{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,23]],"date-time":"2026-01-23T12:08:02Z","timestamp":1769170082604,"version":"3.49.0"},"reference-count":166,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2016,5,2]],"date-time":"2016-05-02T00:00:00Z","timestamp":1462147200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2017,2]]},"DOI":"10.1007\/s11416-016-0273-3","type":"journal-article","created":{"date-parts":[[2016,5,2]],"date-time":"2016-05-02T15:14:26Z","timestamp":1462202066000},"page":"47-85","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":40,"title":["Semantics-aware detection of targeted attacks: a survey"],"prefix":"10.1007","volume":"13","author":[{"given":"Robert","family":"Luh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Marschalek","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Manfred","family":"Kaiser","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Helge","family":"Janicke","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sebastian","family":"Schrittwieser","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,5,2]]},"reference":[{"key":"273_CR1","doi-asserted-by":"crossref","unstructured":"Abdoli, F., Kahani, M.: Ontology-based distributed intrusion detection system. In: Computer Conference, 2009. CSICC 2009, 14th International CSI, IEEE, pp. 65\u201370 (2009)","DOI":"10.1109\/CSICC.2009.5349372"},{"key":"273_CR2","doi-asserted-by":"crossref","unstructured":"AlEroud, A., Karabatis, G.: A system for cyber attack detection using contextual semantics. In: 7th International Conference on Knowledge Management in Organizations: Service and Cloud Computing, pp. 431\u2013442, Springer, New York (2013)","DOI":"10.1007\/978-3-642-30867-3_39"},{"key":"273_CR3","doi-asserted-by":"publisher","unstructured":"Aleroud, A., Karabatis, G.: Context Infusion in Semantic Link Networks to Detect Cyber-attacks: A Flow-Based Detection Approach. pp. 175\u2013182. IEEE (2014). doi: 10.1109\/ICSC.2014.29","DOI":"10.1109\/ICSC.2014.29"},{"key":"273_CR4","unstructured":"Alienvault: OSSIM: The Open Source SIEM | AlienVault. https:\/\/www.alienvault.com\/products\/ossim . Accessed 29 July 2015"},{"key":"273_CR5","doi-asserted-by":"crossref","unstructured":"Anagnostopoulos, T., Anagnostopoulos, C., Hadjiefthymiades, S.: Enabling attack behavior prediction in ubiquitous environments. In: Pervasive Services, 2005. ICPS\u201905, Proceedings of International Conference on, pp. 425\u2013428. IEEE (2005)","DOI":"10.1109\/PERSER.2005.1506559"},{"key":"273_CR6","doi-asserted-by":"crossref","unstructured":"Andersson, S., Clark, A., Mohay, G., Schatz, B., Zimmermann, J.: A framework for detecting network-based code injection attacks targeting Windows and UNIX. In: Computer Security Applications Conference, 21st Annual, pp. 10. IEEE (2005)","DOI":"10.1109\/CSAC.2005.5"},{"key":"273_CR7","doi-asserted-by":"crossref","unstructured":"Ansarinia, M., Asghari, S.A., Souzani, A., Ghaznavi, A.: Ontology-based modeling of DDoS attacks for attack plan detection. In: 2012 6th International Symposium on Telecommunications (IST), pp. 993\u2013998. IEEE (2012)","DOI":"10.1109\/ISTEL.2012.6483131"},{"key":"273_CR8","unstructured":"Apache Software Foundation: Apache JENA. https:\/\/jena.apache.org\/ . Accessed 27 July 2015"},{"key":"273_CR9","unstructured":"Apecechea, G.I., Inci, M.S., Eisenbarth, T., Sunar, B.: Fine grain Cross-VM Attacks on Xen and VMware are possible! IACR Cryptology ePrint Archive p. 248 (2014)"},{"issue":"1\u20134","key":"273_CR10","doi-asserted-by":"crossref","first-page":"315","DOI":"10.1007\/BF01840365","volume":"2","author":"A Apostolico","year":"1987","unstructured":"Apostolico, A., Guerra, C.: The longest common subsequence problem revisited. Algorithmica 2(1\u20134), 315\u2013336 (1987)","journal-title":"Algorithmica"},{"key":"273_CR11","doi-asserted-by":"publisher","unstructured":"Atighetchi, M., Griffith, J., Emmons, I., Mankins, D., Guidorizzi, R.: Federated Access to Cyber Observables for Detection of Targeted Attacks. pp. 60\u201366. IEEE (2014). doi: 10.1109\/MILCOM.2014.15","DOI":"10.1109\/MILCOM.2014.15"},{"key":"273_CR12","doi-asserted-by":"crossref","unstructured":"Balduzzi, M., Ciangaglini, V., McArdle, R.: Targeted attacks detection with spunge. In: 11th Annual International Conference on Privacy, Security and Trust (PST), 2013, pp. 185\u2013194. IEEE (2013)","DOI":"10.1109\/PST.2013.6596053"},{"key":"273_CR13","unstructured":"Bayer, U., Comparetti, P.M., Hlauschek, C., Kruegel, C., Kirda, E.: Scalable, Behavior-Based Malware Clustering. In: NDSS, vol.\u00a09, pp. 8\u201311. Citeseer (2009)"},{"key":"273_CR14","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: TTAnalyze: A Tool for Analyzing Malware. EICAR, pp. 180\u2013192 (2006)"},{"key":"273_CR15","unstructured":"BBN Technologies: Asio BBN. http:\/\/asio.bbn.com . Accessed 27 July 2015"},{"key":"273_CR16","doi-asserted-by":"crossref","unstructured":"Bhatkar, S., Chaturvedi, A., Sekar, R.: Dataflow anomaly detection. In: 2006 IEEE Symposium on Security and Privacy, pp. 15\u2013pp. IEEE (2006)","DOI":"10.1109\/SP.2006.12"},{"key":"273_CR17","doi-asserted-by":"publisher","unstructured":"Bhatt, P., Yano, E.T., Gustavsson, P.: Towards a Framework to Detect Multi-stage Advanced Persistent Threats Attacks. pp. 390\u2013395. IEEE (2014). doi: 10.1109\/SOSE.2014.53","DOI":"10.1109\/SOSE.2014.53"},{"key":"273_CR18","doi-asserted-by":"crossref","unstructured":"Bilge, L., Dumitras, T.: Before we knew it: an empirical study of zero-day attacks in the real world. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 833\u2013844. ACM (2012)","DOI":"10.1145\/2382196.2382284"},{"key":"273_CR19","doi-asserted-by":"crossref","unstructured":"Bond, M.D., McKinley, K.S.: Probabilistic calling context. In: ACM SIGPLAN Notices, vol.