{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,28]],"date-time":"2026-06-28T05:06:35Z","timestamp":1782623195559,"version":"3.54.5"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2017,8,23]],"date-time":"2017-08-23T00:00:00Z","timestamp":1503446400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Ambient Intell Human Comput"],"published-print":{"date-parts":[[2018,8]]},"DOI":"10.1007\/s12652-017-0558-5","type":"journal-article","created":{"date-parts":[[2017,8,23]],"date-time":"2017-08-23T06:34:25Z","timestamp":1503470065000},"page":"1141-1152","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":221,"title":["Detecting crypto-ransomware in IoT networks based on energy consumption footprint"],"prefix":"10.1007","volume":"9","author":[{"given":"Amin","family":"Azmoodeh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9294-7554","authenticated-orcid":false,"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,8,23]]},"reference":[{"key":"558_CR1","doi-asserted-by":"crossref","first-page":"65","DOI":"10.13052\/jcsm2245-1439.414","volume":"4","author":"M Abomhara","year":"2015","unstructured":"Abomhara M, Kien G (2015) Cyber security and the internet of things: vulnerabilities, threats, intruders and attacks. J Cyber Secur 4:65\u201388","journal-title":"J Cyber Secur"},{"key":"558_CR2","doi-asserted-by":"crossref","unstructured":"Andronio N, Zanero S, Maggi F (2015) HelDroid: dissecting and detecting mobile Ransomware. In: Proceedings of the 18th international symposium on research in attacks, intrusions, and defenses, Volume 9404. RAID 2015. Springer, New York, pp 382\u2013404","DOI":"10.1007\/978-3-319-26362-5_18"},{"issue":"4","key":"558_CR3","doi-asserted-by":"crossref","first-page":"22:1","DOI":"10.1145\/3013520","volume":"16","author":"E Bertino","year":"2016","unstructured":"Bertino E, Choo KKR, Georgakopolous D, Nepal S (2016) Internet of things (iot): smart and secure service delivery. ACM Trans Internet Technol 16(4):22:1\u201322:7","journal-title":"ACM Trans Internet Technol"},{"issue":"2","key":"558_CR4","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2016","unstructured":"Buczak AL, Guven E (2016) A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun Surv Tutor 18(2):1153\u20131176","journal-title":"IEEE Commun Surv Tutor"},{"issue":"2","key":"558_CR5","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1023\/A:1009715923555","volume":"2","author":"CJ Burges","year":"1998","unstructured":"Burges CJ (1998) A tutorial on support vector machines for pattern recognition. Data Min Knowl Disc 2(2):121\u2013167","journal-title":"Data Min Knowl Disc"},{"issue":"4","key":"558_CR6","doi-asserted-by":"crossref","first-page":"799","DOI":"10.1109\/TIFS.2015.2510825","volume":"11","author":"L Caviglione","year":"2016","unstructured":"Caviglione L, Gaggero M, Lalande JF, Mazurczyk W, Urba\u0144ski M (2016) Seeing the unseen: revealing mobile malware hidden communications via energy consumption and artificial intelligence. IEEE Trans Inf Forensics Secur 11(4):799\u2013810","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"558_CR7","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1007\/978-1-4899-7439-6_6","volume-title":"ICTs and the millennium development goals: a United Nations perspective","author":"K-KR Choo","year":"2014","unstructured":"Choo K-KR (2014) A conceptual interdisciplinary plug-and-play cyber security framework. In: Kaur H, Tao X (eds) ICTs and the millennium development goals: a United Nations perspective. Springer, Boston, pp 81\u201399"},{"issue":"1","key":"558_CR8","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1109\/TIT.1967.1053964","volume":"13","author":"T Cover","year":"1967","unstructured":"Cover T, Hart P (1967) Nearest neighbor pattern classification. IEEE Trans Inf Theory 13(1):21\u201327","journal-title":"IEEE Trans Inf Theory"},{"issue":"3","key":"558_CR9","first-page":"141","volume":"11","author":"M Damshenas","year":"2015","unstructured":"Damshenas M, Dehghantanha A, Choo K-KR, Mahmud R (2015) M0droid an android behavioral-based malware detection model. J Inf Priv Secur 11(3):141\u2013157","journal-title":"J Inf Priv Secur"},{"issue":"4","key":"558_CR10","first-page":"10","volume":"2","author":"M