{"id":"https://openalex.org/W3196325333","doi":"https://doi.org/10.1155/2021/9396141","title":"Attribution Classification Method of APT Malware in IoT Using Machine Learning Techniques","display_name":"Attribution Classification Method of APT Malware in IoT Using Machine Learning Techniques","publication_year":2021,"publication_date":"2021-09-06","ids":{"openalex":"https://openalex.org/W3196325333","doi":"https://doi.org/10.1155/2021/9396141","mag":"3196325333"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1155/2021/9396141","pdf_url":"https://downloads.hindawi.com/journals/scn/2021/9396141.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0122","issn":["1939-0122","1939-0114"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://downloads.hindawi.com/journals/scn/2021/9396141.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5043717671","display_name":"Shudong Li","orcid":"https://orcid.org/0000-0001-6381-1984"},"institutions":[{"id":"https://openalex.org/I37987034","display_name":"Guangzhou University","ror":"https://ror.org/05ar8rn06","country_code":"CN","type":"education","lineage":["https://openalex.org/I37987034"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Shudong Li","raw_affiliation_strings":["Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China"],"affiliations":[{"raw_affiliation_string":"Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China","institution_ids":["https://openalex.org/I37987034"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102710239","display_name":"Qianqing Zhang","orcid":"https://orcid.org/0000-0002-4097-821X"},"institutions":[{"id":"https://openalex.org/I37987034","display_name":"Guangzhou University","ror":"https://ror.org/05ar8rn06","country_code":"CN","type":"education","lineage":["https://openalex.org/I37987034"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qianqing Zhang","raw_affiliation_strings":["Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China"],"affiliations":[{"raw_affiliation_string":"Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China","institution_ids":["https://openalex.org/I37987034"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100677580","display_name":"Xiaobo Wu","orcid":null},"institutions":[{"id":"https://openalex.org/I37987034","display_name":"Guangzhou University","ror":"https://ror.org/05ar8rn06","country_code":"CN","type":"education","lineage":["https://openalex.org/I37987034"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaobo Wu","raw_affiliation_strings":["School of Computer Science and Cyber Engineering, Guangzhou University, Guangzhou 510006, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Cyber Engineering, Guangzhou University, Guangzhou 510006, China","institution_ids":["https://openalex.org/I37987034"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081140857","display_name":"Weihong Han","orcid":"https://orcid.org/0000-0001-9997-1509"},"institutions":[{"id":"https://openalex.org/I37987034","display_name":"Guangzhou University","ror":"https://ror.org/05ar8rn06","country_code":"CN","type":"education","lineage":["https://openalex.org/I37987034"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Weihong Han","raw_affiliation_strings":["Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China"],"affiliations":[{"raw_affiliation_string":"Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China","institution_ids":["https://openalex.org/I37987034"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5056608045","display_name":"Zhihong Tian","orcid":"https://orcid.org/0000-0002-9409-5359"},"institutions":[{"id":"https://openalex.org/I37987034","display_name":"Guangzhou University","ror":"https://ror.org/05ar8rn06","country_code":"CN","type":"education","lineage":["https://openalex.org/I37987034"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhihong Tian","raw_affiliation_strings":["Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China"],"affiliations":[{"raw_affiliation_string":"Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China","institution_ids":["https://openalex.org/I37987034"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5043717671"],"corresponding_institution_ids":["https://openalex.org/I37987034"],"apc_list":{"value":2100,"currency":"USD","value_usd":2100,"provenance":"doaj"},"apc_paid":{"value":2100,"currency":"USD","value_usd":2100,"provenance":"doaj"},"fwci":7.943,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":60,"citation_normalized_percentile":{"value":0.850791,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"2021","issue":null,"first_page":"1","last_page":"12"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9994,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/popularity","display_name":"Popularity","score":0.5285655}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.89046407},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8305505},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6027742},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.5938885},{"id":"https://openalex.org/C2780586970","wikidata":"https://www.wikidata.org/wiki/Q1357284","display_name":"Popularity","level":2,"score":0.5285655},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5114423},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.50944525},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.44377932},{"id":"https://openalex.org/C148483581","wikidata":"https://www.wikidata.org/wiki/Q446488","display_name":"Feature selection","level":2,"score":0.42159206},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1155/2021/9396141","pdf_url":"https://downloads.hindawi.com/journals/scn/2021/9396141.