{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T00:34:42Z","timestamp":1785285282930,"version":"3.55.0"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2014,8,8]],"date-time":"2014-08-08T00:00:00Z","timestamp":1407456000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2015,5]]},"DOI":"10.1007\/s11416-014-0222-y","type":"journal-article","created":{"date-parts":[[2014,8,7]],"date-time":"2014-08-07T13:22:30Z","timestamp":1407417750000},"page":"75-88","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Sliding window and control flow weight for metamorphic malware detection"],"prefix":"10.1007","volume":"11","author":[{"given":"Shahid","family":"Alam","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ibrahim","family":"Sogukpinar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Issa","family":"Traore","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"R.","family":"Nigel Horspool","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2014,8,8]]},"reference":[{"key":"222_CR1","volume-title":"Compilers: Principles, Techniques, and Tools","author":"AV Aho","year":"2006","unstructured":"Aho, A.V., Lam, M.S., Sethi, R., Ullman, J.D.: Compilers: Principles, Techniques, and Tools, 2nd edn. Addison-Wesley Longman Publishing Co. Inc, Boston (2006)","edition":"2"},{"key":"222_CR2","doi-asserted-by":"crossref","unstructured":"Alam, S., Nigel Horspool, R., Traore, I.: MAIL: malware analysis intermediate language\u2014a step towards automating and optimizing malware detection. In: Security of Information and Networks, SIN \u201913, New York, NY, USA, November 2013. ACM SIGSAC (2013)","DOI":"10.1145\/2523514.2527006"},{"key":"222_CR3","doi-asserted-by":"crossref","unstructured":"Alam, S., Nigel Horspool, R.,Traore, I.: MARD: A framework for metamorphic malware analysis and real-time detection. In: Advanced Information Networking and Applications, Research Track\u2014Security and Privacy, AINA \u201914, Washington, DC, USA, May 2014. IEEE Computer Society, New York (2014)","DOI":"10.1109\/AINA.2014.59"},{"key":"222_CR4","doi-asserted-by":"crossref","unstructured":"Austin, T.H., Filiol, E., Josse, S., Stamp, M.: Exploring hidden Markov models for virus analysis: a semantic approach. In: 46th Hawaii International Conference on System Sciences (HICSS), 2013, pp. 5039\u20135048 (2013)","DOI":"10.1109\/HICSS.2013.217"},{"issue":"4","key":"222_CR5","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1007\/s11416-013-0185-4","volume":"9","author":"D Baysa","year":"2013","unstructured":"Baysa, D., Low, R.M., Stamp, M.: Structural entropy and metamorphic malware. J. Comput. Virol. Hacking Tech. 9(4), 179\u2013192 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"222_CR6","doi-asserted-by":"crossref","unstructured":"Bilar, D.: Opcodes as predictor for malware. Int. J. Electron. Secur. Digit. Forensics 1(2), 156\u2013168 (January 2007)","DOI":"10.1504\/IJESDF.2007.016865"},{"key":"222_CR7","doi-asserted-by":"crossref","unstructured":"Bruschi, D., Martignoni, L., Monga, M.: Detecting self-mutating malware using control-flow graph matching. In: DIMVA, 2006, pp. 129\u2013143. Springer, Berlin (2006)","DOI":"10.1007\/11790754_8"},{"key":"222_CR8","volume-title":"Introduction to Algorithms","author":"TH Cormen","year":"2009","unstructured":"Cormen, T.H., Leiserson, C.E., Rivest, R.L., Stein, C.: Introduction to Algorithms, 3rd edn. The MIT Press, Cambridge (2009)","edition":"3"},{"key":"222_CR9","doi-asserted-by":"crossref","unstructured":"Daubechies, I.: Ten lectures on wavelets. SIAM 61, 1\u2013357 (1992)","DOI":"10.1137\/1.9781611970104"},{"issue":"1","key":"222_CR10","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1007\/s11416-013-0193-4","volume":"10","author":"S Deshpande","year":"2014","unstructured":"Deshpande, S., Park, Y., Stamp, M.: Eigenvalue analysis for metamorphic detection. J. Comput. Virol. Hacking Tech. 10(1), 53\u201365 (2014)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"222_CR11","volume-title":"The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler","author":"C Eagle","year":"2008","unstructured":"Eagle, C.: The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler. No Starch Press, San Francisco (2008)"},{"key":"222_CR12","doi-asserted-by":"crossref","unstructured":"Faruki, P., Laxmi, V., Gaur, M.S., Vinod, P.: Mining control flow graph as API call-grams to detect portable executable malware. In Security of Information and Networks, SIN \u201912, New York, NY, USA, 2012. ACM SIGSAC (2012)","DOI":"10.1145\/2388576.2388594"},{"issue":"1","key":"222_CR13","first-page":"70","volume":"2","author":"E Filiol","year":"2007","unstructured":"Filiol, E.: Metamorphism, formal grammars and undecidable code mutation. Int. J. Comput. Sci. 2(1), 70\u201375 (2007)","journal-title":"Int. J. Comput. Sci."