{"id":"https://openalex.org/W2120900307","doi":"https://doi.org/10.1145/1378600.1378626","title":"Behavioral detection of malware on mobile handsets","display_name":"Behavioral detection of malware on mobile handsets","publication_year":2008,"publication_date":"2008-06-17","ids":{"openalex":"https://openalex.org/W2120900307","doi":"https://doi.org/10.1145/1378600.1378626","mag":"2120900307"},"language":"en","primary_location":{"id":"doi:10.1145/1378600.1378626","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1378600.1378626","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 6th international conference on Mobile systems, applications, and services","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5108793690","display_name":"Abhijit Bose","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Abhijit Bose","raw_affiliation_strings":["IBM TJ Watson Research, Yorktown Heights, NY, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IBM TJ Watson Research, Yorktown Heights, NY, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101916473","display_name":"Xin Hu","orcid":"https://orcid.org/0000-0002-0114-1716"},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xin Hu","raw_affiliation_strings":["The University of Michigan, Ann Arbor, MI, USA","The University of Michigan , Ann Arbor , MI , USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]},{"raw_affiliation_string":"The University of Michigan , Ann Arbor , MI , USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053541912","display_name":"Kang G. Shin","orcid":"https://orcid.org/0000-0003-0086-8777"},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kang G. Shin","raw_affiliation_strings":["The University of Michigan, Ann Arbor, MI, USA","The University of Michigan , Ann Arbor , MI , USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]},{"raw_affiliation_string":"The University of Michigan , Ann Arbor , MI , USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101586319","display_name":"Taejoon Park","orcid":"https://orcid.org/0000-0002-7924-1776"},"institutions":[{"id":"https://openalex.org/I2250650973","display_name":"Samsung (South Korea)","ror":"https://ror.org/04w3jy968","country_code":"KR","type":"company","lineage":["https://openalex.org/I2250650973"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Taejoon Park","raw_affiliation_strings":["Samsung Electronics, Gyeonggi-Do, South Korea","Samsung Electronics, Gyeonggi-Do, South Korea#TAB#"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Samsung Electronics, Gyeonggi-Do, South Korea","institution_ids":["https://openalex.org/I2250650973"]},{"raw_affiliation_string":"Samsung Electronics, Gyeonggi-Do, South Korea#TAB#","institution_ids":["https://openalex.org/I2250650973"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":24.0267,"has_fulltext":false,"cited_by_count":278,"citation_normalized_percentile":{"value":0.99589233,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"225","last_page":"238"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9937000274658203,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8932791948318481},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8183587193489075},{"id":"https://openalex.org/keywords/handset","display_name":"Handset","score":0.6317110061645508},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.5628385543823242},{"id":"https://openalex.org/keywords/mobile-device","display_name":"Mobile device","score":0.5192018151283264},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.4848078787326813},{"id":"https://openalex.org/keywords/mobile-malware","display_name":"Mobile malware","score":0.4827098846435547},{"id":"https://openalex.org/keywords/support-vector-machine","display_name":"Support vector machine","score":0.4696829915046692},{"id":"https://openalex.org/keywords/behavioral-pattern","display_name":"Behavioral pattern","score":0.42172324657440186},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3413221836090088},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.32209229469299316},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.30915164947509766},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2007383108139038}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8932791948318481},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8183587193489075},{"id":"https://openalex.org/C2779971919","wikidata":"https://www.wikidata.org/wiki/Q1378949","display_name":"Handset","level":2,"score":0.6317110061645508},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.5628385543823242},{"id":"https://openalex.org/C186967261","wikidata":"https://www.wikidata.org/wiki/Q5082128","display_name":"Mobile device","level":2,"score":0.5192018151283264},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.4848078787326813},{"id":"https://openalex.org/C2780967490","wikidata":"https://www.wikidata.org/wiki/Q1291200","display_name":"Mobile malware","level":3,"score":0.4827098846435547},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.4696829915046692},{"id":"https://openalex.org/C83804111","wikidata":"https://www.wikidata.org/wiki/Q1063558","display_name":"Behavioral