{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:43:11Z","timestamp":1783438991063,"version":"3.54.6"},"reference-count":28,"publisher":"Elsevier BV","issue":"3","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T00:00:00Z","timestamp":1736812800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["High-Confidence Computing"],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1016\/j.hcc.2025.100299","type":"journal-article","created":{"date-parts":[[2025,1,18]],"date-time":"2025-01-18T14:44:24Z","timestamp":1737211464000},"page":"100299","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":18,"title":["Reinforcement learning for an efficient and effective malware investigation during cyber incident response"],"prefix":"10.1016","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-7376-0477","authenticated-orcid":false,"given":"Dipo","family":"Dunsin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7067-7848","authenticated-orcid":false,"given":"Mohamed Chahine","family":"Ghanem","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Karim","family":"Ouazzane","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vassil","family":"Vassilev","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.hcc.2025.100299_b1","series-title":"MERLIN\u2013Malware Evasion with Reinforcement LearnINg","author":"Quertier","year":"2022"},{"key":"10.1016\/j.hcc.2025.100299_b2","doi-asserted-by":"crossref","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","article-title":"A comprehensive review on malware detection approaches","volume":"8","author":"Aslan","year":"2020","journal-title":"IEEE Access"},{"issue":"11","key":"10.1016\/j.hcc.2025.100299_b3","doi-asserted-by":"crossref","first-page":"2304","DOI":"10.3390\/sym14112304","article-title":"Malware analysis and detection using machine learning algorithms","volume":"14","author":"Akhtar","year":"2022","journal-title":"Symmetry"},{"issue":"8","key":"10.1016\/j.hcc.2025.100299_b4","first-page":"280","article-title":"The use of artificial intelligence in digital forensics and incident response in a constrained environment","volume":"16","author":"Dunsin","year":"2022","journal-title":"Int. J. Inf. Commun. Eng."},{"key":"10.1016\/j.hcc.2025.100299_b5","doi-asserted-by":"crossref","first-page":"48867","DOI":"10.1109\/ACCESS.2019.2908033","article-title":"Evading anti-malware engines with deep reinforcement learning","volume":"7","author":"Fang","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2025.100299_b6","series-title":"Proceedings of the 8th International Conference on Communication and Network Security","first-page":"74","article-title":"Enhancing machine learning based malware detection model by reinforcement learning","author":"Wu","year":"2018"},{"key":"10.1016\/j.hcc.2025.100299_b7","series-title":"2020 IEEE International Conference on Big Data (Big Data)","first-page":"2626","article-title":"Using knowledge graphs and reinforcement learning for malware analysis","author":"Piplai","year":"2020"},{"key":"10.1016\/j.hcc.2025.100299_b8","series-title":"AI-enabled system for efficient and effective cyber incident detection and response in cloud environments","author":"Farzaan","year":"2024"},{"issue":"4","key":"10.1016\/j.hcc.2025.100299_b9","doi-asserted-by":"crossref","first-page":"808","DOI":"10.3390\/jcp3040036","article-title":"D2WFP: a novel protocol for forensically identifying, extracting, and analysing deep and dark web browsing activities","volume":"3","author":"Ghanem","year":"2023","journal-title":"J. Cybersecur. Priv."},{"key":"10.1016\/j.hcc.2025.100299_b10","doi-asserted-by":"crossref","first-page":"176177","DOI":"10.1109\/ACCESS.2019.2957429","article-title":"Feature selection for malware detection based on reinforcement learning","volume":"7","author":"Fang","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2025.100299_b11","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2023.3332834","article-title":"ESASCF: expertise extraction, generalization and reply framework for optimized automation of network security compliance","author":"Ghanem","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2025.100299_b12","series-title":"2019 6th International Conference on Information Science and Control Engineering (ICISCE) (23\u201327), Shanghai, China, 2019","first-page":"23","article-title":"A deep reinforcement learning malware detection method based on PE feature distribution","author":"Binxiang","year":"2019"},{"key":"10.1016\/j.hcc.2025.100299_b13","series-title":"Binary black-box attacks against static malware detectors with reinforcement learning in discrete action spaces","first-page":"85","author":"Ebrahimi","year":"2021"},{"key":"10.1016\/j.hcc.2025.100299_b14","series-title":"Advanced persistent threats (APT) attribution using deep reinforcement