{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T14:58:28Z","timestamp":1781621908025,"version":"3.54.5"},"reference-count":53,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,10]]},"DOI":"10.1109\/cns.2014.6997496","type":"proceedings-article","created":{"date-parts":[[2014,12,31]],"date-time":"2014-12-31T04:15:04Z","timestamp":1419999304000},"page":"283-291","source":"Crossref","is-referenced-by-count":23,"title":["Chatter: Classifying malware families using system event ordering"],"prefix":"10.1109","author":[{"given":"Aziz","family":"Mohaisen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrew G.","family":"West","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Allison","family":"Mankin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Omar","family":"Alrawi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"35","article-title":"Botminer: Clustering analysis of network traffic for protocol-and structure-independent botnet detection","author":"gu","year":"2008","journal-title":"USENIX Sec Symposium"},{"key":"36","article-title":"Botsniffer: Detecting botnet command and control channels in network traffic","author":"gu","year":"2008","journal-title":"NDSS"},{"key":"33","article-title":"Jackstraws: Picking command and control connections from bot traffic","author":"jacob","year":"2011","journal-title":"USENIX Sec Symposium"},{"key":"34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24550-3_17"},{"key":"39","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2008.4690854"},{"key":"37","article-title":"Bothunter: Detecting malware infection through ids-driven dialog correlation","author":"gu","year":"2007","journal-title":"USENIX Sec Symposium"},{"key":"38","article-title":"Measuring and detecting fast-flux service networks","author":"holz","year":"2008","journal-title":"NDSS"},{"key":"43","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.22"},{"key":"42","article-title":"K-tracer: A system for extracting kernel malware behavior","author":"lanzi","year":"2009","journal-title":"NDSS"},{"key":"41","article-title":"Detecting malware domains at the upper dns hierarchy","author":"antonakakis","year":"2011","journal-title":"USENIX Sec Symposium"},{"key":"40","article-title":"Building a dynamic reputation system for dns","author":"antonakakis","year":"2010","journal-title":"USENIX Sec Symposium"},{"key":"22","doi-asserted-by":"publisher","DOI":"10.1145\/1852666.1852716"},{"key":"23","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2008.4690860"},{"key":"24","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-011-0151-y"},{"key":"25","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2010.5665788"},{"key":"26","article-title":"The ghost in the browser analysis of web-based malware","author":"provos","year":"2007","journal-title":"USENIX HotBots"},{"key":"27","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2010.5593240"},{"key":"28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-08509-8_9"},{"key":"29","doi-asserted-by":"publisher","DOI":"10.1109\/IC4E.2010.78"},{"key":"3","article-title":"Towards a methodical evaluation of antivirus scans and labels","author":"mohaisen","year":"2013","journal-title":"The 14th International Workshop on Information Security Applications (WISA2013)"},{"key":"2","year":"0","journal-title":"Nissan is Latest Company to Get Hacked"},{"key":"1","author":"halliday","year":"0","journal-title":"Hackers Attack European Governments Using 'Miniduke' Malware"},{"key":"7","article-title":"Scalable, behavior-based malware clustering","author":"bayer","year":"2009","journal-title":"NDSS"},{"key":"30","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420979"},{"key":"6","doi-asserted-by":"crossref","first-page":"108","DOI":"10.1007\/978-3-540-70542-0_6","article-title":"Learning and classification of malware behavior","author":"rieck","year":"2008","journal-title":"Detection of Intrusions and Malware and Vulnerability Assessment"},{"key":"5","article-title":"Panorama: Capturing system-wide information flow for malware detection and analysis","author":"yin","year":"2007","journal-title":"ACM Conference on Computer and Communications Security"},{"key":"32","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.27"},{"key":"4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40203-6_10"},{"key":"31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.10"},{"key":"9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"8","author":"mohaisen","year":"2013","journal-title":"Amal High-fidelity Behavior-based Automated Malware Analysis and Classification"},{"key":"19","year":"0","journal-title":"Volume of Malware Threatens Security"},{"key":"17","author":"alperovitch","year":"0","journal-title":"Yara Project A Malware Identification and Classification Tool"},{"key":"18","article-title":"Exposure: Finding malicious domains using passive dns analysis","author":"bilge","year":"2011","journal-title":"NDSS"},{"key":"15","first-page":"829","article-title":"Unveiling zeus: Automated classification of malware samples","author":"mohaisen","year":"2013","journal-title":"WWW (Companion Volume)"},{"key":"16","author":"alperovitch","year":"0","journal-title":"Revealed Operation Shady RAT"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.14"},{"key":"14","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"11","article-title":"Automated classification and analysis of internet malware","author":"bailey","year":"2007","journal-title":"RAID"},{"key":"12","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-39235-1_3","article-title":"Exploring discriminatory features for automated malware classification","author":"yan","year":"2013","journal-title":"10th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA)"},{"key":"21","doi-asserted-by":"crossref","first-page":"639","DOI":"10.3233\/JCS-2010-0410","article-title":"Automatic analysis of malware behavior using machine learning","volume":"19","author":"rieck","year":"2011","journal-title":"Journal of Computer Security"},{"key":"20","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2009.5403021"},{"key":"49","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-68768-1_1"},{"key":"48","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"45","first-page":"61","article-title":"A survey on automated dynamic malware-analysis techniques and tools","volume":"44","author":"egele","year":"2008","journal-title":"ACM Comput Surv"},{"key":"44","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866356"},{"key":"47","first-page":"2721","article-title":"Learning to detect and classify malicious executables in the wild","volume":"7","author":"kolter","year":"2006","journal-title":"The Journal of Machine Learning Research"},{"key":"46","first-page":"67","article-title":"A close look on n-grams in intrusion detection: Anomaly detection vs. Classification","author":"wressnegger","year":"2013","journal-title":"2013 ACM Workshop on Artificial Intelligence and Security ACM"},{"key":"10","doi-asserted-by":"publisher","DOI":"10.1145\/2487575.2488219"},{"key":"51","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420969"},{"key":"52","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2013.6682751"},{"key":"53","author":"alpaydin","year":"2004","journal-title":"Introduction to Machine Learning"},{"key":"50","article-title":"Behavioral clustering of http-based malware and signature generation using malicious network traces","author":"perdisci","year":"2010","journal-title":"USENIX NSDI"}],"event":{"name":"2014 IEEE Conference on Communications and Network Security (CNS)","location":"San Francisco, CA, USA","start":{"date-parts":[[2014,10,29]]},"end":{"date-parts":[[2014,10,31]]}},"container-title":["2014 IEEE Conference on Communications and Network Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6982337\/6997445\/06997496.pdf?arnumber=6997496","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,14]],"date-time":"2020-10-14T14:31:44Z","timestamp":1602685904000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/6997496"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,10]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/cns.2014.6997496","relation":{},"subject":[],"published":{"date-parts":[[2014,10]]}}}