{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T09:44:12Z","timestamp":1778319852321,"version":"3.51.4"},"reference-count":55,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2020,1,8]],"date-time":"2020-01-08T00:00:00Z","timestamp":1578441600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,8]],"date-time":"2020-01-08T00:00:00Z","timestamp":1578441600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"name":"the National Key R&D Program of China","award":["2016YFB0800805"],"award-info":[{"award-number":["2016YFB0800805"]}]},{"name":"the Major Projects of Science and Technology Service Industry in Tianjin","award":["16ZXFWGX00140"],"award-info":[{"award-number":["16ZXFWGX00140"]}]},{"name":"the Open Project Foundation of Information Security Evaluation Center of Civil Aviation, Civil Aviation University of China","award":["CAAC-ISECCA-201501"],"award-info":[{"award-number":["CAAC-ISECCA-201501"]}]},{"name":"the Natural Science Foundation of Tianjin","award":["18JCQNJC69900"],"award-info":[{"award-number":["18JCQNJC69900"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mobile Netw Appl"],"published-print":{"date-parts":[[2021,8]]},"DOI":"10.1007\/s11036-019-01503-4","type":"journal-article","created":{"date-parts":[[2020,1,8]],"date-time":"2020-01-08T08:02:41Z","timestamp":1578470561000},"page":"1668-1685","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Malware Detection Based on Multi-level and Dynamic Multi-feature Using Ensemble Learning at Hypervisor"],"prefix":"10.1007","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5163-5458","authenticated-orcid":false,"given":"Jian","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cheng","family":"Gao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liangyi","family":"Gong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhaojun","family":"Gu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dapeng","family":"Man","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wu","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenzhen","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,1,8]]},"reference":[{"key":"1503_CR1","doi-asserted-by":"publisher","unstructured":"Han Y, Hao Z, Cui L, Wang C, Sang Y (2016) A hybrid monitoring mechanism in virtualized environments. In: 2016 IEEE Trustcom\/BigDataSE\/ISPA, pp 1038\u20131045, DOI https:\/\/doi.org\/10.1109\/TrustCom.2016.0173, (to appear in print)","DOI":"10.1109\/TrustCom.2016.0173"},{"key":"1503_CR2","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.ins.2016.07.019","volume":"379","author":"Y Cheng","year":"2017","unstructured":"Cheng Y, Fu X, Du X, Luo B, Guizani M (2017) A lightweight live memory forensic approach based on hardware virtualization. Inform Sci 379:23\u201341. https:\/\/doi.org\/10.1016\/j.ins.2016.07.019","journal-title":"Inform Sci"},{"key":"1503_CR3","doi-asserted-by":"publisher","unstructured":"Mishra P, Pilli ES, Varadharajant V, Tupakula U (2016) Nvcloudids: a security architecture to detect intrusions at network and virtualization layer in cloud environment. In: 2016 international conference on advances in computing, communications and informatics (ICACCI), pp 56\u201362, DOI https:\/\/doi.org\/10.1109\/ICACCI.2016.7732025, (to appear in print)","DOI":"10.1109\/ICACCI.2016.7732025"},{"key":"1503_CR4","doi-asserted-by":"publisher","unstructured":"Riley R, Jiang X, Xu D (2009) Multi-aspect profiling of kernel rootkit behavior. In: Proceedings of the 4th ACM European conference on computer systems, pp 47\u201360, DOI https:\/\/doi.org\/10.1145\/1519065.1519072, (to appear in print)","DOI":"10.1145\/1519065.1519072"},{"key":"1503_CR5","doi-asserted-by":"publisher","unstructured":"Payne BD, Carbone M, Sharif M, Lee W (2008) Lares: an architecture for secure active monitoring using virtualization. In: 2008 IEEE symposium on security and privacy (sp 2008), pp 233\u2013247, DOI