{"id":"https://openalex.org/W4396939939","doi":"https://doi.org/10.1109/isdfs60797.2024.10527225","title":"Identifying Malware Family with String Matching Algorithms Based on API Calls and Entire Strings","display_name":"Identifying Malware Family with String Matching Algorithms Based on API Calls and Entire Strings","publication_year":2024,"publication_date":"2024-04-29","ids":{"openalex":"https://openalex.org/W4396939939","doi":"https://doi.org/10.1109/isdfs60797.2024.10527225"},"language":"en","primary_location":{"id":"doi:10.1109/isdfs60797.2024.10527225","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1109/isdfs60797.2024.10527225","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 12th International Symposium on Digital Forensics and Security (ISDFS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5010078455","display_name":"Kubra Gundogan","orcid":"https://orcid.org/0000-0002-5861-430X"},"institutions":[{"id":"https://openalex.org/I191429286","display_name":"Sam Houston State University","ror":"https://ror.org/00yh3cz06","country_code":"US","type":"education","lineage":["https://openalex.org/I191429286"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kubra Gundogan","raw_affiliation_strings":["Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","institution_ids":["https://openalex.org/I191429286"]},{"raw_affiliation_string":"Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA","institution_ids":["https://openalex.org/I191429286"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055812247","display_name":"Khushi Gupta","orcid":"https://orcid.org/0000-0002-4452-5103"},"institutions":[{"id":"https://openalex.org/I191429286","display_name":"Sam Houston State University","ror":"https://ror.org/00yh3cz06","country_code":"US","type":"education","lineage":["https://openalex.org/I191429286"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Khushi Gupta","raw_affiliation_strings":["Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","institution_ids":["https://openalex.org/I191429286"]},{"raw_affiliation_string":"Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA","institution_ids":["https://openalex.org/I191429286"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110990811","display_name":"Laura Garland","orcid":null},"institutions":[{"id":"https://openalex.org/I191429286","display_name":"Sam Houston State University","ror":"https://ror.org/00yh3cz06","country_code":"US","type":"education","lineage":["https://openalex.org/I191429286"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Laura Garland","raw_affiliation_strings":["Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","institution_ids":["https://openalex.org/I191429286"]},{"raw_affiliation_string":"Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA","institution_ids":["https://openalex.org/I191429286"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061796733","display_name":"Cihan Varol","orcid":"https://orcid.org/0000-0002-4940-6808"},"institutions":[{"id":"https://openalex.org/I191429286","display_name":"Sam Houston State University","ror":"https://ror.org/00yh3cz06","country_code":"US","type":"education","lineage":["https://openalex.org/I191429286"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Cihan Varol","raw_affiliation_strings":["Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","institution_ids":["https://openalex.org/I191429286"]},{"raw_affiliation_string":"Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA","institution_ids":["https://openalex.org/I191429286"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5086039015","display_name":"Narasimha Shashidhar","orcid":"https://orcid.org/0000-0002-4877-158X"},"institutions":[{"id":"https://openalex.org/I191429286","display_name":"Sam Houston State University","ror":"https://ror.org/00yh3cz06","country_code":"US","type":"education","lineage":["https://openalex.org/I191429286"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Narasimha Shashidhar","raw_affiliation_strings":["Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sam Houston State University,Department of Computer Science,Huntsville,Texas,USA","institution_ids":["https://openalex.org/I191429286"]},{"raw_affiliation_string":"Department of Computer Science, Sam Houston State University, Huntsville, Texas, USA","institution_ids":["https://openalex.org/I191429286"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.06539827,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"4","issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9929999709129333,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9851999878883362,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9269343018531799},{"id":"https://openalex.org/keywords/jaccard-index","display_name":"Jaccard index","score":0.8800630569458008},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7040295600891113},{"id":"https://openalex.org/keywords/string","display_name":"String (physics)","score":0.5994874238967896},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.5770552754402161},{"id":"https://openalex.org/keywords/longest-common-subsequence-problem","display_name":"Longest common subsequence problem","score":0.5768802165985107},{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.553130030632019},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.4668147563934326},{"id":"https://openalex.org/keywords/n-gram","display_name":"n-gram","score":0.4473678767681122},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.43992310762405396},{"id":"https://openalex.org/keywords/edit-distance","display_name":"Edit distance","score":0.42957961559295654},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3364506959915161},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.28387248516082764},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2781056761741638},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.21646296977996826},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.18351343274116516},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.13380998373031616}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9269343018531799},{"id":"https://openalex.org/C203519979","wikidata":"https://www.wikidata.org/wiki/Q865360","display_name":"Jaccard