{"id":"https://openalex.org/W2803920557","doi":"https://doi.org/10.3390/e20050390","title":"End-to-End Deep Neural Networks and Transfer Learning for Automatic Analysis of Nation-State Malware","display_name":"End-to-End Deep Neural Networks and Transfer Learning for Automatic Analysis of Nation-State Malware","publication_year":2018,"publication_date":"2018-05-22","ids":{"openalex":"https://openalex.org/W2803920557","doi":"https://doi.org/10.3390/e20050390","mag":"2803920557","pmid":"https://pubmed.ncbi.nlm.nih.gov/33265480"},"language":"en","primary_location":{"id":"doi:10.3390/e20050390","is_oa":true,"landing_page_url":"https://doi.org/10.3390/e20050390","pdf_url":"https://www.mdpi.com/1099-4300/20/5/390/pdf?version=1526974696","source":{"id":"https://openalex.org/S195231649","display_name":"Entropy","issn_l":"1099-4300","issn":["1099-4300"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref","doaj","pubmed"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/1099-4300/20/5/390/pdf?version=1526974696","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Ishai Rosenberg","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Ishai Rosenberg","raw_affiliation_strings":["Deep Instinct Ltd., Tel Aviv 6618356, Israel"],"affiliations":[{"raw_affiliation_string":"Deep Instinct Ltd., Tel Aviv 6618356, Israel","institution_ids":[]}]},{"author_position":"middle","author":{"id":null,"display_name":"Guillaume Sicard","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Guillaume Sicard","raw_affiliation_strings":["Deep Instinct Ltd., Tel Aviv 6618356, Israel"],"affiliations":[{"raw_affiliation_string":"Deep Instinct Ltd., Tel Aviv 6618356, Israel","institution_ids":[]}]},{"author_position":"last","author":{"id":null,"display_name":"Eli (Omid) David","orcid":"https://orcid.org/0000-0003-2904-4982"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Eli (Omid) David","raw_affiliation_strings":["Deep Instinct Ltd., Tel Aviv 6618356, Israel"],"affiliations":[{"raw_affiliation_string":"Deep Instinct Ltd., Tel Aviv 6618356, Israel","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":2000,"currency":"CHF","value_usd":2165},"apc_paid":{"value":2000,"currency":"CHF","value_usd":2165},"fwci":1.1615,"has_fulltext":false,"cited_by_count":23,"citation_normalized_percentile":{"value":0.79077204,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"20","issue":"5","first_page":"390","last_page":"390"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9686999917030334,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9686999917030334,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.006099999882280827,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.00570000009611249,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.5852000117301941},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5361999869346619},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.510699987411499},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.492000013589859},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.4661000072956085},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4075999855995178},{"id":"https://openalex.org/keywords/feature-extraction","display_name":"Feature extraction","score":0.3846000134944916},{"id":"https://openalex.org/keywords/rendering","display_name":"Rendering (computer graphics)","score":0.33869999647140503}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8687000274658203},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6809999942779541},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.5852000117301941},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5361999869346619},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.510699987411499},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.492000013589859},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.4661000072956085},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4507000148296356},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4075999855995178},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.3846000134944916},{"id":"https://openalex.org/C205711294","wikidata":"https://www.wikidata.org/wiki/Q176953","display_name":"Rendering (computer graphics)","level":2,"score":0.33869999647140503},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3215999901294708},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.3176000118255615},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.31349998712539673},{"id":"https://openalex.org/C132964779","wikidata":"https://www.wikidata.org/wiki/Q2110223","display_name":"Raw data","level":2,"score":0.3001999855041504},{"id":"https://openalex.org/C59404180","wikidata":"https://www.wikidata.org/wiki/Q17013334","display_name":"Feature learning","level":2,"score":0.2971999943256378},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.2913999855518341},{"id":"https://openalex.org/C83665646","wikidata":"https://www.wikidata.org/wiki/Q42139305","display_name":"Feature