{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,17]],"date-time":"2025-04-17T14:09:47Z","timestamp":1744898987139},"reference-count":56,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2017,2,28]],"date-time":"2017-02-28T00:00:00Z","timestamp":1488240000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Vietnam J Comput Sci"],"published-print":{"date-parts":[[2017,11]]},"DOI":"10.1007\/s40595-017-0095-3","type":"journal-article","created":{"date-parts":[[2017,2,28]],"date-time":"2017-02-28T07:59:03Z","timestamp":1488268743000},"page":"245-259","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Computational intelligence anti-malware framework for android OS"],"prefix":"10.1007","volume":"4","author":[{"given":"Konstantinos","family":"Demertzis","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lazaros","family":"Iliadis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,2,28]]},"reference":[{"key":"95_CR1","unstructured":"https:\/\/source.android.com\/security\/index.html"},{"key":"95_CR2","volume-title":"Information Security and Cryptology-ICISC 2015","author":"J Danisevskis","year":"2016","unstructured":"Danisevskis, J.: Uncloaking rootkits on mobile devices with a hypervisor-based detector. Information Security and Cryptology-ICISC 2015, vol. 9558. Springer, Berlin (2016)"},{"key":"95_CR3","unstructured":"Rudd, E., et\u00a0al.: A survey of stealth malware: attacks, mitigation measures, and steps toward autonomous open world solutions (2016). arXiv:1603.06028"},{"key":"95_CR4","unstructured":"Hayes, J.: Traffic confirmation attacks despite noise (2016). arXiv:1601.04893"},{"key":"95_CR5","doi-asserted-by":"crossref","unstructured":"Backes, M., et\u00a0al.: Provably secure and practical onion routing. In: Computer Security Foundations Symposium (CSF), 2012 IEEE 25th. IEEE, New York (2012)","DOI":"10.1109\/CSF.2012.32"},{"issue":"6","key":"95_CR6","first-page":"255","volume":"7","author":"D Bansal","year":"2015","unstructured":"Bansal, D., Priya, S., Shipra, K.: Secure socket layer and its security analysis. Netw. Commun. Eng. 7(6), 255\u2013259 (2015)","journal-title":"Netw. Commun. Eng."},{"issue":"1\u20133","key":"95_CR7","doi-asserted-by":"crossref","first-page":"489","DOI":"10.1016\/j.neucom.2005.12.126","volume":"70","author":"Guang-Bin Huang","year":"2006","unstructured":"Huang, Guang-Bin, Qin-Yu, Z., Chee-Kheong, S.: Extreme learning machine: theory and applications. Neurocomputing 70(1\u20133), 489\u2013501 (2006)","journal-title":"Neurocomputing"},{"key":"95_CR8","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1007\/978-3-319-11710-2_2","volume":"441","author":"K Demertzis","year":"2014","unstructured":"Demertzis, K., Iliadis, L.: A hybrid network anomaly and intrusion detection approach based on evolving spiking neural network classification (2014). Commun Comput Inf Sci 441, 11\u201323 (2014). doi: 10.1007\/978-3-319-11710-2_2","journal-title":"Commun Comput Inf Sci"},{"key":"95_CR9","doi-asserted-by":"crossref","first-page":"322","DOI":"10.1007\/978-3-319-07869-4_30","volume":"178","author":"K Demertzis","year":"2014","unstructured":"Demertzis, K., Iliadis, L.: Evolving computational intelligence system for malware detection. Lect. Notes Bus. Inf. Process. 178, 322\u2013334 (2014)","journal-title":"Lect. Notes Bus. Inf. Process."