{"id":"https://openalex.org/W4205607115","doi":"https://doi.org/10.1109/comsnets53615.2022.9668396","title":"Polymorphic Malware Behavior Through Network Trace Analysis","display_name":"Polymorphic Malware Behavior Through Network Trace Analysis","publication_year":2022,"publication_date":"2022-01-04","ids":{"openalex":"https://openalex.org/W4205607115","doi":"https://doi.org/10.1109/comsnets53615.2022.9668396"},"language":"en","primary_location":{"id":"doi:10.1109/comsnets53615.2022.9668396","is_oa":false,"landing_page_url":"https://doi.org/10.1109/comsnets53615.2022.9668396","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 14th International Conference on COMmunication Systems &amp; NETworkS (COMSNETS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5040113167","display_name":"Xiyue Deng","orcid":null},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Xiyue Deng","raw_affiliation_strings":["Information Sciences Institute, University of Southern California, Marina Del Ray, California, United States"],"affiliations":[{"raw_affiliation_string":"Information Sciences Institute, University of Southern California, Marina Del Ray, California, United States","institution_ids":["https://openalex.org/I1174212"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5103177278","display_name":"Jelena Mirkovi\u0107","orcid":"https://orcid.org/0000-0001-7462-8747"},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jelena Mirkovic","raw_affiliation_strings":["Information Sciences Institute, University of Southern California, Marina Del Ray, California, United States"],"affiliations":[{"raw_affiliation_string":"Information Sciences Institute, University of Southern California, Marina Del Ray, California, United States","institution_ids":["https://openalex.org/I1174212"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5040113167"],"corresponding_institution_ids":["https://openalex.org/I1174212"],"apc_list":null,"apc_paid":null,"fwci":1.1886,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.76345263,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"138","last_page":"146"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.995199978351593,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9735999703407288,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9335818290710449},{"id":"https://openalex.org/keywords/obfuscation","display_name":"Obfuscation","score":0.729508638381958},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7248812913894653},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.5904422998428345},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.5201497673988342},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5025780200958252},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.4977171719074249},{"id":"https://openalex.org/keywords/reuse","display_name":"Reuse","score":0.4876362383365631},{"id":"https://openalex.org/keywords/code-reuse","display_name":"Code reuse","score":0.4723055362701416},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.42868414521217346},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.26359719038009644},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.15118595957756042},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.13652750849723816},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.09085169434547424}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9335818290710449},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.729508638381958},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7248812913894653},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.5904422998428345},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.5201497673988342},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5025780200958252},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.4977171719074249},{"id":"https://openalex.org/C206588197","wikidata":"https://www.wikidata.org/wiki/Q846574","display_name":"Reuse","level":2,"score":0.4876362383365631},{"id":"https://openalex.org/C2778583558","wikidata":"https://www.wikidata.org/wiki/Q771245","display_name":"Code reuse","level":3,"score":0.4723055362701416},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.42868414521217346},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.26359719038009644},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.15118595957756042},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.13652750849723816},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.09085169434547424},{"id":"https://openalex.org/C548081761","wikidata":"https://www.wikidata.org/wiki/Q180388","display_name":"Waste