vector","level":2,"score":0.2849999964237213},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2685999870300293},{"id":"https://openalex.org/C67174900","wikidata":"https://www.wikidata.org/wiki/Q178022","display_name":"Minutiae","level":4,"score":0.2587999999523163},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.25529998540878296}],"mesh":[],"locations_count":6,"locations":[{"id":"doi:10.3390/e20050390","is_oa":true,"landing_page_url":"https://doi.org/10.3390/e20050390","pdf_url":"https://www.mdpi.com/1099-4300/20/5/390/pdf?version=1526974696","source":{"id":"https://openalex.org/S195231649","display_name":"Entropy","issn_l":"1099-4300","issn":["1099-4300"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy","raw_type":"journal-article"},{"id":"pmid:33265480","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/33265480","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy (Basel, Switzerland)","raw_type":null},{"id":"pmh:oai:arXiv.org:1912.01493","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1912.01493","pdf_url":"https://arxiv.org/pdf/1912.01493","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:doaj.org/article:f57e7b39b0a64fc7b1900e71ae12e1e2","is_oa":true,"landing_page_url":"https://doaj.org/article/f57e7b39b0a64fc7b1900e71ae12e1e2","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Entropy, Vol 20, Iss 5, p 390 (2018)","raw_type":"article"},{"id":"pmh:oai:mdpi.com:/1099-4300/20/5/390/","is_oa":true,"landing_page_url":"https://dx.doi.org/10.3390/e20050390","pdf_url":null,"source":{"id":"https://openalex.org/S4306400947","display_name":"MDPI (MDPI AG)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210097602","host_organization_name":"Multidisciplinary Digital Publishing Institute (Switzerland)","host_organization_lineage":["https://openalex.org/I4210097602"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Entropy; Volume 20; Issue 5; Pages: 390","raw_type":"Text"},{"id":"pmh:oai:pubmedcentral.nih.gov:7512909","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/7512909","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Entropy (Basel)","raw_type":"Text"}],"best_oa_location":{"id":"doi:10.3390/e20050390","is_oa":true,"landing_page_url":"https://doi.org/10.3390/e20050390","pdf_url":"https://www.mdpi.com/1099-4300/20/5/390/pdf?version=1526974696","source":{"id":"https://openalex.org/S195231649","display_name":"Entropy","issn_l":"1099-4300","issn":["1099-4300"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2803920557.pdf","grobid_xml":"https://content.openalex.org/works/W2803920557.grobid-xml"},"referenced_works_count":20,"referenced_works":["https://openalex.org/W54929040","https://openalex.org/W1666731339","https://openalex.org/W1849277567","https://openalex.org/W2006942880","https://openalex.org/W2008324060","https://openalex.org/W2106100979","https://openalex.org/W2129364433","https://openalex.org/W2163922914","https://openalex.org/W2205815960","https://openalex.org/W2267635142","https://openalex.org/W2476429474","https://openalex.org/W2564822508","https://openalex.org/W2766677542","https://openalex.org/W2776884785","https://openalex.org/W4250089123","https://openalex.org/W6674330103","https://openalex.org/W6676013096","https://openalex.org/W6682889407","https://openalex.org/W6683738474","https://openalex.org/W6950606743"],"related_works":[],"abstract_inverted_index":{"Malware":[0],"allegedly":[1],"developed":[2,171],"by":[3,152],"nation-states,":[4],"also":[5,135],"known":[6],"as":[7,91,114],"<i>advanced":[8],"persistent":[9],"threats</i>":[10],"(APT),":[11],"are":[12],"becoming":[13],"more":[14,43],"common.":[15],"The":[16],"task":[17],"of":[18,62,103,130,166,178],"attributing":[19],"an":[20,175],"APT":[21,32,96,105,142,154],"to":[22,29,124,157],"a":[23,45,86,92,109,163],"specific":[24],"nation-state":[25,41,95],"or":[26],"classifying":[27],"it":[28,113],"the":[30,60,100,104,118,122,131,137,148,153,159],"correct":[31],"family":[33,143,155],"is":[34,66],"challenging":[35],"for":[36,94,117,141],"several":[37],"reasons.":[38],"First,":[39],"each":[40],"has":[42],"than":[44],"single":[46],"cyber":[47],"unit":[48],"that":[49],"develops":[50],"such":[51,63],"malware,":[52],"rendering":[53],"traditional":[54],"authorship":[55],"attribution":[56,160],"algorithms":[57],"useless.":[58],"Furthermore,":[59],"dataset":[61],"available":[64],"APTs":[65,72,132],"still":[67],"extremely":[68],"small.":[69],"Finally,":[70,145],"those":[71],"use":[73,85,112,136,147],"state-of-the-art":[74],"evasion":[75],"techniques,":[76],"making":[77],"feature":[78,128,149],"extraction":[79],"challenging.":[80],"In":[81],"this":[82],"paper,":[83],"we":[84,146,173],"deep":[87],"neural":[88,119],"network":[89],"(DNN)":[90],"classifier":[93,156],"attribution.":[97],"We":[98,134],"record":[99],"dynamic":[101],"behavior":[102],"when":[106],"run":[107],"in":[108],"sandbox":[110],"and":[111,169],"raw":[115,139],"input":[116],"network,":[120],"allowing":[121],"DNN":[123],"learn":[125],"high":[126],"level":[127],"abstractions":[129,150],"itself.":[133],"same":[138],"features":[140],"classification.":[144],"learned":[151],"solve":[158],"problem.":[161],"Using":[162],"test":[164],"set":[165],"1000":[167],"Chinese":[168],"Russian":[170],"APTs,":[172],"achieved":[174],"accuracy":[176],"rate":[177],"98.6.":[179]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2018-06-01T00:00:00"}
