{"id":"https://openalex.org/W1581009051","doi":"https://doi.org/10.1007/978-3-540-70542-0_6","title":"Learning and Classification of Malware Behavior","display_name":"Learning and Classification of Malware Behavior","publication_year":2008,"publication_date":"2008-08-12","ids":{"openalex":"https://openalex.org/W1581009051","doi":"https://doi.org/10.1007/978-3-540-70542-0_6","mag":"1581009051"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-540-70542-0_6","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-540-70542-0_6","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.17877/de290r-2041","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066077721","display_name":"Konrad Rieck","orcid":"https://orcid.org/0000-0002-5054-8758"},"institutions":[{"id":"https://openalex.org/I4923324","display_name":"Fraunhofer-Gesellschaft","ror":"https://ror.org/05hkkdn48","country_code":"DE","type":"government","lineage":["https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Konrad Rieck","raw_affiliation_strings":["Intelligent Data Analysis Department, Fraunhofer Institute FIRST, Berlin, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Intelligent Data Analysis Department, Fraunhofer Institute FIRST, Berlin, Germany","institution_ids":["https://openalex.org/I4923324"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056790702","display_name":"Thorsten Holz","orcid":"https://orcid.org/0000-0002-2783-1264"},"institutions":[{"id":"https://openalex.org/I177802217","display_name":"University of Mannheim","ror":"https://ror.org/031bsb921","country_code":"DE","type":"education","lineage":["https://openalex.org/I177802217"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Thorsten Holz","raw_affiliation_strings":["Laboratory for Dependable Distributed Systems, University of Mannheim, Mannheim, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Laboratory for Dependable Distributed Systems, University of Mannheim, Mannheim, Germany","institution_ids":["https://openalex.org/I177802217"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077167083","display_name":"Carsten Willems","orcid":null},"institutions":[{"id":"https://openalex.org/I177802217","display_name":"University of Mannheim","ror":"https://ror.org/031bsb921","country_code":"DE","type":"education","lineage":["https://openalex.org/I177802217"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Carsten Willems","raw_affiliation_strings":["Laboratory for Dependable Distributed Systems, University of Mannheim, Mannheim, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Laboratory for Dependable Distributed Systems, University of Mannheim, Mannheim, Germany","institution_ids":["https://openalex.org/I177802217"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087841637","display_name":"Patrick D\u00fcssel","orcid":null},"institutions":[{"id":"https://openalex.org/I4923324","display_name":"Fraunhofer-Gesellschaft","ror":"https://ror.org/05hkkdn48","country_code":"DE","type":"government","lineage":["https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Patrick D\u00fcssel","raw_affiliation_strings":["Intelligent Data Analysis Department, Fraunhofer Institute FIRST, Berlin, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Intelligent Data Analysis Department, Fraunhofer Institute FIRST, Berlin, Germany","institution_ids":["https://openalex.org/I4923324"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5089735573","display_name":"Pavel Laskov","orcid":"https://orcid.org/0000-0002-3212-7167"},"institutions":[{"id":"https://openalex.org/I4923324","display_name":"Fraunhofer-Gesellschaft","ror":"https://ror.org/05hkkdn48","country_code":"DE","type":"government","lineage":["https://openalex.org/I4923324"]},{"id":"https://openalex.org/I8087733","display_name":"University of T\u00fcbingen","ror":"https://ror.org/03a1kwz48","country_code":"DE","type":"education","lineage":["https://openalex.org/I8087733"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Pavel Laskov","raw_affiliation_strings":["Intelligent Data Analysis Department, Fraunhofer Institute FIRST, Berlin, Germany","Wilhelm-Schickard-Institute for Computer Science, University of T\u00fcbingen, T\u00fcbingen, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Intelligent Data Analysis Department, Fraunhofer Institute FIRST, Berlin, Germany","institution_ids":["https://openalex.org/I4923324"]},{"raw_affiliation_string":"Wilhelm-Schickard-Institute for Computer Science, University of T\u00fcbingen, T\u00fcbingen, Germany","institution_ids":["https://openalex.org/I8087733"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":null,"fwci":35.8082,"has_fulltext":false,"cited_by_count":582,"citation_normalized_percentile":{"value":0.99869792,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"108","last_page":"125"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9641345143318176},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8190557360649109},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.651400089263916},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5642982721328735},{"id":"https://openalex.org/keywords/honeypot","display_name":"Honeypot","score":0.5638928413391113},{"id":"https://openalex.org/keywords/discriminative-model","display_name":"Discriminative model","score":0.5475356578826904},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5435322523117065},{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.5243992209434509},{"id":"https://openalex.org/keywords/sandbox","display_name":"Sandbox (software development)","score":0.4950369894504547},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.476267546415329},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.4491526782512665},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4414232671260834},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3774828612804413}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9641345143318176},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8190557360649109},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.651400089263916},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5642982721328735},{"id":"https://openalex.org/C191267431","wikidata":"https://www.wikidata.org/wiki/Q911932","display_name":"Honeypot","level":2,"score":0.5638928413391113},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.5475356578826904},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5435322523117065},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.5243992209434509},{"id":"https://openalex.org/C167981075","wikidata":"https://www.wikidata.org/wiki/Q2667186","display_name":"Sandbox (software development)","level":2,"score":0.4950369894504547},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.476267546415329},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.4491526782512665},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4414232671260834},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3774828612804413},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.0}],"mesh":[],"locations_count":8,"locations":[{"id":"doi:10.1007/978-3-540-70542-0_6","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-540-70542-0_6","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.194.552","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.194.552","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www-rsec.cs.uni-tuebingen.de/laskov/papers/dimva2008.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.210.1419","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.210.1419","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://pi1.informatik.uni-mannheim.de/filepool/publications/malware-classification-dimva08.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.412.4057","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.412.4057","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://eprints.pascal-network.org/archive/00004171/01/2008-dimva.pdf","raw_type":"text"},{"id":"pmh:oai:eldorado.tu-dortmund.de:2003/26281","is_oa":false,"landing_page_url":"http://hdl.handle.net/2003/26281","pdf_url":null,"source":{"id":"https://openalex.org/S4306400811","display_name":"Technische Universit\u00e4t Dortmund Eldorado (Technische Universit\u00e4t Dortmund)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210148506","host_organization_name":"Erich-Brost-Institut","host_organization_lineage":["https://openalex.org/I4210148506"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"doc-type:Text"},{"id":"pmh:oai:fraunhofer.de:N-107414","is_oa":false,"landing_page_url":"http://publica.fraunhofer.de/documents/N-107414.html","pdf_url":null,"source":{"id":"https://openalex.org/S4306400801","display_name":"Publikationsdatenbank der Fraunhofer-Gesellschaft (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Fraunhofer FIRST","raw_type":"Conference Paper"},{"id":"pmh:oai:publica.fraunhofer.de:publica/360555","is_oa":false,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/360555","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"},{"id":"doi:10.17877/de290r-2041","is_oa":true,"landing_page_url":"https://doi.org/10.17877/de290r-2041","pdf_url":null,"source":{"id":"https://openalex.org/S4306400811","display_name":"Technische Universit\u00e4t Dortmund Eldorado (Technische Universit\u00e4t Dortmund)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210148506","host_organization_name":"Erich-Brost-Institut","host_organization_lineage":["https://openalex.org/I4210148506"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article-journal"}],"best_oa_location":{"id":"doi:10.17877/de290r-2041","is_oa":true,"landing_page_url":"https://doi.org/10.17877/de290r-2041","pdf_url":null,"source":{"id":"https://openalex.org/S4306400811","display_name":"Technische Universit\u00e4t Dortmund Eldorado (Technische Universit\u00e4t Dortmund)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210148506","host_organization_name":"Erich-Brost-Institut","host_organization_lineage":["https://openalex.org/I4210148506"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article-journal"},"sustainable_development_goals":[{"score":0.6000000238418579,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W198543417","https://openalex.org/W1503224444","https://openalex.org/W1510073064","https://openalex.org/W1529311848","https://openalex.org/W1540550673","https://openalex.org/W1544837488","https://openalex.org/W1549656520","https://openalex.org/W1552906779","https://openalex.org/W1586396059","https://openalex.org/W1595564425","https://openalex.org/W1604459715","https://openalex.org/W1604792744","https://openalex.org/W1618905105","https://openalex.org/W1873122431","https://openalex.org/W1921075642","https://openalex.org/W2014589236","https://openalex.org/W2097101478","https://openalex.org/W2100673955","https://openalex.org/W2111038628","https://openalex.org/W2117030266","https://openalex.org/W2121749752","https://openalex.org/W2131523719","https://openalex.org/W2132874238","https://openalex.org/W2135143063","https://openalex.org/W2138644293","https://openalex.org/W2139212933","https://openalex.org/W2145056020","https://openalex.org/W2146211060","https://openalex.org/W2148603752","https://openalex.org/W2149684865","https://openalex.org/W2150795982","https://openalex.org/W2151135920","https://openalex.org/W2154462399","https://openalex.org/W2154933195","https://openalex.org/W2165612380","https://openalex.org/W2167671111","https://openalex.org/W2911640577","https://openalex.org/W2914982603","https://openalex.org/W3023786531","https://openalex.org/W3193477162"],"related_works":["https://openalex.org/W2789663798","https://openalex.org/W2375896275","https://openalex.org/W4230913293","https://openalex.org/W2166943775","https://openalex.org/W2775236000","https://openalex.org/W2073762068","https://openalex.org/W2151915331","https://openalex.org/W2034129977","https://openalex.org/W1745773915","https://openalex.org/W2765820957"],"abstract_inverted_index":null,"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":8},{"year":2024,"cited_by_count":17},{"year":2023,"cited_by_count":21},{"year":2022,"cited_by_count":30},{"year":2021,"cited_by_count":50},{"year":2020,"cited_by_count":36},{"year":2019,"cited_by_count":49},{"year":2018,"cited_by_count":47},{"year":2017,"cited_by_count":42},{"year":2016,"cited_by_count":43},{"year":2015,"cited_by_count":49},{"year":2014,"cited_by_count":45},{"year":2013,"cited_by_count":42},{"year":2012,"cited_by_count":21}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
