{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,23]],"date-time":"2026-03-23T11:57:07Z","timestamp":1774267027949,"version":"3.50.1"},"reference-count":88,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2018,1,31]],"date-time":"2018-01-31T00:00:00Z","timestamp":1517356800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2018,5,31]]},"abstract":"<jats:p>Identifying free open-source software (FOSS) packages on binaries when the source code is unavailable is important for many security applications, such as malware detection, software infringement, and digital forensics. This capability enhances both the accuracy and the efficiency of reverse engineering tasks by avoiding false correlations between irrelevant code bases. Although the FOSS package identification problem belongs to the field of software engineering, conventional approaches rely strongly on practical methods in data mining and database searching. However, various challenges in the use of these methods prevent existing function identification approaches from being effective in the absence of source code. To make matters worse, the introduction of obfuscation techniques, the use of different compilers and compilation settings, and software refactoring techniques has made the automated detection of FOSS packages increasingly difficult. With very few exceptions, the existing systems are not resilient to such techniques, and the exceptions are not sufficiently efficient.<\/jats:p>\n          <jats:p>\n            To address this issue, we propose\n            <jats:italic>FOSSIL<\/jats:italic>\n            , a novel resilient and efficient system that incorporates three components. The first component extracts the syntactical features of functions by considering opcode frequencies and applying a hidden Markov model statistical test. The second component applies a neighborhood hash graph kernel to random walks derived from control-flow graphs, with the goal of extracting the semantics of the functions. The third component applies z-score to the normalized instructions to extract the behavior of instructions in a function. The components are integrated using a Bayesian network model, which synthesizes the results to determine the FOSS function. The novel approach of combining these components using the Bayesian network has produced stronger resilience to code obfuscation.\n          <\/jats:p>\n          <jats:p>\n            We evaluate our system on three datasets, including real-world projects whose use of FOSS packages is known, malware binaries for which there are security and reverse engineering reports purporting to describe their use of FOSS, and a large repository of malware binaries. We demonstrate that our system is able to identify FOSS packages in real-world projects with a mean precision of 0.95 and with a mean recall of 0.85. Furthermore,\n            <jats:italic>FOSSIL<\/jats:italic>\n            is able to discover FOSS packages in malware binaries that match those listed in security and reverse engineering reports. Our results show that modern malware binaries contain 0.10--0.45 of FOSS packages.\n          <\/jats:p>","DOI":"10.1145\/3175492","type":"journal-article","created":{"date-parts":[[2018,2,1]],"date-time":"2018-02-01T13:10:52Z","timestamp":1517490652000},"page":"1-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":45,"title":["<i>FOSSIL<\/i>"],"prefix":"10.1145","volume":"21","author":[{"given":"Saed","family":"Alrabaee","sequence":"first","affiliation":[{"name":"Security Research Centre, Concordia University Montreal, Quebec, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paria","family":"Shirani","sequence":"additional","affiliation":[{"name":"Security Research Centre, Concordia University Montreal, Quebec, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[{"name":"Security Research Centre, Concordia University Montreal, Quebec, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[{"name":"Security Research Centre, Concordia University Montreal, Quebec, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,1,31]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2012. Full Analysis of Flame\u2019s Command 8 Control servers. Retrieved from https:\/\/securelist.com\/blog\/incidents\/34216\/full-analysis-of-flames-command-control-servers-27\/.  2012. Full Analysis of Flame\u2019s Command 8 Control servers. Retrieved from https:\/\/securelist.com\/blog\/incidents\/34216\/full-analysis-of-flames-command-control-servers-27\/."