{"id":"https://openalex.org/W3166061103","doi":"https://doi.org/10.1145/3433210.3453101","title":"MalPhase: Fine-Grained Malware Detection Using Network Flow Data","display_name":"MalPhase: Fine-Grained Malware Detection Using Network Flow Data","publication_year":2021,"publication_date":"2021-05-24","ids":{"openalex":"https://openalex.org/W3166061103","doi":"https://doi.org/10.1145/3433210.3453101","mag":"3166061103"},"language":"en","primary_location":{"id":"doi:10.1145/3433210.3453101","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3433210.3453101","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2106.00541","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Michal Piskozub","orcid":null},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Michal Piskozub","raw_affiliation_strings":["University of Oxford, Oxford, United Kingdom"],"affiliations":[{"raw_affiliation_string":"University of Oxford, Oxford, United Kingdom","institution_ids":["https://openalex.org/I40120149"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Fabio De Gaspari","orcid":null},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Fabio De Gaspari","raw_affiliation_strings":["Sapienza University of Rome, Rome, Italy"],"affiliations":[{"raw_affiliation_string":"Sapienza University of Rome, Rome, Italy","institution_ids":["https://openalex.org/I861853513"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Freddie Barr-Smith","orcid":null},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Freddie Barr-Smith","raw_affiliation_strings":["University of Oxford, Oxford, United Kingdom"],"affiliations":[{"raw_affiliation_string":"University of Oxford, Oxford, United Kingdom","institution_ids":["https://openalex.org/I40120149"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Luigi Mancini","orcid":null},"institutions":[{"id":"https://openalex.org/I861853513","display_name":"Sapienza University of Rome","ror":"https://ror.org/02be6w209","country_code":"IT","type":"education","lineage":["https://openalex.org/I861853513"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Luigi Mancini","raw_affiliation_strings":["Sapienza University of Rome, Rome, Italy"],"affiliations":[{"raw_affiliation_string":"Sapienza University of Rome, Rome, Italy","institution_ids":["https://openalex.org/I861853513"]}]},{"author_position":"last","author":{"id":null,"display_name":"Ivan Martinovic","orcid":null},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Ivan Martinovic","raw_affiliation_strings":["University of Oxford, Oxford, United Kingdom"],"affiliations":[{"raw_affiliation_string":"University of Oxford, Oxford, United Kingdom","institution_ids":["https://openalex.org/I40120149"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I40120149"],"apc_list":null,"apc_paid":null,"fwci":3.3447,"has_fulltext":true,"cited_by_count":29,"citation_normalized_percentile":{"value":0.92291307,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"774","last_page":"786"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8773000240325928},{"id":"https://openalex.org/keywords/flow-network","display_name":"Flow network","score":0.5027999877929688},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.4823000133037567},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4447000026702881},{"id":"https://openalex.org/keywords/categorization","display_name":"Categorization","score":0.4237000048160553},{"id":"https://openalex.org/keywords/data-set","display_name":"Data set","score":0.3725999891757965},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.35850000381469727},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.3546000123023987}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8773000240325928},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.76419997215271},{"id":"https://openalex.org/C114809511","wikidata":"https://www.wikidata.org/wiki/Q1412924","display_name":"Flow network","level":2,"score":0.5027999877929688},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4966999888420105},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.4823000133037567},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4496999979019165},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4447000026702881},{"id":"https://openalex.org/C94124525","wikidata":"https://www.wikidata.org/wiki/Q912550","display_name":"Categorization","level":2,"score":0.4237000048160553},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.40849998593330383},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.3725999891757965},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.35850000381469727},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.3546000123023987},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.32030001282691956},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.3140999972820282},{"id":"https://openalex.org/C75684735","wikidata":"https://www.wikidata.org/wiki/Q858810","display_name":"Big data","level":2,"score":0.29899999499320984},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.2985999882221222},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.2919999957084656},{"id":"https://openalex.org/C193415008","wikidata":"https://www.wikidata.org/wiki/Q639681","display_name":"Network