{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:57:40Z","timestamp":1760245060249,"version":"3.28.0"},"reference-count":26,"publisher":"IEEE","license":[{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1109\/globecom38437.2019.9014069","type":"proceedings-article","created":{"date-parts":[[2020,2,28]],"date-time":"2020-02-28T04:59:24Z","timestamp":1582865964000},"page":"1-6","source":"Crossref","is-referenced-by-count":5,"title":["Targeted Malicious Email Detection Using Hypervisor-Based Dynamic Analysis and Ensemble Learning"],"prefix":"10.1109","author":[{"given":"Jian","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenzhen","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liangyi","family":"Gong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhaojun","family":"Gu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jeffrey","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","first-page":"181","author":"amin","year":"2010","journal-title":"Detecting Targeted Malicious Email Through Supervised Classification of Persistent Threat and Recipient Oriented Features"},{"key":"ref11","first-page":"797","article-title":"Two-stage elm for phishing web pages detection using hybrid features","volume":"20","author":"wei","year":"2017","journal-title":"WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.21236\/ADA456046"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2004.06.003"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361073"},{"key":"ref15","first-page":"191","article-title":"A virtual machine introspection based architecture for intrusion detection","author":"tal","year":"0","journal-title":"10th Annual Network and Distributed System Security Symposium"},{"key":"ref16","first-page":"133","article-title":"When virtual is better than real","author":"chen","year":"0","journal-title":"The 8th Workshop on Hot Topics in Operating System - HotOS VIII"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/2775111"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.43"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664252"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/IACS.2018.8355435"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2018.05.031"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICFN.2010.39"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/DIPDMWC.2016.7529371"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/2381716.2381863"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-015-2069-7"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.154"},{"key":"ref9","first-page":"2881","article-title":"Emics: E-mail based malware infected ip collection system","volume":"12","author":"lee","year":"2018","journal-title":"KSII Transactions on Internet and Information Systems"},{"journal-title":"Malicious email mitigation strategies","year":"0","key":"ref1"},{"journal-title":"The Art of Memory Forensics Detecting Malware and Threats in Windows Linux and Mac Memory","year":"2014","author":"ligh","key":"ref20"},{"journal-title":"Pcsl","year":"0","key":"ref22"},{"journal-title":"Internet Threat Security Report 2019","year":"2019","key":"ref21"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CTS.2016.0052"},{"journal-title":"VirusTotal","year":"0","key":"ref23"},{"key":"ref26","article-title":"Efficient spear-phishing threat detection using hypervisor monitor","author":"lin","year":"0","journal-title":"International Carnahan Conference on Security Technology"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CAC.2017.8243969"}],"event":{"name":"GLOBECOM 2019 - 2019 IEEE Global Communications Conference","start":{"date-parts":[[2019,12,9]]},"location":"Waikoloa, HI, USA","end":{"date-parts":[[2019,12,13]]}},"container-title":["2019 IEEE Global Communications Conference (GLOBECOM)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8968653\/9013108\/09014069.pdf?arnumber=9014069","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,17]],"date-time":"2022-07-17T17:55:26Z","timestamp":1658080526000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9014069\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/globecom38437.2019.9014069","relation":{},"subject":[],"published":{"date-parts":[[2019,12]]}}}