{"id":"https://openalex.org/W2132979129","doi":"https://doi.org/10.1109/lcn.2009.5355037","title":"Measuring similarity of malware behavior","display_name":"Measuring similarity of malware behavior","publication_year":2009,"publication_date":"2009-10-01","ids":{"openalex":"https://openalex.org/W2132979129","doi":"https://doi.org/10.1109/lcn.2009.5355037","mag":"2132979129"},"language":"en","primary_location":{"id":"doi:10.1109/lcn.2009.5355037","is_oa":false,"landing_page_url":"https://doi.org/10.1109/lcn.2009.5355037","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2009 IEEE 34th Conference on Local Computer Networks","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5058111949","display_name":"Martin Apel","orcid":null},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Martin Apel","raw_affiliation_strings":["University of Dortmund, Dortmund, Germany","University of Dortmund, D-44221, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Dortmund, Dortmund, Germany","institution_ids":["https://openalex.org/I200332995"]},{"raw_affiliation_string":"University of Dortmund, D-44221, Germany","institution_ids":["https://openalex.org/I200332995"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053116245","display_name":"Christian Bockermann","orcid":"https://orcid.org/0000-0001-6570-0583"},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Christian Bockermann","raw_affiliation_strings":["University of Dortmund, Dortmund, Germany","University of Dortmund, D-44221, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Dortmund, Dortmund, Germany","institution_ids":["https://openalex.org/I200332995"]},{"raw_affiliation_string":"University of Dortmund, D-44221, Germany","institution_ids":["https://openalex.org/I200332995"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5062665860","display_name":"Michael Meier","orcid":"https://orcid.org/0000-0002-7727-6561"},"institutions":[{"id":"https://openalex.org/I200332995","display_name":"TU Dortmund University","ror":"https://ror.org/01k97gp34","country_code":"DE","type":"education","lineage":["https://openalex.org/I200332995"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Meier","raw_affiliation_strings":["University of Dortmund, Dortmund, Germany","University of Dortmund, D-44221, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Dortmund, Dortmund, Germany","institution_ids":["https://openalex.org/I200332995"]},{"raw_affiliation_string":"University of Dortmund, D-44221, Germany","institution_ids":["https://openalex.org/I200332995"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.6433,"has_fulltext":false,"cited_by_count":46,"citation_normalized_percentile":{"value":0.95038749,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"891","last_page":"898"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9957000017166138,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9908000230789185,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9598069190979004},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7779197692871094},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.5730998516082764},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.5484188795089722},{"id":"https://openalex.org/keywords/obfuscation","display_name":"Obfuscation","score":0.48212361335754395},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4594143331050873},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.456175297498703},{"id":"https://openalex.org/keywords/measure","display_name":"Measure (data warehouse)","score":0.4554658830165863},{"id":"https://openalex.org/keywords/relation","display_name":"Relation (database)","score":0.44882968068122864},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.43487632274627686},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.400043249130249},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3802340626716614},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2889827787876129}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9598069190979004},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7779197692871094},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.5730998516082764},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.5484188795089722},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.48212361335754395},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4594143331050873},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.456175297498703},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.4554658830165863},{"id":"https://openalex.org/C25343380","wikidata":"https://www.wikidata.org/wiki/Q277521","display_name":"Relation (database)","level":2,"score":0.44882968068122864},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.43487632274627686},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.400043249130249},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3802340626716614},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2889827787876129},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/lcn.2009.5355037","is_oa":false,"landing_page_url":"https://doi.org/10.1109/lcn.2009.5355037","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2009 