{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T10:27:45Z","timestamp":1778840865151,"version":"3.51.4"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2018,6,30]],"date-time":"2018-06-30T00:00:00Z","timestamp":1530316800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Front. Comput. Sci."],"published-print":{"date-parts":[[2019,6]]},"DOI":"10.1007\/s11704-017-6493-y","type":"journal-article","created":{"date-parts":[[2018,6,30]],"date-time":"2018-06-30T04:40:43Z","timestamp":1530333643000},"page":"637-646","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["Fingerprinting Android malware families"],"prefix":"10.1007","volume":"13","author":[{"given":"Nannan","family":"Xie","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xing","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiqiang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,6,30]]},"reference":[{"issue":"12","key":"6493_CR1","doi-asserted-by":"publisher","first-page":"1974","DOI":"10.1016\/j.jss.2009.06.040","volume":"82","author":"W Wang","year":"2009","unstructured":"Wang W, Zhang X L, Gombault S. Constructing attribute weights from computer audit data for effective intrusion detection. Journal of Systems and Software, 2009, 82(12): 1974\u20131981","journal-title":"Journal of Systems and Software"},{"issue":"1","key":"6493_CR2","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1016\/j.jnca.2008.04.006","volume":"32","author":"X H Guan","year":"2009","unstructured":"Guan X H, Wang W, Zhang X L. Fast intrusion detection based on a non-negative matrix factorization model. Journal of Network and Computer Applications, 2009, 32(1): 31\u201344","journal-title":"Journal of Network and Computer Applications"},{"issue":"7","key":"6493_CR3","doi-asserted-by":"publisher","first-page":"539","DOI":"10.1016\/j.cose.2006.05.005","volume":"25","author":"W Wang","year":"2006","unstructured":"Wang W, Guan X H, Zhang X L, Yang L. Profiling program behavior for anomaly intrusion detection based on the transition and frequency property of computer audit data. Computers & Security, 2006, 25(7): 539\u2013550","journal-title":"Computers & Security"},{"issue":"1","key":"6493_CR4","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1016\/j.comcom.2007.10.010","volume":"31","author":"W Wang","year":"2008","unstructured":"Wang W, Guan X, Zhang X L. Processing of massive audit data streams for real-time anomaly intrusion detection. Computer Communications, 2008, 31(1): 58\u201372","journal-title":"Computer Communications"},{"key":"6493_CR5","doi-asserted-by":"crossref","unstructured":"Wang W, Liu J Q, Pitsilis G, Zhang X L. Abstracting massive data for lightweight intrusion detection in computer networks. Information Sciences, doi:10.1016\/j.ins.2016.10.023, 26","DOI":"10.1016\/j.ins.2016.10.023"},{"issue":"4","key":"6493_CR6","doi-asserted-by":"publisher","first-page":"616","DOI":"10.1007\/s11390-013-1362-0","volume":"28","author":"X L Zhang","year":"2013","unstructured":"Zhang X L, T Lee, Pitsilis G. Securing recommender systems against shilling attacks using social-based clustering. Journal of Computer Science and Technology, 2013, 28(4): 616\u2013624","journal-title":"Journal of Computer Science and Technology"},{"key":"6493_CR7","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1016\/j.knosys.2014.06.018","volume":"70","author":"W Wang","year":"2014","unstructured":"Wang W, Guyet T, Quiniou R, Cordier M O, Masseglia F, Zhang X L. Autonomic intrusion detection: adaptively detecting anomalies over unlabeled audit data streams in computer networks. Knowledge-Based Systems, 2014, 70: 103\u2013117","journal-title":"Knowledge-Based Systems"},{"key":"6493_CR8","first-page":"1","volume-title":"Proceedings of the 1st International Conference on Availability, Reliability and Security","author":"W Wang","year":"2006","unstructured":"Wang W, Battiti R. Identifying intrusions in computer networks with principal component analysis. In: Proceedings of the 1st International Conference on Availability, Reliability and Security. 