{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T14:58:51Z","timestamp":1764687531551,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2008,6,17]],"date-time":"2008-06-17T00:00:00Z","timestamp":1213660800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2008,6,17]]},"DOI":"10.1145\/1378600.1378626","type":"proceedings-article","created":{"date-parts":[[2008,6,17]],"date-time":"2008-06-17T13:49:02Z","timestamp":1213710542000},"page":"225-238","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":160,"title":["Behavioral detection of malware on mobile handsets"],"prefix":"10.1145","author":[{"given":"Abhijit","family":"Bose","sequence":"first","affiliation":[{"name":"IBM TJ Watson Research, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xin","family":"Hu","sequence":"additional","affiliation":[{"name":"The University of Michigan, Ann Arbor, MI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kang G.","family":"Shin","sequence":"additional","affiliation":[{"name":"The University of Michigan, Ann Arbor, MI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taejoon","family":"Park","sequence":"additional","affiliation":[{"name":"Samsung Electronics, Gyeonggi-Do, South Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,6,17]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Rootkitrevealer 1.71. http:\/\/technet.microsoft.com\/enus\/sysinternals\/bb897445.aspx.  Rootkitrevealer 1.71. http:\/\/technet.microsoft.com\/enus\/sysinternals\/bb897445.aspx."},{"key":"e_1_3_2_1_2_1","unstructured":"UPX\n  : the ultimate packer for executables. http:\/\/upx.sourceforge.net\/.  UPX: the ultimate packer for executables. http:\/\/upx.sourceforge.net\/."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-6423(92)90005-V"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECCOMW.2006.359562"},{"key":"e_1_3_2_1_5_1","volume-title":"Black Hat USA","author":"Brosch T.","year":"2006","unstructured":"T. Brosch and M. Morgenstern . Runtime packers: The hidden problem? Black Hat USA 2006 . T. Brosch and M. Morgenstern. Runtime packers: The hidden problem? Black Hat USA 2006."},{"key":"e_1_3_2_1_6_1","volume-title":"LIBSVM: a library for support vector machines","author":"Chang C.-C.","year":"2001","unstructured":"C.-C. Chang and C.-J. Lin . LIBSVM: a library for support vector machines , 2001 . Software available at http:\/\/www.csie.ntu.edu.tw\/cjlin\/libsvm. C.-C. Chang and C.-J. Lin. LIBSVM: a library for support vector machines, 2001. Software available at http:\/\/www.csie.ntu.edu.tw\/cjlin\/libsvm."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1247660.1247690"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/345662"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/B978-1-55860-377-6.50023-2"},{"key":"e_1_3_2_1_10_1","unstructured":"S. Corp. Symantec internet security threat report trends. http:\/\/www.symantec.com\/business\/theme.jsp?themeid=threatreport.  S. Corp. Symantec internet security threat report trends. http:\/\/www.symantec.com\/business\/theme.jsp?themeid=threatreport."},{"key":"e_1_3_2_1_11_1","unstructured":"K. Corporation\". Kaspersky Anti-Virus Mobile. http:\/\/usa.kaspersky.com\/products_services\/antivirusmobile.php.  K. Corporation\". Kaspersky Anti-Virus Mobile. http:\/\/usa.kaspersky.com\/products_services\/antivirusmobile.php."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 15th USENIX Security Symposium","author":"Kirda E.","year":"2006","unstructured":"E. Kirda , C. Kruegel , G. Banks , G. Vigna , and R. Kemmerer . Behavior-based spyware detection . In Proceedings of the 15th USENIX Security Symposium , 2006 . E. Kirda, C. Kruegel, G. Banks, G. Vigna, and R. Kemmerer. Behavior-based spyware detection. In Proceedings of the 15th USENIX Security Symposium, 2006."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029625"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102171"},{"key":"e_1_3_2_1_15_1","unstructured":"F-secure. Cabir. http:\/\/www.f-secure.com\/v-descs\/cabir.shtml.  F-secure. Cabir. http:\/\/www.f-secure.com\/v-descs\/cabir.shtml."},{"key":"e_1_3_2_1_16_1","unstructured":"F-secure. Lasco. http:\/\/www.f-secure.com\/v-descs\/lasco_a.shtml.  