{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T00:22:52Z","timestamp":1772065372995,"version":"3.50.1"},"reference-count":111,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2015,7,29]],"date-time":"2015-07-29T00:00:00Z","timestamp":1438128000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2016,5]]},"DOI":"10.1007\/s11416-015-0247-x","type":"journal-article","created":{"date-parts":[[2015,7,28]],"date-time":"2015-07-28T02:44:54Z","timestamp":1438051494000},"page":"69-100","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":45,"title":["Network malware classification comparison using DPI and flow packet headers"],"prefix":"10.1007","volume":"12","author":[{"given":"Amine","family":"Boukhtouta","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Serguei A.","family":"Mokhov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nour-Eddine","family":"Lakhdari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joey","family":"Paquet","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,7,29]]},"reference":[{"key":"247_CR1","unstructured":"Abdelnour, A.F., Selesnick, I.W.: Nearly symmetric orthogonal wavelet bases. In: Proceedings of the IEEE International Conference on Acoustics, Speech, Signal Processing (ICASSP) (2001a)"},{"key":"247_CR2","doi-asserted-by":"crossref","unstructured":"Aggarwal, C.C., Gates, S.C., Yu, P.S.: On the merits of building categorization systems by supervised clustering. In: KDD, KDD\u201999, pp. 352\u2013356. ACM, New York, NY (1999)","DOI":"10.1145\/312129.312279"},{"key":"247_CR3","doi-asserted-by":"crossref","unstructured":"Alshammari, R.A., Zincir-Heywood, A.N.: Investigating two different approaches for encrypted traffic classification. In: Proceedings of the Sixth Annual Conference on Privacy, Security and Trust (PST\u201908), pp. 156\u2013166. IEEE Computer Society, Washington, DC (2008)","DOI":"10.1109\/PST.2008.15"},{"key":"247_CR4","doi-asserted-by":"crossref","unstructured":"Alshammari, R.A., Zincir-Heywood, A.N.: Machine learning based encrypted traffic classification: Identifying SSH and Skype. In: Proceedings of the IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA 2009), pp. 1\u20138. IEEE (2009)","DOI":"10.1109\/CISDA.2009.5356534"},{"key":"247_CR5","unstructured":"Alshammari, R.A.: Automatically generating robust signatures using a machine learning approach to unveil encrypted VOIP traffic without using port numbers, IP addresses and payload inspection. Ph.D. thesis, Dalhousie University, Halifax, Nova Scotia (2012)"},{"key":"247_CR6","unstructured":"Bailey, M., Oberheide, J., Andersen, J., Mao, Z.M., Jahanian, F., Nazario, J.: Automated classification and analysis of Internet malware. Tech. rep., University of Michigan (2007). http:\/\/www.eecs.umich.edu\/techreports\/cse\/2007\/CSE-TR-530-07.pdf"},{"key":"247_CR7","unstructured":"Bayer, U., Comparetti, P.M., Hlauschek, C., Kruegel, C., Kirda, E.: Scalable, behavior-based malware clustering. In: NDSS, vol.\u00a09 (2009)"},{"key":"247_CR8","unstructured":"Binkley, J.R., Singh, S.: An algorithm for anomaly-based botnet detection. In: Proceedings of the 2nd conference on Steps to Reducing Unwanted Traffic on the Internet, no. 2 in SRUTI, pp. 1\u20137. USENIX Association, Berkeley, CA (2006)"},{"key":"247_CR9","unstructured":"Bloedorn, E., Christiansen, A.D., Hill, W., Skorupka, C., Talbot, L.M., Tivel, J.: Data mining for network intrusion detection: How to get started. Tech. rep., The MITRE Corporation (2001). http:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.102.8556&rep=rep1&type=pdf"},{"key":"247_CR10","doi-asserted-by":"crossref","unstructured":"Boggs, N., Hiremagalore, S., Stavrou, A., Stolfo, S.J.: Cross-domain collaborative anomaly detection: so far yet so close. In: Recent Advances in Intrusion Detection, pp. 142\u2013160. Springer, Berlin (2011)","DOI":"10.1007\/978-3-642-23644-0_8"},{"key":"247_CR11","doi-asserted-by":"publisher","unstructured":"Boukhtouta, A., Lakhdari, N.E., Mokhov, S.A., Debbabi, M.: Towards fingerprinting malicious traffic. In: Proceedings of ANT\u201913, vol.