{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:43:32Z","timestamp":1786113812873,"version":"3.56.0"},"reference-count":28,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2020,1,25]],"date-time":"2020-01-25T00:00:00Z","timestamp":1579910400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,25]],"date-time":"2020-01-25T00:00:00Z","timestamp":1579910400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Wireless Pers Commun"],"published-print":{"date-parts":[[2020,6]]},"DOI":"10.1007\/s11277-020-07166-9","type":"journal-article","created":{"date-parts":[[2020,1,25]],"date-time":"2020-01-25T14:02:27Z","timestamp":1579960947000},"page":"2597-2609","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":118,"title":["Two-Stage Ransomware Detection Using Dynamic Analysis and Machine Learning Techniques"],"prefix":"10.1007","volume":"112","author":[{"given":"Jinsoo","family":"Hwang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jeankyung","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Seunghwan","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5350-1771","authenticated-orcid":false,"given":"Kichang","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,1,25]]},"reference":[{"key":"7166_CR1","unstructured":"Alazab, M., Venkatraman, S., & Watters, P. (2011). Zero-day malware detection based on supervised learning algorithms of API call signatures. In Proceedings of the 9th Australasian data mining conference (AusDM 2011) (Vol. 121, pp. 171\u2013182). Australian Computer Society."},{"key":"7166_CR2","unstructured":"Bayer, U., Kruegel, C., & Kirda, E. (2006). TTAnalyze: A tool for analyzing malware. In Proceedings of the European institute for computer antivirus research annual conference."},{"key":"7166_CR3","unstructured":"BBC News. (2016). University pays 20,000 Dollars to ransomware hackers. http:\/\/www.bbc.com\/news\/technology-36478650. Accessed 24 Jan 2020."},{"key":"7166_CR4","unstructured":"Belcher, P. (2016). Sofos-Invincea. https:\/\/www.securitynewspaper.com\/2016\/06\/07\/hash-factory-new-cerber-ransomware-morphs-every-15-seconds\/. Accessed 24 Jan 2020."},{"key":"7166_CR5","unstructured":"Bergeron, J., Debbabi, M., Desharnais, J., Erhioui, M.M., Lavoie, Y., & Tawbi, N. (2001). Static detection of malicious code in executable programs. In Proceedings of the symposium on requirements engineering for information security (SREIS \u201901)."},{"key":"7166_CR6","unstructured":"Butler, K., Scaife, N., Carter, H., & Traynor, P. (2016). CryptoLock (and drop it): Stoping ransomware attacks on user data. In Proceedings of international conference on distributive computing systems."},{"key":"7166_CR7","doi-asserted-by":"crossref","unstructured":"Continella, A., Guagnelli, A., Zingaro, G., De Pasquale, G., Barenghi, A., Zanero, S., & Maggi, F. (2016). Shieldfs: A self-healing, ransomware-aware filesystem. In Proceedings of the 32nd annual conference on computer security applications (pp. 336\u2013347). ACM.","DOI":"10.1145\/2991079.2991110"},{"key":"7166_CR8","unstructured":"CryptoLocker Ransomware Information Guide and FAQ. (2016). [WWW]. http:\/\/www.bleepingcomputer.com\/virus-removal\/cryptolocker-ransomware-information."},{"key":"7166_CR9","unstructured":"CUCKOO FOUNDATION. (2015). Cuckoo sandbox: Automated malware analysis. www.cuckoosandbox.org. Accessed 24 Jan 2020."},{"key":"7166_CR10","unstructured":"Francescani, C. (2016). Ransomware hackers blackmail U.S. police departments. http:\/\/www.cnbc.com\/2016\/04\/26\/ransomware-hackers-blackmail-us-police-departments.html. Accessed 24 Jan 2020."},{"key":"7166_CR11","unstructured":"Gupta, S., Sharma, H., & Kaur S. (2016). Malware characterization using Windows API call sequences. In Proceedings of security, privacy, and applied cryptography engineering: 6th international conferences, SPACE 2016, Hyderabad, India, December 14\u201318."},{"key":"7166_CR12","doi-asserted-by":"crossref","unstructured":"Jang, J. W., Woo, J., Yun, J., & Kim, H. K. (2014). Mal-netminer: Malware classification based on social network analysis of call graph. In Proceedings of the companion publication of the 23rd international conference on world wide web companion (WWWCompanion 2014) (pp. 731\u2013734). International World Wide Web Conferences Steering Committee.","DOI":"10.1145\/2567948.2579364"},{"key":"7166_CR13","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/978-3-642-21393-9_6","volume-title":"Digital forensics approach, dependable computer systems","author":"I Jozwiak","year":"2011","unstructured":"Jozwiak, I., Kedziora, M., & Melinska, A. (2011). Theoretical and practical aspects of encrypted containers detection. In W. Zamojski, J. Kacprzyk, J. Mazurkiewicz, J. Sugier, & T. Walkowiak (Eds.), Digital forensics approach, dependable computer systems (pp. 75\u201385). Berlin: Springer."},{"key":"7166_CR14","unstructured":"Kharraz, A., Robertson, W., Balzarotti, D., Bilge, L., & Kirda, E. (2015). Cutting the Gordian knot: A look under the hood of ransomware attacks (pp. 1\u201310). Retrieved April 8, 2016, from http:\/\/seclab.ccs.neu.edu\/static\/publications\/dimva2015ransomware.pdf."