F-secure. Lasco. http:\/\/www.f-secure.com\/v-descs\/lasco_a.shtml."},{"key":"e_1_3_2_1_17_1","unstructured":"F-secure. Mobile detection descriptions. http:\/\/www.f-secure.com\/v-descs\/mobile-description-index.shtml.  F-secure. Mobile detection descriptions. http:\/\/www.f-secure.com\/v-descs\/mobile-description-index.shtml."},{"key":"e_1_3_2_1_18_1","volume-title":"Aug","author":"Acallno S.","year":"2005","unstructured":"F-Secure. SymbO S. Acallno Trojan description. http:\/\/www.f-secure.com\/sw-desc\/acallno_a.shtml , Aug 2005 . F-Secure. SymbOS.Acallno Trojan description. http:\/\/www.f-secure.com\/sw-desc\/acallno_a.shtml, Aug 2005."},{"key":"e_1_3_2_1_19_1","volume-title":"Sep","author":"Cardtrap S.","year":"2005","unstructured":"F-Secure. SymbO S. Cardtrap Trojan description. http:\/\/www.f-secure.com\/v-descs\/cardtrap_a.shtml , Sep 2005 . F-Secure. SymbOS.Cardtrap Trojan description. http:\/\/www.f-secure.com\/v-descs\/cardtrap_a.shtml, Sep 2005."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314389.1314402"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/525080.884258"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/647593.728880"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-0953-0_7"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.34"},{"key":"e_1_3_2_1_25_1","unstructured":"T. M. Incorporated. Trend Micro mobile security. http:\/\/www.trendmicro.com\/en\/ products\/mobile\/tmms\/ 2006.  T. M. Incorporated. Trend Micro mobile security. http:\/\/www.trendmicro.com\/en\/ products\/mobile\/tmms\/ 2006."},{"key":"e_1_3_2_1_26_1","volume-title":"Advances in Kernel Methods: Support Vector Machines","author":"Joachims T.","year":"1998","unstructured":"T. Joachims . Making large-scale support vector machine learning practical . In B. Scholkopf, C. Burges, and A. Smola, editors, Advances in Kernel Methods: Support Vector Machines . MIT Press , Cambridge, MA , 1998 . T. Joachims. Making large-scale support vector machine learning practical. In B. Scholkopf, C. Burges, and A. Smola, editors, Advances in Kernel Methods: Support Vector Machines. MIT Press, Cambridge, MA, 1998."},{"key":"e_1_3_2_1_27_1","volume-title":"Api spying techniques for windows 9x, nt and","author":"Kaplan Y.","year":"2000","unstructured":"Y. Kaplan . Api spying techniques for windows 9x, nt and 2000 . http:\/\/www.internals.com\/articles\/apispy\/apispy.htm. Y. Kaplan. Api spying techniques for windows 9x, nt and 2000. http:\/\/www.internals.com\/articles\/apispy\/apispy.htm."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1047915.1047918"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1038\/449287a"},{"key":"e_1_3_2_1_30_1","unstructured":"K. Lab. Kaspersky security bulletin 2006: Mobile malware. http:\/\/www.viruslist.com\/en\/analysis?pubid=204791922.  K. Lab. Kaspersky security bulletin 2006: Mobile malware. http:\/\/www.viruslist.com\/en\/analysis?pubid=204791922."},{"key":"e_1_3_2_1_31_1","unstructured":"K. Lab. Mobile malware evolution: An overview part 2. http:\/\/www.viruslist.com\/en\/analysis?pubid=201225789.  K. Lab. Mobile malware evolution: An overview part 2. http:\/\/www.viruslist.com\/en\/analysis?pubid=201225789."},{"key":"e_1_3_2_1_32_1","unstructured":"K. Lab. Mobile threats - myth or reality? http:\/\/www.viruslist.com\/en\/weblog?weblogid=204924390.  K. Lab. Mobile threats - myth or reality? http:\/\/www.viruslist.com\/en\/weblog?weblogid=204924390."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/359545.359563"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.20"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080793.1080806"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0024-y"},{"key":"e_1_3_2_1_37_1","volume-title":"Intl. Joint Conf. on Neural Networks, 2002","author":"Mukkamala S.","year":"2002","unstructured":"S. Mukkamala , G. Janoski , and A. Sung . Intrusion detection using neural networks and support vectormachines . Intl. Joint Conf. on Neural Networks, 2002 , 2, 2002 . S. Mukkamala, G. Janoski, and A. Sung. Intrusion detection using neural networks and support vectormachines. Intl. Joint Conf. on Neural Networks, 2002, 2, 2002."