{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T05:09:06Z","timestamp":1780463346595,"version":"3.54.1"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2017,8,24]],"date-time":"2017-08-24T00:00:00Z","timestamp":1503532800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,8,24]],"date-time":"2017-08-24T00:00:00Z","timestamp":1503532800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1111925"],"award-info":[{"award-number":["1111925"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-12-1-0286"],"award-info":[{"award-number":["W911NF-12-1-0286"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,5]]},"DOI":"10.1007\/s11416-017-0304-8","type":"journal-article","created":{"date-parts":[[2017,8,24]],"date-time":"2017-08-24T11:58:52Z","timestamp":1503575932000},"page":"181-193","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Multi-context features for detecting malicious programs"],"prefix":"10.1007","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1916-3275","authenticated-orcid":false,"given":"Moustafa","family":"Saleh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tao","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shouhuai","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,8,24]]},"reference":[{"key":"304_CR1","doi-asserted-by":"crossref","unstructured":"Ahmadi, M., Giacinto, G., Ulyanov, D., Semenov, S., Trofimov, M.: Novel feature extraction, selection and fusion for effective malware family classification. ArXiv e-prints (2015)","DOI":"10.1145\/2857705.2857713"},{"key":"304_CR2","doi-asserted-by":"publisher","unstructured":"Ahmed, F., Hameed, H., Shafiq, M.Z., Farooq, M.: Using spatio-temporal information in api calls with machine learning algorithms for malware detection. In: Proceedings of the 2Nd ACM Workshop on Security and Artificial Intelligence, AISec \u201909, pp. 55\u201362. ACM, New York, NY, USA (2009). doi:\n                    10.1145\/1654988.1655003","DOI":"10.1145\/1654988.1655003"},{"key":"304_CR3","unstructured":"aldeid.com: PEiD. \n                    http:\/\/www.aldeid.com\/wiki\/PEiD\n                    \n                  . Accessed: Feb. 8th, 2014"},{"key":"304_CR4","doi-asserted-by":"crossref","unstructured":"Anderson, B., Storlie, C., Lane, T.: Improving malware classification: bridging the static\/dynamic gap. In: Proceedings of the 5th ACM workshop on Security and artificial intelligence, pp. 3\u201314. ACM (2012)","DOI":"10.1145\/2381896.2381900"},{"key":"304_CR5","unstructured":"AV-Comparative: File detection test of malicious software. (March 2015)"},{"key":"304_CR6","unstructured":"CNET: lenovo hit by lawsuit over superfish adware. \n                    http:\/\/www.cnet.com\/news\/lenovo-hit-by-lawsuit-over-superfish-adware\/\n                    \n                  . Accessed 9 December 2015"},{"issue":"3","key":"304_CR7","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1145\/2508148.2485970","volume":"41","author":"J Demme","year":"2013","unstructured":"Demme, J., Maycock, M., Schmitz, J., Tang, A., Waksman, A., Sethumadhavan, S., Stolfo, S.: On the feasibility of online malware detection with performance counters. SIGARCH Comput. Archit. News 41(3), 559\u2013570 (2013). doi:\n                    10.1145\/2508148.2485970","journal-title":"SIGARCH Comput. Archit. News"},{"key":"304_CR8","doi-asserted-by":"publisher","unstructured":"Ding, Y., Dai, W., Yan, S., Zhang, Y.: Control flow-based opcode behavior analysis for malware detection. Computers & Security 44, 65\u201374 (2014). doi:\n                    10.1016\/j.cose.2014.04.003\n                    \n                  . \n                    http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404814000558","DOI":"10.1016\/j.cose.2014.04.003"},{"key":"304_CR9","unstructured":"Hiramoto, K.: Technical account manager at VirusTotal. Personal