},{"key":"222_CR14","unstructured":"Flake, H.: Structural comparison of executable objects. In: Flegel, U., Meier, M. (eds.) DIMVA. LNI, vol. 46, pp. 161\u2013173. GI (2004)"},{"key":"222_CR15","unstructured":"G2.: Second Generation Virus Generator. http:\/\/vxheaven.org\/vx.php?id=tg00 . Accessed 28 July 2014"},{"key":"222_CR16","doi-asserted-by":"crossref","unstructured":"Ghiasi, M., Sami, A., Salehi, Z.: Dynamic malware detection using registers values set analysis. In: Information Security and Cryptology, pp. 54\u201359 (2012)","DOI":"10.1109\/ISCISC.2012.6408191"},{"key":"222_CR17","unstructured":"Guo, H., Pang, J., Zhang, Y., Yue, F., Zhao, R.: Hero: a novel malware detection framework based on binary translation. In: ICIS, 2010, vol. 1, pp. 411\u2013415 (2010)"},{"issue":"3","key":"222_CR18","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1080\/0161-119591883944","volume":"19","author":"T Jakobsen","year":"1995","unstructured":"Jakobsen, T.: A fast method for cryptanalysis of substitution ciphers. Cryptologia 19(3), 265\u2013274 (1995)","journal-title":"Cryptologia"},{"key":"222_CR19","doi-asserted-by":"crossref","unstructured":"Sparck Jones, K.: A statistical interpretation of term specificity and its application in retrieval. J. Documentation 28, 11\u201321 (1972)","DOI":"10.1108\/eb026526"},{"key":"222_CR20","unstructured":"Kirda, E., Kruegel, C., Banks, G., Vigna, G., Kemmerer R.A.: Behavior-based spyware detection. In: Proceedings of the 15th Conference on USENIX Security Symposium, vol. 15, USENIX-SS\u201906, Berkeley, CA, USA, 2006. USENIX Association (2006)"},{"key":"222_CR21","doi-asserted-by":"crossref","unstructured":"Kruskal, J.B.: Multidimensional scaling by optimizing goodness of fit to a nonmetric hypothesis. Psychometrika 29, 1\u201327 (1964)","DOI":"10.1007\/BF02289565"},{"key":"222_CR22","doi-asserted-by":"crossref","unstructured":"Kuzurin, N., Shokurov, A., Varnovsky, N., Zakharov, V.: On the Concept of software obfuscation in computer security. In: Proceedings of the 10th International Conference on Information Security, ISC\u201907, pp. 281\u2013298. Springer, Berlin (2007)","DOI":"10.1007\/978-3-540-75496-1_19"},{"issue":"3","key":"222_CR23","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/s11416-010-0148-y","volume":"7","author":"D Lin","year":"2011","unstructured":"Lin, D., Stamp, M.: Hunting for undetectable metamorphic viruses. J. Comput. Virol. 7(3), 201\u2013214 (2011)","journal-title":"J. Comput. Virol."},{"key":"222_CR24","doi-asserted-by":"crossref","unstructured":"Linn, C., Debray, S.: Obfuscation of executable code to improve resistance to static disassembly. In: ACM CCS, pp. 290\u2013299. ACM, New York (2003)","DOI":"10.1145\/948109.948149"},{"key":"222_CR25","doi-asserted-by":"crossref","unstructured":"Sridhara, S.M., Stamp, M.: Metamorphic worm that carries its own morphing engine. J. Comput. Virol. Hacking Tech. 9(2), 49\u201358 (2013)","DOI":"10.1007\/s11416-012-0174-z"},{"key":"222_CR26","unstructured":"NGVCK: Next Generation Virus Construction Kit. http:\/\/vxheaven.org\/vx.php?id=tn02 . Accessed 28 July 2014"},{"key":"222_CR27","doi-asserted-by":"crossref","unstructured":"OKane, P., Sezer, S., McLaughlin, K.: Obfuscation: the hidden malware. IEEE Secur. Privacy 9(5), 41\u201347 (September 2011)","DOI":"10.1109\/MSP.2011.98"},{"key":"222_CR28","doi-asserted-by":"crossref","unstructured":"Rad, B.B., Masrom, M., Ibrahim, S.: Opcodes histogram for classifying metamorphic portable executables malware. In: ICEEE, pp. 209\u2013213 (2012)","DOI":"10.1109\/ICeLeTE.2012.6333411"},{"key":"222_CR29","doi-asserted-by":"crossref","unstructured":"Robertson, S.: Understanding inverse document frequency: on theoretical arguments for idf. J. Documentation 60 (2004)","DOI":"10.1108\/00220410410560582"},{"key":"222_CR30","doi-asserted-by":"crossref","unstructured":"Runwal, N., Low, R.M., Stamp, M.: Opcode graph similarity and metamorphic detection. J. Comput. Virol. 