{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T21:55:16Z","timestamp":1769637316082,"version":"3.49.0"},"reference-count":28,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2011,10,22]],"date-time":"2011-10-22T00:00:00Z","timestamp":1319241600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J Comput Virol"],"published-print":{"date-parts":[[2011,11]]},"DOI":"10.1007\/s11416-011-0156-6","type":"journal-article","created":{"date-parts":[[2011,10,21]],"date-time":"2011-10-21T03:24:19Z","timestamp":1319167459000},"page":"279-295","source":"Crossref","is-referenced-by-count":19,"title":["Classification of packet contents for malware detection"],"prefix":"10.1007","volume":"7","author":[{"given":"Irfan","family":"Ahmed","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kyung-suk","family":"Lhee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2011,10,22]]},"reference":[{"key":"156_CR1","unstructured":"Bro. http:\/\/www.bro-ids.org . Accessed 14 Nov 2010"},{"key":"156_CR2","unstructured":"Publicly available library of malwares (VX Heavens). http:\/\/vx.netlux.org\/ . Accessed 14 Nov 2010"},{"key":"156_CR3","unstructured":"Snort. http:\/\/www.snort.org\/ . Accessed 14 Nov 2010"},{"key":"156_CR4","unstructured":"Tcpdump. http:\/\/www.tcpdump.org . Accessed 14 Nov 2010"},{"key":"156_CR5","unstructured":"Tcptrace. http:\/\/www.tcptrace.org . Accessed 14 Nov 2010"},{"key":"156_CR6","doi-asserted-by":"crossref","unstructured":"Amirani, M.C., Toorani, M., Shirazi, A.A.B.: A new approach to content-based file type detection. In: IEEE Symposium on Computers and Communications (ISCC \u201908), pp. 1103\u20131108 (2008)","DOI":"10.1109\/ISCC.2008.4625611"},{"key":"156_CR7","unstructured":"Bolzoni, D., Etalle, S., Hartel, P.: Poseidon: a 2-tier anomaly-based network intrusion detection system. In: Fourth IEEE International Workshop on Information Assurance (IWIA\u201906). London, UK (2006)"},{"issue":"1","key":"156_CR8","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1016\/j.diin.2008.05.005","volume":"5","author":"W.C. Calhoun","year":"2008","unstructured":"Calhoun W.C., Coles D.: Predicting the types of file fragments. Digit. Investig. 5(1), 14\u201320 (2008)","journal-title":"Digit. Investig."},{"key":"156_CR9","unstructured":"Criscione, C., Zanero, S.: Masibty: an anomaly based intrusion prevention system for web applications. In: Black Hat Europe. Moevenpick City Center, Amsterdam, Netherlands (2009)"},{"key":"156_CR10","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: Bothunter: Detecting malware infection through ids-driven dialog correlation. In: 16th USENIX Security Symposium, Boston, pp. 167\u2013182 (2007)"},{"key":"156_CR11","unstructured":"Harris, R.M.: Using artificial neural networks for forensic file type identification. Technical report, Purdue University (2007)"},{"issue":"1","key":"156_CR12","first-page":"1","volume":"1","author":"A. Kolmogorov","year":"1965","unstructured":"Kolmogorov A.: Three approaches to the quantitative definition of information. Problems Inf Transmission 1(1), 1\u20137 (1965)","journal-title":"Problems Inf Transmission"},{"key":"156_CR13","unstructured":"Kruegel, C., Toth, T., Kirda, E.: Service specific anomaly detection for network intrusion detection. In: ACM Symposium on Applied Computing, Madrid, pp. 201\u2013208 (2010)"},{"key":"156_CR14","doi-asserted-by":"crossref","unstructured":"Li, W.J., Stolfo, S., Stavrou, A., Androulaki, E., Keromytis, A.D.: A study of malcode-bearing documents. In: Proceedings of the 4th international conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Lucerne, pp. 231\u2013250 (2007)","DOI":"10.1007\/978-3-540-73614-1_14"},{"key":"156_CR15","unstructured":"Li, W.J., Wang, K., Stolfo, S.J., Herzog, B.: Fileprints: identifying file types by n-gram analysis. In: Workshop on Information Assurance and Security (IAW\u201905), pp. 64\u201371. United States Military Academy, West Point, New York (2005)"},{"key":"156_CR16","unstructured":"Martin, K., Nahid, S.: File type identification of data fragments by their binary structure. In: Proceedings of the 7th Annual IEEE Information Assurance Workshop, pp. 