\u00a042, pp. 97\u2013112. ACM (2007)","DOI":"10.1145\/1297027.1297035"},{"key":"273_CR20","doi-asserted-by":"crossref","unstructured":"Bond, M.D., Srivastava, V., McKinley, K.S., Shmatikov, V.: Efficient, context-sensitive detection of real-world semantic attacks. In: Proceedings of the 5th ACM SIGPLAN Workshop on Programming Languages and Analysis for Security, p.\u00a01. ACM (2010)","DOI":"10.1145\/1814217.1814218"},{"key":"273_CR21","unstructured":"Bott, E.: Why malware networks are beating antivirus software. http:\/\/www.zdnet.com\/article\/why-malware-networks-are-beating-antivirus-software\/ . Accessed 29 July 2015"},{"key":"273_CR22","unstructured":"Caswell, B., Beale, J.: Snort Intrusion Detection 2.0. Syngress (2003)"},{"key":"273_CR23","unstructured":"Chaturvedi, A., Bhatkar, S., Sekar, R.: Improving attack detection in host-based IDS by learning properties of system call arguments. In: Proceedings of the IEEE Symposium on Security and Privacy, Citeseer (2005)"},{"key":"273_CR24","volume-title":"Ontology-based Mobile Malware Behavioral Analysis","author":"HS Chiang","year":"2009","unstructured":"Chiang, H.S., Tsaur, W.J.: Ontology-based Mobile Malware Behavioral Analysis. Da-Yeh University, Changhua (2009)"},{"key":"273_CR25","unstructured":"Chien, E., OMurchu, L., Falliere, N.: W32. Duqu: the precursor to the next stuxnet. In: Proceedings of the 5th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET) (2012)"},{"key":"273_CR26","doi-asserted-by":"crossref","unstructured":"Chien, S.H., Chang, E.H., Yu, C.Y., Ho, C.S.: Attack subplan-based attack scenario correlation. In: 2007 International Conference on Machine Learning and Cybernetics, vol.\u00a04, pp. 1881\u20131887. IEEE (2007)","DOI":"10.1109\/ICMLC.2007.4370455"},{"key":"273_CR27","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Kruegel, C.: Mining specifications of malicious behavior. In: Proceedings of the 1st India Software Engineering Conference, pp. 5\u201314. ACM (2008)","DOI":"10.1145\/1342211.1342215"},{"key":"273_CR28","unstructured":"Christodorescu, M., Jha, S., Seshia, S., Song, D., Bryant, R.E.: others: Semantics-aware malware detection. In: Security and Privacy, 2005 IEEE Symposium on, pp. 32\u201346. IEEE (2005)"},{"key":"273_CR29","unstructured":"Cisco: Cisco IOS NetFlow. http:\/\/cisco.com\/c\/en\/us\/products\/ios-nx-os-software\/ios-netflow\/index.html . Accessed 29 July 2015"},{"key":"273_CR30","unstructured":"Cisco: Snort.Org. https:\/\/www.snort.org\/ . Accessed 29 July 2015"},{"key":"273_CR31","doi-asserted-by":"crossref","unstructured":"Colmerauer, A., Roussel, P.: The Birth of Prolog. In: History of programming languages\u2013II, pp. 331\u2013367. ACM (1996)","DOI":"10.1145\/234286.1057820"},{"key":"273_CR32","doi-asserted-by":"crossref","unstructured":"Consel, C., Danvy, O.: Static and dynamic semantics processing. In: Proceedings of the 18th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, pp. 14\u201324. ACM (1991)","DOI":"10.1145\/99583.99588"},{"key":"273_CR33","doi-asserted-by":"publisher","unstructured":"Cortes, C., Vapnik, V.: Support-vector networks. Mach. Learn. 20(3), 273\u2013297 (1995). doi: 10.1007\/bf00994018","DOI":"10.1007\/bf00994018"},{"issue":"4","key":"273_CR34","doi-asserted-by":"crossref","first-page":"807","DOI":"10.1109\/TC.2013.13","volume":"63","author":"G Creech","year":"2014","unstructured":"Creech, G., Hu, J.: A semantic approach to host-based intrusion detection systems using contiguousand discontiguous system call patterns. Comput. IEEE Trans. 63(4), 807\u2013819 (2014)","journal-title":"Comput. IEEE Trans."},{"key":"273_CR35","unstructured":"Cuckoo Foundation: Automated Malware Analysis - Cuckoo Sandbox. http:\/\/www.cuckoosandbox.org\/ . Accessed 29 July 2015"},{"issue":"5","key":"273_CR36","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1387673.1387674","volume":"30","author":"M Dalla Preda","year":"2008","unstructured":"Dalla Preda, M., Christodorescu, M., Jha, S., Debray, S.: A semantics-based approach to malware detection. ACM Trans. Program. Lang. Syst. 30(5), 1\u201354 (2008)","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"273_CR37","doi-asserted-by":"crossref","unstructured":"De\u00a0Vries, J., Hoogstraaten, H., van\u00a0den Berg, J., Daskapan, S.: Systems for Detecting Advanced Persistent Threats: A Development Roadmap Using Intelligent Data Analysis. In: Cyber Security (CyberSecurity), 2012 International Conference on, pp. 54\u201361. IEEE (2012)","DOI":"10.1109\/CyberSecurity.2012.14"},{"key":"273_CR38","unstructured":"Debar, H., Curry, D., Feinstein, B.: The Intrusion Detection Message Exchange Format (IDMEF). https:\/\/www.ietf.org\/rfc\/rfc4765.txt . Accessed 29 July 2015"},{"key":"273_CR39","doi-asserted-by":"crossref","unstructured":"Debar, H., Wespi, A.: Aggregation and correlation of intrusion-detection alerts. In: Recent Advances in Intrusion Detection, pp. 85\u2013103. Springer, New York (2001)","DOI":"10.1007\/3-540-45474-8_6"},{"key":"273_CR40","unstructured":"Dell SecureWorks: Truman. http:\/\/www.secureworks.com\/cyber-threat-intelligence\/tools\/truman\/ . Accessed 29 July 2015"},{"key":"273_CR41","doi-asserted-by":"crossref","unstructured":"Dolgikh, A., Nykodym, T., Skormin, V., Birnbaum, Z.: Using behavioral modeling and customized normalcy profiles as protection against targeted cyber-attacks. In: Computer Network Security, pp. 191\u2013202. Springer, New York (2012)","DOI":"10.1007\/978-3-642-33704-8_17"},{"key":"273_CR42","doi-asserted-by":"crossref","unstructured":"Dornhackl, H., Kadletz, K., Luh, R., Tavolato, P.: Malicious behavior patterns. In: 2014 IEEE 8th International Symposium on Service Oriented System Engineering (SOSE), pp. 384\u2013389. IEEE (2014)","DOI":"10.1109\/SOSE.2014.52"},{"issue":"3","key":"273_CR43","doi-asserted-by":"crossref","first-page":"427","DOI":"10.1590\/S1415-47571999000300024","volume":"22","author":"JM Duarte","year":"1999","unstructured":"Duarte, J.M., Santos, J.B., Melo, L.C.: Comparison of similarity coefficients based on RAPD markers in the common bean. Genet. Molecular Biol. 22(3), 427\u2013432 (1999)","journal-title":"Genet. Molecular Biol."