{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:13:25Z","timestamp":1784391205558,"version":"3.55.0"},"reference-count":52,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,1,12]],"date-time":"2018-01-12T00:00:00Z","timestamp":1515715200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2018,1,12]],"date-time":"2018-01-12T00:00:00Z","timestamp":1515715200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Hum. Cent. Comput. Inf. Sci."],"published-print":{"date-parts":[[2018,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Data mining techniques have been concentrated for malware detection in the recent decade. The battle between security analyzers and malware scholars is everlasting as innovation grows. The proposed methodologies are not adequate while evolutionary and complex nature of malware is changing quickly and therefore turn out to be harder to recognize. This paper presents a systematic and detailed survey of the malware detection mechanisms using data mining techniques. In addition, it classifies the malware detection approaches in two main categories including signature-based methods and behavior-based detection. The main contributions of this paper are: (1) providing a summary of the current challenges related to the\u00a0malware detection approaches in data mining, (2) presenting a systematic and categorized overview of the current approaches to machine learning mechanisms, (3) exploring the structure of the significant methods in the\u00a0malware detection approach and (4) discussing the important factors of classification malware approaches in the data mining. The detection approaches have been compared with each other according to their importance factors. The advantages and disadvantages of them were discussed in terms of data mining models, their evaluation method and their proficiency. This survey helps researchers to have a general comprehension of the malware detection field and for specialists to do consequent examinations.<\/jats:p>","DOI":"10.1186\/s13673-018-0125-x","type":"journal-article","created":{"date-parts":[[2018,1,15]],"date-time":"2018-01-15T12:33:47Z","timestamp":1516019627000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":308,"title":["A state-of-the-art survey of malware detection approaches using data mining techniques"],"prefix":"10.1186","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8314-9051","authenticated-orcid":false,"given":"Alireza","family":"Souri","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rahil","family":"Hosseini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,1,12]]},"reference":[{"key":"125_CR1","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/s41870-017-0050-7","volume":"9","author":"A Souri","year":"2017","unstructured":"Souri A, Norouzi M, Asghari P (2017) An analytical automated refinement approach for structural modeling large-scale codes using reverse engineering. Int J Inf Technol 9:329\u2013333. https:\/\/doi.org\/10.1007\/s41870-017-0050-7","journal-title":"Int J Inf Technol"},{"key":"125_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2017.11.007","author":"A Souri","year":"2017","unstructured":"Souri A, Navimipour NJ, Rahmani AM (2017) Formal verification approaches and standards in the cloud computing: a comprehensive and systematic review. Comput Stand Interfaces. https:\/\/doi.org\/10.1016\/j.csi.2017.11.007","journal-title":"Comput Stand Interfaces"},{"key":"125_CR3","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/s11416-016-0278-y","volume":"13","author":"H Hashemi","year":"2017","unstructured":"Hashemi H, Azmoodeh A, Hamzeh A, Hashemi S (2017) Graph embedding as a new approach for unknown malware detection. J Comput Virol Hacking Tech 13:153\u2013166. https:\/\/doi.org\/10.1007\/s11416-016-0278-y","journal-title":"J Comput Virol Hacking Tech"},{"key":"125_CR4","first-page":"643","volume":"13","author":"JH Park","year":"2017","unstructured":"Park JH (2017) Novel approaches for applying linguistic processing techniques based on pattern