140\u2013147. United States Military Academy, West Point, New York (2006)"},{"key":"156_CR17","doi-asserted-by":"crossref","unstructured":"Martin, K., Nahid, S.: Oscar: file type identification of binary data in disk clusters and ram pages. In: Proceedings of IFIP International Information Security Conference: Security and Privacy in Dynamic Environments (SEC2006), pp. 413\u2013424 (2006)","DOI":"10.1007\/0-387-33406-8_35"},{"key":"156_CR18","doi-asserted-by":"crossref","unstructured":"McDaniel, M., Heydari, M.H.: Content based file type detection algorithms. In: Proceedings of the 36th Annual Hawaii International Conference on System Sciences, vol. 9, p. 332a (2003)","DOI":"10.1109\/HICSS.2003.1174905"},{"key":"156_CR19","doi-asserted-by":"crossref","unstructured":"Shafiq, M.Z., Khayam, S.A., Farooq, M.: Embedded malware detection using markov n-grams. In: International Conference on Detection of Intrusions, Malware and Vulnerability Assessment (DIMVA\u201908), Paris, pp. 88\u2013107 (2008)","DOI":"10.1007\/978-3-540-70542-0_5"},{"key":"156_CR20","doi-asserted-by":"crossref","unstructured":"Sommer, R., Paxson, V.: Enhancing byte-level network intrusion detection signatures with context. In: 10th ACM Conference on Computer and Communications Security, Washington, DC, pp. 262\u2013271 (2003)","DOI":"10.1145\/948143.948145"},{"key":"156_CR21","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1007\/978-0-387-44599-1_11","volume":"27","author":"S.J. Stolfo","year":"2007","unstructured":"Stolfo S.J., Wang K., Li W.J.: Towards stealthy malware detection. Adv. Inf. Secur. 27, 231\u2013249 (2007)","journal-title":"Adv. Inf. Secur."},{"key":"156_CR22","unstructured":"Tan, P.N., Steinbach, M., Kumar, V.: Classification: alternative techniques. In: Introduction to Data Mining. AddisonWesley, USA (2005)"},{"key":"156_CR23","doi-asserted-by":"crossref","unstructured":"Veenman, C.J.: Statistical disk cluster classification for file carving. In: IEEE Third International Symposium on Information Assurance and Security, pp. 393\u2013398 (2007)","DOI":"10.1109\/IAS.2007.75"},{"key":"156_CR24","doi-asserted-by":"crossref","unstructured":"Wang, K., Parekh, J.J., Stolfo, S.J.: Anagram: a content anomaly detector resistant to mimicry attack. In: 9th International Symposium on Recent Advances in Intrusion Detection (RAID\u201906), Hamburg, pp. 226\u2013248 (2006)","DOI":"10.1007\/11856214_12"},{"key":"156_CR25","doi-asserted-by":"crossref","unstructured":"Wang, K., Stolfo, S.J.: Anomalous payload-based network intrusion detection. In: Seventh International Symposium on Recent Advances in Intrusion Detection (RAID\u201904), France, pp. 203\u2013222 (2004)","DOI":"10.1007\/978-3-540-30143-1_11"},{"key":"156_CR26","unstructured":"Wang, X., Pan, C.C., Liu, P., Zhu, S.: Sigfree: a signature-free buffer overflow attack blocker. In: 15th USENIX Security Symposium, Boston, pp. 225\u2013240 (2006)"},{"key":"156_CR27","doi-asserted-by":"crossref","unstructured":"Zanero, S.: Ulisse, a network intrusion detection system. In: 4th annual workshop on cyber security and information intelligence research (CSIIRW\u201908). Oak Ridge, TN, USA (2008)","DOI":"10.1145\/1413140.1413163"},{"key":"156_CR28","unstructured":"Zhang, Y., Paxson, V.: Detecting backdoors. In: 9th USENIX Security Symposium, Colorado (2000)"}],"container-title":["Journal in Computer Virology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-011-0156-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-011-0156-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-011-0156-6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,18]],"date-time":"2019-06-18T08:27:03Z","timestamp":1560846423000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-011-0156-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,10,22]]},"references-count":28,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2011,11]]}},"alternative-id":["156"],"URL":"https:\/\/doi.org\/10.1007\/s11416-011-0156-6","relation":{},"ISSN":["1772-9890","1772-9904"],"issn-type":[{"value":"1772-9890","type":"print"},{"value":"1772-9904","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,10,22]]}}}