{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T12:16:06Z","timestamp":1771848966670,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":33,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642330179","type":"print"},{"value":"9783642330186","type":"electronic"}],"license":[{"start":{"date-parts":[[2013,1,1]],"date-time":"2013-01-01T00:00:00Z","timestamp":1356998400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-33018-6_28","type":"book-chapter","created":{"date-parts":[[2012,8,23]],"date-time":"2012-08-23T09:14:19Z","timestamp":1345713259000},"page":"271-280","source":"Crossref","is-referenced-by-count":104,"title":["OPEM: A Static-Dynamic Approach for Machine-Learning-Based Malware Detection"],"prefix":"10.1007","author":[{"given":"Igor","family":"Santos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jaime","family":"Devesa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"F\u00e9lix","family":"Brezo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Javier","family":"Nieves","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pablo Garcia","family":"Bringas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"28_CR1","doi-asserted-by":"crossref","unstructured":"Schultz, M., Eskin, E., Zadok, F., Stolfo, S.: Data mining methods for detection of new malicious executables. In: Proceedings of the 22nd IEEE Symposium on Security and Privacy, pp. 38\u201349 (2001)","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"28_CR2","first-page":"470","volume-title":"Proceedings of the 10th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"J. Kolter","year":"2004","unstructured":"Kolter, J., Maloof, M.: Learning to detect malicious executables in the wild. In: Proceedings of the 10th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 470\u2013478. ACM, New York (2004)"},{"key":"28_CR3","doi-asserted-by":"crossref","unstructured":"Moskovitch, R., Stopel, D., Feher, C., Nissim, N., Elovici, Y.: Unknown malcode detection via text categorization and the imbalance problem. In: Proceedings of the 6th IEEE International Conference on Intelligence and Security Informatics (ISI), pp. 156\u2013161 (2008)","DOI":"10.1109\/ISI.2008.4565046"},{"key":"28_CR4","doi-asserted-by":"crossref","unstructured":"Santos, I., Penya, Y., Devesa, J., Bringas, P.: N-Grams-based file signatures for malware detection. In: Proceedings of the 11th International Conference on Enterprise Information Systems (ICEIS). AIDSS, pp. 317\u2013320 (2009)","DOI":"10.5220\/0001863603170320"},{"key":"28_CR5","doi-asserted-by":"crossref","unstructured":"Christodorescu, M.: Behavior-based malware detection. PhD thesis (2007)","DOI":"10.1007\/978-0-387-44599-1"},{"key":"28_CR6","doi-asserted-by":"crossref","unstructured":"Royal, P., Halpin, M., Dagon, D., Edmonds, R., Lee, W.: Polyunpack: Automating the hidden-code extraction of unpack-executing malware. In: Proceedings of the 22nd Annual Computer Security Applications Conference (ACSAC), pp. 289\u2013300 (2006)","DOI":"10.1109\/ACSAC.2006.38"},{"key":"28_CR7","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC), pp. 421\u2013430 (2007)","DOI":"10.1109\/ACSAC.2007.21"},{"key":"28_CR8","doi-asserted-by":"crossref","unstructured":"Kolbitsch, C., Holz, T., Kruegel, C., Kirda, E.: Inspector Gadget: Automated Extraction of Proprietary Gadgets from Malware Binaries. In: Proceedings of the 30th IEEE Symposium on Security & Privacy (2010)","DOI":"10.1109\/SP.2010.10"},{"key":"28_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1007\/978-3-540-70542-0_8","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"L. Cavallaro","year":"2008","unstructured":"Cavallaro, L., Saxena, P., Sekar, R.: On the Limits of Information Flow Techniques for Malware Analysis and Containment. In: Zamboni, D. (ed.) DIMVA 2008. LNCS, vol.\u00a05137, pp. 143\u2013163. Springer, Heidelberg (2008)"},{"key":"28_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/978-3-642-11747-3_3","volume-title":"Engineering Secure Software and Systems","author":"I. Santos","year":"2010","unstructured":"Santos, I., Brezo, F., Nieves, J., Penya, Y.K., Sanz, B., Laorden, C., Bringas, P.G.: Idea: Opcode-Sequence-Based Malware Detection. In: Massacci, F., Wallach, D., Zannone, N. (eds.) ESSoS 2010. LNCS, vol.\u00a05965, pp. 35\u201343. Springer, Heidelberg (2010)"},{"key":"28_CR11","unstructured":"Devesa, J., Santos, I., Cantero, X., Penya, Y.K., Bringas, P.G.: Automatic Behaviour-based Analysis and Classification System for Malware Detection. In: Proceedings of the 12th International Conference on Enterprise Information Systems, ICEIS (2010)"},{"key":"28_CR12","unstructured":"McGill, M., Salton, G.: Introduction to modern information retrieval. McGraw-Hill (1983)"},{"issue":"2","key":"28_CR13","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C. Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using cwsandbox. IEEE Security & Privacy\u00a05(2), 32\u201339 (2007)","journal-title":"IEEE Security & Privacy"},{"key":"28_CR14","unstructured":"Ferrie, P.: Attacks on virtual machine emulators. In: Proc. of AVAR Conference, pp. 128\u2013143 (2006)"},{"key":"28_CR15","unstructured":"Lee, T., Mody, J.: Behavioral classification. In: Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR) Conference (2006)"},{"issue":"1","key":"28_CR16","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1093\/biomet\/70.1.163","volume":"70","author":"J.T. Kent","year":"1983","unstructured":"Kent, J.T.: Information gain and a general measure of correlation. Biometrika\u00a070(1), 163 (1983)","journal-title":"Biometrika"},{"key":"28_CR17","volume-title":"Pattern recognition and machine learning","author":"C.M. Bishop","year":"2006","unstructured":"Bishop, C.M.: Pattern recognition and machine learning. Springer, New York (2006)"},{"key":"28_CR18","unstructured":"Kohavi, R.: A study of cross-validation and bootstrap for accuracy estimation and model selection. In: International Joint Conference on Artificial Intelligence, vol.