{"id":"https://openalex.org/W3091248761","doi":"https://doi.org/10.1016/j.procs.2020.09.053","title":"Identification of library functions statically linked to Linux malware without symbols","display_name":"Identification of library functions statically linked to Linux malware without symbols","publication_year":2020,"publication_date":"2020-01-01","ids":{"openalex":"https://openalex.org/W3091248761","doi":"https://doi.org/10.1016/j.procs.2020.09.053","mag":"3091248761"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.procs.2020.09.053","pdf_url":null,"source":{"id":"https://openalex.org/S120348307","display_name":"Procedia Computer Science","issn_l":"1877-0509","issn":["1877-0509"],"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1016/j.procs.2020.09.053","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5090066072","display_name":"Shu Akabane","orcid":"https://orcid.org/0009-0006-1525-9789"},"institutions":[{"id":"https://openalex.org/I182069643","display_name":"Kanagawa Institute of Technology","ror":"https://ror.org/007gj5v75","country_code":"JP","type":"education","lineage":["https://openalex.org/I182069643"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Shu Akabane","raw_affiliation_strings":["Kanagawa Institute of Technology, 1030 Shimo-ogino, Atsugi, Kanagawa 243-0292, JAPAN"],"affiliations":[{"raw_affiliation_string":"Kanagawa Institute of Technology, 1030 Shimo-ogino, Atsugi, Kanagawa 243-0292, JAPAN","institution_ids":["https://openalex.org/I182069643"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100800691","display_name":"Takeshi Okamoto","orcid":null},"institutions":[{"id":"https://openalex.org/I182069643","display_name":"Kanagawa Institute of Technology","ror":"https://ror.org/007gj5v75","country_code":"JP","type":"education","lineage":["https://openalex.org/I182069643"]}],"countries":["JP"],"is_corresponding":true,"raw_author_name":"Takeshi Okamoto","raw_affiliation_strings":["Kanagawa Institute of Technology, 1030 Shimo-ogino, Atsugi, Kanagawa 243-0292, JAPAN"],"affiliations":[{"raw_affiliation_string":"Kanagawa Institute of Technology, 1030 Shimo-ogino, Atsugi, Kanagawa 243-0292, JAPAN","institution_ids":["https://openalex.org/I182069643"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5100800691"],"corresponding_institution_ids":["https://openalex.org/I182069643"],"apc_list":null,"apc_paid":null,"fwci":0.528,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.483968,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":76,"max":78},"biblio":{"volume":"176","issue":null,"first_page":"3436","last_page":"3445"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9953,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9914,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/identification","display_name":"Identification","score":0.6676022},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.488739},{"id":"https://openalex.org/keywords/library-function","display_name":"Library function","score":0.44856945}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.86523694},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.83192813},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.6676022},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.54313874},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.5249063},{"id":"https://openalex.org/C68859911","wikidata":"https://www.wikidata.org/wiki/Q1503724","display_name":"Pattern matching","level":2,"score":0.51928276},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.488739},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.46329463},{"id":"https://openalex.org/C2992306863","wikidata":"https://www.wikidata.org/wiki/Q188860","display_name":"Library function","level":2,"score":0.44856945},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.31254435},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.07925838},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.059815586},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C78458016","wikidata":"https://www.wikidata.org/wiki/Q840400","display_name":"Evolutionary biology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.procs.2020.09.053","pdf_url":null,"source":{"id":"https://openalex.org/S120348307","display_name":"Procedia Computer Science","issn_l":"1877-0509","issn":["1877-0509"],"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.procs.2020.09.053","pdf_url":null,"source":{"id":"https://openalex.org/S120348307","display_name":"Procedia Computer Science","issn_l":"1877-0509","issn":["1877-0509"],"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":5,"referenced_works":["https://openalex.org/W2514847810","https://openalex.org/W2532962075","https://openalex.org/W2602804099","https://openalex.org/W2794801050","https://openalex.org/W2939132464"],"related_works":["https://openalex.org/W83212619","https://openalex.org/W4285507391","https://openalex.org/W2883822334","https://openalex.org/W2768892939","https://openalex.org/W2602767565","https://openalex.org/W2469507153","https://openalex.org/W2397240470","https://openalex.org/W2134874482","https://openalex.org/W2008790809","https://openalex.org/W170652726"],"abstract_inverted_index":{"Many":[0],"Linux":[1],"malware":[2,15,37,99],"have":[3,7],"been":[4,76],"found":[5],"to":[6,35,78],"statically":[8],"linked":[9,34],"library":[10,31,56,70,95],"functions.":[11],"Much":[12],"of":[13,18,54,60,81,85,104],"this":[14],"are":[16,88],"stripped":[17],"function":[19],"names":[20],"and":[21,83,110],"addresses,":[22],"hindering":[23],"function-level":[24,27],"analysis.":[25],"For":[26],"analysis,":[28],"we":[29],"identified":[30,50],"functions":[32,57],"stically":[33],"2,256":[36],"samples":[38],"with":[39],"the":[40,55,61,86,91,98,105],"Intel":[41],"80386":[42],"architecture":[43],"by":[44,97],"matching":[45,49,65],"patterns.":[46],"The":[47,93],"pattern":[48,64],"more":[51],"than":[52],"90%":[53],"for":[58,69],"97.7%":[59],"samples.":[62],"Thus,":[63],"can":[66],"be":[67],"effective":[68],"identification.":[71],"Only":[72],"12":[73],"toolchains":[74,87],"had":[75],"used":[77,96],"build":[79],"99.8%":[80],"samples,":[82,106],"11":[84],"available":[89],"on":[90],"Internet.":[92],"C":[94],"was":[100],"uClibc":[101],"in":[102,108,112],"96.5%":[103],"musl":[107],"1.3%":[109],"GLIBC":[111],"2.0%.":[113]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W3091248761","counts_by_year":[{"year":2023,"cited_by_count":3},{"year":2021,"cited_by_count":1}],"updated_date":"2025-04-28T23:16:48.849516","created_date":"2020-10-08"}