{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,3]],"date-time":"2025-08-03T04:11:47Z","timestamp":1754194307787,"version":"3.40.3"},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319998275"},{"type":"electronic","value":"9783319998282"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-99828-2_16","type":"book-chapter","created":{"date-parts":[[2018,8,25]],"date-time":"2018-08-25T11:35:10Z","timestamp":1535196910000},"page":"216-230","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Anti-forensic = Suspicious: Detection of Stealthy Malware that Hides Its Network Traffic"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6374-6737","authenticated-orcid":false,"given":"Mayank","family":"Agarwal","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7229-3899","authenticated-orcid":false,"given":"Rami","family":"Puzis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2911-0329","authenticated-orcid":false,"given":"Jawad","family":"Haj-Yahya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3593-7330","authenticated-orcid":false,"given":"Polina","family":"Zilberman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,8,26]]},"reference":[{"key":"16_CR1","unstructured":"AbuseIPDB - IP address abuse reports. https:\/\/www.abuseipdb.com\/"},{"key":"16_CR2","unstructured":"Azazel is a userland rootkit. https:\/\/github.com\/chokepoint\/azazel"},{"key":"16_CR3","unstructured":"Cloudflare Bug - Cloudbleed May Have Leaked Data From Millions of Sites. https:\/\/www.wired.com\/2017\/02\/crazy-cloudflare-bug-jeopardized-millions-sites\/"},{"key":"16_CR4","unstructured":"Data Mining for Threat Intelligence. https:\/\/www.threatminer.org"},{"key":"16_CR5","unstructured":"DDoS attacks in Q4 2017 - Securelist. https:\/\/securelist.com\/ddos-attacks-in-q4-2017\/83729\/"},{"key":"16_CR6","unstructured":"enyelkm - LKM rootkit for Linux x86 with the 2.6 kernel. https:\/\/github.com\/David-Reguera-Garcia-Dreg\/enyelkm"},{"key":"16_CR7","unstructured":"Open Threat Exchange. https:\/\/otx.alienvault.com"},{"key":"16_CR8","unstructured":"Open Threat Intelligence. https:\/\/cymon.io\/"},{"key":"16_CR9","unstructured":"Ransomware Tracker. https:\/\/ransomwaretracker.abuse.ch"},{"key":"16_CR10","unstructured":"VirusSign\u2014Malware Research & Data Center, Virus Free Downloads. http:\/\/samples.virussign.com\/samples\/"},{"key":"16_CR11","unstructured":"vlany is a Linux LD-PRELOAD rootkit. https:\/\/github.com\/mempodippy\/vlany"},{"key":"16_CR12","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1016\/j.cose.2014.10.011","volume":"48","author":"S Alam","year":"2015","unstructured":"Alam, S., Horspool, R.N., Traore, I., Sogukpinar, I.: A framework for metamorphic malware analysis and real-time detection. Comput. Secur. 48, 212\u2013233 (2015)","journal-title":"Comput. Secur."},{"key":"16_CR13","first-page":"17","volume":"61","author":"J Butler","year":"2004","unstructured":"Butler, J., Hoglund, G.: VICE-catch the hookers. Black Hat USA 61, 17\u201335 (2004)","journal-title":"Black Hat USA"},{"key":"16_CR14","doi-asserted-by":"crossref","unstructured":"Chen, S., Guo, C., Yuan, X., Merkle, F., Schaefer, H., Ertl, T.: Oceans: online collaborative explorative analysis on network security. In: Proceedings of the Eleventh Workshop on Visualization for Cyber Security, pp. 1\u20138. ACM (2014)","DOI":"10.1145\/2671491.2671493"},{"key":"16_CR15","unstructured":"Cogswell, B., Russinovich, M.: Rootkitrevealer v1. 71. Rootkit detection tool by Microsoft (2006)"},{"issue":"1","key":"16_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11416-015-0261-z","volume":"13","author":"A Damodaran","year":"2017","unstructured":"Damodaran, A., Troia, F.D., Visaggio, C.A., Austin, T.H., Stamp, M.: A comparison of static, dynamic, and hybrid analysis for malware detection. J. Comput. Virol. Hacking Tech. 13(1), 1\u201312 (2017)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"16_CR17","doi-asserted-by":"crossref","unstructured":"Guri, M., Kedma, G., Sela, T., Carmeli, B., Rosner, A., Elovici, Y.: Noninvasive detection of anti-forensic malware. In: 2013 8th International Conference on Malicious and Unwanted Software: \u201cThe Americas\u201d (MALWARE), pp. 1\u201310. IEEE (2013)","DOI":"10.1109\/MALWARE.2013.6703679"},{"key":"16_CR18","volume-title":"Rootkits: Subverting the Windows Kernel","author":"G Hoglund","year":"2006","unstructured":"Hoglund, G., Butler, J.: Rootkits: Subverting the Windows Kernel. Addison-Wesley Professional, Boston (2006)"},{"key":"16_CR19","unstructured":"Kalita, E.: WannaCry Ransomware Attack: Protect Yourself from WannaCry Ransomware Cyber Risk and Cyber War. Independently Published (2017)"},{"issue":"9","key":"16_CR20","doi-asserted-by":"publisher","first-page":"1465","DOI":"10.1109\/TIFS.2014.2337256","volume":"9","author":"SA Musavi","year":"2014","unstructured":"Musavi, S.A., Kharrazi, M.: Back to static analysis for kernel-level rootkit detection. IEEE Trans. Inf. Forensics Secur. 9(9), 1465\u20131476 (2014)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"16_CR21","unstructured":"Rutkowska, J.: Detecting windows server compromises with patchfinder 2. Personal Communication, January 2004"},{"key":"16_CR22","volume-title":"The Art of Computer Virus Research and Defense","author":"P Szor","year":"2005","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Pearson Education, London (2005)"}],"container-title":["IFIP Advances in Information and Communication Technology","ICT Systems Security and Privacy Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-99828-2_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,26]],"date-time":"2022-08-26T00:04:16Z","timestamp":1661472256000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-99828-2_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319998275","9783319998282"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-99828-2_16","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"26 August 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on ICT Systems Security and Privacy Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poznan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 September 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"33","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sec2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ifipsec2018.pwr.edu.pl\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"89","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"330% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}