{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T23:24:43Z","timestamp":1783553083006,"version":"3.55.0"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2017,7,25]],"date-time":"2017-07-25T00:00:00Z","timestamp":1500940800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"name":"Scientific Research Foundation in Shenzhen","award":["JCYJ20140627163809422"],"award-info":[{"award-number":["JCYJ20140627163809422"]}]},{"name":"Scientific Research Foundation in Shenzhen","award":["JCYJ20160525163756635"],"award-info":[{"award-number":["JCYJ20160525163756635"]}]},{"DOI":"10.13039\/501100003453","name":"Natural Science Foundation of Guangdong Province","doi-asserted-by":"crossref","award":["Grant No. 2016A030313664"],"award-info":[{"award-number":["Grant No. 2016A030313664"]}],"id":[{"id":"10.13039\/501100003453","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2019,2]]},"DOI":"10.1007\/s00521-017-3077-6","type":"journal-article","created":{"date-parts":[[2017,7,25]],"date-time":"2017-07-25T06:28:52Z","timestamp":1500964132000},"page":"461-472","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":116,"title":["Malware detection based on deep learning algorithm"],"prefix":"10.1007","volume":"31","author":[{"given":"Ding","family":"Yuxin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhu","family":"Siyi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,7,25]]},"reference":[{"key":"3077_CR1","doi-asserted-by":"crossref","unstructured":"Ahmed F, Hameed H, Shafiq MZ, Farooq M (2009) Using spatio-temporal information in API calls with machine learning algorithms for malware detection. In: AISec \u201809 Proceedings of the 2nd ACM workshop on Security and artificial intelligence, pp 55\u201362","DOI":"10.1145\/1654988.1655003"},{"key":"3077_CR2","doi-asserted-by":"crossref","unstructured":"Christodorescu M, Jha S (2004) Testing malware detectors. In: ACM SIGSOFT international symposium on software testing and analysis (ISSTA \u201804), Boston, USA, pp 34\u201344","DOI":"10.1145\/1007512.1007518"},{"issue":"1","key":"3077_CR3","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/TASL.2011.2134090","volume":"20","author":"GE Dahl","year":"2012","unstructured":"Dahl GE, Yu D, Deng L, Acero A (2012) Context-dependent pretrained deep neural networks for large-vocabulary speech recognition. IEEE Trans Audio Speech Lang Process 20(1):30\u201341","journal-title":"IEEE Trans Audio Speech Lang Process"},{"issue":"1","key":"3077_CR4","first-page":"64","volume":"44","author":"Y Ding","year":"2014","unstructured":"Ding Y, Dai W, Yan S et al (2014) Control flow-based opcode behavior analysis for malware detection. Comput Secur 44(1):64\u201382","journal-title":"Comput Secur"},{"key":"3077_CR5","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1016\/j.cose.2014.07.004","volume":"46","author":"AAE Elhadi","year":"2014","unstructured":"Elhadi AAE, Maarof MA, Barry BIA, Hamza H (2014) Enhancing the detection of metamorphic malware using call graphs. Comput Secur 46:62\u201378","journal-title":"Comput Secur"},{"key":"3077_CR6","first-page":"625","volume":"11","author":"D Erhan","year":"2010","unstructured":"Erhan D, Bengio Y, Courville A, Manzagol P, Vincent P (2010) Why does unsupervised pre-training help deep learning? J Mach Learn Res 11:625\u2013660","journal-title":"J Mach Learn Res"},{"issue":"3","key":"3077_CR7","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.jvlc.2012.02.002","volume":"23","author":"M Eskandari","year":"2012","unstructured":"Eskandari M, Hashemi S (2012) A graph mining approach for detecting unknown malwares. J Visu Lang Comput 23(3):154\u2013162","journal-title":"J Visu Lang Comput"},{"key":"3077_CR8","unstructured":"Hex-Rays SA (2009) IDA pro Introduction. http:\/\/www.hex-rays.com\/products.shtml\/ . Accessed 23 Mar 2010"},{"key":"3077_CR9","doi-asserted-by":"crossref","unstructured":"Henchiri O, Japkowicz N (2006) A feature