{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:18:41Z","timestamp":1783610321430,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2010,10,4]],"date-time":"2010-10-04T00:00:00Z","timestamp":1286150400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2010,10,4]]},"DOI":"10.1145\/1866307.1866353","type":"proceedings-article","created":{"date-parts":[[2010,10,5]],"date-time":"2010-10-05T14:38:23Z","timestamp":1286289503000},"page":"399-412","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":127,"title":["AccessMiner"],"prefix":"10.1145","author":[{"given":"Andrea","family":"Lanzi","sequence":"first","affiliation":[{"name":"Institute Eurecom, Sophia-Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"Institute Eurecom, Sophia-Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, CA, Santa Barbara, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mihai","family":"Christodorescu","sequence":"additional","affiliation":[{"name":"IBM T.J. Watson Research, Center, Yorktown Heights, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Institute Eurecom, Sophia Antipolis, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2010,10,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"}}Anubis: analyzing unknown binaries. http:\/\/anubis.iseclab.org 2008.  }}Anubis: analyzing unknown binaries. http:\/\/anubis.iseclab.org 2008."},{"key":"e_1_3_2_1_2_1","series-title":"Lecture Notes in Computer Science}","doi-asserted-by":"crossref","first-page":"178","DOI":"10.1007\/978-3-540-74320-0_10","volume-title":"Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID'07)","author":"Bailey M.","year":"2007","unstructured":"}} M. Bailey , J. Oberheide , J. Andersen , Z.M. Mao , F. Jahanian , and J. Nazario . Automated classification and analysis of internet malware . In C.Kruegel, R.Lippmann, and A.Clark, editors, Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID'07) , volume 4637 of Lecture Notes in Computer Science} , pages 178 -- 197 , Gold Goast, Australia, Sept . 2007 . Springer-Verlag . }}M.Bailey, J.Oberheide, J.Andersen, Z.M. Mao, F.Jahanian, and J.Nazario. Automated classification and analysis of internet malware. In C.Kruegel, R.Lippmann, and A.Clark, editors, Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID'07), volume 4637 of Lecture Notes in Computer Science}, pages 178--197, Gold Goast, Australia, Sept. 2007. Springer-Verlag."},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS'09)","author":"Bayer U.","year":"2009","unstructured":"}} U. Bayer , P.M. Comparetti , C. Hlauschek , C. Kruegel , and E. Kirda . Scalable, behavior-based malware clustering . In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS'09) , San Diego, CA, USA , Feb. 2009 . }}U.Bayer, P.M. Comparetti, C.Hlauschek, C.Kruegel, and E.Kirda. Scalable, behavior-based malware clustering. In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS'09), San Diego, CA, USA, Feb. 2009."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/11790754_8"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.20"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1287624.1287628"},{"key":"e_1_3_2_1_7_1","first-page":"1","volume-title":"Proceedings of the Symposium on Requirements Engineering for Information Security (SREIS'01)","author":"Debbabi M.","year":"2001","unstructured":"}} M. Debbabi , M. Girard , L. Poulin , M. Salois , and N. Tawbi . Dynamic monitoring of malicious activity in software systems . In Proceedings of the Symposium on Requirements Engineering for Information Security (SREIS'01) , pages 1 -- 10 , Indianapolis, IN, USA , Mar. 2001 . }}M.Debbabi, M.Girard, L.Poulin, M.Salois, and N.Tawbi. Dynamic monitoring of malicious activity in software systems. In Proceedings of the Symposium on Requirements Engineering for Information Security (SREIS'01), pages 1--10, Indianapolis, IN, USA, Mar. 2001."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.41"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/525080.884258"},{"key":"e_1_3_2_1_10_1","volume-title":"Rootkits: Subverting the Windows kernel}","author":"Hoglund G.","year":"2005","unstructured":"}} G. Hoglund and J. Butler . Rootkits: Subverting the Windows kernel} . Addison-Wesley Professional , 2005 . }}G.Hoglund and J.Butler. Rootkits: Subverting the Windows kernel}. Addison-Wesley Professional, 2005."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/1813084.1813086"},{"key":"e_1_3_2_1_12_1","volume-title":"Studying Spamming Botnets using Botlab. &gt;In Usenix NSDI","author":"John J.","year":"2009","unstructured":"}} J. John , A. Moshchuk , S. Gribble , and A. Krishnamurthy . Studying Spamming Botnets using Botlab. &gt;In Usenix NSDI , 2009 . }}J.John, A.Moshchuk, S.Gribble, and A.Krishnamurthy. Studying Spamming Botnets using Botlab. &gt;In Usenix NSDI, 2009."},{"key":"e_1_3_2_1_13_1","volume-title":"6th IEEE Systems Man and Cybernetics Information Assurance Workshop (IAW)","author":"Kang D.","year":"2005","unstructured":"}} D. Kang , D. Fuller , and V. Honavar . Learning classifiers for misuse and anomaly detection using a bag on system calls representation . In 6th IEEE Systems Man and Cybernetics Information Assurance Workshop (IAW) , 2005 . }}D.Kang, D.Fuller, and V.Honavar. Learning classifiers for misuse and anomaly detection using a bag on system calls representation. In 6th IEEE Systems Man and Cybernetics Information Assurance Workshop (IAW), 2005."