},{"key":"95_CR10","doi-asserted-by":"publisher","unstructured":"Demertzis, K., Iliadis L.: Bio-inspired hybrid artificial intelligence framework for cyber security. In: Proceedings of 2nd CryptAAF (Cryptography and Its Applications in the Armed Forces), 2 April 2014, Athens, Greece. Computation, Cryptography, and Network Security. Computation, Cryptography, and Network Security. Springer International Publishing, Berlin, pp. 161\u2013193. doi: 10.1007\/978-3-319-18275-9_7","DOI":"10.1007\/978-3-319-18275-9_7"},{"key":"95_CR11","unstructured":"Demertzis K., Iliadis L.: Bio-Inspired Hybrid Intelligent Method for Detecting Android Malware Proceedings of 9th International Conference on Knowledge, Information and Creativity Support Systems (KICSS 2014). ISBN: 978-9963-700-84-4 (\u201cKICSS\u20192014 Proceedings\u201d)"},{"key":"95_CR12","doi-asserted-by":"publisher","unstructured":"Demertzis, K., Iliadis, L.: Evolving smart URL filter in a zone-based policy firewall for detecting algorithmically generated malicious domains. Statistical learning and data sciences. In: Series Lecture Notes in Computer Science. Third International Symposium, SLDS 2015, Egham, UK, April 20\u201323, 2015, Proceedings, vol. 9047, pp. 223\u2013233. Springer International Publishing, Berlin. doi: 10.1007\/978-3-319-17091-6_17","DOI":"10.1007\/978-3-319-17091-6_17"},{"key":"95_CR13","doi-asserted-by":"crossref","unstructured":"Schmidt, A.D., Schmidt, H.G., Batyuk, L., Clausen, J.H., Camtepe, S.A., Albayrak, S., Yildizli, C.: Smartphone malware evolution revisited: android next target? In: Proceedings of the 4th IEEE International Conference on Malicious and Unwanted Software, pp. 1\u20137. IEEE, New York (2009)","DOI":"10.1109\/MALWARE.2009.5403026"},{"key":"95_CR14","doi-asserted-by":"crossref","unstructured":"Schmidt, A.D., Bye, R., Schmidt, H.G., Clausen, J., Kiraz, O., Y\u00fcksel, K., Camtepe, A., Albayrak, S.: Static analysis of executables for collaborative malware detection on android. In: IEEE International Congress on Communication (ICC) (2009)","DOI":"10.1109\/ICC.2009.5199486"},{"issue":"1","key":"95_CR15","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1109\/MSP.2009.26","volume":"7","author":"W Enck","year":"2009","unstructured":"Enck, W., Ongtang, M., McDaniel, P.: Understanding android security. IEEE Secur. Priv. 7(1), 50\u201357 (2009)","journal-title":"IEEE Secur. Priv."},{"key":"95_CR16","doi-asserted-by":"crossref","unstructured":"Shabtai A., Fledel, Y., Elovici, Y.: Securing android powered mobile devices using selinux. IEEE Security and Privacy, vol. 99 (2009). (PrePrints)","DOI":"10.1109\/MSP.2009.144"},{"key":"95_CR17","doi-asserted-by":"crossref","unstructured":"Scandariato, R., Walden, J.: Predicting vulnerable classes in an android application (2012)","DOI":"10.1145\/2372225.2372231"},{"key":"95_CR18","first-page":"329","volume":"2010","author":"A Shabtai","year":"2010","unstructured":"Shabtai, A., Fledel, Y., Elovici, Y.: Automated static code analysis for classifying android applications using machine learning. CIS. Conf. IEEE 2010, 329\u2013333 (2010)","journal-title":"CIS. Conf. IEEE"},{"key":"95_CR19","doi-asserted-by":"crossref","unstructured":"Chin, E., Felt, A., Greenwood, K., Wagner, D.: Analyzing inter-application communication in android. In: 9th Conference on Mobile Systems, Applications, and Services. ACM, New York, pp. 239\u2013252 (2011)","DOI":"10.1145\/1999995.2000018"},{"key":"95_CR20","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., Nadjm-Tehrani, S.: Crowdroid: behavior-based malware detection system for android. In: 1st ACM Workshop on on SPSM. ACM, New York, pp. 15\u201326 (2011)","DOI":"10.1145\/2046614.2046619"},{"key":"95_CR21","doi-asserted-by":"crossref","unstructured":"Glodek, W., Harang, R.R.: Permissions-based detection and analysis of mobile malware using random decision forests. In: IEEE Military Communications Conference (2013)","DOI":"10.1109\/MILCOM.2013.170"},{"issue":"2","key":"95_CR22","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1109\/TNSM.2013.022713.120250","volume":"10","author":"J Zhang","year":"2013","unstructured":"Zhang, J., et al.: An effective network traffic classification method with unknown flow detection. IEEE Trans. Netw. Serv. Manag. 