{"id":"https://openalex.org/W3113371616","doi":"https://doi.org/10.1145/3427228.3427256","title":"The Tangled Genealogy of IoT Malware","display_name":"The Tangled Genealogy of IoT Malware","publication_year":2020,"publication_date":"2020-12-07","ids":{"openalex":"https://openalex.org/W3113371616","doi":"https://doi.org/10.1145/3427228.3427256","mag":"3113371616"},"language":"en","primary_location":{"id":"doi:10.1145/3427228.3427256","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427256","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5109525581","display_name":"Emanuele Cozzi","orcid":null},"institutions":[{"id":"https://openalex.org/I1902872","display_name":"EURECOM","ror":"https://ror.org/00sse7z02","country_code":"FR","type":"education","lineage":["https://openalex.org/I1902872","https://openalex.org/I205703379"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Emanuele Cozzi","raw_affiliation_strings":["Eurecom, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Eurecom, France","institution_ids":["https://openalex.org/I1902872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110188430","display_name":"Pierre\u2010Antoine Vervier","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Pierre-Antoine Vervier","raw_affiliation_strings":["NortonLifeLock Research Group, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"NortonLifeLock Research Group, France","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027942683","display_name":"Matteo Dell\u2019Amico","orcid":"https://orcid.org/0000-0003-3152-4993"},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Matteo Dell'Amico","raw_affiliation_strings":["NortonLifeLock Research Group"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"NortonLifeLock Research Group","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050781579","display_name":"Yun Shen","orcid":"https://orcid.org/0000-0001-7863-8475"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yun Shen","raw_affiliation_strings":["NortonLifeLock Research Group, United Kingdom"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"NortonLifeLock Research Group, United Kingdom","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034154377","display_name":"Leyla Bilge","orcid":"https://orcid.org/0000-0002-8408-3741"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Leyla Bilge","raw_affiliation_strings":["NortonLifeLock Research Group, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"NortonLifeLock Research Group, France","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5002025561","display_name":"Davide Balzarotti","orcid":"https://orcid.org/0000-0001-5957-6213"},"institutions":[{"id":"https://openalex.org/I1902872","display_name":"EURECOM","ror":"https://ror.org/00sse7z02","country_code":"FR","type":"education","lineage":["https://openalex.org/I1902872","https://openalex.org/I205703379"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Davide Balzarotti","raw_affiliation_strings":["Eurecom, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Eurecom, France","institution_ids":["https://openalex.org/I1902872"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":7.5531,"has_fulltext":false,"cited_by_count":70,"citation_normalized_percentile":{"value":0.97586727,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"16"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9933000206947327,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9879000186920166,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9250024557113647},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.8614756464958191},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6981078386306763},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5004217624664307},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.4959276616573334},{"id":"https://openalex.org/keywords/sophistication","display_name":"Sophistication","score":0.4564135670661926},{"id":"https://openalex.org/keywords/scale","display_name":"Scale (ratio)","score":0.4522739350795746},{"id":"https://openalex.org/keywords/code-reuse","display_name":"Code reuse","score":0.4397363066673279},{"id":"https://openalex.org/keywords/reuse","display_name":"Reuse","score":0.41624781489372253},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.310219943523407},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.23716109991073608},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.18912050127983093},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.12821578979492188},{"id":"https://openalex.org/keywords/geography","display_name":"Geography","score":0.12224152684211731},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.12020260095596313}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9250024557113647},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.8614756464958191},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6981078386306763},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5004217624664307},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.4959276616573334},{"id":"https://openalex.org/C168725872","wikidata":"https://www.wikidata.org/wiki/Q991663","display_name":"Sophistication","level":2,"score":0.4564135670661926},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.4522739350795746},{"id":"https://openalex.org/C2778583558","wikidata":"https://www.wikidata.org/wiki/Q771245","display_name":"Code