{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:38:12Z","timestamp":1780634292250,"version":"3.54.1"},"reference-count":50,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2017,10,20]],"date-time":"2017-10-20T00:00:00Z","timestamp":1508457600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"European Council International Incoming Fellowship","award":["FP7-PEOPLE-2013-IIF"],"award-info":[{"award-number":["FP7-PEOPLE-2013-IIF"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,8]]},"DOI":"10.1007\/s11416-017-0307-5","type":"journal-article","created":{"date-parts":[[2017,10,20]],"date-time":"2017-10-20T09:47:14Z","timestamp":1508492834000},"page":"213-223","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":58,"title":["Intelligent OS X malware threat detection with code inspection"],"prefix":"10.1007","volume":"14","author":[{"given":"Hamed Haddad","family":"Pajouh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9294-7554","authenticated-orcid":false,"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raouf","family":"Khayami","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,10,20]]},"reference":[{"key":"307_CR1","doi-asserted-by":"crossref","unstructured":"Daryabar, F., Dehghantanha, A., Udzir, N.I.: Investigation of bypassing malware defences and malware detections. In: 2011 7th International Conference on Information Assurance and Security (IAS), p. 1738 (2011)","DOI":"10.1109\/ISIAS.2011.6122815"},{"key":"307_CR2","doi-asserted-by":"crossref","unstructured":"Bisio, F., Gastaldo, P., Meda, C, Nasta, S., Zunino, R.: Machine learning-based system for detecting unseen malicious software. In: Gloria A.D. (eds) Applications in Electronics Pervading Industry, Environment and Society [Internet], p. 915. Springer International Publishing (2016) [cited 2016 Nov 28]. (Lecture Notes in Electrical Engineering). http:\/\/link.springer.com\/chapter\/10.1007\/978-3-319-20227-3_2","DOI":"10.1007\/978-3-319-20227-3_2"},{"key":"307_CR3","unstructured":"Kaspersky Lab: Overall statistics for 2015 [Internet]. Kaspersky Lab, Russia (2016). https:\/\/securelist.com\/files\/2015\/12\/KSB_2015_Statistics_FINAL_EN.pdf"},{"key":"307_CR4","unstructured":"Panda Lab: Pandalabs annual report 2015 [Internet], p. 30. (2016) [cited 2016 Nov 30]. Report No.: 4. http:\/\/www.pandasecurity.com\/mediacenter\/src\/uploads\/2014\/07\/Pandalabs-2015-anual-EN.pdf"},{"key":"307_CR5","unstructured":"Beek, C., Frosst, D., Greve, P., Gund, Y., Moreno, F., Peterson, E., Schmugar, C., Simon, R., Sommer, D., Sun, B., Tiwari, R., Weafer, V.: McAfee Labs Threats Report [Internet], p. 49. McAfee Lab (April 2017). https:\/\/www.mcafee.com\/us\/resources\/reports\/rp-quarterly-threats-mar-2017.pdf"},{"key":"307_CR6","unstructured":"Stack Overflow Developer Survey 2016 Results [Internet]. Stack Overflow. [cited 2016 Nov 28]. http:\/\/stackoverflow.com\/research\/developer-survey-2016"},{"key":"307_CR7","unstructured":"Aquilino, B.I.: FLASHBACK OS X MALWARE. In: Proceedings of Virus Bulletin Conference [Internet], p. 102114. (2012) [cited 2017 Apr 7]. https:\/\/pdfs.semanticscholar.org\/6b7b\/d026676c5e30b42b40f50ed8076b81eb2764.pdf"},{"issue":"3","key":"307_CR8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3003816","volume":"49","author":"J Gardiner","year":"2016","unstructured":"Gardiner, J., Nagaraja, S.: On the security of machine learning in malware C&C detection: a survey. ACM Comput. Surv. 49(3), 1\u201339 (2016)","journal-title":"ACM Comput. Surv."},{"issue":"5","key":"307_CR9","first-page":"110312","volume":"12","author":"M Sun","year":"2017","unstructured":"Sun, M., Li, X., Lui, J.C.S., Ma, R.T.B., Liang, Z.: Monet: a user-oriented behavior-based malware variants detection system for android. IEEE Trans. Inf. Forensics Secur. 12(5), 110312 (2017)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"3","key":"307_CR10","doi-asserted-by":"crossref","first-page":"63146","DOI":"10.1109\/TIFS.2016.2631905","volume":"12","author":"N Nissim","year":"2017","unstructured":"Nissim, N., Cohen, A., Elovici, Y.: ALDOCX: detection of unknown malicious microsoft office documents using designated active learning methods based on new structural feature extraction methodology. IEEE Trans. Inf. Forensics Secur. 