index","level":3,"score":0.8800630569458008},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7040295600891113},{"id":"https://openalex.org/C157486923","wikidata":"https://www.wikidata.org/wiki/Q1376436","display_name":"String (physics)","level":2,"score":0.5994874238967896},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.5770552754402161},{"id":"https://openalex.org/C120098539","wikidata":"https://www.wikidata.org/wiki/Q141001","display_name":"Longest common subsequence problem","level":2,"score":0.5768802165985107},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.553130030632019},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.4668147563934326},{"id":"https://openalex.org/C117884012","wikidata":"https://www.wikidata.org/wiki/Q94489","display_name":"n-gram","level":3,"score":0.4473678767681122},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.43992310762405396},{"id":"https://openalex.org/C44359876","wikidata":"https://www.wikidata.org/wiki/Q5338467","display_name":"Edit distance","level":2,"score":0.42957961559295654},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3364506959915161},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.28387248516082764},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2781056761741638},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.21646296977996826},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.18351343274116516},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.13380998373031616},{"id":"https://openalex.org/C37914503","wikidata":"https://www.wikidata.org/wiki/Q156495","display_name":"Mathematical physics","level":1,"score":0.0},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isdfs60797.2024.10527225","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1109/isdfs60797.2024.10527225","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 12th International Symposium on Digital Forensics and Security (ISDFS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.7400000095367432}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W2036575863","https://openalex.org/W2109227373","https://openalex.org/W2125980212","https://openalex.org/W2267635142","https://openalex.org/W2307930854","https://openalex.org/W2384622762","https://openalex.org/W2594215738","https://openalex.org/W2795063185","https://openalex.org/W2808649067","https://openalex.org/W2887921593","https://openalex.org/W2963003683","https://openalex.org/W2972877457","https://openalex.org/W2981360604","https://openalex.org/W3131954256","https://openalex.org/W3157039573","https://openalex.org/W6710713934"],"related_works":["https://openalex.org/W2938635738","https://openalex.org/W4292436243","https://openalex.org/W2998685384","https://openalex.org/W3002517191","https://openalex.org/W2902509208","https://openalex.org/W4240117647","https://openalex.org/W2163993443","https://openalex.org/W2018366250","https://openalex.org/W2012010763","https://openalex.org/W3031506718"],"abstract_inverted_index":{"Malware":[0],"is":[1,94,235],"a":[2,91],"growing":[3],"concern":[4],"for":[5,51,155,158,162,166,199,204,219,224,240,245],"governments,":[6],"organizations,":[7],"and":[8,25,107,113,126,160,174,179,202,222,243],"individuals,":[9],"as":[10],"it":[11,49,56],"can":[12,29],"corrupt":[13],"or":[14,17,146],"steal":[15],"confidential":[16],"sensitive":[18],"data.":[19],"Although":[20,46],"security":[21],"software":[22],"constantly":[23],"identifies":[24],"blocks":[26],"malware,":[27],"adversaries":[28],"produce":[30],"slightly":[31],"altered":[32],"variants":[33],"within":[34,170],"the":[35,44,52,65,96,102,119,131,142,190,208,228,231],"same":[36,66,97,143],"malware":[37,63,86,92,138,144,172],"family":[38,67,145],"by":[39],"making":[40],"minor":[41],"alterations":[42],"to":[43,54,61,84,88,129,134,182],"original.":[45],"this":[47,77],"makes":[48],"challenging":[50],"system":[53],"detect,":[55],"also":[57,211],"provides":[58],"an":[59],"opportunity":[60],"detect":[62],"from":[64,95],"early":[68],"since":[69],"many":[70],"of":[71,104,197,217],"its":[72],"strings":[73,103,139,169,201,221,242],"remain":[74],"similar.":[75],"In":[76],"study,":[78],"we":[79,100,117,149,175],"apply":[80],"three":[81],"similarity":[82],"algorithms":[83,128],"nine":[85],"families":[87],"identify":[89],"whether":[90,136],"string":[93],"family.":[98],"First,":[99],"extract":[101],"each":[105],"executable":[106],"divide":[108],"these":[109],"into":[110],"API":[111,205,225,246],"calls":[112],"entire":[114,200,220,241],"strings.":[115],"Next,":[116],"use":[118],"Jaccard":[120,209],"Coefficient,":[121],"Longest":[122],"Common":[123],"Subsequence":[124],"(LCS),":[125],"N-gram":[127,163,191],"determine":[130,135,150],"optimal":[132,165],"threshold":[133,152],"two":[137],"belong":[140],"in":[141],"not.":[147],"Finally,":[148],"that":[151,189],"values":[153],"26.84%":[154],"LCS,":[156],"28.02%":[157],"Jaccard,":[159],"54.16%":[161],"are":[164],"detecting":[167],"similar":[168],"all":[171],"families,":[173],"conduct":[176],"both":[177],"within-family":[178],"cross-family":[180],"analyses":[181],"substantiate":[183],"our":[184],"results.":[185],"Our":[186],"analysis":[187],"shows":[188],"algorithm":[192,210],"achieves":[193],"high":[194],"accuracy":[195,234],"rates":[196,216],"91.16%":[198],"93.11%":[203],"calls.":[206,226,247],"Similarly,":[207],"demonstrates":[212],"strong":[213],"accuracy,":[214],"with":[215,238],"91%":[218],"91.68%":[223],"On":[227],"other":[229],"hand,":[230],"LCS":[232],"algorithm's":[233],"comparatively":[236],"lower,":[237],"83.78%":[239],"71.65%":[244]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
