{"id":"https://openalex.org/W2944304051","doi":"https://doi.org/10.1109/fuzz-ieee.2019.8858803","title":"Cyberthreat Hunting - Part 1: Triaging Ransomware using Fuzzy Hashing, Import Hashing and YARA Rules","display_name":"Cyberthreat Hunting - Part 1: Triaging Ransomware using Fuzzy Hashing, Import Hashing and YARA Rules","publication_year":2019,"publication_date":"2019-06-01","ids":{"openalex":"https://openalex.org/W2944304051","doi":"https://doi.org/10.1109/fuzz-ieee.2019.8858803","mag":"2944304051"},"language":"en","primary_location":{"id":"doi:10.1109/fuzz-ieee.2019.8858803","is_oa":false,"landing_page_url":"https://doi.org/10.1109/fuzz-ieee.2019.8858803","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 IEEE International Conference on Fuzzy Systems (FUZZ-IEEE)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://nrl.northumbria.ac.uk/id/eprint/38877/1/FUZZ_IEEE_19_CyberThreatHunting_I.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5089628794","display_name":"Nitin Naik","orcid":"https://orcid.org/0000-0002-0659-9646"},"institutions":[{"id":"https://openalex.org/I1306956679","display_name":"Ministry of Defence","ror":"https://ror.org/01bvxzn29","country_code":"GB","type":"government","lineage":["https://openalex.org/I1306956679","https://openalex.org/I2802373619"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Nitin Naik","raw_affiliation_strings":["Defence School of Communications and Information Systems, Ministry of Defence, United Kingdom"],"affiliations":[{"raw_affiliation_string":"Defence School of Communications and Information Systems, Ministry of Defence, United Kingdom","institution_ids":["https://openalex.org/I1306956679"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064994129","display_name":"Paul Jenkins","orcid":"https://orcid.org/0000-0002-9854-9450"},"institutions":[{"id":"https://openalex.org/I1306956679","display_name":"Ministry of Defence","ror":"https://ror.org/01bvxzn29","country_code":"GB","type":"government","lineage":["https://openalex.org/I1306956679","https://openalex.org/I2802373619"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Paul Jenkins","raw_affiliation_strings":["Defence School of Communications and Information Systems, Ministry of Defence, United Kingdom"],"affiliations":[{"raw_affiliation_string":"Defence School of Communications and Information Systems, Ministry of Defence, United Kingdom","institution_ids":["https://openalex.org/I1306956679"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008471645","display_name":"Nick Savage","orcid":"https://orcid.org/0000-0001-9391-5100"},"institutions":[{"id":"https://openalex.org/I63072094","display_name":"University of Portsmouth","ror":"https://ror.org/03ykbk197","country_code":"GB","type":"education","lineage":["https://openalex.org/I63072094"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Nick Savage","raw_affiliation_strings":["School of Computing, University of Portsmouth, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computing, University of Portsmouth, United Kingdom","institution_ids":["https://openalex.org/I63072094"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5065079117","display_name":"Longzhi Yang","orcid":"https://orcid.org/0000-0003-2115-4909"},"institutions":[{"id":"https://openalex.org/I32394136","display_name":"Northumbria University","ror":"https://ror.org/049e6bc10","country_code":"GB","type":"education","lineage":["https://openalex.org/I32394136"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Longzhi Yang","raw_affiliation_strings":["Department of Computer and Information Sciences, Northumbria University, United Kingdom"],"affiliations":[{"raw_affiliation_string":"Department of Computer and Information Sciences, Northumbria University, United Kingdom","institution_ids":["https://openalex.org/I32394136"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5089628794"],"corresponding_institution_ids":["https://openalex.org/I1306956679"],"apc_list":null,"apc_paid":null,"fwci":3.8389,"has_fulltext":true,"cited_by_count":29,"citation_normalized_percentile":{"value":0.94382911,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9947999715805054,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/ransomware","display_name":"Ransomware","score":0.9589861631393433},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7236419916152954},{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.6981099843978882},{"id":"https://openalex.org/keywords/fuzzy-logic","display_name":"Fuzzy logic","score":0.4797478914260864},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4176279604434967},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.41146230697631836},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.38170427083969116},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2518974244594574}],"concepts":[{"id":"https://openalex.org/C2777667771","wikidata":"https://www.wikidata.org/wiki/Q926331","display_name":"Ransomware","level":3,"score":0.9589861631393433},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7236419916152954},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.6981099843978882},{"id":"https://openalex.org/C58166","wikidata":"https://www.wikidata.org/wiki/Q224821","display_name":"Fuzzy