{"id":"https://openalex.org/W7117363894","doi":"https://doi.org/10.1007/s10791-025-09842-5","title":"Detecting malware evidences through static and dynamic information using extreme machine learning for forensic analysis","display_name":"Detecting malware evidences through static and dynamic information using extreme machine learning for forensic analysis","publication_year":2025,"publication_date":"2025-12-27","ids":{"openalex":"https://openalex.org/W7117363894","doi":"https://doi.org/10.1007/s10791-025-09842-5"},"language":"en","primary_location":{"id":"doi:10.1007/s10791-025-09842-5","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10791-025-09842-5","pdf_url":"https://link.springer.com/content/pdf/10.1007/s10791-025-09842-5.pdf","source":{"id":"https://openalex.org/S5407036663","display_name":"Discover Computing","issn_l":"2948-2992","issn":["2948-2992"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Discover Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://link.springer.com/content/pdf/10.1007/s10791-025-09842-5.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5028236063","display_name":"Rijvan Beg","orcid":"https://orcid.org/0009-0008-6895-3576"},"institutions":[{"id":"https://openalex.org/I91277730","display_name":"Maulana Azad National Institute of Technology","ror":"https://ror.org/026vtd268","country_code":"IN","type":"education","lineage":["https://openalex.org/I91277730"]}],"countries":["IN"],"is_corresponding":true,"raw_author_name":"Rijvan Beg","raw_affiliation_strings":["Computer Science & Engineering Department, Maulana Azad National Institute of Technology, Bhopal, Madhya Pradesh, 462003, India"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Computer Science & Engineering Department, Maulana Azad National Institute of Technology, Bhopal, Madhya Pradesh, 462003, India","institution_ids":["https://openalex.org/I91277730"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5121369117","display_name":"R. K. Pateriya","orcid":null},"institutions":[{"id":"https://openalex.org/I91277730","display_name":"Maulana Azad National Institute of Technology","ror":"https://ror.org/026vtd268","country_code":"IN","type":"education","lineage":["https://openalex.org/I91277730"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"R. K. Pateriya","raw_affiliation_strings":["Computer Science & Engineering Department, Maulana Azad National Institute of Technology, Bhopal, Madhya Pradesh, 462003, India"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Computer Science & Engineering Department, Maulana Azad National Institute of Technology, Bhopal, Madhya Pradesh, 462003, India","institution_ids":["https://openalex.org/I91277730"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074527311","display_name":"Deepak Singh Tomar","orcid":"https://orcid.org/0000-0001-9025-1679"},"institutions":[{"id":"https://openalex.org/I91277730","display_name":"Maulana Azad National Institute of Technology","ror":"https://ror.org/026vtd268","country_code":"IN","type":"education","lineage":["https://openalex.org/I91277730"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Deepak Singh Tomar","raw_affiliation_strings":["Computer Science & Engineering Department, Maulana Azad National Institute of Technology, Bhopal, Madhya Pradesh, 462003, India"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Computer Science & Engineering Department, Maulana Azad National Institute of Technology, Bhopal, Madhya Pradesh, 462003, India","institution_ids":["https://openalex.org/I91277730"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5044287222","display_name":"Surendra Solanki","orcid":"https://orcid.org/0000-0002-5067-7621"},"institutions":[{"id":"https://openalex.org/I73779912","display_name":"Manipal University Jaipur","ror":"https://ror.org/040h76494","country_code":null,"type":"education","lineage":["https://openalex.org/I73779912"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Surendra Solanki","raw_affiliation_strings":["Department of Artificial Intelligence and Machine Learning, Manipal University Jaipur, Jaipur, Rajasthan, India"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Artificial Intelligence and Machine Learning, Manipal University Jaipur, Jaipur, Rajasthan, India","institution_ids":["https://openalex.org/I73779912"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5028236063"],"corresponding_institution_ids":["https://openalex.org/I91277730"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.61540425,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"28","issue":"1","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.8411999940872192,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.8411999940872192,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.09740000218153,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.018699999898672104,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8277999758720398},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.6159999966621399},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.5493999719619751},{"id":"https://openalex.org/keywords/extreme-learning-machine","display_name":"Extreme learning machine","score":0.5005000233650208},{"id":"https://openalex.org/keywords/static-analysis","display_name":"Static