{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T14:53:50Z","timestamp":1780325630870,"version":"3.54.1"},"reference-count":26,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2020,8,4]],"date-time":"2020-08-04T00:00:00Z","timestamp":1596499200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"La Sapienza University of Rome Bando Ricerca 2017","award":["RM11715C7878B045"],"award-info":[{"award-number":["RM11715C7878B045"]}]},{"name":"Consorzio Interuniversitario Nazionale Informatica (CINI) National Laboratory of Cyber Security"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2020,9,30]]},"abstract":"<jats:p>\n            In the past decade, a new class of cyber-threats, known as \u201cAdvanced Persistent Threat\u201d (APT), has emerged and has been used by different organizations to perform dangerous and effective attacks against financial and politic entities, critical infrastructures, and so on. To identify APT related malware early, a semi-automatic approach for malware samples analysis is needed. Recently, a\n            <jats:italic>malware triage<\/jats:italic>\n            step for a semi-automatic malware analysis architecture has been introduced. This step identifies incoming APT samples early, among all the malware delivered per day in the cyber-space, to immediately dispatch them to deeper analysis. In the article, the authors have built the knowledge base on known APTs obtained from publicly available reports. For efficiency reasons, they rely on static malware features, extracted with negligible delay, and use machine learning techniques for the identification. Unfortunately, the proposed solution has the disadvantage of requiring a long training time and needs to be completely retrained each time new APT samples or even a new APT class are discovered. In this article, we move from multi-class classification to a group of one-class classifiers, which significantly decreases runtime and allows higher modularity, while still guaranteeing precision and accuracy over 90%.\n          <\/jats:p>","DOI":"10.1145\/3386581","type":"journal-article","created":{"date-parts":[[2020,7,7]],"date-time":"2020-07-07T12:32:18Z","timestamp":1594125138000},"page":"1-17","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["Malware Triage for Early Identification of Advanced Persistent Threat Activities"],"prefix":"10.1145","volume":"1","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3763-4598","authenticated-orcid":false,"given":"Giuseppe","family":"Laurenza","sequence":"first","affiliation":[{"name":"Sapienza University of Rome, Via Ariosto, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Lazzeretti","sequence":"additional","affiliation":[{"name":"Sapienza University of Rome, Via Ariosto, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luca","family":"Mazzotti","sequence":"additional","affiliation":[{"name":"Sapienza University of Rome, Via Ariosto, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,8,4]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the Conference on Data and Application Security and Privacy (CODASPY\u201916)","author":"Ahmadi Mansour","year":"2016","unstructured":"Mansour Ahmadi , Dmitry Ulyanov , Stanislav Semenov , Mikhail Trofimov , and Giorgio Giacinto . 2016 . Novel feature extraction, selection and fusion for effective malware family classification . In Proceedings of the Conference on Data and Application Security and Privacy (CODASPY\u201916) . ACM, 183--194. Mansour Ahmadi, Dmitry Ulyanov, Stanislav Semenov, Mikhail Trofimov, and Giorgio Giacinto. 2016. Novel feature extraction, selection and fusion for effective malware family classification. In Proceedings of the Conference on Data and Application Security and Privacy (CODASPY\u201916). ACM, 183--194."},{"key":"e_1_2_1_2_1","volume-title":"McAfee Labs Threats Report","author":"Bassett Alex","year":"2018","unstructured":"Alex Bassett , Christiaan Beek , Niamh Minihane , Eric Peterson , Raj Samani , Craig Schmugar , ReseAnne Sims , Dan Sommer , and Bing Sun . 2018. McAfee Labs Threats Report : December 2018 . Technical Report. McAfee. Retrieved from https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-quarterly-threats-dec-2018.pdf. Alex Bassett, Christiaan Beek, Niamh Minihane, Eric Peterson, Raj Samani, Craig Schmugar, ReseAnne Sims, Dan Sommer, and Bing Sun. 2018. McAfee Labs Threats Report: December 2018. Technical Report. McAfee. Retrieved from https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-quarterly-threats-dec-2018.pdf."