},{"key":"e_1_2_1_2_1","unstructured":"2016. Script modifies GNU assembly files (.s) to confuse linear sweep disassemblers like objdump. It does not confuse recursive traversal disassemblers like IDA Pro. It is very inefficient making simple code about 2x slower. Retrieved from https:\/\/github.com\/defuse\/gas-obfuscation.  2016. Script modifies GNU assembly files (.s) to confuse linear sweep disassemblers like objdump. It does not confuse recursive traversal disassemblers like IDA Pro. It is very inefficient making simple code about 2x slower. Retrieved from https:\/\/github.com\/defuse\/gas-obfuscation."},{"key":"e_1_2_1_3_1","unstructured":"2016. The Lintian Reports. Retrieved from https:\/\/lintian.debian.org.  2016. The Lintian Reports. Retrieved from https:\/\/lintian.debian.org."},{"key":"e_1_2_1_4_1","unstructured":"2016. The Paradyn project. Retrieved from http:\/\/www.paradyn.org\/html\/dyninst9.0.0-features.html.  2016. The Paradyn project. Retrieved from http:\/\/www.paradyn.org\/html\/dyninst9.0.0-features.html."},{"key":"e_1_2_1_5_1","unstructured":"2016. The tracelet system. Retrieved from https:\/\/github.com\/Yanivmd\/TRACY.  2016. The tracelet system. Retrieved from https:\/\/github.com\/Yanivmd\/TRACY."},{"key":"e_1_2_1_6_1","unstructured":"2016. The Z table. Retrieved from http:\/\/www.stat.ufl.edu\/athienit\/Tables\/Ztable.pdf.  2016. The Z table. Retrieved from http:\/\/www.stat.ufl.edu\/athienit\/Tables\/Ztable.pdf."},{"key":"e_1_2_1_7_1","unstructured":"2016. Tigress is a diversifying virtualizer\/obfuscator for the C language. Retrieved from http:\/\/tigress.cs.arizona.edu\/.  2016. Tigress is a diversifying virtualizer\/obfuscator for the C language. Retrieved from http:\/\/tigress.cs.arizona.edu\/."},{"key":"e_1_2_1_8_1","unstructured":"A.S.L. 2016. EXEINFO PE. Retrieved from http:\/\/exeinfo.atwebpages.com\/. Accessed on March 2017.  A.S.L. 2016. EXEINFO PE. Retrieved from http:\/\/exeinfo.atwebpages.com\/. Accessed on March 2017."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.01.011"},{"key":"e_1_2_1_10_1","unstructured":"B. Bencs\u00e1th L. Butty\u00e1n and M. F\u00e9legyh\u00e1zi. 2012a. P\u00e9k G. sKyWIper (aka flame aka flamer): A complex malware for targeted attacks. CrySyS Lab: Budapest Hungary (2012).  B. Bencs\u00e1th L. Butty\u00e1n and M. F\u00e9legyh\u00e1zi. 2012a. P\u00e9k G. sKyWIper (aka flame aka flamer): A complex malware for targeted attacks. CrySyS Lab: Budapest Hungary (2012)."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi4040971"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJESDF.2007.016865"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi4040971"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2430553.2430557"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382217"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-004-0400-9"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.40"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950350"},{"key":"e_1_2_1_19_1","volume-title":"Havrilla","author":"Cohen Cory","year":"2009","unstructured":"Cory Cohen and Jeffrey S . Havrilla . 2009 . Function hashing for malicious code analysis. CERT Research Annual Report ( 2009), 26--29. Cory Cohen and Jeffrey S. Havrilla. 2009. Function hashing for malicious code analysis. CERT Research Annual Report (2009), 26--29."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.12"},{"key":"e_1_2_1_21_1","unstructured":"Scott A. Czepiel. 2002. Maximum likelihood estimation of logistic regression models: Theory and implementation. 1--23. https:\/\/czep.net\/stat\/mlelr.pdf.  Scott A. Czepiel. 2002. Maximum likelihood estimation of logistic regression models: Theory and implementation. 1--23. https:\/\/czep.net\/stat\/mlelr.pdf."},{"key":"e_1_2_1_22_1","unstructured":"DARPA. 2016. DARPA-BAA-10-36 Cyber Genome Program. Retrieved from https:\/\/www.fbo.gov\/index?s&equals;opportunity.  DARPA. 2016. DARPA-BAA-10-36 Cyber Genome Program. Retrieved from https:\/\/www.fbo.gov\/index?s&equals;opportunity."},{"key":"e_1_2_1_23_1","unstructured":"DevExpress. 2016b. Refactoring tool. Retrieved from https:\/\/www.devexpress.com\/Products\/CodeRush\/.  DevExpress. 2016b. Refactoring tool. Retrieved from https:\/\/www.devexpress.com\/Products\/CodeRush\/."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2015.2491300"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594343"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143844.1143874"},{"key":"e_1_2_1_27_1","volume-title":"Hybrid Artificial Intelligent Systems","author":"de la Puerta Jos\u00e9 Gaviria","unstructured":"Jos\u00e9 Gaviria de la Puerta , Borja Sanz , Igor Santos , and Pablo Garc\u00eda Bringas . 