reuse","level":3,"score":0.4397363066673279},{"id":"https://openalex.org/C206588197","wikidata":"https://www.wikidata.org/wiki/Q846574","display_name":"Reuse","level":2,"score":0.41624781489372253},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.310219943523407},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.23716109991073608},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.18912050127983093},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.12821578979492188},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.12224152684211731},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.12020260095596313},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0},{"id":"https://openalex.org/C548081761","wikidata":"https://www.wikidata.org/wiki/Q180388","display_name":"Waste management","level":1,"score":0.0},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C58640448","wikidata":"https://www.wikidata.org/wiki/Q42515","display_name":"Cartography","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3427228.3427256","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427256","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},{"id":"pmh:oai:HAL:hal-04093093v1","is_oa":false,"landing_page_url":"https://hal.science/hal-04093093","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"ACSAC 2020, Annual Computer Security Applications Conference, 7-11 December 2020, Dec 2020, Austin, United States. pp.1-16, &#x27E8;10.1145/3427228.3427256&#x27E9;","raw_type":"Conference papers"},{"id":"pmh:oai:iris.unige.it:11567/1070906","is_oa":false,"landing_page_url":"https://hdl.handle.net/11567/1070906","pdf_url":null,"source":{"id":"https://openalex.org/S4377196291","display_name":"CINECA IRIS Institutial Research Information System (University of Genoa)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I83816512","host_organization_name":"University of Genoa","host_organization_lineage":["https://openalex.org/I83816512"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G7157196595","display_name":null,"funder_award_id":"771844 ? BitCrumbs","funder_id":"https://openalex.org/F4320338352","funder_display_name":"FP7 Ideas: European Research Council"}],"funders":[{"id":"https://openalex.org/F4320338352","display_name":"FP7 Ideas: European Research Council","ror":"https://ror.org/0472cxd90"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W149460151","https://openalex.org/W151377110","https://openalex.org/W844137998","https://openalex.org/W1548500763","https://openalex.org/W1591082683","https://openalex.org/W1669806660","https://openalex.org/W1673310716","https://openalex.org/W1827212170","https://openalex.org/W1910686388","https://openalex.org/W1999823999","https://openalex.org/W2018175892","https://openalex.org/W2046185165","https://openalex.org/W2052854541","https://openalex.org/W2057079516","https://openalex.org/W2110026675","https://openalex.org/W2121398530","https://openalex.org/W2132874238","https://openalex.org/W2138644293","https://openalex.org/W2145056020","https://openalex.org/W2514847810","https://openalex.org/W2515415680","https://openalex.org/W2602804099","https://openalex.org/W2740924709","https://openalex.org/W2748868501","https://openalex.org/W2794801050","https://openalex.org/W2890859663","https://openalex.org/W2892187814","https://openalex.org/W2963284996","https://openalex.org/W2963469388","https://openalex.org/W2963562762","https://openalex.org/W2981273440","https://openalex.org/W2999620626","https://openalex.org/W3023279601"],"related_works":["https://openalex.org/W2929621094","https://openalex.org/W1996006176","https://openalex.org/W4285325964","https://openalex.org/W2182697532","https://openalex.org/W1517387344","https://openalex.org/W1544062218","https://openalex.org/W185550498","https://openalex.org/W2348203156","https://openalex.org/W2226868092","https://openalex.org/W2164928043"],"abstract_inverted_index":{"The":[0,30],"recent":[1],"emergence":[2],"of":[3,12,23,37,65,85],"consumer":[4],"off-the-shelf":[5],"embedded":[6],"(IoT)":[7],"devices":[8],"and":[9,21,56,80],"the":[10,19,28,62,82],"rise":[11],"large-scale":[13],"IoT":[14,70],"botnets":[15],"has":[16,33],"dramatically":[17],"increased":[18],"volume":[20],"sophistication":[22],"Linux":[24],"malware":[25,71],"observed":[26],"in":[27],"wild.":[29],"security":[31],"community":[32],"put":[34],"a":[35],"lot":[36],"effort":[38],"to":[39,54,58,77],"document":[40],"these":[41],"threats":[42],"but":[43],"analysts":[44],"mostly":[45],"rely":[46],"on":[47],"manual":[48],"work,":[49],"which":[50],"makes":[51],"it":[52],"difficult":[53],"scale":[55],"hard":[57],"regularly":[59],"maintain.":[60],"Moreover,":[61],"vast":[63],"amount":[64],"code":[66],"reuse":[67],"that":[68],"characterizes":[69],"calls":[72],"for":[73],"an":[74],"automated":[75],"approach":[76],"detect":[78],"similarities":[79],"identify":[81],"phylogenetic":[83],"tree":[84],"each":[86],"family.":[87]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":10},{"year":2024,"cited_by_count":13},{"year":2023,"cited_by_count":14},{"year":2022,"cited_by_count":17},{"year":2021,"cited_by_count":14}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2020-12-21T00:00:00"}