},{"issue":"3","key":"273_CR44","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1109\/JSYST.2012.2221913","volume":"7","author":"TE Dube","year":"2013","unstructured":"Dube, T.E., Raines, R.A., Grimaila, M.R., Bauer, K.W., Rogers, S.K.: Malware target recognition of unknown threats. IEEE Syst. J. 7(3), 467\u2013477 (2013). doi: 10.1109\/JSYST.2012.2221913","journal-title":"IEEE Syst. J."},{"issue":"2","key":"273_CR45","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1145\/2089125.2089126","volume":"44","author":"M Egele","year":"2012","unstructured":"Egele, M., Scholte, T., Kirda, E., Kruegel, C.: A survey on automated dynamic malware-analysis techniques and tools. ACM Comput. Surv. (CSUR) 44(2), 6 (2012)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"273_CR46","doi-asserted-by":"crossref","unstructured":"Eric, S.Y.: Social Modeling and i*. In: Conceptual Modeling: Foundations and Applications, pp. 99\u2013121. Springer, New York (2009)","DOI":"10.1007\/978-3-642-02463-4_7"},{"key":"273_CR47","unstructured":"Falliere, N., Murchu, L., Chien, E.: W32.Stuxnet.Dossier. https:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/w32_stuxnet_dossier . Accessed 18 Sept 2015"},{"key":"273_CR48","unstructured":"Farrell, J.A.: http:\/\/www.cs.man.ac.uk\/~pjj\/farrell\/comp2.html#EBNF . Accessed 29 July 2015"},{"key":"273_CR49","unstructured":"Fern\u00e1ndez-L\u00f3pez, M., G\u00f3mez-P\u00e9rez, A., Juristo, N.: Methontology: from ontological art towards ontological engineering. In: AAAI Symposium on Ontological Engineering. American Association for Artificial Intelligence (1997)"},{"key":"273_CR50","unstructured":"FireEye: FireEye Malware Analysis. https:\/\/www.fireeye.com\/products\/malware-analysis.html . Accessed 29 July 2015"},{"key":"273_CR51","doi-asserted-by":"crossref","unstructured":"Fox, M.S., Barbuceanu, M., Gruninger, M.: An organisation ontology for enterprise modelling: preliminary concepts for linking structure and behaviour. In: Proceedings of the 4th Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises, 1995, pp. 71\u201381. IEEE (1995)","DOI":"10.1109\/ENABL.1995.484550"},{"key":"273_CR52","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Christodorescu, M., Sailer, R., Yan, X.: Synthesizing near-optimal malware specifications from suspicious behaviors. In: 2010 IEEE Symposium on Security and Privacy (SP), pp. 45\u201360. IEEE (2010)","DOI":"10.1109\/SP.2010.11"},{"key":"273_CR53","doi-asserted-by":"crossref","unstructured":"Fukushima, Y., Sakai, A., Hori, Y., Sakurai, K.: A behavior based malware detection scheme for avoiding false positive. In: Secure Network Protocols (NPSec), 2010 6th IEEE Workshop on, pp. 79\u201384. IEEE (2010)","DOI":"10.1109\/NPSEC.2010.5634444"},{"key":"273_CR54","doi-asserted-by":"publisher","unstructured":"Gabriel, R., Hoppe, T., Pastwa, A., Sowa, S.: Analyzing Malware Log Data to Support Security Information and Event Management: Some Research Results. pp. 108\u2013113. IEEE (2009). doi: 10.1109\/DBKDA.2009.26","DOI":"10.1109\/DBKDA.2009.26"},{"key":"273_CR55","unstructured":"Gamer, T., Scholler, M., Bless, R.: A granularity-adaptive system for in-network attack detection. In: Proceedings of the IEEE\/IST Workshop on Monitoring, Attack Detection and Mitigation, pp. 47\u201350 (2006)"},{"key":"273_CR56","doi-asserted-by":"crossref","unstructured":"Giura, P., Wang, W.: A context-based detection framework for advanced persistent threats. In: Cyber Security (CyberSecurity), 2012 International Conference on, pp. 69\u201374. IEEE (2012)","DOI":"10.1109\/CyberSecurity.2012.16"},{"key":"273_CR57","unstructured":"GlobalSecurity.org: Open Source Information System (OSIS). http:\/\/www.globalsecurity.org\/intell\/systems\/osis.htm . Accessed 29 July 2015"},{"issue":"4","key":"273_CR58","first-page":"191","volume":"18","author":"V Gorodetski","year":"2003","unstructured":"Gorodetski, V., Kotenko, I., Karsaev, O.: Multi-agent technologies for computer network security: attack simulation, intrusion detection and intrusion detection learning. Comput. Syst. Sci. Eng. 18(4), 191\u2013200 (2003)","journal-title":"Comput. Syst. Sci. Eng."},{"key":"273_CR59","unstructured":"Greenberg, A.: Russians fingered for \u2019Uroburos\u2019 spy malware campaign, went undetected for years - SC Magazine. http:\/\/www.scmagazine.com\/russians-fingered-for-uroburos-spy-malware-campaign-went-undetected-for-years\/article\/336570\/ . Accessed 29 July 2015"},{"key":"273_CR60","doi-asserted-by":"crossref","unstructured":"Gr\u00e9gio, A.R., Fernandes\u00a0Filho, D.S., Afonso, V.M., Santos, R.D., Jino, M., de\u00a0Geus, P.L.: Behavioral analysis of malicious code through network traffic and system call monitoring. In: SPIE Defense, Security, and Sensing. International Society for Optics and Photonics (2011)","DOI":"10.1117\/12.883457"},{"key":"273_CR61","doi-asserted-by":"crossref","unstructured":"Guarino, N., Welty, C.A.: An overview of OntoClean. In: Handbook on ontologies, pp. 201\u2013220. Springer, New York (2009)","DOI":"10.1007\/978-3-540-92673-3_9"},{"key":"273_CR62","doi-asserted-by":"crossref","unstructured":"He, P., Karabatis, G.: Using