{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T11:26:05Z","timestamp":1772364365833,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":27,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540699712","type":"print"},{"value":"9783540705000","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-70500-0_25","type":"book-chapter","created":{"date-parts":[[2008,8,12]],"date-time":"2008-08-12T16:07:43Z","timestamp":1218557263000},"page":"336-349","source":"Crossref","is-referenced-by-count":67,"title":["Signature Generation and Detection of Malware Families"],"prefix":"10.1007","author":[{"given":"V. Sai","family":"Sathyanarayan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pankaj","family":"Kohli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bezawada","family":"Bruhadeshwar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"25_CR1","unstructured":"Pietrek, M.: An In-Depth Look into the Win32 Portable Executable File Format, in MSDN Magazine (March 2002)"},{"key":"25_CR2","unstructured":"VX Heavens, http:\/\/vx.netlux.org"},{"key":"25_CR3","unstructured":"Viruslist.com - Email-Worm.Win32.Borzella, http:\/\/www.viruslist.com\/en\/viruses\/encyclopedia?virusid=21991"},{"key":"25_CR4","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S.A., Song, D., Bryant, R.E.: Semantics-Aware Malware Detection. In: Proceedings of the 2005 IEEE Symposium on Security and Privacy, May 08-11, 2005, pp. 32\u201346 (2005)","DOI":"10.1109\/SP.2005.20"},{"key":"25_CR5","unstructured":"Marinescu, A.: An Analysis of Simile, http:\/\/www.securityfocus.com\/infocus\/1671"},{"key":"25_CR6","volume-title":"Biometry: The principles and practice of statistics in biological research","author":"R.R. Sokal","year":"1994","unstructured":"Sokal, R.R., Rohlf, F.J.: Biometry: The principles and practice of statistics in biological research, 3rd edn. Freeman, New York (1994)","edition":"3"},{"key":"25_CR7","doi-asserted-by":"crossref","unstructured":"Martignoni, L., Christodorescu, M., Jha, S.: OmniUnpack: Fast, Generic, and Safe Unpacking of Malware. In: Twenty-Third Annual Computer Security Applications Conference (ACSAC), Miami Beach, FL (December 2007)","DOI":"10.1109\/ACSAC.2007.15"},{"key":"25_CR8","unstructured":"Guilfanov, I.: An Advanced Interactive Multi-processor Disassembler (2000), http:\/\/www.datarescue.com"},{"key":"25_CR9","unstructured":"Ferrie, P., Sz\u00f6r, P.: Zmist opportunities. Virus Bullettin (2001)"},{"key":"25_CR10","unstructured":"Bilar, D.: Statistical Structures: Tolerant Fingerprinting for Classification and Analysis given at BH 2006, Las Vegas, NV. Blackhat Briefings USA (August 2006)"},{"key":"25_CR11","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1016\/0167-4048(87)90122-2","volume":"6","author":"F. Cohen","year":"1987","unstructured":"Cohen, F.: Computer Virus: Theory and experiments. Computers and Security\u00a06, 22\u201335 (1987)","journal-title":"Computers and Security"},{"key":"25_CR12","unstructured":"Chess, D.M., White, S.R.: An undetectable computer virus. In: Proceedings of Virus Bulletin Conference (2000)"},{"issue":"4","key":"25_CR13","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1145\/161494.161501","volume":"1","author":"N. Landi","year":"1992","unstructured":"Landi, N.: Undecidability of static analysis. ACM Letters on Programming Language and systems (LOPLAS)\u00a01(4), 323\u2013337 (1992)","journal-title":"ACM Letters on Programming Language and systems (LOPLAS)"},{"key":"25_CR14","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1145\/567532.567556","volume-title":"Conference Record of the 8th Annual ACM SIGPLAN-SIGACT Symp. on Principles of Programming Languages (POPL 1981)","author":"E.M. Myres","year":"1981","unstructured":"Myres, E.M.: A precise interprocedural data flow algorithm. In: Conference Record of the 8th Annual ACM SIGPLAN-SIGACT Symp. on Principles of Programming Languages (POPL 1981), pp. 219\u2013230. ACM Press, New York (1981)"},{"key":"25_CR15","unstructured":"Christodorescu, M., Jha, S.: Static Anlaysis of Executables to Detect Malicious Patterns. In: Proceeding of the 12th USENIX Security Symp (Security 2003), pp. 169\u2013186 (August 