},{"key":"e_1_2_1_3_1","volume-title":"Machine Learning","author":"Breiman Leo","unstructured":"Leo Breiman . 2001. Random forests . In Machine Learning . Springer , Berlin , 5--32. Leo Breiman. 2001. Random forests. In Machine Learning. Springer, Berlin, 5--32."},{"key":"e_1_2_1_4_1","volume-title":"Threat Report","year":"2013","unstructured":"FireEyeLabs. 2014. Advanced Threat Report 2013 . Technical Report. FireEyeLabs. Retrieved from https:\/\/www2.fireeye.com\/advanced-threat-report-2013.html. FireEyeLabs. 2014. Advanced Threat Report 2013. Technical Report. FireEyeLabs. Retrieved from https:\/\/www2.fireeye.com\/advanced-threat-report-2013.html."},{"key":"e_1_2_1_5_1","volume-title":"Computers 8 Security","author":"Friedberg Ivo","unstructured":"Ivo Friedberg , Florian Skopik , Giuseppe Settanni , and Roman Fiedler . 2015. Combating advanced persistent threats: From network event correlation to incident detection . In Computers 8 Security . Elsevier , 35--57. Ivo Friedberg, Florian Skopik, Giuseppe Settanni, and Roman Fiedler. 2015. Combating advanced persistent threats: From network event correlation to incident detection. In Computers 8 Security. Elsevier, 35--57."},{"key":"e_1_2_1_6_1","doi-asserted-by":"crossref","first-page":"1076","DOI":"10.1109\/TBME.1986.325684","article-title":"1986. Classification of EEG spatial patterns with a tree-structured methodology","volume":"12","author":"Grajski Kamil A.","year":"1986","unstructured":"Kamil A. Grajski , Leo Breiman , Gonzalo Viana Di Prisco , and Walter J. Freeman . 1986. Classification of EEG spatial patterns with a tree-structured methodology : CART. IEEE Trans. Biomed. Eng. 12 ( 1986 ), 1076 -- 1086 . Kamil A. Grajski, Leo Breiman, Gonzalo Viana Di Prisco, and Walter J. Freeman. 1986. Classification of EEG spatial patterns with a tree-structured methodology: CART. IEEE Trans. Biomed. Eng. 12 (1986), 1076--1086.","journal-title":"CART. IEEE Trans. Biomed. Eng."},{"key":"e_1_2_1_7_1","volume-title":"Amin","author":"Hutchins Eric M.","year":"2011","unstructured":"Eric M. Hutchins , Michael J. Cloppert , and Rohan M . Amin . 2011 . Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. In Leading Issues in Information Warfare 8 Security Research . 80. Eric M. Hutchins, Michael J. Cloppert, and Rohan M. Amin. 2011. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. In Leading Issues in Information Warfare 8 Security Research. 80."},{"key":"e_1_2_1_8_1","volume-title":"Bitshred: Fast, scalable malware triage. Cylab, Technical Report CMU-Cylab-10","author":"Jang Jiyong","year":"2010","unstructured":"Jiyong Jang , David Brumley , and Shobha Venkataraman . 2010 . Bitshred: Fast, scalable malware triage. Cylab, Technical Report CMU-Cylab-10 , Carnegie Mellon University , Pittsburgh, PA . Jiyong Jang, David Brumley, and Shobha Venkataraman. 2010. Bitshred: Fast, scalable malware triage. Cylab, Technical Report CMU-Cylab-10, Carnegie Mellon University, Pittsburgh, PA."},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the Annual Computer Security Applications Conference (ACSAC\u201913)","author":"Kirat Dhilung","unstructured":"Dhilung Kirat , Lakshmanan Nataraj , Giovanni Vigna , and B. S. Manjunath . 2013. Sigmal: A static signal processing based malware triage . In Proceedings of the Annual Computer Security Applications Conference (ACSAC\u201913) . ACM, 89--98. Dhilung Kirat, Lakshmanan Nataraj, Giovanni Vigna, and B. S. Manjunath. 2013. Sigmal: A static signal processing based malware triage. In Proceedings of the Annual Computer Security Applications Conference (ACSAC\u201913). ACM, 89--98."},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the International Conference on Knowledge Discovery and Data Mining, ACM SIGKDD. ACM, 1357--1365","author":"Kong Deguang","year":"2013","unstructured":"Deguang Kong and Guanhua Yan . 2013 . Discriminant malware distance learning on structural information for automated malware classification . In Proceedings of the International Conference on Knowledge Discovery and Data Mining, ACM SIGKDD. ACM, 1357--1365 . Deguang Kong and Guanhua Yan. 2013. Discriminant malware distance learning on structural information for automated malware classification. In Proceedings of the International Conference on Knowledge Discovery and Data Mining, ACM SIGKDD. ACM, 1357--1365."