learning","author":"Basnet","year":"2024"},{"key":"10.1016\/j.hcc.2025.100299_b15","series-title":"Workshops at the Thirty-Second AAAI Conference on Artificial Intelligence","article-title":"Malware detection by eating a whole exe","author":"Raff","year":"2018"},{"key":"10.1016\/j.hcc.2025.100299_b16","series-title":"2020 20th IEEE\/ACM International Symposium on Cluster, Cloud and Internet Computing (CCGRID), Melbourne, VIC, Australia","first-page":"420","article-title":"Cost-effective malware detection as a service over serverless cloud using deep reinforcement learning","author":"Birman","year":"2020"},{"key":"10.1016\/j.hcc.2025.100299_b17","series-title":"Learning to evade static PE machine learning malware models via reinforcement learning","author":"Anderson","year":"2018"},{"key":"10.1016\/j.hcc.2025.100299_b18","series-title":"Mab-malware: A reinforcement learning framework for attacking static malware classifiers","author":"Song","year":"2020"},{"issue":"1","key":"10.1016\/j.hcc.2025.100299_b19","first-page":"9567","article-title":"Policy teaching in reinforcement learning via environment poisoning attacks","volume":"22","author":"Rakhsha","year":"2021","journal-title":"J. Mach. Learn. Res."},{"key":"10.1016\/j.hcc.2025.100299_b20","series-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"issue":"7587","key":"10.1016\/j.hcc.2025.100299_b21","doi-asserted-by":"crossref","first-page":"484","DOI":"10.1038\/nature16961","article-title":"Mastering the game of go with deep neural networks and tree search","volume":"529","author":"Silver","year":"2016","journal-title":"Nature"},{"key":"10.1016\/j.hcc.2025.100299_b22","article-title":"A comprehensive analysis of the role of artificial intelligence and machine learning in modern digital forensics and incident response. Forensic Science International","volume":"48","author":"Dunsin","year":"2024","journal-title":"Digit. Investig."},{"key":"10.1016\/j.hcc.2025.100299_b23","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1109\/72.80230","article-title":"Perceptron-based learning algorithms","volume":"1","author":"Gallant","year":"1990","journal-title":"IEEE Trans. Neural Netw."},{"issue":"3","key":"10.1016\/j.hcc.2025.100299_b24","doi-asserted-by":"crossref","first-page":"677","DOI":"10.3390\/sym15030677","article-title":"Artificial intelligence-based malware detection, analysis, and mitigation","volume":"15","author":"Djenna","year":"2023","journal-title":"Symmetry"},{"issue":"4","key":"10.1016\/j.hcc.2025.100299_b25","doi-asserted-by":"crossref","first-page":"79","DOI":"10.3390\/computers12040079","article-title":"Developing resilient cyber\u2013physical systems: a review of state-of-the-art malware detection approaches, gaps, and future directions","volume":"12","author":"Malik","year":"2023","journal-title":"Computers"},{"key":"10.1016\/j.hcc.2025.100299_b26","doi-asserted-by":"crossref","first-page":"100529","DOI":"10.1016\/j.cosrev.2022.100529","article-title":"A comprehensive survey on deep learning based malware detection techniques","volume":"47","author":"Gopinath","year":"2023","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.hcc.2025.100299_b27","doi-asserted-by":"crossref","first-page":"46717","DOI":"10.1109\/ACCESS.2019.2906934","article-title":"Robust intelligent malware detection using deep learning","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"issue":"4","key":"10.1016\/j.hcc.2025.100299_b28","doi-asserted-by":"crossref","first-page":"800","DOI":"10.3390\/jcp2040041","article-title":"A survey of the recent trends in deep learning based malware detection","volume":"2","author":"Tayyab","year":"2022","journal-title":"J. Cybersecur. Priv."}],"container-title":["High-Confidence Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295225000030?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295225000030?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T04:28:56Z","timestamp":1758688136000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2667295225000030"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":28,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,9]]}},"alternative-id":["S2667295225000030"],"URL":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100299","relation":{},"ISSN":["2667-2952"],"issn-type":[{"value":"2667-2952","type":"print"}],"subject":[],"published":{"date-parts":[[2025,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Reinforcement learning for an efficient and effective malware investigation during cyber incident response","name":"articletitle","label":"Article Title"},{"value":"High-Confidence Computing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100299","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 The Author(s). Published by Elsevier B.V. on behalf of Shandong University.","name":"copyright","label":"Copyright"}],"article-number":"100299"}}