2015. Using dalvik opcodes for malware detection on android . In Hybrid Artificial Intelligent Systems . Springer , 416--426. Jos\u00e9 Gaviria de la Puerta, Borja Sanz, Igor Santos, and Pablo Garc\u00eda Bringas. 2015. Using dalvik opcodes for malware detection on android. In Hybrid Artificial Intelligent Systems. Springer, 416--426."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939719"},{"key":"e_1_2_1_29_1","unstructured":"Chris Eagle. 2011. HexRays: IDA Pro. Retrieved from https:\/\/www.hex-rays.com\/products\/ida\/index.shtml.  Chris Eagle. 2011. HexRays: IDA Pro. Retrieved from https:\/\/www.hex-rays.com\/products\/ida\/index.shtml."},{"key":"e_1_2_1_30_1","volume-title":"23rd USENIX Security Symposium. 303--317","author":"Egele Manuel","year":"2014","unstructured":"Manuel Egele , Maverick Woo , Peter Chapman , and David Brumley . 2014 . Blanket execution: Dynamic similarity testing for program binaries and components . 23rd USENIX Security Symposium. 303--317 . Manuel Egele, Maverick Woo, Peter Chapman, and David Brumley. 2014. Blanket execution: Dynamic similarity testing for program binaries and components. 23rd USENIX Security Symposium. 303--317."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23185"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SERE.2014.21"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.06.001"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978370"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-007-0041-5"},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201904)","author":"Flake Halvar","year":"2004","unstructured":"Halvar Flake . 2004 . Structural comparison of executable objects . In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201904) . Halvar Flake. 2004. Structural comparison of executable objects. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201904)."},{"key":"e_1_2_1_37_1","volume-title":"Refactoring: Improving the Design of Existing Code. Pearson Education India.","author":"Fowler Martin","year":"1999","unstructured":"Martin Fowler . 1999 . Refactoring: Improving the Design of Existing Code. Pearson Education India. Martin Fowler. 1999. Refactoring: Improving the Design of Existing Code. Pearson Education India."},{"key":"e_1_2_1_38_1","unstructured":"GReAT. 2016. Resource 207: Kaspersky Lab Research proves that Stuxnet and Flame developers are connected. Retrieved from http:\/\/newsroom.kaspersky.eu\/fileadmin\/user_upload\/en\/Images\/Lifestyle\/20120611_Kaspersky_Lab_Press_Release_Flame_Stuxnet_cooperation_final_-_UK.pdf. Accessed on Feb 2016.  GReAT. 2016. Resource 207: Kaspersky Lab Research proves that Stuxnet and Flame developers are connected. Retrieved from http:\/\/newsroom.kaspersky.eu\/fileadmin\/user_upload\/en\/Images\/Lifestyle\/20120611_Kaspersky_Lab_Press_Release_Flame_Stuxnet_cooperation_final_-_UK.pdf. Accessed on Feb 2016."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714579"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88625-9_16"},{"key":"e_1_2_1_41_1","volume-title":"Learning Theory and Kernel Machines","author":"G\u00e4rtner Thomas","unstructured":"Thomas G\u00e4rtner , Peter Flach , and Stefan Wrobel . 2003. On graph kernels: Hardness results and efficient alternatives . In Learning Theory and Kernel Machines . Springer , 129--143. Thomas G\u00e4rtner, Peter Flach, and Stefan Wrobel. 2003. On graph kernels: Hardness results and efficient alternatives. In Learning Theory and Kernel Machines. Springer, 129--143."},{"key":"e_1_2_1_42_1","volume-title":"Fast library identification and recognition technology. DataRescue","author":"Guilfanov Ilfak","year":"1997","unstructured":"Ilfak Guilfanov . 1997. Fast library identification and recognition technology. DataRescue ( 1997 ). Ilfak Guilfanov. 1997. Fast library identification and recognition technology. DataRescue (1997)."},{"key":"e_1_2_1_43_1","unstructured":"IDA Pro. 2016. HexRays: FLAIR. Retrieved from https:\/\/www.hex-rays.com\/products\/ida\/support\/download.shtml.  IDA Pro. 2016. HexRays: FLAIR. Retrieved from https:\/\/www.hex-rays.com\/products\/ida\/support\/download.shtml."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2024569.2024571"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046742"},{"key":"e_1_2_1_46_1","volume-title":"Proceedings of the USENIX Security Symposium. 81--96","author":"Jang Jiyong","year":"2013","unstructured":"Jiyong Jang , Maverick Woo , and David Brumley . 