},{"key":"e_1_2_1_11_1","volume-title":"Proceedings of the International Conference on Cyber Security Cryptography and Machine Learning (CSCML\u201917)","author":"Laurenza Giuseppe","year":"2017","unstructured":"Giuseppe Laurenza , Leonardo Aniello , Riccardo Lazzeretti , and Roberto Baldoni . 2017 . Malware triage based on static features and public APT reports . In Proceedings of the International Conference on Cyber Security Cryptography and Machine Learning (CSCML\u201917) . Springer, 288--305. Giuseppe Laurenza, Leonardo Aniello, Riccardo Lazzeretti, and Roberto Baldoni. 2017. Malware triage based on static features and public APT reports. In Proceedings of the International Conference on Cyber Security Cryptography and Machine Learning (CSCML\u201917). Springer, 288--305."},{"key":"e_1_2_1_12_1","volume-title":"Computer Security","author":"Laurenza Giuseppe","unstructured":"Giuseppe Laurenza and Riccardo Lazzeretti . 2019. dAPTaset: A comprehensive mapping of APT-related data . In Computer Security . Springer , 217--225. Giuseppe Laurenza and Riccardo Lazzeretti. 2019. dAPTaset: A comprehensive mapping of APT-related data. In Computer Security. Springer, 217--225."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the International Conference on Dependable Systems and Networks Workshop (DSN\u201916)","author":"Laurenza Giuseppe","year":"2016","unstructured":"Giuseppe Laurenza , Daniele Ucci , Leonardo Aniello , and Roberto Baldoni . 2016 . An architecture for semi-automatic collaborative malware analysis for cis . In Proceedings of the International Conference on Dependable Systems and Networks Workshop (DSN\u201916) . IEEE, 137--142. Giuseppe Laurenza, Daniele Ucci, Leonardo Aniello, and Roberto Baldoni. 2016. An architecture for semi-automatic collaborative malware analysis for cis. In Proceedings of the International Conference on Dependable Systems and Networks Workshop (DSN\u201916). IEEE, 137--142."},{"key":"e_1_2_1_14_1","volume-title":"Intelligent Methods for Cyber Warfare","author":"LeDoux Charles","unstructured":"Charles LeDoux and Arun Lakhotia . 2015. Malware and machine learning . In Intelligent Methods for Cyber Warfare . Springer , 1--42. Charles LeDoux and Arun Lakhotia. 2015. Malware and machine learning. In Intelligent Methods for Cyber Warfare. Springer, 1--42."},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the International Conference on Data Mining (ICDM\u201908)","author":"Liu Fei Tony","year":"2008","unstructured":"Fei Tony Liu , Kai Ming Ting , and Zhi-Hua Zhou . 2008 . Isolation forest . In Proceedings of the International Conference on Data Mining (ICDM\u201908) . IEEE, 413--422. Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou. 2008. Isolation forest. In Proceedings of the International Conference on Data Mining (ICDM\u201908). IEEE, 413--422."},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the International Conference on Trends in Automation, Communications and Computing Technology (I-TACT\u201915)","author":"Makandar Aziz","year":"2015","unstructured":"Aziz Makandar and Anita Patrot . 2015 . Malware analysis and classification using artificial neural network . In Proceedings of the International Conference on Trends in Automation, Communications and Computing Technology (I-TACT\u201915) . IEEE, 1--6. Aziz Makandar and Anita Patrot. 2015. Malware analysis and classification using artificial neural network. In Proceedings of the International Conference on Trends in Automation, Communications and Computing Technology (I-TACT\u201915). IEEE, 1--6."},{"key":"e_1_2_1_17_1","volume-title":"Computer Networks","author":"Marchetti Mirco","unstructured":"Mirco Marchetti , Fabio Pierazzi , Michele Colajanni , and Alessandro Guido . 2016. Analysis of high volumes of network traffic for advanced persistent threat detection . In Computer Networks . Elsevier , 127--141. Mirco Marchetti, Fabio Pierazzi, Michele Colajanni, and Alessandro Guido. 2016. Analysis of high volumes of network traffic for advanced persistent threat detection. In Computer Networks. Elsevier, 127--141."},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the Neural Networks for Signal Processing, Signal Processing Society Workshop. IEEE, 41--48","author":"Mika Sebastian","year":"1999","unstructured":"Sebastian Mika , Gunnar Ratsch , Jason Weston , Bernhard Scholkopf , and Klaus-Robert Mullers . 