\u00a014, pp. 1137\u20131145 (1995)"},{"issue":"1","key":"28_CR19","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1023\/A:1010933404324","volume":"45","author":"L. Breiman","year":"2001","unstructured":"Breiman, L.: Random forests. Machine Learning\u00a045(1), 5\u201332 (2001)","journal-title":"Machine Learning"},{"key":"28_CR20","unstructured":"Quinlan, J.: C4. 5 programs for machine learning. Morgan Kaufmann Publishers (1993)"},{"key":"28_CR21","doi-asserted-by":"crossref","unstructured":"Cooper, G.F., Herskovits, E.: A bayesian method for constructing bayesian belief networks from databases. In: Proceedings of the 7th Conference on Uncertainty in Artificial Intelligence (1991)","DOI":"10.1016\/B978-1-55860-203-8.50015-2"},{"key":"28_CR22","unstructured":"Russell, S.J., Norvig: Artificial Intelligence: A Modern Approach, 2nd edn. Prentice-Hall (2003)"},{"key":"28_CR23","unstructured":"Geiger, D., Goldszmidt, M., Provan, G., Langley, P., Smyth, P.: Bayesian network classifiers. Machine Learning, 131\u2013163 (1997)"},{"key":"28_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1007\/BFb0026666","volume-title":"Machine Learning: ECML-98","author":"D.D. Lewis","year":"1998","unstructured":"Lewis, D.D.: Naive (Bayes) at Forty: The Independence Assumption in Information Retrieval. In: N\u00e9dellec, C., Rouveirol, C. (eds.) ECML 1998. LNCS, vol.\u00a01398, pp. 4\u201318. Springer, Heidelberg (1998)"},{"key":"28_CR25","unstructured":"Platt, J.: Sequential minimal optimization: A fast algorithm for training support vector machines. Advances in Kernel Methods-Support Vector Learning\u00a0208 (1999)"},{"issue":"6","key":"28_CR26","doi-asserted-by":"publisher","first-page":"783","DOI":"10.1016\/S0893-6080(99)00032-5","volume":"12","author":"S. Amari","year":"1999","unstructured":"Amari, S., Wu, S.: Improving support vector machine classifiers by modifying kernel functions. Neural Networks\u00a012(6), 783\u2013789 (1999)","journal-title":"Neural Networks"},{"issue":"1","key":"28_CR27","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1016\/j.chemolab.2005.09.003","volume":"81","author":"B. \u00dcst\u00fcn","year":"2006","unstructured":"\u00dcst\u00fcn, B., Melssen, W.J., Buydens, L.M.C.: Facilitating the application of Support Vector Regression by using a universal Pearson VII function based kernel. Chemometrics and Intelligent Laboratory Systems\u00a081(1), 29\u201340 (2006)","journal-title":"Chemometrics and Intelligent Laboratory Systems"},{"issue":"2","key":"28_CR28","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1504\/IJCAT.2009.026595","volume":"35","author":"Y. Singh","year":"2009","unstructured":"Singh, Y., Kaur, A., Malhotra, R.: Comparative analysis of regression and machine learning methods for predicting fault proneness models. International Journal of Computer Applications in Technology\u00a035(2), 183\u2013193 (2009)","journal-title":"International Journal of Computer Applications in Technology"},{"key":"28_CR29","doi-asserted-by":"crossref","unstructured":"Kang, M., Poosankam, P., Yin, H.: Renovo: A hidden code extractor for packed executables. In: Proceedings of the 2007 ACM Workshop on Recurring Malcode, pp. 46\u201353 (2007)","DOI":"10.1145\/1314389.1314399"},{"key":"28_CR30","doi-asserted-by":"crossref","unstructured":"Martignoni, L., Christodorescu, M., Jha, S.: Omniunpack: Fast, generic, and safe unpacking of malware. In: Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC), pp. 431\u2013441 (2007)","DOI":"10.1109\/ACSAC.2007.15"},{"key":"28_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1007\/978-3-540-88313-5_31","volume-title":"Computer Security - ESORICS 2008","author":"M. Sharif","year":"2008","unstructured":"Sharif, M., Yegneswaran, V., Saidi, H., Porras, P.A., Lee, W.: Eureka: A Framework for Enabling Static Malware Analysis. In: Jajodia, S., Lopez, J. (eds.) ESORICS 2008. LNCS, vol.\u00a05283, pp. 481\u2013500. Springer, Heidelberg (2008)"},{"key":"28_CR32","unstructured":"Ferrie, P.: Anti-Unpacker Tricks. In: Proc. of the 2nd International CARO Workshop (2008)"},{"key":"28_CR33","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Exploring multiple execution paths for malware analysis. In: Proceedings of the 28th IEEE Symposium on Security and Privacy, pp. 231\u2013245 (2007)","DOI":"10.1109\/SP.2007.17"}],"container-title":["Advances in Intelligent Systems and Computing","International Joint Conference CISIS\u201912-ICEUTE\u00b412-SOCO\u00b412 Special Sessions"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-33018-6_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,7]],"date-time":"2025-04-07T04:04:20Z","timestamp":1743998660000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-33018-6_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642330179","9783642330186"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-33018-6_28","relation":{},"ISSN":["2194-5357","2194-5365"],"issn-type":[{"value":"2194-5357","type":"print"},{"value":"2194-5365","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013]]}}}