\u00a019, pp. 548\u2013555. Elsevier, Amsterdam (2013). doi: 10.1016\/j.procs.2013.06.073","DOI":"10.1016\/j.procs.2013.06.073"},{"key":"247_CR12","doi-asserted-by":"publisher","unstructured":"Bozorgi, M., Saul, L.K., Savage, S., Voelker, G.M.: Beyond heuristics: Learning to classify vulnerabilities and predict exploits. In: Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD\u201910, pp. 105\u2013114. ACM, New York, NY (2010). doi: 10.1145\/1835804.1835821","DOI":"10.1145\/1835804.1835821"},{"key":"247_CR13","doi-asserted-by":"crossref","unstructured":"Chang, S., Daniels, T.E.: P2P botnet detection using behavior clustering & statistical tests. In: Proceedings of the 2nd ACM Workshop on Security and Artificial Intelligence. AISec, pp. 23\u201330. ACM, New York, NY (2009)","DOI":"10.1145\/1654988.1654996"},{"key":"247_CR14","unstructured":"CrySyS Lab: sKyWIper (a.k.a. Flame a.k.a. Flamer): A complex malware for targeted attacks. Tech. rep., Budapest University of Technology and Economics: Department of Telecommunications, Budapest, Hungary (2012). http:\/\/www.crysys.hu\/skywiper\/skywiper.pdf"},{"key":"247_CR15","first-page":"1265","volume":"3","author":"IS Dhillon","year":"2003","unstructured":"Dhillon, I.S., Mallela, S., Kumar, R.: A divisive information theoretic feature clustering algorithm for text classification. J. Mach. Learn. Res. 3, 1265\u20131287 (2003)","journal-title":"J. Mach. Learn. Res."},{"issue":"2","key":"247_CR16","doi-asserted-by":"crossref","first-page":"475","DOI":"10.1016\/j.comnet.2012.06.019","volume":"57","author":"CJ Dietrich","year":"2013","unstructured":"Dietrich, C.J., Rossow, C., Pohlmann, N.: CoCoSpot: clustering and recognizing botnet command and control channels using traffic analysis. Comput. Netw. 57(2), 475\u2013486 (2013)","journal-title":"Comput. Netw."},{"key":"247_CR17","volume-title":"Pattern Classification","author":"RO Duda","year":"2012","unstructured":"Duda, R.O., Hart, P.E., Stork, D.G.: Pattern Classification. Wiley, New York (2012)"},{"key":"247_CR18","doi-asserted-by":"publisher","unstructured":"Fan, W., Miller, M., Stolfo, S., Lee, W., Chan, P.: Using artificial anomalies to detect unknown and known network intrusions. In: Proceedings of the IEEE International Conference on Data Mining (ICDM 2001), pp. 123\u2013130 (2001). doi: 10.1109\/ICDM.2001.989509","DOI":"10.1109\/ICDM.2001.989509"},{"key":"247_CR19","unstructured":"Frank, E.: J48. [online] (2012). http:\/\/weka.sourceforge.net\/doc.dev\/weka\/classifiers\/trees\/J48.html"},{"key":"247_CR20","unstructured":"Frank, E., Legg, S., Inglis, S.: Class SMO. [online] (2012). http:\/\/weka.sourceforge.net\/doc\/weka\/classifiers\/functions\/SMO.html"},{"issue":"2","key":"247_CR21","doi-asserted-by":"crossref","first-page":"256","DOI":"10.1006\/inco.1995.1136","volume":"121","author":"Y Freund","year":"1995","unstructured":"Freund, Y.: Boosting a weak learning algorithm by majority. Inf. Comput. 121(2), 256\u2013285 (1995)","journal-title":"Inf. Comput."},{"key":"247_CR22","doi-asserted-by":"crossref","unstructured":"Golovko, V., Bezobrazov, S., Kachurka, P., Vaitsekhovich, L.: Neural network and artificial immune systems for malware and network intrusion detection. In: Advances in Machine Learning II, pp. 485\u2013513. Springer, Berlin (2010)","DOI":"10.1007\/978-3-642-05179-1_23"},{"key":"247_CR23","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: BotHunter: detecting malware infection through IDS-driven dialog correlation. In: Proceedings of 16th USENIX Security Symposium, SS, pp. 1\u201316. USENIX Association, Berkeley, CA (2007)"},{"key":"247_CR24","unstructured":"Gu, G., Zhang, J., Lee, W.: BotSniffer: Detecting botnet command and control channels in network traffic. In: Proceedings of the Network and Distributed System Security Symposium, NDSS. The Internet Society (2008)"},{"key":"247_CR25","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: BotMiner: clustering analysis of network traffic for protocol- and structure-independent botnet detection. In: Proceedings of the 17th Security Symposium, SS, pp. 139\u2013154. USENIX Association, Berkeley, CA (2008)"},{"key":"247_CR26","unstructured":"Han, B.: Towards a multi-tier runtime system for GIPSY. Master\u2019s thesis, Department of Computer Science and Software Engineering, Concordia University, Montreal (2010)"},{"key":"247_CR27","volume-title":"Data Mining: Concepts and