{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:40:51Z","timestamp":1742913651698,"version":"3.40.3"},"publisher-location":"Singapore","reference-count":23,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789819902712"},{"type":"electronic","value":"9789819902729"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-981-99-0272-9_7","type":"book-chapter","created":{"date-parts":[[2023,2,15]],"date-time":"2023-02-15T14:16:09Z","timestamp":1676470569000},"page":"103-115","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["System Call Processing Using Lightweight NLP for\u00a0IoT Behavioral Malware Detection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4391-0269","authenticated-orcid":false,"given":"John","family":"Carter","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6354-4281","authenticated-orcid":false,"given":"Spiros","family":"Mancoridis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4066-7267","authenticated-orcid":false,"given":"Malvin","family":"Nkomo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9235-6922","authenticated-orcid":false,"given":"Steven","family":"Weber","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1936-2514","authenticated-orcid":false,"given":"Kapil R.","family":"Dandekar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,2,16]]},"reference":[{"key":"7_CR1","doi-asserted-by":"publisher","unstructured":"Ali, A.I., Partal, S.Z., Kepke, S., Partal, H.P.: ZigBee and LoRa based wireless sensors for smart environment and IoT applications. In: 2019 1st Global Power, Energy and Communication Conference (GPECOM), pp. 19\u201323 (2019). https:\/\/doi.org\/10.1109\/GPECOM.2019.8778505","DOI":"10.1109\/GPECOM.2019.8778505"},{"key":"7_CR2","doi-asserted-by":"publisher","unstructured":"An, N., Duff, A., Noorani, M., Weber, S., Mancoridis, S.: Malware anomaly detection on virtual assistants, pp. 124\u2013131, October 2018. https:\/\/doi.org\/10.1109\/MALWARE.2018.8659366","DOI":"10.1109\/MALWARE.2018.8659366"},{"key":"7_CR3","unstructured":"Antonakakis, M., et al.: Understanding the mirai botnet. In: 26th USENIX security symposium (USENIX Security 17), pp. 1093\u20131110 (2017)"},{"key":"7_CR4","doi-asserted-by":"publisher","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","volume":"8","author":"A Aslan","year":"2020","unstructured":"Aslan, A., Samet, R.: A comprehensive review on malware detection approaches. IEEE Access 8, 6249\u20136271 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2019.2963724","journal-title":"IEEE Access"},{"key":"7_CR5","doi-asserted-by":"publisher","unstructured":"Bilge, L., Dumitra\u015f, T.: Before we knew it: an empirical study of zero-day attacks in the real world. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security. CCS 2012, New York, NY, USA, pp. 833\u2013844. Association for Computing Machinery (2012). https:\/\/doi.org\/10.1145\/2382196.2382284","DOI":"10.1145\/2382196.2382284"},{"key":"7_CR6","doi-asserted-by":"publisher","unstructured":"Bradley, A.P.: The use of the area under the ROC curve in the evaluation of machine learning algorithms. Pattern Recognition 30(7), 1145\u20131159 (1997). https:\/\/doi.org\/10.1016\/S0031-3203(96)00142-2, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0031320396001422","DOI":"10.1016\/S0031-3203(96)00142-2"},{"key":"7_CR7","doi-asserted-by":"publisher","unstructured":"Carter, J., Mancoridis, S., Galinkin, E.: Fast, lightweight IoT anomaly detection using feature pruning and PCA. In: Proceedings of the 37th ACM\/SIGAPP Symposium on Applied Computing. SAC 2022, New York, NY, USA, pp. 133\u2013138. Association for Computing Machinery (2022). https:\/\/doi.org\/10.1145\/3477314.3508377","DOI":"10.1145\/3477314.3508377"},{"key":"7_CR8","unstructured":"Chung, J., Gulcehre, C., Cho, K., Bengio, Y.: Empirical evaluation of gated recurrent neural networks on sequence modeling. arXiv preprint arXiv:1412.3555 (2014)"},{"key":"7_CR9","unstructured":"Du, W.K.: Tool 78: Reset every TCP packet. https:\/\/web.ecs.syr.edu\/~wedu\/Teaching\/cis758\/netw522\/netwox-doc_html\/tools\/78.html"},{"key":"7_CR10","doi-asserted-by":"publisher","unstructured":"Hasan, M., Islam, M.M., Zarif, M.I.I., Hashem, M.: Attack and anomaly detection in IoT sensors in IoT sites using machine learning approaches. Internet of Things 7, 100059 (2019). https:\/\/doi.org\/10.1016\/j.iot.2019.100059, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2542660519300241","DOI":"10.1016\/j.iot.2019.100059"},{"issue":"8","key":"7_CR11","doi-asserted-by":"publisher","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter, S., Schmidhuber, J.: Long short-term memory. Neural Comput. 9(8), 1735\u20131780 (1997). https:\/\/doi.org\/10.1162\/neco.1997.9.8.1735","journal-title":"Neural Comput."