recognition and machine learning. JIPS (J Inf Process Syst) 13:643\u2013652","journal-title":"JIPS (J Inf Process Syst)"},{"key":"125_CR5","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/s12927-017-0011-5","volume":"9","author":"A Souri","year":"2017","unstructured":"Souri A, Asghari P, Rezaei R (2017) Software as a service based CRM providers in the cloud computing: challenges and technical issues. J Serv Sci Res 9:219\u2013237. https:\/\/doi.org\/10.1007\/s12927-017-0011-5","journal-title":"J Serv Sci Res"},{"key":"125_CR6","doi-asserted-by":"crossref","unstructured":"Bhattacharya A, Goswami RT (2017) DMDAM: data mining based detection of android malware. In: Mandal JK, Satapathy SC, Sanyal MK, Bhateja V (eds) Proceedings of the first international conference on intelligent computing and communication springer Singapore, Singapore, pp 187\u2013194","DOI":"10.1007\/978-981-10-2035-3_20"},{"key":"125_CR7","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/s11416-016-0267-1","volume":"13","author":"SD Nikolopoulos","year":"2017","unstructured":"Nikolopoulos SD, Polenakis I (2017) A graph-based model for malware detection and classification using system-call groups. J Comput Virol Hacking Tech 13:29\u201346. https:\/\/doi.org\/10.1007\/s11416-016-0267-1","journal-title":"J Comput Virol Hacking Tech"},{"key":"125_CR8","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1016\/j.jisa.2017.10.005","volume":"37","author":"A Pekta\u015f","year":"2017","unstructured":"Pekta\u015f A, Acarman T (2017) Classification of malware families based on runtime behaviors. J Inf Secur Appl 37:91\u2013100. https:\/\/doi.org\/10.1016\/j.jisa.2017.10.005","journal-title":"J Inf Secur Appl"},{"key":"125_CR9","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-017-1058-9","author":"Y Ye","year":"2017","unstructured":"Ye Y, Chen L, Hou S, Hardy W, Li X (2017) DeepAM: a heterogeneous deep learning framework for intelligent malware detection. Knowl Inf Syst. https:\/\/doi.org\/10.1007\/s10115-017-1058-9","journal-title":"Knowl Inf Syst"},{"key":"125_CR10","doi-asserted-by":"publisher","first-page":"1324","DOI":"10.1016\/j.procs.2015.07.443","volume":"57","author":"A Safarkhanlou","year":"2015","unstructured":"Safarkhanlou A, Souri A, Norouzi M, Sardroud SEH (2015) Formalizing and verification of an antivirus protection service using model checking. Procedia Comput Sci 57:1324\u20131331. https:\/\/doi.org\/10.1016\/j.procs.2015.07.443","journal-title":"Procedia Comput Sci"},{"key":"125_CR11","doi-asserted-by":"crossref","unstructured":"Li Z, Sun L, Yan Q, Srisa-an W, Chen Z (2017) DroidClassifier: efficient adaptive mining of application-layer header for classifying android malware. In: Deng R, Weng J, Ren K, Yegneswaran V (eds) Security and privacy in communication networks: 12th international conference, securecomm 2016, Guangzhou, China, October 10\u201312, 2016, Proceedings. Springer International Publishing, Cham, pp 597\u2013616","DOI":"10.1007\/978-3-319-59608-2_33"},{"issue":"4","key":"125_CR12","doi-asserted-by":"publisher","first-page":"778","DOI":"10.3745\/JIPS.04.0013","volume":"13","author":"R Malhotra","year":"2017","unstructured":"Malhotra R, Jangra R (2017) Prediction & assessment of change prone classes using statistical & machine learning techniques. J Inf Process Syst 13(4):778\u2013804. https:\/\/doi.org\/10.3745\/JIPS.04.0013","journal-title":"J Inf Process Syst"},{"key":"125_CR13","doi-asserted-by":"crossref","unstructured":"Chowdhury M, Rahman A, Islam R (2018) Malware analysis and detection using data mining and machine learning classification. In: Abawajy J, Choo K-KR, Islam R (eds) International conference on applications and techniques in cyber security and intelligence: applications and techniques in cyber security and intelligence. Springer International Publishing, Cham, pp 266\u2013274","DOI":"10.1007\/978-3-319-67071-3_33"},{"key":"125_CR14","doi-asserted-by":"publisher","first-page":"689","DOI":"10.1016\/j.cose.2017.07.013","volume":"70","author":"P