{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T20:34:29Z","timestamp":1730320469743,"version":"3.28.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,8,27]],"date-time":"2018-08-27T00:00:00Z","timestamp":1535328000000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,8,27]]},"DOI":"10.1145\/3230833.3233282","type":"proceedings-article","created":{"date-parts":[[2018,8,13]],"date-time":"2018-08-13T12:29:48Z","timestamp":1534163388000},"page":"1-8","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Hunting Observable Objects for Indication of Compromise"],"prefix":"10.1145","author":[{"given":"Arnold","family":"Sykosch","sequence":"first","affiliation":[{"name":"University of Bonn, Computer Science IV, Bonn, NRW, Germany Fraunhofer FKIE, Cyber Security, Bonn, NRW, Germany"}]},{"given":"Marc","family":"Ohm","sequence":"additional","affiliation":[{"name":"University of Bonn, Computer Science IV, Bonn, NRW, Germany"}]},{"given":"Michael","family":"Meier","sequence":"additional","affiliation":[{"name":"University of Bonn, Computer Science IV, Bonn, NRW, Germany Fraunhofer FKIE, Cyber Security, Bonn, NRW, Germany"}]}],"member":"320","published-online":{"date-parts":[[2018,8,27]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1515\/pik-2012-0004piko.2012.35.1.17"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808128.2808131"},{"key":"e_1_3_2_1_3_1","volume-title":"Standardizing Cyber Threat Intelligence Information with the Structured Threat Information expression (STIX\u2122)","author":"Barnum Sean","year":"2012","unstructured":"Sean Barnum . 2012. Standardizing Cyber Threat Intelligence Information with the Structured Threat Information expression (STIX\u2122) . MITRE Corporation ( 2012 ). Sean Barnum. 2012. Standardizing Cyber Threat Intelligence Information with the Structured Threat Information expression (STIX\u2122). MITRE Corporation (2012)."},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR).","author":"Bayer Ulrich","year":"2006","unstructured":"Ulrich Bayer , Christopher Kruegel , and Engin Kirda . 2006 . TTAnalyze: A Tool for Analyzing Malware . In Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR). Ulrich Bayer, Christopher Kruegel, and Engin Kirda. 2006. TTAnalyze: A Tool for Analyzing Malware. In Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR)."},{"key":"e_1_3_2_1_5_1","volume-title":"Retrieved July 3rd","author":"Bremer Jurriaan","year":"2014","unstructured":"Jurriaan Bremer and Thorsten Sick . 2014 . VMCloak - Automated Virtual Machine Generation and Cloaking tailored for Cuckoo Sandbox. v0.1. (2014) . Retrieved July 3rd , 2017 from http:\/\/vmcloak.org Jurriaan Bremer and Thorsten Sick. 2014. VMCloak - Automated Virtual Machine Generation and Cloaking tailored for Cuckoo Sandbox. v0.1. (2014). Retrieved July 3rd, 2017 from http:\/\/vmcloak.org"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808128.2808133"},{"volume-title":"Botnet Detection: Countering the Largest Security Threat","author":"Brumley David","key":"e_1_3_2_1_7_1","unstructured":"David Brumley , Cody Hartwig , Zhenkai Liang , James Newsome , Dawn Song , and Heng Yin . 2008. Automatically Identifying Trigger-based Behavior in Malware . In Botnet Detection: Countering the Largest Security Threat . Springer , 65--88. David Brumley, Cody Hartwig, Zhenkai Liang, James Newsome, Dawn Song, and Heng Yin. 2008. Automatically Identifying Trigger-based Behavior in Malware. In Botnet Detection: Countering the Largest Security Threat. Springer, 65--88."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/1947337.1947356"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the 3rd International Conference on Malicious and Unwanted Software (MALWARE). IEEE.","author":"Holz Thorsten","year":"2008","unstructured":"Thorsten Holz , Christian Gorecki , Konrad Rieck , and Felix C Freiling . 2008 . Measuring and Detecting Fast-Flux Service Networks . In Proceedings of the 3rd International Conference on Malicious and Unwanted Software (MALWARE). IEEE. Thorsten Holz, Christian Gorecki, Konrad Rieck, and Felix C Freiling. 2008. Measuring and Detecting Fast-Flux Service Networks. In Proceedings of the 3rd International Conference on Malicious and Unwanted Software (MALWARE). IEEE."},{"key":"e_1_3_2_1_10_1","volume-title":"Distributed Worm Signature Detection. In Proceedings of the 12th USENIX Security Symposium (USENIX Security 04","volume":"286","author":"Kim Hyang-Ah","year":"2004","unstructured":"Hyang-Ah Kim and Brad Karp . 2004 . Autograph: Toward Automated , Distributed Worm Signature Detection. In Proceedings of the 12th USENIX Security Symposium (USENIX Security 04 , Vol. 286 . Hyang-Ah Kim and Brad Karp. 2004. Autograph: Toward Automated, Distributed Worm Signature Detection. In Proceedings of the 12th USENIX Security Symposium (USENIX Security 04, Vol. 286."},{"key":"e_1_3_2_1_11_1","volume-title":"Retrieved May 2nd","author":"Kirillov Ivan","year":"2016","unstructured":"Ivan Kirillov . 2016 . maec-to-stix v1.0.0 alpha 1. (2016) . Retrieved May 2nd , 2018 from https:\/\/github.com\/MAECProject\/maec-to-stix Ivan Kirillov. 