Communication. Sept. 24th, 2014"},{"key":"304_CR10","doi-asserted-by":"publisher","unstructured":"Huang, J., Zhang, X., Tan, L., Wang, P., Liang, B.: Asdroid: Detecting stealthy behaviors in android applications by user interface and program behavior contradiction. In: Proceedings of the 36th International Conference on Software Engineering, ICSE 2014, pp. 1036\u20131046. ACM, New York, NY, USA (2014). doi:\n                    10.1145\/2568225.2568301","DOI":"10.1145\/2568225.2568301"},{"key":"304_CR11","doi-asserted-by":"publisher","unstructured":"Kang, B., Han, K.S., Kang, B., Im, E.G.: Malware categorization using dynamic mnemonic frequency analysis with redundancy filtering. Digit. Investig. 11(4), 323\u2013335 (2014). doi:\n                    10.1016\/j.diin.2014.06.003\n                    \n                  . \n                    http:\/\/www.sciencedirect.com\/science\/article\/pii\/S1742287614000772","DOI":"10.1016\/j.diin.2014.06.003"},{"key":"304_CR12","doi-asserted-by":"publisher","unstructured":"Kolter, J.Z., Maloof, M.A.: Learning to detect malicious executables in the wild. In: Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD \u201904, pp. 470\u2013478. ACM, New York, NY, USA (2004). doi:\n                    10.1145\/1014052.1014105","DOI":"10.1145\/1014052.1014105"},{"key":"304_CR13","doi-asserted-by":"crossref","unstructured":"Kompalli, S.: Using existing hardware services for malware detection. In: Security and Privacy Workshops (SPW), 2014 IEEE, pp. 204\u2013208. IEEE (2014)","DOI":"10.1109\/SPW.2014.49"},{"key":"304_CR14","unstructured":"Labs, K.: The great bank robbery: the carbanak apt. \n                    http:\/\/securelist.com\/blog\/research\/68732\/the-great-bank-robbery-the-carbanak-apt\/\n                    \n                  . Accessed 25 Mar 2015"},{"key":"304_CR15","unstructured":"Labs, M.: Mcafee labs threats report for february 2015. \n                    http:\/\/www.mcafee.com\/us\/resources\/reports\/rp-quarterly-threat-q4-2014.pdf\n                    \n                  . Accessed 25 Mar 2015"},{"key":"304_CR16","unstructured":"M0SA: Syp.01: Bypassing online dynamic analysis systems. Valhalla ezine, issue #4, November 2013. \n                    http:\/\/vxheaven.org\/lib\/vmo04.html"},{"key":"304_CR17","unstructured":"Martinez, E.: Software engineer at VirusTotal. Personal Communication. Dec. 25th, 2014"},{"issue":"14","key":"304_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10207-015-0297-6","volume":"15","author":"Q Miao","year":"2015","unstructured":"Miao, Q., Liu, J., Cao, Y., Song, J.: Malware detection using bilayer behavior abstraction and improved one-class support vector machines. Int. J. Inf. Secur. 15(14), 1\u201319 (2015). doi:\n                    10.1007\/s10207-015-0297-6","journal-title":"Int. J. Inf. Secur."},{"key":"304_CR19","unstructured":"Microsoft: Microsoft pe and coff specification. \n                    https:\/\/msdn.microsoft.com\/en-us\/windows\/hardware\/gg463119.aspx\n                    \n                  . Accessed 20 Nov 2015"},{"key":"304_CR20","unstructured":"pefile: \n                    https:\/\/github.com\/erocarrera\/pefile\n                    \n                  . Accessed 6 June 2015"},{"issue":"14","key":"304_CR21","doi-asserted-by":"publisher","first-page":"1941","DOI":"10.1016\/j.patrec.2008.06.016","volume":"29","author":"R Perdisci","year":"2008","unstructured":"Perdisci, R., Lanzi, A., Lee, W.: Classification of packed executables for accurate computer virus detection. Pattern Recogn. Lett. 29(14), 1941\u20131946 (2008). doi:\n                    10.1016\/j.patrec.2008.06.016","journal-title":"Pattern Recogn. Lett."