10(2), 133\u2013147 (2013)","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"95_CR23","first-page":"321","volume":"XXII","author":"J Gardiner","year":"2014","unstructured":"Gardiner, J., Shishir, N.: On the reliability of network measurement techniques used for malware traffic analysis. Secur. Protoc. XXII, 321\u2013333 (2014)","journal-title":"Secur. Protoc."},{"key":"95_CR24","doi-asserted-by":"crossref","unstructured":"Wang, H.T., et\u00a0al.: Real-time fast-flux identification via localized spatial geolocation detection. In: Computer Software and Applications Conference (COMPSAC). IEEE, New York (2012)","DOI":"10.1109\/COMPSAC.2012.35"},{"key":"95_CR25","doi-asserted-by":"crossref","unstructured":"Tu, T.D., Cheng, G., Liang, Y.X.: Detecting bot-infected machines based on analyzing the similar periodic DNS queries. In: 2015 International Conference on Communications, Management and Telecommunications (ComManTel). IEEE, New York (2015)","DOI":"10.1109\/ComManTel.2015.7394256"},{"issue":"28","key":"95_CR26","first-page":"1","volume":"8","author":"AA Sangroudi","year":"2015","unstructured":"Sangroudi, A.A., Seyed, J.M.: Botnets detection for keeping the security of computer systems based on fuzzy clustering. Ind. J. Sci. Technol. 8(28), 1 (2015)","journal-title":"Ind. J. Sci. Technol."},{"key":"95_CR27","unstructured":"Soltanaghaei, E., Kharrazi, M.: Detection of fast-flux botnets through DNS traffic analysis. Scientia Iranica. Trans D Comput Sci Eng Electr 22(6), 2389 (2015)"},{"key":"95_CR28","unstructured":"Wright, M.K., Adler, M., Levine, B.N., Shields, C.: An analysis of the degradation of anonymous protocols. In: Proceed. of the Network and Distributed Security Symposium (2002)"},{"key":"95_CR29","doi-asserted-by":"crossref","unstructured":"Shmatikov, V., Wang, M.H.: Timing analysis in low-latency mixnetworks: attacks and defenses. In: Proceedings of ESORICS (2006)","DOI":"10.1007\/11863908_2"},{"key":"95_CR30","doi-asserted-by":"publisher","unstructured":"Cheng, C., Peng, T.W., Guang-Bin, H.: Extreme learning machines for intrusion detection: IJCNN. In: International Joint Conference (2012). doi: 10.1109\/IJCNN.2012.6252449","DOI":"10.1109\/IJCNN.2012.6252449"},{"key":"95_CR31","doi-asserted-by":"crossref","unstructured":"Hsu, C.H., Huang, C.Y., Chen, K.T.: Fast-flux bot detection in real time. In: 13th International Conference on Recent Advances in Intrusion Detection, ser. RAID\u201910 (2010)","DOI":"10.1007\/978-3-642-15512-3_24"},{"key":"95_CR32","doi-asserted-by":"crossref","unstructured":"Haffner, P., Sen, S., Spatscheck, O., Wang, D.: ACAS: auto-mated construction of application signatures. In: Proceedings of the ACM SIGCOMM, pp. 197\u2013202 (2005)","DOI":"10.1145\/1080173.1080183"},{"key":"95_CR33","doi-asserted-by":"crossref","unstructured":"Alshammari, R., Zincir-Heywood, N.A.: A flow based approach for SSH traffic detection. In: IEEE International Conference on Cybernetics, ISIC, pp. 296\u2013301 (2007)","DOI":"10.1109\/ICSMC.2007.4414006"},{"key":"95_CR34","unstructured":"Holz, T., Gorecki, C., Rieck, K., Freiling, F.: Measuring and detecting fast-flux service networks. In: NDSS \u201908: Proceedings of the Network & Distributed System Security (2008)"},{"issue":"1\u20132","key":"95_CR35","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1007\/s11416-012-0162-3","volume":"8","author":"A Apvrille","year":"2012","unstructured":"Apvrille, A., Strazzere, T.: Reducing the window of opportunity forandroid malware: Gotta catch \u2019em all. J. Comput. Virol. 