2003)"},{"key":"25_CR16","unstructured":"Kruegel, C., Robertson, W., Valeur, F., Vigna, G.: Static disassembly of obfuscated binaries. In: Proceedings of USENIX Security, San Diego, CA, pp. 255\u2013270 (August 2004)"},{"key":"25_CR17","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Krugel, C.: Mining Specification of Malicious Behavior. In: Proceeding of the 6th joint meeting of the European Software Engineering Conference. ACM SIGSOFT Symp. On ESES\/FSE 2007 (2007)","DOI":"10.1145\/1287624.1287628"},{"key":"25_CR18","unstructured":"Bergeron, J., Debbabi, M., Desharnais, J., Erhioui, M.M., Lavoie, Y., Tawbi, N.: Static Detection of Malicious Code in Executable Programs. In: Symposium on Requirements Engineering for Information Security (SREIS 2001) (2001)"},{"key":"25_CR19","series-title":"LNAI","doi-asserted-by":"crossref","first-page":"629","DOI":"10.1007\/11539506_78","volume-title":"Fuzzy Systems and Knowledge Discovery","author":"B. Zhang","year":"2005","unstructured":"Zhang, B., Yin, J., Hao, J.: Using Fuzzy Pattern Recognition to Detect Unknown Malicious Executables Code. In: Wang, L., Jin, Y. (eds.) Fuzzy Systems and Knowledge Discovery. LNCS (LNAI), vol.\u00a03613, pp. 629\u2013634. Springer, Heidelberg (2005)"},{"key":"25_CR20","doi-asserted-by":"crossref","unstructured":"Peisert, S., Bishop, M., Karin, S., Marzullo, K.: Analysis of Computer Intrusions Using Sequences of Function Calls. IEEE Transactions on Dependable and Secure Computing (TDSC)\u00a04(2) (April-June, 2007)","DOI":"10.1109\/TDSC.2007.1003"},{"key":"25_CR21","doi-asserted-by":"crossref","unstructured":"Bergeron, J., Debbabi, M., Erhioui, M.M., Ktari, B.: Static Analysis of Binary Code to Isolate Malicious Behaviors. In: Proceedings of the 8th Workshop on Enabling Technologies on Infrastructure for Collaborative Enterprises, June 16-18, 1999, pp. 184\u2013189 (1999)","DOI":"10.1109\/ENABL.1999.805197"},{"key":"25_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/11780656_14","volume-title":"Information Security and Privacy","author":"H.-M. Sun","year":"2006","unstructured":"Sun, H.-M., Lin, Y.-H., Wu, M.-F.: API Monitoring System for Defeating Worms and Exploits in MS-Windows System. In: Batten, L.M., Safavi-Naini, R. (eds.) ACISP 2006. LNCS, vol.\u00a04058. Springer, Heidelberg (2006)"},{"key":"25_CR23","doi-asserted-by":"crossref","unstructured":"Jesse, C., Rabek, R., Khazan, I., Scott, M., Robert, L., Cunningham, K.: Detection of Injected, Dynamically Generated,and Obfuscated Malicious Code. In: Proc. of 2003 ACM workshop on Rapid Malcode (October 2003)","DOI":"10.1145\/948187.948201"},{"key":"25_CR24","doi-asserted-by":"crossref","unstructured":"Forrest, S., Hofmeyr, S.A., Somayaji, A., Longstaff, T.A.: A Sense of Self for Unix Processes. In: IEEE Symposium on Security and Privacy 1996 (1996)","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"25_CR25","doi-asserted-by":"crossref","unstructured":"Sekar, R., Bendre, M., Dhurjati, D., Bollineni, P.: A Fast Automaton-Based Method for Detecting Anomalous Program Behaviors. In: IEEE Symposium on Security and Privacy (2001)","DOI":"10.1109\/SECPRI.2001.924295"},{"key":"25_CR26","doi-asserted-by":"crossref","unstructured":"Peisert, S., Bishop, M., Karin, S., Marzullo, K.: Analysis of Computer Intrusions Using Sequences of Function Calls. IEEE Transactions On Dependable and Secure Computing\u00a04(2) (April-June, 2007)","DOI":"10.1109\/TDSC.2007.1003"},{"key":"25_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74309-5_22","volume-title":"Advances in Computer Systems Architecture","author":"Q. Zhang","year":"2007","unstructured":"Zhang, Q., Reeves, D.S.: MetaAware: Identifying Metamorphic Malware. In: Choi, L., Paek, Y., Cho, S. (eds.) ACSAC 2007. LNCS, vol.\u00a04697, Springer, Heidelberg (2007)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-70500-0_25.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T05:06:42Z","timestamp":1605762402000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-70500-0_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540699712","9783540705000"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-70500-0_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[]}}