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0122","issn":["1939-0122","1939-0114"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":false,"landing_page_url":"https://doaj.org/article/974b5e8f87b54f2ea1410ff22ccbfc3c","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1155/2021/9396141","pdf_url":"https://downloads.hindawi.com/journals/scn/2021/9396141.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0122","issn":["1939-0122","1939-0114"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"display_name":"Peace, justice, and strong institutions","score":0.55,"id":"https://metadata.un.org/sdg/16"}],"grants":[{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"202102010442"},{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"61972106"},{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"2019B010136003"},{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"2019QY1406"},{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"62072131"}],"datasets":[],"versions":[],"referenced_works_count":23,"referenced_works":["https://openalex.org/W1936523258","https://openalex.org/W1969381345","https://openalex.org/W1982041549","https://openalex.org/W2039998965","https://openalex.org/W2040339820","https://openalex.org/W2073903244","https://openalex.org/W2148143831","https://openalex.org/W2153957938","https://openalex.org/W2182819203","https://openalex.org/W2508693087","https://openalex.org/W2561342496","https://openalex.org/W2586493909","https://openalex.org/W2612545613","https://openalex.org/W2785022326","https://openalex.org/W2964061570","https://openalex.org/W2966031774","https://openalex.org/W2980205871","https://openalex.org/W3004349306","https://openalex.org/W3035366542","https://openalex.org/W3037398645","https://openalex.org/W3118258377","https://openalex.org/W3131819656","https://openalex.org/W3196006413"],"related_works":["https://openalex.org/W4294565801","https://openalex.org/W2952704802","https://openalex.org/W2518037665","https://openalex.org/W2477036161","https://openalex.org/W2384861574","https://openalex.org/W2368605798","https://openalex.org/W2368049389","https://openalex.org/W2348524959","https://openalex.org/W2170801710","https://openalex.org/W2142306706"],"abstract_inverted_index":{"In":[0],"recent":[1],"years,":[2],"the":[3,38,52,56,63,94,107,128,134,172,175,196],"popularity":[4],"of":[5,8,37,55,65,109,130,140,174,184],"IoT":[6,22,86,203],"(Internet":[7],"Things)":[9],"applications":[10],"and":[11,42,105,116,132,158,188,205],"services":[12],"has":[13,23,46],"brought":[14,25,47],"great":[15],"convenience":[16],"to":[17,92,99,170],"people's":[18],"lives,":[19],"but":[20],"ubiquitous":[21],"also":[24],"many":[26],"security":[27,49,108],"problems.":[28,160],"Among":[29],"them,":[30],"advanced":[31],"persistent":[32],"threat":[33],"(APT)":[34],"is":[35,69],"one":[36],"most":[39],"representative":[40],"attacks,":[41],"its":[43],"continuous":[44],"outbreak":[45],"unprecedented":[48],"challenges":[50],"for":[51,79,181],"large-scale":[53],"deployment":[54],"IoT.":[57,110],"However,":[58],"important":[59],"research":[60],"on":[61,120,163],"analyzing":[62],"attribution":[64,80,182],"APT":[66,83,102,121,185,200],"malware":[67,84,186],"samples":[68,187],"still":[70],"relatively":[71],"few.":[72],"Therefore,":[73],"we":[74],"propose":[75],"a":[76,137,147],"classification":[77],"method":[78,112,176,193],"organizations":[81],"with":[82,136,156],"in":[85,127,178,202],"using":[87],"machine":[88],"learning.":[89],"It":[90],"aims":[91],"mark":[93],"real":[95,164],"attacking":[96],"organization":[97,197],"entities":[98],"better":[100,154],"identify":[101,195],"attack":[103],"activity":[104],"protect":[106],"This":[111],"performs":[113],"feature":[114,117],"representation":[115],"selection":[118],"based":[119],"behavior":[122,166],"data":[123,167],"obtained":[124],"from":[125],"devices":[126,204],"Internet":[129],"Things":[131],"selects":[133],"features":[135],"high":[138],"degree":[139],"differentiation":[141],"among":[142],"organizations.":[143],"Then,":[144],"it":[145],"trains":[146],"multiclass":[148],"model":[149],"named":[150],"SMOTE-RF":[151],"that":[152],"can":[153],"deal":[155],"imbalance":[157],"multiclassification":[159],"Our":[161,192],"experiments":[162],"dynamic":[165],"are":[168],"combined":[169],"verify":[171],"effectiveness":[173],"proposed":[177],"this":[179],"paper":[180],"analysis":[183],"achieve":[189],"good":[190],"performance.":[191],"could":[194],"behind":[198],"complex":[199],"attacks":[201],"services.":[206]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W3196325333","counts_by_year":[{"year":2024,"cited_by_count":21},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":25},{"year":2021,"cited_by_count":5}],"updated_date":"2025-01-20T08:59:14.137535","created_date":"2021-09-13"}