{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:03:00Z","timestamp":1781107380402,"version":"3.54.1"},"reference-count":31,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,4]]},"abstract":"<jats:p>This paper describes a research effort to use executable slicing as a pre-processing aid to improve the prediction performance of rogue software detection. The prediction technique used here is an information retrieval classifier known as cosine similarity that can be used to detect previously unknown, known or variances of known rogue software by applying the feature extraction technique of randomized projection. This paper provides direction in answering the question of is it possible to only use portions or subsets, known as slices, of an application to make a prediction on whether or not the software contents are rogue. This research extracts sections or slices from potentially rogue applications and uses these slices instead of the entire application to make a prediction. Results show promise when applying randomized projections to cosine similarity for the predictions, with as much as a 4% increase in prediction performance and a five-fold decrease in processing time when compared to using the entire application.<\/jats:p>","DOI":"10.4018\/jsse.2011040103","type":"journal-article","created":{"date-parts":[[2011,10,19]],"date-time":"2011-10-19T12:46:17Z","timestamp":1319028377000},"page":"53-64","source":"Crossref","is-referenced-by-count":2,"title":["Using Executable Slicing to Improve Rogue Software Detection Algorithms"],"prefix":"10.4018","volume":"2","author":[{"given":"Jan","family":"Durand","sequence":"first","affiliation":[{"name":"Louisiana Tech University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Juan","family":"Flores","sequence":"additional","affiliation":[{"name":"Louisiana Tech University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Travis","family":"Atkison","sequence":"additional","affiliation":[{"name":"Louisiana Tech University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nicholas","family":"Kraft","sequence":"additional","affiliation":[{"name":"University of Alabama, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Randy","family":"Smith","sequence":"additional","affiliation":[{"name":"University of Alabama, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2011040103-0","doi-asserted-by":"crossref","unstructured":"Abou-Assaleh, T., Cercone, N., Keselj, V., & Sweidan, R. (2004a). Detection of new malicious code using n-grams signatures. In Proceedings of the 2nd Annual Conference on Privacy, Security and Trust, New Brunswick, Canada (pp. 193-196).","DOI":"10.1109\/CMPSAC.2004.1342667"},{"key":"jsse.2011040103-1","doi-asserted-by":"crossref","unstructured":"Abou-Assaleh, T., Cercone, N., Keselj, V., & Sweidan, R. (2004b). N-gram-based detection of new malicious code. In Proceedings of the 28th Annual International Computer Software and Applications Conference (pp. 41-42).","DOI":"10.1109\/CMPSAC.2004.1342667"},{"key":"jsse.2011040103-2","doi-asserted-by":"crossref","unstructured":"Atkison, T. (2009). Applying randomized projection to aid prediction algorithms in detecting high-dimensional rogue applications. In Proceedings of the 47th ACM Southeast Conference, Clemson, SC (p. 23).","DOI":"10.1145\/1566445.1566477"},{"key":"jsse.2011040103-3","author":"R.Baeza-Yates","year":"1999","journal-title":"Modern information retrieval"},{"key":"jsse.2011040103-4","unstructured":"Bergeron, J., Debbabi, M., Desharnais, J., Erhioui, M. M., Lavoie, Y., Tawbi, N., et al. (2001). Static detection of malicious code in executable programs. In Proceedings of the Symposium on Requirements Engineering for Information Security (pp. 184-189)."},{"key":"jsse.2011040103-5","doi-asserted-by":"crossref","unstructured":"Bergeron, J., Debbabi, M., Erhioui, M. M., & Ktari, B. (1999). Static analysis of binary code to isolate malicious behaviors. In Proceedings of the IEEE 8th International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (pp. 184-189).","DOI":"10.1109\/ENABL.1999.805197"},{"key":"jsse.2011040103-6","doi-asserted-by":"crossref","unstructured":"Bingham, E., & Mannila, H. (2001). Random projection in dimensionality reduction: Applications to image and text data. In Proceedings of the 7th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 245-250).","DOI":"10.1145\/502512.502546"},{"key":"jsse.2011040103-7","unstructured":"Christodorescu, M., & Jha, S. (2003). Static analysis of executables to detect malicious patterns. In Proceedings of the 12th Conference on USENIX Security Symposium (p. 12)."