pattern","level":2,"score":0.42172324657440186},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3413221836090088},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.32209229469299316},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30915164947509766},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2007383108139038},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/1378600.1378626","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1378600.1378626","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 6th international conference on Mobile systems, applications, and services","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10","score":0.5899999737739563},{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.4099999964237213}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W740415","https://openalex.org/W1011453836","https://openalex.org/W1527422375","https://openalex.org/W1551618785","https://openalex.org/W1552906779","https://openalex.org/W1560724230","https://openalex.org/W1563088657","https://openalex.org/W1574862351","https://openalex.org/W1592090113","https://openalex.org/W1670263352","https://openalex.org/W1984773706","https://openalex.org/W1984845499","https://openalex.org/W1988194087","https://openalex.org/W1997810707","https://openalex.org/W2029224396","https://openalex.org/W2061022487","https://openalex.org/W2068011000","https://openalex.org/W2081938726","https://openalex.org/W2098691354","https://openalex.org/W2100238254","https://openalex.org/W2102399005","https://openalex.org/W2103396020","https://openalex.org/W2106649514","https://openalex.org/W2113755340","https://openalex.org/W2120617515","https://openalex.org/W2128217000","https://openalex.org/W2129281072","https://openalex.org/W2129860818","https://openalex.org/W2131523719","https://openalex.org/W2135143063","https://openalex.org/W2153635508","https://openalex.org/W2156909104","https://openalex.org/W2165184405","https://openalex.org/W2293069947","https://openalex.org/W2914982603","https://openalex.org/W3120421331","https://openalex.org/W3137220996","https://openalex.org/W4243868733","https://openalex.org/W6633127768","https://openalex.org/W7058071925"],"related_works":["https://openalex.org/W2538622067","https://openalex.org/W2181494682","https://openalex.org/W3114159050","https://openalex.org/W4245250093","https://openalex.org/W2609233367","https://openalex.org/W2484248966","https://openalex.org/W4244354662","https://openalex.org/W4200054778","https://openalex.org/W2777464647","https://openalex.org/W2965539362"],"abstract_inverted_index":{"A":[0],"novel":[1],"behavioral":[2,156],"detection":[3,157],"framework":[4],"is":[5],"proposed":[6],"to":[7],"detect":[8],"mobile":[9,24,80,161,195],"worms,":[10],"viruses":[11,81,162],"and":[12,82,95,116,150,163,176],"Trojans,":[13],"instead":[14],"of":[15,32,44,68,79,127,133,179],"the":[16,41,52,85,89,112,124,130,174,181],"signature-based":[17],"solutions":[18],"currently":[19],"available":[20],"for":[21,191],"use":[22],"in":[23,119,194],"devices.":[25,196],"First,":[26],"we":[27,64,99],"propose":[28,100],"an":[29,45],"efficient":[30],"representation":[31],"malware":[33,128,152],"behaviors":[34],"based":[35,139],"on":[36,140,147],"a":[37,66,101,137],"key":[38],"observation":[39],"that":[40,105,155,173],"logical":[42],"ordering":[43],"application's":[46],"actions":[47],"over":[48],"time":[49,175],"often":[50],"reveals":[51],"malicious":[53,69,125],"intent":[54],"even":[55],"when":[56],"each":[57],"action":[58],"alone":[59],"may":[60],"appear":[61],"harmless.":[62],"Then,":[63],"generate":[65],"database":[67],"behavior":[70,126,132,182],"signatures":[71,108,183],"by":[72,135],"studying":[73],"more":[74,166],"than":[75,167],"25":[76],"distinct":[77],"families":[78],"worms":[83,164],"targeting":[84],"Symbian":[86,120],"OS":[87,93],"-":[88,94],"most":[90],"widely-deployed":[91],"handset":[92],"their":[96,192],"variants.":[97],"Next,":[98],"two-stage":[102],"mapping":[103],"technique":[104],"constructs":[106],"these":[107],"at":[109],"run-time":[110],"from":[111,129,184],"monitored":[113],"system":[114],"events":[115],"API":[117,186],"calls":[118,187],"OS.":[121],"We":[122,170],"discriminate":[123],"normal":[131],"applications":[134],"training":[136],"classifier":[138],"Support":[141],"Vector":[142],"Machines":[143],"(SVMs).":[144],"Our":[145],"evaluation":[146],"both":[148],"simulated":[149],"real-world":[151],"samples":[153],"indicates":[154],"can":[158],"identify":[159],"current":[160],"with":[165],"96%":[168],"accuracy.":[169],"also":[171],"find":[172],"resource":[177],"overheads":[178],"constructing":[180],"low-level":[185],"are":[188],"acceptably":[189],"low":[190],"deployment":[193]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":10},{"year":2019,"cited_by_count":9},{"year":2018,"cited_by_count":14},{"year":2017,"cited_by_count":16},{"year":2016,"cited_by_count":13},{"year":2015,"cited_by_count":30},{"year":2014,"cited_by_count":40},{"year":2013,"cited_by_count":38},{"year":2012,"cited_by_count":33}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