Palumbo","year":"2017","unstructured":"Palumbo P, Sayfullina L, Komashinskiy D, Eirola E, Karhunen J (2017) A pragmatic android malware detection procedure. Comput Secur 70:689\u2013701. https:\/\/doi.org\/10.1016\/j.cose.2017.07.013","journal-title":"Comput Secur"},{"key":"125_CR15","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9539-8","author":"A Narayanan","year":"2017","unstructured":"Narayanan A, Chandramohan M, Chen L, Liu Y (2017) A multi-view context-aware approach to Android malware detection and malicious code localization. Empir Softw Eng. https:\/\/doi.org\/10.1007\/s10664-017-9539-8","journal-title":"Empir Softw Eng"},{"key":"125_CR16","unstructured":"Mohamed GAN, Ithnin NB (2018) SBRT: API signature behaviour based representation technique for improving metamorphic malware detection. In: Saeed F, Gazem N, Patnaik S, Saed Balaid AS, Mohammed F (eds) Recent trends in information and communication technology. Proceedings of the 2nd international conference of reliable information and communication technology (IRICT 2017). Springer International Publishing, Cham, pp 767\u2013777"},{"key":"125_CR17","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1007\/s40012-016-0095-y","volume":"4","author":"A Malhotra","year":"2016","unstructured":"Malhotra A, Bajaj K (2016) A hybrid pattern based text mining approach for malware detection using DBScan. CSI Trans ICT 4:141\u2013149. https:\/\/doi.org\/10.1007\/s40012-016-0095-y","journal-title":"CSI Trans ICT"},{"key":"125_CR18","doi-asserted-by":"crossref","unstructured":"Siddiqui M, Wang MC, Lee J (2008) A survey of data mining techniques for malware detection using file features. In: Proceedings of the 46th annual southeast regional conference on xx. 2008. ACM","DOI":"10.1145\/1593105.1593239"},{"key":"125_CR19","doi-asserted-by":"crossref","unstructured":"Sun L, Li Z, Yan Q, Srisa-an W, Pan Y (2016) SigPID: significant permission identification for android malware detection. In: 2016 11th international conference on malicious and unwanted software (MALWARE), pp 1\u20138","DOI":"10.1109\/MALWARE.2016.7888730"},{"key":"125_CR20","doi-asserted-by":"crossref","unstructured":"Boujnouni ME, Jedra M, Zahid N (2015) New malware detection framework based on N-grams and support vector domain description. In: 2015 11th international conference on information assurance and security (IAS), pp 123\u2013128","DOI":"10.1109\/ISIAS.2015.7492756"},{"key":"125_CR21","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2017.2675881","author":"T Wuechner","year":"2017","unstructured":"Wuechner T, Cislak A, Ochoa M, Pretschner A (2017) Leveraging compression-based graph mining for behavior-based malware detection. IEEE Trans Dependable Secur Comput. https:\/\/doi.org\/10.1109\/tdsc.2017.2675881","journal-title":"IEEE Trans Dependable Secur Comput"},{"key":"125_CR22","doi-asserted-by":"crossref","unstructured":"Bhattacharya A, Goswami RT (2017) Comparative analysis of different feature ranking techniques in data mining-based android malware detection. In: Satapathy SC, Bhateja V, Udgata SK, Pattnaik PK (eds) Proceedings of the 5th international conference on frontiers in intelligent computing: theory and applications: FICTA 2016, Volume 1. Springer Singapore, Singapore, pp 39\u201349","DOI":"10.1007\/978-981-10-3153-3_5"},{"key":"125_CR23","doi-asserted-by":"crossref","unstructured":"Fan CI, Hsiao HW, Chou CH, Tseng YF (2015) Malware detection systems based on API log data mining. In: 2015 IEEE 39th annual computer software and applications conference, pp 255\u2013260","DOI":"10.1109\/COMPSAC.2015.241"},{"key":"125_CR24","doi-asserted-by":"publisher","first-page":"1012","DOI":"10.1016\/j.jcss.2014.12.014","volume":"81","author":"P Wang","year":"2015","unstructured":"Wang P, Wang Y-S (2015) Malware behavioural detection and vaccine development by using a support vector model classifier. J Comput Syst Sci 81:1012\u20131026. https:\/\/doi.org\/10.1016\/j.jcss.2014.12.014","journal-title":"J Comput Syst