{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,27]],"date-time":"2026-01-27T22:59:11Z","timestamp":1769554751314,"version":"3.49.0"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2015,12,31]],"date-time":"2015-12-31T00:00:00Z","timestamp":1451520000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100003621","name":"Korea government(MSIP)","doi-asserted-by":"publisher","award":["No.B0101-15-1293"],"award-info":[{"award-number":["No.B0101-15-1293"]}],"id":[{"id":"10.13039\/501100003621","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2017,7]]},"DOI":"10.1007\/s11227-015-1604-8","type":"journal-article","created":{"date-parts":[[2015,12,31]],"date-time":"2015-12-31T08:27:49Z","timestamp":1451550469000},"page":"2881-2895","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":131,"title":["DTB-IDS: an intrusion detection system based on decision tree using behavior analysis for preventing APT attacks"],"prefix":"10.1007","volume":"73","author":[{"given":"Daesung","family":"Moon","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hyungjin","family":"Im","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ikkyun","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jong Hyuk","family":"Park","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,12,31]]},"reference":[{"key":"1604_CR1","unstructured":"Nikos V, Gritzalis D, Apostolopoulos T (2013) Trusted Computing vs. advanced persistent threats: can a defender win this game?. In: Ubiquitous Intelligence and Computing, 2013 IEEE 10th international conference on and 10th international conference on autonomic and trusted computing (UIC\/ATC). IEEE, pp 396\u2013403"},{"key":"1604_CR2","unstructured":"Nikos V, Gritzalis D (2013) The big four-what we did wrong in advanced persistent threat detection?. In: Availability, Reliability and Security (ARES), 2013 Eighth International Conference on. IEEE"},{"key":"1604_CR3","doi-asserted-by":"crossref","unstructured":"Seresht NA, Azmi R. MAIS-IDS: a distributed intrusion detection system using multi-agent AIS approach. Eng Appl Artif Intell 35:286\u2013298","DOI":"10.1016\/j.engappai.2014.06.022"},{"issue":"1","key":"1604_CR4","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.jnca.2012.09.004","volume":"36","author":"L Hung-Jen","year":"2013","unstructured":"Hung-Jen L, Lin C-HR, Lin Y-C, Tung K-Y (2013) Intrusion detection system: A comprehensive. J Netw Comput Appl 36(1):16\u201324","journal-title":"J Netw Comput Appl"},{"issue":"32","key":"1604_CR5","first-page":"19","volume":"5","author":"Madhu Sharma Gaur","year":"2015","unstructured":"Gaur Madhu Sharma, Pant Bhaskar (2015) Trusted and secure clustering in mobile pervasive environment. Human-centric Comput Inf Sci 5(32):19","journal-title":"Human-centric Comput Inf Sci"},{"issue":"1","key":"1604_CR6","first-page":"39","volume":"11","author":"H-S Kang","year":"2015","unstructured":"Kang H-S (2015) A real-time integrated hierarchical temporal memory network for the real-time continuous multi-interval prediction of data streams. J Inf Process Syst 11(1):39\u201356","journal-title":"J Inf Process Syst"},{"key":"1604_CR7","unstructured":"Falliere N, Murchu Liam O, Chien E (2011) W32.Stuxnet Dossier Version 1.4 (February 2011). Symantec Corporation"},{"key":"1604_CR8","unstructured":"Bencs\u00e1th B, P\u00e9k G, Butty\u00e1n L, F\u00e9legyh\u00e1zi M (2012) Duqu: analysis, detection, and lessons learned. ACM Eur Workshop Syst Secur (EuroSec) 2012"},{"key":"1604_CR9","unstructured":"(2013) The \u2018Red October\u2019 Campaign\u2014an advanced cyber espionage network targeting diplomatic and government agencies. GReAT, Kaspersky Lab"},{"key":"1604_CR10","unstructured":"(2015) CARBANAK APT THE GREAT BANK ROBBERY\u201d, Version 2.1. Kaspersky lab"},{"issue":"1","key":"1604_CR11","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1016\/j.jnca.2012.05.003","volume":"36","author":"C Modi","year":"2013","unstructured":"Modi C, Patel D, Borisaniya B, Patel H, Patel Avi, Rajarajan Muttukrishnan (2013) A survey of intrusion detection techniques in Cloud. J Netw Comput Appl 36(1):42\u201357","journal-title":"J Netw Comput Appl"},{"issue":"13","key":"1604_CR12","doi-asserted-by":"crossref","first-page":"5843","DOI":"10.1016\/j.eswa.2014.02.053","volume":"41","author":"N Nissim","year":"2014","unstructured":"Nissim N, Moskovitch R, Rokach L, Elovici Y (2014) Novel active learning methods for enhanced PC malware detection in windows OS. Expert Syst Appl 41(13):5843\u20135857","journal-title":"Expert Syst Appl"},{"issue":"4","key":"1604_CR13","first-page":"11","volume":"5","author":"Hosang