{"id":"https://openalex.org/W2602324024","doi":"https://doi.org/10.1109/malware.2016.7888729","title":"Automatic extraction of malicious behaviors","display_name":"Automatic extraction of malicious behaviors","publication_year":2016,"publication_date":"2016-10-01","ids":{"openalex":"https://openalex.org/W2602324024","doi":"https://doi.org/10.1109/malware.2016.7888729","mag":"2602324024"},"language":"en","primary_location":{"id":"doi:10.1109/malware.2016.7888729","is_oa":false,"landing_page_url":"https://doi.org/10.1109/malware.2016.7888729","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2016 11th International Conference on Malicious and Unwanted Software (MALWARE)","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5109121593","display_name":"Khanh-Huu-The Dam","orcid":null},"institutions":[{"id":"https://openalex.org/I1294671590","display_name":"Centre National de la Recherche Scientifique","ror":"https://ror.org/02feahw73","country_code":"FR","type":"government","lineage":["https://openalex.org/I1294671590"]},{"id":"https://openalex.org/I169173203","display_name":"D\u00e9l\u00e9gation Paris 7","ror":"https://ror.org/00bw5n526","country_code":"FR","type":"government","lineage":["https://openalex.org/I154526488","https://openalex.org/I169173203"]},{"id":"https://openalex.org/I204730241","display_name":"Universit\u00e9 Paris Cit\u00e9","ror":"https://ror.org/05f82e368","country_code":"FR","type":"education","lineage":["https://openalex.org/I204730241"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Khanh-Huu-The Dam","raw_affiliation_strings":["IRIF, University Paris Diderot and CNRS"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IRIF, University Paris Diderot and CNRS","institution_ids":["https://openalex.org/I1294671590","https://openalex.org/I169173203","https://openalex.org/I204730241"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5044579457","display_name":"Tayssir Touili","orcid":"https://orcid.org/0000-0002-1134-2220"},"institutions":[{"id":"https://openalex.org/I1294671590","display_name":"Centre National de la Recherche Scientifique","ror":"https://ror.org/02feahw73","country_code":"FR","type":"government","lineage":["https://openalex.org/I1294671590"]},{"id":"https://openalex.org/I4210091279","display_name":"Universit\u00e9 Sorbonne Paris Nord","ror":"https://ror.org/0199hds37","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210091279"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Tayssir Touili","raw_affiliation_strings":["LIPN, CNRS and University Paris 13"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"LIPN, CNRS and University Paris 13","institution_ids":["https://openalex.org/I1294671590","https://openalex.org/I4210091279"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.6596,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.68927733,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"10"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9965999722480774,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9210801124572754},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8597720861434937},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.47314298152923584},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4444449245929718},{"id":"https://openalex.org/keywords/ransomware","display_name":"Ransomware","score":0.44402581453323364},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.42218077182769775},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.41737282276153564},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3766753077507019},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3349834084510803},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.19476714730262756},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.095142662525177}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9210801124572754},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8597720861434937},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.47314298152923584},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4444449245929718},{"id":"https://openalex.org/C2777667771","wikidata":"https://www.wikidata.org/wiki/Q926331","display_name":"Ransomware","level":3,"score":0.44402581453323364},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.42218077182769775},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.41737282276153564},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3766753077507019},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3349834084510803},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.19476714730262756},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.095142662525177},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/malware.2016.7888729","is_oa":false,"landing_page_url":"https://doi.org/10.1109/malware.2016.7888729","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2016 