Sci"},{"key":"125_CR25","doi-asserted-by":"crossref","unstructured":"Fraley JB, Figueroa M (2016) Polymorphic malware detection using topological feature extraction with data mining. In: SoutheastCon 2016, pp 1\u20137","DOI":"10.1109\/SECON.2016.7506685"},{"key":"125_CR26","doi-asserted-by":"publisher","first-page":"1103","DOI":"10.1109\/TIFS.2016.2646641","volume":"12","author":"M Sun","year":"2017","unstructured":"Sun M, Li X, Lui JC, Ma RT, Liang Z (2017) Monet: a user-oriented behavior-based malware variants detection system for android. IEEE Trans Inf Forensics Secur 12:1103\u20131112","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"125_CR27","doi-asserted-by":"publisher","first-page":"421","DOI":"10.1002\/spe.2420","volume":"47","author":"H Sun","year":"2017","unstructured":"Sun H, Wang X, Buyya R, Su J (2017) CloudEyes: cloud-based malware detection with reversible sketch for resource-constrained internet of things (IoT) devices. Softw Pract Exp 47:421\u2013441. https:\/\/doi.org\/10.1002\/spe.2420","journal-title":"Softw Pract Exp"},{"key":"125_CR28","doi-asserted-by":"publisher","first-page":"565","DOI":"10.1109\/TC.2010.130","volume":"60","author":"Y Tang","year":"2011","unstructured":"Tang Y, Xiao B, Lu X (2011) Signature tree generation for polymorphic worms. IEEE Trans Comput 60:565\u2013579. https:\/\/doi.org\/10.1109\/TC.2010.130","journal-title":"IEEE Trans Comput"},{"key":"125_CR29","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1109\/CC.2014.7085617","volume":"11","author":"B Wu","year":"2014","unstructured":"Wu B, Lu T, Zheng K, Zhang D, Lin X (2014) Smartphone malware detection model based on artificial immune system. China Commun 11:86\u201392. https:\/\/doi.org\/10.1109\/CC.2014.7022530","journal-title":"China Commun"},{"issue":"3","key":"125_CR30","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/s10207-016-0330-4","volume":"16","author":"M Bat-Erdene","year":"2017","unstructured":"Bat-Erdene M, Park H, Li H, Lee H, Choi MS (2017) Entropy analysis to classify unknown packing algorithms for malware detection. Int J Inf Secur 16(3):227\u2013248. https:\/\/doi.org\/10.1007\/s10207-016-0330-4","journal-title":"Int J Inf Secur"},{"key":"125_CR31","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1016\/j.pmcj.2015.06.006","volume":"24","author":"B Cui","year":"2015","unstructured":"Cui B, Jin H, Carullo G, Liu Z (2015) Service-oriented mobile malware detection system based on mining strategies. Pervasive Mob Comput 24:101\u2013116. https:\/\/doi.org\/10.1016\/j.pmcj.2015.06.006","journal-title":"Pervasive Mob Comput"},{"key":"125_CR32","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.eswa.2016.01.002","volume":"52","author":"Y Fan","year":"2016","unstructured":"Fan Y, Ye Y, Chen L (2016) Malicious sequential pattern mining for automatic malware detection. Expert Syst Appl 52:16\u201325. https:\/\/doi.org\/10.1016\/j.eswa.2016.01.002","journal-title":"Expert Syst Appl"},{"key":"125_CR33","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.cose.2016.06.004","volume":"62","author":"A Hellal","year":"2016","unstructured":"Hellal A, Romdhane LB (2016) Minimal contrast frequent pattern mining for malware detection. Comput Secur 62:19\u201332. https:\/\/doi.org\/10.1016\/j.cose.2016.06.004","journal-title":"Comput Secur"},{"key":"125_CR34","doi-asserted-by":"publisher","first-page":"7405","DOI":"10.1007\/s00500-016-2283-y","volume":"21","author":"A Mart\u00edn","year":"2016","unstructured":"Mart\u00edn A, Men\u00e9ndez HD, Camacho D (2016) MOCDroid: multi-objective evolutionary classifier for Android malware detection. Soft Comput 21:7405\u20137415. https:\/\/doi.org\/10.1007\/s00500-016-2283-y","journal-title":"Soft Comput"},{"key":"125_CR35","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1016\/j.ins.2011.08.020","volume":"231","author":"I Santos","year":"2013","unstructured":"Santos I, Brezo F, Ugarte-Pedrero X, Bringas PG (2013) Opcode sequences as representation of executables for data-mining-based unknown malware detection. Inf Sci 