semantic networks to counter cyber threats. In: Intelligence and Security Informatics (ISI), 2012 IEEE International Conference on, pp. 184\u2013184. IEEE (2012)","DOI":"10.1109\/ISI.2012.6284294"},{"key":"273_CR63","unstructured":"Herman, L.: Malware Attack at US Health Organization Went Undetected for 2 Years. http:\/\/www.hackbusters.com\/news\/stories\/187232-malware-attack-at-us-health-organization-went-undetected-for-2-years . Accessed 20 Oct 2015"},{"key":"273_CR64","unstructured":"Hex-Rays: IDA: About. https:\/\/www.hex-rays.com\/products\/ida\/ . Accessed 29 July 2015"},{"key":"273_CR65","doi-asserted-by":"publisher","unstructured":"Hirono, S., Yamaguchi, Y., Shimada, H., Takakura, H.: Development of a Secure Traffic Analysis System to Trace Malicious Activities on Internal Networks. pp. 305\u2013310. IEEE (2014). doi: 10.1109\/COMPSAC.2014.41","DOI":"10.1109\/COMPSAC.2014.41"},{"key":"273_CR66","doi-asserted-by":"crossref","unstructured":"Huang, H.D., Chuang, T.Y., Tsai, Y.L., Lee, C.S.: Ontology-based intelligent system for malware behavioral analysis. In: Fuzzy Systems (FUZZ), 2010 IEEE International Conference on, pp. 1\u20136. IEEE (2010)","DOI":"10.1109\/FUZZY.2010.5584325"},{"key":"273_CR67","first-page":"80","volume":"1","author":"EM Hutchins","year":"2011","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M.: Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Lead. Issues Inf. Warfare Secur. Res. 1, 80 (2011)","journal-title":"Lead. Issues Inf. Warfare Secur. Res."},{"key":"273_CR68","unstructured":"Idika, N., Mathur, A.P.: A survey of malware detection techniques. Technical report 286, Department of Computer Science, Purdue University, USA (2007)"},{"key":"273_CR69","doi-asserted-by":"crossref","unstructured":"Indyk, P., Motwani, R.: Approximate nearest neighbors: towards removing the curse of dimensionality. In: Proceedings of the thirtieth annual ACM symposium on Theory of computing, pp. 604\u2013613. ACM (1998)","DOI":"10.1145\/276698.276876"},{"key":"273_CR70","unstructured":"International Secure Systems Lab: Anubis - Malware Analysis for Unknown Binaries. https:\/\/anubis.iseclab.org\/ . Accessed 29 July 2015"},{"issue":"3","key":"273_CR71","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1007\/s11416-008-0086-0","volume":"4","author":"G Jacob","year":"2008","unstructured":"Jacob, G., Debar, H., Filiol, E.: Behavioral detection of malware: from a survey towards an established taxonomy. J. Comput. Virol. 4(3), 251\u2013266 (2008)","journal-title":"J. Comput. Virol."},{"key":"273_CR72","unstructured":"Jacob, G., Hund, R., Kruegel, C., Holz, T.: Jackstraws: Picking command and control connections from bot traffic. In: USENIX Security Symposium, vol. 2011. San Francisco, CA, USA (2011)"},{"key":"273_CR73","doi-asserted-by":"crossref","DOI":"10.1007\/b95112","volume-title":"Coloured Petri Nets: Modelling and Validation of Concurrent Systems","author":"K Jensen","year":"2009","unstructured":"Jensen, K., Kristensen, L.M.: Coloured Petri Nets: Modelling and Validation of Concurrent Systems. Springer, Dordrecht (2009)"},{"key":"273_CR74","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through vmm-based out-of-the-box semantic view reconstruction. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 128\u2013138. ACM (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"273_CR75","unstructured":"Joe Security: Agile Malware Analysis - Joe Sandbox Desktop. http:\/\/www.joesecurity.org\/joe-sandbox-desktop . Accessed 29 July 2015"},{"key":"273_CR76","doi-asserted-by":"crossref","unstructured":"Julisch, K., Kruegel, C.: Detection of Intrusions and Malware, and Vulnerability Assessment. In: 2005, Proceedings of 2nd International Conference, DIMVA 2005, Vienna, Austria, July 7-8, Springer, New York (2005)","DOI":"10.1007\/b137798"},{"issue":"2","key":"273_CR77","first-page":"84","volume":"1","author":"P Kabiri","year":"2005","unstructured":"Kabiri, P., Ghorbani, A.A.: Research on intrusion detection and response: a survey. IJ Netw. Secur. 1(2), 84\u2013102 (2005)","journal-title":"IJ Netw. Secur."},{"key":"273_CR78","unstructured":"Kaspersky Lab: Duqu: Steal Everything. http:\/\/www.kaspersky.com\/about\/press\/major_malware_outbreaks\/duqu . Accessed 29 July 2015"},{"key":"273_CR79","unstructured":"Kaspersky Lab: What is Flame Malware | Definition and Risks | Kaspersky Lab. http:\/\/www.kaspersky.com\/flame . Accessed 29 July 2015"},{"key":"273_CR80","unstructured":"Kaspersky Lab\u2019s Global Research & Analysis Team: Gauss: Abnormal Distribution - Securelist. https:\/\/securelist.com\/analysis\/36620\/gauss-abnormal-distribution\/ . Accessed 29 July 2015"},{"key":"273_CR81","unstructured":"Kendall, K., McMillan, C.: Practical malware analysis. In: Black Hat Conference, USA (2007)"},{"key":"273_CR82","unstructured":"Kitchenham, B.A.: Procedures for undertaking systematic reviews. Tech. rep. Computer Science Department, Keele University (2004)"},{"key":"273_CR83","unstructured":"Knight, S.: Sophisticated malware dubbed \u2019The Mask\u2019 went undetected for the past seven years - TechSpot. http:\/\/www.techspot.com\/news\/55640-sophisticated-malware-dubbed-the-mask-went-undetected-for-the-past-seven-years.html . Accessed 29 July 2015"},{"issue":"1","key":"273_CR84","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1016\/S0020-7373(86)80040-2","volume":"24","author":"B Kosko","year":"1986","unstructured":"Kosko, B.: Fuzzy cognitive maps. Int. J. Man-Mach. Stud. 24(1), 65\u201375 (1986)","journal-title":"Int. J. Man-Mach. Stud."