12(3), 63146 (2017)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"374","key":"307_CR11","first-page":"193209","volume":"20","author":"M Nauman","year":"2016","unstructured":"Nauman, M., Azam, N., Yao, J.: A three-way decision making approach to malware analysis using probabilistic rough sets. Inf. Sci. 20(374), 193209 (2016)","journal-title":"Inf. Sci."},{"key":"307_CR12","doi-asserted-by":"crossref","first-page":"3350","DOI":"10.1016\/j.cose.2015.03.007","volume":"52","author":"A Fattori","year":"2015","unstructured":"Fattori, A., Lanzi, A., Balzarotti, D., Kirda, E.: Hypervisor-based malware protection with accessminer. Comput. Secur. 52, 3350 (2015)","journal-title":"Comput. Secur."},{"key":"307_CR13","doi-asserted-by":"crossref","first-page":"25166","DOI":"10.1016\/j.cose.2015.04.001","volume":"52","author":"A Mohaisen","year":"2015","unstructured":"Mohaisen, A., Alrawi, O., Mohaisen, M.: AMAL: high-fidelity, behavior-based automated malware analysis and classification. Comput. Secur. 52, 25166 (2015)","journal-title":"Comput. Secur."},{"key":"307_CR14","doi-asserted-by":"crossref","first-page":"37690","DOI":"10.1016\/j.future.2014.06.001","volume":"55","author":"S Huda","year":"2016","unstructured":"Huda, S., Abawajy, J., Alazab, M., Abdollalihian, M., Islam, R., Yearwood, J.: Hybrids of support vector machine wrapper and filter based framework for malware detection. Future Gener. Comput. Syst. 55, 37690 (2016)","journal-title":"Future Gener. Comput. Syst."},{"issue":"13","key":"307_CR15","doi-asserted-by":"crossref","first-page":"584357","DOI":"10.1016\/j.eswa.2014.02.053","volume":"41","author":"N Nissim","year":"2014","unstructured":"Nissim, N., Moskovitch, R., Rokach, L., Elovici, Y.: Novel active learning methods for enhanced PC malware detection in windows OS. Expert Syst. Appl. 41(13), 584357 (2014)","journal-title":"Expert Syst. Appl."},{"key":"307_CR16","unstructured":"Damodaran, A., Troia, F.D., Visaggio, C.A., Austin, T.H., Stamp, M.A.: Comparison of static, dynamic, and hybrid analysis for malware detection. J. Comput. Virol. Hacking Tech. [Internet]. 29 December 2015 [cited 2016 Oct 4]. http:\/\/link.springer.com\/10.1007\/s11416-015-0261-z"},{"issue":"9","key":"307_CR17","doi-asserted-by":"crossref","first-page":"30807","DOI":"10.1109\/TLA.2015.7350062","volume":"13","author":"RJ Mangialardo","year":"2015","unstructured":"Mangialardo, R.J., Duarte, J.C.: Integrating static and dynamic malware analysis using machine learning. IEEE Lat. Am. Trans. 13(9), 30807 (2015)","journal-title":"IEEE Lat. Am. Trans."},{"issue":"3","key":"307_CR18","first-page":"2140","volume":"8","author":"K Shaerpour","year":"2013","unstructured":"Shaerpour, K., Dehghantanha, A., Mahmod, R.: Trends in android malware detection. J. Digit. Forensics Secur. Law. 8(3), 2140 (2013)","journal-title":"J. Digit. Forensics Secur. Law."},{"issue":"2","key":"307_CR19","doi-asserted-by":"crossref","first-page":"998","DOI":"10.1109\/COMST.2014.2386139","volume":"17","author":"P Faruki","year":"2015","unstructured":"Faruki, P., Bharmal, A., Laxmi, V., Ganmoor, V., Gaur, M.S., Conti, M., et al.: Android security: a survey of issues, malware penetration, and defenses. IEEE Commun. Surv. Tutor. 17(2), 998\u20131022 (2015)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"307_CR20","doi-asserted-by":"crossref","first-page":"2237","DOI":"10.1016\/j.diin.2015.02.001","volume":"13","author":"A Feizollah","year":"2015","unstructured":"Feizollah, A., Anuar, N.B., Salleh, R., Wahab, A.W.A.: A review on feature selection in mobile malware detection. Digit. Investig. 13, 2237 (2015)","journal-title":"Digit. Investig."},{"issue":"4","key":"307_CR21","first-page":"789802","volume":"15","author":"G Suarez-Tangil","year":"2016","unstructured":"Suarez-Tangil, G., Tapiador, J.E., Lombardi, F., Pietro, R.D.: ALTERDROID: differential fault analysis of obfuscated smartphone malware. IEEE Trans. Mob. Comput. 