{"id":"https://openalex.org/W2933569725","doi":"https://doi.org/10.1109/ceec.2018.8674233","title":"Accuracy Improved Malware Detection Method using Snort Sub-signatures and Machine Learning Techniques","display_name":"Accuracy Improved Malware Detection Method using Snort Sub-signatures and Machine Learning Techniques","publication_year":2018,"publication_date":"2018-09-01","ids":{"openalex":"https://openalex.org/W2933569725","doi":"https://doi.org/10.1109/ceec.2018.8674233","mag":"2933569725"},"language":"en","primary_location":{"id":"doi:10.1109/ceec.2018.8674233","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ceec.2018.8674233","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 10th Computer Science and Electronic Engineering (CEEC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087393194","display_name":"Ban Mohammed Khammas","orcid":"https://orcid.org/0000-0003-3117-7493"},"institutions":[{"id":"https://openalex.org/I56409017","display_name":"Nahrain University","ror":"https://ror.org/05v2p9075","country_code":"IQ","type":"education","lineage":["https://openalex.org/I56409017"]}],"countries":["IQ"],"is_corresponding":false,"raw_author_name":"Ban M. Khammas","raw_affiliation_strings":["Department of Networks Eng., Al-Nahrain University, Baghdad, Iraq"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Networks Eng., Al-Nahrain University, Baghdad, Iraq","institution_ids":["https://openalex.org/I56409017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110207401","display_name":"Sami Hasan","orcid":null},"institutions":[{"id":"https://openalex.org/I56409017","display_name":"Nahrain University","ror":"https://ror.org/05v2p9075","country_code":"IQ","type":"education","lineage":["https://openalex.org/I56409017"]}],"countries":["IQ"],"is_corresponding":false,"raw_author_name":"Sami Hasan","raw_affiliation_strings":["Department System Eng., Al-Nahrain University, Baghdad, Iraq"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department System Eng., Al-Nahrain University, Baghdad, Iraq","institution_ids":["https://openalex.org/I56409017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050323616","display_name":"Rabah Abood Ahmed","orcid":"https://orcid.org/0000-0001-5878-9604"},"institutions":[{"id":"https://openalex.org/I56409017","display_name":"Nahrain University","ror":"https://ror.org/05v2p9075","country_code":"IQ","type":"education","lineage":["https://openalex.org/I56409017"]}],"countries":["IQ"],"is_corresponding":false,"raw_author_name":"Rabah Abood Ahmed","raw_affiliation_strings":["Department of Networks Eng., Al-Nahrain University, Baghdad, Iraq"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Networks Eng., Al-Nahrain University, Baghdad, Iraq","institution_ids":["https://openalex.org/I56409017"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046385196","display_name":"Joseph Stephen Bassi","orcid":"https://orcid.org/0000-0001-5050-0132"},"institutions":[{"id":"https://openalex.org/I64351976","display_name":"University of Maiduguri","ror":"https://ror.org/016na8197","country_code":"NG","type":"education","lineage":["https://openalex.org/I64351976"]}],"countries":["NG"],"is_corresponding":false,"raw_author_name":"Joseph Stephen Bassi","raw_affiliation_strings":["Department of Computer Eng., University of Maiduguri, Maiduguri, Borno State, Nigeria"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Eng., University of Maiduguri, Maiduguri, Borno State, Nigeria","institution_ids":["https://openalex.org/I64351976"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101639245","display_name":"Ismahani Ismail","orcid":"https://orcid.org/0000-0002-7630-6706"},"institutions":[{"id":"https://openalex.org/I4576418","display_name":"University of Technology Malaysia","ror":"https://ror.org/026w31v75","country_code":"MY","type":"education","lineage":["https://openalex.org/I4576418"]}],"countries":["MY"],"is_corresponding":false,"raw_author_name":"Ismahani Ismail","raw_affiliation_strings":["Department of Electronic and Computer Engineering (ECE), Universiti Teknologi Malaysia, Johor Bahru, Malaysia"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electronic and Computer Engineering (ECE), Universiti Teknologi Malaysia, Johor Bahru, Malaysia","institution_ids":["https://openalex.org/I4576418"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.6651,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.71706967,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":96},"biblio":{"volume":"3","issue":null,"first_page":"107","last_page":"112"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9259931445121765},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8403063416481018},{"id":"https://openalex.org/keywords/feature-selection","display_name":"Feature selection","score":0.6670233011245728},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6639068722724915},{"id":"https://openalex.org/keywords/support-vector-machine","display_name":"Support vector machine","score":0.5998772978782654},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5823423862457275},{"id":"https://openalex.org/keywords/feature-extraction","display_name":"Feature extraction","score":0.5695748925209045},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.5132665634155273},{"id":"https://openalex.org/keywords/n-gram","display_name":"n-gram","score":0.4777740240097046},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.4425489902496338},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4171144962310791},{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.4166964888572693},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3610072135925293},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.12886753678321838},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.07333225011825562}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9259931445121765},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8403063416481018},{"id":"https://openalex.org/C148483581","wikidata":"https://www.wikidata.org/wiki/Q446488","display_name":"Feature