{"id":"W2237959143","doi":"10.1016/j.eswa.2016.01.002","title":"Malicious sequential pattern mining for automatic malware detection","year":2016,"lang":"en","type":"article","venue":"Expert Systems with Applications","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":157,"is_retracted":false,"has_abstract":false,"ca_institutions":"Université de Sherbrooke","funders":"Natural Science Foundation of Fujian Province; National Natural Science Foundation of China","keywords":"Malware; Computer science; Executable; Data mining; Classifier (UML); Trojan; Cryptovirology; Intrusion detection system; Sequential Pattern Mining; System call; Artificial intelligence; Machine learning; Computer security; Operating system","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0007711028,0.000710879,0.0007063558,0.003567757,0.0007455968,0.00079345,0.0008263281,0.0005710993,0.001496048],"category_scores_gemma":[0.003399845,0.0003444531,0.0008217377,0.001817767,0.0003519769,0.001003939,0.0005420207,0.0007320522,0.0007990344],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0003382063,"about_ca_system_score_gemma":0.0009793343,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002223353,"about_ca_topic_score_gemma":0.004183549,"domain_scores_codex":[0.9990802,0.0001653188,0.0001152567,0.0002519789,0.0003118892,0.00007531647],"domain_scores_gemma":[0.9977629,0.001056455,0.0002462802,0.0003416286,0.0005023944,0.00009022326],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004766662,0.0004336999,0.02041536,0.0003432747,0.0002433045,0.0006928627,0.0001694706,0.02902675,0.05657515,0.005295506,0.005479482,0.8808486],"study_design_scores_gemma":[0.0000187459,0.0001903452,0.004449356,0.0000268621,0.00008970998,0.0009468088,0.00006367661,0.9545246,0.02673277,0.009229061,0.003706674,0.00002127911],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1631972,0.001334612,0.8262768,0.000258253,0.0001194921,0.0002317376,0.001137709,0.005365267,0.002078986],"genre_scores_gemma":[0.6103246,0.0004347964,0.3840964,0.0000845445,0.00007803326,0.0001425188,0.001894455,0.000152639,0.002791936],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003567757,"threshold_uncertainty_score":0.005004764,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01557217367219011,"score_gpt":0.2475662252126508,"score_spread":0.2319940515404607,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}