Techniques","author":"J Han","year":"2005","unstructured":"Han, J.: Data Mining: Concepts and Techniques. Morgan Kaufmann Publishers Inc., San Francisco, CA (2005)"},{"issue":"4","key":"247_CR28","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/5254.708428","volume":"13","author":"MA Hearst","year":"1998","unstructured":"Hearst, M.A., Dumais, S., Osman, E., Platt, J., Scholkopf, B.: Support vector machines. IEEE of Intelligent Systems and Their Applications 13(4), 18\u201328 (1998)","journal-title":"IEEE of Intelligent Systems and Their Applications"},{"key":"247_CR29","unstructured":"Hu, X., Shin, K.G., Bhatkar, S., Griffin, K.: MutantX-S: Scalable malware clustering based on static features. In: USENIX Annual Technical Conference, pp. 187\u2013198 (2013)"},{"key":"247_CR30","unstructured":"Ji, Y.: Scalability evaluation of the GIPSY runtime system. Master\u2019s thesis, Department of Computer Science and Software Engineering, Concordia University, Montreal (2011). http:\/\/spectrum.library.concordia.ca\/7152\/"},{"key":"247_CR31","unstructured":"Karasaridis, A., Rexroad, B., Hoeflin, D.: Wide-scale botnet detection and characterization. In: Proceedings of the First Workshop on Hot Topics in Understanding Botnets, HotBots, pp. 1\u20137. USENIX Association, Berkeley, CA (2007)"},{"key":"247_CR32","unstructured":"Karypis Lab: Data clustering software. [online] (2006\u20132014). http:\/\/glaros.dtc.umn.edu\/gkhome\/views\/cluto"},{"key":"247_CR33","doi-asserted-by":"crossref","unstructured":"Katz, G., Shabtai, A., Rokach, L., Ofek, N.: ConfDTree: Improving decision trees using confidence intervals. In: 12th IEEE International Conference on, Data Mining (ICDM), pp. 339\u2013348 (2012)","DOI":"10.1109\/ICDM.2012.19"},{"key":"247_CR34","doi-asserted-by":"crossref","unstructured":"Kheir, N., Blanc, G., Debar, H., Garcia-Alfaro, J., Yang, D.: Automated classification of C&C connections through malware URL clustering. In: ICT Systems Security and Privacy Protection, pp. 252\u2013266. Springer, Berlin (2015)","DOI":"10.1007\/978-3-319-18467-8_17"},{"key":"247_CR35","doi-asserted-by":"publisher","unstructured":"Kirat, D., Nataraj, L., Vigna, G., Manjunath, B.S.: SigMal: a static signal processing based malware triage. In: ACSAC\u201913. ACM, New York, NY (2013). doi: 10.1145\/2523649.2523682","DOI":"10.1145\/2523649.2523682"},{"issue":"35","key":"247_CR36","doi-asserted-by":"crossref","first-page":"1168","DOI":"10.1109\/TSMCB.2005.850176","volume":"6","author":"M Kokare","year":"2005","unstructured":"Kokare, M., Biswas, P.K., Chatterji, B.N.: Texture image retrieval using new rotated complex wavelet filters. IEEE Transaction on Systems, Man, and Cybernetics-Part B: Cybernetics 6(35), 1168\u20131178 (2005)","journal-title":"IEEE Transaction on Systems, Man, and Cybernetics-Part B: Cybernetics"},{"issue":"36","key":"247_CR37","doi-asserted-by":"crossref","first-page":"1273","DOI":"10.1109\/TSMCB.2006.874692","volume":"6","author":"M Kokare","year":"2006","unstructured":"Kokare, M., Biswas, P.K., Chatterji, B.N.: Rotation-invariant texture image retrieval using rotated complex wavelet filters. IEEE Transaction on Systems, Man, and Cybernetics-Part B: Cybernetics 6(36), 1273\u20131282 (2006)","journal-title":"IEEE Transaction on Systems, Man, and Cybernetics-Part B: Cybernetics"},{"key":"247_CR38","doi-asserted-by":"crossref","unstructured":"Kremenek, T., Engler, D.: Z-ranking: Using statistical analysis to counter the impact of static analysis approximations. In: SAS 2003 (2003)","DOI":"10.1007\/3-540-44898-5_16"},{"key":"247_CR39","doi-asserted-by":"crossref","unstructured":"Kremenek, T., Ashcraft, K., Yang, J., Engler, D.: Correlation exploitation in error ranking. In: Foundations of Software Engineering (FSE) (2004)","DOI":"10.1145\/1041685.1029909"},{"key":"247_CR40","unstructured":"Kremenek, T., Twohey, P., Back, G., Ng, A., Engler, D.: From uncertainty to belief: inferring the specification within. In: Proceedings of the 7th Symposium on Operating System Design and Implementation (2006)"},{"key":"247_CR41","doi-asserted-by":"crossref","unstructured":"Larsen, B., Aone, C.: Fast and effective text mining using linear-time document clustering. In: KDD, KDD\u201999, pp. 16\u201322. ACM, New