management","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/comsnets53615.2022.9668396","is_oa":false,"landing_page_url":"https://doi.org/10.1109/comsnets53615.2022.9668396","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 14th International Conference on COMmunication Systems &amp; NETworkS (COMSNETS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7599999904632568,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W1505580166","https://openalex.org/W1544837488","https://openalex.org/W1634470931","https://openalex.org/W1981229864","https://openalex.org/W2038974217","https://openalex.org/W2039858940","https://openalex.org/W2066220442","https://openalex.org/W2092756033","https://openalex.org/W2111038628","https://openalex.org/W2115175195","https://openalex.org/W2134385885","https://openalex.org/W2158167094","https://openalex.org/W2193838104","https://openalex.org/W2320700546","https://openalex.org/W2344840125","https://openalex.org/W2614419969","https://openalex.org/W2618822292","https://openalex.org/W2712617220","https://openalex.org/W2900633536","https://openalex.org/W2901448867","https://openalex.org/W2915893383","https://openalex.org/W2983734430","https://openalex.org/W3105952379","https://openalex.org/W3118559199","https://openalex.org/W6683365901","https://openalex.org/W6687138502","https://openalex.org/W6700104154","https://openalex.org/W6756279550","https://openalex.org/W6769855775"],"related_works":["https://openalex.org/W4296272594","https://openalex.org/W2469507153","https://openalex.org/W4360993664","https://openalex.org/W2008790809","https://openalex.org/W2465235098","https://openalex.org/W2470029541","https://openalex.org/W2768892939","https://openalex.org/W2470502009","https://openalex.org/W2167003418","https://openalex.org/W2900526031"],"abstract_inverted_index":{"Malware":[0],"continues":[1],"to":[2,7,70,78,97,112,163,210],"be":[3],"a":[4,32,42,61,168,242],"major":[5],"threat":[6],"information":[8],"security.":[9],"To":[10],"avoid":[11],"being":[12],"detected":[13,39],"and":[14,26,83,144,146,197,248],"analyzed,":[15],"modern":[16],"malware":[17,37,92,133,151,166,207,219,260],"is":[18],"continuously":[19],"improving":[20],"its":[21,64,76,95,103],"stealthiness,":[22],"including":[23],"code":[24,47,96,142,246,256],"obfuscation":[25,58],"encryption.":[27],"On":[28],"the":[29,50,80,110,114,160,178,202,214],"other":[30,231],"hand,":[31],"high":[33,44,237,243],"number":[34],"of":[35,46,52,132,201,213,239,245],"unique":[36],"samples":[38,134,176,186],"daily":[40],"suggests":[41],"likely":[43],"degree":[45],"reuse":[48,143],"under":[49],"layers":[51],"stealth.":[53],"We":[54,68,128,158,183],"observe":[55],"that":[56,102,135],"although":[57],"greatly":[59],"changes":[60],"malware's":[62,72,81,115,155],"binary,":[63],"functionalities":[65],"remain":[66],"intact.":[67],"propose":[69,129],"leverage":[71,159],"network":[73,105,156,190,225],"behavior":[74,226],"during":[75],"execution,":[77],"understand":[79],"functionality":[82],"detect":[84],"related":[85],"or":[86],"even":[87],"same":[88,161],"(polymorphic)":[89],"malware.":[90],"While":[91],"may":[93],"transform":[94],"evade":[98],"analysis,":[99],"we":[100],"contend":[101],"key":[104],"behaviors":[106],"must":[107],"endure":[108],"through":[109],"transformations":[111],"achieve":[113],"ultimate":[116],"purpose,":[117],"such":[118],"as":[119,227],"sending":[120],"victim":[121],"information,":[122],"scanning":[123],"for":[124,150,259],"vulnerable":[125],"hosts,":[126],"etc.":[127],"an":[130],"encoding":[131,162],"can":[136,253],"help":[137],"us":[138],"classify":[139],"samples,":[140,220],"identify":[141,164,216],"genealogy,":[145],"develop":[147],"behavioral":[148],"signatures":[149],"defense":[152],"based":[153,192],"on":[154,193],"behavior.":[157],"polymorphic":[165,206,218],"in":[167,233],"random":[169],"dataset":[170],"containing":[171],"more":[172,198],"than":[173,199],"8,000":[174],"diverse":[175],"from":[177],"Georgia":[179],"Tech":[180],"Apiary":[181],"project.":[182],"cluster":[184,203],"6,595":[185],"which":[187],"show":[188],"some":[189],"activity":[191],"our":[194,234,251],"embedding":[195],"features":[196],"90%":[200],"contains":[204],"potentially":[205],"with":[208],"up":[209],"80":[211],"%":[212],"clusters":[215],"truly":[217],"i.e.,":[221],"they":[222],"have":[223],"identical":[224],"at":[228],"least":[229],"one":[230],"sample":[232],"dataset.":[235],"Such":[236],"level":[238,244],"polymorphism":[240],"indicates":[241],"reuse,":[247],"shows":[249],"how":[250],"approach":[252],"complement":[254],"traditional":[255],"analysis":[257],"techniques":[258],"defense.":[261]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":3}],"updated_date":"2026-03-01T08:55:55.761014","created_date":"2025-10-10T00:00:00"}