},{"key":"273_CR85","doi-asserted-by":"crossref","unstructured":"Krishnamurthy, B., Sen, S., Zhang, Y., Chen, Y.: Sketch-based change detection: methods, evaluation, and applications. In: Proceedings of the 3rd ACM SIGCOMM Conference on Internet Measurement, pp. 234\u2013247. ACM (2003)","DOI":"10.1145\/948205.948236"},{"key":"273_CR86","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Lippmann, R., Clark, A. (eds.): Recent advances in intrusion detection. In: 10th International Symposium, RAID 2007, Gold Coast [i.e. Coast], Australia, September 5\u20137, 2007: Proceedings on No. 4637 in Lecture Notes in Computer Science. Springer, Berlin (2007)","DOI":"10.1007\/978-3-540-74320-0"},{"key":"273_CR87","unstructured":"Kumar, S., Spafford, E.H.: A pattern matching model for misuse intrusion detection. In: Proceedings of the 17th National computer Security Conference, pp.11\u201321 (1994)"},{"key":"273_CR88","doi-asserted-by":"crossref","unstructured":"Kwon, J., Lee, H.: Bingraph: Discovering mutant malware using hierarchical semantic signatures. In: Malicious and Unwanted Software (MALWARE), 2012 7th International Conference on, pp. 104\u2013111. IEEE (2012)","DOI":"10.1109\/MALWARE.2012.6461015"},{"key":"273_CR89","doi-asserted-by":"crossref","unstructured":"Lakhotia, A., Preda, M.D., Giacobazzi, R.: Fast location of similar code fragments using semantic \u2019juice\u2019. In: Proceedings of the 2nd ACM SIGPLAN Program Protection and Reverse Engineering Workshop, p.\u00a05. ACM (2013)","DOI":"10.1145\/2430553.2430558"},{"issue":"3","key":"273_CR90","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1145\/185403.185412","volume":"26","author":"CE Landwehr","year":"1994","unstructured":"Landwehr, C.E., Bull, A.R., McDermott, J.P., Choi, W.S.: A taxonomy of computer program security flaws. ACM Comput. Surv. (CSUR) 26(3), 211\u2013254 (1994)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"273_CR91","unstructured":"Langeder, S.: Towards Dynamic Attack Recognition for SIEM. Ph.D. thesis, St. Poelten University of Applied Sciences (2014)"},{"key":"273_CR92","first-page":"707","volume":"10","author":"VI Levenshtein","year":"1966","unstructured":"Levenshtein, V.I.: Binary codes capable of correcting deletions, insertions, and reversals. Sov. Phys. Doklady 10, 707\u2013710 (1966)","journal-title":"Sov. Phys. Doklady"},{"key":"273_CR93","doi-asserted-by":"crossref","unstructured":"Li, F., Lai, A., Ddl, D.: Evidence of advanced persistent threat: A case study of malware for political espionage. In: Malicious and Unwanted Software (MALWARE), 2011 6th International Conference on, pp. 102\u2013109. IEEE (2011)","DOI":"10.1109\/MALWARE.2011.6112333"},{"key":"273_CR94","doi-asserted-by":"publisher","unstructured":"Line, M.B., Zand, A., Stringhini, G., Kemmerer, R.: Targeted Attacks Against Industrial Control Systems: Is the Power Industry Prepared? pp. 13\u201322. ACM Press (2014). doi: 10.1145\/2667190.2667192","DOI":"10.1145\/2667190.2667192"},{"key":"273_CR95","doi-asserted-by":"crossref","unstructured":"Luo, X., Chan, E.W., Chang, R.K.: Vanguard: a new detection scheme for a class of TCP-targeted denial-of-service attacks. In: Network Operations and Management Symposium, 2006. NOMS 2006. 10th IEEE\/IFIP, pp. 507\u2013518. IEEE (2006)","DOI":"10.1109\/NOMS.2006.1687579"},{"key":"273_CR96","unstructured":"MacDonald, N.: Is Antivirus Obsolete? http:\/\/blogs.gartner.com\/neil_macdonald\/2012\/09\/13\/is-antivirus-obsolete\/ . Accessed 29 July 2015"},{"key":"273_CR97","doi-asserted-by":"crossref","unstructured":"Mankin, J., Kaeli, D.: DIONE: a flexible disk monitoring and analysis framework. In: Research in Attacks, Intrusions, and Defenses, pp. 127\u2013146. Springer, New York (2012)","DOI":"10.1007\/978-3-642-33338-5_7"},{"key":"273_CR98","doi-asserted-by":"crossref","unstructured":"Mathew, S., Giomundo, R., Upadhyaya, S., Sudit, M., Stotz, A.: Understanding multistage attacks by attack-track based visualization of heterogeneous event streams. In: Proceedings of the 3rd International Workshop on Visualization for Computer Security, pp. 1\u20136. ACM (2006)","DOI":"10.1145\/1179576.1179578"},{"key":"273_CR99","doi-asserted-by":"crossref","unstructured":"Mathew, S., Upadhyaya, S., Sudit, M., Stotz, A.: Situation awareness of multistage cyber attacks by semantic event fusion. In: Military Communications Conference, 2010-MILCOM 2010, pp. 1286\u20131291. IEEE (2010)","DOI":"10.1109\/MILCOM.2010.5680121"},{"issue":"10","key":"273_CR100","first-page":"2004","volume":"10","author":"DL McGuinness","year":"2004","unstructured":"McGuinness, D.L., Van Harmelen, F.: OWL web ontology language overview. W3C Recomm. 10(10), 2004 (2004)","journal-title":"W3C Recomm."},{"key":"273_CR101","doi-asserted-by":"crossref","unstructured":"Meier, M.: A model for the semantics of attack signatures in misuse detection systems. In: Information Security, pp. 158\u2013169. Springer, New York (2004)","DOI":"10.1007\/978-3-540-30144-8_14"},{"key":"273_CR102","doi-asserted-by":"crossref","unstructured":"Miles, C., Lakhotia, A., LeDoux, C., Newsom, A., Notani, V.: VirusBattle: State-of-the-art malware analysis for better cyber threat intelligence. In: Resilient Control Systems (ISRCS), 2014 7th International Symposium on, pp. 1\u20136. IEEE (2014)","DOI":"10.1109\/ISRCS.2014.6900103"},{"key":"273_CR103","unstructured":"Mills, E.: A who\u2019s who of Mideast-targeted malware. http:\/\/www.cnet.com\/news\/a-whos-who-of-mideast-targeted-malware\/ . Accessed 18 Sept 2015"},{"key":"273_CR104","unstructured":"MIT Lincoln Laboratory: DARPA Intrusion Detection Evaluation. http:\/\/www.ll.mit.edu\/ideval\/data\/ . Accessed 29 July 2015"},{"key":"273_CR105","unstructured":"MITRE Corporation: CAPEC - Common Attack Pattern Enumeration and Classification (CAPEC). https:\/\/capec.mitre.org\/ . Accessed 22 Sept 