2016. maec-to-stix v1.0.0 alpha 1. (2016). Retrieved May 2nd, 2018 from https:\/\/github.com\/MAECProject\/maec-to-stix"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972384"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978315"},{"key":"e_1_3_2_1_15_1","volume-title":"Retrieved July 3rd","author":"MANDIANT.","year":"2011","unstructured":"MANDIANT. 2011 . Sophisticated Indicators for the Modern Threat Landscape: An Introduction to OpenIOC. (2011) . Retrieved July 3rd , 2017 from openioc.org MANDIANT. 2011. Sophisticated Indicators for the Modern Threat Landscape: An Introduction to OpenIOC. (2011). Retrieved July 3rd, 2017 from openioc.org"},{"volume-title":"An Introduction to Information Retrieval","author":"Manning Christopher D.","key":"e_1_3_2_1_16_1","unstructured":"Christopher D. Manning , Prabhakar Raghavan , and Hinrich Sch\u00c3ijtze . 2009. An Introduction to Information Retrieval . Cambridge University Press . Christopher D. Manning, Prabhakar Raghavan, and Hinrich Sch\u00c3ijtze. 2009. An Introduction to Information Retrieval. Cambridge University Press."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2013.03.003"},{"key":"e_1_3_2_1_18_1","volume-title":"Retrieved","author":"Applications Net","year":"2017","unstructured":"Net Applications . 2017 . Desktop Operating System Market Share. (2017) . Retrieved February 20, 2017 from https:\/\/www.netmarketshare.com\/operating-system-market-share.aspx?qprid=10&qpcustomd=0 Net Applications. 2017. Desktop Operating System Market Share. (2017). Retrieved February 20, 2017 from https:\/\/www.netmarketshare.com\/operating-system-market-share.aspx?qprid=10&qpcustomd=0"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"key":"e_1_3_2_1_20_1","volume-title":"Retrieved April 28th","author":"Open OASIS","year":"2018","unstructured":"OASIS Open . 2018 . Introduction to STIX. (2018) . Retrieved April 28th , 2018 from https:\/\/oasis-open.github.io\/cti-documentation\/resources#stix-20-specification OASIS Open. 2018. Introduction to STIX. (2018). Retrieved April 28th, 2018 from https:\/\/oasis-open.github.io\/cti-documentation\/resources#stix-20-specification"},{"key":"e_1_3_2_1_21_1","volume-title":"Retrieved May 2nd","author":"Ortega Alberto","year":"2016","unstructured":"Alberto Ortega . 2016 . pafisch v058. (2016) . Retrieved May 2nd , 2018 from https:\/\/github.com\/a0rtega\/pafish Alberto Ortega. 2016. pafisch v058. (2016). Retrieved May 2nd, 2018 from https:\/\/github.com\/a0rtega\/pafish"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241115"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/2011216.2011217"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/0306-4573(88)90021-0"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994539.2994546"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1108\/eb026526"},{"key":"e_1_3_2_1_28_1","volume-title":"Retrieved April 28th","author":"Sykosch Arnold","year":"2015","unstructured":"Arnold Sykosch and Matthias W\u00fcbbeling . 2015 . STIX 2 IDS. (2015) . Retrieved April 28th , 2018 from https:\/\/www.iab.org\/activities\/workshops\/caris\/ Arnold Sykosch and Matthias W\u00fcbbeling. 2015. STIX 2 IDS. (2015). Retrieved April 28th, 2018 from https:\/\/www.iab.org\/activities\/workshops\/caris\/"},{"key":"e_1_3_2_1_29_1","volume-title":"Retrieved July 3rd","author":"The MITRE Corporation","year":"2017","unstructured":"The MITRE Corporation . 2017 . Cyber Observable expression (CybOX\u2122) Archive Website. (2017) . Retrieved July 3rd , 2017 from https:\/\/cyboxproject.github.io The MITRE Corporation. 2017. Cyber Observable expression (CybOX\u2122) Archive Website. (2017). Retrieved July 3rd, 2017 from https:\/\/cyboxproject.github.io"},{"key":"e_1_3_2_1_30_1","volume-title":"Retrieved","author":"Westcott David","year":"2017","unstructured":"David Westcott and Lenny Zeltser . 2017 . REMnux: A Linux Toolkit for Reverse-Engineering and Analyzing Malware. (2017) . Retrieved February 20, 2017 from https:\/\/remnux.org David Westcott and Lenny Zeltser. 2017. REMnux: A Linux Toolkit for Reverse-Engineering and Analyzing Malware. (2017). Retrieved February 20, 2017 from https:\/\/remnux.org"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/GreenCom.2012.121"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00039"}],"event":{"name":"ARES 2018: International Conference on Availability, Reliability and Security","sponsor":["Universit\u00e4t Hamburg Universit\u00e4t Hamburg"],"location":"Hamburg Germany","acronym":"ARES 2018"},"container-title":["Proceedings of the 13th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3230833.3233282","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,6]],"date-time":"2023-09-06T02:53:04Z","timestamp":1693968784000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3233282"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8,27]]},"references-count":32,"alternative-id":["10.1145\/3230833.3233282","10.1145\/3230833"],"URL":"https:\/\/doi.org\/10.1145\/3230833.3233282","relation":{},"subject":[],"published":{"date-parts":[[2018,8,27]]},"assertion":[{"value":"2018-08-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}