{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T16:25:36Z","timestamp":1771604736854,"version":"3.50.1"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2014,5,23]],"date-time":"2014-05-23T00:00:00Z","timestamp":1400803200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2015,5]]},"DOI":"10.1007\/s11416-014-0215-x","type":"journal-article","created":{"date-parts":[[2014,5,22]],"date-time":"2014-05-22T16:21:26Z","timestamp":1400775686000},"page":"59-73","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":83,"title":["Hidden Markov models for malware classification"],"prefix":"10.1007","volume":"11","author":[{"given":"Chinmayee","family":"Annachhatre","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas H.","family":"Austin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Stamp","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,5,23]]},"reference":[{"key":"215_CR1","unstructured":"Annachhatre, C.: Hidden Markov models for malware classification. Department of Computer Science, San Jose State University, Master\u2019s report (2013)"},{"issue":"2","key":"215_CR2","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/s11416-008-0105-1","volume":"5","author":"S Attaluri","year":"2009","unstructured":"Attaluri, S., McGhee, S., Stamp, M.: Profile hidden Markov models and metamorphic virus detection. J. Comput. Virol. 5(2), 151\u2013169 (2009)","journal-title":"J. Comput. Virol."},{"key":"215_CR3","doi-asserted-by":"crossref","unstructured":"Austin, T., Filiol, E., Josse, S., Stamp, M.: Exploring hidden Markov models for virus analysis: a semantic approach. In: 46th Hawaii International Conference on System Sciences (HICSS 46), pp. 5039\u20135048 (2013)","DOI":"10.1109\/HICSS.2013.217"},{"issue":"4","key":"215_CR4","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1007\/s11416-013-0185-4","volume":"9","author":"D Baysa","year":"2013","unstructured":"Baysa, D., Low, R.M., Stamp, M.: Structural entropy and metamorphic malware. J. Comput. Virol. Hacking Tech. 9(4), 179\u2013192 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"215_CR5","doi-asserted-by":"crossref","unstructured":"Bradley, A.P.: The use of the area under the ROC curve in the evaluation of machine learning algorithms. Pattern Recognit. 30, 1145\u20131159 (1997)","DOI":"10.1016\/S0031-3203(96)00142-2"},{"key":"215_CR6","doi-asserted-by":"crossref","unstructured":"Canzanese, R., Kam, M., Mancoridis, S.: Toward an automatic, online behavioral malware classification system. https:\/\/www.cs.drexel.edu\/~spiros\/papers\/saso2013.pdf (2013)","DOI":"10.1109\/SASO.2013.8"},{"key":"215_CR7","unstructured":"Cesare, S., Xiang, Y.: Classification of Malware using structured control flow. In: 8th Australasian Symposium on Parallel and Distributed Computing, vol. 107, pp. 61\u201370 (2010)"},{"key":"215_CR8","doi-asserted-by":"crossref","unstructured":"Do, C.B., Batzoglou, S.: What is the expectation maximization algorithm? Nat. Biotechnol. 26(8), 897\u2013899. http:\/\/ai.stanford.edu\/~chuongdo\/papers\/em_tutorial.pdf (2008)","DOI":"10.1038\/nbt1406"},{"key":"215_CR9","unstructured":"Indika: Difference between hierarchical and partitional clustering. http:\/\/www.differencebetween.com\/difference-between-hierarchical-and-vs-partitional-clustering (2011)"},{"key":"215_CR10","volume-title":"Algorithms for Clustering Data","author":"A Jain","year":"1988","unstructured":"Jain, A., Dubes, R.: Algorithms for Clustering Data. Prentice Hall, Englewood Cliffs (1988)"},{"key":"215_CR11","unstructured":"Jin, R.: Cluster validation. http:\/\/www.cs.kent.edu\/~jin\/DM08\/ClusterValidation.pdf (2008)"},{"issue":"1","key":"215_CR12","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1108\/eb026526","volume":"28","author":"K Jones","year":"1972","unstructured":"Jones, K.: A statistical interpretation of term specificity and its application in retrieval. J. Doc. 28(1), 11\u201321 (1972)","journal-title":"J. Doc."},{"key":"215_CR13","first-page":"2721","volume":"7","author":"S Kolter","year":"2006","unstructured":"Kolter, S., Maloof, M.: Learning to detect and classify malicious executables in the wild. J. Mach. Learn. Res. 7, 2721\u20132744 (2006)","journal-title":"J. Mach. Learn. Res."},{"key":"215_CR14","volume-title":"An Introduction to Hidden Markov Models for Biological Sequences. Computational Methods in Molecular Biology","author":"A Krogh","year":"1998","unstructured":"Krogh, A.: An Introduction to Hidden Markov Models for Biological Sequences. Computational Methods in Molecular Biology. Elsevier, Lyngby (1998)"},{"issue":"5","key":"215_CR15","doi-asserted-by":"crossref","first-page":"1501","DOI":"10.1006\/jmbi.1994.1104","volume":"235","author":"A Krogh","year":"1994","unstructured":"Krogh, A., et al.: Hidden Markov models in computational biology: applications to protein modeling. J. Mol. Biol. 235(5), 1501\u20131531 (1994)","journal-title":"J. Mol. Biol."},{"issue":"3","key":"215_CR16","first-page":"109","volume":"9","author":"A Lakhotia","year":"2013","unstructured":"Lakhotia, A., Walenstein, A., Miles, C., Singh, A.: VILO: a rapid learning nearest-neighbor classifier for malware triage. J. Comput. Virol. 9(3), 109\u2013123 (2013)","journal-title":"J. Comput. Virol."