York, NY (1999)","DOI":"10.1145\/312129.312186"},{"issue":"2","key":"247_CR42","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1145\/772862.772868","volume":"4","author":"W Lee","year":"2001","unstructured":"Lee, W.: Applying data mining to intrusion detection: the quest for automation, efficiency, and credibility. ACM SIGKDD Explorations Newsletter 4(2), 35\u201342 (2001)","journal-title":"ACM SIGKDD Explorations Newsletter"},{"key":"247_CR43","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1023\/1006624031083","volume":"14","author":"W Lee","year":"2000","unstructured":"Lee, W., Stolfo, S.J., Mok, K.W.: Adaptive intrusion detection: a data mining approach. Artificial Intelligence Review 14, 533\u2013567 (2000). doi: 10.1023\/1006624031083","journal-title":"Artificial Intelligence Review"},{"key":"247_CR44","doi-asserted-by":"publisher","unstructured":"Li, R., Xi, O.J., Pang, B., Shen, J., Ren, C.L.: Network application identification based on wavelet transform and k-means algorithm. In: Proceedings of the IEEE International Conference on Intelligent Computing and Intelligent Systems (ICIS2009), vol.\u00a01, pp. 38\u201341 (2009). doi: 10.1109\/ICICISYS.2009.5357939","DOI":"10.1109\/ICICISYS.2009.5357939"},{"key":"247_CR45","doi-asserted-by":"crossref","first-page":"790","DOI":"10.1016\/j.comnet.2008.11.016","volume":"53","author":"W Li","year":"2009","unstructured":"Li, W., Canini, M., Moore, A.W., Bolla, R.: Efficient application identification and the temporal and spatial stability of classification schema. Comput. Netw. 53, 790\u2013809 (2009)","journal-title":"Comput. Netw."},{"key":"247_CR46","doi-asserted-by":"publisher","unstructured":"Limthong, K., Kensuke, F., Watanapongse, P.: Wavelet-based unwanted traffic time series analysis. In: 2008 International Conference on Computer and Electrical Engineering, pp. 445\u2013449. IEEE Computer Society, Washington, DC (2008). doi: 10.1109\/ICCEE.2008.106","DOI":"10.1109\/ICCEE.2008.106"},{"key":"247_CR47","doi-asserted-by":"crossref","unstructured":"Livadas, C., Walsh, R., Lapsley, D.E., Strayer, W.T.: Using machine learning techniques to identify botnet traffic. In: LCN, pp. 967\u2013974. IEEE Computer Society, Washington, DC (2006)","DOI":"10.1109\/LCN.2006.322210"},{"key":"247_CR48","unstructured":"Locasto, M.E., Parekh, J.J., Stolfo, S., Misra, V.: Collaborative distributed intrusion detection. Tech. Rep. CUCS-012-04 (2004). http:\/\/hdl.handle.net\/10022\/AC:P:29215"},{"key":"247_CR49","doi-asserted-by":"crossref","unstructured":"Locasto, M.E., Parekh, J.J., Keromytis, A.D., Stolfo, S.J.: Towards collaborative security and P2P intrusion detection. In: Proceedings of the Information Assurance Workshop (IAW\u201905), from the Sixth Annual IEEE SMC, pp. 333\u2013339. IEEE (2005)","DOI":"10.1109\/IAW.2005.1495971"},{"key":"247_CR50","volume-title":"Foundations of Statistical Natural Language Processing","author":"CD Manning","year":"2002","unstructured":"Manning, C.D., Schutze, H.: Foundations of Statistical Natural Language Processing. MIT Press, Cambridge, MA (2002)"},{"key":"247_CR51","unstructured":"MathWorks: MATLAB. [online] (2000\u20132012). http:\/\/www.mathworks.com\/products\/matlab\/"},{"key":"247_CR52","unstructured":"MathWorks: MATLAB Coder. [online] (2012). http:\/\/www.mathworks.com\/help\/toolbox\/coder\/coder_product_page.html , last viewed June 2012"},{"key":"247_CR53","unstructured":"MathWorks: MATLAB Coder: codegen\u2014generate C\/C++ code from MATLAB code. [online] (2012). http:\/\/www.mathworks.com\/help\/toolbox\/coder\/ref\/codegen.html , last viewed June 2012"},{"key":"247_CR54","volume-title":"The EM Algorithm and Extensions","author":"G McLachlan","year":"2007","unstructured":"McLachlan, G., Krishnan, T.: The EM Algorithm and Extensions, vol. 382. Wiley, New York (2007)"},{"key":"247_CR55","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1145\/1370256.1370262","volume-title":"Proceedings of C3S2E\u201908","author":"SA Mokhov","year":"2008","unstructured":"Mokhov, S.A.: Study of best algorithm combinations for speech processing tasks in machine learning using median vs. mean clusters in MARF. In: Desai, B.C. (ed.) Proceedings of C3S2E\u201908, pp. 29\u201343. ACM, Montreal, Quebec (2008). doi: 