2013 . Towards automatic software lineage inference . In Proceedings of the USENIX Security Symposium. 81--96 . Jiyong Jang, Maverick Woo, and David Brumley. 2013. Towards automatic software lineage inference. In Proceedings of the USENIX Security Symposium. 81--96."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2012.70"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.5555\/2821429.2821434"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.5555\/2821429.2821434"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314389.1314399"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.5555\/2487085.2487147"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1810295.1810324"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_11"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2430553.2430558"},{"key":"e_1_2_1_56_1","volume-title":"Proceedings of the 6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET\u201913)","author":"LeDoux Charles","year":"2013","unstructured":"Charles LeDoux , Arun Lakhotia , Craig Miles , Vivek Notani , Avi Pfeffer , and Charles River Analytics . 2013 . FuncTracker: Discovering shared code to aid malware forensics extended abstract . In Proceedings of the 6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET\u201913) . Charles LeDoux, Arun Lakhotia, Craig Miles, Vivek Notani, Avi Pfeffer, and Charles River Analytics. 2013. FuncTracker: Discovering shared code to aid malware forensics extended abstract. In Proceedings of the 6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET\u201913)."},{"key":"e_1_2_1_57_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911)","author":"Lee JongHyup","year":"2011","unstructured":"JongHyup Lee , Thanassis Avgerinos , and David Brumley . 2011 . TIE: Principled reverse engineering of types in binary programs . In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911) . Citeseer. JongHyup Lee, Thanassis Avgerinos, and David Brumley. 2011. TIE: Principled reverse engineering of types in binary programs. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201911). Citeseer."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-010-0148-y"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.5555\/2788959.2788964"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2421001"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.15"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1186\/1471-2105-6-S1-S6"},{"key":"e_1_2_1_63_1","volume-title":"Citadel trojan malware analysis. DELL SecureWorks","author":"Milletary Jason","year":"2014","unstructured":"Jason Milletary . 2012. Citadel trojan malware analysis. DELL SecureWorks . Vol. 13 . 2014 . Jason Milletary. 2012. Citadel trojan malware analysis. DELL SecureWorks. Vol. 13. 2014."},{"key":"e_1_2_1_64_1","volume-title":"Supply Chain Analysis: From Quartermaster to Sun-shop","author":"Moran Ned","unstructured":"Ned Moran and James Bennett . 2013. Supply Chain Analysis: From Quartermaster to Sun-shop . Vol. 11 . FireEye Labs . Ned Moran and James Bennett. 2013. Supply Chain Analysis: From Quartermaster to Sun-shop. Vol. 11. FireEye Labs."},{"key":"e_1_2_1_65_1","unstructured":"Naynaeve. 2016. Adventure in Windows debugging and reverse engineering. Retrieved from http:\/\/www.nynaeve.net\/.  Naynaeve. 2016. Adventure in Windows debugging and reverse engineering. Retrieved from http:\/\/www.nynaeve.net\/."},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the Annual Computer Security Conference (ACSAC) Worshop on Next Generation Malware Attacks and Defense (NGMAD\u201913)","author":"Nataraj Lakshmanan","year":"2013","unstructured":"Lakshmanan Nataraj , Dhilung Kirat , B. S. Manjunath , and Giovanni Vigna . 2013 . Sarvam: Search and retrieval of malware . In Proceedings of the Annual Computer Security Conference (ACSAC) Worshop on Next Generation Malware Attacks and Defense (NGMAD\u201913) . Lakshmanan Nataraj, Dhilung Kirat, B. S. Manjunath, and Giovanni Vigna. 2013. Sarvam: Search and retrieval of malware. In Proceedings of the Annual Computer Security Conference (ACSAC) Worshop on Next Generation Malware Attacks and Defense (NGMAD\u201913)."},{"key":"e_1_2_1_67_1","unstructured":"Oreans Technologies. 2016. Advanced Windows software protection system developed for software developers who wish to protect their applications against advanced reverse engineering and software cracking. Retrieved from http:\/\/www.oreans.com\/themida.php.  Oreans Technologies. 2016. Advanced Windows software protection system developed for software developers who wish to protect their applications against advanced reverse engineering and software cracking. Retrieved from http:\/\/www.oreans.com\/themida.php."