11th International Conference on Malicious and Unwanted Software (MALWARE)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":44,"referenced_works":["https://openalex.org/W62298501","https://openalex.org/W131049964","https://openalex.org/W1482214997","https://openalex.org/W1532325895","https://openalex.org/W1544225867","https://openalex.org/W1544837488","https://openalex.org/W1553801604","https://openalex.org/W1558357780","https://openalex.org/W1572855107","https://openalex.org/W1581009051","https://openalex.org/W1591374738","https://openalex.org/W1605436333","https://openalex.org/W1639956611","https://openalex.org/W1845054399","https://openalex.org/W1952910495","https://openalex.org/W1989626928","https://openalex.org/W1994676549","https://openalex.org/W2003094813","https://openalex.org/W2020184885","https://openalex.org/W2050918226","https://openalex.org/W2058470415","https://openalex.org/W2099053789","https://openalex.org/W2127969088","https://openalex.org/W2144112223","https://openalex.org/W2159676889","https://openalex.org/W2166924764","https://openalex.org/W2167671111","https://openalex.org/W2169889002","https://openalex.org/W2247654784","https://openalex.org/W2295755339","https://openalex.org/W2304489333","https://openalex.org/W2894041772","https://openalex.org/W2964051315","https://openalex.org/W4234200495","https://openalex.org/W4252076394","https://openalex.org/W6602539881","https://openalex.org/W6628905179","https://openalex.org/W6632679741","https://openalex.org/W6635142148","https://openalex.org/W6636253740","https://openalex.org/W6649033134","https://openalex.org/W6655500103","https://openalex.org/W6697196120","https://openalex.org/W6755516314"],"related_works":["https://openalex.org/W2469507153","https://openalex.org/W2964256930","https://openalex.org/W2008790809","https://openalex.org/W2768892939","https://openalex.org/W3164408430","https://openalex.org/W4285507391","https://openalex.org/W2397240470","https://openalex.org/W2602767565","https://openalex.org/W170652726","https://openalex.org/W4292056024"],"abstract_inverted_index":{"The":[0,16],"number":[1],"of":[2,26,83,95,135,148],"new":[3],"malwares":[4,158],"is":[5,11],"increasing":[6],"everyday.":[7],"Thus":[8],"malware":[9,20,130],"detection":[10,21,131,149],"nowadays":[12],"a":[13,23,54,68,133],"big":[14],"challenge.":[15],"existing":[17],"techniques":[18,115],"for":[19,100,129],"require":[22],"huge":[24],"effort":[25],"engineering":[27],"to":[28,46,80,155],"manually":[29],"extract":[30,48],"the":[31,49,64,75,81,86,93,118],"malicious":[32,50,65,69,76,89,101,126],"behaviors.":[33,51,102],"To":[34],"avoid":[35],"this":[36,42,105],"tedious":[37],"task,":[38],"we":[39,62,145,152],"propose":[40],"in":[41],"paper":[43],"an":[44,57],"approach":[45],"automatically":[47,124],"We":[52,72,103,121,139],"model":[53],"program":[55],"using":[56,67,132],"API":[58,70,90],"call":[59,91],"graph,":[60],"and":[61,88,109,161,178],"represent":[63],"behaviors":[66],"graph.":[71],"then":[73],"reduce":[74],"behavior":[77,127],"extraction":[78],"problem":[79,82],"retrieving":[84],"from":[85],"benign":[87],"graphs":[92],"set":[94],"subgraphs":[96],"that":[97,159],"are":[98],"relevant":[99],"solve":[104],"issue":[106],"by":[107],"applying":[108],"adapting":[110],"well-known":[111,160],"efficient":[112],"Information":[113],"Retrieval":[114],"based":[116],"on":[117],"TFIDF":[119],"scheme.":[120],"use":[122],"our":[123],"extracted":[125],"specification":[128],"kind":[134],"product":[136],"between":[137],"graphs.":[138],"obtained":[140],"interesting":[141],"experimental":[142],"results,":[143],"as":[144,166],"get":[146],"99.04%":[147],"rate.":[150],"Moreover,":[151],"were":[153],"able":[154],"detect":[156],"several":[157],"widely":[162],"used":[163],"antiviruses":[164],"such":[165],"Panda,":[167],"Avira,":[168],"Kaspersky,":[169],"Avast,":[170],"Qihoo-":[171],"360,":[172],"McAfee,":[173],"AVG,":[174],"BitDefender,":[175],"ESET-NOD32,":[176],"F-Secure,":[177],"Symantec":[179],"could":[180],"not":[181],"detect.":[182]},"counts_by_year":[{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":1},{"year":2018,"cited_by_count":3}],"updated_date":"2026-07-29T14:22:42.915294","created_date":"2025-10-10T00:00:00"}