},{"key":"215_CR17","unstructured":"MacQueen, J.: Some methods for classification and analysis of multivariate observations. In: Proceedings of 5th Berkeley Symposium on Mathematical Statistics and Probability, pp. 281\u2013297 (1967)"},{"key":"215_CR18","doi-asserted-by":"crossref","DOI":"10.1007\/1-84628-253-5","volume-title":"Machine Learning and Data Mining for Computer Security: Methods and Applications","author":"MA Maloof","year":"2006","unstructured":"Maloof, M.A.: Machine Learning and Data Mining for Computer Security: Methods and Applications. Springer, Berlin (2006)"},{"issue":"1","key":"215_CR19","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1007\/s11416-012-0175-y","volume":"9","author":"X Ming","year":"2013","unstructured":"Ming, X., et al.: A similarity metric method of obfuscated malware using function-call graph. J. Comput. Virol. Hacking Tech. 9(1), 35\u201347 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"215_CR20","unstructured":"MITRE: Malware attribute enumeration and characterization. http:\/\/maec.mitre.org (2013)"},{"key":"215_CR21","unstructured":"Moore, A.W.: $$K$$ K -Means and hierarchical clustering. http:\/\/www.autonlab.org\/tutorials\/kmeans11.pdf (2001)"},{"key":"215_CR22","doi-asserted-by":"crossref","unstructured":"Nappa, A., Zubair Rafique, M., Caballero, J.: Driving in the cloud: an analysis of drive-by download operations and abuse reporting of viruses. In: Proceedings of the 10th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (2013)","DOI":"10.1007\/978-3-642-39235-1_1"},{"issue":"B","key":"215_CR23","doi-asserted-by":"crossref","first-page":"419","DOI":"10.1016\/j.cose.2013.09.006","volume":"39","author":"Y Park","year":"2013","unstructured":"Park, Y., Reeves, D.S., Stamp, M.: Deriving common malware behavior through graph clustering. Comput. Secur. 39(B), 419\u2013430 (2013)","journal-title":"Comput. Secur."},{"issue":"2","key":"215_CR24","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1109\/5.18626","volume":"77","author":"L Rabiner","year":"1989","unstructured":"Rabiner, L.: A tutorial on hidden Markov models and selected applications in speech recognition. Proc. IEEE 77(2), 257\u2013286 (1989)","journal-title":"Proc. IEEE"},{"key":"215_CR25","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1007\/s11416-012-0160-5","volume":"8","author":"N Runwal","year":"2012","unstructured":"Runwal, N., Low, R., Stamp, M.: Opcode graph similarity and metamorphic detection. J. Comput. Virol. 8, 37\u201352 (2012)","journal-title":"J. Comput. Virol."},{"issue":"4","key":"215_CR26","doi-asserted-by":"crossref","first-page":"191","DOI":"10.1049\/iet-ifs.2010.0136","volume":"5","author":"M Saleh","year":"2011","unstructured":"Saleh, M., Mohamed, A., Nabi, A.: Eigenviruses for metamorphic virus recognition. IET Inf. Secur. 5(4), 191\u2013198 (2011)","journal-title":"IET Inf. Secur."},{"key":"215_CR27","unstructured":"Skulason, F., Solomon, A., Bontchev, V.: CARO naming scheme. http:\/\/www.caro.org\/naming\/scheme.html (1991)"},{"issue":"4","key":"215_CR28","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1007\/s11416-011-0153-9","volume":"7","author":"I Sorokin","year":"2011","unstructured":"Sorokin, I.: Comparing files using structural entropy. J. Comput. Virol. 7(4), 259\u2013265 (2011)","journal-title":"J. Comput. Virol."},{"issue":"2","key":"215_CR29","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1007\/s11416-012-0174-z","volume":"9","author":"SM Sridhara","year":"2013","unstructured":"Sridhara, S.M., Stamp, M.: Metamorphic worm that carries its own morphing engine. J. Comput. Virol. Hacking Tech. 9(2), 49\u201358 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"215_CR30","unstructured":"Stamp, M.: A revealing introduction to hidden Markov models. http:\/\/www.cs.sjsu.edu\/faculty\/stamp\/RUA\/HMM.pdf (2012)"},{"key":"215_CR31","doi-asserted-by":"crossref","unstructured":"Swimmer, M.: Response to the proposal for a \u201cC virus\u201d database. ACM SIGSAC Review, vol. 8, pp. 1\u20135. http:\/\/www.odysci.com\/article\/1010112993890087 (1990)","DOI":"10.1145\/382097.382099"},{"key":"215_CR32","unstructured":"Symantec: Trojan.Zbot. http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2010-011016-3514-99 (2010)"},{"key":"215_CR33","unstructured":"Symantec Security Response: Trojan.Zeroaccess. http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2011-071314-0410-99 (2011)"},{"key":"215_CR34","unstructured":"Virus Removal Services: Beware of FAKE antivirus\u2014Winwebsec. http:\/\/virus.myfirstattempt.com\/2012\/11\/beware-of-fake-anti-virus-winwebsec.html (2012)"},{"key":"215_CR35","unstructured":"VX Heavens. http:\/\/vx.netlux.org\/ (2013)"},{"issue":"3","key":"215_CR36","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11416-006-0028-7","volume":"2","author":"W Wong","year":"2006","unstructured":"Wong, W., Stamp, M.: Hunting for metamorphic engines. J. Comput. Virol. 2(3), 211\u2013229 (2006)","journal-title":"J. Comput. Virol."}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0215-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-014-0215-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0215-x","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,10]],"date-time":"2019-08-10T15:16:39Z","timestamp":1565450199000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-014-0215-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,5,23]]},"references-count":36,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,5]]}},"alternative-id":["215"],"URL":"https:\/\/doi.org\/10.1007\/s11416-014-0215-x","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,5,23]]}}}