{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T11:18:59Z","timestamp":1743074339029,"version":"3.40.3"},"publisher-location":"Cham","reference-count":18,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319998275"},{"type":"electronic","value":"9783319998282"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-99828-2_26","type":"book-chapter","created":{"date-parts":[[2018,8,25]],"date-time":"2018-08-25T11:35:10Z","timestamp":1535196910000},"page":"370-384","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Performance Improvements in Behavior Based Malware Detection Solutions"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8664-8956","authenticated-orcid":false,"given":"Gheorghe","family":"H\u0103jm\u0103\u015fan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2096-3771","authenticated-orcid":false,"given":"Alexandra","family":"Mondoc","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9008-1462","authenticated-orcid":false,"given":"Radu","family":"Portase","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6657-634X","authenticated-orcid":false,"given":"Octavian","family":"Cre\u0163","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,8,26]]},"reference":[{"key":"26_CR1","unstructured":"AV-Test: Malware statistics. http:\/\/www.av-test.org\/en\/statistics\/malware\/"},{"key":"26_CR2","unstructured":"AV-Test: Performance testing. https:\/\/www.av-test.org\/en\/test-procedures\/test-modules\/performance\/"},{"key":"26_CR3","volume-title":"The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System","author":"B Blunden","year":"2009","unstructured":"Blunden, B.: The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System. Jones and Bartlett Publishers, Inc., Burlington (2009)"},{"key":"26_CR4","doi-asserted-by":"crossref","unstructured":"Chau, D.H., Nachenberg, C., Wilhelm, J., Wright, A., Faloutsos, C.: Polonium: tera-scale graph mining and inference for malware detection. In: SIAM International Conference on Data Mining, SDM, pp. 131\u2013142 (2011)","DOI":"10.1137\/1.9781611972818.12"},{"key":"26_CR5","unstructured":"ClamAV. https:\/\/www.clamav.net"},{"issue":"5","key":"26_CR6","first-page":"29","volume":"7","author":"AAE Elhadi","year":"2013","unstructured":"Elhadi, A.A.E., Maarof, M.A., Barry, B.I.: Improving the detection of malware behaviour using simplified data dependent API call graph. Int. J. Secur. Appl. 7(5), 29\u201342 (2013)","journal-title":"Int. J. Secur. Appl."},{"key":"26_CR7","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1049\/iet-ifs.2012.0192","volume":"7","author":"AM Espinoza","year":"2013","unstructured":"Espinoza, A.M., Al-Saleh, M.I., Crandall, J.R.: Antivirus performance characterisation: system-wide view. IET Inf. Secur. 7, 126\u2013133 (2013)","journal-title":"IET Inf. Secur."},{"key":"26_CR8","doi-asserted-by":"crossref","unstructured":"H\u0103jm\u0103\u015fan, G., Mondoc, A., Cre\u0163, O.: Dynamic behavior evaluation for malware detection. In: 2017 5th International Symposium on Digital Forensic and Security, ISDFS, pp. 1\u20136, April 2017","DOI":"10.1109\/ISDFS.2017.7916495"},{"key":"26_CR9","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1007\/978-3-319-58469-0_3","volume-title":"ICT Systems Security and Privacy Protection","author":"G H\u0103jm\u0103\u015fan","year":"2017","unstructured":"H\u0103jm\u0103\u015fan, G., Mondoc, A., Portase, R., Cre\u0163, O.: Evasive malware detection using groups of processes. In: De Capitani di Vimercati, S., Martinelli, F. (eds.) SEC 2017. IAICT, vol. 502, pp. 32\u201345. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-58469-0_3"},{"issue":"5","key":"26_CR10","doi-asserted-by":"publisher","first-page":"524627","DOI":"10.1155\/2015\/524627","volume":"11","author":"Y Ji","year":"2015","unstructured":"Ji, Y., Li, Q., He, Y., Guo, D.: Overhead analysis and evaluation of approaches to host-based bot detection. Int. J. Distrib. Sens. Netw. 11(5), 524627 (2015)","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"26_CR11","unstructured":"Kolbitsch, C., Comparetti, P.M., Kruegel, C., Kirda, E., Zhou, X., Wang, X.: Effective and efficient malware detection at the end host. In: Proceedings of the 18th Conference on USENIX Security Symposium, SSYM 2009, pp. 351\u2013366. USENIX Association, Berkeley (2009)"},{"key":"26_CR12","unstructured":"Mircescu, D.: Systems and methods for using a reputation indicator to facilitate malware scanning, US Patent 9,117,077, August 2015. https:\/\/www.google.com\/patents\/US9117077"},{"key":"26_CR13","unstructured":"Ramzan, Z., Seshadri, V., Nachenberg, C.: Reputation-based security an analysis of real world effectiveness. Symantec Security Response. https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/white-papers\/reputation-based-security-en.pdf"},{"issue":"13","key":"26_CR14","doi-asserted-by":"publisher","first-page":"2628","DOI":"10.1016\/j.comnet.2013.05.010","volume":"57","author":"S Shin","year":"2013","unstructured":"Shin, S., Xu, Z., Gu, G.: EFFORT: a new host-network cooperated framework for efficient and effective bot malware detection. Comput. Netw. 57(13), 2628\u20132642 (2013)","journal-title":"Comput. Netw."},{"key":"26_CR15","doi-asserted-by":"crossref","unstructured":"Tamersoy, A., Roundy, K., Chau, D.H.: Guilt by association: large scale malware detection by mining file-relation graphs. In: Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD 2014, pp. 1524\u20131533. ACM, New York (2014)","DOI":"10.1145\/2623330.2623342"},{"key":"26_CR16","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1145\/1055626.1055639","volume":"33","author":"D Uluski","year":"2005","unstructured":"Uluski, D., Moffie, M., Kaeli, D.: Characterizing antivirus workload execution. ACM SIGARCH Comput. Archit. News 33, 90\u201398 (2005)","journal-title":"ACM SIGARCH Comput. Archit. News"},{"key":"26_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1007\/978-3-642-15512-3_5","volume-title":"Recent Advances in Intrusion Detection","author":"G Vasiliadis","year":"2010","unstructured":"Vasiliadis, G., Ioannidis, S.: GrAVity: a massively parallel antivirus engine. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 79\u201396. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15512-3_5"},{"key":"26_CR18","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D., Egele, M., Kruegel, C., Kirda, E.: Panorama: capturing system-wide information flow for malware detection and analysis. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS 2007, pp. 116\u2013127. ACM, New York (2007)","DOI":"10.1145\/1315245.1315261"}],"container-title":["IFIP Advances in Information and Communication Technology","ICT Systems Security and Privacy Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-99828-2_26","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,26]],"date-time":"2022-08-26T00:05:28Z","timestamp":1661472328000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-99828-2_26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319998275","9783319998282"],"references-count":18,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-99828-2_26","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"26 August 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on ICT Systems Security and Privacy Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poznan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 September 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"33","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sec2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ifipsec2018.pwr.edu.pl\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"89","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"330% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}