},{"key":"7_CR12","doi-asserted-by":"publisher","unstructured":"Jain, A., et al.: Overview and importance of data quality for machine learning tasks. In: Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. KDD 2020, pp. 3561\u20133562, New York, NY, USA. Association for Computing Machinery (2020). https:\/\/doi.org\/10.1145\/3394486.3406477, https:\/\/doi.org\/10.1145\/3394486.3406477","DOI":"10.1145\/3394486.3406477 10.1145\/3394486.3406477"},{"key":"7_CR13","doi-asserted-by":"publisher","unstructured":"Kang, D.K., Fuller, D., Honavar, V.: Learning classifiers for misuse and anomaly detection using a bag of system calls representation. In: Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop, pp. 118\u2013125 (2005). https:\/\/doi.org\/10.1109\/IAW.2005.1495942","DOI":"10.1109\/IAW.2005.1495942"},{"key":"7_CR14","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MC.2017.201","volume":"50","author":"C Kolias","year":"2017","unstructured":"Kolias, C., Kambourakis, G., Stavrou, A., Voas, J.: DDoS in the IoT: Mirai and other botnets. Computer 50, 80\u201384 (2017). https:\/\/doi.org\/10.1109\/MC.2017.201","journal-title":"Computer"},{"key":"7_CR15","doi-asserted-by":"publisher","unstructured":"Lemay, A., Calvet, J., Menet, F., Fernandez, J.M.: Survey of publicly available reports on advanced persistent threat actors. Comput. Secur. 72, 26\u201359 (2018). https:\/\/doi.org\/10.1016\/j.cose.2017.08.005, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404817301608","DOI":"10.1016\/j.cose.2017.08.005"},{"key":"7_CR16","doi-asserted-by":"publisher","unstructured":"Li, S., Zhang, Q., Wu, X., Han, W., Tian, Z., Yu, S.: Attribution classification method of apt malware in IoT using machine learning techniques. Sec. Commun. Netw. 2021 (2021). https:\/\/doi.org\/10.1155\/2021\/9396141","DOI":"10.1155\/2021\/9396141"},{"key":"7_CR17","doi-asserted-by":"publisher","unstructured":"Liu, A., Martin, C., Hetherington, T., Matzner, S.: A comparison of system call feature representations for insider threat detection. In: Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop, pp. 340\u2013347 (2005). https:\/\/doi.org\/10.1109\/IAW.2005.1495972","DOI":"10.1109\/IAW.2005.1495972"},{"key":"7_CR18","doi-asserted-by":"publisher","first-page":"177","DOI":"10.5121\/ijcses.2011.2413","volume":"2","author":"A Mittal","year":"2011","unstructured":"Mittal, A., Shrivastava, K., Manoria, M.: A review of DDOS attack and its countermeasures in TCP based networks. IJCSES 2, 177\u2013187 (2011). https:\/\/doi.org\/10.5121\/ijcses.2011.2413","journal-title":"IJCSES"},{"key":"7_CR19","first-page":"2825","volume":"12","author":"F Pedregosa","year":"2011","unstructured":"Pedregosa, F., et al.: Scikit-learn: machine learning in Python. J. Mach. Learn. Res. 12, 2825\u20132830 (2011)","journal-title":"J. Mach. Learn. Res."},{"key":"7_CR20","unstructured":"Ramos, J.: Using TF-IDF to determine word relevance in document queries, January 2003"},{"key":"7_CR21","doi-asserted-by":"publisher","unstructured":"Surya, S.R., Magrica, G.A.: A survey on wireless networks attacks. In: 2017 2nd International Conference on Computing and Communications Technologies (ICCCT), pp. 240\u2013247 (2017). https:\/\/doi.org\/10.1109\/ICCCT2.2017.7972278","DOI":"10.1109\/ICCCT2.2017.7972278"},{"key":"7_CR22","unstructured":"ThingsBoard - Open source IoT Platform: Thingsboard - open source IoT platform. https:\/\/thingsboard.io"},{"key":"7_CR23","doi-asserted-by":"publisher","unstructured":"Wallach, H.M.: Topic modeling: Beyond bag-of-words. In: Proceedings of the 23rd International Conference on Machine Learning. ICML 2006, New York, NY, USA, pp. 977\u2013984, Association for Computing Machinery (2006). https:\/\/doi.org\/10.1145\/1143844.1143967","DOI":"10.1145\/1143844.1143967"}],"container-title":["Communications in Computer and Information Science","Ubiquitous Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-99-0272-9_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,13]],"date-time":"2023-06-13T17:02:55Z","timestamp":1686675775000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-99-0272-9_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9789819902712","9789819902729"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-981-99-0272-9_7","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"16 February 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"UbiSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Ubiquitous Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Zhangjiajie","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 December 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31 December 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ubisec2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ubisecurity.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"98","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"34","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}