},{"key":"jsse.2011040103-8","author":"S.Dasgupta","year":"1999","journal-title":"An elementary proof of the Johnson-Lindenstrauss Lemma"},{"key":"jsse.2011040103-9","unstructured":"Food and Drug Administration. (2010). Infusion pump software safety research at FDA. Retrieved from http:\/\/www.fda.gov\/MedicalDevices\/ProductsandMedicalProcedures\/GeneralHospitalDevicesandSupplies\/InfusionPumps\/ucm202511.htm"},{"key":"jsse.2011040103-10","unstructured":"Haventools Software. (2009). Heaventools: PE Explorer. Retrieved from http:\/\/www.heaventools.net"},{"key":"jsse.2011040103-11","doi-asserted-by":"crossref","unstructured":"Henchiri, O., & Japkowicz, N. (2006). A feature selection and evaluation scheme for computer virus detection. In Proceedings of the 6th International Conference on Data Mining (pp. 891-895).","DOI":"10.1109\/ICDM.2006.4"},{"key":"jsse.2011040103-12","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1090\/conm\/026\/737400","article-title":"Extensions of Lipschitz mappings into a Hilbert space.","volume":"26","author":"W. B.Johnson","year":"1984","journal-title":"Contemporary Mathematics"},{"key":"jsse.2011040103-13","unstructured":"Jovanovic, N., Kruegel, C., & Kirda, E. (2006). Pixy: A static analysis tool for extracting web application vulnerabilities. In Proceedings of the IEEE Symposium on Security and Privacy (pp. 258-263)."},{"key":"jsse.2011040103-14","doi-asserted-by":"crossref","unstructured":"Kang, M. G., Poosankam, P., & Yin, H. (2007). Renovo: A hidden code extractor for packed executables. In Proceedings of the ACM Workshop on Recurring Malcode.","DOI":"10.1145\/1314389.1314399"},{"key":"jsse.2011040103-15","doi-asserted-by":"crossref","unstructured":"Kaski, S. (1998). Dimensionality reduction by random mapping: Fast similarity computation for clustering. In Proceedings of the IEEE World Congress International Joint Conference on Neural Networks and Computational Intelligence (pp. 413-418).","DOI":"10.1109\/IJCNN.1998.682302"},{"key":"jsse.2011040103-16","unstructured":"Kephart, J. O., Sorkin, G. B., Arnold, W. C., Chess, D. M., Tesauro, G. J., & White, S. R. (1995). Biologically inspired defenses against computer viruses. In Proceedings of the 14th International Joint Conference on Artificial Intelligence, San Francisco, CA (pp. 985-996)."},{"key":"jsse.2011040103-17","doi-asserted-by":"crossref","unstructured":"Kurimo, M. (1999). Indexing audio documents by using latent semantic analysis and SOM. Kohonen Maps, 363-374.","DOI":"10.1016\/B978-044450270-4\/50029-2"},{"key":"jsse.2011040103-18","unstructured":"Lin, J., & Gunopulos, D. (2003, May). Dimensionality reduction by random projection and latent semantic indexing. In Proceedings of the Text Mining Workshop at the 3rd SIAM International Conference on Data Mining."},{"key":"jsse.2011040103-19","doi-asserted-by":"crossref","unstructured":"Liu, N., Zhang, B., Yan, J., Yang, Q., Yan, S., Chen, Z., et al. (2004). Learning similarity measures in non-orthogonal space. In Proceedings of the Thirteenth ACM International Conference on Information and Knowledge Management (pp. 334-341).","DOI":"10.1145\/1031171.1031240"},{"key":"jsse.2011040103-20","unstructured":"Mannila, H., & Sepp\u00e4nen, J. K. (2001). Finding similar situations in sequences of events. In Proceedings of the 1st SIAM International Conference on Data Mining."},{"key":"jsse.2011040103-21","doi-asserted-by":"crossref","unstructured":"Marceau, C. (2000). Characterizing the behavior of a program using multiple-length n-grams. In Proceedings of the Workshop on New Security Paradigms (pp. 101-110).","DOI":"10.1145\/366173.366197"},{"key":"jsse.2011040103-22","doi-asserted-by":"publisher","DOI":"10.1109\/52.877857"},{"key":"jsse.2011040103-23","doi-asserted-by":"publisher","DOI":"10.1006\/jcss.2000.1711"},{"key":"jsse.2011040103-24","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2008.06.016"},{"key":"jsse.2011040103-25","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0027-8"},{"key":"jsse.2011040103-26","doi-asserted-by":"publisher","DOI":"10.1016\/0306-4573(88)90021-0"},{"key":"jsse.2011040103-27","doi-asserted-by":"publisher","DOI":"10.1145\/361219.361220"},{"key":"jsse.2011040103-28","doi-asserted-by":"crossref","unstructured":"Schultz, M., Eskin, E., Zadok, E., & Stolfo, S. (2001). Data mining methods for detection of new malicious executables. In Proceedings of the IEEE Symposium on Security and Privacy (pp. 38-49).","DOI":"10.1109\/SECPRI.2001.924286"},{"issue":"4","key":"jsse.2011040103-29","first-page":"35","article-title":"Modern information retrieval: A brief overview.","volume":"24","author":"A.Singhal","year":"2001","journal-title":"A Quarterly Bulletin of the Computer Society of the IEEE Technical Committee on Data Engineering"},{"key":"jsse.2011040103-30","author":"S. S.Vempala","year":"2004","journal-title":"The random projection method"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=55269","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,11]],"date-time":"2021-12-11T16:48:36Z","timestamp":1639241316000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2011040103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2011,4]]},"references-count":31,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2011040103","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,4]]}}}