{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:02:58Z","timestamp":1760241778170,"version":"build-2065373602"},"reference-count":33,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2018,8,14]],"date-time":"2018-08-14T00:00:00Z","timestamp":1534204800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1636201"],"award-info":[{"award-number":["U1636201"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>In the malware detection process, obfuscated malicious codes cannot be efficiently and accurately detected solely in the dynamic or static feature space. Aiming at this problem, an integrative feature extraction algorithm based on simhash was proposed, which combines the static information e.g., API (Application Programming Interface) calls and dynamic information (such as file, registry and network behaviors) of malicious samples to form integrative features. The experiment extracts the integrative features of some static information and dynamic information, and then compares the classification, time and obfuscated-detection performance of the static, dynamic and integrated features, respectively, by using several common machine learning algorithms. The results show that the integrative features have better time performance than the static features, and better classification performance than the dynamic features, and almost the same obfuscated-detection performance as the dynamic features. This algorithm can provide some support for feature extraction of malware detection.<\/jats:p>","DOI":"10.3390\/a11080124","type":"journal-article","created":{"date-parts":[[2018,8,14]],"date-time":"2018-08-14T10:31:16Z","timestamp":1534242676000},"page":"124","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["A Simhash-Based Integrative Features Extraction Algorithm for Malware Detection"],"prefix":"10.3390","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0694-0277","authenticated-orcid":false,"given":"Yihong","family":"Li","sequence":"first","affiliation":[{"name":"Electronic Countermeasures College, National University of Defense Technology, Hefei 230031, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangzheng","family":"Liu","sequence":"additional","affiliation":[{"name":"Electronic Countermeasures College, National University of Defense Technology, Hefei 230031, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhenyu","family":"Du","sequence":"additional","affiliation":[{"name":"Electronic Countermeasures College, National University of Defense Technology, Hefei 230031, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dubing","family":"Zhang","sequence":"additional","affiliation":[{"name":"78092 troop of the PLA, Chengdu 610031, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2018,8,14]]},"reference":[{"key":"ref_1","unstructured":"Sikorski, M., and Honig, A. (2012). Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software, No Starch Press."},{"key":"ref_2","first-page":"1","article-title":"Software and Cyber Security-A Survey","volume":"29","author":"Liu","year":"2018","journal-title":"Chin. J. Softw."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Shalaginov, A., and Franke, K. (2016, January 12\u201314). Automated intelligent multinomial classification of malware species using dynamic behavioural analysis. Proceedings of the 14th Annual Conference on Privacy, Security and Trust (PST), Auckland, New Zealand.","DOI":"10.1109\/PST.2016.7906939"},{"key":"ref_4","first-page":"291","article-title":"Risk Prediction of Malicious Code-Infected Websites by Mining Vulnerability Features","volume":"8","author":"Lee","year":"2014","journal-title":"Int. J. Secur. Appl."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Rajsingh, E., Veerasamy, J., Alavi, A., and Peter, J. (2018). Advances in Big Data and Cloud Computing, Springer. Advances in Intelligent Systems and Computing In Static and Dynamic Analysis for Android Malware Detection.","DOI":"10.1007\/978-981-10-7200-0"},{"key":"ref_6","first-page":"1","article-title":"Detecting and classifying android malware using static analysis along with creator information","volume":"7","author":"Kang","year":"2015","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"439","DOI":"10.1007\/s10207-014-0233-1","article-title":"A defense framework against malware and vulnerability exploits","volume":"13","author":"Zhang","year":"2014","journal-title":"Int. J. Inf. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"48","DOI":"10.5815\/ijmecs.2017.03.06","article-title":"Dynamic Malware Analysis and Detection in Virtual Environment","volume":"9","author":"Sujyothi","year":"2017","journal-title":"Int. J. Mod. Educ. Comput. Sci."},{"key":"ref_9","first-page":"1120","article-title":"Analytical method of high dimensional feature fusion for malicious classification","volume":"34","author":"Cui","year":"2017","journal-title":"Appl. Res. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"646","DOI":"10.1016\/j.jnca.2012.10.004","article-title":"Classification of malware based on integrated static and dynamic features","volume":"36","author":"Islam","year":"2013","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_11","first-page":"15","article-title":"A malware behavior detection system of android applications based on multi-class features","volume":"1","author":"Yang","year":"2014","journal-title":"Chin. J. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1129","DOI":"10.1109\/TMI.2014.2305394","article-title":"Image-based quantitative analysis of gold immunochromatographic strip via cellular neural network approach","volume":"33","author":"Zeng","year":"2014","journal-title":"IEEE Trans. Med. Imaging"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"333","DOI":"10.1109\/TASE.2014.2348555","article-title":"An Incremental-and-static-combined schemefor matrix-factorization-based collaborative filtering","volume":"13","author":"Luo","year":"2016","journal-title":"IEEE Trans. Autom. Sci. Eng."