8(1\u20132), 61\u201371 (2012)","journal-title":"J. Comput. Virol."},{"key":"95_CR36","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., Nadjm-Tehrani, S.: Crowdroid: behavior-based malware detection system for android. In: ACM Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM) (2011)","DOI":"10.1145\/2046614.2046619"},{"key":"95_CR37","doi-asserted-by":"crossref","unstructured":"Afonso, V.M., de Amorim, M.F., Gr\u2019egio, A.R.A., Junquera, G.B., de Geus, P.L.: Identifying android malware using dynamically obtained features. J. Comput. Virol. Hack. Techniq. (2014)","DOI":"10.1007\/s11416-014-0226-7"},{"key":"95_CR38","doi-asserted-by":"crossref","unstructured":"Dini, G., Martinelli, F., Saracino, A., Sgandurra, D.: MADAM: a multi-level anomaly detector for android malware. In: Proceedings of 6 $$^{th}$$ t h MMM-ACNS, St. Petersburg, Russia (2012)","DOI":"10.1007\/978-3-642-33704-8_21"},{"key":"95_CR39","doi-asserted-by":"crossref","unstructured":"Wu, W.-C., Hung, S.-H.: DroidDolphin: a dynamic androidmalware detection framework using big data and machine learning. In: Conference on Research in Adaptive and Convergent Systems (RACS) (2014)","DOI":"10.1145\/2663761.2664223"},{"key":"95_CR40","doi-asserted-by":"crossref","unstructured":"Chakravarty, S., Barbera, M.V., Portokalidis, G., Polychronakis, M., Keromytis, A.D.: On the effectiveness of traffic analysis against anonymity networks using flow records. In: Proceedings on 15th International Conference, PAM 2014, pp 247\u2013257, Springer, Berlin (2014)","DOI":"10.1007\/978-3-319-04918-2_24"},{"key":"95_CR41","first-page":"10","volume":"7","author":"A Almubayed","year":"2015","unstructured":"Almubayed, A., Hadi, A., Atoum, J.: A model for detecting tor encrypted traffic using supervised machine learning, I. J. Comput. Netw. Inf. Secur. 7, 10\u201323 (2015)","journal-title":"J. Comput. Netw. Inf. Secur."},{"key":"95_CR42","doi-asserted-by":"crossref","unstructured":"Chaabane, A., Manils, P., Kaafar, M.A.: Digging into anonymous traffic: a deep analysis of the tor anonymizing network. In: 4th International Conference on Network and System Security (NSS), pp. 167\u2013174 (2010)","DOI":"10.1109\/NSS.2010.47"},{"key":"95_CR43","doi-asserted-by":"crossref","unstructured":"Chakravarty, S., Stavrou, A., Keromytis, A.D.: Traffic analysis against low-latency anonymity networks using available bandwidth estimation. In: Proceedings of the 15th European Conference on Research in Computer Security, Ser. ESORICS\u201910, pp. 249\u2013267. Springer, Berlin (2010)","DOI":"10.1007\/978-3-642-15497-3_16"},{"key":"95_CR44","doi-asserted-by":"crossref","unstructured":"Chakravarty, S., Stavrou, A., Keromytis, A.D.: Identifying proxy nodes in a tor anonymization circuit. In: Proceedings of the 2nd Workshop on Security and Privacy in Telecommunications and Information Systems (SePTIS), December 2008, pp. 633\u2013639","DOI":"10.1109\/SITIS.2008.93"},{"key":"95_CR45","doi-asserted-by":"crossref","unstructured":"Demertzis, K., Lazaros I.: SAME: An Intelligent Anti-Malware Extension for Android ART Virtual Machine,\u00a0Computational Collective Intelligence, pp. 235\u2013245. Springer, Berlin (2015)","DOI":"10.1007\/978-3-319-24306-1_23"},{"issue":"6","key":"95_CR46","doi-asserted-by":"crossref","first-page":"1411","DOI":"10.1109\/TNN.2006.880583","volume":"17","author":"N-Y Liang","year":"2006","unstructured":"Liang, N.