IEEE 34th Conference on Local Computer Networks","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W17153952","https://openalex.org/W96967778","https://openalex.org/W150122260","https://openalex.org/W157706324","https://openalex.org/W1553273090","https://openalex.org/W1573286687","https://openalex.org/W1580559113","https://openalex.org/W1581009051","https://openalex.org/W1604459715","https://openalex.org/W1638203394","https://openalex.org/W1873122431","https://openalex.org/W1972969203","https://openalex.org/W1982402725","https://openalex.org/W2059513841","https://openalex.org/W2097101478","https://openalex.org/W2099194862","https://openalex.org/W2101694047","https://openalex.org/W2104290684","https://openalex.org/W2110908283","https://openalex.org/W2111038628","https://openalex.org/W2128859735","https://openalex.org/W2132874238","https://openalex.org/W2138644293","https://openalex.org/W2145056020","https://openalex.org/W2155615465","https://openalex.org/W2162744351","https://openalex.org/W2165654401","https://openalex.org/W2166064672","https://openalex.org/W2166901988","https://openalex.org/W2168154523","https://openalex.org/W2952484491","https://openalex.org/W3136767761","https://openalex.org/W4230960895","https://openalex.org/W4285719527","https://openalex.org/W4299828519","https://openalex.org/W6606170237","https://openalex.org/W6606400708","https://openalex.org/W6633156400","https://openalex.org/W6634259793","https://openalex.org/W6634623742","https://openalex.org/W6635142148","https://openalex.org/W6636411187","https://openalex.org/W6639366190","https://openalex.org/W6674403372","https://openalex.org/W6674998358","https://openalex.org/W6675789689","https://openalex.org/W6680604901","https://openalex.org/W6682706510"],"related_works":["https://openalex.org/W4296272594","https://openalex.org/W2469507153","https://openalex.org/W4360993664","https://openalex.org/W2008790809","https://openalex.org/W2465235098","https://openalex.org/W2470029541","https://openalex.org/W2470502009","https://openalex.org/W2167003418","https://openalex.org/W2900526031","https://openalex.org/W3022706011"],"abstract_inverted_index":{"Malicious":[0],"software":[1],"(malware)":[2],"represents":[3],"a":[4,60,69,104,121,147,205,236],"major":[5],"threat":[6],"for":[7,109,127,151,182,208,227,241],"computer":[8],"systems":[9],"of":[10,21,47,59,103,123,135,149,204,217],"almost":[11,75],"all":[12],"types.":[13],"In":[14,83,145],"the":[15,19,30,76],"past":[16],"few":[17],"years":[18],"number":[20,122,148],"prevalent":[22],"malware":[23,33,50,61,89,99,114,136,153,187,218,228,243],"samples":[24,100,115,137,154,244],"has":[25],"increased":[26],"dramatically":[27],"due":[28],"to":[29,36,44,85,96],"fact":[31],"that":[32],"authors":[34],"started":[35],"deploy":[37],"morphing":[38],"(aka":[39],"obfuscation)":[40],"techniques":[41,56],"in":[42,198],"order":[43,84],"hinder":[45],"detection":[46],"such":[48],"polymorphic":[49,88],"by":[51,120],"anti-malware":[52],"products.":[53],"Using":[54],"these":[55,66],"numerous":[57],"variants":[58,67,102],"can":[62],"be":[63],"generated.":[64],"All":[65],"have":[68,155],"different":[70,160,195,224],"syntactic":[71],"representation":[72],"while":[73],"providing":[74],"same":[77],"functionality":[78],"and":[79,200,219,221],"showing":[80],"similar":[81,247],"behavior.":[82,229,248],"effectively":[86],"detect":[87],"it":[90,172],"is":[91,138,173],"advantageous":[92],"(if":[93],"not":[94],"required)":[95],"know":[97],"which":[98,177],"are":[101,117,163,180],"particular":[105,133,146,210],"malware.":[106],"Respective":[107],"approaches":[108,150],"determining":[110,183],"this":[111,129,191,209],"relation":[112,130],"between":[113,186],"automatically":[116],"currently":[118],"investigated":[119],"researchers.":[124],"A":[125],"prerequisite":[126],"assessing":[128],"based":[131,245],"on":[132,214,231,246],"features":[134,216],"an":[139,174],"appropriate":[140,181,238],"similarity":[141,161,178],"or":[142],"distance":[143,196,206,225,239],"measure.":[144],"clustering":[152],"been":[156],"recently":[157],"published.":[158],"Thereby":[159],"measures":[162,179,197,226],"used":[164],"but":[165],"without":[166],"thoroughly":[167],"discussing":[168],"their":[169],"choice.":[170],"So":[171],"unanswered":[175],"question":[176,192],"respective":[184],"relations":[185],"samples.":[188],"To":[189],"answer":[190],"we":[193,234],"study":[194],"detail":[199],"discuss":[201],"desirable":[202],"properties":[203],"measure":[207,240],"purpose.":[211],"We":[212],"focus":[213],"behavioral":[215],"compare":[220],"experimentally":[222],"evaluate":[223],"Based":[230],"our":[232],"results":[233],"identify":[235],"most":[237],"grouping":[242]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":2},{"year":2018,"cited_by_count":3},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":4},{"year":2015,"cited_by_count":3},{"year":2014,"cited_by_count":6},{"year":2013,"cited_by_count":5},{"year":2012,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
