{"id":"https://openalex.org/W2775300889","doi":"https://doi.org/10.1109/ccst.2017.8167802","title":"Malware family identification with BIRCH clustering","display_name":"Malware family identification with BIRCH clustering","publication_year":2017,"publication_date":"2017-10-01","ids":{"openalex":"https://openalex.org/W2775300889","doi":"https://doi.org/10.1109/ccst.2017.8167802","mag":"2775300889"},"language":"en","primary_location":{"id":"doi:10.1109/ccst.2017.8167802","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ccst.2017.8167802","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2017 International Carnahan Conference on Security Technology (ICCST)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5065182693","display_name":"Gregorio Pitolli","orcid":null},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Gregorio Pitolli","raw_affiliation_strings":["Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome"],"affiliations":[{"raw_affiliation_string":"Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","institution_ids":["https://openalex.org/I861853513"]},{"raw_affiliation_string":"Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome","institution_ids":["https://openalex.org/I861853513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089567320","display_name":"Leonardo Aniello","orcid":"https://orcid.org/0000-0003-2886-8445"},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Leonardo Aniello","raw_affiliation_strings":["Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome"],"affiliations":[{"raw_affiliation_string":"Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","institution_ids":["https://openalex.org/I861853513"]},{"raw_affiliation_string":"Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome","institution_ids":["https://openalex.org/I861853513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038561286","display_name":"Giuseppe Laurenza","orcid":"https://orcid.org/0000-0002-3763-4598"},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Giuseppe Laurenza","raw_affiliation_strings":["Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome"],"affiliations":[{"raw_affiliation_string":"Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","institution_ids":["https://openalex.org/I861853513"]},{"raw_affiliation_string":"Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome","institution_ids":["https://openalex.org/I861853513"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051841898","display_name":"Leonardo Querzoni","orcid":"https://orcid.org/0000-0002-8711-4216"},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Leonardo Querzoni","raw_affiliation_strings":["Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome"],"affiliations":[{"raw_affiliation_string":"Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","institution_ids":["https://openalex.org/I861853513"]},{"raw_affiliation_string":"Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome","institution_ids":["https://openalex.org/I861853513"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5111427499","display_name":"Roberto Baldoni","orcid":null},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Roberto Baldoni","raw_affiliation_strings":["Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome"],"affiliations":[{"raw_affiliation_string":"Department of Computer and System Sciences \u201cAntonio Ruberti\u201d, \u201cLa Sapienza\u201d University of Rome","institution_ids":["https://openalex.org/I861853513"]},{"raw_affiliation_string":"Department of Computer and System Sciences \"Antonio Ruberti\", \"La Sapienza\" University of Rome","institution_ids":["https://openalex.org/I861853513"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5065182693"],"corresponding_institution_ids":["https://openalex.org/I861853513"],"apc_list":null,"apc_paid":null,"fwci":1.8642,"has_fulltext":false,"cited_by_count":29,"citation_normalized_percentile":{"value":0.87402111,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9807000160217285,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9018899202346802},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7709997892379761},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.7503880858421326},{"id":"https://openalex.org/keywords/identification","display_name":"Identification (biology)","score":0.6138358116149902},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5917955636978149},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5729542374610901},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.5171096324920654},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5107190608978271},{"id":"https://openalex.org/keywords/ground-truth","display_name":"Ground truth","score":0.48663029074668884},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.48192453384399414},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4336516559123993},{"id":"https://openalex.org/keywords/voting","display_name":"Voting","score":0.4238743782043457},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2690666913986206}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9018899202346802},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7709997892379761},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.7503880858421326},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.6138358116149902},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5917955636978149},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5729542374610901},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.5171096324920654},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5107190608978271},{"id":"https://openalex.org/C146849305","wikidata":"https://www.wikidata.org/wiki/Q370766","display_name":"Ground truth","level":2,"score":0.48663029074668884},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.48192453384399414},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4336516559123993},{"id":"https://openalex.org/C520049643","wikidata":"https://www.wikidata.org/wiki/Q189760","display_name":"Voting","level":3,"score":0.4238743782043457},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2690666913986206},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C94625758","wikidata":"https://www.wikidata.org/wiki/Q7163","display_name":"Politics","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/ccst.2017.8167802","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ccst.2017.8167802","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2017 