1999 . Fisher discriminant analysis with kernels . In Proceedings of the Neural Networks for Signal Processing, Signal Processing Society Workshop. IEEE, 41--48 . Sebastian Mika, Gunnar Ratsch, Jason Weston, Bernhard Scholkopf, and Klaus-Robert Mullers. 1999. Fisher discriminant analysis with kernels. In Proceedings of the Neural Networks for Signal Processing, Signal Processing Society Workshop. IEEE, 41--48."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the International Conference on Computing, Networking and Communications (ICNC\u201913)","author":"Nari Saeed","year":"2013","unstructured":"Saeed Nari and Ali A Ghorbani . 2013 . Automated malware classification based on network behavior . In Proceedings of the International Conference on Computing, Networking and Communications (ICNC\u201913) . IEEE, 642--647. Saeed Nari and Ali A Ghorbani. 2013. Automated malware classification based on network behavior. In Proceedings of the International Conference on Computing, Networking and Communications (ICNC\u201913). IEEE, 642--647."},{"key":"e_1_2_1_20_1","volume-title":"Neurobiology of Attention","author":"Oliva Aude","unstructured":"Aude Oliva . 2005. Gist of the scene . In Neurobiology of Attention . Elsevier , 251--256. Aude Oliva. 2005. Gist of the scene. In Neurobiology of Attention. Elsevier, 251--256."},{"key":"e_1_2_1_21_1","volume-title":"Annual Report","year":"2015","unstructured":"PandaLabs. 2015. Annual Report 2015 . Technical Report. PandaLabs. Retrieved from https:\/\/www.pandasecurity.com\/mediacenter\/src\/uploads\/2014\/07\/Pandalabs-2015-anual-EN.pdf. PandaLabs. 2015. Annual Report 2015. Technical Report. PandaLabs. Retrieved from https:\/\/www.pandasecurity.com\/mediacenter\/src\/uploads\/2014\/07\/Pandalabs-2015-anual-EN.pdf."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2012.6461006"},{"key":"e_1_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Robert Serfling and Shanshan Wang. 2014. General foundations for studying masking and swamping robustness of outlier identifiers. In Statistical Methodology. 79--90.  Robert Serfling and Shanshan Wang. 2014. General foundations for studying masking and swamping robustness of outlier identifiers. In Statistical Methodology. 79--90.","DOI":"10.1016\/j.stamet.2013.08.004"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2381896.2381910"},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the International Conference on New Technologies, Mobility and Security (NTMS\u201915)","author":"Ussath Martin","year":"2015","unstructured":"Martin Ussath , Feng Cheng , and Christoph Meinel . 2015 . Concept for a security investigation framework . In Proceedings of the International Conference on New Technologies, Mobility and Security (NTMS\u201915) . IEEE, 1--5. Martin Ussath, Feng Cheng, and Christoph Meinel. 2015. Concept for a security investigation framework. In Proceedings of the International Conference on New Technologies, Mobility and Security (NTMS\u201915). IEEE, 1--5."},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of the International Conference on Trust, Security and Privacy in Computing and Communications. IEEE, 254--263","author":"Welch Ian","year":"2012","unstructured":"Ian Welch , Xiaoying Gao , Peter Komisarczuk , 2012 . A novel scoring model to detect potential malicious web pages . In Proceedings of the International Conference on Trust, Security and Privacy in Computing and Communications. IEEE, 254--263 . Ian Welch, Xiaoying Gao, Peter Komisarczuk, et al. 2012. A novel scoring model to detect potential malicious web pages. In Proceedings of the International Conference on Trust, Security and Privacy in Computing and Communications. IEEE, 254--263."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3386581","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3386581","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:04Z","timestamp":1750200064000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3386581"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,4]]},"references-count":26,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,9,30]]}},"alternative-id":["10.1145\/3386581"],"URL":"https:\/\/doi.org\/10.1145\/3386581","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,4]]},"assertion":[{"value":"2019-05-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-03-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-08-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}