{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:57:10Z","timestamp":1760245030283},"reference-count":30,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2009,2,7]],"date-time":"2009-02-07T00:00:00Z","timestamp":1233964800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J Comput Virol"],"published-print":{"date-parts":[[2010,5]]},"DOI":"10.1007\/s11416-009-0119-3","type":"journal-article","created":{"date-parts":[[2009,2,7]],"date-time":"2009-02-07T06:45:20Z","timestamp":1233989120000},"page":"91-103","source":"Crossref","is-referenced-by-count":12,"title":["Auto-Sign: an automatic signature generator for high-speed malware filtering devices"],"prefix":"10.1007","volume":"6","author":[{"given":"Gil","family":"Tahan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chanan","family":"Glezer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lior","family":"Rokach","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,2,7]]},"reference":[{"key":"119_CR1","doi-asserted-by":"crossref","unstructured":"Brumley, D., Newsome, J., Song, D., Wang, H., Jha, S.: Towards automatic generation of vulnerability-based signatures. In: Proceedings of the 2006 IEEE Symposium on Security and Privacy (2006)","DOI":"10.1109\/SP.2006.41"},{"key":"119_CR2","volume-title":"The Art of Computer Virus Research and Defense","author":"P. Szor","year":"2005","unstructured":"Szor P.: The Art of Computer Virus Research and Defense. Addison\u2013Wesley, Reading (2005)"},{"key":"119_CR3","unstructured":"Kim, H.A., Karp, B.: Autograph: Toward automated, distributed worm Signature detection. In: Proceedings of the 13th Usenix Security Symposium (Security 2004), San Diego, CA, August (2004)"},{"key":"119_CR4","doi-asserted-by":"crossref","unstructured":"Wang, K., Stolfo, S.J.: Anomalous payload-based network intrusion detection. In: Recent Advance in Intrusion Detection (RAID), September (2004)","DOI":"10.1007\/978-3-540-30143-1_11"},{"key":"119_CR5","unstructured":"Singh, S., Eitan, C., Varghese, G., Savage, S.: Automated worm fingerprinting. In: 6th Symposium on Operating Systems Design and Implementation (OSDI), December (2004)"},{"key":"119_CR6","doi-asserted-by":"crossref","unstructured":"Yegneswaran, V., Giffin, J.T., Barford, P., Jha, S.: An architecture for generating semantics-aware signatures. In: 14th USENIX Security Symposium. Baltimore, Maryland, August (2005)","DOI":"10.21236\/ADA449063"},{"key":"119_CR7","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S., Song, D., Bryant, R.E.: Semantics-aware malware detection. In: IEEE Symposium on Security and Privacy. Oakland, California, May (2005)","DOI":"10.1109\/SP.2005.20"},{"issue":"1","key":"119_CR8","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1145\/972374.972384","volume":"34","author":"C. Kreibich","year":"2004","unstructured":"Kreibich C., Crowcroft J.: Honeycomb: creating intrusion detection signatures using honeypots. SIGCOMM Comput. Commun. Rev. 34(1), 51\u201356 (2004)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"119_CR9","unstructured":"Provos, N.: A virtual honeypot framework. CITI Technical Report 03-1, Center for Information Technology Integration, University of Michigan, Ann Arbor, Michigan, USA, October (2003)"},{"key":"119_CR10","unstructured":"Tang, Y., Chen, S.: Defending against Internet worms: a signature-based approach. In: Proceedings of IEEE INFOCOM\u201905, Miami, Florida, USA, May (2005)"},{"issue":"1","key":"119_CR11","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1007\/s11416-006-0009-x","volume":"2","author":"E. Filiol","year":"2006","unstructured":"Filiol E.: Malware pattern scanning schemes secure against black-box analysis. J. Comput. Virol. 2(1), 35\u201350 (2006)","journal-title":"J. Comput. Virol."},{"issue":"1","key":"119_CR12","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1007\/s11416-007-0036-2","volume":"3","author":"B. Morin","year":"2007","unstructured":"Morin B., M\u00e9 L.: Intrusion detection and virology: an analysis of differences, similarities and complementariness. J. Comput. Virol. 3(1), 39\u201349 (2007)","journal-title":"J. Comput. Virol."},{"key":"119_CR13","doi-asserted-by":"crossref","unstructured":"Elovici, Y., Shabtai, A., Moskovitch, R., Tahan, G., Glezer, C.: Applying Machine Learning Techniques for Detection of Malicious Code in Network Traffic. In: The 30th Annual German Conference on Artificial Intelligence (KI-2007), Lecture Notes in Computer Science, vol. 4667, pp. 44\u201350. Springer, Osnabr\u00fcck (2007)","DOI":"10.1007\/978-3-540-74565-5_5"},{"issue":"2","key":"119_CR14","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1007\/s11416-007-0041-5","volume":"3","author":"E. Filiol","year":"2007","unstructured":"Filiol E., Josse S.: A statistical model for viral detection undecidability. J. Comput. Virol. 3(2), 65\u201374 (2007)","journal-title":"J. Comput. Virol."