231:64\u201382. https:\/\/doi.org\/10.1016\/j.ins.2011.08.020","journal-title":"Inf Sci"},{"key":"125_CR36","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2017.11.028","author":"Z-U Rehman","year":"2017","unstructured":"Rehman Z-U, Khan SN, Muhammad K, Lee JW, Lv Z, Baik SW, Shah PA, Awan K, Mehmood I (2017) Machine learning-assisted signature and heuristic-based detection of malwares in Android devices. Comput Electr Eng. https:\/\/doi.org\/10.1016\/j.compeleceng.2017.11.028","journal-title":"Comput Electr Eng"},{"key":"125_CR37","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1016\/j.cose.2016.11.011","volume":"65","author":"S Alam","year":"2017","unstructured":"Alam S, Qu Z, Riley R, Chen Y, Rastogi V (2017) DroidNative: automating and optimizing detection of Android native code malware variants. Comput Secur 65:230\u2013246. https:\/\/doi.org\/10.1016\/j.cose.2016.11.011","journal-title":"Comput Secur"},{"key":"125_CR38","doi-asserted-by":"publisher","first-page":"4147","DOI":"10.1007\/s00521-016-2708-7","volume":"28","author":"A Altaher","year":"2016","unstructured":"Altaher A (2016) An improved Android malware detection scheme based on an evolving hybrid neuro-fuzzy classifier (EHNFC) and permission-based features. Neural Comput Appl 28:4147\u20134157. https:\/\/doi.org\/10.1007\/s00521-016-2708-7","journal-title":"Neural Comput Appl"},{"key":"125_CR39","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1016\/j.cose.2015.04.001","volume":"52","author":"A Mohaisen","year":"2015","unstructured":"Mohaisen A, Alrawi O, Mohaisen M (2015) AMAL: high-fidelity, behavior-based automated malware analysis and classification. Comput Secur 52:251\u2013266. https:\/\/doi.org\/10.1016\/j.cose.2015.04.001","journal-title":"Comput Secur"},{"key":"125_CR40","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1109\/TST.2016.7399288","volume":"21","author":"Z Yuan","year":"2016","unstructured":"Yuan Z, Lu Y, Xue Y (2016) Droiddetector: android malware characterization and detection using deep learning. Tsinghua Sci Technol 21:114\u2013123. https:\/\/doi.org\/10.1109\/TST.2016.7399288","journal-title":"Tsinghua Sci Technol"},{"key":"125_CR41","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1007\/s11416-015-0247-x","volume":"12","author":"A Boukhtouta","year":"2016","unstructured":"Boukhtouta A, Mokhov SA, Lakhdari N-E, Debbabi M, Paquet J (2016) Network malware classification comparison using DPI and flow packet headers. J Comput Virol Hacking Tech 12:69\u2013100. https:\/\/doi.org\/10.1007\/s11416-015-0247-x","journal-title":"J Comput Virol Hacking Tech"},{"issue":"Part B","key":"125_CR42","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1016\/j.cose.2013.08.008","volume":"39","author":"Y Ding","year":"2013","unstructured":"Ding Y, Yuan X, Tang K, Xiao X, Zhang Y (2013) A fast malware detection algorithm based on objective-oriented association mining. Comput Secur 39(Part B):315\u2013324. https:\/\/doi.org\/10.1016\/j.cose.2013.08.008","journal-title":"Comput Secur"},{"key":"125_CR43","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/s11416-013-0181-8","volume":"9","author":"M Eskandari","year":"2013","unstructured":"Eskandari M, Khorshidpour Z, Hashemi S (2013) HDM-Analyser: a hybrid analysis approach based on data mining techniques for malware detection. J Comput Virol Hacking Tech 9:77\u201393. https:\/\/doi.org\/10.1007\/s11416-013-0181-8","journal-title":"J Comput Virol Hacking Tech"},{"key":"125_CR44","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/s10207-015-0297-6","volume":"15","author":"Q Miao","year":"2016","unstructured":"Miao Q, Liu J, Cao Y, Song J (2016) Malware detection using bilayer behavior abstraction and improved one-class support vector machines. Int J Inf Secur 15:361\u2013379. https:\/\/doi.org\/10.1007\/s10207-015-0297-6","journal-title":"Int J Inf Secur"},{"key":"125_CR45","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/s11416-016-0281-3","volume":"13","author":"J Ming","year":"2016","unstructured":"Ming J, Xin Z, Lan