https:\/\/doi.org\/10.1109\/SP.2008.24, (to appear in print)","DOI":"10.1109\/SP.2008.24"},{"key":"1503_CR6","doi-asserted-by":"publisher","unstructured":"Suneja S, Isci C, de Lara E, Bala V (2015) Exploring vm introspection: Techniques and trade-offs. In: Acm Sigplan Notices, vol 50, pp 133\u2013146, DOI https:\/\/doi.org\/10.1145\/2731186.2731196","DOI":"10.1145\/2731186.2731196"},{"key":"1503_CR7","doi-asserted-by":"publisher","unstructured":"Xiao J, Lu L, Wang H, Zhu X (2016) Hyperlink: Virtual machine introspection and memory forensic analysis without kernel source code. In: 2016 IEEE international conference on autonomic computing (ICAC), pp 127\u2013136, DOI https:\/\/doi.org\/10.1109\/ICAC.2016.46, (to appear in print)","DOI":"10.1109\/ICAC.2016.46"},{"key":"1503_CR8","unstructured":"Fu Y, Zeng J, Lin Z (2014) Hypershell: a practical hypervisor layer guest os shell for automated in-vm management. In: 2014 USENIX annual technical conference (USENIX ATC 14), pp 85\u201396"},{"issue":"1","key":"1503_CR9","doi-asserted-by":"publisher","first-page":"647","DOI":"10.1186\/s40064-016-2257-7","volume":"5","author":"J Shi","year":"2016","unstructured":"Shi J, Yang Y, Tang C (2016) Hardware assisted hypervisor introspection. SpringerPlus 5(1):647. https:\/\/doi.org\/10.1186\/s40064-016-2257-7","journal-title":"SpringerPlus"},{"key":"1503_CR10","doi-asserted-by":"publisher","first-page":"S114","DOI":"10.1016\/j.diin.2016.01.014","volume":"16","author":"B Taubmann","year":"2016","unstructured":"Taubmann B, Fr\u00e4drich C, Dusold D, Reiser HP (2016) Tlskex: Harnessing virtual machine introspection for decrypting tls communication. Digit Investig 16:S114\u2013S123. https:\/\/doi.org\/10.1016\/j.diin.2016.01.014","journal-title":"Digit Investig"},{"key":"1503_CR11","doi-asserted-by":"publisher","unstructured":"Sebasti\u00e1n M, Rivera R, Kotzias P, Caballero J (2016) Avclass: a tool for massive malware labeling. In: International symposium on research in attacks, intrusions, and defenses, pp 230\u2013253, DOI https:\/\/doi.org\/10.1007\/978-3-319-45719-2_11, (to appear in print)","DOI":"10.1007\/978-3-319-45719-2_11"},{"key":"1503_CR12","doi-asserted-by":"publisher","unstructured":"Tang A, Sethumadhavan S, Stolfo S (2014) Unsupervised anomaly-based malware detection using hardware features. In: International workshop on recent advances in intrusion detection, pp 109\u2013129, DOI https:\/\/doi.org\/10.1007\/978-3-319-11379-1_6, (to appear in print)","DOI":"10.1007\/978-3-319-11379-1_6"},{"key":"1503_CR13","doi-asserted-by":"publisher","unstructured":"Kong D, Yan G (2013) Discriminant malware distance learning on structural information for automated malware classification. In: Proceedings of the 19th ACM SIGKDD international conference on knowledge discovery and data mining, pp 1357\u20131365, DOI https:\/\/doi.org\/10.1145\/2465529.2465531, (to appear in print)","DOI":"10.1145\/2465529.2465531"},{"key":"1503_CR14","doi-asserted-by":"publisher","first-page":"431","DOI":"10.1016\/j.future.2017.06.002","volume":"79","author":"A Kumara","year":"2018","unstructured":"Kumara A, Jaidhar C (2018) Automated multi-level malware detection system based on reconstructed semantic view of executables using machine learning techniques at vmm. Futur Gener Comput Syst 79:431\u2013446. https:\/\/doi.org\/10.1016\/j.future.2017.06.002","journal-title":"Futur Gener Comput Syst"},{"key":"1503_CR15","doi-asserted-by":"publisher","unstructured":"Jang J, Brumley D, Venkataraman S (2011) Bitshred: feature hashing malware for scalable triage and semantic analysis. In: Proceedings of the 18th ACM conference on Computer and communications security, pp 309\u2013320, DOI https:\/\/doi.org\/10.1145\/2046707.2046742, (to appear in print)","DOI":"10.1145\/2046707.2046742"},{"key":"1503_CR16","doi-asserted-by":"publisher","unstructured":"Ye Y, Li T, Chen Y, Jiang