{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T13:46:11Z","timestamp":1773409571396,"version":"3.50.1"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2014,11,30]],"date-time":"2014-11-30T00:00:00Z","timestamp":1417305600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2015,5]]},"DOI":"10.1007\/s11416-014-0232-9","type":"journal-article","created":{"date-parts":[[2014,12,2]],"date-time":"2014-12-02T14:08:22Z","timestamp":1417529302000},"page":"103-118","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Dueling hidden Markov models for virus analysis"],"prefix":"10.1007","volume":"11","author":[{"given":"Ashwin","family":"Kalbhor","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas H.","family":"Austin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Filiol","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S\u00e9bastien","family":"Josse","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Stamp","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,11,30]]},"reference":[{"key":"232_CR1","doi-asserted-by":"publisher","unstructured":"Annachhatre, C., Austin, T.H., Stamp, M.: Hidden markov models for malware classification. J. Comput. Virol. Hack. Tech. pp. 1\u201315 (2014). doi: 10.1007\/s11416-014-0215-x","DOI":"10.1007\/s11416-014-0215-x"},{"key":"232_CR2","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s11416-008-0105-1","volume":"5","author":"S Attaluri","year":"2009","unstructured":"Attaluri, S., McGhee, S., Stamp, M.: Profile hidden markov models and metamorphic virus detection. J. Comput. Virol. 5, 151\u2013169 (2009). doi: 10.1007\/s11416-008-0105-1","journal-title":"J. Comput. Virol."},{"key":"232_CR3","doi-asserted-by":"crossref","unstructured":"Austin, T.H., Filiol, E., Josse, S., Stamp, M.: Exploring hidden markov models for virus analysis: a semantic approach. In: IEEE HICSS, pp. 5039\u20135048 (2013)","DOI":"10.1109\/HICSS.2013.217"},{"key":"232_CR4","doi-asserted-by":"crossref","unstructured":"Bruschi, D., Martignoni, L., Monga, M.: Detecting self-mutating malware using control-flow graph matching. In: DIMVA (2006)","DOI":"10.1007\/11790754_8"},{"key":"232_CR5","unstructured":"Cave, R.L., Neuwirth, L.P.: Hidden markov models for english. In: Ferguson, J.D. (ed) Hidden Markov Models for Speech (1980)"},{"key":"232_CR6","doi-asserted-by":"publisher","unstructured":"Chen, S.F., Goodman, J.: An empirical study of smoothing techniques for language modeling. In: Association for computational linguistics (1996). doi: 10.3115\/981863.981904","DOI":"10.3115\/981863.981904"},{"key":"232_CR7","unstructured":"Chess, D.M., White, S.R.: An undetectable computer virus. In: Virus bulletin conference (2000)"},{"key":"232_CR8","doi-asserted-by":"crossref","unstructured":"Cho, S.B., Han, S.J.: Two sophisticated techniques to improve hmm-based intrusion detection systems. In: RAID (2003)","DOI":"10.1007\/978-3-540-45248-5_12"},{"key":"232_CR9","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S.: Testing malware detectors. In: ISSTA (2004)","DOI":"10.1145\/1007512.1007518"},{"key":"232_CR10","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S.A., Song, D.X., Bryant, R.E.: Semantics-aware malware detection. In: Symposium on security and privacy (2005)","DOI":"10.1109\/SP.2005.20"},{"key":"232_CR11","unstructured":"Clang: a C language family frontend for LLVM. http:\/\/www.clang.llvm.org . Accessed November 2011"},{"key":"232_CR12","unstructured":"Driller, T.M.: Metamorphic permutating high-obfuscating reassembler source. http:\/\/vx.netlux.org\/29a\/29a-6\/29a-6.602 . Accessed December 2011"},{"key":"232_CR13","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/s11416-007-0041-5","volume":"3","author":"E Filiol","year":"2007","unstructured":"Filiol, E., Josse, S.: A statistical model for undecidable viral detection. J. Comput. Virol. 3, 64\u201374 (2007). doi: 10.1007\/s11416-007-0041-5","journal-title":"J. Comput. Virol."