2006, 1\u20138"},{"issue":"7","key":"6493_CR9","doi-asserted-by":"publisher","first-page":"1644","DOI":"10.1109\/TKDE.2013.146","volume":"26","author":"X L Zhang","year":"2014","unstructured":"Zhang X L, Furtlehner C, Germain-Renaud C, Sebag M. Data stream clustering with affinity propagation. IEEE Transactions on Knowledge and Data Engineering, 2014, 26(7): 1644\u20131656","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"issue":"2","key":"6493_CR10","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1109\/TC.2013.208","volume":"64","author":"J Li","year":"2015","unstructured":"Li J, Li J W, Chen X F, Lou W. Identity-based encryption with outsourced revocation in cloud computing. IEEE Transactions on Computers, 2015, 64(2): 425\u2013437","journal-title":"IEEE Transactions on Computers"},{"issue":"5","key":"6493_CR11","doi-asserted-by":"publisher","first-page":"1206","DOI":"10.1109\/TPDS.2014.2318320","volume":"26","author":"J Li","year":"2015","unstructured":"Li J, Li Y K, Chen X F, Lee P, Lou W. A hybrid cloud approach for secure authorized deduplication. IEEE Transactions on Parallel & Distributed Systems, 2015, 26(5): 1206\u20131216","journal-title":"IEEE Transactions on Parallel & Distributed Systems"},{"key":"6493_CR12","first-page":"95","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"Y Zhou","year":"2012","unstructured":"Zhou Y, Jiang X. Detecting Android malware: characterization and evolution. In: Proceedings of IEEE Symposium on Security and Privacy. 2012, 95\u2013109"},{"key":"6493_CR13","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1145\/1653662.1653691","volume-title":"Proceedings of the 16th ACM Conference on Computer and Communications Security","author":"W Enck","year":"2009","unstructured":"Enck W, Ongtang M, McDaniel P. On lightweight mobile phone application certification. In: Proceedings of the 16th ACM Conference on Computer and Communications Security. 2009, 235\u2013245"},{"key":"6493_CR14","first-page":"125","volume-title":"Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks","author":"P F Chan","year":"2012","unstructured":"Chan P F, Hui L K, Yiu S M. Droidchecker: analyzing Android applications for capability leak. In: Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks. 2012, 125\u2013136"},{"key":"6493_CR15","first-page":"229","volume-title":"Proceedings of ACM Conference on Computer and Communications Security","author":"L Lu","year":"2012","unstructured":"Lu L, Li Z, Wu Z, Lee W, Jiang G. Chex: statically vetting Android apps for component hijacking vulnerabilities. In: Proceedings of ACM Conference on Computer and Communications Security. 2012, 229\u2013240"},{"key":"6493_CR16","first-page":"627","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security","author":"A P Felt","year":"2011","unstructured":"Felt A P, Chin E, Hanna S, Song D, Wagner D. Android permissions demystified. In: Proceedings of the ACM Conference on Computer and Communications Security. 2011, 627\u2013638"},{"key":"6493_CR17","first-page":"23","volume-title":"Proceedings of the 20th USENIX Conference of Security","author":"M Dietz","year":"2011","unstructured":"Dietz M, Shekhar S, Pisetsky Y, Shu A, Wallach D S. Quire: lightweight provenance for smart phone operating systems. In: Proceedings of the 20th USENIX Conference of Security. 2011, 23\u201324"},{"key":"6493_CR18","doi-asserted-by":"crossref","first-page":"1036","DOI":"10.1145\/2568225.2568301","volume-title":"Proceedings of the 36th International Conference on Software Engineering","author":"J J Huang","year":"2014","unstructured":"Huang J J, Zhang X Y, Tan L, Wang P, Liang B. AsDroid: detecting stealthy behaviors in Android applications by user interface and program behaviors contradiction. In: Proceedings of the 36th International Conference on Software Engineering. 2014, 1036\u20131046"},{"issue":"11","key":"6493_CR19","doi-asserted-by":"publisher","first-page":"1869","DOI":"10.1109\/TIFS.2014.2353996","volume":"9","author":"W Wang","year":"2014","unstructured":"WangW, Wang X, Feng D, Liu J. Exploring permission-induced risk in Android applications for malicious application detection. IEEE Transactions on Information Forensics and Security. 2014, 9(11): 1869\u20131882","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"1","key":"6493_CR20","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/s11280-017-0446-0","volume":"21","author":"X Liu","year":"2018","unstructured":"Liu X, Liu J, Wang W, He Y, Zhang X. Discovering and understanding Android sensor usage behaviors with data flow analysis. World Wide Web, 2018, 21(1): 105\u2013126","journal-title":"World Wide Web"},{"key":"6493_CR21","first-page":"10","volume-title":"Proceedings of the 12th EAI International Conference on Security and Privacy in Communication Networks","author":"X Liu","year":"2016","unstructured":"Liu X, Zhu S, Wang W, Liu J. Alde: privacy risk analysis of analytics libraries in the Android ecosystem. In: Proceedings of the 12th EAI International Conference on Security and Privacy in Communication Networks. 