2015"},{"key":"273_CR106","unstructured":"MITRE Corporation: Common Event Expression: CEE, A Standard Log Language for Event Interoperability in Electronic Systems. https:\/\/cee.mitre.org\/ . Accessed 29 July 2015"},{"key":"273_CR107","unstructured":"MITRE Corporation: CVE - Common Vulnerabilities and Exposures (CVE). https:\/\/cve.mitre.org\/ . Accessed 22 Sept 2015"},{"key":"273_CR108","unstructured":"MITRE Corporation: CWE - Common Weakness Enumeration. https:\/\/cwe.mitre.org\/ . Accessed 22 Sept 2015"},{"key":"273_CR109","unstructured":"MITRE Corporation: STIX - Structured Threat Information Expression | STIX Project Documentation. https:\/\/stixproject.github.io\/ . Accessed 22 Sept 2015"},{"key":"273_CR110","doi-asserted-by":"crossref","unstructured":"M\u00fcnz, G., Carle, G.: Real-time analysis of flow data for network attack detection. In: Integrated Network Management, 2007. IM\u201907. 10th IFIP\/IEEE International Symposium on, pp. 100\u2013108. IEEE (2007)","DOI":"10.1109\/INM.2007.374774"},{"key":"273_CR111","volume-title":"Cybersecurity: Managing Systems, Conducting Testing, and Investigating Intrusions","author":"TJ Mowbray","year":"2013","unstructured":"Mowbray, T.J.: Cybersecurity: Managing Systems, Conducting Testing, and Investigating Intrusions. Wiley, New York (2013)"},{"key":"273_CR112","unstructured":"Munsey, C.: Economic Espionage: Competing For Trade By Stealing Industrial Secrets. https:\/\/leb.fbi.gov\/2013\/october-november\/economic-espionage-competing-for-trade-by-stealing-industrial-secrets . Accessed 15 Sept 2015"},{"key":"273_CR113","doi-asserted-by":"crossref","unstructured":"Ou, X., Rajagopalan, R., Sakthivelmurugan, S.: A practical approach to modeling uncertainty in intrusion analysis. In: Technical Report, Department of Computing and Information Sciences, Kansas State University(2008)","DOI":"10.1109\/ACSAC.2009.53"},{"key":"273_CR114","doi-asserted-by":"crossref","unstructured":"Payne, B.D., Carbone, M., Sharif, M., Lee, W.: Lares: An architecture for secure active monitoring using virtualization. In: Security and Privacy, 2008. SP 2008. IEEE Symposium on, pp. 233\u2013247. IEEE (2008)","DOI":"10.1109\/SP.2008.24"},{"key":"273_CR115","doi-asserted-by":"crossref","unstructured":"Perez-Botero, D., Szefer, J., Lee, R.B.: Characterizing hypervisor vulnerabilities in cloud computing servers. In: Proceedings of the 2013 International Workshop on Security in Cloud Computing, pp. 3\u201310. ACM (2013)","DOI":"10.1145\/2484402.2484406"},{"key":"273_CR116","doi-asserted-by":"crossref","unstructured":"Peshkin, L.: Structure induction by lossless graph compression. arXiv:cs\/0703132 (2007)","DOI":"10.1109\/DCC.2007.73"},{"key":"273_CR117","doi-asserted-by":"crossref","unstructured":"Raskin, V., Hempelmann, C.F., Triezenberg, K.E., Nirenburg, S.: Ontology in information security: a useful theoretical foundation and methodological tool. In: Proceedings of the 2001 Workshop on New Security Paradigms, pp. 53\u201359. ACM (2001)","DOI":"10.1145\/508171.508180"},{"key":"273_CR118","unstructured":"Raywood, D.: Failure to detect Flame marks the end of signaturebased antivirus. http:\/\/www.scmagazineuk.com\/failure-to-detect-flame-marks-the-end-of-signature-based-anti-virus\/article\/243505\/ . Accessed 29 July 2015"},{"key":"273_CR119","doi-asserted-by":"crossref","unstructured":"Razzaq, A., Ahmed, H.F., Hur, A., Haider, N.: Ontology based application level intrusion detection system by using bayesian filter. In: Computer, Control and Communication, 2009. IC4 2009. 2nd International Conference on, pp. 1\u20136. IEEE (2009)","DOI":"10.1109\/IC4.2009.4909223"},{"key":"273_CR120","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1016\/j.cose.2014.05.005","volume":"45","author":"A Razzaq","year":"2014","unstructured":"Razzaq, A., Anwar, Z., Ahmad, H.F., Latif, K., Munir, F.: Ontology for attack detection: an intelligent approach to web application security. Comput. Secur. 45, 124\u2013146 (2014). doi: 10.1016\/j.cose.2014.05.005","journal-title":"Comput. Secur."},{"key":"273_CR121","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.ins.2013.08.007","volume":"254","author":"A Razzaq","year":"2014","unstructured":"Razzaq, A., Latif, K., Ahmad, H.F., Hur, A., Anwar, Z., Bloodsworth, P.C.: Semantic security against web application attacks. Inf. Sci. 254, 19\u201338 (2014). doi: 10.1016\/j.ins.2013.08.007","journal-title":"Inf. Sci."},{"key":"273_CR122","unstructured":"Respect-IT: Kaos tutorial. http:\/\/www.objectiver.com\/fileadmin\/download\/documents\/KaosTutorial . Accessed 27 July 2015"},{"key":"273_CR123","unstructured":"Rieck, K.: Malheur - Automatic Analysis of Malware Behavior. http:\/\/www.mlsec.org\/malheur\/ . Accessed 27 July 2015"},{"issue":"4","key":"273_CR124","doi-asserted-by":"crossref","first-page":"639","DOI":"10.3233\/JCS-2010-0410","volume":"19","author":"K Rieck","year":"2011","unstructured":"Rieck, K., Trinius, P., Willems, C., Holz, T.: Automatic analysis of malware behavior using machine learning. J. Comput. Secur. 19(4), 639\u2013668 (2011)","journal-title":"J. Comput. Secur."