International Carnahan Conference on Security Technology (ICCST)","raw_type":"proceedings-article"},{"id":"pmh:oai:eprints.soton.ac.uk:450669","is_oa":false,"landing_page_url":"https://eprints.soton.ac.uk/450669/","pdf_url":null,"source":{"id":"https://openalex.org/S4306401019","display_name":"ePrints Soton (University of Southampton)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I43439940","host_organization_name":"University of Southampton","host_organization_lineage":["https://openalex.org/I43439940"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Book Section"},{"id":"pmh:oai:iris.uniroma1.it:11573/1016194","is_oa":false,"landing_page_url":"http://hdl.handle.net/11573/1016194","pdf_url":null,"source":{"id":"https://openalex.org/S4377196107","display_name":"IRIS Research product catalog (Sapienza University of Rome)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G3164523449","display_name":null,"funder_award_id":"EP/R007268/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320307791","display_name":"Cisco Systems","ror":"https://ror.org/03yt1ez60"},{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W94487276","https://openalex.org/W152854583","https://openalex.org/W250426404","https://openalex.org/W1673310716","https://openalex.org/W1851403712","https://openalex.org/W1910686388","https://openalex.org/W1987971958","https://openalex.org/W2002830978","https://openalex.org/W2010065958","https://openalex.org/W2018175892","https://openalex.org/W2047888527","https://openalex.org/W2095897464","https://openalex.org/W2127218421","https://openalex.org/W2131687179","https://openalex.org/W2138644293","https://openalex.org/W2142838865","https://openalex.org/W2143365760","https://openalex.org/W2154986869","https://openalex.org/W2289955225","https://openalex.org/W2471986960","https://openalex.org/W2514847810","https://openalex.org/W2528679397","https://openalex.org/W2883460582","https://openalex.org/W4205930639","https://openalex.org/W4233278418","https://openalex.org/W6606151733","https://openalex.org/W6637131181","https://openalex.org/W6639864006","https://openalex.org/W6678914141"],"related_works":["https://openalex.org/W2469507153","https://openalex.org/W2768892939","https://openalex.org/W2008790809","https://openalex.org/W4285507391","https://openalex.org/W3164408430","https://openalex.org/W2397240470","https://openalex.org/W2602767565","https://openalex.org/W170652726","https://openalex.org/W2883822334","https://openalex.org/W2134874482"],"abstract_inverted_index":{"Identifying":[0],"families":[1,58,204],"of":[2,13,19,50,90,94,116,127,163,176,205,213,248],"malware":[3,52,56,97,166,249],"is":[4,59,188],"today":[5],"considered":[6],"a":[7,20,24,74,91,96,101,114,199,284],"fundamental":[8],"problem":[9,85],"in":[10,57,103,119,245],"the":[11,48,51,88,104,161,173,186,191,229,246,273,292],"context":[12,247],"computer":[14],"security.":[15],"The":[16,233],"correct":[17],"mapping":[18],"malicious":[21,117],"sample":[22],"to":[23,33,79,112,159,260,268],"known":[25],"family":[26,98,167,250],"simplifies":[27],"its":[28],"analysis":[29,53],"and":[30,141,222,225,279],"allows":[31],"experts":[32],"focus":[34],"their":[35],"efforts":[36],"only":[37],"on":[38,145,190,277],"those":[39],"samples":[40,118,207,227],"presenting":[41],"unknown":[42],"characteristics":[43],"or":[44,266],"behaviours,":[45],"thus":[46],"improving":[47],"efficiency":[49],"process.":[54],"Grouping":[55],"an":[60,157,210,236,262],"activity":[61],"that":[62,71,241,255],"can":[63,257],"be":[64,80,258],"performed":[65],"using":[66,228,272],"widely":[67],"different":[68,110],"approaches,":[69],"but":[70,178],"currently":[72],"lacks":[73],"globally":[75],"accepted":[76],"ground":[77,168,274],"truth":[78,169],"used":[81],"for":[82,202,291],"comparison.":[83],"This":[84],"stems":[86],"from":[87,209],"absence":[89],"formal":[92],"definition":[93],"what":[95],"is.":[99],"As":[100],"consequence,":[102],"last":[105],"few":[106],"years":[107],"researchers":[108],"proposed":[109],"methodologies":[111],"group":[113],"dataset":[115,212],"families.":[120],"Notable":[121],"examples":[122],"include":[123,172],"solutions":[124,143],"combining":[125],"labels":[126,181],"commercial":[128],"anti-malware":[129],"software,":[130],"where":[131,287],"possible":[132],"disagreements":[133],"are":[134],"solved":[135],"by":[136,183,194],"majority":[137],"voting":[138],"(e.g.,":[139,149],"AVclass),":[140],"dedicated":[142],"based":[144,189,276],"machine":[146],"learning":[147],"algorithms":[148],"Malheur).":[150],"In":[151],"this":[152],"paper":[153,234],"we":[154,197,253,282],"first":[155],"present":[156],"evaluation":[158,238],"assess":[160],"quality":[162],"two":[164],"distinct":[165],"datasets.":[170],"Both":[171],"same":[174],"set":[175],"malware,":[177],"one":[179],"has":[180],"produced":[182],"AVclass":[184,278],"while":[185],"other":[187],"clusters":[192],"identified":[193],"Malheur.":[195,280],"Then":[196],"propose":[198],"novel":[200],"solution":[201],"identifying":[203],"similar":[206],"starting":[208],"unlabelled":[211],"malware.":[214],"We":[215],"leverage":[216],"features":[217],"extracted":[218],"through":[219],"both":[220],"static":[221],"dynamic":[223],"analysis,":[224],"cluster":[226],"BIRCH":[230,242,256,288],"clustering":[231,270,294],"algorithm.":[232],"includes":[235],"experimental":[237],"which":[239],"shows":[240],"fits":[243],"well":[244],"identification.":[251],"Indeed,":[252],"prove":[254],"tuned":[259],"obtain":[261],"accuracy":[263],"higher":[264],"than":[265],"comparable":[267],"standard":[269],"algorithms,":[271],"truths":[275],"Furthermore,":[281],"provide":[283],"performance":[285],"comparison":[286],"stands":[289],"out":[290],"low":[293],"time":[295],"it":[296],"provides.":[297]},"counts_by_year":[{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":4},{"year":2018,"cited_by_count":1}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