Q (2010) Automatic malware categorization using cluster ensemble. In: Proceedings of the 16th ACM SIGKDD international conference on knowledge discovery and data mining, pp 95\u2013104, DOI https:\/\/doi.org\/10.1145\/1835804.1835820, (to appear in print)","DOI":"10.1145\/1835804.1835820"},{"key":"1503_CR17","unstructured":"Garfinkel T, Rosenblum M, et al. (2003) A virtual machine introspection based architecture for intrusion detection. In: Ndss, vol 3, pp 191\u2013206"},{"issue":"1","key":"1503_CR18","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1145\/2775111","volume":"48","author":"E Bauman","year":"2015","unstructured":"Bauman E, Ayoade G, Lin Z (2015) A survey on hypervisor-based monitoring: approaches, applications, and evolutions. ACM Computing Surveys (CSUR) 48(1):10. https:\/\/doi.org\/10.1145\/2775111","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"1503_CR19","doi-asserted-by":"publisher","unstructured":"Hebbal Y, Laniepce S, Menaud J-M (2015) Virtual machine introspection: Techniques and applications. In: 2015 10th international conference on availability, reliability and security, pp 676\u2013685, DOI https:\/\/doi.org\/10.1109\/ARES.2015.43, (to appear in print)","DOI":"10.1109\/ARES.2015.43"},{"key":"1503_CR20","unstructured":"Petroni NL Jr, Fraser T, Molina J, Arbaugh WA (2004) Copilot-a coprocessor-based kernel runtime integrity monitor. In: USENIX security symposium, pp 179\u2013194"},{"key":"1503_CR21","doi-asserted-by":"publisher","unstructured":"Dolan-Gavitt B, Leek T, Zhivich M, Giffin J, Lee W (2011) Virtuoso: Narrowing the semantic gap in virtual machine introspection. In: 2011 IEEE symposium on security and privacy, pp 297\u2013312, DOI https:\/\/doi.org\/10.1109\/SP.2011.11, (to appear in print)","DOI":"10.1109\/SP.2011.11"},{"key":"1503_CR22","doi-asserted-by":"publisher","unstructured":"Fu Y, Lin Z (2012) Space traveling across vm: Automatically bridging the semantic gap in virtual machine introspection via online kernel data redirection. In: 2012 IEEE symposium on security and privacy, pp 586\u2013600, DOI https:\/\/doi.org\/10.1109\/SP.2012.40, (to appear in print)","DOI":"10.1109\/SP.2012.40"},{"key":"1503_CR23","doi-asserted-by":"crossref","unstructured":"Saberi A, Fu Y, Lin Z (2014) Hybrid-bridge: Efficiently bridging the semantic gap in virtual machine introspection via decoupled execution and training memoization. In: Proceedings of the 21st annual network and distributed system security symposium","DOI":"10.14722\/ndss.2014.23226"},{"key":"1503_CR24","doi-asserted-by":"publisher","unstructured":"Demme J, Maycock M, Schmitz J, Tang A, Waksman A, Sethumadhavan S, Stolfo S (2013) On the feasibility of online malware detection with performance counters. In: ACM SIGARCH computer architecture news, vol 41, pp 559\u2013570, DOI https:\/\/doi.org\/10.1145\/2508148.2485970","DOI":"10.1145\/2508148.2485970"},{"key":"1503_CR25","doi-asserted-by":"publisher","unstructured":"Avritzer A, Tanikella R, James K, Cole RG, Weyuker E (2010) Monitoring for security intrusion using performance signatures. In: Proceedings of the first joint WOSP\/SIPEW international conference on performance engineering, pp 93\u2013104, DOI https:\/\/doi.org\/10.1145\/1712605.1712623, (to appear in print)","DOI":"10.1145\/1712605.1712623"},{"key":"1503_CR26","doi-asserted-by":"publisher","first-page":"S98","DOI":"10.1016\/j.diin.2018.04.015","volume":"26","author":"T Tuzel","year":"2018","unstructured":"Tuzel T, Bridgman M, Zepf J, Lengyel TK, Temkin K (2018) Who watches the watcher? detecting hypervisor introspection from unprivileged guests. Digit Investig 26:S98\u2013S106. https:\/\/doi.org\/10.1016\/j.diin.2018.04.015","journal-title":"Digit Investig"},{"key":"1503_CR27","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1016\/j.cose.2018.08.010","volume":"79","author":"S Hong","year":"2018","unstructured":"Hong