architecture","level":2,"score":0.28940001130104065},{"id":"https://openalex.org/C29122968","wikidata":"https://www.wikidata.org/wiki/Q1414816","display_name":"Incentive","level":2,"score":0.27630001306533813},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.27230000495910645},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.2662999927997589},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.25200000405311584}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/3433210.3453101","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3433210.3453101","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2106.00541","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2106.00541","pdf_url":"https://arxiv.org/pdf/2106.00541","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:zenodo.org:5095391","is_oa":true,"landing_page_url":"https://zenodo.org/record/5095391","pdf_url":"https://zenodo.org/record/5095391","source":{"id":"https://openalex.org/S4306400562","display_name":"Zenodo (CERN European Organization for Nuclear Research)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I67311998","host_organization_name":"European Organization for Nuclear Research","host_organization_lineage":["https://openalex.org/I67311998"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferencePaper"},{"id":"pmh:oai:iris.uniroma1.it:11573/1560421","is_oa":false,"landing_page_url":"https://hdl.handle.net/11573/1560421","pdf_url":null,"source":{"id":"https://openalex.org/S4377196107","display_name":"IRIS Research product catalog (Sapienza University of Rome)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2106.00541","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2106.00541","pdf_url":"https://arxiv.org/pdf/2106.00541","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W52120761","https://openalex.org/W191098608","https://openalex.org/W1507388815","https://openalex.org/W1523098686","https://openalex.org/W1531782611","https://openalex.org/W1571989395","https://openalex.org/W1775772884","https://openalex.org/W1827212170","https://openalex.org/W1974189812","https://openalex.org/W2040424958","https://openalex.org/W2083183119","https://openalex.org/W2145094598","https://openalex.org/W2146337213","https://openalex.org/W2150423842","https://openalex.org/W2161406213","https://openalex.org/W2171331105","https://openalex.org/W2342408547","https://openalex.org/W2498359591","https://openalex.org/W2510850936","https://openalex.org/W2514847810","https://openalex.org/W2517430515","https://openalex.org/W2584414817","https://openalex.org/W2614419969","https://openalex.org/W2712617220","https://openalex.org/W2747715470","https://openalex.org/W2798159728","https://openalex.org/W2806678366","https://openalex.org/W2808649067","https://openalex.org/W2912095101","https://openalex.org/W2913857451","https://openalex.org/W2921434519","https://openalex.org/W2973368506","https://openalex.org/W3008443984","https://openalex.org/W3029868457","https://openalex.org/W3091890513","https://openalex.org/W3093195617","https://openalex.org/W6621219108","https://openalex.org/W6753975912","https://openalex.org/W6943565351","https://openalex.org/W6981170678"],"related_works":[],"abstract_inverted_index":{"Economic":[0],"incentives":[1],"encourage":[2],"malware":[3,11,57,131,175,211],"authors":[4],"to":[5,12,35,54,67,76,92,117,163,172,194,216,227],"constantly":[6],"develop":[7],"new,":[8],"increasingly":[9],"complex":[10],"steal":[13],"sensitive":[14],"data":[15,66],"or":[16,43],"blackmail":[17],"individuals":[18],"and":[19,39,83,102,134,147,169,179,189],"companies":[20],"into":[21],"paying":[22],"large":[23],"ransoms.":[24],"In":[25,106],"2017,":[26],"the":[27,51,69,120,184],"worldwide":[28],"economic":[29],"impact":[30],"of":[31,45,50,71,85,122,139,143,186,202,218],"cyberattacks":[32],"is":[33,58,89,99],"estimated":[34],"be":[36],"between":[37],"445":[38],"600":[40],"billion":[41],"USD,":[42],"0.8%":[44],"global":[46],"GDP.":[47],"Traditionally,":[48],"one":[49],"approaches":[52],"used":[53],"defend":[55],"against":[56],"network":[59,65,81,87,96,144,230],"traffic":[60,204],"analysis,":[61],"which":[62,98],"relies":[63],"on":[64,94,197],"detect":[68,164],"presence":[70],"potentially":[72],"malicious":[73,165],"software.":[74],"However,":[75],"keep":[77],"up":[78],"with":[79,119,199,213,224],"increasing":[80],"speeds":[82],"amount":[84],"traffic,":[86],"analysis":[88],"generally":[90],"limited":[91],"work":[93],"aggregated":[95,123],"data,":[97],"traditionally":[100],"challenging":[101],"yields":[103],"mixed":[104,205],"results.":[105],"this":[107],"paper":[108],"we":[109],"present":[110],"MalPhase,":[111],"a":[112,127,148,153,173],"system":[113],"that":[114,217],"was":[115],"designed":[116],"cope":[118],"limitations":[121],"flows.":[124],"MalPhase":[125,193,208],"features":[126,146,188],"multi-phase":[128],"pipeline":[129],"for":[130,156],"detection,":[132],"type":[133,176],"family":[135,180],"classification.":[136],"The":[137],"use":[138,185],"an":[140],"extended":[141],"set":[142],"flow":[145],"simultaneous":[149],"multi-tier":[150],"architecture":[151],"facilitates":[152],"performance":[154,214],"improvement":[155],"deep":[157],"learning":[158],"models,":[159],"making":[160],"them":[161,171],"able":[162],"flows":[166,226],"(>98%":[167],"F1)":[168,178],"categorize":[170],"respective":[174],"(>93%":[177],"(>91%":[181],"F1).":[182],"Furthermore,":[183],"robust":[187],"denoising":[190],"autoencoders":[191],"allows":[192],"perform":[195],"well":[196],"samples":[198,212],"varying":[200],"amounts":[201],"benign":[203,225],"in.":[206],"Finally,":[207],"detects":[209],"unseen":[210],"comparable":[215],"known":[219],"samples,":[220],"even":[221],"when":[222],"interlaced":[223],"reflect":[228],"realistic":[229],"environments.":[231]},"counts_by_year":[{"year":2025,"cited_by_count":8},{"year":2024,"cited_by_count":11},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":6},{"year":2021,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2021-06-22T00:00:00"}
