{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T09:51:27Z","timestamp":1785577887284,"version":"3.56.0"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2014,4,29]],"date-time":"2014-04-29T00:00:00Z","timestamp":1398729600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2015,2]]},"DOI":"10.1007\/s10207-014-0242-0","type":"journal-article","created":{"date-parts":[[2014,4,28]],"date-time":"2014-04-28T09:59:57Z","timestamp":1398679197000},"page":"1-14","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":140,"title":["Malware analysis using visualized images and entropy graphs"],"prefix":"10.1007","volume":"14","author":[{"given":"Kyoung Soo","family":"Han","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jae Hyun","family":"Lim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boojoong","family":"Kang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eul Gyu","family":"Im","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2014,4,29]]},"reference":[{"issue":"4","key":"242_CR1","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1145\/1013886.1007518","volume":"29","author":"M Christodorescu","year":"2004","unstructured":"Christodorescu, M., Jha, S.: Testing malware detectors. ACM SIGSOFT Softw. Eng. Notes 29(4), 34\u201344 (2004)","journal-title":"ACM SIGSOFT Softw. Eng. Notes"},{"key":"242_CR2","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual 2007, pp. 421\u2013430. IEEE","DOI":"10.1109\/ACSAC.2007.21"},{"issue":"2","key":"242_CR3","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using cwsandbox. IEEE Secur. Priv. 5(2), 32\u201339 (2007)","journal-title":"IEEE Secur. Priv."},{"key":"242_CR4","doi-asserted-by":"crossref","unstructured":"Jang, J., Brumley, D., Venkataraman, S.: Bitshred: feature hashing malware for scalable triage and semantic analysis. In: Proceedings of the 18th ACM Conference on Computer and Communications Security 2011, pp. 309\u2013320. ACM","DOI":"10.1145\/2046707.2046742"},{"key":"242_CR5","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security 2008, pp. 51\u201362. ACM","DOI":"10.1145\/1455770.1455779"},{"key":"242_CR6","unstructured":"Christodorescu, M., Jha, S., Seshia, S.A., Song, D., Bryant, R.E.: Semantics-aware malware detection. In: Security and Privacy, 2005 IEEE Symposium on 2005, pp. 32\u201346. IEEE"},{"key":"242_CR7","doi-asserted-by":"crossref","unstructured":"Cesare, S., Xiang, Y.: A fast flowgraph based classification system for packed and polymorphic malware on the endhost. In: Advanced Information Networking and Applications (AINA), 2010 24th IEEE International Conference on 2010, pp. 721\u2013728. IEEE","DOI":"10.1109\/AINA.2010.121"},{"key":"242_CR8","unstructured":"Chowdhury, G.: Introduction to Modern Information Retrieval. Facet publishing (2010)"},{"key":"242_CR9","doi-asserted-by":"crossref","unstructured":"Shang, S., Zheng, N., Xu, J., Xu, M., Zhang, H.: Detecting malware variants via function-call graph similarity. In: Malicious and Unwanted Software (MALWARE), 2010 5th International Conference on 2010, pp. 113\u2013120. IEEE","DOI":"10.1109\/MALWARE.2010.5665787"},{"key":"242_CR10","doi-asserted-by":"crossref","unstructured":"Abou-Assaleh, T., Cercone, N., Keselj, V., Sweidan, R.: Detection of new malicious code using n-grams signatures. In: Proceedings of Second Annual Conference on Privacy, Security and Trust 2004, pp. 193\u2013196","DOI":"10.1109\/CMPSAC.2004.1342667"},{"key":"242_CR11","doi-asserted-by":"crossref","unstructured":"Santos, I., Brezo, F., Nieves, J., Penya, Y.K., Sanz, B., Laorden, C., Bringas, P.G.: Idea: Opcode-sequence-based malware detection. In: Engineering Secure Software and Systems. pp. 35\u201343. Springer, Berlin (2010)","DOI":"10.1007\/978-3-642-11747-3_3"},{"issue":"2","key":"242_CR12","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1504\/IJESDF.2007.016865","volume":"1","author":"D Bilar","year":"2007","unstructured":"Bilar, D.: Opcodes as predictor for malware. Int. J. Electron. Secur. Digit. Forensics 1(2), 156\u2013168 (2007)","journal-title":"Int. J. Electron. Secur. Digit. Forensics"},{"issue":"7","key":"242_CR13","first-page":"2973","volume":"15","author":"KS Han","year":"2012","unstructured":"Han, K.S., Kim, S.-R., Im, E.G.: Instruction frequency-based malware classification method. INFORMATION Int. Interdiscip. J. 15(7), 2973\u20132984 (2012)","journal-title":"INFORMATION Int. Interdiscip. J."},{"key":"242_CR14","unstructured":"Egele, M., Kruegel, C., Kirda, E., Yin, H., Song, D.: Dynamic spyware analysis. In: Usenix Annual Technical Conference 2007"},{"key":"242_CR15","doi-asserted-by":"crossref","unstructured":"Nair, V.P., Jain, H., Golecha, Y.K., Gaur, M.S., Laxmi, V.: MEDUSA: MEtamorphic malware dynamic analysis using signature from API. In: Proceedings of the 3rd International Conference on Security of Information and Networks 2010, pp. 263\u2013269. ACM","DOI":"10.1145\/1854099.1854152"},{"key":"242_CR16","doi-asserted-by":"crossref","unstructured":"Miao, Q.-G., Wang, Y., Cao, Y., Zhang, X.-G., Liu, Z.-L.: APICapture-a tool for monitoring the behavior of malware. In: Advanced Computer Theory and Engineering (ICACTE), 2010 3rd International Conference on 2010, pp. V4\u2013390-V394-394. IEEE","DOI":"10.1109\/ICACTE.2010.5579452"},{"key":"242_CR17","unstructured":"Fredrikson, M., Jha, S., Christodorescu, M., Sailer, R., Yan, X.: Synthesizing near-optimal malware specifications from suspicious behaviors. In: Security and Privacy (SP), 2010 IEEE Symposium on 2010, pp. 45\u201360. IEEE"},{"key":"242_CR18","doi-asserted-by":"crossref","unstructured":"Trinius, P., Holz, T., Gobel, J., Freiling, F.C.: Visual analysis of malware behavior using treemaps and thread graphs. In: Visualization for Cyber Security, 2009. VizSec 2009. 6th International Workshop on 2009, pp. 33\u201338. IEEE","DOI":"10.1109\/VIZSEC.2009.5375540"},{"key":"242_CR19","doi-asserted-by":"crossref","unstructured":"Saxe, J., Mentis, D., Greamo, C.: Visualization of shared system call sequence relationships in large malware corpora. In: Proceedings of the Ninth International Symposium on Visualization for Cyber, Security 2012, pp. 33\u201340. ACM","DOI":"10.1145\/2379690.2379695"},{"key":"242_CR20","doi-asserted-by":"crossref","unstructured":"Conti, G., Dean, E., Sinda, M., Sangster, B.: Visual Reverse engineering of binary and data files. In: Visualization for Computer Security, pp. 1\u201317. Springer, Berlin (2008)","DOI":"10.1007\/978-3-540-85933-8_1"},{"key":"242_CR21","doi-asserted-by":"crossref","unstructured":"Anderson, B., Storlie, C., Lane, T.: Improving malware classification: bridging the static\/dynamic gap. In: Proceedings of the 5th ACM Workshop on Security and Artificial Intelligence 2012, pp. 3\u201314. ACM","DOI":"10.1145\/2381896.2381900"},{"key":"242_CR22","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., Manjunath, B.: Malware images: visualization and automatic classification. In: Proceedings of the 8th International Symposium on Visualization for Cyber, Security 2011, p. 4. ACM","DOI":"10.1145\/2016904.2016908"},{"key":"242_CR23","doi-asserted-by":"crossref","unstructured":"Torralba, A., Murphy, K.P., Freeman, W.T., Rubin, M.A.: Context-based vision system for place and object recognition. In: Computer Vision, 2003. Proceedings. Ninth IEEE International Conference on 2003, pp. 273\u2013280. IEEE","DOI":"10.1109\/ICCV.2003.1238354"},{"issue":"3","key":"242_CR24","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1023\/A:1011139631724","volume":"42","author":"A Oliva","year":"2001","unstructured":"Oliva, A., Torralba, A.: Modeling the shape of the scene: a holistic representation of the spatial envelope. Int. J. Comput. Vis. 42(3), 145\u2013175 (2001)","journal-title":"Int. J. Comput. Vis."