10.1145\/1370256.1370262"},{"key":"247_CR56","unstructured":"Mokhov, S.A.: MARFCAT\u2014MARF-based Code Analysis Tool. Published electronically within the MARF project. http:\/\/sourceforge.net\/projects\/marf\/files\/Applications\/MARFCAT\/ (2010\u20132015). Last viewed February 2014"},{"key":"247_CR57","unstructured":"Mokhov, S.A.: The use of machine learning with signal- and NLP processing of source code to fingerprint, detect, and classify vulnerabilities and weaknesses with MARFCAT. Tech. Rep. NIST SP 500\u2013283, NIST (2011). Report: http:\/\/www.nist.gov\/manuscript-publication-search.cfm?pub_id=909407 , online e-print at http:\/\/arxiv.org\/abs\/1010.2511"},{"key":"247_CR58","unstructured":"Mokhov, S.A.: Intensional cyberforensics. Ph.D. thesis, Department of Computer Science and Software Engineering, Concordia University, Montreal (2013). arXiv:1312.0466"},{"key":"247_CR59","unstructured":"Mokhov, S.A., Debbabi, M.: File type analysis using signal processing techniques and machine learning vs. file unix utility for forensic analysis. In: O. Goebel, S. Frings, D. Guenther, J. Nedon, D. Schadt (eds.) Proceedings of the IT Incident Management and IT Forensics (IMF\u201908), LNI140, pp. 73\u201385. GI (2008)"},{"key":"247_CR60","unstructured":"Mokhov, S.A., Paquet, J., Debbabi, M.: Formally specifying operational semantics and language constructs of Forensic Lucid. In: O. G\u00f6bel, S. Frings, D. G\u00fcnther, J. Nedon, D. Schadt (eds.) Proceedings of the IT Incident Management and IT Forensics (IMF\u201908), LNI, vol. 140, pp. 197\u2013216. GI (2008). Online at http:\/\/subs.emis.de\/LNI\/Proceedings\/Proceedings140\/gi-proc-140-014.pdf"},{"key":"247_CR61","doi-asserted-by":"publisher","unstructured":"Mokhov, S.A., Paquet, J., Debbabi, M.: Towards automatic deduction and event reconstruction using Forensic Lucid and probabilities to encode the IDS evidence. In: S.\u00a0Jha, R.\u00a0Sommer, C.\u00a0Kreibich (eds.) Proceedings of Recent Advances in Intrusion Detection RAID\u201910, Lecture Notes in Computer Science (LNCS), vol. 6307, pp. 508\u2013509. Springer, Berlin (2010). doi: 10.1007\/978-3-642-15512-3_36","DOI":"10.1007\/978-3-642-15512-3_36"},{"key":"247_CR62","doi-asserted-by":"publisher","unstructured":"Mokhov, S.A., Paquet, J., Debbabi, M.: The use of NLP techniques in static code analysis to detect weaknesses and vulnerabilities. In: M.\u00a0Sokolova, P.\u00a0van Beek (eds.) Proceedings of Canadian Conference on AI\u201914, LNAI, vol. 8436, pp. 326\u2013332. Springer, Berlin (2014). doi: 10.1007\/978-3-319-06483-3_33 . Short paper","DOI":"10.1007\/978-3-319-06483-3_33"},{"key":"247_CR63","doi-asserted-by":"crossref","unstructured":"Mokhov, S.A., Paquet, J., Debbabi, M.: MARFCAT: Fast code analysis for defects and vulnerabilities. In: Proceedings of SWAN\u201915, pp. 35\u201338. IEEE (2015) (to appear)","DOI":"10.1109\/SWAN.2015.7070488"},{"key":"247_CR64","unstructured":"Motorola: Efficient polyphase FIR resampler for numpy: Native C\/C++ implementation of the function upfirdn(). [online] (2009). http:\/\/code.google.com\/p\/upfirdn\/source\/browse\/upfirdn"},{"key":"247_CR65","unstructured":"Murphy, K.P.: HMM toolbox. [online] (2002\u20132014). http:\/\/www.cs.ubc.ca\/murphyk\/Software\/HMM\/hmm_download.html"},{"key":"247_CR66","doi-asserted-by":"crossref","unstructured":"Nari, S., Ghorbani, A.A.: Automated malware classification based on network behavior. In: Proceedings of the 2013 International Conference on Computing, Networking and Communications (ICNC), pp. 642\u2013647. IEEE (2013)","DOI":"10.1109\/ICCNC.2013.6504162"},{"key":"247_CR67","doi-asserted-by":"crossref","unstructured":"Noh, S.K., Oh, J.H., Lee, J.S., Noh, B.N., Jeong, H.C.: Detecting p2p botnets using a multi-phased flow model. In: International Conference on Digital Society, ICDS, pp. 247\u2013253. IEEE Computer Society, Washington, DC (2009)","DOI":"10.1109\/ICDS.2009.37"},{"key":"247_CR68","doi-asserted-by":"crossref","unstructured":"Okada, Y., Ata, S., Nakamura, N., Nakahira, Y., Oka, I.: Comparisons of machine learning algorithms for application identification of encrypted traffic. In: Proceedings of the 10th International Conference on Machine Learning and Applications and Workshops (ICMLA), vol.