{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T14:06:39Z","timestamp":1774533999557,"version":"3.50.1"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2011,4,26]],"date-time":"2011-04-26T00:00:00Z","timestamp":1303776000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Knowl Inf Syst"],"published-print":{"date-parts":[[2012,3]]},"DOI":"10.1007\/s10115-011-0393-5","type":"journal-article","created":{"date-parts":[[2011,4,25]],"date-time":"2011-04-25T04:12:37Z","timestamp":1303704757000},"page":"589-612","source":"Crossref","is-referenced-by-count":47,"title":["ELF-Miner: using structural knowledge and data mining methods to detect new (Linux) malicious executables"],"prefix":"10.1007","volume":"30","author":[{"given":"Farrukh","family":"Shahzad","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muddassar","family":"Farooq","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2011,4,26]]},"reference":[{"key":"393_CR1","unstructured":"Fedora Project: Security features of Linux. http:\/\/fedoraproject.org\/wiki\/Security\/Features (viewed-on-June-18-2010)"},{"key":"393_CR2","unstructured":"Linux market share sees increase. http:\/\/www.gamegrep.com\/news\/8342-linux_market_share_sees_increase\/ (viewed-on-July-07-2010)"},{"key":"393_CR3","unstructured":"Offensive Computing: Online malware database. http:\/\/www.offensivecomputing.net\/"},{"key":"393_CR4","unstructured":"Symbol Table Layout and Conventions. http:\/\/docs.sun.com\/app\/docs\/doc\/819-0690\/stlac?a=view (viewed-on-July-7-2010)"},{"key":"393_CR5","unstructured":"The Section Header Table (ELF). http:\/\/www.cs.ucdavis.edu (viewed-on-July-07-2010)"},{"key":"393_CR6","unstructured":"User Commands, Linux Man Pages Section 1. http:\/\/docs.sun.com\/app\/docs\/doc\/819-2239\/strip-1?a=view (viewed-on-July-07-2010)"},{"key":"393_CR7","unstructured":"VX Heavens: Free malware collection website. http:\/\/vx.netlux.org\/"},{"issue":"3","key":"393_CR8","first-page":"307","volume":"13","author":"J Alcala-Fdez","year":"2009","unstructured":"Alcala-Fdez J, Garcia S, Berlanga FJ, Fernandez A, Sanchez L, del Jesus MJ, Herrera F (2009) KEEL: a software tool to assess evolutionary algorithms for data mining problems. Soft Comput A Fus Found Methodol Appl 13(3): 307\u2013318","journal-title":"Soft Comput A Fus Found Methodol Appl"},{"key":"393_CR9","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1007\/978-3-540-71231-2_5","volume":"4399","author":"J Bacardit","year":"2007","unstructured":"Bacardit J, Garrell J (2007) Bloat control and generalization pressure using the minimum description length principle for a pittsburgh approach learning classifier system. Learn Class Syst 4399: 59\u201379","journal-title":"Learn Class Syst"},{"issue":"3","key":"393_CR10","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1162\/106365603322365289","volume":"11","author":"E Bernad\u00f3-Mansilla","year":"2003","unstructured":"Bernad\u00f3-Mansilla E, Garrell-Guiu JM (2003) Accuracy-based learning classifier systems: models, analysis and applications to classification tasks. Evol Comput 11(3): 209\u2013238","journal-title":"Evol Comput"},{"key":"393_CR11","doi-asserted-by":"crossref","unstructured":"Cohen WW (1995) Fast effective rule induction. In: Proceedings of the international conference on machine learning. Morgan Kaufmann, London, pp 115\u2013123","DOI":"10.1016\/B978-1-55860-377-6.50023-2"},{"key":"393_CR12","volume-title":"Elements of information theory","author":"TM Cover","year":"2006","unstructured":"Cover TM, Thomas JA (2006) Elements of information theory. Wiley, London"},{"key":"393_CR13","first-page":"1","volume":"31","author":"T Fawcett","year":"2004","unstructured":"Fawcett T (2004) ROC graphs: notes and practical considerations for researchers. Mach Learn 31: 1\u201338","journal-title":"Mach Learn"},{"key":"393_CR14","unstructured":"Frank E, Witten IH (1998) Generating accurate rule sets without global optimization. In: Proceedings of the international conference on machine learning. Citeseer, pp 144\u2013151"},{"key":"393_CR15","unstructured":"Holland J, Booker L, Colombetti M, Dorigo M, Goldberg D, Forrest S, Riolo R, Smith R, Lanzi P, Stolzmann W et\u00a0al (2000) What is a learning classifier system? In: Internatinoal workshop on learning classifier systems, volume 1813 of Lecture Notes in Artificial Intelligence. Springer, Berlin, pp 3\u201332"},{"issue":"2","key":"393_CR16","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1007\/s10115-009-0280-5","volume":"26","author":"K Hovsepian","year":"2010","unstructured":"Hovsepian K, Anselmo P, Mazumdar S (2010) Supervised inductive learning with lotka\u00fb volterra derived models. Knowl Inf Syst 26(2): 195\u2013223","journal-title":"Knowl Inf Syst"},{"issue":"1","key":"393_CR17","first-page":"1","volume":"1","author":"DH Johnson","year":"2001","unstructured":"Johnson DH, Sinanovic S (2001) Symmetrizing the kullback-leibler distance. IEEE Trans Inf Theory 1(1): 1\u201310","journal-title":"IEEE Trans Inf Theory"},{"key":"393_CR18","unstructured":"Kolter JZ, Maloof MA (2004) Learning to detect malicious executables in the wild. In: Proceedings of the ACM SIGKDD international conference on knowledge discovery