Ahn","year":"2014","unstructured":"Ahn Hosang, Kim Hanna, Park Jae Roh (2014) Smart Monitoring of indoor asbestos based on the distinct optical properties of asbestos from particulate matters. J Converg 5(4):11\u201314","journal-title":"J Converg"},{"key":"1604_CR14","doi-asserted-by":"crossref","first-page":"350","DOI":"10.1016\/j.cageo.2012.08.023","volume":"51","author":"B Pradhan","year":"2013","unstructured":"Pradhan B (2013) A comparative study on the predictive ability of the decision tree, support vector machine and neuro-fuzzy models in landslide susceptibility mapping using GIS. Comput Geosci 51:350\u2013365","journal-title":"Comput Geosci"},{"key":"1604_CR15","unstructured":"Jidiga GR, Sammulal P (2014) Anomaly detection using machine learning with a case study. In: 2014 IEEE international conference on advanced communication control and computing technologies (ICACCCT), pp 1060\u20131065"},{"key":"1604_CR16","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1016\/j.cose.2014.10.011","volume":"48","author":"S Alam","year":"2015","unstructured":"Alam S, Horspool RN, Traore I, Sogukpinar I (2015) A framework for metamorphic malware analysis and real-time detection. Comput Secur 48:212\u2013233","journal-title":"Comput Secur"},{"key":"1604_CR17","doi-asserted-by":"crossref","unstructured":"Mohaisen A, Alrawi O, Mohaisen M (2015) Amal: high-fidelity, behavior-based automated malware analysis and classification. Comput Secur 1\u201316","DOI":"10.1016\/j.cose.2015.04.001"},{"issue":"6","key":"1604_CR18","doi-asserted-by":"crossref","first-page":"1012","DOI":"10.1016\/j.jcss.2014.12.014","volume":"81","author":"P Wang","year":"2015","unstructured":"Wang P, Wang Y-S (2015) Malware behavioural detection and vaccine development by using a support vector model classifier. J Comput Syst Sci 81(6):1012\u20131026","journal-title":"J Comput Syst Sci"},{"key":"1604_CR19","doi-asserted-by":"crossref","first-page":"62","DOI":"10.1016\/j.cose.2014.07.004","volume":"46","author":"AAE Elhadi","year":"2014","unstructured":"Elhadi AAE, Maarof MA, Barry BIA, Hamza H (2014) Enhancing the detection of metamorphic malware using call graphs. Computer Secur 46:62\u201378","journal-title":"Computer Secur"},{"key":"1604_CR20","doi-asserted-by":"crossref","unstructured":"Wu LIU, Ping REN, Ke LIU, Hai-xin DUAN (2011) Behavior-based malware analysis and detection. In: 2011 first international workshop on complexity and data mining, pp 39-42","DOI":"10.1109\/IWCDM.2011.17"},{"key":"1604_CR21","doi-asserted-by":"crossref","unstructured":"Ki Y, Kim E, Kim HK (2015) A novel approach to detect malware based on API call sequence analysis. Int J Distrib Sensor Netw 2015(Article ID 659101):9","DOI":"10.1155\/2015\/659101"},{"key":"1604_CR22","doi-asserted-by":"crossref","unstructured":"Tian R, Islam MR, Batten L, Versteeg S (October 2010) Differentiating malware from cleanware using behavioural analysis. In: Proceedings of the 5th International Conference onMalicious and Unwanted Software (MALWARE \u201910). Nancy, France, pp 23\u201330","DOI":"10.1109\/MALWARE.2010.5665796"},{"key":"1604_CR23","doi-asserted-by":"crossref","unstructured":"Ye Y, Wang D, Li T, Ye D (2007) IMDS: intelligent malware detection system. In: Proceedings of the 13th ACM SIGKDD International conference on knowledge discovery and data mining. ACM, pp 1043\u20131047","DOI":"10.1145\/1281192.1281308"},{"key":"1604_CR24","doi-asserted-by":"crossref","unstructured":"Sathyanarayan VS, Kohli P, Bruhadeshwar B (2008) Signature generation and detection of malware families. In: Information Security and Privacy. Springer, Berlin","DOI":"10.1007\/978-3-540-70500-0_25"},{"key":"1604_CR25","unstructured":"API Monitor. http:\/\/www.rohitab.com\/apimonitor , Accessed 30 Nov 2015"},{"key":"1604_CR26","unstructured":"Malshare. http:\/\/malshare.com\/ , Accessed 30 Nov 2015"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11227-015-1604-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-015-1604-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-015-1604-8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-015-1604-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,2]],"date-time":"2019-09-02T23:04:18Z","timestamp":1567465458000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11227-015-1604-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,12,31]]},"references-count":26,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2017,7]]}},"alternative-id":["1604"],"URL":"https:\/\/doi.org\/10.1007\/s11227-015-1604-8","relation":{},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,12,31]]}}}