},{"issue":"2","key":"242_CR25","doi-asserted-by":"crossref","first-page":"300","DOI":"10.1109\/TPAMI.2007.40","volume":"29","author":"C Siagian","year":"2007","unstructured":"Siagian, C., Itti, L.: Rapid biologically-inspired scene classification using features shared with visual attention. IEEE Trans. Pattern Anal. Mach. Intell. 29(2), 300\u2013312 (2007)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"242_CR26","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Yegneswaran, V., Porras, P., Zhang, J.: A comparative assessment of malware classification using binary texture analysis and dynamic analysis. In: Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence 2011, pp. 21\u201330. ACM","DOI":"10.1145\/2046684.2046689"},{"key":"242_CR27","unstructured":"Baysa, D., Low, R.M., Stamp, M.: Structural entropy and metamorphic malware. J. Comput. Virol. Hack. Tech. 9, 179\u2013192 (2013)"},{"key":"242_CR28","unstructured":"Conti, G., Bratus, S., Shubina, A., Lichtenberg, A., Ragsdale, R., Perez-Alemany, R., Sangster, B., Supan, M.: A Visual Study of Primitive Binary Fragment Types. White Paper, Black Hat USA (2010)"},{"issue":"3","key":"242_CR29","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1016\/0734-189X(85)90125-2","volume":"29","author":"J Kapur","year":"1985","unstructured":"Kapur, J., Sahoo, P.K., Wong, A.: A new method for gray-level picture thresholding using the entropy of the histogram. Comput. Vis. Gr. Image Process. 29(3), 273\u2013285 (1985)","journal-title":"Comput. Vis. Gr. Image Process."},{"issue":"13","key":"242_CR30","doi-asserted-by":"crossref","first-page":"1768","DOI":"10.1016\/j.patrec.2008.05.002","volume":"29","author":"V Strelkov","year":"2008","unstructured":"Strelkov, V.: A new similarity measure for histogram comparison and its application in time series analysis. Pattern Recognit. Lett. 29(13), 1768\u20131774 (2008)","journal-title":"Pattern Recognit. Lett."},{"key":"242_CR31","unstructured":"VxHeaven. http:\/\/vx.netlux.org\/index.html"},{"key":"242_CR32","unstructured":"Kaspersky Lab. http:\/\/www.kaspersky.com"},{"key":"242_CR33","unstructured":"Gnuplot. http:\/\/www.gnuplot.info"},{"key":"242_CR34","doi-asserted-by":"crossref","unstructured":"Karampatziakis, N., Stokes, J.W., Thomas, A., Marinescu, M.: Using file relationships in malware classification. In: Detection of Intrusions and Malware, and Vulnerability Assessment. pp. 1\u201320. Springer, Berlin (2013)","DOI":"10.1007\/978-3-642-37300-8_1"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0242-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-014-0242-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0242-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T15:40:41Z","timestamp":1746200441000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-014-0242-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,4,29]]},"references-count":34,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,2]]}},"alternative-id":["242"],"URL":"https:\/\/doi.org\/10.1007\/s10207-014-0242-0","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,4,29]]}}}