{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T23:30:06Z","timestamp":1780961406234,"version":"3.54.1"},"reference-count":24,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,9]]},"DOI":"10.1109\/icnss.2011.6059956","type":"proceedings-article","created":{"date-parts":[[2011,11,1]],"date-time":"2011-11-01T20:59:24Z","timestamp":1320181164000},"page":"25-32","source":"Crossref","is-referenced-by-count":3,"title":["Towards ground truthing observations in gray-box anomaly detection"],"prefix":"10.1109","author":[{"given":"Jiang","family":"Ming","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haibin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Debin","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-540-39650-5_19","article-title":"On the detection of anomalous system call arguments","author":"kruegel","year":"2003","journal-title":"Proceedings of ESORICS 2003"},{"key":"ref11","article-title":"Learning rules from system calls arguments and sequences from anomaly detection","author":"tandon","year":"2003","journal-title":"Proc ICDM Workshop Data Mining for Computer Security (DMSEC)"},{"key":"ref12","article-title":"Learning useful system call attributes for anomaly detection","author":"tandon","year":"2005","journal-title":"Proceedings of the 18th International FLAIRS Conference"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.17"},{"key":"ref14","article-title":"Scalable, behavior based malware clustering","author":"bayer","year":"2009","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref15","article-title":"Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones","author":"enck","year":"2010","journal-title":"Proceedings of the second USENIX symposium on Operating systems design and implementation"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.26"},{"key":"ref17","article-title":"Dynamic spyware analysis","author":"egele","year":"2007","journal-title":"Proceedings of the 2007 USENIX Annual Technical Conference"},{"key":"ref18","article-title":"Panorama: capturing system-wide information flow for malware detection and analysis","author":"yin","year":"2007","journal-title":"ACM Conference on Computer and Communications Security (CCS 2007)"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.36"},{"key":"ref4","article-title":"On gray-box program tracking for anomaly detection","author":"gao","year":"2004","journal-title":"Proceedings of the 13th USENIX Security Symposium"},{"key":"ref3","article-title":"Gray-box extraction of execution graphs for anomaly detection","author":"gao","year":"2003","journal-title":"Proceedings of the 11th ACM Conference on Computer and Communication Security(CCS 2003)"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924296"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924295"},{"key":"ref8","doi-asserted-by":"crossref","DOI":"10.1007\/3-540-39945-3_8","article-title":"Intrusion detection using variable-length audit trail patterns","author":"wespi","year":"2000","journal-title":"Proc Int l Symp Recent Advances in Intrusion Detection"},{"key":"ref7","article-title":"An intrusion-detection system based on the teiresias pattern-discovery algorithm","author":"wespi","year":"1999","journal-title":"Proceedings of the 1999 European Institute for Computer Anti-Virus Research Conference"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2003.1199328"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.12"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"ref22","article-title":"Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software","author":"newsome","year":"2005","journal-title":"Proceedings of NDSS 2005"},{"key":"ref21","article-title":"Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks","author":"xu","year":"2006","journal-title":"Proceedings of the 15th conference on USENIX Security Symposium"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_34"},{"key":"ref23","article-title":"Temu: Binary code analysis via whole-system layered annotative execution","author":"yin","year":"2010","journal-title":"EECS Department University of California Berkeley Tech Rep"}],"event":{"name":"2011 5th International Conference on Network and System Security (NSS)","location":"Milan, Italy","start":{"date-parts":[[2011,9,6]]},"end":{"date-parts":[[2011,9,8]]}},"container-title":["2011 5th International Conference on Network and System Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6044613\/6059944\/06059956.pdf?arnumber=6059956","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,20]],"date-time":"2017-06-20T08:56:13Z","timestamp":1497948973000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6059956\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,9]]},"references-count":24,"URL":"https:\/\/doi.org\/10.1109\/icnss.2011.6059956","relation":{},"subject":[],"published":{"date-parts":[[2011,9]]}}}