{"id":"https://openalex.org/W2145969515","doi":"https://doi.org/10.1145/2590296.2590309","title":"Detection of stealthy malware activities with traffic causality and scalable triggering relation discovery","display_name":"Detection of stealthy malware activities with traffic causality and scalable triggering relation discovery","publication_year":2014,"publication_date":"2014-05-30","ids":{"openalex":"https://openalex.org/W2145969515","doi":"https://doi.org/10.1145/2590296.2590309","mag":"2145969515"},"language":"en","primary_location":{"id":"doi:10.1145/2590296.2590309","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2590296.2590309","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 9th ACM symposium on Information, computer and communications security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100397061","display_name":"Hao Zhang","orcid":"https://orcid.org/0000-0003-3877-7512"},"institutions":[{"id":"https://openalex.org/I859038795","display_name":"Virginia Tech","ror":"https://ror.org/02smfhw86","country_code":"US","type":"education","lineage":["https://openalex.org/I859038795"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Hao Zhang","raw_affiliation_strings":["Virginia Tech, Blacksburg, VA, USA","Virginia Tech, , Blacksburg, VA, USA"],"affiliations":[{"raw_affiliation_string":"Virginia Tech, Blacksburg, VA, USA","institution_ids":["https://openalex.org/I859038795"]},{"raw_affiliation_string":"Virginia Tech, , Blacksburg, VA, USA","institution_ids":["https://openalex.org/I859038795"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034366344","display_name":"Danfeng Yao","orcid":"https://orcid.org/0000-0001-8969-2792"},"institutions":[{"id":"https://openalex.org/I859038795","display_name":"Virginia Tech","ror":"https://ror.org/02smfhw86","country_code":"US","type":"education","lineage":["https://openalex.org/I859038795"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Danfeng Daphne Yao","raw_affiliation_strings":["Virginia Tech, Blacksburg, VA, USA","Virginia Tech, , Blacksburg, VA, USA"],"affiliations":[{"raw_affiliation_string":"Virginia Tech, Blacksburg, VA, USA","institution_ids":["https://openalex.org/I859038795"]},{"raw_affiliation_string":"Virginia Tech, , Blacksburg, VA, USA","institution_ids":["https://openalex.org/I859038795"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5035052603","display_name":"Naren Ramakrishnan","orcid":"https://orcid.org/0000-0002-1821-9743"},"institutions":[{"id":"https://openalex.org/I859038795","display_name":"Virginia Tech","ror":"https://ror.org/02smfhw86","country_code":"US","type":"education","lineage":["https://openalex.org/I859038795"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Naren Ramakrishnan","raw_affiliation_strings":["Virginia Tech, Blacksburg, VA, USA","Virginia Tech, , Blacksburg, VA, USA"],"affiliations":[{"raw_affiliation_string":"Virginia Tech, Blacksburg, VA, USA","institution_ids":["https://openalex.org/I859038795"]},{"raw_affiliation_string":"Virginia Tech, , Blacksburg, VA, USA","institution_ids":["https://openalex.org/I859038795"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5100397061"],"corresponding_institution_ids":["https://openalex.org/I859038795"],"apc_list":null,"apc_paid":null,"fwci":11.5109,"has_fulltext":false,"cited_by_count":56,"citation_normalized_percentile":{"value":0.98670884,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"39","last_page":"50"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8448237776756287},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.779991626739502},{"id":"https://openalex.org/keywords/relation","display_name":"Relation (database)","score":0.6753655672073364},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6723913550376892},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.6034873723983765},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.4963381886482239},{"id":"https://openalex.org/keywords/causality","display_name":"Causality (physics)","score":0.49594172835350037},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4565325677394867},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.4126582145690918},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4028412401676178},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.07555705308914185}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8448237776756287},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.779991626739502},{"id":"https://openalex.org/C25343380","wikidata":"https://www.wikidata.org/wiki/Q277521","display_name":"Relation (database)","level":2,"score":0.6753655672073364},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6723913550376892},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.6034873723983765},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.4963381886482239},{"id":"https://openalex.org/C64357122","wikidata":"https://www.wikidata.org/wiki/Q1149766","display_name":"Causality (physics)","level":2,"score":0.49594172835350037},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4565325677394867},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.4126582145690918},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4028412401676178},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.07555705308914185},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/2590296.2590309","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2590296.2590309","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 9th ACM symposium on Information, computer and communications