{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T10:52:44Z","timestamp":1725533564381},"publisher-location":"Berlin, Heidelberg","reference-count":24,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642026195"},{"type":"electronic","value":"9783642026201"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-02620-1_4","type":"book-chapter","created":{"date-parts":[[2009,6,20]],"date-time":"2009-06-20T01:46:36Z","timestamp":1245462396000},"page":"44-59","source":"Crossref","is-referenced-by-count":13,"title":["On Improving the Accuracy and Performance of Content-Based File Type Identification"],"prefix":"10.1007","author":[{"given":"Irfan","family":"Ahmed","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kyung-suk","family":"Lhee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hyunjung","family":"Shin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"ManPyo","family":"Hong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"4_CR1","unstructured":"Exclusion option to skip the files for the scanning in Norton antivirus, http:\/\/service1.symantec.com\/SUPPORT\/nav.nsf\/0\/c829006aa01d540b852565a6007770d8?OpenDocument"},{"key":"4_CR2","unstructured":"Stegdetect, http:\/\/packages.debian.org\/unstable\/utils\/stegdetect"},{"key":"4_CR3","unstructured":"Libmagic1 package, http:\/\/packages.debian.org\/unstable\/libs\/libmagic1"},{"key":"4_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2004","unstructured":"Wang, K., Stolfo, S.J.: Anomalous Payload-based Network Intrusion Detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 203\u2013222. Springer, Heidelberg (2004)"},{"key":"4_CR5","doi-asserted-by":"crossref","unstructured":"Ahmed, I., Lhee, K.-s.: Detection of malcodes by packet classification. In: Workshop on Privacy and Security by means of Artificial Intelligence, ARES 2008, pp. 1028\u20131035 (2008)","DOI":"10.1109\/ARES.2008.100"},{"key":"4_CR6","unstructured":"Li, W.J., Wang, K., Stolfo, S., Herzog, B.: Fileprints: Identifying File Types by n-gram Analysis. In: Workshop on Information Assurance and security (IAW 2005), United States Military Academy, West Point, NY, pp. 64\u201371 (2005)"},{"key":"4_CR7","doi-asserted-by":"crossref","unstructured":"Srinivasan, N., Vaidehil, V.: Reduction of False Alarm Rate in Detecting Network Anomaly using Mahalanobis Distance and Similarity Measure. In: Proceedings of ICSCN, pp. 366\u2013371 (2007)","DOI":"10.1109\/ICSCN.2007.350764"},{"key":"4_CR8","volume-title":"Introduction to data mining","author":"P.-N. Tan","year":"2005","unstructured":"Tan, P.-N., Steinbach, M., Kumar, V.: Introduction to data mining. Addison-Wesley, Reading (2005)"},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Martin, K., Nahid, S.: Oscar - file type identification of binary data in disk clusters and RAM pages. In: IFIP security and privacy in dynamic environments, pp. 413\u2013424 (2006)","DOI":"10.1007\/0-387-33406-8_35"},{"key":"4_CR10","unstructured":"Martin, K., Nahid, S.: File type identification of data fragments by their binary structure. In: Proceedings of the IEEE workshop on information assurance, pp. 140\u2013147 (2006)"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Veenman, C.J.: Statistical disk cluster classification for file carving. In: IEEE third international symposium on information assurance and security, pp. 393\u2013398 (2007)","DOI":"10.1109\/IAS.2007.75"},{"key":"4_CR12","doi-asserted-by":"publisher","DOI":"10.1002\/0471271357","volume-title":"Methods of Multivariate Analysis","author":"A.C. Rencher","year":"2002","unstructured":"Rencher, A.C.: Methods of Multivariate Analysis. Wiley Interscience, Hoboken (2002)"},{"key":"4_CR13","unstructured":"File extensions, http:\/\/www.file-extension.com\/"},{"key":"4_CR14","unstructured":"Magic numbers, http:\/\/qdn.qnx.com\/support\/docs\/qnx4\/utils\/m\/magic.html"},{"key":"4_CR15","unstructured":"Nachenberg, C.: Polymorphic virus detection module, United States Patent # 5,826,013 (1998)"},{"key":"4_CR16","unstructured":"Szor, P., Ferrie, P.: Hunting for metamorphic. In: Proceedings of Virus Bulletin Conference, pp. 123\u2013144 (2001)"},{"key":"4_CR17","unstructured":"RIX, Writing IA32 Alphanumeric Shell codes, http:\/\/www.phrack.org\/issues.html?issue=57&id=15#article"},{"key":"4_CR18","unstructured":"Eller, R.: Bypassing MSB Data Filters for Buffer Overflow Exploits on Intel platforms (2003), http:\/\/community.core-di.com\/~juliano\/bypassmsb.txt"},{"key":"4_CR19","doi-asserted-by":"crossref","unstructured":"McDaniel, M., Hossain Heydari, M.: Content Based File Type Detection Algorithms. In: Proceedings of the 36th Annual Hawaii International Conference on System Sciences (2003)","DOI":"10.1109\/HICSS.2003.1174905"},{"key":"4_CR20","unstructured":"Kolmogorov, A.N.: Three approaches to the quantitative definition of information. Problems of Information Transmission, 1\u201311 (1965)"},{"issue":"1","key":"4_CR21","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/j.diin.2008.05.005","volume":"5","author":"W.C. Calhoun","year":"2008","unstructured":"Calhoun, W.C., Coles, D.: Predicting the types of file fragments. Digital Investigation\u00a05(1), 14\u201320 (2008)","journal-title":"Digital Investigation"},{"key":"4_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1007\/11856214_12","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2006","unstructured":"Wang, K., Parekh, J.J., Stolfo, S.J.: Anagram: A Content Anomaly Detector Resistant to Mimicry Attack. In: Zamboni, D., Kr\u00fcgel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 226\u2013248. Springer, Heidelberg (2006)"},{"key":"4_CR23","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation: in 16th USENIX Security Symposium (2007)"},{"key":"4_CR24","doi-asserted-by":"crossref","unstructured":"Ward, J.H.: Hierarchical grouping to optimize an objective function. Journal of the American Statistical Association, 235\u2013244 (1963)","DOI":"10.1080\/01621459.1963.10500845"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-02620-1_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,20]],"date-time":"2019-05-20T20:32:56Z","timestamp":1558384376000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-02620-1_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642026195","9783642026201"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-02620-1_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2009]]}}}