analysis","score":0.46209999918937683},{"id":"https://openalex.org/keywords/computer-forensics","display_name":"Computer forensics","score":0.46000000834465027},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.44620001316070557},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.44200000166893005},{"id":"https://openalex.org/keywords/support-vector-machine","display_name":"Support vector machine","score":0.44190001487731934}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8277999758720398},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8083000183105469},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.6159999966621399},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6080999970436096},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.5493999719619751},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.538100004196167},{"id":"https://openalex.org/C2780150128","wikidata":"https://www.wikidata.org/wiki/Q21948731","display_name":"Extreme learning machine","level":3,"score":0.5005000233650208},{"id":"https://openalex.org/C97686452","wikidata":"https://www.wikidata.org/wiki/Q7604153","display_name":"Static analysis","level":2,"score":0.46209999918937683},{"id":"https://openalex.org/C556601545","wikidata":"https://www.wikidata.org/wiki/Q878553","display_name":"Computer forensics","level":3,"score":0.46000000834465027},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.44620001316070557},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.44200000166893005},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.44190001487731934},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.4138999879360199},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.4124000072479248},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.398499995470047},{"id":"https://openalex.org/C2781357168","wikidata":"https://www.wikidata.org/wiki/Q5276084","display_name":"Digital evidence","level":3,"score":0.39089998602867126},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.3783999979496002},{"id":"https://openalex.org/C83665646","wikidata":"https://www.wikidata.org/wiki/Q42139305","display_name":"Feature vector","level":2,"score":0.3743000030517578},{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.3481999933719635},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.3476000130176544},{"id":"https://openalex.org/C27438332","wikidata":"https://www.wikidata.org/wiki/Q2873","display_name":"Principal component analysis","level":2,"score":0.32749998569488525},{"id":"https://openalex.org/C111030470","wikidata":"https://www.wikidata.org/wiki/Q1430460","display_name":"Curse of dimensionality","level":2,"score":0.3237999975681305},{"id":"https://openalex.org/C519991488","wikidata":"https://www.wikidata.org/wiki/Q28865","display_name":"Python (programming language)","level":2,"score":0.3059999942779541},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.2964000105857849},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.2955999970436096},{"id":"https://openalex.org/C34736171","wikidata":"https://www.wikidata.org/wiki/Q918333","display_name":"Preprocessor","level":2,"score":0.27630001306533813},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.26829999685287476},{"id":"https://openalex.org/C2777667771","wikidata":"https://www.wikidata.org/wiki/Q926331","display_name":"Ransomware","level":3,"score":0.2667999863624573},{"id":"https://openalex.org/C51929080","wikidata":"https://www.wikidata.org/wiki/Q2425187","display_name":"Codebase","level":3,"score":0.26269999146461487},{"id":"https://openalex.org/C2780945871","wikidata":"https://www.wikidata.org/wiki/Q194274","display_name":"Backup","level":2,"score":0.25360000133514404}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/s10791-025-09842-5","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10791-025-09842-5","pdf_url":"https://link.springer.com/content/pdf/10.1007/s10791-025-09842-5.pdf","source":{"id":"https://openalex.org/S5407036663","display_name":"Discover Computing","issn_l":"2948-2992","issn":["2948-2992"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Discover Computing","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:6fad95766dbd4c0e9c2fb141eeb779a6","is_oa":true,"landing_page_url":"https://doaj.org/article/6fad95766dbd4c0e9c2fb141eeb779a6","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Discover Computing, Vol 28, Iss 1, Pp 1-29 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1007/s10791-025-09842-5","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10791-025-09842-5","pdf_url":"https://link.springer.com/content/pdf/10.1007/s10791-025-09842-5.pdf","source":{"id":"https://openalex.org/S5407036663","display_name":"Discover Computing","issn_l":"2948-2992","issn":["2948-2992"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Discover