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"657","DOI":"10.1016\/j.procs.2016.03.084","article-title":"Trust-based voting method for efficient malware detection","volume":"79","author":"More","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Ni, S., Qian, Q., and Zhang, R. (2018). Malware identification using visualization images and deep learning. Comput. Secur.","DOI":"10.1016\/j.cose.2018.04.005"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Idrees, F., and Rajarajan, M. (2014, January 8\u201310). Investigating the android intents and permissions for malware detection. Proceedings of the 2014 IEEE 10th International Conference on Wireless and Mobile Computing, Networking and Communications, Larnaca, Cyprus.","DOI":"10.1109\/WiMOB.2014.6962194"},{"key":"ref_17","unstructured":"Rosmansyah, Y., and Dabarsyah, B. (2015, January 10\u201311). Malware detection on android smartphones using API class and machine learning. Proceedings of the 2015 International Conference on Electrical Engineering and Informatics, Denpasar, Indonesia."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1370","DOI":"10.1016\/j.neucom.2014.08.060","article-title":"Dynamical analysis and optimal control for a malware propagation model in an information network","volume":"149","author":"Zhu","year":"2015","journal-title":"Neurocomputing"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Wei, T., Mao, C., Jeng, A.B., Lee, H., Wang, H., and Wu, D. (2012, January 25\u201327). Android Malware Detection via a Latent Network Behavior Analysis. Proceedings of the 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications, Liverpool, UK.","DOI":"10.1109\/TrustCom.2012.91"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Shibahara, T., Yagi, T., Akiyama, M., Chiba, D., and Yada, T. (2016, January 4\u20138). Efficient Dynamic Malware Analysis Based on Network Behavior Using Deep Learning. Proceedings of the 2016 IEEE Global Communications Conference, Washington, DC, USA.","DOI":"10.1109\/GLOCOM.2016.7841778"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"638","DOI":"10.1016\/j.neucom.2017.07.030","article-title":"Droiddet: Effective and robust detection of android malware using static analysis along with rotation forest model","volume":"272","author":"Zhu","year":"2017","journal-title":"Neurocomputing"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Bai, L., Pang, J., Zhang, Y., Fu, W., and Zhu, J. (2009, January 26\u201328). Detecting Malicious Behavior Using Critical API-Calling Graph Matching. Proceedings of the First International Conference on Information Science & Engineering, Nanjing, China.","DOI":"10.1109\/ICISE.2009.494"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1002\/cpe.4172","article-title":"Detection of malicious behavior in android apps through API calls and permission uses analysis","volume":"29","author":"Yang","year":"2017","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_24","unstructured":"Duan, X. (2016). Research on the Malware Detection Based on Windows API Call Behavior. [Ph.D. Thesis, Southwest Jiaotong University]."},{"key":"ref_25","unstructured":"Alazab, M., Venkatraman, S., Watters, P., and Alazab, M. (2011, January 1\u20132). Zero-day Malware Detection based on Supervised Learning Algorithms of API call Signatures. Proceedings of the Ninth Australasian Data Mining Conference, Ballarat, Australia."},{"key":"ref_26","unstructured":"(2018, January 13). Automated Malware Analysis: Cuckoo Sandbox. Available online: http:\/\/docs.cuc-koosandbox.org."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Manku, G.S., Jain, A., and Sarma, A.D. (2007, January 8\u201312). Detecting near-duplicates for web crawling. Proceedings of the 16th International Conference on World Wide Web, Banff, AB, Canada.","DOI":"10.1145\/1242572.1242592"},{"key":"ref_28","unstructured":"Feng, B. (2013). Malware Detection Techniques Based on Data Mining and Machine Learning. [Master Thesis, Central South University]."},{"key":"ref_29","unstructured":"(2018, July 27). Naive Bayes Classifier. Available online: https:\/\/en.wikipedia.org\/wiki\/Naive_Bayes_classifier."},{"key":"ref_30","unstructured":"Song, M., Montanari, A., and Nguyen, P. (2018). A mean field view of the landscape of two-layers neural networks."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"273","DOI":"10.1007\/BF00994018","article-title":"Support-vector networks","volume":"20","author":"Cortes","year":"1995","journal-title":"Mach. Learn."},{"key":"ref_32","unstructured":"(2018, July 27). AdaBoost. Available online: https:\/\/en.wikipedia.org\/wiki\/AdaBoost."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"832","DOI":"10.1109\/34.709601","article-title":"The random subspace method for constructing decision forests","volume":"20","author":"Ho","year":"1998","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/11\/8\/124\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T15:18:41Z","timestamp":1760195921000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/11\/8\/124"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8,14]]},"references-count":33,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2018,8]]}},"alternative-id":["a11080124"],"URL":"https:\/\/doi.org\/10.3390\/a11080124","relation":{},"ISSN":["1999-4893"],"issn-type":[{"type":"electronic","value":"1999-4893"}],"subject":[],"published":{"date-parts":[[2018,8,14]]}}}