},{"key":"273_CR125","doi-asserted-by":"crossref","unstructured":"Ristenpart, T., Tromer, E., Shacham, H., Savage, S.: Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. In: Proceedings of the 16th ACM conference on Computer and communications security, pp. 199\u2013212. ACM (2009)","DOI":"10.1145\/1653662.1653687"},{"key":"273_CR126","unstructured":"Russinovich, M.: Process Monitor. https:\/\/technet.microsoft.com\/en-us\/library\/bb896645.aspx . Accessed 29 July 2015"},{"key":"273_CR127","doi-asserted-by":"crossref","unstructured":"Sadighian, A., Zargar, S.T., Fernandez, J.M., Lemay, A.: Semantic-based context-aware alert fusion for distributed Intrusion Detection Systems. In: 2013 International Conference on, Risks and Security of Internet and Systems (CRiSIS), pp. 1\u20136. IEEE (2013)","DOI":"10.1109\/CRiSIS.2013.6766352"},{"issue":"2","key":"273_CR128","doi-asserted-by":"publisher","first-page":"39","DOI":"10.5121\/ijnsa.2010.2204","volume":"2","author":"S Sangeetha","year":"2010","unstructured":"Sangeetha, S., Vaidehi, V.: Fuzzy aided application layer semantic intrusion detection system - FASIDS. Int. J. Netw. Secur. Appl. 2(2), 39\u201356 (2010). doi: 10.5121\/ijnsa.2010.2204","journal-title":"Int. J. Netw. Secur. Appl."},{"issue":"1","key":"273_CR129","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1504\/IJSN.2008.016199","volume":"3","author":"W Scheirer","year":"2008","unstructured":"Scheirer, W., Chuah, M.C.: Syntax vs. semantics: competing approaches to dynamic network intrusion detection. Int. J. Secure. Netw. 3(1), 24\u201335 (2008)","journal-title":"Int. J. Secure. Netw."},{"key":"273_CR130","unstructured":"Seculert: Mahdi - The Cyberwar Savior? http:\/\/www.seculert.com\/blog\/2012\/07\/mahdi-cyberwar-savior.html . Accessed 29 July 2015"},{"issue":"1","key":"273_CR131","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1145\/584091.584093","volume":"5","author":"CE Shannon","year":"2001","unstructured":"Shannon, C.E.: A mathematical theory of communication. ACM SIGMOBILE Mob. Comput. Commun. Rev. 5(1), 3\u201355 (2001)","journal-title":"ACM SIGMOBILE Mob. Comput. Commun. Rev."},{"key":"273_CR132","doi-asserted-by":"crossref","unstructured":"Sharif, M., Yegneswaran, V., Saidi, H., Porras, P., Lee, W.: Eureka: A framework for enabling static malware analysis. In: Computer security-ESORICS 2008, pp. 481\u2013500. Springer, New York (2008)","DOI":"10.1007\/978-3-540-88313-5_31"},{"key":"273_CR133","volume-title":"Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software","author":"M Sikorski","year":"2012","unstructured":"Sikorski, M., Honig, A.: Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software. No Starch Press, San Francisco (2012)"},{"key":"273_CR134","first-page":"54","volume":"1","author":"AK Sood","year":"2013","unstructured":"Sood, A.K., Enbody, R.J.: Targeted cyberattacks: a superset of advanced persistent threats. IEEE Secur. Privacy 1, 54\u201361 (2013)","journal-title":"IEEE Secur. Privacy"},{"issue":"3","key":"273_CR135","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1109\/SURV.2010.032210.00054","volume":"12","author":"A Sperotto","year":"2010","unstructured":"Sperotto, A., Schaffrath, G., Sadre, R., Morariu, C., Pras, A., Stiller, B.: An overview of IP flow-based intrusion detection. IEEE Commun. Surv. Tutorials 12(3), 343\u2013356 (2010). doi: 10.1109\/SURV.2010.032210.00054","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"273_CR136","unstructured":"Stanford Center for Biomedical Informatics Research: Prot\u00e9g\u00e9. http:\/\/protege.stanford.edu\/ . Accessed 29 July 2015"},{"key":"273_CR137","doi-asserted-by":"crossref","unstructured":"Stotz, A., Sudit, M.: INformation fusion engine for real-time decision-making (INFERD): a perceptual system for cyber attack tracking. In: Information Fusion, 2007 10th International Conference on, pp. 1\u20138. IEEE (2007)","DOI":"10.1109\/ICIF.2007.4408113"},{"key":"273_CR138","doi-asserted-by":"publisher","unstructured":"Strasburg, C., Basu, S., Wong, J.S.: S-MAIDS: A Semantic Model for Automated Tuning, Correlation, and Response Selection in Intrusion Detection Systems. pp. 319\u2013328. IEEE (2013). doi: 10.1109\/COMPSAC.2013.57","DOI":"10.1109\/COMPSAC.2013.57"},{"key":"273_CR139","unstructured":"Symantec: Regin: Top-tier espionage tool enables stealthy surveillance. http:\/\/www.symantec.com\/connect\/blogs\/regin-top-tier-espionage-tool-enables-stealthy-surveillance . Accessed 15 Sept 2015"},{"issue":"3","key":"273_CR140","doi-asserted-by":"publisher","first-page":"190","DOI":"10.5121\/ijnsa.2010.2313","volume":"2","author":"U Thakar","year":"2010","unstructured":"Thakar, U., Dagdee, N., Varma, S.: Pattern analysis and signature extraction for intrusion attacks on web services. Int. J. Netw. Secur. Appl. 2(3), 190\u2013205 (2010). doi: 10.5121\/ijnsa.2010.2313","journal-title":"Int. J. Netw. Secur. Appl."},{"key":"273_CR141","unstructured":"The Hacker News: Harkonnen Operation\u2013Malware Campaign that Went Undetected for 12 Years. http:\/\/thehackernews.com\/2014\/09\/harkonnen-operation-malware-campaign_16.html . Accessed 29 July 2015"},{"key":"273_CR142","unstructured":"ThreatTrack Security: Dynamic Malware Analysis Tools, Malware Sandbox - ThreatAnalyzer - ThreatTrack Security. http:\/\/www.threattracksecurity.com\/enterprise-security\/malware-analysis-sandbox-software.aspx . Accessed 29 July 2015"},{"key":"273_CR143","doi-asserted-by":"crossref","unstructured":"Totel, E., Vivinis, B., M\u00e9, L.: A language driven intrusion detection system for event and alert correlation. In: Proceedings at the 19th IFIP International Information Security Conference, Kluwer Academic, Toulouse, pp. 209\u2013224. Springer, New York (2004)","DOI":"10.1007\/1-4020-8143-X_14"},{"key":"273_CR144","unstructured":"Trammell, B., Claise, B.: Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of Flow Information. https:\/\/tools.ietf.org\/html\/rfc7011 . Accessed 29 July 2015"},{"key":"273_CR145","unstructured":"Trinius, P., Willems, C., Holz, T., Rieck, K.: A malware instruction set for behavior-based analysis. Tech. Rep. TR-2009-07, University of Mannheim (2009)"},{"key":"273_CR146","unstructured":"University of California: KDD Cup 1999 Data. http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html . Accessed 29 July 