security","raw_type":"proceedings-article"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.644.8381","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.644.8381","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://people.cs.vt.edu/~ramakris/papers/asia075-yaoATSFG1.pdf","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.713.163","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.713.163","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://people.cs.vt.edu/danfeng/papers/Traffic-Triggering-Relation-Discovery-ASIACCS14-Yao.pdf","raw_type":"text"},{"id":"pmh:oai:vtechworks.lib.vt.edu:10919/87831","is_oa":false,"landing_page_url":"http://hdl.handle.net/10919/87831","pdf_url":null,"source":{"id":"https://openalex.org/S4306400248","display_name":"VTechWorks (Virginia Tech)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I859038795","host_organization_name":"Virginia Tech","host_organization_lineage":["https://openalex.org/I859038795"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"utility"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7699999809265137,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G7325303688","display_name":null,"funder_award_id":"CNS-0953638","funder_id":"https://openalex.org/F4320337388","funder_display_name":"Division of Computer and Network Systems"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320337388","display_name":"Division of Computer and Network Systems","ror":"https://ror.org/02rdzmk74"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":54,"referenced_works":["https://openalex.org/W47175211","https://openalex.org/W167016754","https://openalex.org/W1233141674","https://openalex.org/W1484012142","https://openalex.org/W1502099332","https://openalex.org/W1517710060","https://openalex.org/W1523185445","https://openalex.org/W1526879126","https://openalex.org/W1541722909","https://openalex.org/W1588651819","https://openalex.org/W1633185320","https://openalex.org/W1660390307","https://openalex.org/W1775772884","https://openalex.org/W1861453724","https://openalex.org/W1884606608","https://openalex.org/W1912123407","https://openalex.org/W1954903228","https://openalex.org/W1956767865","https://openalex.org/W1964731129","https://openalex.org/W1970867218","https://openalex.org/W1975411458","https://openalex.org/W1988741337","https://openalex.org/W1989598342","https://openalex.org/W1995412393","https://openalex.org/W2017102965","https://openalex.org/W2031489231","https://openalex.org/W2037933327","https://openalex.org/W2040431736","https://openalex.org/W2042454716","https://openalex.org/W2044675702","https://openalex.org/W2073089243","https://openalex.org/W2076438261","https://openalex.org/W2078417425","https://openalex.org/W2081980144","https://openalex.org/W2096118443","https://openalex.org/W2106188980","https://openalex.org/W2107569009","https://openalex.org/W2119821739","https://openalex.org/W2120665430","https://openalex.org/W2124380089","https://openalex.org/W2127577941","https://openalex.org/W2148847267","https://openalex.org/W2149668059","https://openalex.org/W2156165192","https://openalex.org/W2245026288","https://openalex.org/W2247654784","https://openalex.org/W2272631739","https://openalex.org/W2350778671","https://openalex.org/W2914982603","https://openalex.org/W3150719513","https://openalex.org/W4240946707","https://openalex.org/W4256361765","https://openalex.org/W6606837198","https://openalex.org/W6676167480"],"related_works":["https://openalex.org/W4366249425","https://openalex.org/W2900235625","https://openalex.org/W2053293719","https://openalex.org/W2105631555","https://openalex.org/W2461970972","https://openalex.org/W3083187169","https://openalex.org/W2594153842","https://openalex.org/W2849301851","https://openalex.org/W2990396213","https://openalex.org/W2902215642"],"abstract_inverted_index":{"Studies":[0],"show":[1],"that":[2,48],"a":[3,44,55,67,93],"significant":[4],"portion":[5],"of":[6,66,70,82,96,100,121,130],"networked":[7],"computers":[8],"are":[9,31,35],"infected":[10],"with":[11],"stealthy":[12,88],"malware.":[13],"Infection":[14],"allows":[15],"remote":[16],"attackers":[17],"to":[18,37,78,86],"control,":[19],"utilize,":[20],"or":[21,28],"spy":[22],"on":[23,54,107,127],"victim":[24],"machines.":[25],"Conventional":[26],"signature-scan":[27],"counting-based":[29],"techniques":[30],"limited,":[32],"as":[33],"they":[34],"unable":[36],"stop":[38],"new":[39,58,94],"zero-day":[40],"exploits.":[41],"We":[42,73,91],"describe":[43],"traffic":[45,120],"analysis":[46],"method":[47],"can":[49],"effectively":[50],"detect":[51],"malware":[52,89],"activities":[53],"host.":[56],"Our":[57,103,113],"approach":[59],"efficiently":[60],"discovers":[61],"the":[62,80,128],"underlying":[63],"triggering":[64,76,97,132],"relations":[65,77],"massive":[68],"amount":[69],"network":[71,83,101],"events.":[72,102],"use":[74],"these":[75],"reason":[79],"occurrences":[81],"events":[84],"and":[85],"pinpoint":[87],"activities.":[90],"define":[92],"problem":[95],"relation":[98,133],"discovery":[99],"solution":[104],"is":[105],"based":[106],"domain-knowledge":[108],"guided":[109],"advanced":[110],"learning":[111],"algorithms.":[112],"extensive":[114],"experimental":[115],"evaluation":[116],"involving":[117],"6+":[118],"GB":[119],"various":[122],"types":[123],"shows":[124],"promising":[125],"results":[126],"accuracy":[129],"our":[131],"discovery.":[134]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":11},{"year":2017,"cited_by_count":9},{"year":2016,"cited_by_count":11},{"year":2015,"cited_by_count":7},{"year":2014,"cited_by_count":5}],"updated_date":"2026-04-05T17:49:38.594831","created_date":"2025-10-10T00:00:00"}