-Y., Huang, G.-B., Saratchandran, P., Sundararajan, N.: A fast and accurate on-line sequential learning algorithm for feedforward networks. IEEE Trans. Neural Netw. 17(6), 1411\u20131423 (2006)","journal-title":"IEEE Trans. Neural Netw."},{"key":"95_CR47","unstructured":"Cambria, E., Guang-Bin, H.: Extreme learning machines. IEEE InTeLLIGenT SYSTemS 541-1672\/13 (2013)"},{"key":"95_CR48","unstructured":"Huang G.-B., Liang N.-Y., Rong H.-J., Saratchandran P., Sundararajan N.: On-line sequential extreme learning machine, IASTED (2005)"},{"key":"95_CR49","unstructured":"http:\/\/malware-traffic-analysis.net\/"},{"key":"95_CR50","first-page":"1530","volume":"3","author":"W Haining","year":"2002","unstructured":"Haining, W., Danlu, Z., Kang, G.S.: Detecting SYN flooding attacks, proceedings on INFOCOM 2002. Twenty-First Annu. Joint Conf. IEEE Comput. Commun. Soc. 3, 1530\u20131539 (2002)","journal-title":"Twenty-First Annu. Joint Conf. IEEE Comput. Commun. Soc."},{"key":"95_CR51","unstructured":"http:\/\/www.netresec.com\/?page=PcapFiles"},{"key":"95_CR52","doi-asserted-by":"crossref","unstructured":"Arndt, D.J., Zincir-Heywood, A.N.: 2011 IEEE Symposium on A Comparison of Three Machine Learning Techniques for Encrypted Network Traffic Analysis, Computational Intelligence for Security and Defense Applications (CISDA), pp. 107\u2013114","DOI":"10.1109\/CISDA.2011.5945941"},{"key":"95_CR53","unstructured":"http:\/\/contagiodump.blogspot.gr\/"},{"key":"95_CR54","unstructured":"Iliadis, L.: Intelligent Information Systems and Applications in Risk Estimation. ISBN: 978-960-6741-33-3 A. Stamoulis Publication, Thessaloniki (2008)"},{"key":"95_CR55","doi-asserted-by":"crossref","unstructured":"Bailey, M., Oberheide, J., Andersen, J., Mao, Z.M., Jahanian, F., Nazario, J.: Automated classification and analysis of internet malware. In: Kr\u00c3ijgel, C., Lippmann, R., Clark, A. (eds.). RAID of Lecture Notes in Computer Science, vol. 4637, pp. 178\u2013197. Springer, Berlin (2007)","DOI":"10.1007\/978-3-540-74320-0_10"},{"issue":"13","key":"95_CR56","first-page":"34","volume":"44","author":"A Desai","year":"2012","unstructured":"Desai, A., Jadav, P.M.: An empirical evaluation of adaboost extensions for cost-sensitive classification. Int. J. Comput. Appl. 44(13), 34\u201341 (2012)","journal-title":"Int. J. Comput. Appl."}],"container-title":["Vietnam Journal of Computer Science"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s40595-017-0095-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s40595-017-0095-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s40595-017-0095-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,19]],"date-time":"2019-09-19T05:01:04Z","timestamp":1568869264000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s40595-017-0095-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,28]]},"references-count":56,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,11]]}},"alternative-id":["95"],"URL":"https:\/\/doi.org\/10.1007\/s40595-017-0095-3","relation":{},"ISSN":["2196-8888","2196-8896"],"issn-type":[{"value":"2196-8888","type":"print"},{"value":"2196-8896","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,28]]}}}