},{"key":"304_CR22","unstructured":"Quist, D., Smith, V., Computing, O.: Detecting the presence of virtual machines using the local data table. Offens. Comput. (2006)"},{"key":"304_CR23","doi-asserted-by":"crossref","unstructured":"Ravula, R.R., Liszka, K.J., Chan, C.C.: Learning attack features from static and dynamic analysis of malware. In: Knowledge Discovery, Knowledge Engineering and Knowledge Management, pp. 109\u2013125. Springer (2013)","DOI":"10.1007\/978-3-642-37186-8_7"},{"key":"304_CR24","doi-asserted-by":"publisher","unstructured":"Saleh, M., Ratazzi, E., Xu, S.: Instructions-based detection of sophisticated obfuscation and packing. In: Military Communications Conference (MILCOM), 2014 IEEE, pp. 1\u20136 (2014). doi:\n                    10.1109\/MILCOM.2014.9","DOI":"10.1109\/MILCOM.2014.9"},{"issue":"4","key":"304_CR25","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1049\/iet-ifs.2010.0136","volume":"5","author":"ME Saleh","year":"2011","unstructured":"Saleh, M.E., Mohamed, A.B., Nabi, A.A.: Eigenviruses for metamorphic virus recognition. IET Inf. Secur. 5(4), 191\u2013198 (2011)","journal-title":"IET Inf. Secur."},{"issue":"9","key":"304_CR26","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1016\/S1361-3723(14)70531-7","volume":"2014","author":"Z Salehi","year":"2014","unstructured":"Salehi, Z., Sami, A., Ghiasi, M.: Using feature generation from API calls for malware detection. Comput. Fraud Secur. 2014(9), 9\u201318 (2014)","journal-title":"Comput. Fraud Secur."},{"key":"304_CR27","unstructured":"Sandbox, C.: Cuckoo sandbox: automated malware analysis. Accessed 6 June 2015"},{"key":"304_CR28","doi-asserted-by":"crossref","unstructured":"Santos, I., Devesa, J., Brezo, F., Nieves, J., Bringas, P.G.: Opem: a static-dynamic approach for machine-learning-based malware detection. In: International Joint Conference CISIS12-ICEUTE\u2019 12-SOCO\u2019 12 Special Sessions, pp. 271\u2013280. Springer (2013)","DOI":"10.1007\/978-3-642-33018-6_28"},{"key":"304_CR29","doi-asserted-by":"publisher","unstructured":"Santos, I., Ugarte-Pedrero, X., Sanz, B., Laorden, C., Bringas, P.G.: Collective classification for packed executable identification. In: Proceedings of the 8th Annual Collaboration, Electronic Messaging, Anti-Abuse and Spam Conference, CEAS \u201911, pp. 23\u201330. ACM, New York, NY, USA (2011). doi:\n                    10.1145\/2030376.2030379","DOI":"10.1145\/2030376.2030379"},{"key":"304_CR30","doi-asserted-by":"crossref","unstructured":"Saxe, J., Berlin, K.: Deep neural network based malware detection using two dimensional binary program features. arXiv preprint \n                    arXiv:1508.03096\n                    \n                   (2015)","DOI":"10.1109\/MALWARE.2015.7413680"},{"key":"304_CR31","unstructured":"Schultz, M.G., Eskin, E., Zadok, E., Stolfo, S.J.: Data mining methods for detection of new malicious executables. In: Proceedings 2001 IEEE Symposium on Security and Privacy, 2001. S&P 2001, pp. 38\u201349. IEEE (2001)"},{"key":"304_CR32","doi-asserted-by":"crossref","unstructured":"Shafiq, M., Tabish, S., Farooq, M.: PE-probe: leveraging packer detection and structural information to detect malicious portable executables. In: Proceedings of the Virus Bulletin Conference (VB), pp. 29\u201333 (2009)","DOI":"10.1007\/978-3-642-04342-0_7"},{"key":"304_CR33","doi-asserted-by":"publisher","unstructured":"Shafiq, M., Tabish, S., Mirza, F., Farooq, M.: PE-Miner: Mining structural information to detect malicious executables in real-time. In: E.\u00a0Kirda, S.\u00a0Jha, D.\u00a0Balzarotti (eds.) Recent Advances in Intrusion Detection. Lecture Notes in Computer Science, vol. 5758, pp. 121\u2013141. Springer, Berlin Heidelberg (2009). doi:\n                    10.1007\/978-3-642-04342-0_7","DOI":"10.1007\/978-3-642-04342-0_7"},{"issue":"3","key":"304_CR34","doi-asserted-by":"publisher","first-page":"589","DOI":"10.1007\/s10115-011-0393-5","volume":"30","author":"F Shahzad","year":"2012","unstructured":"Shahzad, F., Farooq, M.: Elf-miner: using structural knowledge and data mining methods to detect new (linux) malicious executables. Knowl. Inf. Syst. 30(3), 589\u2013612 (2012). doi:\n                    10.1007\/s10115-011-0393-5","journal-title":"Knowl. Inf. Syst."