and data mining. ACM, New York, pp 470\u2013478"},{"issue":"1","key":"393_CR19","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1007\/s10796-007-9054-3","volume":"10","author":"MM Masud","year":"2008","unstructured":"Masud MM, Khan L, Thuraisingham BM (2008) A scalable multi-level feature extraction technique to detect malicious executables. Inf Syst Front 10(1): 33\u201345","journal-title":"Inf Syst Front"},{"key":"393_CR20","doi-asserted-by":"crossref","unstructured":"Otero F, Freitas A, Johnson C (2008) cAnt-Miner: an ant colony classification algorithm to cope with continuous attributes. In: Ant colony optimization and swarm intelligence, volume 5217 of Lecture Notes in Computer Science. Springer, Berlin, pp 48\u201359","DOI":"10.1007\/978-3-540-87527-7_5"},{"key":"393_CR21","doi-asserted-by":"crossref","unstructured":"Perdisci R, Lanzi A, Lee W (2008) McBoost: boosting scalability in malware collection and analysis using statistical classification of executables. In: Proceedings of the Computer Security Applications Conference. Citeseer, pp 301\u2013310","DOI":"10.1109\/ACSAC.2008.22"},{"key":"393_CR22","volume-title":"C4. 5: programs for machine learning","author":"JR Quinlan","year":"1993","unstructured":"Quinlan JR (1993) C4. 5: programs for machine learning. Morgan Kaufmann, Los Altos"},{"key":"393_CR23","doi-asserted-by":"crossref","unstructured":"Quinlan JR (1995) MDL and categorical theories (continued). In: Proceedings of the international conference on machine learning. Citeseer, pp 464\u2013470","DOI":"10.1016\/B978-1-55860-377-6.50064-5"},{"key":"393_CR24","unstructured":"Rodriguez-Gonzalez AY, Martinez-Trinidad JF, Carrasco-Ochoa JA, Ruiz-Shulcloper J (2010) Rp-miner: a relaxed prune algorithm for frequent similar pattern mining. Knowl Inf Syst, pp. 1\u201321"},{"key":"393_CR25","doi-asserted-by":"crossref","unstructured":"Schultz MG, Eskin E, Zadok E, Stolfo SJ (2001) Data mining methods for detection of new malicious executables. In: Proceedings of the IEEE symposium on security and privacy. Citeseer, pp 38\u201349","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"393_CR26","doi-asserted-by":"crossref","unstructured":"Shafiq MZ, Momina Tabish S, Farooq M (2009) PE-probe: leveraging packer detection and structural information to detect malicious portable executables. Proc Int Virus Bull Conf","DOI":"10.1007\/978-3-642-04342-0_7"},{"key":"393_CR27","doi-asserted-by":"crossref","unstructured":"Shafiq MZ, Momina Tabish S, Mirza F, Farooq M (2009) A framework for efficient mining of structural information to detect zero-daymalicious portable executables. Technical report, TRnexGINRC- 2009-21, nexGIN RC","DOI":"10.1007\/978-3-642-04342-0_7"},{"key":"393_CR28","doi-asserted-by":"crossref","unstructured":"Shafiq MZ, Momina Tabish S, Mirza F, Farooq M (2009) PE-Miner: mining structural information to detect malicious executables in real time. In: Proceedings of the recent advances in intrusion detection, volume 5758 of Lecture Notes in Computer Science. Springer, Berlin, pp 121\u2013141","DOI":"10.1007\/978-3-642-04342-0_7"},{"key":"393_CR29","unstructured":"Standard TI (1993) Executable and linking format (ELF) specification Version 1.1. TIS Committee"},{"issue":"13","key":"393_CR30","doi-asserted-by":"crossref","first-page":"2025","DOI":"10.1002\/sim.2103","volume":"24","author":"SD Walter","year":"2005","unstructured":"Walter SD (2005) The partial area under the summary ROC curve. Stat Med 24(13): 2025\u20132040","journal-title":"Stat Med"},{"issue":"2","key":"393_CR31","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1162\/evco.1995.3.2.149","volume":"3","author":"SW Wilson","year":"1995","unstructured":"Wilson SW (1995) Classifier fitness based on accuracy. Evol Comput 3(2): 149\u2013175","journal-title":"Evol Comput"},{"key":"393_CR32","volume-title":"Data mining: practical machine learning tools and techniques","author":"IH Witten","year":"2005","unstructured":"Witten IH, Frank E (2005) Data mining: practical machine learning tools and techniques. Morgan Kaufmann, New York"},{"issue":"3","key":"393_CR33","first-page":"419","volume":"26","author":"Z Richong","year":"2010","unstructured":"Richong Z, Tran TT (2010) An information gain-based approach for recommending useful product reviews. Knowl Inf Syst 26(3): 419\u2013434","journal-title":"Knowl Inf Syst"}],"container-title":["Knowledge and Information Systems"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10115-011-0393-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10115-011-0393-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10115-011-0393-5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,10]],"date-time":"2019-06-10T09:09:28Z","timestamp":1560157768000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10115-011-0393-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,4,26]]},"references-count":33,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,3]]}},"alternative-id":["393"],"URL":"https:\/\/doi.org\/10.1007\/s10115-011-0393-5","relation":{},"ISSN":["0219-1377","0219-3116"],"issn-type":[{"value":"0219-1377","type":"print"},{"value":"0219-3116","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,4,26]]}}}