Computing","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7919572591781616}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7117363894.pdf","grobid_xml":"https://content.openalex.org/works/W7117363894.grobid-xml"},"referenced_works_count":42,"referenced_works":["https://openalex.org/W1497716074","https://openalex.org/W1977236908","https://openalex.org/W1986896180","https://openalex.org/W2050704454","https://openalex.org/W2065311994","https://openalex.org/W2085540759","https://openalex.org/W2086200747","https://openalex.org/W2111072639","https://openalex.org/W2117030266","https://openalex.org/W2132874238","https://openalex.org/W2136189313","https://openalex.org/W2141087758","https://openalex.org/W2150795982","https://openalex.org/W2154933195","https://openalex.org/W2167671111","https://openalex.org/W2215444025","https://openalex.org/W2574215789","https://openalex.org/W2599823825","https://openalex.org/W2608570228","https://openalex.org/W2650222044","https://openalex.org/W2783390333","https://openalex.org/W2789580363","https://openalex.org/W2800695847","https://openalex.org/W2801996842","https://openalex.org/W2849301851","https://openalex.org/W2887670066","https://openalex.org/W2888897661","https://openalex.org/W2910657275","https://openalex.org/W2947447457","https://openalex.org/W3006140559","https://openalex.org/W3015737415","https://openalex.org/W3037015170","https://openalex.org/W3085659883","https://openalex.org/W3120554811","https://openalex.org/W3164621419","https://openalex.org/W3167683049","https://openalex.org/W4212997118","https://openalex.org/W4282550951","https://openalex.org/W4313307688","https://openalex.org/W4388692993","https://openalex.org/W4406261718","https://openalex.org/W4411887449"],"related_works":[],"abstract_inverted_index":{"Malware":[0,21],"forensics":[1,7],"is":[2,9,22,31,130,155,194,275],"a":[3,15,19,143,148,174,225,244,259,298,340],"field":[4],"in":[5,142,173,224],"digital":[6],"that":[8,52,327],"dedicated":[10],"to":[11,33,101,124,146,157,196,212,231,256],"collecting":[12],"evidence":[13,100],"of":[14,62,83,92,105,121,200,227,262,271,294],"malware":[16,44,94,110,123,139,249],"attack":[17],"on":[18,37],"system.":[20],"also":[23,45,321],"executable":[24],"code,":[25],"but":[26],"unlike":[27],"regular":[28],"executables,":[29],"it":[30,243],"designed":[32],"perform":[34],"unauthorized":[35],"actions":[36],"victim":[38],"computers.":[39],"Being":[40],"an":[41,106],"executable,":[42],"the":[43,63,90,93,103,116,122,133,138,159,163,184,188,198,201,214,228,232,253,272,292,295,328,345],"performs":[46],"designated":[47],"tasks":[48],"through":[49],"several":[50],"processes":[51],"can":[53,86,96,221],"leave":[54],"its":[55,126],"traces":[56,85],"(digital":[57],"footprints)":[58],"throughout":[59],"different":[60],"components":[61],"operating":[64],"system,":[65],"such":[66],"as":[67,99],"registries,":[68],"file":[69],"systems,":[70],"DLL":[71],"calls,":[72,74],"API":[73],"memory":[75],"usage,":[76],"CPU":[77],"utilization,":[78],"network":[79],"traffic,":[80],"etc.":[81],"Some":[82],"these":[84],"exist":[87],"even":[88],"after":[89],"removal":[91],"and":[95,118,177,264,287,318,339],"be":[97,222],"used":[98,156,211],"verify":[102],"occurrence":[104],"attack.":[107],"The":[108,152,204,219,269,323],"proposed":[109,273,296,329],"forensic":[111,250],"analysis":[112,150,166,191],"technique":[113,330],"combines":[114],"both":[115,170],"static":[117],"dynamic":[119],"features":[120,161,171],"trace":[125],"evidence.":[127],"This":[128,241],"information":[129],"collected":[131],"using":[132,277],"Cuckoo":[134],"sandbox,":[135],"which":[136,181],"executes":[137],"sample":[140],"files":[141],"virtual":[144],"environment":[145],"generate":[147],"JSON-formatted":[149],"report.":[151,167],"Python":[153],"script":[154],"extract":[158],"non-volatile":[160],"from":[162],"JSON":[164],"format":[165],"However,":[168],"combining":[169],"results":[172,325],"very":[175],"long":[176],"sparse":[178],"feature":[179,202,208],"vector,":[180],"negatively":[182],"affects":[183],"classifier\u2019s":[185],"performance.":[186],"Therefore,":[187],"principal":[189],"component":[190],"(PCA)":[192],"algorithm":[193],"adopted":[195],"reduce":[197],"dimensionality":[199,207],"vectors.":[203],"generated":[205],"reduced":[206],"vectors":[209],"are":[210],"train":[213,257],"extreme":[215],"learning":[216],"machine":[217,235],"(ELM).":[218],"ELM":[220],"trained":[223],"fraction":[226],"time":[229],"compared":[230],"support":[233],"vector":[234],"(SVM),":[236,313],"while":[237],"achieving":[238],"similar":[239],"accuracy.":[240],"makes":[242],"favorable":[245],"choice,":[246],"especially":[247],"for":[248],"analysis,":[251],"where":[252],"classifier":[254],"needs":[255],"with":[258,300],"large":[260],"amount":[261],"data":[263],"requires":[265],"quick":[266],"decision-making":[267],"capabilities.":[268],"performance":[270],"techniques":[274],"evaluated":[276],"90":[278],"malicious":[279],"code":[280],"samples":[281],"containing":[282],"41":[283],"Trojans,":[284],"28":[285],"worms,":[286],"21":[288],"bots.":[289],"To":[290],"demonstrate":[291],"superiority":[293],"algorithm,":[297],"comparison":[299,324],"some":[301],"state-of-the-art":[302],"classification":[303],"methods,":[304],"named":[305],"Hidden":[306],"Markov":[307],"Model":[308],"(HMM),":[309],"Support":[310],"Vector":[311],"Machine":[312],"Artificial":[314],"Neural":[315],"Network":[316],"(ANN),":[317],"ELM,":[319],"was":[320],"performed.":[322],"show":[326],"achieves":[331],"approximately":[332],"11%":[333],"higher":[334,337,342],"precision,":[335],"10%":[336],"recall,":[338],"10.5%":[341],"F-score":[343],"than":[344],"competitors.":[346]},"counts_by_year":[],"updated_date":"2026-05-06T08:25:59.206177","created_date":"2025-12-27T00:00:00"}