S, Nicolae A, Srivastava A, Dumitra\u015f T (2018) Peek-a-boo: Inferring program behaviors in a virtualized infrastructure without introspection. Computers & Security 79:190\u2013207. https:\/\/doi.org\/10.1016\/j.cose.2018.08.010","journal-title":"Computers & Security"},{"key":"1503_CR28","doi-asserted-by":"publisher","unstructured":"Xuan C, Copeland J, Beyah R (2009) Toward revealing kernel malware behavior in virtual execution environments. In: International workshop on recent advances in intrusion detection, pp 304\u2013325, DOI https:\/\/doi.org\/10.1007\/978-3-642-04342-0_16, (to appear in print)","DOI":"10.1007\/978-3-642-04342-0_16"},{"key":"1503_CR29","doi-asserted-by":"publisher","unstructured":"Dinaburg A, Royal P, Sharif M, Lee W (2008) Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM conference on computer and communications security, pp 51\u201362, DOI https:\/\/doi.org\/10.1145\/1455770.1455779, (to appear in print)","DOI":"10.1145\/1455770.1455779"},{"key":"1503_CR30","doi-asserted-by":"publisher","unstructured":"Dai S-Y, Fyodor Y, Wu J-S, Lin C-H, Huang Y, Kuo S-Y (2009) Holography: a hardware virtualization tool for malware analysis. In: 2009 15th IEEE Pacific rim international symposium on dependable computing, pp 263\u2013268, DOI https:\/\/doi.org\/10.1109\/PRDC.2009.48, (to appear in print)","DOI":"10.1109\/PRDC.2009.48"},{"key":"1503_CR31","doi-asserted-by":"publisher","unstructured":"Henderson A, Prakash A, Yan LK, Hu X, Wang X, Zhou R, Yin H (2014) Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform. In: Proceedings of the 2014 international symposium on software testing and analysis, pp 248\u2013258, DOI https:\/\/doi.org\/10.1145\/2610384.2610407, (to appear in print)","DOI":"10.1145\/2610384.2610407"},{"key":"1503_CR32","doi-asserted-by":"publisher","unstructured":"Schultz MG, Eskin E, Zadok F, Stolfo S (2001) Data mining methods for detection of new malicious executables. In: Proceedings 2001 IEEE symposium on security and privacy. S&P 2001, pp 38\u201349, DOI https:\/\/doi.org\/10.1109\/SECPRI.2001.924286, (to appear in print)","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"1503_CR33","doi-asserted-by":"publisher","unstructured":"Zhang Y, Huang Q, Ma X, Yang Z, Jiang J (2016) Using multi-features and ensemble learning method for imbalanced malware classification. In: 2016 IEEE Trustcom\/BigDataSE\/ISPA, pp 965\u2013973, DOI https:\/\/doi.org\/10.1109\/TrustCom.2016.0163, (to appear in print)","DOI":"10.1109\/TrustCom.2016.0163"},{"issue":"17","key":"1503_CR34","doi-asserted-by":"publisher","first-page":"4227","DOI":"10.1002\/sec.1600","volume":"9","author":"J Bai","year":"2016","unstructured":"Bai J, Wang J (2016) Improving malware detection using multi-view ensemble learning. Sec Commun Netw 9(17):4227\u20134241. https:\/\/doi.org\/10.1002\/sec.1600","journal-title":"Sec Commun Netw"},{"key":"1503_CR35","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1016\/j.eswa.2018.02.039","volume":"102","author":"A Cohen","year":"2018","unstructured":"Cohen A, Nissim N (2018) Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory. Expert Syst Appl 102:158\u2013178. https:\/\/doi.org\/10.1016\/j.eswa.2018.02.039","journal-title":"Expert Syst Appl"},{"key":"1503_CR36","doi-asserted-by":"publisher","unstructured":"Heidari P, Desnoyers M, Dagenais M (2008) Performance analysis of virtual machines through tracing. In: 2008 Canadian conference on electrical and computer engineering, pp 000261\u2013000266, DOI https:\/\/doi.org\/10.1109\/CCECE.2008.4564536, (to appear in print)","DOI":"10.1109\/CCECE.2008.4564536"},{"key":"1503_CR37","unstructured":"Weaver VM (2013) Linux perf_event features and overhead. In: The 2nd international workshop on performance analysis of workload optimized systems, FastPath, vol. 13"},{"key":"1503_CR38","doi-asserted-by":"publisher","unstructured":"Lengyel TK, Maresca