Damshenas","year":"2013","unstructured":"Damshenas M, Dehghantanha A, Mahmoud R (2013) A survey on malware propagation, analysis, and detection. Int J Cyber Secur Digit Forensics 2(4):10\u201329","journal-title":"Int J Cyber Secur Digit Forensics"},{"key":"558_CR11","doi-asserted-by":"crossref","unstructured":"Daryabar F, Dehghantanha A, Udzir NI, binti Mohd\u00a0Sani NF, bin Shamsuddin S (2012) Towards secure model for SCADA systems. In: Proceedings title: 2012 International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec), pp 60\u201364","DOI":"10.1109\/CyberSec.2012.6246111"},{"issue":"4","key":"558_CR12","doi-asserted-by":"crossref","first-page":"469","DOI":"10.1080\/00450618.2015.1066854","volume":"48","author":"FN Dezfouli","year":"2016","unstructured":"Dezfouli FN, Dehghantanha A, Eterovic-Soric B, Choo K-KR (2016) Investigating social networking applications on smartphones detecting facebook, twitter, linkedin and google+ artefacts on android and ios platforms. Aust J Forensic Sci 48(4):469\u2013488","journal-title":"Aust J Forensic Sci"},{"key":"558_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2016.11.010","author":"CJ D\u2019Orazio","year":"2016","unstructured":"D\u2019Orazio CJ, Choo K-KR (2016) Circumventing iOS security mechanisms for APT forensic investigations: a security taxonomy for cloud apps. Future Gener Comput Syst. \n                        https:\/\/doi.org\/10.1016\/j.future.2016.11.010","journal-title":"Future Gener Comput Syst"},{"issue":"2","key":"558_CR14","doi-asserted-by":"crossref","first-page":"524","DOI":"10.1109\/JIOT.2016.2569094","volume":"4","author":"CJ D\u2019Orazio","year":"2017","unstructured":"D\u2019Orazio CJ, Choo K-KR, Yang LT (2017) Data exfiltration from internet of things devices: IOS devices as case studies. IEEE Internet Things J 4(2):524\u2013535","journal-title":"IEEE Internet Things J"},{"issue":"2","key":"558_CR15","doi-asserted-by":"crossref","first-page":"998","DOI":"10.1109\/COMST.2014.2386139","volume":"17","author":"P Faruki","year":"2015","unstructured":"Faruki P, Bharmal A, Laxmi V, Ganmoor V, Gaur MS, Conti M, Rajarajan M (2015) Android security: a survey of issues, malware penetration, and defenses. IEEE Commun Surv Tutor 17(2):998\u20131022","journal-title":"IEEE Commun Surv Tutor"},{"key":"558_CR16","unstructured":"FBI (2016) How to protecting your networks from Ransomware. Tech. rep., USA Government. \nhttps:\/\/www.justice.gov\/criminal-ccips\/file\/872771\/download\n\n. Accessed 10 Feb 2017"},{"key":"558_CR17","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-00491-4","volume-title":"Internet of things based on smart objects: technology, middleware and applications","author":"G Fortino","year":"2014","unstructured":"Fortino G, Trunfio P (2014) Internet of things based on smart objects: technology, middleware and applications. Springer, Berlin"},{"issue":"1","key":"558_CR18","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1016\/j.engappai.2010.09.007","volume":"24","author":"T-C Fu","year":"2011","unstructured":"Fu T-C (2011) A review on time series data mining. Eng Appl Artif Intell 24(1):164\u2013181","journal-title":"Eng Appl Artif Intell"},{"issue":"7","key":"558_CR19","doi-asserted-by":"crossref","first-page":"1645","DOI":"10.1016\/j.future.2013.01.010","volume":"29","author":"J Gubbi","year":"2013","unstructured":"Gubbi J, Buyya R, Marusic S, Palaniswami M (2013) Internet of things (IOT): a vision, architectural elements, and future directions. Future Gener Comput Syst 29(7):1645\u20131660","journal-title":"Future Gener Comput Syst"},{"key":"558_CR20","volume-title":"Neural networks: a comprehensive foundation","author":"S Haykin","year":"1998","unstructured":"Haykin S (1998) Neural networks: a comprehensive foundation, 2nd edn. Prentice Hall, Upper Saddle River","edition":"2"},{"issue":"8","key":"558_CR21","doi-asserted-by":"crossref","first-page":"2481","DOI":"10.1007\/s11276-014-0761-7","volume":"20","author":"Q Jing","year":"2014","unstructured":"Jing Q, Vasilakos AV, Wan J, Lu J, Qiu D (2014) Security of the internet of things: perspectives and challenges. Wireless Netw 20(8):2481\u20132501","journal-title":"Wireless