2016, 10\u201312"},{"key":"6493_CR22","doi-asserted-by":"publisher","first-page":"987","DOI":"10.1016\/j.future.2017.01.019","volume":"78","author":"W Wang","year":"2018","unstructured":"Wang W, Li Y, Wang X, Liu J Q, Zhang X L. Detecting Android malicious apps and categorizing benign apps with ensemble of classifiers. Future Generation Computer Systems, 2018, 78: 987\u2013994","journal-title":"Future Generation Computer Systems"},{"key":"6493_CR23","first-page":"73","volume-title":"Proceedings of ACM Conference on Computer and Communications Security","author":"D Barrera","year":"2010","unstructured":"Barrera D, Oorschot P, Somayaji A. A methodology for empirical analysis of permission-based security models and its application to Android. In: Proceedings of ACM Conference on Computer and Communications Security. 2010, 73\u201384"},{"issue":"1","key":"6493_CR24","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1007\/s10844-010-0148-x","volume":"38","author":"A Shabtai","year":"2012","unstructured":"Shabtai A, Kanonov U, Elovici Y, Glezer C, Weiss Y. \u201cAndromaly\u201d: a behavioral malware detection framework for Android devices. Journal of Intelligent Information Systems, 2012, 38(1): 161\u2013190","journal-title":"Journal of Intelligent Information Systems"},{"key":"6493_CR25","first-page":"701","volume-title":"Proceedings of IEEE Conference on Communications & Network Security","author":"A Munoz","year":"2015","unstructured":"Munoz A, Martin I, Guzman A, Hernandez J. Android malware detection from Google Play meta-data: selection of important features. In: Proceedings of IEEE Conference on Communications & Network Security. 2015, 701\u2013702"},{"issue":"1","key":"6493_CR26","first-page":"45","volume":"27","author":"S H Qing","year":"2016","unstructured":"Qing S H. Research progress on Android security. Journal of Software, 2016, 27(1): 45\u201371","journal-title":"Journal of Software"},{"issue":"1","key":"6493_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40064-015-1659-2","volume":"5","author":"JW Jang","year":"2016","unstructured":"Jang JW, Yun J, Mohaisen A, Woo J, Kim H K. Detecting and classifying method based on similarity matching of Android malware behavior with profile. Spingerplus, 2016, 5(1): 1\u201323","journal-title":"Spingerplus"},{"issue":"5","key":"6493_CR28","doi-asserted-by":"publisher","first-page":"942","DOI":"10.1007\/s11390-015-1573-7","volume":"30","author":"J Chen","year":"2015","unstructured":"Chen J, Alalfi M H, Dean T R, Zou Y. Detecting Android malware using clone detection. Journal of Computer Science and Technology, 2015, 30(5): 942\u2013956","journal-title":"Journal of Computer Science and Technology"},{"key":"6493_CR29","doi-asserted-by":"publisher","DOI":"10.1201\/b17598","volume-title":"Android Malware and Analysis","author":"K Dunham","year":"2014","unstructured":"Dunham K, Hartman S, Morales J A, Quintans M, Strazzere T. Android Malware and Analysis. Boca Raion, Florida: CRC Press, 2014"},{"issue":"4","key":"6493_CR30","doi-asserted-by":"publisher","first-page":"491","DOI":"10.1109\/TKDE.2005.66","volume":"17","author":"H Liu","year":"2005","unstructured":"Liu H, Yu L. Toward integrating feature selection algorithms for classification and clustering. IEEE Transactions on Knowledge and Data Engineering, 2005, 17(4): 491\u2013502","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"issue":"10","key":"6493_CR31","doi-asserted-by":"publisher","first-page":"1361","DOI":"10.3724\/SP.J.1004.2010.01361","volume":"36","author":"Z D Cheng","year":"2010","unstructured":"Cheng Z D, Zhang Y J, Fan X, Zhu B. Study on discriminant matrices of commonly-used fisher discriminant functions. Acta Automatica Sinica, 2010, 36(10): 1361\u20131370","journal-title":"Acta Automatica Sinica"},{"issue":"4","key":"6493_CR32","first-page":"481","volume":"29","author":"J Yang","year":"2003","unstructured":"Yang J, Ye H. Theory of fisher discriminant analysis and its application. Acta Automatica Sinica, 2003, 29(4): 481\u2013493","journal-title":"Acta Automatica Sinica"}],"container-title":["Frontiers of Computer Science"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-017-6493-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11704-017-6493-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-017-6493-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,26]],"date-time":"2022-08-26T20:03:11Z","timestamp":1661544191000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11704-017-6493-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,6,30]]},"references-count":32,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2019,6]]}},"alternative-id":["6493"],"URL":"https:\/\/doi.org\/10.1007\/s11704-017-6493-y","relation":{},"ISSN":["2095-2228","2095-2236"],"issn-type":[{"value":"2095-2228","type":"print"},{"value":"2095-2236","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,6,30]]},"assertion":[{"value":"7 October 2016","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 April 2017","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 June 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}