2015"},{"key":"273_CR147","unstructured":"University of Toronto: GRL Syntax. http:\/\/www.cs.toronto.edu\/km\/GRL\/grl_syntax.html . Accessed 27 July 2015"},{"key":"273_CR148","doi-asserted-by":"crossref","unstructured":"Vance, A.: Flow based analysis of Advanced Persistent Threats detecting targeted attacks in cloud computing. In: Infocommunications Science and Technology, 2014 1st International Scientific-Practical Conference Problems of, pp. 173\u2013176. IEEE (2014)","DOI":"10.1109\/INFOCOMMST.2014.6992342"},{"key":"273_CR149","unstructured":"Vanderwende, L.H., Loritz, D.: The analysis of noun sequences using semantic information extracted from on-line dictionaries. Ph.D. thesis, Georgetown University (1995)"},{"key":"273_CR150","unstructured":"W3C: Semantic web. http:\/\/www.w3.org\/standards\/semanticweb\/ . Accessed 29 July 2015"},{"key":"273_CR151","unstructured":"W3C: SOAP Version 1.2 Part 1: Messaging Framework (Second Edition). http:\/\/www.w3.org\/TR\/soap12\/ . Accessed 22 July 2015"},{"key":"273_CR152","unstructured":"W3C: SPARQL 1.1 Overview. http:\/\/www.w3.org\/TR\/sparql11-overview\/ . Accessed 29 July 2015"},{"key":"273_CR153","doi-asserted-by":"crossref","unstructured":"Wagner, D., Soto, P.: Mimicry attacks on host-based intrusion detection systems. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 255\u2013264. ACM (2002)","DOI":"10.1145\/586110.586145"},{"key":"273_CR154","unstructured":"Wagner, M., Fischer, F., Luh, R., Haberson, A., Rind, A., Keim, D., Aigner, W., Borgo, R., Ganovelli, F., Viola, I.: A Survey of Visualization Systems for Malware Analysis. In: EG Conference on Visualization (EuroVis)-STARs, pp. 105\u2013125. EuroGraphics (2015)"},{"key":"273_CR155","doi-asserted-by":"publisher","unstructured":"Wang, R., Jia, X., Nie, C.: A Behavior Feature Generation Method for Obfuscated Malware Detection. pp. 470\u2013474. IEEE (2012). doi: 10.1109\/CSSS.2012.124","DOI":"10.1109\/CSSS.2012.124"},{"key":"273_CR156","doi-asserted-by":"publisher","unstructured":"W\u00fcchner, T., Pretschner, A., Ochoa, M.: DAVAST: data-centric system level activity visualization. pp. 25\u201332. ACM Press (2014) doi: 10.1145\/2671491.2671499","DOI":"10.1145\/2671491.2671499"},{"key":"273_CR157","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"2","author":"C Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using cwsandbox. IEEE Secur. Privacy 2, 32\u201339 (2007)","journal-title":"IEEE Secur. Privacy"},{"key":"273_CR158","series-title":"Foundations of computing","volume-title":"The formal semantics of programming languages: an introduction","author":"G Winskel","year":"2001","unstructured":"Winskel, G.: The formal semantics of programming languages: an introduction. Foundations of computing, 5th edn. MIT Press, Cambridge, MA (2001)","edition":"5"},{"key":"273_CR159","doi-asserted-by":"crossref","unstructured":"Xu, H., Du, W., Chapin, S.J.: Context sensitive anomaly monitoring of process control flow to detect mimicry attacks and impossible paths. In: RAID, pp. 21\u201338. Springer, New York (2004)","DOI":"10.1007\/978-3-540-30143-1_2"},{"key":"273_CR160","unstructured":"Yan, W., Hou, E., Ansari, N.: Extracting attack knowledge using principal-subordinate consequence tagging case grammar and alerts semantic networks. In: Local Computer Networks, 2004. 29th Annual IEEE International Conference on, pp. 110\u2013117. IEEE (2004)"},{"key":"273_CR161","unstructured":"Yan, W., Hou, E., Ansari, N.: A description logic based approach for IDS security information management. In: Advances in Wired and Wireless Communication, 2005 IEEE\/Sarnoff Symposium on, pp. 25\u201328. IEEE (2005)"},{"key":"273_CR162","unstructured":"Yan, X., Han, J.: gspan: graph-based substructure pattern mining. In: Data Mining, 2002. ICDM 2003. Proceedings of 2002 IEEE International Conference on, pp. 721\u2013724. IEEE (2002)"},{"key":"273_CR163","doi-asserted-by":"crossref","unstructured":"Zarras, A., Papadogiannakis, A., Gawlik, R., Holz, T.: Automated generation of models for fast and precise detection of HTTP-based malware. In: 2014 12th Annual International Conference on, Privacy, Security and Trust (PST), pp. 249\u2013256. IEEE (2014)","DOI":"10.1109\/PST.2014.6890946"},{"key":"273_CR164","doi-asserted-by":"crossref","unstructured":"Zhang, Q., Reeves, D.S., Ning, P., Iyer, S.P.: Analyzing network traffic to detect self-decrypting exploit code. In: Proceedings of the 2nd ACM Symposium on Information, Computer and Communications security, pp. 4\u201312. ACM (2007)","DOI":"10.1145\/1229285.1229291"},{"key":"273_CR165","unstructured":"Zhu, B., Ghorbani, A.A.: Alert correlation for extracting attack strategies. Ph.D. thesis, Citeseer (2005)"},{"key":"273_CR166","doi-asserted-by":"crossref","unstructured":"Zimmer, D., Unland, R.: On the semantics of complex events in active database management systems. In: 1999, Proceedings of 15th International Conference on, Data Engineering, pp. 392\u2013399. IEEE (1999)","DOI":"10.1109\/ICDE.1999.754955"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0273-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-016-0273-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0273-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0273-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,2]],"date-time":"2025-06-02T23:47:28Z","timestamp":1748908048000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-016-0273-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,5,2]]},"references-count":166,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2017,2]]}},"alternative-id":["273"],"URL":"https:\/\/doi.org\/10.1007\/s11416-016-0273-3","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,5,2]]}}}