},{"key":"232_CR14","doi-asserted-by":"crossref","unstructured":"Filiol, E., Josse, S.: Malware spectral analysis: security evaluation of Bayesian network based detection models. In: EICAR conference (2011)","DOI":"10.1109\/HICSS.2012.450"},{"key":"232_CR15","unstructured":"Francois, J.M.: JAHMM: An implementation of hidden Markov models in Java. http:\/\/code.google.com\/p\/jahmm\/ . Accessed October 2011"},{"key":"232_CR16","unstructured":"GCC, the GNU compiler collection. http:\/\/gcc.gnu.org\/ . Accessed November 2011"},{"key":"232_CR17","unstructured":"Iliopoulos, D., Adami, C., Szor, P.: Darwin inside the machines: malware evolution and the consequences for computer security. CoRR abs\/1111.2503 (2011)"},{"key":"232_CR18","unstructured":"Intersimone, D.: Antique software: Turbo C version 2.01. http:\/\/edn.embarcadero.com\/article\/20841 . Accessed November 2011"},{"key":"232_CR19","doi-asserted-by":"crossref","unstructured":"Kr\u00fcgel, C., Kirda, E., Mutz, D., Robertson, W.K., Vigna, G.: Polymorphic worm detection using structural information of executables. In: RAID (2005)","DOI":"10.1007\/11663812_11"},{"key":"232_CR20","doi-asserted-by":"crossref","unstructured":"Leder, F., Steinbock, B., Martini, P.: Classification and detection of metamorphic malware using value set analysis. In: International conference on malicious and unwanted software MALWARE (2009)","DOI":"10.1109\/MALWARE.2009.5403019"},{"issue":"3","key":"232_CR21","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/s11416-010-0148-y","volume":"7","author":"D Lin","year":"2011","unstructured":"Lin, D., Stamp, M.: Hunting for undetectable metamorphic viruses. J. Comput. Virol. 7(3), 201\u2013214 (2011)","journal-title":"J. Comput. Virol."},{"key":"232_CR22","doi-asserted-by":"publisher","unstructured":"Madenur Sridhara, S., Stamp, M.: Metamorphic worm that carries its own morphing engine. J. Comput. Virol. 9(2), 49\u201358 (2013). doi: 10.1007\/s11416-012-0174-z","DOI":"10.1007\/s11416-012-0174-z"},{"key":"232_CR23","unstructured":"MinGW | the minimalist GNU for Windows. http:\/\/www.mingw.org\/ . Accessed November 2011"},{"key":"232_CR24","unstructured":"Mohammed, M.: Zeroing in on metaphoric computer viruses. Master\u2019s thesis, University of Louisiana at Lafayette (2003)"},{"key":"232_CR25","unstructured":"SnakeByte: next generation virus construktion kit. http:\/\/vxheavens.com\/vx.php?id=tn02 . Accessed December 2011"},{"issue":"2","key":"232_CR26","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1007\/s10994-009-5143-5","volume":"81","author":"Y Song","year":"2010","unstructured":"Song, Y., Locasto, M.E., Stavrou, A., Keromytis, A.D., Stolfo, S.J.: On the infeasibility of modeling polymorphic shellcode\u2014re-thinking the role of learning in intrusion detection systems. Mach. Learn. 81(2), 179\u2013205 (2010)","journal-title":"Mach. Learn."},{"key":"232_CR27","unstructured":"Stamp, M.: A revealing introduction to hidden Markov models (2004). http:\/\/www.cs.sjsu.edu\/faculty\/stamp\/RUA\/HMM.pdf . Accessed October 2011"},{"key":"232_CR28","unstructured":"Symantec security response: W32.simile. http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2002-030617-5423-99 . Accessed December 2011"},{"key":"232_CR29","volume-title":"The Art of Computer Virus Research and Defense","author":"P Szor","year":"2005","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Addison Wesley, Boston (2005)"},{"issue":"3","key":"232_CR30","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11416-006-0028-7","volume":"2","author":"W Wong","year":"2006","unstructured":"Wong, W., Stamp, M.: Hunting for metamorphic engines. J. Comput. Virol. 2(3), 211\u2013229 (2006)","journal-title":"J. Comput. Virol."},{"key":"232_CR31","doi-asserted-by":"crossref","unstructured":"Zhang, Q., Reeves, D.S.: Metaaware: identifying metamorphic malware. In: ACSAC (2007)","DOI":"10.1109\/ACSAC.2007.9"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0232-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-014-0232-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0232-9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,18]],"date-time":"2019-08-18T01:59:56Z","timestamp":1566093596000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-014-0232-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,11,30]]},"references-count":31,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,5]]}},"alternative-id":["232"],"URL":"https:\/\/doi.org\/10.1007\/s11416-014-0232-9","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,11,30]]}}}