},{"key":"7166_CR15","unstructured":"Kharraz, A, et al. (2016). UNVEIL: A large-scale, automated approach to detecting ransomware. In 25th USENIX security symposium (USENIX Security 16)."},{"key":"7166_CR16","doi-asserted-by":"crossref","unstructured":"Kolodenker, E., Koch, W., Stringhini, G., & Egele, M. (2017). Paybreak: Defense against cryptographic ransomware. In Proceedings of the 2017 ACM on Asia conference on computer and communications security, ASIA CCS 2017, New York, NY, USA (pp. 599\u2013611).","DOI":"10.1145\/3052973.3053035"},{"key":"7166_CR17","unstructured":"Lipovsky, R. (2014). We live security. Retrieved December 22, 2014, from https:\/\/www.welivesecurity.com\/2014\/12\/22\/win32virlock-first-self-reproducing-ransomware-also-shape-shifter\/."},{"key":"7166_CR18","doi-asserted-by":"crossref","unstructured":"Mariconti, E., Onwuzurike, L., Andriotis, P., Cristofaro, E. D., Ross, G., & Stringhini, G. (2017). MaMaDroid: Detecting android malware by building Markov chains of behavioral models. In The proceedings of 24th network and distributed system security symposium.","DOI":"10.14722\/ndss.2017.23353"},{"key":"7166_CR19","unstructured":"Mimoso, M. (2017). Leaked NSA exploit spreading ransomware worldwide. https:\/\/threatpost.com\/leaked-nsa-exploit-spreading-ransomware-worldwide\/125654\/. Accessed 24 Jan 2020."},{"issue":"2","key":"7166_CR20","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1109\/TDSC.2007.1003","volume":"4","author":"S Peisert","year":"2007","unstructured":"Peisert, S., Bishop, M., Karin, S., & Marzullo, K. (2007). Analysis of computer intrusions using sequences of function calls. IEEE Transactions on Dependable and Secure Computing, 4(2), 137\u2013150.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"7166_CR21","unstructured":"Qiao, Y., Yang, Y., Ji, L., & He, J. (2013). Analyzing malware by abstracting the frequent item sets in API call sequences. In Proceedings of the 12th IEEE international conference on trust, security and privacy in computing and communications (TrustCom 2013) (pp. 265\u2013270)."},{"key":"7166_CR22","unstructured":"Sathyanarayan, V. S., Kohli, P., & Bruhadeshwar, B. (2008). Signature generation and detection of malware families. In Information security and privacy. Berlin: Springer."},{"key":"7166_CR23","unstructured":"Sgandurra, D., Munoz-Gonzalez, L. M., Mohsen, R., & Lupu, E. C. (2016). Automated dynamic analysis of ransomware: Benefits, limitations and use for detection. arXiv:1609.03020v1."},{"key":"7166_CR24","doi-asserted-by":"crossref","unstructured":"Shankarapani, M., Kancherla, K., Ramammoorthy, S., Movva, R., & Mukkamala, S. (2010). Kernel machines for malware classification and similarity analysis. In Proceedings of the international joint conference on neural networks (IJCNN 2010) (pp. 1\u20136).","DOI":"10.1109\/IJCNN.2010.5596339"},{"key":"7166_CR25","unstructured":"WIRED Magazine. (2016). Why hospitals are the perfect targets for ransomware. https:\/\/www.wired.com\/2016\/03\/ransomware-why-hospitals-are-the-perfect-targets\/. Accessed 24 Jan 2020."},{"key":"7166_CR26","unstructured":"You, K., & Yim, I. (2016). Malware obfuscation techniques: A brief survey. In International conference on broadband, wireless computing communication and application."},{"key":"7166_CR27","doi-asserted-by":"publisher","DOI":"10.1155\/2015\/659101","author":"K Youngjoon","year":"2015","unstructured":"Youngjoon, K., Eunjin, K., & HuyKang, K. (2015). A Novel approach to detect Malware based on API call sequence analysis. International Journal of Distributed Sensor Networks. https:\/\/doi.org\/10.1155\/2015\/659101","journal-title":"International Journal of Distributed Sensor Networks"},{"key":"7166_CR28","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.future.2018.07.052","volume":"90","author":"H Zhang","year":"2019","unstructured":"Zhang, H., Xiao, X., Mercaldo, F., Ni, S., Martinelli, F., & Sangaiah, A. K. (2019). Classification of ransomware families with machine learning based on N-gram of opcodes. Future Generation Computer Systems, 90, 211\u2013211.","journal-title":"Future Generation Computer Systems"}],"container-title":["Wireless Personal Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-020-07166-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11277-020-07166-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-020-07166-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,1,24]],"date-time":"2021-01-24T00:15:50Z","timestamp":1611447350000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11277-020-07166-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,1,25]]},"references-count":28,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,6]]}},"alternative-id":["7166"],"URL":"https:\/\/doi.org\/10.1007\/s11277-020-07166-9","relation":{},"ISSN":["0929-6212","1572-834X"],"issn-type":[{"value":"0929-6212","type":"print"},{"value":"1572-834X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,1,25]]},"assertion":[{"value":"25 January 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}