{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T02:11:34Z","timestamp":1773799894650,"version":"3.50.1"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T00:00:00Z","timestamp":1692576000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T00:00:00Z","timestamp":1692576000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Science and Technology Project of State Grid Corporation of China","award":["5108-202218280A-2-154-XG"],"award-info":[{"award-number":["5108-202218280A-2-154-XG"]}]},{"name":"Science and Technology Project of State Grid Corporation of China","award":["5108-202218280A-2-154-XG"],"award-info":[{"award-number":["5108-202218280A-2-154-XG"]}]},{"name":"Science and Technology Project of State Grid Corporation of China","award":["5108-202218280A-2-154-XG"],"award-info":[{"award-number":["5108-202218280A-2-154-XG"]}]},{"name":"Science and Technology Project of State Grid Corporation of China","award":["5108-202218280A-2-154-XG"],"award-info":[{"award-number":["5108-202218280A-2-154-XG"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2024,1]]},"DOI":"10.1007\/s11227-023-05556-x","type":"journal-article","created":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T19:01:31Z","timestamp":1692644491000},"page":"2748-2766","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["A novel malware detection method based on API embedding and API parameters"],"prefix":"10.1007","volume":"80","author":[{"given":"Bo","family":"Zhou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hai","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Xia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Donghai","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,8,21]]},"reference":[{"key":"5556_CR1","doi-asserted-by":"crossref","unstructured":"Aghakhani H, Gritti F, Mecca F, Lindorfer M, Ortolani S, Balzarotti D, Vigna G, Kruegel C (2020) When malware is packin\u2019 heat; limits of machine learning classifiers based on static analysis features. In: Proceedings of Symposium on Network and Distributed System Security (NDSS). The Internet Society","DOI":"10.14722\/ndss.2020.24310"},{"key":"5556_CR2","doi-asserted-by":"crossref","unstructured":"Ahmed F, Hameed H, Zubair Shafiq M, Farooq M (2009). Using spatio-temporal information in API calls with machine learning algorithms for malware detection. In: Proceedings of the 2nd ACM Workshop on Security and Artificial Intelligence, AISec \u201909, pp 55\u201362","DOI":"10.1145\/1654988.1655003"},{"issue":"8","key":"5556_CR3","doi-asserted-by":"publisher","first-page":"5551","DOI":"10.1007\/s11227-019-02810-z","volume":"75","author":"BM Bagher","year":"2019","unstructured":"Bagher BM, Mahdi A, Asghar T (2019) HLMD: a signature-based approach to hardware-level behavioral malware detection and classification. J. Supercomput. 75(8):5551\u20135582","journal-title":"J. Supercomput."},{"key":"5556_CR4","doi-asserted-by":"crossref","unstructured":"Borrello P, Coppa E, D\u2019Elia DC (2021) Hiding in the particles: When return-oriented programming meets program obfuscation. In: 2021 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp 555\u2013568","DOI":"10.1109\/DSN48987.2021.00064"},{"key":"5556_CR5","doi-asserted-by":"crossref","unstructured":"Canzanese R, Mancoridis S, Kam M (2015) System call-based detection of malicious processes. In: 2015 IEEE International Conference on Software Quality, Reliability and Security, pp 119\u2013124","DOI":"10.1109\/QRS.2015.26"},{"key":"5556_CR6","doi-asserted-by":"crossref","unstructured":"Chen L, Sultana S, Sahita R (2018) Henet: A deep learning approach on intel\u00aeprocessor trace for effective exploit detection. In: 2018 IEEE Security and Privacy Workshops (SPW), pp 109\u2013115","DOI":"10.1109\/SPW.2018.00025"},{"key":"5556_CR7","doi-asserted-by":"publisher","first-page":"788","DOI":"10.1109\/TIFS.2022.3152360","volume":"17","author":"Xiaohui