},{"key":"e_1_3_2_1_38_1","first-page":"98","article-title":"Temporal logic of causal knowledge","author":"Penczek W.","year":"1998","unstructured":"W. Penczek . Temporal logic of causal knowledge . Proc. of WoLLiC , 98 , 1998 . W. Penczek. Temporal logic of causal knowledge. Proc. of WoLLiC, 98, 1998.","journal-title":"Proc. of WoLLiC"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_4"},{"key":"e_1_3_2_1_40_1","volume-title":"Regularization, Optimization, and Beyond","author":"Scholkopf B.","year":"2001","unstructured":"B. Scholkopf and A. J. Smola . Learning with Kernels: Support Vector Machines , Regularization, Optimization, and Beyond . MIT Press , Cambridge, MA, USA , 2001 . B. Scholkopf and A. J. Smola. Learning with Kernels: Support Vector Machines, Regularization, Optimization, and Beyond. MIT Press, Cambridge, MA, USA, 2001."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884433"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294294"},{"key":"e_1_3_2_1_43_1","volume-title":"October","author":"Commwarrior Worm Description S.","year":"2005","unstructured":"Symantec. SymbO S. Commwarrior Worm Description . http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/symbos.commwarrior.a.html , October 2005 . Symantec. SymbOS.Commwarrior Worm Description. http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/symbos.commwarrior.a.html, October 2005."},{"key":"e_1_3_2_1_44_1","volume-title":"April","author":"Mabir Worm Description S.","year":"2005","unstructured":"Symantec. SymbO S. Mabir Worm Description . http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/symbos.mabir.html , April 2005 . Symantec. SymbOS.Mabir Worm Description. http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/symbos.mabir.html, April 2005."},{"key":"e_1_3_2_1_45_1","unstructured":"Symbian. Symbian Signed platform security. http:\/\/www.symbiansigned.com.  Symbian. Symbian Signed platform security. http:\/\/www.symbiansigned.com."},{"key":"e_1_3_2_1_46_1","unstructured":"T. Lee and J. J. Mody. Behavioral classification. http:\/\/www.microsoft.com\/downloads\/details.aspx?FamilyID=7b5d8cc8-b336-4091-abb5-2cc500a6c41a&displaylang=en 2006.  T. Lee and J. J. Mody. Behavioral classification. http:\/\/www.microsoft.com\/downloads\/details.aspx?FamilyID=7b5d8cc8-b336-4091-abb5-2cc500a6c41a&displaylang=en 2006."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0022-0"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"V. Vapnik. The Nature of Statistical Learning Theory. Springer New York 1995.   V. Vapnik. The Nature of Statistical Learning Theory. Springer New York 1995.","DOI":"10.1007\/978-1-4757-2440-0"},{"key":"e_1_3_2_1_49_1","volume-title":"Mimicry attacks on host based intrusion detection systems","author":"Wagner D.","year":"2002","unstructured":"D. Wagner and P. Soto . Mimicry attacks on host based intrusion detection systems , 2002 . D. Wagner and P. Soto. Mimicry attacks on host based intrusion detection systems, 2002."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_12"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.18"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229285.1229294"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.857113"}],"event":{"name":"Mobisys08: The 6th International Conference on Mobile Systems, Applications, and Services","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing","ACM Association for Computing Machinery"],"location":"Breckenridge CO USA","acronym":"Mobisys08"},"container-title":["Proceedings of the 6th international conference on Mobile systems, applications, and services"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1378600.1378626","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1378600.1378626","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T14:57:54Z","timestamp":1750258674000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1378600.1378626"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,6,17]]},"references-count":54,"alternative-id":["10.1145\/1378600.1378626","10.1145\/1378600"],"URL":"https:\/\/doi.org\/10.1145\/1378600.1378626","relation":{},"subject":[],"published":{"date-parts":[[2008,6,17]]},"assertion":[{"value":"2008-06-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}