{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T13:43:45Z","timestamp":1760708625332},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2013,10,20]],"date-time":"2013-10-20T00:00:00Z","timestamp":1382227200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Wireless Pers Commun"],"published-print":{"date-parts":[[2014,4]]},"DOI":"10.1007\/s11277-013-1400-9","type":"journal-article","created":{"date-parts":[[2013,10,19]],"date-time":"2013-10-19T08:48:12Z","timestamp":1382172492000},"page":"1591-1609","source":"Crossref","is-referenced-by-count":8,"title":["Generating Lightweight Behavioral Signature for Malware Detection in People-Centric Sensing"],"prefix":"10.1007","volume":"75","author":[{"given":"Huabiao","family":"Lu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baokang","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinshu","family":"Su","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peidai","family":"Xie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,10,20]]},"reference":[{"key":"1400_CR1","unstructured":"Johnson, P., Kapadia, A., Kotz, D., & Triandopoulos, N. (2007). People-centric urban sensing: Security challenges for the new paradigm. Dartmouth Computer Science Technical Report TR2007-586."},{"key":"1400_CR2","doi-asserted-by":"crossref","unstructured":"Felt, A. P., Finifter, M., Chin, E., et al. (2011). A survey of mobile malware in the wild. In First workshop on security and privacy in smartphones and mobile devices (CCS-SPSM\u201911). Chicago, Illinois, USA.","DOI":"10.1145\/2046614.2046618"},{"key":"1400_CR3","unstructured":"Symantec Corporation (2012). Internet Security Threat Report-2011 Trends Volume 17. Available: http:\/\/www.symantec.com\/threatreport\/"},{"key":"1400_CR4","unstructured":"Symantec Corporation (2013). Internet Security Threat Report-2012 Trends Volume 18. Available: http:\/\/www.symantec.com\/threatreport\/"},{"key":"1400_CR5","doi-asserted-by":"crossref","unstructured":"Rastogi, V., Chen, Y., & Jiang, X. (2013). DroidChameleon: Evaluating android anti-malware against transformation attacks. Short Paper. In Proceedings of the 8th ACM symposium on information, computer and communications Security (ASIACCS).","DOI":"10.1145\/2484313.2484355"},{"key":"1400_CR6","doi-asserted-by":"crossref","unstructured":"You, I., & Yim, K. (2010). Malware obfuscation techniques: A brief survey. In 2010 International conference on broadband, wireless computing, communication and applications.","DOI":"10.1109\/BWCCA.2010.85"},{"key":"1400_CR7","doi-asserted-by":"crossref","unstructured":"Forrest, S., Longstaff, T. A., & Hofmeyr, S. A. (1996). A sense of self for unix processes. In Proceedings of the 1996 IEEE symposium on security and privacy.","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"1400_CR8","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., & Kruegel, C. (2007). Mining specifications of malicious behavior. In Proceedings of the 6th joint meeting of the European software engineering conference and the ACM SIGSOFT symposium on the foundations of software engineering.","DOI":"10.1145\/1287624.1287628"},{"key":"1400_CR9","unstructured":"Clemens, K., Paolo, M. C., Christopher, K., et al. (2009). Effective and efficient malware detection at the end host. In USENIX Security\u201909."},{"key":"1400_CR10","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Christodorescu, M., & Jha, S. (2011). Dynamic behavior matching: A complexity analysis and new approximation algorithms. In 23rd international conference on Automated deduction, LNAI 6803 (pp. 252\u2013267).","DOI":"10.1007\/978-3-642-22438-6_20"},{"key":"1400_CR11","volume-title":"Rootkits: subverting the Windows kernel","author":"G Hoglund","year":"2005","unstructured":"Hoglund, G., & Butler, J. (2005). Rootkits: subverting the Windows kernel. Reading, MA: Addison-Wesley Professional."