S, Payne BD, Webster GD, Vogl S, Kiayias A (2014) Scalability, fidelity and stealth in the drakvuf dynamic malware analysis system. In: Proceedings of the 30th annual computer security applications conference, pp 386\u2013395, DOI https:\/\/doi.org\/10.1145\/2664243.2664252, (to appear in print)","DOI":"10.1145\/2664243.2664252"},{"key":"1503_CR39","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1016\/j.cose.2017.11.010","volume":"73","author":"C-H Lin","year":"2018","unstructured":"Lin C-H, Pao H-K, Liao J-W (2018) Efficient dynamic malware analysis using virtual time control mechanics. Computers & Security 73:359\u2013373. https:\/\/doi.org\/10.1016\/j.cose.2017.11.010","journal-title":"Computers & Security"},{"key":"1503_CR40","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/j.cose.2018.12.005","volume":"83","author":"RM Yadav","year":"2019","unstructured":"Yadav RM (2019) Effective analysis of malware detection in cloud computing. Computers & Security 83:14\u201321. https:\/\/doi.org\/10.1016\/j.cose.2018.12.005","journal-title":"Computers & Security"},{"key":"1503_CR41","doi-asserted-by":"publisher","unstructured":"Nataraj L, Karthikeyan S, Jacob G, Manjunath B (2011) Malware images: visualization and automatic classification. In: Proceedings of the 8th international symposium on visualization for cyber security, p 4, DOI https:\/\/doi.org\/10.1145\/2016904.2016908, (to appear in print)","DOI":"10.1145\/2016904.2016908"},{"key":"1503_CR42","doi-asserted-by":"publisher","first-page":"871","DOI":"10.1016\/j.cose.2018.04.005","volume":"77","author":"S Ni","year":"2018","unstructured":"Ni S, Qian Q, Zhang R (2018) Malware identification using visualization images and deep learning. Computers & Security 77:871\u2013885. https:\/\/doi.org\/10.1016\/j.cose.2018.04.005","journal-title":"Computers & Security"},{"key":"1503_CR43","doi-asserted-by":"publisher","unstructured":"Abou-Assaleh T, Cercone N, Keselj V, Sweidan R (2004) N-gram-based detection of new malicious code. In: Proceedings of the 28th annual international computer software and applications conference, 2004. COMPSAC 2004, vol 2, pp 41\u201342, DOI https:\/\/doi.org\/10.1109\/CMPSAC.2004.1342667","DOI":"10.1109\/CMPSAC.2004.1342667"},{"issue":"1","key":"1503_CR44","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/2190-8532-1-1","volume":"1","author":"A Shabtai","year":"2012","unstructured":"Shabtai A, Moskovitch R, Feher C, Dolev S, Elovici Y (2012) Detecting unknown malicious code by applying classification techniques on opcode patterns. Security Informatics 1(1):1. https:\/\/doi.org\/10.1186\/2190-8532-1-1","journal-title":"Security Informatics"},{"key":"1503_CR45","doi-asserted-by":"publisher","unstructured":"Wang L, Meng J, Huang R, Zhu H, Peng K Incremental feature weighting for fuzzy feature selection, Fuzzy Sets and Systems. https:\/\/doi.org\/10.1016\/j.fss.2018.10.021","DOI":"10.1016\/j.fss.2018.10.021"},{"key":"1503_CR46","doi-asserted-by":"publisher","first-page":"996","DOI":"10.1016\/j.knosys.2018.10.023","volume":"163","author":"Q Tuo","year":"2019","unstructured":"Tuo Q, Zhao H, Hu Q (2019) Hierarchical feature selection with subtree based graph regularization. Knowl-Based Syst 163:996\u20131008. https:\/\/doi.org\/10.1016\/j.knosys.2018.10.023","journal-title":"Knowl-Based Syst"},{"key":"1503_CR47","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1016\/j.inffus.2018.11.019","volume":"50","author":"R Zhang","year":"2019","unstructured":"Zhang R, Nie F, Li X, Wei X (2019) Feature selection with multi-view data: a survey. Information Fusion 50:158\u2013167. https:\/\/doi.org\/10.1016\/j.inffus.2018.11.019","journal-title":"Information Fusion"},{"key":"1503_CR48","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1016\/j.jisa.2018.11.007","volume":"44","author":"S Mohammadi","year":"2019","unstructured":"Mohammadi S, Mirvaziri