8(1\u20132), 37\u201352 (May 2012)","DOI":"10.1007\/s11416-012-0160-5"},{"key":"222_CR31","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.ins.2011.08.020","volume":"231","author":"I Santos","year":"2013","unstructured":"Santos, I., Brezo, F., Ugarte-Pedrero, X., Bringas, P.G.: Opcode sequences as representation of executables for data-mining-based unknown malware detection. Inf. Sci. 231, 64\u201382 (2013). Data Mining for Information Security","journal-title":"Inf. Sci."},{"issue":"1","key":"222_CR32","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/2190-8532-1-1","volume":"1","author":"A Shabtai","year":"2012","unstructured":"Shabtai, A., Moskovitch, R., Feher, C., Dolev, S., Elovici, Y.: Detecting unknown malicious code by applying classification techniques on opcode patterns. Secur Inform 1(1), 1\u201322 (2012)","journal-title":"Secur Inform"},{"key":"222_CR33","doi-asserted-by":"crossref","unstructured":"Shanmugam, G., Low, R.M., Stamp, M.: Simple substitution distance and metamorphic detection. J. Comput. Virol. Hacking Tech. 9(3), 159\u2013170 (2013)","DOI":"10.1007\/s11416-013-0184-5"},{"key":"222_CR34","doi-asserted-by":"crossref","unstructured":"Song, F., Touili, T.: Efficient malware detection using model-checking. In: Giannakopoulou, D., Mery, D. (eds.) FM: Formal Methods. Lecture Notes in Computer Science, vol. 7436, pp. 418\u2013433. Springer, Berlin (2012)","DOI":"10.1007\/978-3-642-32759-9_34"},{"issue":"4","key":"222_CR35","doi-asserted-by":"crossref","first-page":"259","DOI":"10.1007\/s11416-011-0153-9","volume":"7","author":"I Sorokin","year":"2011","unstructured":"Sorokin, I.: Comparing files using structural entropy. J. Comput. Virol. 7(4), 259\u2013265 (2011)","journal-title":"J. Comput. Virol."},{"key":"222_CR36","doi-asserted-by":"crossref","unstructured":"Toderici, A.H., Stamp, M.: Chi-squared distance and metamorphic virus detection. J. Comput. Virol. 9, 1\u201314 (2013)","DOI":"10.1007\/s11416-012-0171-2"},{"key":"222_CR37","doi-asserted-by":"crossref","unstructured":"Vinod, P., Laxmi, V., Gaur, M.S., Chauhan G.: MOMENTUM: metamorphic malware exploration techniques using MSA signatures. In: IIT, pp. 232\u2013237 (2012)","DOI":"10.1109\/INNOVATIONS.2012.6207739"},{"key":"222_CR38","unstructured":"Weisstein, E.W.: Chi-squared test. In: MathWorld\u2014A Wolfram Web Resource. Wolfram Research Inc. http:\/\/mathworld.wolfram.com\/Chi-SquaredTest.html . Accessed 28 July 2014"},{"key":"222_CR39","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11416-006-0028-7","volume":"2","author":"W Wong","year":"2006","unstructured":"Wong, W., Stamp, M.: Hunting for metamorphic engines. J. Comput. Virol. 2, 211\u2013229 (2006)","journal-title":"J. Comput. Virol."},{"key":"222_CR40","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D.: Privacy-breaching behavior analysis. In: Automatic Malware Analysis, Springer Briefs in Computer Science, pp. 27\u201342. Springer, New York (2013)","DOI":"10.1007\/978-1-4614-5523-3_4"},{"issue":"8","key":"222_CR41","doi-asserted-by":"crossref","first-page":"2962","DOI":"10.1109\/TIT.2005.851780","volume":"51","author":"Z Zuo","year":"2005","unstructured":"Zuo, Z., Zhu, Q., Zhou, M.: On the time complexity of computer viruses. IEEE Trans. Inf. Theor. 51(8), 2962\u20132966 (2005)","journal-title":"IEEE Trans. Inf. Theor."}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0222-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-014-0222-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0222-y","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,13]],"date-time":"2019-08-13T17:17:06Z","timestamp":1565716626000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-014-0222-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,8,8]]},"references-count":41,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,5]]}},"alternative-id":["222"],"URL":"https:\/\/doi.org\/10.1007\/s11416-014-0222-y","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,8,8]]}}}