{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T13:52:45Z","timestamp":1762005165228,"version":"3.41.0"},"reference-count":37,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2020,3,12]],"date-time":"2020-03-12T00:00:00Z","timestamp":1583971200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2020,7,31]]},"abstract":"<jats:p>The rapid increase in the number of malicious programs has made malware forensics a daunting task and caused users\u2019 systems to become in danger. Timely identification of malware characteristics including its origin and the malware sample family would significantly limit the potential damage of malware. This is a more profound risk in Cyber-Physical Systems (CPSs), where a malware attack may cause significant physical damage to the infrastructure. Due to limited on-device available memory and processing power in CPS devices, most of the efforts for protecting CPS networks are focused on the edge layer, where the majority of security mechanisms are deployed.<\/jats:p>\n          <jats:p>Since the majority of advanced and sophisticated malware programs are combining features from different families, these malicious programs are not similar enough to any existing malware family and easily evade binary classifier detection. Therefore, in this article, we propose a novel multilabel fuzzy clustering system for malware attack attribution. Our system is deployed on the edge layer to provide insight into applicable malware threats to the CPS network. We leverage static analysis by utilizing Opcode frequencies as the feature space to classify malware families.<\/jats:p>\n          <jats:p>We observed that a multilabel classifier does not classify a part of samples. We named this problem the instance coverage problem. To overcome this problem, we developed an ensemble-based multilabel fuzzy classification method to suggest the relevance of a malware instance to the stricken families. This classifier identified samples of VirusShare, RansomwareTracker, and BIG2015 with an accuracy of 94.66%, 94.26%, and 97.56%, respectively.<\/jats:p>","DOI":"10.1145\/3351881","type":"journal-article","created":{"date-parts":[[2020,3,12]],"date-time":"2020-03-12T07:49:20Z","timestamp":1583999360000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["A Multilabel Fuzzy Relevance Clustering System for Malware Attack Attribution in the Edge Layer of Cyber-Physical Networks"],"prefix":"10.1145","volume":"4","author":[{"given":"Mohammadhadi","family":"Alaeiyan","sequence":"first","affiliation":[{"name":"School of Computer Engineering, Iran University of Science and Technology, Narmak, Tehran, Tehran, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[{"name":"University of Guelph, Guelph, Ontario,Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tooska","family":"Dargahi","sequence":"additional","affiliation":[{"name":"University of Salford, The Crescent, Salford, Greater Manchester, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Padua, Padua, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saeed","family":"Parsa","sequence":"additional","affiliation":[{"name":"School of Computer Engineering, Iran University of Science and Technology, Narmak, Tehran, Tehran, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,3,12]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Abuse.ch. [n.d.]. Ransomware Tracker. Retrieved from https:\/\/ransomwaretracker.abuse.ch\/.  Abuse.ch. [n.d.]. Ransomware Tracker. Retrieved from https:\/\/ransomwaretracker.abuse.ch\/."},{"key":"e_1_2_1_2_1","unstructured":"A.S.L. [n.d.]. Exeinfo PE. Retrieved from http:\/\/exeinfo.atwebpages.com.  A.S.L. [n.d.]. Exeinfo PE. Retrieved from http:\/\/exeinfo.atwebpages.com."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2018.2809665"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-017-0558-5"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.07.060"},{"volume-title":"Control flow-based opcode behavior analysis for malware detection. Computers 8 Security 44","year":"2014","author":"Ding Yuxin","key":"e_1_2_1_6_1"},{"key":"e_1_2_1_7_1","unstructured":"Chris Eagle. 2011. The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler. No Starch Press.  Chris Eagle. 2011. The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler. No Starch Press."},{"key":"e_1_2_1_8_1","unstructured":"GDATA. [n.d.]. G-DATA. Retrieved from https:\/\/www.gdatasoftware.com\/blog\/2018\/03\/30610-malware-number-2017.  GDATA. [n.d.]. G-DATA. Retrieved from https:\/\/www.gdatasoftware.com\/blog\/2018\/03\/30610-malware-number-2017."},{"volume-title":"2015 2nd International Conference on Computing for Sustainable Global Development (INDIACom\u201915)","author":"George N.","key":"e_1_2_1_9_1"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.03.007"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-018-0314-1"},{"volume-title":"Know abnormal, find evil: Frequent pattern mining for ransomware threat hunting and intelligence","year":"2017","author":"Homayoun Sajad","key":"e_1_2_1_12_1"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.07.045"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.12.037"},{"volume-title":"Kaspersky Lab Number of the Year: 360,000 Malicious Files Detected Daily","year":"2017","key":"e_1_2_1_15_1"},{"volume-title":"Combining Pattern Classifiers: Methods and Algorithms","author":"Kuncheva Ludmila I.","key":"e_1_2_1_16_1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.2013.2294355"},{"key":"e_1_2_1_18_1","volume-title":"8th Workshop on Cyber Security Experimentation and Test (cset\u201915)","volume":"5","author":"Li Yuping","year":"2015"},{"volume-title":"version 9.1.0.441655 (R2016a)","author":"MATLAB.","key":"e_1_2_1_19_1"},{"volume-title":"Microsoft Malware Classification Challenge (BIG","year":"2015","key":"e_1_2_1_20_1"},{"volume-title":"Machine learning aided Android malware classification. Computers 8 Electrical Engineering 61","year":"2017","author":"Milosevic Nikola","key":"e_1_2_1_21_1"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-017-0307-5"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2016.11.009"},{"volume-title":"Bringas","year":"2010","author":"Santos Igor","key":"e_1_2_1_24_1"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1007649029923"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/505282.505283"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI.2017.8280788"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2016.7727266"},{"volume-title":"Data Mining and Knowledge Discovery Handbook","author":"Tsoumakas Grigorios","key":"e_1_2_1_29_1"},{"volume-title":"Alp Erkan Savli, Guner Ogunc, and Murat Canpolat.","year":"2019","author":"Ulusar Umit Deniz","key":"e_1_2_1_30_1"},{"key":"e_1_2_1_31_1","first-page":"333","article-title":"A machine learning based approach to detect malicious android apps using discriminant system calls","volume":"94","author":"Vinod P.","year":"2018","journal-title":"Future Generation Computer Systems"},{"key":"e_1_2_1_32_1","unstructured":"virusshare. [n.d.]. virusshare. Retrieved from http:\/\/www.virusshare.com.  virusshare. [n.d.]. virusshare. Retrieved from http:\/\/www.virusshare.com."},{"key":"e_1_2_1_33_1","unstructured":"virustotal. [n.d.]. virustotal. Retrieved from http:\/\/www.virustotal.com.  virustotal. [n.d.]. virustotal. Retrieved from http:\/\/www.virustotal.com."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2771228"},{"volume-title":"Pal","year":"2016","author":"Witten Ian H.","key":"e_1_2_1_35_1"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0028-7"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-017-3077-6"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3351881","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3351881","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:13:03Z","timestamp":1750201983000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3351881"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,12]]},"references-count":37,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,7,31]]}},"alternative-id":["10.1145\/3351881"],"URL":"https:\/\/doi.org\/10.1145\/3351881","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"type":"print","value":"2378-962X"},{"type":"electronic","value":"2378-9638"}],"subject":[],"published":{"date-parts":[[2020,3,12]]},"assertion":[{"value":"2018-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-03-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}