{"id":"https://openalex.org/W2049208027","doi":"https://doi.org/10.1145/2382196.2382217","title":"Aligot","display_name":"Aligot","publication_year":2012,"publication_date":"2012-10-15","ids":{"openalex":"https://openalex.org/W2049208027","doi":"https://doi.org/10.1145/2382196.2382217","mag":"2049208027"},"language":"en","primary_location":{"id":"doi:10.1145/2382196.2382217","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2382196.2382217","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2012 ACM conference on Computer and communications security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5002841791","display_name":"Joan Vivancos Calvet","orcid":"https://orcid.org/0000-0001-7180-6990"},"institutions":[{"id":"https://openalex.org/I4210121838","display_name":"Laboratoire Lorrain de Recherche en Informatique et ses Applications","ror":"https://ror.org/02vnf0c38","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I1294671590","https://openalex.org/I1326498283","https://openalex.org/I277688954","https://openalex.org/I4210107720","https://openalex.org/I4210121838","https://openalex.org/I4210159245","https://openalex.org/I90183372"]},{"id":"https://openalex.org/I90183372","display_name":"Universit\u00e9 de Lorraine","ror":"https://ror.org/04vfs2w97","country_code":"FR","type":"education","lineage":["https://openalex.org/I90183372"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Joan Calvet","raw_affiliation_strings":["Universite de Lorraine, LORIA, Nancy, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Universite de Lorraine, LORIA, Nancy, France","institution_ids":["https://openalex.org/I90183372","https://openalex.org/I4210121838"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067704386","display_name":"Jos\u00e9 M. Fernandez","orcid":"https://orcid.org/0000-0001-9836-3595"},"institutions":[{"id":"https://openalex.org/I45683168","display_name":"Polytechnique Montr\u00e9al","ror":"https://ror.org/05f8d4e86","country_code":"CA","type":"education","lineage":["https://openalex.org/I45683168"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Jos\u00e9 M. Fernandez","raw_affiliation_strings":["Ecole Polytechnique de Montreal, Montreal, Canada","Ecole Polytechnique de Montreal , Montreal , Canada"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Ecole Polytechnique de Montreal, Montreal, Canada","institution_ids":["https://openalex.org/I45683168"]},{"raw_affiliation_string":"Ecole Polytechnique de Montreal , Montreal , Canada","institution_ids":["https://openalex.org/I45683168"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5106028817","display_name":"Jean-Yves Marion","orcid":"https://orcid.org/0009-0002-8262-3887"},"institutions":[{"id":"https://openalex.org/I4210121838","display_name":"Laboratoire Lorrain de Recherche en Informatique et ses Applications","ror":"https://ror.org/02vnf0c38","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I1294671590","https://openalex.org/I1326498283","https://openalex.org/I277688954","https://openalex.org/I4210107720","https://openalex.org/I4210121838","https://openalex.org/I4210159245","https://openalex.org/I90183372"]},{"id":"https://openalex.org/I90183372","display_name":"Universit\u00e9 de Lorraine","ror":"https://ror.org/04vfs2w97","country_code":"FR","type":"education","lineage":["https://openalex.org/I90183372"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Jean-Yves Marion","raw_affiliation_strings":["Universite de Lorraine, LORIA, Nancy, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Universite de Lorraine, LORIA, Nancy, France","institution_ids":["https://openalex.org/I90183372","https://openalex.org/I4210121838"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.706,"has_fulltext":false,"cited_by_count":71,"citation_normalized_percentile":{"value":0.9660406,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"169","last_page":"182"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8334087133407593},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.7372028827667236},{"id":"https://openalex.org/keywords/payload","display_name":"Payload (computing)","score":0.7032343149185181},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.6706057190895081},{"id":"https://openalex.org/keywords/cryptographic-primitive","display_name":"Cryptographic primitive","score":0.6240463256835938},{"id":"https://openalex.org/keywords/identification","display_name":"Identification (biology)","score":0.5648627877235413},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.5106299519538879},{"id":"https://openalex.org/keywords/implementation","display_name":"Implementation","score":0.4904443919658661},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.46373191475868225},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.33354753255844116},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.29548022150993347},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.28163111209869385},{"id":"https://openalex.org/keywords/cryptographic-protocol","display_name":"Cryptographic protocol","score":0.25471001863479614},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.07321450114250183}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8334087133407593},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.7372028827667236},{"id":"https://openalex.org/C134066672","wikidata":"https://www.wikidata.org/wiki/Q1424639","display_name":"Payload (computing)","level":3,"score":0.7032343149185181},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.6706057190895081},{"id":"https://openalex.org/C15927051","wikidata":"https://www.wikidata.org/wiki/Q246593","display_name":"Cryptographic primitive","level":4,"score":0.6240463256835938},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.5648627877235413},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.5106299519538879},{"id":"https://openalex.org/C26713055","wikidata":"https://www.wikidata.org/wiki/Q245962","display_name":"Implementation","level":2,"score":0.4904443919658661},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.46373191475868225},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.33354753255844116},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.29548022150993347},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.28163111209869385},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.25471001863479614},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.07321450114250183},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/2382196.2382217","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2382196.2382217","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2012 ACM conference on Computer and communications security","raw_type":"proceedings-article"},{"id":"pmh:oai:publications.polymtl.ca:15708","is_oa":false,"landing_page_url":"https://publications.polymtl.ca/15708/","pdf_url":null,"source":{"id":"https://openalex.org/S4306401013","display_name":"PolyPublie (\u00c9cole Polytechnique de Montr\u00e9al)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I45683168","host_organization_name":"Polytechnique Montr\u00e9al","host_organization_lineage":["https://openalex.org/I45683168"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Communication de conf\u00e9rence"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":22,"referenced_works":["https://openalex.org/W2440755","https://openalex.org/W89505464","https://openalex.org/W126407768","https://openalex.org/W1513250879","https://openalex.org/W1543331277","https://openalex.org/W1553308705","https://openalex.org/W1572300106","https://openalex.org/W1996360405","https://openalex.org/W2002089154","https://openalex.org/W2002821154","https://openalex.org/W2004814164","https://openalex.org/W2109394932","https://openalex.org/W2115351238","https://openalex.org/W2132271754","https://openalex.org/W2133271279","https://openalex.org/W2134633067","https://openalex.org/W2136331433","https://openalex.org/W2156453323","https://openalex.org/W2175377689","https://openalex.org/W4232836212","https://openalex.org/W4302339081","https://openalex.org/W6630859158"],"related_works":["https://openalex.org/W4249009605","https://openalex.org/W2900526031","https://openalex.org/W2395100307","https://openalex.org/W3183826413","https://openalex.org/W4243179955","https://openalex.org/W2968504645","https://openalex.org/W2909615516","https://openalex.org/W2557742076","https://openalex.org/W4234891089","https://openalex.org/W1956767865"],"abstract_inverted_index":{"Analyzing":[0],"cryptographic":[1,36,54,111,132,141],"implementations":[2,30,87],"has":[3],"important":[4],"applications,":[5],"especially":[6],"for":[7,47],"malware":[8,19,48,162],"analysis":[9],"where":[10],"they":[11,63],"are":[12,31,64,71],"an":[13,122],"integral":[14],"part":[15],"both":[16,148],"of":[17,52,77,94,130],"the":[18,22,50,60,75,90,95,140],"payload":[20],"and":[21,125,146,158,168],"unpacking":[23],"code":[24],"that":[25,62,105],"decrypts":[26],"this":[27,99,107],"payload.":[28],"These":[29],"often":[32],"based":[33],"on":[34],"well-known":[35],"functions,":[37],"whose":[38],"description":[39],"is":[40,56],"publicly":[41],"available.":[42],"While":[43],"potentially":[44],"very":[45],"useful":[46],"analysis,":[49],"identification":[51,69],"such":[53,184],"primitives":[55],"made":[57],"difficult":[58],"by":[59,116,153],"fact":[61,108],"usually":[65],"obfuscated.":[66],"Current":[67],"state-of-the-art":[68],"tools":[70],"ineffective":[72],"due":[73],"to":[74,109,176],"absence":[76],"easily":[78],"identifiable":[79],"static":[80],"features":[81],"in":[82,113,121,149,159,181],"obfuscated":[83,114,161],"code.":[84],"However,":[85],"these":[86],"still":[88],"maintain":[89],"input-output":[91],"(I/O)":[92],"relationship":[93],"original":[96],"function.":[97],"In":[98,134,170],"paper,":[100],"we":[101,137],"present":[102],"a":[103,154],"tool":[104,173],"leverages":[106],"identify":[110],"functions":[112,142],"programs,":[115],"retrieving":[117],"their":[118],"I/O":[119],"parameters":[120],"implementation-independent":[123],"fashion,":[124],"comparing":[126],"them":[127],"with":[128],"those":[129],"known":[131],"functions.":[133],"experimental":[135],"evaluation,":[136],"successfully":[138],"identified":[139],"TEA,":[143],"RC4,":[144],"AES":[145],"MD5":[147],"synthetic":[150],"examples":[151],"protected":[152],"commercial-grade":[155],"packer":[156],"(AsProtect),":[157],"several":[160],"samples":[163],"(Sality,":[164],"Waledac,":[165],"Storm":[166],"Worm":[167],"SilentBanker).":[169],"addition,":[171],"our":[172],"was":[174],"able":[175],"recognize":[177],"basic":[178],"operations":[179],"done":[180],"asymmetric":[182],"ciphers":[183],"as":[185],"RSA.":[186]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":7},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":12},{"year":2017,"cited_by_count":8},{"year":2016,"cited_by_count":6},{"year":2015,"cited_by_count":9},{"year":2014,"cited_by_count":4},{"year":2013,"cited_by_count":5},{"year":2012,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2016-06-24T00:00:00"}