},{"key":"304_CR35","doi-asserted-by":"crossref","unstructured":"Storlie, C., Anderson, B., Vander Wiel, S., Quist, D., Hash, C., Brown, N.: Stochastic identification of malware with dynamic traces. ArXiv e-prints (2014)","DOI":"10.1214\/13-AOAS703"},{"key":"304_CR36","doi-asserted-by":"crossref","unstructured":"Tang, A., Sethumadhavan, S., Stolfo, S.J.: Unsupervised anomaly-based malware detection using hardware features. CoRR \n                    arXiv:1403.1631\n                    \n                   (2014)","DOI":"10.1007\/978-3-319-11379-1_6"},{"key":"304_CR37","doi-asserted-by":"publisher","unstructured":"Tian, R., Islam, M., Batten, L., Versteeg, S.: Differentiating malware from cleanware using behavioural analysis. In: 2010 5th International Conference on Malicious and Unwanted Software (MALWARE), pp. 23\u201330 (2010). doi:\n                    10.1109\/MALWARE.2010.5665796","DOI":"10.1109\/MALWARE.2010.5665796"},{"key":"304_CR38","doi-asserted-by":"publisher","unstructured":"Treadwell, S., Zhou, M.: A heuristic approach for detection of obfuscated malware. In: IEEE International Conference on Intelligence and Security Informatics, 2009 ISI \u201909, pp. 291\u2013299 (2009). doi:\n                    10.1109\/ISI.2009.5137328","DOI":"10.1109\/ISI.2009.5137328"},{"key":"304_CR39","unstructured":"UPX: Upx: The ultimate packer for executables. \n                    http:\/\/upx.sourceforge.net\/\n                    \n                  . Accessed 7 Dec 2015"},{"key":"304_CR40","unstructured":"VirusTotal: \n                    http:\/\/www.VirusTotal.com\/\n                    \n                  . Accessed 6 June 2015"},{"key":"304_CR41","unstructured":"Weka: Weka 3: Data mining software in Java. \n                    http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/\n                    \n                  . Accessed 6 June 2015"},{"key":"304_CR42","doi-asserted-by":"crossref","unstructured":"Yan, G., Brown, N., Kong, D.: Exploring discriminatory features for automated malware classification. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 41\u201361. Springer (2013)","DOI":"10.1007\/978-3-642-39235-1_3"},{"key":"304_CR43","doi-asserted-by":"crossref","unstructured":"You, I., Yim, K.: Malware obfuscation techniques: a brief survey. In: BWCCA, pp. 297\u2013300 (2010)","DOI":"10.1109\/BWCCA.2010.85"},{"key":"304_CR44","volume-title":"Countdown to Zero Day: Stuxnet and the Launch of the World\u2019s First Digital Weapon","author":"K Zetter","year":"2014","unstructured":"Zetter, K.: Countdown to Zero Day: Stuxnet and the Launch of the World\u2019s First Digital Weapon. Crown Publishing Group, New York (2014)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-017-0304-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0304-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0304-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,14]],"date-time":"2020-05-14T08:38:54Z","timestamp":1589445534000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-017-0304-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,24]]},"references-count":44,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,5]]}},"alternative-id":["304"],"URL":"https:\/\/doi.org\/10.1007\/s11416-017-0304-8","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,8,24]]},"assertion":[{"value":"14 November 2016","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 August 2017","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 August 2017","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}