selection and evaluation scheme for computer virus detection. In: Proceedings ofICDM-2006, Hong Kong, pp 891\u2013895","DOI":"10.1109\/ICDM.2006.4"},{"issue":"6","key":"3077_CR10","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/MSP.2012.2205597","volume":"29","author":"G Hinton","year":"2012","unstructured":"Hinton G et al (2012) Deep neural networks for acoustic modeling in speech recognition: the shared views of four research groups. IEEE Signal Process Mag 29(6):82\u201397","journal-title":"IEEE Signal Process Mag"},{"key":"3077_CR11","doi-asserted-by":"publisher","first-page":"1527","DOI":"10.1162\/neco.2006.18.7.1527","volume":"18","author":"GE Hinton","year":"2006","unstructured":"Hinton GE, Osindero S, Teh YW (2006) A fast learning algorithm for deep belief nets. Neural Comput 18:1527\u20131554","journal-title":"Neural Comput"},{"key":"3077_CR12","doi-asserted-by":"publisher","first-page":"646","DOI":"10.1016\/j.jnca.2012.10.004","volume":"36","author":"R Islam","year":"2013","unstructured":"Islam R et al (2013) Classification of malware based on integrated static and dynamic features. J Netw Comput Appl 36:646\u2013656","journal-title":"J Netw Comput Appl"},{"key":"3077_CR13","doi-asserted-by":"crossref","unstructured":"Kolter JZ, Maloof MA (2004) Learning to detect malicious executables in the wild. In: Proceedings of the tenth ACM SIGKDD international conference on knowledge discovery and data mining. ACM Press, New York, NY, pp 470\u2013478","DOI":"10.1145\/1014052.1014105"},{"issue":"2","key":"3077_CR14","first-page":"1","volume":"44","author":"E Manuel","year":"2012","unstructured":"Manuel E, Theodoor S, Engin K, Christopher K (2012) A survey on automated dynamic malware-analysis techniques and tools. ACM Comput Surv 44(2):1\u201342","journal-title":"ACM Comput Surv"},{"key":"3077_CR15","unstructured":"Mitchell TM (1997) Machine learning. McGraw-Hill, New York. ISBN: 0070428077"},{"key":"3077_CR16","doi-asserted-by":"crossref","unstructured":"Moskovitch R, Feher C, Zachar N, Berger E, Gitelman M, Dolev S, et al (2008a) Unknown malcode detection using OPCODE representation. In: European conference on intelligence and security informatics 2008 (EuroISI08), Esbjerg, Denmark, pp 204\u2013215","DOI":"10.1007\/978-3-540-89900-6_21"},{"key":"3077_CR17","doi-asserted-by":"crossref","unstructured":"Moskovitch R, Stopel D, Feher C, Nissim N, Elovici Y (2008b) Unknown malcode detection via text categorization and the imbalance problem. In: IEEE intelligence and security informatics, Taiwan, pp 156\u2013161","DOI":"10.1109\/ISI.2008.4565046"},{"key":"3077_CR18","unstructured":"Peid (2007) Peid v0.94. http:\/\/www.peid.info\/ . Accessed 23 Mar 2010"},{"key":"3077_CR19","doi-asserted-by":"publisher","first-page":"1967","DOI":"10.1162\/NECO_a_00311","volume":"24","author":"R Salakhutdinov","year":"2012","unstructured":"Salakhutdinov R, Hinton G (2012) An efficient learning procedure for deep Boltzmann machines. Neural Comput 24:1967\u20132006","journal-title":"Neural Comput"},{"key":"3077_CR20","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1016\/0306-4573(88)90021-0","volume":"24","author":"G Salton","year":"1988","unstructured":"Salton G, Buckley C (1988) Term-weighting approaches in automatic text retrieval. Inf Process Manag 24:513\u2013523","journal-title":"Inf Process Manag"},{"key":"3077_CR21","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1016\/j.ins.2011.08.020","volume":"231","author":"I Santos","year":"2013","unstructured":"Santos I, Brezo F, Ugarte-pedrero X, Bringas PG (2013) Opcode sequences as representation of executables for data-mining-based unknown malware detection. Inf Sci 231:64\u201382","journal-title":"Inf Sci"},{"issue":"4","key":"3077_CR22","doi-asserted-by":"publisher","first-page":"778","DOI":"10.1109\/TASLP.2014.2303296","volume":"22","author":"R Sarikaya","year":"2014","unstructured":"Sarikaya R, Hinton GE, Deoras A (2014) Application of deep belief networks for natural language understanding. IEEE Trans Audio Speech Lang Process 22(4):778\u2013784","journal-title":"IEEE Trans Audio Speech Lang Process"},{"key":"3077_CR23","doi-asserted-by":"crossref","unstructured":"Saxe J, Berlin K (2015) Deep neural network based malware detection using two dimensional binary program features. In: International conference on malicious & unwanted software, pp 11\u201320","DOI":"10.1109\/MALWARE.2015.7413680"},{"issue":"1","key":"3077_CR24","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.istr.2009.03.003","volume":"14","author":"A Shabtai","year":"2009","unstructured":"Shabtai A, Moskovitch R, Elovici Y, Glezer C (2009) Detection of malicious code by applying machine learning classifiers on static features\u2014a state-of-the-art survey. Inf Secur Tech Rep 14(1):16\u201329","journal-title":"Inf Secur Tech Rep"},{"key":"3077_CR25","doi-asserted-by":"crossref","unstructured":"Schultz MG, Eskin E, Zadok E, Stolfo SJ (2001) Data mining methods for detection of new malicious executables. In: Proceedings of the IEEE symposium on security and privacy, Oakland USA, pp 38\u201349","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"3077_CR26","doi-asserted-by":"crossref","unstructured":"Stopel D, Boger Z, Moskovitch R, Shahar Y, Elovici Y (2006a) Application of Artificial Neural Networks Techniques to Computer Worm Detections. In: Proceedings of IEEE international joint conference on neural networks, Vancouver","DOI":"10.1109\/IJCNN.2006.247059"},{"key":"3077_CR27","unstructured":"Stopel D, Boger Z, Moskovitch R, Shahar Y, Elovici Y (2006b) Improving worm detection with artificial neural networks through feature selection and temporal analysis techniques. In: Proceedings of the third international conference on neural networks, Barcelona"},{"key":"3077_CR28","doi-asserted-by":"crossref","unstructured":"Tian R, Islam R, Batten L, Versteeg S (2010) Differentiating malware from cleanware using behavioral analysis. In: Proceedings of the 5th international conference on malicious and unwanted software: MALWARE 2010, pp 23\u201330","DOI":"10.1109\/MALWARE.2010.5665796"},{"issue":"1","key":"3077_CR29","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1016\/S0031-3203(02)00026-2","volume":"36","author":"DY Yeung","year":"2003","unstructured":"Yeung DY, Ding Y (2003) Host-based intrusion detection using dynamic and static behavioral models. Pattern Recognit 36(1):229\u2013243","journal-title":"Pattern Recognit"},{"key":"3077_CR30","unstructured":"Yuan MY (2014) Data mining and machine learning: WEKA applied technology and practice. Tsinghua University Press. ISBN: 978-7302371748"},{"issue":"1","key":"3077_CR31","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1049\/iet-ifs.2012.0289","volume":"8","author":"Z Zhao","year":"2014","unstructured":"Zhao Z, Wang J, Bai J (2014) Malware detection method based on the control-flow construct feature of software. Inf Secur IET 8(1):18\u201324","journal-title":"Inf Secur IET"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-017-3077-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00521-017-3077-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-017-3077-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,1]],"date-time":"2019-10-01T11:18:54Z","timestamp":1569928734000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00521-017-3077-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,7,25]]},"references-count":31,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2019,2]]}},"alternative-id":["3077"],"URL":"https:\/\/doi.org\/10.1007\/s00521-017-3077-6","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,7,25]]},"assertion":[{"value":"10 May 2015","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 June 2017","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 July 2017","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}