\u00a02, pp. 358\u2013361 (2011)","DOI":"10.1109\/ICMLA.2011.162"},{"key":"247_CR69","unstructured":"Okun, V., Delaitre, A., Black, P.E., NIST SAMATE: Static Analysis Tool Exposition (SATE) 2010. [online] (2010). http:\/\/samate.nist.gov\/SATE2010Workshop.html"},{"key":"247_CR70","doi-asserted-by":"crossref","unstructured":"Ouchani, S., Ait\u2019Mohamed, O., Debbabi, M.: A non-convex classifier support for abstraction-refinement framework. In: 24th International Conference on Microelectronics (ICM), pp. 1\u20134 (2012)","DOI":"10.1109\/ICM.2012.6471409"},{"key":"247_CR71","doi-asserted-by":"publisher","unstructured":"Paquet, J.: Distributed eductive execution of hybrid intensional programs. In: Proceedings of the 33rd Annual IEEE International Computer Software and Applications Conference (COMPSAC\u201909), pp. 218\u2013224. IEEE Computer Society, Washington, DC (2009). doi: 10.1109\/COMPSAC.2009.137","DOI":"10.1109\/COMPSAC.2009.137"},{"key":"247_CR72","doi-asserted-by":"crossref","unstructured":"Paxson, V.: Bro: a system for detecting network intruders in real-time. Comput. Netw. 31(23\u201324), 2435\u20132463 (1999). http:\/\/www.icir.org\/vern\/papers\/bro-CN99.pdf","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"247_CR73","doi-asserted-by":"crossref","unstructured":"Peng, Y., Kou, G., Sabatka, A., Chen, Z., Khazanchi, D., Shi, Y.: Application of clustering methods to health insurance fraud detection. In: Proceedings of the 2006 International Conference on Service Systems and Service Management, vol. 1, pp. 116\u2013120 (2006)","DOI":"10.1109\/ICSSSM.2006.320598"},{"issue":"6","key":"247_CR74","doi-asserted-by":"crossref","first-page":"864","DOI":"10.1016\/j.comnet.2008.11.011","volume":"53","author":"R Perdisci","year":"2009","unstructured":"Perdisci, R., Ariu, D., Fogla, P., Giacinto, G., Lee, W.: McPAD: a multiple classifier system for accurate payload-based anomaly detection. Comput. Netw. 53(6), 864\u2013881 (2009)","journal-title":"Comput. Netw."},{"key":"247_CR75","volume-title":"C4.5: Programs for Machine Learning","author":"R Quinlan","year":"1993","unstructured":"Quinlan, R.: C4.5: Programs for Machine Learning. Morgan Kaufmann Publishers, San Mateo, CA (1993)"},{"key":"247_CR76","doi-asserted-by":"crossref","unstructured":"Rahimian, A., Ziarati, R., Preda, S., Debbabi, M.: On the reverse engineering of the Citadel botnet. In: Foundations and Practice of Security. Lecture Notes in Computer Science, pp. 408\u2013425. Springer, Berlin (2014)","DOI":"10.1007\/978-3-319-05302-8_25"},{"key":"247_CR77","doi-asserted-by":"crossref","unstructured":"Rieck, K., Holz, T., Willems, C., D\u00fcssel, P., Laskov, P.: Learning and classification of malware behavior. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 108\u2013125. Springer, Berlin (2008)","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"247_CR78","doi-asserted-by":"crossref","unstructured":"Rodr\u00edguez, L.J., Torres, I.: Comparative study of the baum-welch and viterbi training algorithms applied to read and spontaneous speech recognition. In: Pattern Recognition and Image Analysis. Lecture Notes in Computer Science, vol. 2652, pp. 847\u2013857. Springer, Berlin (2003)","DOI":"10.1007\/978-3-540-44871-6_98"},{"key":"247_CR79","doi-asserted-by":"crossref","unstructured":"Rossow, C., Dietrich, C.J., Bos, H., Cavallaro, L., Van\u00a0Steen, M., Freiling, F.C., Pohlmann, N.: Sandnet: network traffic analysis of malicious software. In: Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, pp. 78\u201388. ACM, New york (2011)","DOI":"10.1145\/1978672.1978682"},{"key":"247_CR80","volume-title":"Automatic Text Processing: The Transformation, Analysis, and Retrieval of Information by Computer","author":"G Salton","year":"1989","unstructured":"Salton, G.: Automatic Text Processing: The Transformation, Analysis, and Retrieval of Information by Computer. Addison-Wesley, Boston, MA (1989)"},{"key":"247_CR81","doi-asserted-by":"publisher","unstructured":"Schreiber, R.: MATLAB. Scholarpedia 2(6), 2929 (2007). doi: 10.4249\/scholarpedia.2929 . http:\/\/www.scholarpedia.org\/article\/MATLAB","DOI":"10.4249\/scholarpedia.2929"},{"key":"247_CR82","doi-asserted-by":"crossref","unstructured":"Schultz, M.G., Eskin, E., Zadok, E., Stolfo, S.J.: Data mining methods for detection of new malicious executables. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 38\u201349. Oakland (2001)","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"247_CR83","unstructured":"Selesnick, I., Cai, S., Li, K., Sendur, L., Abdelnour, A.F.: MATLAB implementation of wavelet transforms. Tech. rep., Electrical Engineering, Polytechnic University, Brooklyn, NY (2003). http:\/\/taco.poly.edu\/WaveletSoftware\/"},{"key":"247_CR84","doi-asserted-by":"crossref","unstructured":"Simon, G.J., Xiong, H., Eilertson, E., Kumar, V.: Scan detection: a data mining approach. In: Proceedings of SDM 2006, pp. 118\u2013129. SIAM, Philadelphia, PA (2006). http:\/\/www.siam.org\/meetings\/sdm06\/proceedings\/011simong.pdf","DOI":"10.1137\/1.9781611972764.11"},{"key":"247_CR85","unstructured":"Sly Technologies Inc: jNetPcap OpenSource. [online] (2012). http:\/\/www.jnetpcap.com\/"},{"key":"247_CR86","unstructured":"Song, D.: BitBlaze: Security via binary analysis. [online] (2010). http:\/\/bitblaze.cs.berkeley.edu"},{"key":"247_CR87","unstructured":"Song, D.: WebBlaze: New techniques and tools for web security. [online] (2010). http:\/\/webblaze.cs.berkeley.edu"},{"key":"247_CR88","unstructured":"Song, Y., Keromytis, A.D., Stolfo, S.: Spectrogram: a mixture-of-markov-chains model for anomaly detection in web traffic. In: Proceedings of the Network and Distributed System Security Symposium, pp. 121\u2013135. Internet Society (2009)"},{"key":"247_CR89","unstructured":"Sourcefire: Snort: open-source network intrusion prevention and detection system (IDS\/IPS). [online] (1999\u20132015). http:\/\/www.snort.org\/"},{"issue":"4","key":"247_CR90","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1145\/604264.604267","volume":"30","author":"SJ Stolfo","year":"2001","unstructured":"Stolfo, S.J., Lee, W., Chan, P.K., Fan, W., Eskin, E.: Data mining-based intrusion detectors: an overview of the Columbia IDS Project. ACM SIGMOD Record 30(4), 5\u201314 (2001)","journal-title":"ACM SIGMOD Record"},{"key":"247_CR91","unstructured":"Su, J., Zhang, H.: A fast decision tree learning algorithm. In: Proceedings of the 21st National Conference on Artificial Intelligence, AAAI\u201906, vol. 1, pp. 500\u2013505. AAAI Press (2006)"},{"key":"247_CR92","doi-asserted-by":"crossref","unstructured":"Tegeler, F., Fu, X., Vigna, G., Kruegel, C.: BotFinder: finding bots in network traffic without deep packet inspection. In: Proceedings of the 8th International Conference on Emerging Networking Experiments and Technologies, CoNEXT, pp. 349\u2013360. ACM, New York, NY (2012)","DOI":"10.1145\/2413176.2413217"},{"key":"247_CR93","unstructured":"The Weka Project: Weka 3: data mining with open source machine learning software in Java. [online] (2006\u20132014). http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/"},{"key":"247_CR94","doi-asserted-by":"crossref","unstructured":"Thorat, S.A., Khandelwal, A.K., Bruhadeshwar, B., Kishore, K.: Payload content based network anomaly detection. In: Proceedings of the First International Conference on the Applications of Digital Information and Web Technologies (ICADIWT 2008), pp. 127\u2013132. IEEE (2008)","DOI":"10.1109\/ICADIWT.2008.4664331"},{"key":"247_CR95","unstructured":"ThreatTrack Security: ThreadAnalyzer: dynamic sandboxing and malware analysis (formerly GFI SandBox). [online] (2013). http:\/\/www.threattracksecurity.com\/enterprise-security\/sandbox-software.aspx"},{"key":"247_CR96","unstructured":"Trinius, P., Willems, C., Holz, T., Rieck, K.: A malware instruction set for behavior-based analysis (2011)"},{"key":"247_CR97","unstructured":"Vassev, E.I.: General architecture for demand migration in the GIPSY demand-driven execution engine. Master\u2019s thesis, Department of Computer Science and Software Engineering, Concordia University, Montreal (2005). http:\/\/spectrum.library.concordia.ca\/8681\/"},{"key":"247_CR98","doi-asserted-by":"crossref","unstructured":"Wang, K., Stolfo, S.J.: Anomalous payload-based network intrusion detection. In: Recent Advances in Intrusion Detection, pp. 203\u2013222. Springer, Berlin (2004)","DOI":"10.1007\/978-3-540-30143-1_11"},{"key":"247_CR99","doi-asserted-by":"crossref","unstructured":"Whalen, S., Boggs, N., Stolfo, S.J.: Model aggregation for distributed content anomaly detection. In: Proceedings of the 2014 Workshop on Artificial Intelligent and Security Workshop, pp. 61\u201371. ACM, New York (2014)","DOI":"10.1145\/2666652.2666660"},{"key":"247_CR100","unstructured":"Wicherski, G.: pehash: a novel approach to fast malware clustering. In: 2nd USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET) (2009)"},{"key":"247_CR101","unstructured":"Wireless and Secure Networks Research Lab: WISNET: downloads. [online] (2009\u20132014). http:\/\/wisnet.seecs.nust.edu.pk\/downloads.php"},{"key":"247_CR102","unstructured":"Wu, M.D., Wolfthusen, S.D.: Network forensics of partial SSL\/TLS encrypted traffic classification using clustering algorithms. In: O. G\u00f6bel, S. Frings, D. G\u00fcnther, J. Nedon, D. Schadt (eds.) Proceedings of the IT Incident Management and IT Forensics (IMF\u201908), LNI140, pp. 157\u2013172 (2008)"},{"key":"247_CR103","doi-asserted-by":"crossref","unstructured":"Yen, T.F., Reiter, M.K.: Traffic aggregation for malware detection. In: Proceedings of the 5th international conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA, pp. 207\u2013227. Springer, Berlin (2008)","DOI":"10.1007\/978-3-540-70542-0_11"},{"key":"247_CR104","doi-asserted-by":"crossref","unstructured":"Zanero, S.: Analyzing TCP traffic patterns using self organizing maps. In: Image Analysis and Processing (ICIAP 2005), pp. 83\u201390. Springer, Berlin (2005)","DOI":"10.1007\/11553595_10"},{"key":"247_CR105","doi-asserted-by":"crossref","unstructured":"Zanero, S., Savaresi, S.M.: Unsupervised learning techniques for an intrusion detection system. In: Proceedings of the 2004 ACM Symposium on Applied Computing, pp. 412\u2013419. ACM, New York (2004)","DOI":"10.1145\/967900.967988"},{"key":"247_CR106","doi-asserted-by":"crossref","unstructured":"Zanero, S., Serazzi, G.: Unsupervised learning algorithms for intrusion detection. In: Network Operations and Management Symposium (NOMS 2008), pp. 1043\u20131048. IEEE (2008)","DOI":"10.1109\/NOMS.2008.4575276"},{"key":"247_CR107","unstructured":"Zetter, K.: Meet \u2018Flame\u2019, The Massive Spy Malware Infiltrating Iranian Computers. WIRED (2012). http:\/\/www.wired.com\/threatlevel\/2012\/05\/flame\/"},{"key":"247_CR108","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1016\/j.jss.2013.08.033","volume":"87","author":"D Zhang","year":"2014","unstructured":"Zhang, D., Liu, D., Csallner, C., Kung, D., Lei, Y.: A distributed framework for demand-driven software vulnerability detection. J. Syst. Softw. 87, 60\u201373 (2014). doi: 10.1016\/j.jss.2013.08.033","journal-title":"J. Syst. Softw."},{"key":"247_CR109","unstructured":"Zhao, Y., Karypis, G.: Criterion functions for document clustering: experiments and analysis. Tech. rep., University of Minnesota (2002)"},{"issue":"2","key":"247_CR110","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1007\/s10618-005-0361-3","volume":"10","author":"Y Zhao","year":"2005","unstructured":"Zhao, Y., Karypis, G., Fayyad, U.: Hierarchical clustering algorithms for document datasets. Data Min. Knowl. Discov. 10(2), 141\u2013168 (2005)","journal-title":"Data Min. Knowl. Discov."},{"issue":"3","key":"247_CR111","doi-asserted-by":"crossref","first-page":"374","DOI":"10.1007\/s10115-004-0194-1","volume":"8","author":"S Zhong","year":"2005","unstructured":"Zhong, S., Ghosh, J.: Generative model-based document clustering: a comparative study. Knowl. Inf. Syst. 8(3), 374\u2013384 (2005)","journal-title":"Knowl. Inf. Syst."}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-015-0247-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-015-0247-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-015-0247-x","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,28]],"date-time":"2019-08-28T20:09:29Z","timestamp":1567022969000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-015-0247-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,7,29]]},"references-count":111,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2016,5]]}},"alternative-id":["247"],"URL":"https:\/\/doi.org\/10.1007\/s11416-015-0247-x","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,7,29]]}}}