Netw"},{"key":"558_CR22","doi-asserted-by":"crossref","unstructured":"Kim H, Smith J, Shin KG (2008) Detecting energy-greedy anomalies and mobile malware variants. In: Proceedings of the 6th international conference on mobile systems, applications, and services. ACM, pp 239\u2013252","DOI":"10.1145\/1378600.1378627"},{"key":"558_CR23","first-page":"1137","volume":"14","author":"R Kohavi","year":"1995","unstructured":"Kohavi R et al (1995) A study of cross-validation and bootstrap for accuracy estimation and model selection. Ijcai 14:1137\u20131145","journal-title":"Ijcai"},{"issue":"11","key":"558_CR24","first-page":"20","volume":"90","author":"JS Kumar","year":"2014","unstructured":"Kumar JS, Patel DR (2014) A survey on internet of things: security and privacy issues. Int J Comput Appl 90(11):20\u201326","journal-title":"Int J Comput Appl"},{"key":"558_CR25","unstructured":"Mercaldo F, Luo X, Liao Q, Mercaldo F, Nardone V, Santone A, Visaggio CA (2016) Ransomware steals your phone. formal methods rescue it. In: Formal techniques for distributed objects, components, and systems: 36th IFIP WG 6.1 International Conference, FORTE 2016, Held as Part of the 11th International Federated Conference on Distributed Computing Techniques, DisCoTec 2016, Heraklion, Crete, Greece, June 6\u20139, 2016, Proceedings. Vol. 9688 of Lecture Notes in Computer Science. Springer, pp 212\u2013221"},{"key":"558_CR26","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1016\/j.pmcj.2015.05.005","volume":"24","author":"A Merlo","year":"2015","unstructured":"Merlo A, Migliardi M, Caviglione L (2015a) A survey on energy-aware security mechanisms. Pervasive Mob Comput 24:77\u201390","journal-title":"Pervasive Mob Comput"},{"issue":"5","key":"558_CR27","doi-asserted-by":"crossref","first-page":"611","DOI":"10.3233\/JCS-150530","volume":"23","author":"A Merlo","year":"2015","unstructured":"Merlo A, Migliardi M, Fontanelli P (2015b) Measuring and estimating power consumption in android to support energy-based intrusion detection. J Comput Secur 23(5):611\u2013637","journal-title":"J Comput Secur"},{"key":"558_CR28","volume-title":"Machine learning: an artificial intelligence approach. Artificial intelligence series","author":"RS Michalski","year":"2013","unstructured":"Michalski RS, Carbonell JG, Mitchell TM (2013) Machine learning: an artificial intelligence approach. Artificial intelligence series. Springer, Berlin"},{"key":"558_CR29","volume-title":"Dynamic time warping","author":"M M\u00fcller","year":"2007","unstructured":"M\u00fcller M (2007) Dynamic time warping. Springer, Berlin"},{"key":"558_CR30","unstructured":"O\u2019Gorman G, McDonald G (2012) Ransomware: a growing menace. Tech. rep., Symantec Corporation. \nhttp:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/ransomware-a-growing-menace.pdf\n\n. Accessed 12 Feb 2017"},{"key":"558_CR31","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2016.2633228","author":"HH Pajouh","year":"2016","unstructured":"Pajouh HH, Javidan R, Khayami R, Ali D, Choo K-KR (2016) A two-layer dimension reduction and two-tier classification model for anomaly-based intrusion detection in IoT backbone networks. IEEE Trans Emerg Top Comput. \n                        https:\/\/doi.org\/10.1109\/TETC.2016.2633228","journal-title":"IEEE Trans Emerg Top Comput"},{"issue":"2","key":"558_CR32","doi-asserted-by":"crossref","first-page":"128","DOI":"10.1109\/TMC.2006.16","volume":"5","author":"NR Potlapally","year":"2006","unstructured":"Potlapally NR, Ravi S, Raghunathan A, Jha NK (2006) A study of the energy consumption characteristics of cryptographic algorithms and security protocols. IEEE Trans Mob Comput 5(2):128\u2013143","journal-title":"IEEE Trans Mob Comput"},{"key":"558_CR33","unstructured":"Sgandurra D, Mu\u00f1oz-Gonz\u00e1lez L, Mohsen R, Lupu EC (2016) Automated dynamic analysis of ransomware: Benefits, limitations and use for detection. \narXiv:1609.03020\n\n (preprint)"},{"issue":"3","key":"558_CR34","first-page":"21","volume":"8","author":"K Shaerpour","year":"2013","unstructured":"Shaerpour K, Dehghantanha A, Mahmod R (2013) Trends in android malware detection. J Digit Forensics Secur Law 8(3):21\u201340","journal-title":"J Digit Forensics Secur