{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T23:05:34Z","timestamp":1729638334626,"version":"3.28.0"},"reference-count":28,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,9]]},"DOI":"10.1109\/icnss.2011.6060027","type":"proceedings-article","created":{"date-parts":[[2011,11,1]],"date-time":"2011-11-01T16:59:24Z","timestamp":1320166764000},"page":"342-346","source":"Crossref","is-referenced-by-count":12,"title":["Semi-supervised learning for packed executable detection"],"prefix":"10.1109","author":[{"given":"Xabier","family":"Ugarte-Pedrero","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor","family":"Santos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pablo G.","family":"Bringas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mikel","family":"Gastesi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jose Miguel","family":"Esparza","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.15"},{"key":"ref11","article-title":"Eureka: A framework for enabling static analysis on malware","author":"yegneswaran","year":"2008","journal-title":"Technical Report SRI-CSL-08&#x2013;01 Tech Rep"},{"key":"ref12","article-title":"Anti-debugging and anti-emulation techniques","volume":"5","author":"danielescu","year":"2008","journal-title":"Code-Breakers Journal"},{"key":"ref13","first-page":"121","article-title":"PE-Miner: Mining Structural Information to Detect Malicious Executables in Realtime","author":"farooq","year":"2009","journal-title":"Proceedings of the 12th International Symposium on Recent Advances in Intrusion Detection (RAID) Springer-Verlag"},{"key":"ref14","article-title":"PE-Probe: Leveraging Packer Detection and Structural Information to Detect Malicious Portable Executables","author":"shafiq","year":"2009","journal-title":"Proceedings of the Virus Bulletin Conference (VB)"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.22"},{"key":"ref16","first-page":"488","article-title":"Using an ensemble of one-class svm classifiers to harden payload-based anomaly detection systems","author":"perdisci","year":"2007","journal-title":"Proc IEEE Int Conf Data Mining (ICDM)"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/9780262033589.001.0001"},{"key":"ref18","first-page":"595","article-title":"Learning with local and global consistency","author":"zhou","year":"2004","journal-title":"Advances In Neural Information Processing Systems 16 Proceedings of The 2003 Conference"},{"key":"ref19","first-page":"50","article-title":"Structural feature based anomaly detection for packed executable identification","author":"ugarte-pedrero","year":"2011","journal-title":"Proceedings of the 4th International Conference on Computational Intelligence in Security for Information Systems (CISIS)"},{"key":"ref28","article-title":"Unpacking virtualization obfuscators","author":"rolles","year":"2009","journal-title":"Proceedings of USENIX Workshop on Offensive Technologies (WOOT)"},{"key":"ref4","article-title":"Useful and useless statistics about viruses and anti-virus programs","author":"morgenstern","year":"2010","journal-title":"Proceedings of the CARO Work shop"},{"article-title":"Rotalume: A Tool for Automatic Reverse Engineering of Malware Emulators","year":"2009","author":"sharif","key":"ref27"},{"journal-title":"Faster Universal Unpacker","year":"1999","key":"ref3"},{"journal-title":"Data Rescue","article-title":"Universal PE Unpacker plug-in","year":"0","key":"ref6"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/IC4.2009.4909168"},{"key":"ref8","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1109\/ACSAC.2006.38","article-title":"Polyunpack: Automating the hidden-code extraction of unpack-executing malware","author":"royal","year":"2006","journal-title":"Proceedings of the 2006 Annual Computer Security Applications Conference (ACSAC)"},{"key":"ref7","article-title":"Ollybone: Semi-automatic unpacking on ia-32","author":"stewart","year":"2006","journal-title":"Proceedings of the 14th DEF CON Hacking Conference"},{"journal-title":"PeiD","article-title":"PEiD webpage","year":"2010","key":"ref2"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/1314389.1314399"},{"journal-title":"McAfee Labs","article-title":"Mcafee whitepaper: The good, the bad, and the unknown","year":"2011","key":"ref1"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1093\/biomet\/70.1.163"},{"journal-title":"VX heavens","year":"0","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.48"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1504\/IJCAT.2009.026595"},{"key":"ref23","first-page":"57","article-title":"Weka: The Waikato environment for knowledge analysis","author":"garner","year":"1995","journal-title":"Proceedings of the New Zealand Computer Science Research Students Conference"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.27"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2008.06.016"}],"event":{"name":"2011 5th International Conference on Network and System Security (NSS)","start":{"date-parts":[[2011,9,6]]},"location":"Milan, Italy","end":{"date-parts":[[2011,9,8]]}},"container-title":["2011 5th International Conference on Network and System Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6044613\/6059944\/06060027.pdf?arnumber=6060027","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,20]],"date-time":"2017-06-20T04:56:15Z","timestamp":1497934575000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6060027\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,9]]},"references-count":28,"URL":"https:\/\/doi.org\/10.1109\/icnss.2011.6060027","relation":{},"subject":[],"published":{"date-parts":[[2011,9]]}}}