selection","level":2,"score":0.6670233011245728},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6639068722724915},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.5998772978782654},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5823423862457275},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.5695748925209045},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.5132665634155273},{"id":"https://openalex.org/C117884012","wikidata":"https://www.wikidata.org/wiki/Q94489","display_name":"n-gram","level":3,"score":0.4777740240097046},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.4425489902496338},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4171144962310791},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.4166964888572693},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3610072135925293},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.12886753678321838},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.07333225011825562},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ceec.2018.8674233","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ceec.2018.8674233","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 10th Computer Science and Electronic Engineering (CEEC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":46,"referenced_works":["https://openalex.org/W4081608","https://openalex.org/W9976069","https://openalex.org/W567160446","https://openalex.org/W779818195","https://openalex.org/W1258780651","https://openalex.org/W1497883910","https://openalex.org/W1586252162","https://openalex.org/W1845054399","https://openalex.org/W1987684126","https://openalex.org/W2004511978","https://openalex.org/W2022473311","https://openalex.org/W2023450550","https://openalex.org/W2042816384","https://openalex.org/W2079215333","https://openalex.org/W2099053789","https://openalex.org/W2099426598","https://openalex.org/W2111571136","https://openalex.org/W2121749752","https://openalex.org/W2125347499","https://openalex.org/W2129650357","https://openalex.org/W2150188172","https://openalex.org/W2153393809","https://openalex.org/W2155461860","https://openalex.org/W2156938859","https://openalex.org/W2157734500","https://openalex.org/W2163900540","https://openalex.org/W2164463255","https://openalex.org/W2167101736","https://openalex.org/W2256319980","https://openalex.org/W2410416192","https://openalex.org/W2414657077","https://openalex.org/W2466023328","https://openalex.org/W2557423851","https://openalex.org/W2736425583","https://openalex.org/W2963461515","https://openalex.org/W2998216295","https://openalex.org/W3199644723","https://openalex.org/W4285719527","https://openalex.org/W4323288509","https://openalex.org/W6628268980","https://openalex.org/W6635086389","https://openalex.org/W6678051712","https://openalex.org/W6692093865","https://openalex.org/W6719473894","https://openalex.org/W6850399123","https://openalex.org/W7066667914"],"related_works":["https://openalex.org/W2439951656","https://openalex.org/W2160606508","https://openalex.org/W1573526548","https://openalex.org/W1998188341","https://openalex.org/W4360982091","https://openalex.org/W3176864451","https://openalex.org/W2053632570","https://openalex.org/W3211525895","https://openalex.org/W2187910102","https://openalex.org/W2128507946"],"abstract_inverted_index":{"Malware":[0],"is":[1,54],"a":[2,26,62,154],"major":[3],"computer":[4],"security":[5],"concern":[6],"as":[7],"many":[8],"computing":[9],"systems":[10],"are":[11,36,78,87,129,185],"connected":[12],"to":[13,51,80,90,117,132,172],"the":[14,23,47,74,96,101,104,119,134,167,190],"Internet.":[15],"The":[16,138],"number":[17,120],"of":[18,38,46,107,112,121,125,159,166,189],"malware":[19,28,34,53,64,76,108,135,156],"has":[20,29],"increased":[21],"over":[22],"years":[24],"and":[25,69,103,123,179],"new":[27,33],"emerged":[30],"daily.":[31],"These":[32],"variants":[35],"capable":[37],"evading":[39],"conventional":[40],"system":[41,66],"detection":[42,65,105,136,157],"through":[43],"obfuscations.":[44],"One":[45],"promising":[48],"methods":[49,116],"used":[50],"detect":[52],"machine":[55,70,150],"learning":[56,71,151],"(ML)":[57],"techniques.":[58,72],"This":[59],"work":[60],"presents":[61],"static":[63],"using":[67,149],"n-gram":[68,91,144],"Successively,":[73],"known":[75],"sub-signatures":[77],"developed":[79,131],"reduce":[81],"large":[82],"feature":[83,92,97,114],"search":[84],"spaces.":[85],"That":[86],"generated":[88],"due":[89],"extraction":[93],"methods.":[94],"Consequently,":[95],"space":[98],"directly":[99],"affects":[100],"performance":[102],"accuracy":[106,158],"ML":[109,127,192],"classifiers.":[110,193],"Analysis":[111],"multiple":[113,126],"selection":[115],"minimize":[118],"features":[122,148,184],"analysis":[124],"classifiers":[128],"also":[130],"improve":[133],"accuracy.":[137],"results":[139],"have":[140],"shown":[141],"that":[142],"analyzing":[143],"with":[145],"Snort":[146],"sub-signature":[147],"may":[152],"produce":[153],"good":[155],"more":[160],"than":[161],"99.78%,":[162],"minimized":[163],"processing":[164],"time":[165],"optimum":[168],"SVM":[169],"classifier":[170],"down":[171],"5":[173],"sec.":[174],"for":[175,187],"all":[176],"data":[177],"set":[178],"zero":[180],"FPR":[181],"when":[182],"4gram":[183],"applied":[186],"most":[188],"verified":[191]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":2},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
