{"id":"https://openalex.org/W3168412632","doi":"https://doi.org/10.1109/syscon48628.2021.9447094","title":"Malware System Calls Detection Using Hybrid System","display_name":"Malware System Calls Detection Using Hybrid System","publication_year":2021,"publication_date":"2021-04-15","ids":{"openalex":"https://openalex.org/W3168412632","doi":"https://doi.org/10.1109/syscon48628.2021.9447094","mag":"3168412632"},"language":"en","primary_location":{"id":"doi:10.1109/syscon48628.2021.9447094","is_oa":false,"landing_page_url":"https://doi.org/10.1109/syscon48628.2021.9447094","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Systems Conference (SysCon)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102826639","display_name":"Yue Guan","orcid":"https://orcid.org/0000-0002-9979-5901"},"institutions":[{"id":"https://openalex.org/I186803428","display_name":"Brock University","ror":"https://ror.org/056am2717","country_code":"CA","type":"education","lineage":["https://openalex.org/I186803428"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Yue Guan","raw_affiliation_strings":["Brock University, St.Catharines, Canada"],"affiliations":[{"raw_affiliation_string":"Brock University, St.Catharines, Canada","institution_ids":["https://openalex.org/I186803428"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5019537475","display_name":"Naser Ezzati\u2010Jivan","orcid":"https://orcid.org/0000-0003-1435-6297"},"institutions":[{"id":"https://openalex.org/I186803428","display_name":"Brock University","ror":"https://ror.org/056am2717","country_code":"CA","type":"education","lineage":["https://openalex.org/I186803428"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Naser Ezzati-Jivan","raw_affiliation_strings":["Brock University, St.Catharines, Canada"],"affiliations":[{"raw_affiliation_string":"Brock University, St.Catharines, Canada","institution_ids":["https://openalex.org/I186803428"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5102826639"],"corresponding_institution_ids":["https://openalex.org/I186803428"],"apc_list":null,"apc_paid":null,"fwci":0.9547,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.76576323,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8088263273239136},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7826265096664429},{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.7436341047286987},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.741564154624939},{"id":"https://openalex.org/keywords/anomaly-based-intrusion-detection-system","display_name":"Anomaly-based intrusion detection system","score":0.7395917773246765},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7342053651809692},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5432930588722229},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.5364227294921875},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4270384907722473},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3918522000312805},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.37549132108688354},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.21932607889175415}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8088263273239136},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7826265096664429},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.7436341047286987},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.741564154624939},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.7395917773246765},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7342053651809692},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5432930588722229},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.5364227294921875},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4270384907722473},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3918522000312805},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.37549132108688354},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.21932607889175415},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/syscon48628.2021.9447094","is_oa":false,"landing_page_url":"https://doi.org/10.1109/syscon48628.2021.9447094","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Systems Conference (SysCon)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9","score":0.6499999761581421}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":43,"referenced_works":["https://openalex.org/W641864578","https://openalex.org/W1488532897","https://openalex.org/W1499064909","https://openalex.org/W1554085250","https://openalex.org/W1565377632","https://openalex.org/W1583975142","https://openalex.org/W1627728918","https://openalex.org/W1649901946","https://openalex.org/W1866240378","https://openalex.org/W2007087405","https://openalex.org/W2019014808","https://openalex.org/W2038045252","https://openalex.org/W2053757129","https://openalex.org/W2076063813","https://openalex.org/W2093488494","https://openalex.org/W2104593144","https://openalex.org/W2105557138","https://openalex.org/W2119463329","https://openalex.org/W2122646361","https://openalex.org/W2128217000","https://openalex.org/W2129860818","https://openalex.org/W2138209477","https://openalex.org/W2146082061","https://openalex.org/W2150355110","https://openalex.org/W2154579873","https://openalex.org/W2156909104","https://openalex.org/W2482589566","https://openalex.org/W2521815480","https://openalex.org/W2551087083","https://openalex.org/W2594266659","https://openalex.org/W2911153497","https://openalex.org/W2946132891","https://openalex.org/W2963403868","https://openalex.org/W2963769791","https://openalex.org/W3136767761","https://openalex.org/W3161875877","https://openalex.org/W4234038454","https://openalex.org/W4234845324","https://openalex.org/W4385245566","https://openalex.org/W6629175646","https://openalex.org/W6634829514","https://openalex.org/W6681721004","https://openalex.org/W6739901393"],"related_works":["https://openalex.org/W2439951656","https://openalex.org/W2337148208","https://openalex.org/W3004832009","https://openalex.org/W3036013726","https://openalex.org/W1969635302","https://openalex.org/W2183313954","https://openalex.org/W11100131","https://openalex.org/W1805274772","https://openalex.org/W3146948916","https://openalex.org/W2148459958"],"abstract_inverted_index":{"Due":[0],"to":[1,12,53,121,171],"the":[2,10,23,54,64,81,86,107,114,158,173,177],"rapid":[3],"and":[4,16,36,92,111,140],"continuous":[5],"increase":[6],"of":[7,66,77,116,149,169],"network":[8],"intrusion,":[9],"need":[11],"protect":[13],"computer":[14],"systems":[15,24],"underlying":[17],"infrastructure":[18],"becomes":[19,39],"inevitable.":[20],"Beside":[21],"this,":[22],"have":[25],"additionally":[26],"gotten":[27],"extremely":[28],"intricate":[29],"as":[30],"they":[31],"fill":[32],"in":[33,85,176],"both":[34],"scale":[35],"usefulness;hence,intrusion/anomaly":[37],"detection":[38,45,127],"essential.":[40],"The":[41],"intrusion":[42],"or":[43],"anomaly":[44,68],"poses":[46],"several":[47],"challenges":[48],"including":[49],"data":[50,108],"collections":[51],"due":[52],"inherent":[55],"datasets":[56,79],"imbalance,":[57],"caused":[58],"by":[59],"systems'":[60],"reliability":[61],"requirements":[62],"causing":[63],"event":[65],"an":[67,98],"a":[69,74,93,122,131,147,150,167],"irregularity":[70],"phenomenon.":[71],"Therefore,":[72],"only":[73],"small":[75],"percentage":[76],"available":[78],"captures":[80],"anomaly,":[82],"which":[83],"brings":[84],"second":[87],"challenge,":[88],"i.e,":[89],"model":[90,162],"selection,":[91],"specific":[94],"approach":[95,133],"for":[96],"detecting":[97],"anomaly.":[99],"While":[100],"much":[101],"research":[102],"has":[103],"been":[104],"concentrated":[105],"on":[106,135],"collection":[109],"part":[110],"statistical":[112],"techniques,":[113],"focus":[115],"this":[117],"work":[118],"is":[119,163],"devoted":[120],"multi-module":[123],"system":[124,151],"call":[125,152],"anomalies":[126],"technique.":[128],"We":[129],"propose":[130],"novel":[132],"based":[134],"Long":[136],"Short":[137],"Term":[138],"Memory(LSTM)":[139],"attention":[141],"using":[142],"transformers":[143],"that":[144,157],"can":[145],"learn":[146],"sequence":[148],"efficiently.":[153],"Experimental":[154],"results":[155],"showed":[156],"proposed":[159],"deep":[160],"learning":[161],"92.6%":[164],"precise":[165],"with":[166],"recall":[168],"93.8%":[170],"classify":[172],"malicious":[174],"process":[175],"system.":[178]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":2}],"updated_date":"2026-03-15T09:29:46.208133","created_date":"2025-10-10T00:00:00"}
