"21_CR20","unstructured":"O\u2019Gorman, G., McDonald, G.: The elderwood project. Symantec Whitepaper (2012)"},{"key":"21_CR21","unstructured":"R Development Core Team: R: A language and environment for statistical computing. R Foundation for Statistical Computing, Vienna, Austria (2008). ISBN 3-900051-07-0, http:\/\/www.R-project.org"},{"key":"21_CR22","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/978-3-642-33018-6_28","volume-title":"International Joint Conference CISIS\u201912-ICEUTE\u201912-SOCO\u201912 Special Sessions","author":"I Santos","year":"2013","unstructured":"Santos, I., Devesa, J., Brezo, F., Nieves, J., Bringas, P.G.: OPEM: a static-dynamic approach for machine-learning-based malware detection. In: Herrero, \u00c1., et al. (eds.) International Joint Conference CISIS\u201912-ICEUTE\u201912-SOCO\u201912 Special Sessions. AISC, pp. 271\u2013280. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-33018-6_28"},{"key":"21_CR23","doi-asserted-by":"crossref","unstructured":"Su, Y., Lib, M., Tang, C., Shen, R.: A framework of APT detection based on dynamic analysis (2016)","DOI":"10.2991\/nceece-15.2016.187"},{"issue":"8","key":"21_CR24","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/S1353-4858(11)70086-1","volume":"2011","author":"C Tankard","year":"2011","unstructured":"Tankard, C.: Advanced persistent threats and how to monitor and deter them. Netw. Secur. 2011(8), 16\u201319 (2011)","journal-title":"Netw. Secur."},{"key":"21_CR25","unstructured":"Villeneuve, N., Bennett, J.T., Moran, N., Haq, T., Scott, M., Geers, K.: Operation \u201cKE3CHANG\u201d Targeted Attacks Against Ministries of Foreign Affairs (2013)"},{"key":"21_CR26","doi-asserted-by":"crossref","unstructured":"Virvilis, N., Gritzalis, D., Apostolopoulos, T.: Trusted computing vs. advanced persistent threats: can a defender win this game? In: 2013 IEEE 10th International Conference on Ubiquitous Intelligence and Computing and 10th International Conference on Autonomic and Trusted Computing (UIC\/ATC), pp. 396\u2013403. IEEE (2013)","DOI":"10.1109\/UIC-ATC.2013.80"},{"key":"21_CR27","doi-asserted-by":"crossref","unstructured":"Vukalovi\u0107, J., Delija, D.: Advanced persistent threats-detection and defense. In: 2015 38th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO), pp. 1324\u20131330. IEEE (2015)","DOI":"10.1109\/MIPRO.2015.7160480"},{"key":"21_CR28","first-page":"8","volume":"9","author":"G Wicherski","year":"2009","unstructured":"Wicherski, G.: peHash: a novel approach to fast malware clustering. LEET 9, 8 (2009)","journal-title":"LEET"}],"container-title":["Lecture Notes in Computer Science","Cyber Security Cryptography and Machine Learning"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-60080-2_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,23]],"date-time":"2023-08-23T21:32:10Z","timestamp":1692826330000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-60080-2_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319600796","9783319600802"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-60080-2_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}