Chen","year":"2022","unstructured":"Chen Xiaohui, Hao Zhiyu, Li Lun, Cui Lei, Zhu Yiran, Ding Zhenquan, Liu Yongji (2022) Cruparamer: learning on parameter-augmented API sequences for malware detection. IEEE Tran Inf Forensics Secur 17:788\u2013803","journal-title":"IEEE Tran Inf Forensics Secur"},{"key":"5556_CR8","doi-asserted-by":"crossref","unstructured":"Chen X, Tong Y, Du C, Liu Y, Ding Z, Ran Q, Zhang Y, Cui L, Hao Z (2022) Malpro: Learning on process-aware behaviors for malware detection. In: 2022 IEEE Symposium on Computers and Communications (ISCC), pp 01\u201307","DOI":"10.1109\/ISCC55528.2022.9913030"},{"key":"5556_CR9","doi-asserted-by":"crossref","unstructured":"Christodorescu M, Jha S, Seshia SA, Song D, Bryant RE (2005) Semantics-aware malware detection. In: 2005 IEEE Symposium on Security and Privacy (S P\u201905), pp 32\u201346","DOI":"10.1109\/SP.2005.20"},{"key":"5556_CR10","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1016\/j.future.2021.06.032","volume":"125","author":"A Darem","year":"2021","unstructured":"Darem A, Abawajy J, Makkar A, Alhashmi A, Alanazi S (2021) Visualization and deep-learning-based malware variant detection using opcode-level features. Fut Gener Comput Syst 125:314\u2013323","journal-title":"Fut Gener Comput Syst"},{"key":"5556_CR11","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1016\/j.cose.2019.02.007","volume":"83","author":"W Han","year":"2019","unstructured":"Han W, Xue J, Wang Y, Huang L, Kong Z, Limin M (2019) Maldae: detecting and explaining malware based on correlation and fusion of static and dynamic characteristics. Comput Secur 83:208\u2013233","journal-title":"Comput Secur"},{"key":"5556_CR12","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1016\/j.jnca.2018.10.022","volume":"125","author":"W Han","year":"2019","unstructured":"Han W, Xue J, Wang Y, Liu Z, Kong Z (2019) Malinsight: a systematic profiling based malware detection framework. J Netw Comput Appl 125:236\u2013250","journal-title":"J Netw Comput Appl"},{"key":"5556_CR13","doi-asserted-by":"crossref","unstructured":"Jindal C, Salls C, Aghakhani H, Long K, Kruegel C, Vigna G (2019) Neurlux: dynamic malware analysis without feature engineering. In: Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC \u201919, pp 444\u2013455","DOI":"10.1145\/3359789.3359835"},{"key":"5556_CR14","doi-asserted-by":"crossref","unstructured":"Kalash M, Rochan M, Mohammed N, Bruce ND, Wang Y, Iqbal F (2018) Malware classification with deep convolutional neural networks. In: 2018 9th IFIP international conference on new technologies, mobility and security (NTMS), pp 1\u20135","DOI":"10.1109\/NTMS.2018.8328749"},{"key":"5556_CR15","doi-asserted-by":"crossref","unstructured":"Kolosnjaji B, Zarras A, Webster G, Eckert C (2016) Deep learning for classification of malware system call sequences. In: Kang BH, Bai Q, editors, AI 2016: Advances in Artificial Intelligence, pp 137\u2013149","DOI":"10.1007\/978-3-319-50127-7_11"},{"key":"5556_CR16","doi-asserted-by":"crossref","unstructured":"Kong D, Yan G (2013) Discriminant malware distance learning on structural information for automated malware classification. In: Proceedings of the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp 1357\u20131365","DOI":"10.1145\/2487575.2488219"},{"key":"5556_CR17","doi-asserted-by":"crossref","unstructured":"Lanzi A, Balzarotti D, Kruegel C, Christodorescu M, Kirda E (2010) Accessminer: Using system-centric models for malware protection. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS \u201910, pp 399\u2013412","DOI":"10.1145\/1866307.1866353"},{"key":"5556_CR18","doi-asserted-by":"publisher","first-page":"102872","DOI":"10.1016\/j.cose.2022.102872","volume":"122","author":"C Li","year":"2022","unstructured":"Li C, Cheng Z, Zhu H, Wang L, Lv Q, Wang Y, Li N, Sun D (2022) DMalNet: dynamic malware analysis based on API feature engineering and graph learning. Comput Secur 122:102872","journal-title":"Comput Secur"},{"key":"5556_CR19","doi-asserted-by":"publisher","first-page":"3886","DOI":"10.1109\/TIFS.2020.3003571","volume":"15","author":"D Li","year":"2020","unstructured":"Li D, Li Q (2020) Adversarial deep ensemble: evasion attacks and defenses for malware detection. IEEE Trans Inf Forensics Secur 15:3886\u20133900","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"5556_CR20","unstructured":"Lu R (2019) Malware detection with LSTM using opcode language. arxiv:1906.04593"},{"key":"5556_CR21","unstructured":"Mikolov T, Sutskever I, Chen K, Corrado GS, Dean J (2013) Distributed representations of words and phrases and their compositionality. In: Proceedings of the 26th International Conference on Neural Information Processing Systems - Vol 2, NIPS\u201913, pp 3111\u20133119"},{"issue":"2","key":"5556_CR22","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1109\/LCA.2018.2883431","volume":"17","author":"D Min","year":"2018","unstructured":"Min D, Park D, Ahn J, Walker R, Lee J, Park S, Kim Y (2018) Amoeba: an autonomous backup and recovery SSD for ransomware attack defense. IEEE Comput Architect Lett 17(2):245\u2013248","journal-title":"IEEE Comput Architect Lett"},{"key":"5556_CR23","doi-asserted-by":"crossref","unstructured":"Moskovitch R, Feher C, Tzachar N, Berger E, Gitelman M, Dolev S, Elovici Y (2008) Unknown malcode detection using opcode representation. In: Intelligence and Security Informatics, pp 204\u2013215","DOI":"10.1007\/978-3-540-89900-6_21"},{"key":"5556_CR24","doi-asserted-by":"publisher","first-page":"102154","DOI":"10.1016\/j.adhoc.2020.102154","volume":"105","author":"H Naeem","year":"2020","unstructured":"Naeem H, Ullah F, Naeem MR, Khalid S, Vasan D, Jabbar S, Saeed S (2020) Malware detection in industrial internet of things based on hybrid image visualization and deep learning model. Ad Hoc Netw 105:102154","journal-title":"Ad Hoc Netw"},{"issue":"18","key":"5556_CR25","doi-asserted-by":"publisher","first-page":"3311","DOI":"10.1002\/sec.1255","volume":"8","author":"M Narouei","year":"2015","unstructured":"Narouei M, Ahmadi M, Giacinto G, Takabi H, Sami A (2015) DLLMiner: structural mining for malware detection. Secur Commun Netw 8(18):3311\u20133322","journal-title":"Secur Commun Netw"},{"key":"5556_CR26","doi-asserted-by":"publisher","first-page":"871","DOI":"10.1016\/j.cose.2018.04.005","volume":"77","author":"S Ni","year":"2018","unstructured":"Ni S, Qian Q, Zhang R (2018) Malware identification using visualization images and deep learning. Comput Secur 77:871\u2013885","journal-title":"Comput Secur"},{"key":"5556_CR27","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102871","volume":"122","author":"W Qiang","year":"2022","unstructured":"Qiang W, Yang L, Jin H (2022) Efficient and robust malware detection based on control flow traces using deep neural networks. Comput Secur 122:102871","journal-title":"Comput Secur"},{"key":"5556_CR28","unstructured":"Ravnas OAV (2022) FRIDA: a world-class dynamic instrumentation toolkit. https:\/\/frida.re\/"},{"issue":"3","key":"5556_CR29","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1016\/j.eng.2019.12.012","volume":"6","author":"K Ren","year":"2020","unstructured":"Ren K, Zheng T, Qin Z, Liu X (2020) Adversarial attacks and defenses in deep learning. Engineering 6(3):346\u2013360","journal-title":"Engineering"},{"key":"5556_CR30","doi-asserted-by":"crossref","unstructured":"Sayadi H, Patel N, Sasan A, Rafatirad S, Homayoun H (2018) Ensemble learning for effective run-time hardware-based malware detection: a comprehensive analysis and classification. In: 2018 55th ACM\/ESDA\/IEEE Design Automation Conference (DAC), pp 1\u20136","DOI":"10.1109\/DAC.2018.8465828"},{"key":"5556_CR31","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101775","volume":"93","author":"S