15(4), 789802 (2016)","journal-title":"IEEE Trans. Mob. Comput."},{"issue":"6","key":"307_CR22","doi-asserted-by":"crossref","first-page":"31320","DOI":"10.1049\/iet-ifs.2014.0099","volume":"9","author":"SY Yerima","year":"2015","unstructured":"Yerima, S.Y., Sezer, S., Muttik, I.: High accuracy android malware detection using ensemble learning. IET Inf. Secur. 9(6), 31320 (2015)","journal-title":"IET Inf. Secur."},{"key":"307_CR23","unstructured":"Saracino, A., Sgandurra, D., Dini, G., Martinelli, F.: Madam: Effective and efficient behavior-based android malware detection and prevention. IEEE Trans. Dependable Secure Comput. (2016)"},{"key":"307_CR24","unstructured":"Brien, D.O.: The apple threat landscape [Internet], p. 31. Symantec 2016 Feb. (SECURITY RESPONSE). Report No.: 1.02. https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/security-center\/white-papers\/apple-threat-landscape-16-en.pdf"},{"key":"307_CR25","doi-asserted-by":"crossref","unstructured":"Europe key target for cybercrime. Comput Fraud Secur. 2011(1), 3, 20 (2011)","DOI":"10.1016\/S1361-3723(11)70003-3"},{"issue":"2","key":"307_CR26","doi-asserted-by":"crossref","first-page":"S3","DOI":"10.1016\/j.diin.2014.05.011","volume":"11","author":"GG Richard III","year":"2014","unstructured":"Richard III, G.G., Case, A.: In lieu of swap: analyzing compressed RAM in Mac OS X and Linux. Digit. Investig. 11(2), S3\u2013S12 (2014)","journal-title":"Digit. Investig."},{"key":"307_CR27","doi-asserted-by":"crossref","first-page":"S25","DOI":"10.1016\/j.diin.2015.05.005","volume":"14","author":"A Case","year":"2015","unstructured":"Case, A., Richard, G.G.: Advancing Mac OS X rootkit detection. Digit. Investig. 14, S25\u2013S33 (2015)","journal-title":"Digit. Investig."},{"key":"307_CR28","unstructured":"Walkup E.: Mac malware detection via static file structure analysis. Standford [Internet] (2014) [cited 2017 Mar 28]. http:\/\/cs229.stanford.edu\/proj2014\/Elizabeth%20Walkup,%20MacMalware.pdf"},{"key":"307_CR29","unstructured":"VirusTotal-Free online virus, malware and URL scanner [Internet]. [cited 2016 Nov 28]. https:\/\/www.virustotal.com\/"},{"key":"307_CR30","unstructured":"Objective-see [Internet]: Objective-See. [cited 2016 Nov 28]. https:\/\/objective-see.com"},{"key":"307_CR31","unstructured":"Contagio Malware Dump: Mila. http:\/\/contagiodump.blogspot.com\/ . Accessed 28 Jun 2016"},{"key":"307_CR32","doi-asserted-by":"crossref","unstructured":"Masud, M.M., Khan, L., Thuraisingham, B.: A hybrid model to detect malicious executables. In: 2007 IEEE International Conference on Communications, 14438 (2007)","DOI":"10.1109\/ICC.2007.242"},{"key":"307_CR33","unstructured":"[Internet]. [cited 2017 Sep 13]. https:\/\/developer.apple.com\/library\/content\/documentation\/CoreFoundation\/Conceptual\/CFBundles\/BundleTypes\/BundleTypes.html#apple_ref\/doc\/uid\/10000123i-CH101-SW1"},{"key":"307_CR34","unstructured":"Mac App Store Downloads on iTunes [Internet]. [cited 2016 Nov 28]. https:\/\/itunes.apple.com\/us\/genre\/mac\/id39?mt=12"},{"key":"307_CR35","unstructured":"KDD Cup 1999 Data: 2000 [Online]. http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html . Accessed 17 Sept 2017"},{"key":"307_CR36","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garcia","year":"2014","unstructured":"Garcia, S., Grill, M., Stiborek, J., Zunino, A.: An empirical comparison of botnet detection methods. Comput. Secur. 45, 100\u2013123 (2014)","journal-title":"Comput. Secur."