{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T09:24:52Z","timestamp":1762507492458,"version":"3.37.3"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,9,10]],"date-time":"2018-09-10T00:00:00Z","timestamp":1536537600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61472131"],"award-info":[{"award-number":["61472131"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004735","name":"Natural Science Foundation of\u00a0Hunan Province","doi-asserted-by":"publisher","award":["2017JJ2292"],"award-info":[{"award-number":["2017JJ2292"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2018,12]]},"DOI":"10.1186\/s42400-018-0010-y","type":"journal-article","created":{"date-parts":[[2018,9,10]],"date-time":"2018-09-10T14:32:41Z","timestamp":1536589961000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Sensitive system calls based packed malware variants detection using principal component initialized MultiLayers neural networks"],"prefix":"10.1186","volume":"1","author":[{"given":"Jixin","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kehuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng","family":"Qin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hui","family":"Yin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qixin","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,9,10]]},"reference":[{"key":"10_CR1","unstructured":"ASPack, http:\/\/www.aspack.com (2017)"},{"issue":"2","key":"10_CR2","doi-asserted-by":"publisher","first-page":"140","DOI":"10.1049\/iet-ifs.2012.0343","volume":"8","author":"H Bai","year":"2014","unstructured":"Bai H et al (2014) Approach for malware identification using dynamic behaviour and outcome triggering. IET Inf Secur 8(2):140\u2013151","journal-title":"IET Inf Secur"},{"key":"10_CR3","first-page":"169","volume-title":"Proc. of ACM Conference on Computer and Communications Security","author":"J Calvet","year":"2012","unstructured":"Calvet J et al (2012) Aligot: Cryptographic Function Identification in Obfuscated Binary Programs. In: Proc. of ACM Conference on Computer and Communications Security, pp 169\u2013182"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Canzanese R. et al. (2015) System call-based detection of malicious processes. In proc. of 2015 IEEE international conference on software quality, Reliability and Security, 119\u201324","DOI":"10.1109\/QRS.2015.26"},{"issue":"4","key":"10_CR5","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1109\/TDSC.2013.40","volume":"11","author":"S Cesare","year":"2014","unstructured":"Cesare S et al (2014) Control flow-based malware variant detection. IEEE Trans Dependable and Secure Comput 11(4):307\u2013317","journal-title":"IEEE Trans Dependable and Secure Comput"},{"key":"10_CR6","first-page":"167","volume-title":"Proc. of Working Conference on Reverse Engineering","author":"K Coogan","year":"2009","unstructured":"Coogan K et al (2009) Automatic Static Unpacking of Malware Binaries. In: Proc. of Working Conference on Reverse Engineering, pp 167\u2013176"},{"key":"10_CR7","first-page":"1","volume-title":"Proc. of IEEE Conference on Information and Knowledge Technology","author":"J Esmaily","year":"2015","unstructured":"Esmaily J et al (2015) Intrusion detection system based on Multi-Layer Perceptron Neural Networks and Decision Tree. In: Proc. of IEEE Conference on Information and Knowledge Technology, pp 1\u20135"},{"key":"10_CR8","unstructured":"Euclidean Space, https:\/\/en.wikipedia.org\/wiki\/Euclidean_space (2017)"},{"issue":"2","key":"10_CR9","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1016\/S0893-6080(02)00233-2","volume":"16","author":"A Fern\u00e1ndezcaballero","year":"2003","unstructured":"Fern\u00e1ndezcaballero A et al (2003) On motion detection through a multi-layer neural network architecture. Neural Netw 16(2):205\u2013222","journal-title":"Neural Netw"},{"key":"10_CR10","unstructured":"Gradient descent, https:\/\/en.wikipedia.org\/wiki\/Gradient_descent (2017)"},{"key":"10_CR11","doi-asserted-by":"crossref","first-page":"1036","DOI":"10.1145\/2568225.2568301","volume-title":"Proc. of ACM\/IEEE International Conference on Software Engineering","author":"J Huang","year":"2014","unstructured":"Huang J et al (2014) AsDroid detecting stealthy behaviors in Android applications by user interface and program behavior contradiction. In: Proc. of ACM\/IEEE International Conference on Software Engineering, pp 1036\u20131046"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Jang J et al (2015) Mal-Netminer: Malware Classification