H, Ghazizadeh-Ahsaee M, Karimipour H (2019) Cyber intrusion detection by combined feature selection algorithm. J Inf Sec Appl 44:80\u201388. https:\/\/doi.org\/10.1016\/j.jisa.2018.11.007","journal-title":"J Inf Sec Appl"},{"key":"1503_CR49","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1016\/j.future.2018.09.066","volume":"92","author":"P Salza","year":"2019","unstructured":"Salza P, Ferrucci F (2019) Speed up genetic algorithms in the cloud using software containers. Futur Gener Comput Syst 92:276\u2013289","journal-title":"Futur Gener Comput Syst"},{"key":"1503_CR50","doi-asserted-by":"publisher","unstructured":"Kennedy J, Eberhart RC (1997) A discrete binary version of the particle swarm algorithm. In: 1997 IEEE international conference on systems, man, and cybernetics. Computational cybernetics and simulation, vol 5, pp 4104\u20134108, DOI https:\/\/doi.org\/10.1109\/ICSMC.1997.637339","DOI":"10.1109\/ICSMC.1997.637339"},{"key":"1503_CR51","doi-asserted-by":"publisher","first-page":"709","DOI":"10.1016\/j.cam.2018.04.036","volume":"340","author":"G Xu","year":"2018","unstructured":"Xu G, Yu G (2018) Reprint of: on convergence analysis of particle swarm optimization algorithm. J Comput Appl Math 340:709\u2013717. https:\/\/doi.org\/10.1016\/j.cam.2018.04.036","journal-title":"J Comput Appl Math"},{"issue":"1","key":"1503_CR52","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1016\/j.ejor.2018.09.038","volume":"274","author":"R Jovanovic","year":"2019","unstructured":"Jovanovic R, Tuba M, Vo\u00df S (2019) An efficient ant colony optimization algorithm for the blocks relocation problem. Eur J Oper Res 274(1):78\u201390. https:\/\/doi.org\/10.1016\/j.ejor.2018.09.038","journal-title":"Eur J Oper Res"},{"key":"1503_CR53","doi-asserted-by":"publisher","unstructured":"Khasawneh KN, Ozsoy M, Donovick C, Abu-Ghazaleh N, Ponomarev D (2015) Ensemble learning for low-level hardware-supported malware detection. In: International workshop on recent advances in intrusion detection, pp 3\u201325, DOI https:\/\/doi.org\/10.1007\/978-3-319-26362-5_1, (to appear in print)","DOI":"10.1007\/978-3-319-26362-5_1"},{"key":"1503_CR54","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.jnca.2016.10.015","volume":"77","author":"P Mishra","year":"2017","unstructured":"Mishra P, Pilli ES, Varadharajan V, Tupakula U (2017) Intrusion detection techniques in cloud environment: a survey. J Netw Comput Appl 77:18\u201347. https:\/\/doi.org\/10.1016\/j.jnca.2016.10.015","journal-title":"J Netw Comput Appl"},{"key":"1503_CR55","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.ins.2016.09.041","volume":"379","author":"S Huda","year":"2017","unstructured":"Huda S, Miah S, Hassan MM, Islam R, Yearwood J, Alrubaian M, Almogren A (2017) Defending unknown attacks on cyber-physical systems by semi-supervised approach and available unlabeled data. Inform Sci 379:211\u2013228. https:\/\/doi.org\/10.1016\/j.ins.2016.09.041","journal-title":"Inform Sci"}],"container-title":["Mobile Networks and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-019-01503-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11036-019-01503-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-019-01503-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,27]],"date-time":"2021-10-27T03:40:12Z","timestamp":1635306012000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11036-019-01503-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,1,8]]},"references-count":55,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,8]]}},"alternative-id":["1503"],"URL":"https:\/\/doi.org\/10.1007\/s11036-019-01503-4","relation":{},"ISSN":["1383-469X","1572-8153"],"issn-type":[{"value":"1383-469X","type":"print"},{"value":"1572-8153","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,1,8]]},"assertion":[{"value":"8 January 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}