},{"key":"e_1_2_1_68_1","unstructured":"PELock. 2016. PELock is a software security solution designed for protection of any 32 bit Windows applications. Retrieved from https:\/\/www.pelock.com\/.  PELock. 2016. PELock is a software security solution designed for protection of any 32 bit Windows applications. Retrieved from https:\/\/www.pelock.com\/."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2005.159"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.49"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2015.2470241"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-37119-6_14"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.05.015"},{"key":"e_1_2_1_74_1","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Ruttenberg Brian","unstructured":"Brian Ruttenberg , Craig Miles , Lee Kellogg , Vivek Notani , Michael Howard , Charles LeDoux , Arun Lakhotia , and Avi Pfeffer . 2014. Identifying shared software components to support malware forensics . In Detection of Intrusions and Malware, and Vulnerability Assessment . Springer , 21--40. Brian Ruttenberg, Craig Miles, Lee Kellogg, Vivek Notani, Michael Howard, Charles LeDoux, Arun Lakhotia, and Avi Pfeffer. 2014. Identifying shared software components to support malware forensics. In Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 21--40."},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/1572272.1572287"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2014.6999417"},{"key":"e_1_2_1_77_1","volume-title":"Static Analysis","author":"Shapiro Marc","unstructured":"Marc Shapiro and Susan Horwitz . 1997. The effects of the precision of pointer analysis . In Static Analysis . Springer , 16--34. Marc Shapiro and Susan Horwitz. 1997. The effects of the precision of pointer analysis. In Static Analysis. Springer, 16--34."},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_14"},{"key":"e_1_2_1_79_1","volume-title":"A revealing introduction to hidden Markov models. Department of Computer Science","author":"Stamp Mark","unstructured":"Mark Stamp . 2004. A revealing introduction to hidden Markov models. Department of Computer Science , San Jose State University . Mark Stamp. 2004. A revealing introduction to hidden Markov models. Department of Computer Science, San Jose State University."},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2014.06.012"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950321"},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-012-0171-2"},{"key":"e_1_2_1_83_1","first-page":"1201","article-title":"Graph kernels","volume":"11","author":"Vichy S.","year":"2010","unstructured":"S. Vichy , N. Vishwanathan , Nicol N. Schraudolph , Risi Kondor , and Karsten M. Borgwardt . 2010 . Graph kernels . J. Mach. Learn. Res. 11 (2010), 1201 -- 1242 . S. Vichy, N. Vishwanathan, Nicol N. Schraudolph, Risi Kondor, and Karsten M. Borgwardt. 2010. Graph kernels. J. Mach. Learn. Res. 11 (2010), 1201--1242.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_2_1_84_1","unstructured":"Whole Tomato Software. 2016a. C++ refactoring tools for visual studio. Retrieved from http:\/\/www.wholetomato.com\/.  Whole Tomato Software. 2016a. C++ refactoring tools for visual studio. Retrieved from http:\/\/www.wholetomato.com\/."},{"key":"e_1_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2012.6461003"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33704-8_20"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835820"},{"key":"e_1_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jbi.2011.08.011"},{"key":"e_1_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCBB.2012.50"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3175492","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3175492","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T21:37:00Z","timestamp":1750282620000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3175492"}},"subtitle":["A Resilient and Efficient System for Identifying FOSS Functions in Malware Binaries"],"short-title":[],"issued":{"date-parts":[[2018,1,31]]},"references-count":88,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,5,31]]}},"alternative-id":["10.1145\/3175492"],"URL":"https:\/\/doi.org\/10.1145\/3175492","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,1,31]]},"assertion":[{"value":"2017-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2017-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-01-31","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}