P, Wu D, Liu P, Mao B (2016) Impeding behavior-based malware analysis via replacement attacks to malware specifications. J Comput Virol Hacking Tech 13:193\u2013207. https:\/\/doi.org\/10.1007\/s11416-016-0281-3","journal-title":"J Comput Virol Hacking Tech"},{"key":"125_CR46","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/s11416-016-0267-1","volume":"13","author":"SD Nikolopoulos","year":"2016","unstructured":"Nikolopoulos SD, Polenakis I (2016) A graph-based model for malware detection and classification using system-call groups. J Comput Virol Hacking Tech 13:29\u201346. https:\/\/doi.org\/10.1007\/s11416-016-0267-1","journal-title":"J Comput Virol Hacking Tech"},{"issue":"Part 2","key":"125_CR47","doi-asserted-by":"publisher","first-page":"905","DOI":"10.1016\/j.neucom.2014.10.004","volume":"151","author":"S Sheen","year":"2015","unstructured":"Sheen S, Anitha R, Natarajan V (2015) Android based malware detection using a multifeature collaborative decision fusion approach. Neurocomputing 151(Part 2):905\u2013912. https:\/\/doi.org\/10.1016\/j.neucom.2014.10.004","journal-title":"Neurocomputing"},{"key":"125_CR48","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1155\/2016\/8069672","volume":"2016","author":"M Norouzi","year":"2016","unstructured":"Norouzi M, Souri A, Samad Zamini M (2016) A data mining classification approach for behavioral malware detection. J Comput Netw Commun 2016:9. https:\/\/doi.org\/10.1155\/2016\/8069672","journal-title":"J Comput Netw Commun"},{"key":"125_CR49","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/s11416-015-0244-0","volume":"12","author":"HS Galal","year":"2016","unstructured":"Galal HS, Mahdy YB, Atiea MA (2016) Behavior-based features model for malware detection. J Comput Virol Hacking Tech 12:59\u201367. https:\/\/doi.org\/10.1007\/s11416-015-0244-0","journal-title":"J Comput Virol Hacking Tech"},{"key":"125_CR50","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1016\/j.cose.2017.02.009","volume":"68","author":"W Mao","year":"2017","unstructured":"Mao W, Cai Z, Towsley D, Feng Q, Guan X (2017) Security importance assessment for system objects and malware detection. Comput Secur 68:47\u201368. https:\/\/doi.org\/10.1016\/j.cose.2017.02.009","journal-title":"Comput Secur"},{"key":"125_CR51","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1016\/j.infsof.2016.03.004","volume":"75","author":"S Wu","year":"2016","unstructured":"Wu S, Wang P, Li X, Zhang Y (2016) Effective detection of android malware based on the usage of data flow APIs and machine learning. Inf Softw Technol 75:17\u201325. https:\/\/doi.org\/10.1016\/j.infsof.2016.03.004","journal-title":"Inf Softw Technol"},{"key":"125_CR52","doi-asserted-by":"crossref","unstructured":"Dali Z, Hao J, Ying Y, Wu D, Weiyi C (2017) DeepFlow: deep learning-based malware detection by mining Android application for abnormal usage of sensitive data. In: 2017 IEEE symposium on computers and communications (ISCC), pp 438\u2013443","DOI":"10.1109\/ISCC.2017.8024568"}],"container-title":["Human-centric Computing and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13673-018-0125-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-018-0125-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-018-0125-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,30]],"date-time":"2021-07-30T08:21:06Z","timestamp":1627633266000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13673-018-0125-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,1,12]]},"references-count":52,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,12]]}},"alternative-id":["125"],"URL":"https:\/\/doi.org\/10.1186\/s13673-018-0125-x","relation":{},"ISSN":["2192-1962"],"issn-type":[{"value":"2192-1962","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,1,12]]},"assertion":[{"value":"20 July 2017","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 January 2018","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 January 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"3"}}