},{"key":"119_CR15","unstructured":"Filiol, E., Raynal, F.: Malicioux, Malicious Cryptography ... Reloaded and also Malicious Statistics. CanSecWest 2008 Vancouver, pp. 26\u201328 Mars (2008)"},{"key":"119_CR16","volume-title":"Introduction to Algorithms","author":"T.H. Cormen","year":"2001","unstructured":"Cormen T.H., Leiserson C.E., Rivest R.L., Stein C.: Introduction to Algorithms. MIT Press, London (2001)"},{"key":"119_CR17","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1002\/prot.340070105","volume":"7","author":"C.E. Lawrence","year":"1990","unstructured":"Lawrence C.E., Reilly A.A.: An expectation maximization (EM) algorithm for the identification and characterization of common sites in unaligned biopolymer sequences. Proteins Struct. Funct. Genet. 7, 41\u201351 (1990)","journal-title":"Proteins Struct. Funct. Genet."},{"key":"119_CR18","doi-asserted-by":"crossref","first-page":"208","DOI":"10.1126\/science.8211139","volume":"262","author":"C.E. Lawrence","year":"1993","unstructured":"Lawrence C.E., Altschul S.F., Boguski M.S., Liu J.S., Neuwald A.F., Wootton J.C.: Detecting subtle sequence signals: a Gibbs sampling strategy for multiple alignment. Science 262, 208\u2013214 (1993)","journal-title":"Science"},{"key":"119_CR19","doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., Song, D.: Polygraph: automatically generating signatures for polymorphic worms. In: 2005 IEEE Symposium on Security and Privacy (S&P\u201905), pp. 226\u2013241 (2005)","DOI":"10.1109\/SP.2005.15"},{"key":"119_CR20","doi-asserted-by":"crossref","first-page":"664","DOI":"10.1145\/322033.322044","volume":"244","author":"D.S. Hirschberg","year":"1977","unstructured":"Hirschberg D.S.: Algorithms for the longest common subsequence problem. J. ACM 244, 664\u2013675 (1977)","journal-title":"J. ACM"},{"key":"119_CR21","unstructured":"DefensePro, Radware. http:\/\/www.radware.com\/"},{"key":"119_CR22","doi-asserted-by":"crossref","unstructured":"Abou-Assaleh, T., Cercone, N., Ke\u0161elj, V., Sweidan, R.: NGram Based Detection of New Malicious Code. In: 28th Annual International Computer Software and Applications Conference Workshops and Fast Abstracts (COMPSAC\u201904), pp. 41\u201342 (2004)","DOI":"10.1109\/CMPSAC.2004.1342667"},{"key":"119_CR23","doi-asserted-by":"crossref","unstructured":"Goldberg L.A., Goldberg, P.W., Phillips, C.A., Sorkin, G.: Constructing Computer virus phylogenies. J. Algorithms 26(1), pp. 188\u2013208","DOI":"10.1006\/jagm.1997.0897"},{"key":"119_CR24","unstructured":"Karim, M.E., Walenstein, A., Lakhotia, A.: Malware Phylogeny Using Maximal \u03c0Patterns. In: EICAR 2005 Conference: Best Paper Proceedings, pp. 167\u2013174 (2005)"},{"key":"119_CR25","doi-asserted-by":"crossref","first-page":"1181","DOI":"10.2140\/pjm.1960.10.1181","volume":"10","author":"L. Le Cam","year":"1960","unstructured":"Le Cam L.: An approximation theorem for Poisson binomial distribution. Pac. J. Math. 10, 1181\u20131197 (1960)","journal-title":"Pac. J. Math."},{"issue":"4","key":"119_CR26","doi-asserted-by":"crossref","first-page":"420","DOI":"10.1002\/bimj.200410033","volume":"46","author":"C.D. Lai","year":"2004","unstructured":"Lai C.D., Wood G.R., Qiao C.G.: The mean of the inverse of a punctured normal distribution and its application. Biom. J. 46(4), 420\u2013429 (2004)","journal-title":"Biom. J."},{"issue":"4","key":"119_CR27","doi-asserted-by":"crossref","first-page":"1015","DOI":"10.1016\/j.csda.2008.12.001","volume":"53","author":"L. Rokach","year":"2009","unstructured":"Rokach L.: Collective-agreement-based pruning of ensembles. Comput. Stat. Data Anal. 53(4), 1015\u20131026 (2009)","journal-title":"Comput. Stat. Data Anal."},{"issue":"4","key":"119_CR28","doi-asserted-by":"crossref","first-page":"1483","DOI":"10.1016\/j.csda.2008.10.015","volume":"53","author":"E. Menahem","year":"2009","unstructured":"Menahem E., Shabtai A., Rokach L., Elovici Y.: Improving malware detection by applying multi-inducer ensemble. Comput. Stat. Data Anal. 53(4), 1483\u20131494 (2009)","journal-title":"Comput. Stat. Data Anal."},{"issue":"9","key":"119_CR29","doi-asserted-by":"crossref","first-page":"4544","DOI":"10.1016\/j.csda.2008.01.028","volume":"52","author":"R. Moskovitch","year":"2008","unstructured":"Moskovitch R., Elovici Y., Rokach L.: Detection of unknown computer worms based on behavioral classification of the host. Comput. Stat. Data Anal. 52(9), 4544\u20134566 (2008)","journal-title":"Comput. Stat. Data Anal."},{"issue":"4","key":"119_CR30","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1007\/s11416-006-0030-0","volume":"2","author":"K. Rieck","year":"2007","unstructured":"Rieck K., Laskov P.: Language models for detection of unknown attacks in network traffic. J. Comput. Virol. 2(4), 243\u2013256 (2007)","journal-title":"J. Comput. Virol."}],"container-title":["Journal in Computer Virology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-009-0119-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-009-0119-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-009-0119-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,15]],"date-time":"2020-05-15T12:18:07Z","timestamp":1589545087000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-009-0119-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,2,7]]},"references-count":30,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2010,5]]}},"alternative-id":["119"],"URL":"https:\/\/doi.org\/10.1007\/s11416-009-0119-3","relation":{},"ISSN":["1772-9890","1772-9904"],"issn-type":[{"value":"1772-9890","type":"print"},{"value":"1772-9904","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,2,7]]}}}