},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 15th USENIX Security Symposium (Security'06)","author":"Kirda E.","year":"2006","unstructured":"}} E. Kirda , C. Kruegel , G. Banks , G. Vigna , and R. Kemmerer . Behavior-based spyware detection . In Proceedings of the 15th USENIX Security Symposium (Security'06) , Vancouver, BC, Canada , August 2006 . }}E.Kirda, C.Kruegel, G.Banks, G.Vigna, and R.Kemmerer. Behavior-based spyware detection. In Proceedings of the 15th USENIX Security Symposium (Security'06), Vancouver, BC, Canada, August 2006."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/1855768.1855790"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 14th USENIX Security Symposium (Security'05)","author":"Kruegel C.","year":"2005","unstructured":"}} C. Kruegel , E. Kirda , D. Mutz , W. Robertson , and G. Vigna . Automating mimicry attacks using static binary analysis . In Proceedings of the 14th USENIX Security Symposium (Security'05) , Baltimore, MD, USA , August 2005 . }}C.Kruegel, E.Kirda, D.Mutz, W.Robertson, and G.Vigna. Automating mimicry attacks using static binary analysis. In Proceedings of the 14th USENIX Security Symposium (Security'05), Baltimore, MD, USA, August 2005."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_11"},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 15th Annual European Institute for Computer Antivirus Research Conference (EICAR'06)","author":"Lee T.","year":"2006","unstructured":"}} T. Lee and J.J. Mody . Behavioral classification . In Proceedings of the 15th Annual European Institute for Computer Antivirus Research Conference (EICAR'06) , May 2006 . }}T.Lee and J.J. Mody. Behavioral classification. In Proceedings of the 15th Annual European Institute for Computer Antivirus Research Conference (EICAR'06), May 2006."},{"key":"e_1_3_2_1_19_1","first-page":"64","volume-title":"Proceedings of the 6th Annual IEEE Systems, Man, and Cybernetics (SMC) Workshop on Information Assurance","author":"Li W.-J.","year":"2005","unstructured":"}} W.-J. Li , K. Wang , S.J. Stolfo , and B. Herzog . Fileprints : Identifying file types by n-gram analysis . In Proceedings of the 6th Annual IEEE Systems, Man, and Cybernetics (SMC) Workshop on Information Assurance , pages 64 -- 71 , West Point, NY , June 2005 . United States Military Academy. }}W.-J. Li, K.Wang, S.J. Stolfo, and B.Herzog. Fileprints: Identifying file types by n-gram analysis. In Proceedings of the 6th Annual IEEE Systems, Man, and Cybernetics (SMC) Workshop on Information Assurance, pages 64--71, West Point, NY, June 2005. United States Military Academy."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.5555\/647054.715771"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/1433006.1433013"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.37"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"e_1_3_2_1_24_1","first-page":"16","volume-title":"Proceedings of the Information Systems Technology Panel (IST) Symposium on Commercial Off-the-Shelf Products in Defence Applications \"The Ruthless Pursuit of COTS\"","author":"Salois M.","year":"2000","unstructured":"}} M. Salois and R. Charpentier . Dynamic detection of malicious code in COTS software . In Proceedings of the Information Systems Technology Panel (IST) Symposium on Commercial Off-the-Shelf Products in Defence Applications \"The Ruthless Pursuit of COTS\" , pages 16 -- 11 --16--13, Brussels, Belgium , Apr. 2000 . NATO Research and Technology Organization. }}M.Salois and R.Charpentier. Dynamic detection of malicious code in COTS software. In Proceedings of the Information Systems Technology Panel (IST) Symposium on Commercial Off-the-Shelf Products in Defence Applications \"The Ruthless Pursuit of COTS\", pages 16--1--16--13, Brussels, Belgium, Apr. 2000. NATO Research and Technology Organization."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884439"},{"key":"e_1_3_2_1_26_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID'07)","author":"Stinson E.","year":"2007","unstructured":"}} E. Stinson and J.C. Mitchell . Characterizing bots' remote control behavior . In C.Kruegel, R.Lippmann, and A.Clark, editors, Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID'07) , volume 4637 of Lecture Notes in Computer Science . Springer-Verlag , 2007 . }}E.Stinson and J.C. Mitchell. Characterizing bots' remote control behavior. In C.Kruegel, R.Lippmann, and A.Clark, editors, Proceedings of the 10th International Symposium on Recent Advances in Intrusion Detection (RAID'07), volume 4637 of Lecture Notes in Computer Science. Springer-Verlag, 2007."},{"key":"e_1_3_2_1_27_1","volume-title":"The Art of Computer Virus Research and Defense","author":"Szor P.","year":"2005","unstructured":"}} P. Szor . The Art of Computer Virus Research and Defense . Addison-Wesley , 2005 . }}P.Szor. The Art of Computer Virus Research and Defense. Addison-Wesley, 2005."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICHIS.2004.75"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315261"}],"event":{"name":"CCS '10: 17th ACM Conference on Computer and Communications Security 2010","location":"Chicago Illinois USA","acronym":"CCS '10","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 17th ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1866307.1866353","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1866307.1866353","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:08:59Z","timestamp":1750248539000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1866307.1866353"}},"subtitle":["using system-centric models for malware protection"],"short-title":[],"issued":{"date-parts":[[2010,10,4]]},"references-count":30,"alternative-id":["10.1145\/1866307.1866353","10.1145\/1866307"],"URL":"https:\/\/doi.org\/10.1145\/1866307.1866353","relation":{},"subject":[],"published":{"date-parts":[[2010,10,4]]},"assertion":[{"value":"2010-10-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}