Sebastio","year":"2020","unstructured":"Sebastio S, Baranov E, Biondi F, Decourbe O, Given-Wilson T, Legay A, Puodzius C, Quilbeuf J (2020) Optimizing symbolic execution for malware behavior classification. Comput Secur 93:101775","journal-title":"Comput Secur"},{"key":"5556_CR32","unstructured":"SL SD, Jaidhar CD (2019) Windows malware detector using convolutional neural network based on visualization images. In: IEEE Transactions on Emerging Topics in Computing"},{"key":"5556_CR33","unstructured":"Sun G, Qian Q (2018) Deep learning and visualization for identifying malware families. In: IEEE Transactions on Dependable and Secure Computing"},{"key":"5556_CR34","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1007\/978-3-319-11379-1_6","volume-title":"Research in attacks, intrusions and defenses","author":"A Tang","year":"2014","unstructured":"Tang A, Sethumadhavan S, Stolfo SJ (2014) Unsupervised anomaly-based malware detection using hardware features. In: Stavrou A, Bos H, Portokalidis G (eds) Research in attacks, intrusions and defenses. Springer International Publishing, Cham, pp 109\u2013129"},{"key":"5556_CR35","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101997","volume":"97","author":"F Tang","year":"2020","unstructured":"Tang F, Ma B, Li J, Zhang F, Su J, Ma J (2020) Ransomspector: an introspection-based approach to detect crypto ransomware. Comput Secur 97:101997","journal-title":"Comput Secur"},{"key":"5556_CR36","doi-asserted-by":"publisher","first-page":"108394","DOI":"10.1016\/j.comnet.2021.108394","volume":"198","author":"D Tian","year":"2021","unstructured":"Tian D, Ying Q, Jia X, Ma R, Hu C, Liu W (2021) MDCHD: a novel malware detection method in cloud using hardware trace and deep learning. Comput Netw 198:108394","journal-title":"Comput Netw"},{"key":"5556_CR37","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1016\/j.comnet.2019.04.007","volume":"157","author":"L Xiaofeng","year":"2019","unstructured":"Xiaofeng L, Fangshuo J, Xiao Z, Shengwei Y, Jing S, Lio P (2019) ASSCA: API sequence and statistics features combined architecture for malware detection. Comput Netw 157:99\u2013111","journal-title":"Comput Netw"},{"key":"5556_CR38","doi-asserted-by":"crossref","unstructured":"Xu D, Ming J, Fu Y, Wu D (2018) Vmhunt: A verifiable approach to partially-virtualized binary code simplification. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201918, pp 442-458","DOI":"10.1145\/3243734.3243827"},{"key":"5556_CR39","doi-asserted-by":"crossref","unstructured":"Yang Z, Yang D, Dyer C, He X, Smola A, Hovy E (2016) Hierarchical attention networks for document classification. In: Proceedings of the 2016 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, pp 1480\u20131489","DOI":"10.18653\/v1\/N16-1174"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-023-05556-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11227-023-05556-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-023-05556-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,15]],"date-time":"2024-01-15T09:36:51Z","timestamp":1705311411000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11227-023-05556-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,21]]},"references-count":39,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,1]]}},"alternative-id":["5556"],"URL":"https:\/\/doi.org\/10.1007\/s11227-023-05556-x","relation":{},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,21]]},"assertion":[{"value":"2 August 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 August 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors state that they have no known competing financial interests or personal ties that could have appeared to affect the work reported in this study.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}