Law"},{"key":"558_CR35","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1016\/j.comnet.2014.11.008","volume":"76","author":"S Sicari","year":"2015","unstructured":"Sicari S, Rizzardi A, Grieco LA, Coen-Porisini A (2015) Security, privacy and trust in internet of things: the road ahead. Comput Netw 76:146\u2013164","journal-title":"Comput Netw"},{"key":"558_CR36","first-page":"3","volume":"2016","author":"S Song","year":"2016","unstructured":"Song S, Kim B, Lee S (2016) The effective ransomware prevention technique using process monitoring on android platform. Mob Inf Syst 2016:3\u201311","journal-title":"Mob Inf Syst"},{"issue":"2","key":"558_CR37","doi-asserted-by":"crossref","first-page":"961","DOI":"10.1109\/SURV.2013.101613.00077","volume":"16","author":"G Suarez-Tangil","year":"2014","unstructured":"Suarez-Tangil G, Tapiador JE, Peris-Lopez P, Ribagorda A (2014) Evolution, detection and analysis of malware for smart devices. IEEE Commun Surv Tutor 16(2):961\u2013987","journal-title":"IEEE Commun Surv Tutor"},{"issue":"9","key":"558_CR38","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1016\/S1361-3723(15)30084-1","volume":"2015","author":"C Tankard","year":"2015","unstructured":"Tankard C (2015) The security issues of the internet of things. Comput Fraud Secur 2015(9):11\u201314","journal-title":"Comput Fraud Secur"},{"key":"558_CR39","doi-asserted-by":"publisher","first-page":"350","DOI":"10.1016\/j.compeleceng.2016.08.020","volume":"58","author":"Y-Y Teing","year":"2017","unstructured":"Teing Y-Y, Dehghantanha A, Choo K-KR, Yang LT (2017) Forensic investigation of P2P cloud storage services and backbone for IoT networks: BitTorrent Sync as a case study. Comput Electr Eng 58:350\u2013363. \n                        https:\/\/doi.org\/10.1016\/j.compeleceng.2016.08.020","journal-title":"Comput Electr Eng"},{"issue":"2","key":"558_CR40","doi-asserted-by":"crossref","first-page":"330","DOI":"10.1016\/j.patcog.2010.08.011","volume":"44","author":"A Verikas","year":"2011","unstructured":"Verikas A, Gelzinis A, Bacauskiene M (2011) Mining data with random forests: a survey and results of new tests. Pattern Recogn 44(2):330\u2013349","journal-title":"Pattern Recogn"},{"issue":"6","key":"558_CR41","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S1361-3723(15)30045-2","volume":"2016","author":"S Watson","year":"2016","unstructured":"Watson S, Dehghantanha A (2016) Digital forensics: the missing piece of the internet of things promise. Comput Fraud Secur 2016(6):5\u20138","journal-title":"Comput Fraud Secur"},{"issue":"1","key":"558_CR42","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1145\/1882471.1882478","volume":"12","author":"Z Xing","year":"2010","unstructured":"Xing Z, Pei J, Keogh E (2010) A brief survey on sequence classification. ACM SIGKDD Explor Newsl 12(1):40\u201348","journal-title":"ACM SIGKDD Explor Newsl"},{"key":"558_CR43","first-page":"1","volume":"2016","author":"H Yang","year":"2016","unstructured":"Yang H, Tang R (2016) Power consumption based android malware detection. J Electr Comput Eng 2016:1\u20137","journal-title":"J Electr Comput Eng"},{"key":"558_CR44","unstructured":"Yang Z (2012) Powertutor\u2014a power monitor for android-based mobile platforms. Tech. rep., EECS, University of Michigan. \nhttp:\/\/ziyang.eecs.umich.edu\/projects\/powertutor\n\n. Accessed 25 Jan 2017"}],"container-title":["Journal of Ambient Intelligence and Humanized Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s12652-017-0558-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12652-017-0558-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12652-017-0558-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,7,30]],"date-time":"2018-07-30T09:25:39Z","timestamp":1532942739000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s12652-017-0558-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,23]]},"references-count":44,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2018,8]]}},"alternative-id":["558"],"URL":"https:\/\/doi.org\/10.1007\/s12652-017-0558-5","relation":{},"ISSN":["1868-5137","1868-5145"],"issn-type":[{"value":"1868-5137","type":"print"},{"value":"1868-5145","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,8,23]]}}}