Approach Based on Social Network Analysis of System Call Graph. In: Proc. of the 23rd international conference on World wide web companion pp 731\u201334.","DOI":"10.1155\/2015\/769624"},{"key":"10_CR13","unstructured":"Kolosnjaji B et al (2016) Deep Learning for Classication of Malware System Call Sequences. In: Proc. of Australasian Joint Conference on Artificial Intelligence pp 137\u2013149"},{"key":"10_CR14","doi-asserted-by":"publisher","first-page":"639","DOI":"10.3233\/JCS-2010-0410","volume":"19","author":"R Konrad","year":"2011","unstructured":"Konrad R et al (2011) Automatic analysis of malware behavior using machine learning. J Comput Secur 19:639\u2013668","journal-title":"J Comput Secur"},{"key":"10_CR15","unstructured":"Kullback-Leibler divergence, https:\/\/en.wikipedia.org\/wiki\/Kullback-Leibler_divergence (2018)"},{"key":"10_CR16","first-page":"289","volume-title":"Proc. Of ACM International Conference on Security of Internet of Things","author":"C Kumar","year":"2012","unstructured":"Kumar C et al (2012) Obfuscated Malware Detection Using API Call Dependency. In: Proc. Of ACM International Conference on Security of Internet of Things, pp 289\u2013300"},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"Li Z. et al.: VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In Proc. of arXiv:1801.01681v1 [cs.CR] (2018)","DOI":"10.14722\/ndss.2018.23158"},{"key":"10_CR18","unstructured":"Malwr, https:\/\/malwr.com \/ (2018)"},{"key":"10_CR19","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1145\/2046684.2046689","volume-title":"Proc. of ACM Workshop on Security & Artificial Intelligence","author":"L Nataraj","year":"2011","unstructured":"Nataraj L et al (2011) A Comparative Assessment of Malware Classification using Binary Texture Analysis and Dynamic Analysis. In: Proc. of ACM Workshop on Security & Artificial Intelligence, pp 21\u201330"},{"key":"10_CR20","unstructured":"PCA, https:\/\/en.wikipedia.org\/wiki\/Principal_component_analysis (2017)"},{"issue":"8","key":"10_CR21","doi-asserted-by":"publisher","first-page":"1226","DOI":"10.1109\/TPAMI.2005.159","volume":"27","author":"H Peng","year":"2005","unstructured":"Peng H et al (2005) Feature selection based on mutual information: criteria of max-dependency, max-relevance, and min-redundancy. IEEE Trans Pattern Anal Mach Intell 27(8):1226\u20131238","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"10_CR22","volume-title":"InfoSec Southwest","author":"K Raman","year":"2012","unstructured":"Raman K et al (2012) Selecting features to classify malware. In: InfoSec Southwest"},{"key":"10_CR23","unstructured":"Receiver Operating Characteristic, https:\/\/en.wikipedia.org\/wiki\/Receiver_operating_characteristic (2018)"},{"key":"10_CR24","first-page":"289","volume-title":"Proc. of 22nd Annual Computer Security Applications Conference","author":"P Royal","year":"2006","unstructured":"Royal P et al (2006) PolyUnpack: Automating the Hidden-Code Extraction of Unpac Executing Malware. In: Proc. of 22nd Annual Computer Security Applications Conference, pp 289\u2013300"},{"key":"10_CR25","first-page":"6104","volume-title":"Proc. of Annual International Conference of the IEEE Engineering in Medicine and Biology Society","author":"V Salai Selvam","year":"2011","unstructured":"Salai Selvam V et al (2011) Brain tumor detection using scalp eeg with modified Wavelet-ICA and multi layer feed forward neural network. In: Proc. of Annual International Conference of the IEEE Engineering in Medicine and Biology Society, pp 6104\u20136109"},{"key":"10_CR26","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1145\/2642687.2642705","volume-title":"Proc. of ACM symposium on QoS and security for wireless and mobile networks","author":"O Salcedo Parra","year":"2014","unstructured":"Salcedo Parra O et al (2014) Traffic forecasting using a multi layer perceptron model. In: Proc. of ACM symposium on QoS and security for wireless and mobile networks, pp 133\u2013136"},{"issue":"9","key":"10_CR27","first-page":"64","volume":"231","author":"I Santos","year":"2011","unstructured":"Santos I et al (2011) Opcode sequences as representation of executables for data mining based malware variant detection. Inf Sci 231(9):64\u201382","journal-title":"Inf Sci"},{"key":"10_CR28","first-page":"271","volume-title":"Proc. of International Conference CISIS\u201912","author":"I Santos","year":"2013","unstructured":"Santos I et al (2013) OPEM: A Static-Dynamic Approach for Machine Learning Base Malware Detection. In: Proc. of