logic","level":2,"score":0.4797478914260864},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4176279604434967},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.41146230697631836},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.38170427083969116},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2518974244594574}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/fuzz-ieee.2019.8858803","is_oa":false,"landing_page_url":"https://doi.org/10.1109/fuzz-ieee.2019.8858803","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 IEEE International Conference on Fuzzy Systems (FUZZ-IEEE)","raw_type":"proceedings-article"},{"id":"pmh:oai:nrl.northumbria.ac.uk:38877","is_oa":true,"landing_page_url":null,"pdf_url":"http://nrl.northumbria.ac.uk/id/eprint/38877/1/FUZZ_IEEE_19_CyberThreatHunting_I.pdf","source":{"id":"https://openalex.org/S4306401884","display_name":"Northumbria Research Link (Northumbria University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I32394136","host_organization_name":"Northumbria University","host_organization_lineage":["https://openalex.org/I32394136"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Book Section"}],"best_oa_location":{"id":"pmh:oai:nrl.northumbria.ac.uk:38877","is_oa":true,"landing_page_url":null,"pdf_url":"http://nrl.northumbria.ac.uk/id/eprint/38877/1/FUZZ_IEEE_19_CyberThreatHunting_I.pdf","source":{"id":"https://openalex.org/S4306401884","display_name":"Northumbria Research Link (Northumbria University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I32394136","host_organization_name":"Northumbria University","host_organization_lineage":["https://openalex.org/I32394136"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Book Section"},"sustainable_development_goals":[{"score":0.41999998688697815,"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure"}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2944304051.pdf","grobid_xml":"https://content.openalex.org/works/W2944304051.grobid-xml"},"referenced_works_count":34,"referenced_works":["https://openalex.org/W1549130775","https://openalex.org/W1990999691","https://openalex.org/W1995077566","https://openalex.org/W2038683228","https://openalex.org/W2083331665","https://openalex.org/W2126120381","https://openalex.org/W2164215197","https://openalex.org/W2168154523","https://openalex.org/W2216493166","https://openalex.org/W2468072172","https://openalex.org/W2520938204","https://openalex.org/W2528880615","https://openalex.org/W2556507683","https://openalex.org/W2587798408","https://openalex.org/W2614042168","https://openalex.org/W2705431144","https://openalex.org/W2746282326","https://openalex.org/W2747994176","https://openalex.org/W2768881458","https://openalex.org/W2780698577","https://openalex.org/W2891168291","https://openalex.org/W2897156262","https://openalex.org/W2897846265","https://openalex.org/W2902638435","https://openalex.org/W2902669569","https://openalex.org/W2907840713","https://openalex.org/W2912055266","https://openalex.org/W2913412946","https://openalex.org/W2913428813","https://openalex.org/W2945500821","https://openalex.org/W2980004293","https://openalex.org/W6684316442","https://openalex.org/W6688795101","https://openalex.org/W6737892506"],"related_works":["https://openalex.org/W3201228709","https://openalex.org/W2922354075","https://openalex.org/W4389157351","https://openalex.org/W4232561318","https://openalex.org/W4253977752","https://openalex.org/W2942879794","https://openalex.org/W2964829536","https://openalex.org/W2904586340","https://openalex.org/W3120595989","https://openalex.org/W4380791770"],"abstract_inverted_index":{"Ransomware":[0],"is":[1,33,116],"currently":[2],"one":[3],"of":[4,53,105,124,153],"the":[5,14,44,51,71,103,130,151],"most":[6,45,72,132],"significant":[7,63],"cyberthreats":[8],"to":[9,61,91,99],"both":[10],"national":[11],"infrastructure":[12],"and":[13,56,74,83,112,139,146],"individual,":[15],"often":[16],"requiring":[17],"severe":[18],"treatment":[19],"as":[20],"an":[21,34,122],"antidote.":[22],"Triaging":[23],"ran-somware":[24],"based":[25],"on":[26],"its":[27],"similarity":[28],"with":[29],"well-known":[30],"ransomware":[31,41,95,134],"samples":[32,96],"imperative":[35],"preliminary":[36],"step":[37],"in":[38,59],"preventing":[39],"a":[40,66],"pandemic.":[42],"Selecting":[43],"appropriate":[46],"triaging":[47,76,129,144],"method":[48],"can":[49,87],"improve":[50],"precision":[52],"further":[54],"static":[55],"dynamic":[57],"analysis":[58],"addition":[60],"saving":[62],"t":[64],"ime":[65],"nd":[67],"e":[68],"ffort.":[69],"Currently,":[70],"popular":[73],"proven":[75],"methods":[77,108,127],"are":[78,97,109],"fuzzy":[79],"hashing,":[80],"import":[81],"hashing":[82],"YARA":[84],"rules,":[85],"which":[86],"ascertain":[88],"whether,":[89],"or":[90],"what":[92],"degree,":[93],"two":[94],"similar":[98],"each":[100,154],"other.":[101],"However,":[102],"mechanisms":[104],"these":[106,125],"three":[107,126],"quite":[110],"different":[111],"their":[113,143],"comparative":[114],"assessment":[115],"difficult.":[117],"Therefore,":[118],"this":[119],"paper":[120],"presents":[121],"evaluation":[123],"for":[128],"four":[131],"pertinent":[133],"categories":[135],"WannaCry,":[136],"Locky,":[137],"Cerber":[138],"CryptoWall.":[140],"It":[141],"evaluates":[142],"performance":[145],"run-time":[147],"system":[148],"performance,":[149],"highlighting":[150],"limitations":[152],"method.":[155]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":9},{"year":2019,"cited_by_count":5}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
