{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T15:52:09Z","timestamp":1781193129086,"version":"3.54.1"},"reference-count":41,"publisher":"Wiley","license":[{"start":{"date-parts":[[2018,12,2]],"date-time":"2018-12-02T00:00:00Z","timestamp":1543708800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2018,12,2]]},"abstract":"<jats:p>With the explosion of Internet of Things (IoT) worldwide, there is an increasing threat from malicious software (malware) attackers that calls for efficient monitoring of vulnerable systems. Large amounts of data collected from computer networks, servers, and mobile devices need to be analysed for malware proliferation. Effective analysis methods are needed to match with the scale and complexity of such a data-intensive environment. In today\u2019s Big Data contexts, visualisation techniques can support malware analysts going through the time-consuming process of analysing suspicious activities thoroughly. This paper takes a step further in contributing to the evolving realm of visualisation techniques used in the information security field. The aim of the paper is twofold: <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" id=\"M1\"><mml:mo stretchy=\"false\">(<\/mml:mo><mml:mn fontstyle=\"italic\">1<\/mml:mn><mml:mo stretchy=\"false\">)<\/mml:mo><\/mml:math> to provide a comprehensive overview of the existing visualisation techniques for detecting suspicious behaviour of systems and <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\" id=\"M2\"><mml:mo stretchy=\"false\">(<\/mml:mo><mml:mn fontstyle=\"italic\">2<\/mml:mn><mml:mo stretchy=\"false\">)<\/mml:mo><\/mml:math> to design a novel visualisation using similarity matrix method for establishing malware classification accurately. The prime motivation of our proposal is to identify obfuscated malware using visualisation of the extended x86 IA-32 (opcode) similarity patterns, which are hard to detect with the existing approaches. Our approach uses hybrid models wherein static and dynamic malware analysis techniques are combined effectively along with visualisation of similarity matrices in order to detect and classify zero-day malware efficiently. Overall, the high accuracy of classification achieved with our proposed method can be visually observed since different malware families exhibit significantly dissimilar behaviour patterns.<\/jats:p>","DOI":"10.1155\/2018\/1728303","type":"journal-article","created":{"date-parts":[[2018,12,2]],"date-time":"2018-12-02T18:31:41Z","timestamp":1543775501000},"page":"1-13","source":"Crossref","is-referenced-by-count":119,"title":["Use of Data Visualisation for Zero-Day Malware Detection"],"prefix":"10.1155","volume":"2018","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2772-133X","authenticated-orcid":true,"given":"Sitalakshmi","family":"Venkatraman","sequence":"first","affiliation":[{"name":"Department of IT, Melbourne Polytechnic, Prahran Campus, Melbourne, VIC 3181, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1928-3704","authenticated-orcid":true,"given":"Mamoun","family":"Alazab","sequence":"additional","affiliation":[{"name":"Charles Darwin University, Darwin, NT 0810, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","reference":[{"key":"1","volume-title":"Computer Viruses and Malware","year":"2006"},{"key":"2","year":"2017","journal-title":"System American Journal of Applied Sciences"},{"key":"5","doi-asserted-by":"publisher","DOI":"10.1145\/2089125.2089126"},{"key":"7","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-016-0267-1"},{"key":"8","doi-asserted-by":"publisher","DOI":"10.4304\/jnw.9.11.2878-2891"},{"key":"9","doi-asserted-by":"publisher","DOI":"10.1504\/IJESDF.2013.055047"},{"key":"10","doi-asserted-by":"publisher","DOI":"10.1007\/s40012-016-0095-y"},{"key":"11","year":"2006"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-47217-1_8"},{"key":"14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67071-3_33"},{"key":"16","doi-asserted-by":"publisher","DOI":"10.1186\/s13673-018-0125-x"},{"key":"20","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2014.10.031"},{"key":"21","doi-asserted-by":"publisher","DOI":"10.5121\/ijmit.2017.9301"},{"key":"23","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.102913.00020"},{"key":"24","doi-asserted-by":"publisher","DOI":"10.1007\/s12650-014-0246-x"},{"key":"25","doi-asserted-by":"publisher","DOI":"10.2991\/978-94-6239-186-4"},{"key":"26","doi-asserted-by":"publisher","DOI":"10.1109\/2945.981847"},{"key":"27","year":"2006"},{"key":"30","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2011.144"},{"key":"31","year":"2014"},{"issue":"12","key":"32","volume":"60","year":"2017","journal-title":"Scince China Information Sciences"},{"key":"33","year":"2015"},{"key":"34","doi-asserted-by":"publisher","DOI":"10.1109\/MCG.2006.49"},{"key":"35","first-page":"139","volume-title":"Visual Analytics: Foundations and Experiences in Malware Analysis","year":"2017"},{"key":"37","year":"2017"},{"key":"38","year":"2007"},{"key":"39","year":"2009"},{"key":"40","volume-title":"Data-driven security analysis, visualisation, and dashboards","year":"2014"},{"key":"41","doi-asserted-by":"publisher","DOI":"10.1109\/38.974517"},{"key":"43","doi-asserted-by":"publisher","DOI":"10.1109\/MCG.2006.31"},{"key":"44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60753-5_19"},{"key":"47","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-014-0242-0"},{"key":"50","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/132713"},{"key":"54","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/6451260"},{"key":"55","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/7247095"},{"key":"56","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2014.2388208"},{"key":"58","doi-asserted-by":"publisher","DOI":"10.1108\/17440081311316361"},{"key":"60","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1723"},{"key":"61","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2799854"},{"key":"62","year":"2017","journal-title":"Computers & Security"},{"key":"63","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.02.003"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2018\/1728303.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2018\/1728303.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2018\/1728303.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,12,2]],"date-time":"2018-12-02T18:31:43Z","timestamp":1543775503000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2018\/1728303\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,2]]},"references-count":41,"alternative-id":["1728303","1728303"],"URL":"https:\/\/doi.org\/10.1155\/2018\/1728303","relation":{},"ISSN":["1939-0114","1939-0122"],"issn-type":[{"value":"1939-0114","type":"print"},{"value":"1939-0122","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,12,2]]}}}