International Conference CISIS\u201912, pp 271\u2013280"},{"key":"10_CR29","first-page":"289","volume-title":"Proc. of IEEE International Conference on Next Generation Mobile Applications, Security and Technologies","author":"Z Shehu","year":"2016","unstructured":"Shehu Z et al (2016) Towards the Usage of Invariant-Based App Behavioral Fingerprinting for the Detection of Obfuscated Versions of Known Malware. In: Proc. of IEEE International Conference on Next Generation Mobile Applications, Security and Technologies, pp 289\u2013300"},{"issue":"4","key":"10_CR30","first-page":"789","volume":"15","author":"G Suarez-Tangil","year":"2016","unstructured":"Suarez-Tangil G et al (2016) ALTERDROID: differential fault analysis of obfuscated smart-phone malware. IEEE Trans Mob Comput 15(4):789\u2013802","journal-title":"IEEE Trans Mob Comput"},{"key":"10_CR31","first-page":"291","volume-title":"Proc. of IEEE International Conference on Intelligence & Security Informatics","author":"S Treadwell","year":"2009","unstructured":"Treadwell S et al (2009) A Heuristic Approach for Detection of Obfuscated Malware. In: Proc. of IEEE International Conference on Intelligence & Security Informatics, pp 291\u2013299"},{"key":"10_CR32","unstructured":"UPX, https:\/\/upx.github.io (2017)"},{"key":"10_CR33","unstructured":"VMProtect, https:\/\/vmpsoft.com\/products\/vmprotect\/ (2017)"},{"key":"10_CR34","unstructured":"VX Heaven, https:\/\/hypestat.com\/info\/vxheaven.org (2017)"},{"key":"10_CR35","first-page":"220","volume-title":"Proc. of IEEE International Conference on Cyber Security and Cloud Computing","author":"L Xu","year":"2016","unstructured":"Xu L et al (2016) Dynamic Android Malware Classification Using Graph-Based Representations. In: Proc. of IEEE International Conference on Cyber Security and Cloud Computing, pp 220\u2013231"},{"key":"10_CR36","doi-asserted-by":"crossref","unstructured":"W. Yang et al. (2015) AppContext: differentiating malicious and benign mobile app behaviors using context. In: Proc. of IEEE\/ACM International Conference on Software Engineering (2015), Firenze, Italy, pp 303\u2013313","DOI":"10.1109\/ICSE.2015.50"},{"key":"10_CR37","first-page":"1","volume-title":"Proc. of IEEE International Conference on Computer Communication and Networks","author":"J Zhang","year":"2016","unstructured":"Zhang J et al (2016a) Malware Variant Detection Using Opcode Image Recognition with Small Training Sets. In: Proc. of IEEE International Conference on Computer Communication and Networks, pp 1\u20139"},{"key":"10_CR38","first-page":"1175","volume-title":"Proc. of IEEE International Conference on Parallel and Distributed Systems","author":"J Zhang","year":"2016","unstructured":"Zhang J et al (2016b) IRMD: Malware Variant Detection Using Opcode Image Recognition. In: Proc. of IEEE International Conference on Parallel and Distributed Systems, pp 1175\u20131180"},{"issue":"2","key":"10_CR39","first-page":"article 4","volume":"19","author":"H Zhang","year":"2016","unstructured":"Zhang H et al (2016c) Detection of stealthy malware activities with traffic causality and scalable triggering relation discovery. ACM Transactions on Privacy and Security 19(2):article 4","journal-title":"ACM Transactions on Privacy and Security"},{"key":"10_CR40","unstructured":"ZProtect, https:\/\/tuts4you.com\/download.php?view.3017 (2017)"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-018-0010-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s42400-018-0010-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-018-0010-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,1]],"date-time":"2022-09-01T01:26:49Z","timestamp":1661995609000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-018-0010-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,9,10]]},"references-count":40,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,12]]}},"alternative-id":["10"],"URL":"https:\/\/doi.org\/10.1186\/s42400-018-0010-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"type":"electronic","value":"2523-3246"}],"subject":[],"published":{"date-parts":[[2018,9,10]]},"assertion":[{"value":"26 April 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 August 2018","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 September 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"No conflict of interest exits in the submission of this manuscript, and manuscript is approved by all authors for publication.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Publisher\u2019s Note"}}],"article-number":"10"}}