},{"key":"307_CR37","doi-asserted-by":"crossref","unstructured":"Song, J., Takakura, H., Okabe, Y., Eto, M., Inoue, D., Nakao, K.: Statistical analysis of honeypot data and building of Kyoto 2006+ dataset for NIDS evaluation. In: Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (2011)","DOI":"10.1145\/1978672.1978676"},{"key":"307_CR38","unstructured":"Executing Mach-O Files [Internet]. [cited 2017 May 13]. https:\/\/developer.apple.com\/library\/content\/documentation\/DeveloperTools\/Conceptual\/MachOTopics\/1-Articles\/executing_files.html#apple_ref\/doc\/uid\/TP40001829-SW1"},{"key":"307_CR39","unstructured":"HNSX\/OSXMalware [Internet]. GitHub. [cited 2017 Apr 25]. https:\/\/github.com\/HNSX\/OSXMalware"},{"key":"307_CR40","unstructured":"Hastie, T., Tibshirani, R., Sherlock, G., Eisen, M., Brown, P., Botstein, D.: Imputing Missing Data for Gene Expression Arrays. Stanford University Statistics Department Technical Report (1999)"},{"issue":"1","key":"307_CR41","doi-asserted-by":"crossref","first-page":"16190","DOI":"10.1007\/s10844-010-0148-x","volume":"38","author":"A Shabtai","year":"2012","unstructured":"Shabtai, A., Kanonov, U., Elovici, Y., Glezer, C., Weiss, Y.: {Andromaly}: a behavioral malware detection framework for android devices. J. Intell. Inf. Syst. 38(1), 16190 (2012)","journal-title":"J. Intell. Inf. Syst."},{"key":"307_CR42","doi-asserted-by":"crossref","unstructured":"Shabtai, A., Fledel, Y., Elovici, Y.: Automated static code analysis for classifying android applications using machine learning. In: Computational Intelligence and Security (CIS), 2010 International Conference on IEEE, pp. 329-333 (2010)","DOI":"10.1109\/CIS.2010.77"},{"key":"307_CR43","doi-asserted-by":"crossref","unstructured":"Joachims, T.: Text categorization with support vector machines: learning with many relevant features. In: European Conference on Machine Learning, pp. 137\u2013142 (1998)","DOI":"10.1007\/BFb0026683"},{"issue":"1","key":"307_CR44","first-page":"706","volume":"37","author":"Z Zhu","year":"2007","unstructured":"Zhu, Z., Ong, Y.-S., Dash, M.: Wrapperfilter feature selection algorithm using a memetic framework. IEEE Trans. Syst. Man. Cybern. Part B Cybern. 37(1), 706 (2007)","journal-title":"IEEE Trans. Syst. Man. Cybern. Part B Cybern."},{"key":"307_CR45","doi-asserted-by":"crossref","first-page":"321357","DOI":"10.1613\/jair.953","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla, N.V., Bowyer, K.W., Hall, L.O., Kegelmeyer, W.P.: SMOTE: synthetic minority over-sampling technique. J. Artif. Intell. Res. 16, 321357 (2002)","journal-title":"J. Artif. Intell. Res."},{"key":"307_CR46","unstructured":"The Nature of Statistical Learning Theory | Vladimir Vapnik | Springer [Internet]. [cited 2016 Dec 17]. http:\/\/www.springer.com\/gp\/book\/9780387987804"},{"key":"307_CR47","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/4175.001.0001","volume-title":"Learning with Kernels: Support Vector Machines, Regularization, Optimization, and Beyond","author":"B Scholkopf","year":"2001","unstructured":"Scholkopf, B., Smola, A.J.: Learning with Kernels: Support Vector Machines, Regularization, Optimization, and Beyond. MIT Press, Cambridge (2001)"},{"key":"307_CR48","unstructured":"Shashua, A.: Introduction to machine learning: class notes 67577. ArXiv Preprint arXiv:0904.3664 [Internet]. 2009 [cited 2016 Dec 17]. arXiv:0904.3664"},{"issue":"2","key":"307_CR49","doi-asserted-by":"crossref","first-page":"121167","DOI":"10.1023\/A:1009715923555","volume":"2","author":"CJ Burges","year":"1998","unstructured":"Burges, C.J.: A tutorial on support vector machines for pattern recognition. Data Min. Knowl. Discov. 2(2), 121167 (1998)","journal-title":"Data Min. Knowl. Discov."},{"key":"307_CR50","unstructured":"Kavzoglu, T., Colkesen, I.: The effects of training set size for performance of support vector machines and decision trees. In: Proceeding of the 10th International Symposium on Spatial Accuracy Assessment in Natural Resources and Environmental Sciences, p. 1013 (July 2012)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-017-0307-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0307-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0307-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,27]],"date-time":"2024-06-27T22:29:15Z","timestamp":1719527355000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-017-0307-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,10,20]]},"references-count":50,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,8]]}},"alternative-id":["307"],"URL":"https:\/\/doi.org\/10.1007\/s11416-017-0307-5","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,10,20]]}}}