{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T18:23:05Z","timestamp":1778696585166,"version":"3.51.4"},"reference-count":41,"publisher":"Wiley","license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Journal of Computer Networks and Communications"],"published-print":{"date-parts":[[2016]]},"abstract":"<jats:p>Data mining techniques have numerous applications in malware detection. Classification method is one of the most popular data mining techniques. In this paper we present a data mining classification approach to detect malware behavior. We proposed different classification methods in order to detect malware based on the feature and behavior of each malware. A dynamic analysis method has been presented for identifying the malware features. A suggested program has been presented for converting a malware behavior executive history XML file to a suitable WEKA tool input. To illustrate the performance efficiency as well as training data and test, we apply the proposed approaches to a real case study data set using WEKA tool. The evaluation results demonstrated the availability of the proposed data mining approach. Also our proposed data mining approach is more efficient for detecting malware and behavioral classification of malware can be useful to detect malware in a behavioral antivirus.<\/jats:p>","DOI":"10.1155\/2016\/8069672","type":"journal-article","created":{"date-parts":[[2016,7,26]],"date-time":"2016-07-26T17:01:13Z","timestamp":1469552473000},"page":"1-9","source":"Crossref","is-referenced-by-count":35,"title":["A Data Mining Classification Approach for Behavioral Malware Detection"],"prefix":"10.1155","volume":"2016","author":[{"given":"Monire","family":"Norouzi","sequence":"first","affiliation":[{"name":"Young Researchers and Elite Club, Islamic Azad University, Hadishahr Branch, Hadishahr, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8314-9051","authenticated-orcid":true,"given":"Alireza","family":"Souri","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Islamic Azad University, Hadishahr Branch, Hadishahr, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Majid","family":"Samad Zamini","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Islamic Azad University, Sardroud Branch, Sardroud, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","reference":[{"key":"1","doi-asserted-by":"crossref","first-page":"56","DOI":"10.4236\/jis.2014.52006","volume":"5","year":"2014","journal-title":"Journal of Information Security"},{"key":"2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcss.2014.12.014"},{"key":"3","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(08)70135-0"},{"key":"4","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2015.05.008"},{"key":"5","first-page":"129","volume-title":"Detecting self-mutating malware using control-flow graph matching","volume":"4064","year":"2006"},{"key":"7","first-page":"281","volume-title":"On the concept of software obfuscation in computer security","volume":"4779","year":"2007"},{"key":"8","doi-asserted-by":"publisher","DOI":"10.1145\/1013886.1007518"},{"key":"9","volume":"1","year":"2012"},{"key":"10","first-page":"1","volume":"44","year":"2008","journal-title":"ACM Computing Surveys"},{"key":"11","doi-asserted-by":"crossref","first-page":"57","DOI":"10.5121\/ijfcst.2014.4506","volume":"4","year":"2014","journal-title":"International Journal in Foundations of Computer Science & Technology"},{"key":"12","doi-asserted-by":"crossref","first-page":"1324","DOI":"10.1016\/j.procs.2015.07.443","volume":"57","year":"2015","journal-title":"Procedia Computer Science"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2011.08.020"},{"key":"14","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2014.03.019"},{"key":"15","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-008-0086-0"},{"key":"16","doi-asserted-by":"publisher","DOI":"10.1016\/j.istr.2009.03.003"},{"key":"18","doi-asserted-by":"publisher","DOI":"10.1145\/331499.331504"},{"key":"19","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.256"},{"key":"20","doi-asserted-by":"publisher","DOI":"10.5120\/6194-8715"},{"issue":"2","key":"21","first-page":"69","volume":"29","year":"2011","journal-title":"Journal of Theoretical and Applied Information Technology"},{"issue":"2","key":"22","volume":"44","year":"2012","journal-title":"International Journal of Advanced Research in Computer Science and Software Engineering"},{"key":"23","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2009.05.003"},{"key":"24","first-page":"949","volume":"13","year":"2012","journal-title":"Journal of Machine Learning Research"},{"key":"25","first-page":"178","volume-title":"Automated classification and analysis of internet malware","volume":"4637","year":"2007"},{"key":"26","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0012-2"},{"key":"27","first-page":"2721","volume":"7","year":"2006","journal-title":"Journal of Machine Learning Research"},{"key":"28","year":"2009"},{"key":"29","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-014-0380-z"},{"key":"32","first-page":"48","volume":"6","year":"2008","journal-title":"Journal of Systemics, Cybernetics and Informatics"},{"key":"33","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2015.03.019"},{"key":"34","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2015.02.052"},{"key":"35","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2011.03.015"},{"key":"36","doi-asserted-by":"publisher","DOI":"10.1016\/j.eij.2014.08.001"},{"key":"37","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-013-0707-x"},{"key":"39","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-009-0238-2"},{"key":"41","doi-asserted-by":"publisher","DOI":"10.1007\/s10044-012-0296-4"},{"key":"42","first-page":"1407","volume-title":"Modeling of wind turbine power curves using firefly algorithm","volume":"326","year":"2015"},{"key":"43","year":"1892"},{"key":"44","doi-asserted-by":"publisher","DOI":"10.1162\/089120104773633402"},{"key":"45","doi-asserted-by":"crossref","first-page":"1237","DOI":"10.1016\/j.procs.2010.12.198","volume":"3","year":"2011","journal-title":"Procedia Computer Science"},{"key":"46","year":"2002"},{"key":"47","first-page":"77","volume-title":"Partial segmentation and matching technique for iris recognition","volume":"31","year":"2015"}],"container-title":["Journal of Computer Networks and Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/jcnc\/2016\/8069672.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/jcnc\/2016\/8069672.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/jcnc\/2016\/8069672.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,24]],"date-time":"2017-06-24T15:15:19Z","timestamp":1498317319000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.hindawi.com\/journals\/jcnc\/2016\/8069672\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"references-count":41,"alternative-id":["8069672","8069672"],"URL":"https:\/\/doi.org\/10.1155\/2016\/8069672","relation":{},"ISSN":["2090-7141","2090-715X"],"issn-type":[{"value":"2090-7141","type":"print"},{"value":"2090-715X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}