},{"key":"1400_CR12","doi-asserted-by":"crossref","unstructured":"Lanzi, A., Balzarotti, D., Kruegel, C. et al. (2010). AccessMiner: Using system-centric models for malware protection. In CCS\u201910.","DOI":"10.1145\/1866307.1866353"},{"key":"1400_CR13","unstructured":"Wikipedia. System call [Online]. Available: http:\/\/en.wikipedia.org\/wiki\/System_call , September, 2012"},{"key":"1400_CR14","doi-asserted-by":"crossref","unstructured":"Srivastava, A., Lanzi, A., & Giffin, J. (2008). System call API obfuscation (Extended Abstract). In RAID\u201908.","DOI":"10.1007\/978-3-540-87403-4_36"},{"key":"1400_CR15","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Christodorescu, M. et al. (2010). Synthesizing near-optimal malware specifications from suspicious behaviors. In Proceedings of the 2010 IEEE symposium on security and privacy.","DOI":"10.1109\/SP.2010.11"},{"key":"1400_CR16","unstructured":"Mark Russinovich. Inside the Native API [Online]. Available: http:\/\/netcode.cz\/img\/83\/nativeapi.html , September, 2012"},{"key":"1400_CR17","unstructured":"Wikipedia. Handle (computing) [Online]. Available: http:\/\/en.wikipedia.org\/wiki\/Handle_(computing) , September, 2012"},{"key":"1400_CR18","unstructured":"Bayer, U., Habibi, I., & Balzarotti, D. (2009). A view on current malware behaviors. In 2nd USENIX workshop on large-scale exploits and emergent threats (LEET\u201909)."},{"key":"1400_CR19","unstructured":"Dreger, H., Feldmann, A., Mai, M., Paxson, V., & Sommer, R. (2005). Dynamic application-layer protocol analysis for network intrusion detection. In 15th USENIX security symposium."},{"key":"1400_CR20","unstructured":"Wikipedia. Sequence alignment [Online]. Available: http:\/\/en.wikipedia.org\/wiki\/Sequence_alignment , May, 2013"},{"key":"1400_CR21","doi-asserted-by":"crossref","first-page":"827","DOI":"10.1016\/j.cose.2009.06.003","volume":"28","author":"Y Tang","year":"2009","unstructured":"Tang, Y., Xiao, B., & Lu, X. (2009). Using a bioinformatics approach to generate accurate exploit-based signatures for polymorphic worms. Computers & Security, 28, 827\u2013842.","journal-title":"Computers & Security"},{"issue":"3","key":"1400_CR22","doi-asserted-by":"crossref","first-page":"4430453","DOI":"10.1016\/0022-2836(70)90057-4","volume":"48","author":"SB Needleman","year":"1970","unstructured":"Needleman, S. B., & Wunsch, C. D. (1970). A general method applicable to the search for similarities in the amino acid sequence of two proteins. Journal of Molecular Biology, 48(3), 4430453.","journal-title":"Journal of Molecular Biology"},{"issue":"1","key":"1400_CR23","doi-asserted-by":"crossref","first-page":"2050217","DOI":"10.1006\/jmbi.2000.4042","volume":"302","author":"C Notredame","year":"2000","unstructured":"Notredame, C., Higgins, D. G., & Heringa, J. (2000). T-coffee: A novel method for fast and accurate multiple sequence alignment. Journal of Molecular Biology, 302(1), 2050217.","journal-title":"Journal of Molecular Biology"},{"key":"1400_CR24","unstructured":"Li, Z., Sanghi, M., Chen, Y., et al. (2006). Hamsa: Fast signature generation for zero-day polymorphic worms with provable attack resilience. In IEEE symposium on security and privacy 2006."},{"key":"1400_CR25","unstructured":"mwanalysis. [Online]. http:\/\/mwanalysis.org\/"},{"key":"1400_CR26","unstructured":"[Online]. http:\/\/code.google.com\/p\/wusstrace\/"}],"container-title":["Wireless Personal Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-013-1400-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11277-013-1400-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-013-1400-9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,31]],"date-time":"2019-07-31T00:57:48Z","timestamp":1564534668000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11277-013-1400-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,10,20]]},"references-count":26,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2014,4]]}},"alternative-id":["1400"],"URL":"https:\/\/doi.org\/10.1007\/s11277-013-1400-9","relation":{},"ISSN":["0929-6212","1572-834X"],"issn-type":[{"value":"0929-6212","type":"print"},{"value":"1572-834X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,10,20]]}}}