{"id":"W4409839251","doi":"10.1007/s11227-025-07267-x","title":"Unveiling evasive malware behavior: toward generating a multi-sources benchmark dataset and evasive malware behavior profiling using network traffic and memory analysis","year":2025,"lang":"en","type":"article","venue":"The Journal of Supercomputing","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":3,"is_retracted":false,"has_abstract":false,"ca_institutions":"Bell (Canada); York University","funders":"Canada Research Chairs","keywords":"Computer science; Malware; Profiling (computer programming); Benchmark (surveying); Traffic analysis; Malware analysis; Computer security; Operating system","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001195866,0.001827234,0.0005762266,0.00504457,0.0007039067,0.001172176,0.001463187,0.001382366,0.0005453663],"category_scores_gemma":[0.005322915,0.0003287024,0.0008164094,0.002469596,0.0005396319,0.001601455,0.001351939,0.001340138,0.0007240853],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006765865,"about_ca_system_score_gemma":0.0009995817,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.007769242,"about_ca_topic_score_gemma":0.01362708,"domain_scores_codex":[0.9983866,0.0002731631,0.0001377313,0.0004312096,0.0005445215,0.0002267852],"domain_scores_gemma":[0.996556,0.0008220692,0.0004173174,0.0008904563,0.001016795,0.0002973515],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001542941,0.004677921,0.2868668,0.002072041,0.001252118,0.001765865,0.0008098674,0.1254463,0.06242504,0.00643281,0.2035806,0.3031277],"study_design_scores_gemma":[0.0002694018,0.001479663,0.193103,0.0002590713,0.0003756578,0.001996647,0.0011502,0.655243,0.06814226,0.007618234,0.07015429,0.0002086136],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.8585226,0.00144302,0.02839317,0.001006593,0.000343281,0.0005095834,0.09371561,0.01169984,0.004366249],"genre_scores_gemma":[0.7056673,0.0004788912,0.04833592,0.0004126809,0.0001306331,0.000499957,0.2415401,0.0006826192,0.002252021],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.007769242,"threshold_uncertainty_score":0.01544809,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02944905947358488,"score_gpt":0.2875120779469746,"score_spread":0.2580630184733897,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}