<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1692-1798</journal-id>
<journal-title><![CDATA[Iteckne]]></journal-title>
<abbrev-journal-title><![CDATA[Iteckne]]></abbrev-journal-title>
<issn>1692-1798</issn>
<publisher>
<publisher-name><![CDATA[Universidad Santo Tomás]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1692-17982018000200107</article-id>
<article-id pub-id-type="doi">10.15332/iteckne.v15i2.2072</article-id>
<title-group>
<article-title xml:lang="en"><![CDATA[BUILDING MALWARE CLASSIFICATORS USABLE BY STATE SECURITY AGENCIES]]></article-title>
<article-title xml:lang="es"><![CDATA[CONSTRUCCIÓN DE CLASIFICADORES DE MALWARE PARA AGENCIAS DE SEGURIDAD DEL ESTADO]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Useche-Peláez]]></surname>
<given-names><![CDATA[David Esteban]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Sepúlveda-Alzate]]></surname>
<given-names><![CDATA[Daniela]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Díaz-López]]></surname>
<given-names><![CDATA[Daniel Orlando]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Cabuya-Padilla]]></surname>
<given-names><![CDATA[Diego Edison]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Escuela Colombiana de Ingeniería Julio Garavito  ]]></institution>
<addr-line><![CDATA[Bogotá ]]></addr-line>
<country>Colombia</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Escuela Colombiana de Ingeniería Julio Garavito  ]]></institution>
<addr-line><![CDATA[Bogotá ]]></addr-line>
<country>Colombia</country>
</aff>
<aff id="Af3">
<institution><![CDATA[,Escuela Colombiana de Ingeniería Julio Garavito  ]]></institution>
<addr-line><![CDATA[Bogotá ]]></addr-line>
<country>Colombia</country>
</aff>
<aff id="Af4">
<institution><![CDATA[,Comando Conjunto Cibernético  ]]></institution>
<addr-line><![CDATA[Bogotá ]]></addr-line>
<country>Colombia</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>12</month>
<year>2018</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>12</month>
<year>2018</year>
</pub-date>
<volume>15</volume>
<numero>2</numero>
<fpage>107</fpage>
<lpage>121</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_arttext&amp;pid=S1692-17982018000200107&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_abstract&amp;pid=S1692-17982018000200107&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_pdf&amp;pid=S1692-17982018000200107&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract Sandboxing has been used regularly to analyze software samples and determine if these contain suspicious properties or behaviors. Even if sandboxing is a powerful technique to perform malware analysis, it requires that a malware analyst performs a rigorous analysis of the results to determine the nature of the sample: goodware or malware. This paper proposes two machine learning models able to classify samples based on signatures and permissions obtained through Cuckoo sandbox, Androguard and VirusTotal. The developed models are also tested obtaining an acceptable percentage of correctly classified samples, being in this way useful tools for a malware analyst. A proposal of architecture for an IoT sentinel that uses one of the developed machine learning model is also showed. Finally, different approaches, perspectives, and challenges about the use of sandboxing and machine learning by security teams in State security agencies are also shared.]]></p></abstract>
<abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen El sandboxing ha sido usado de manera regular para analizar muestras de software y determinar si estas contienen propiedades o comportamientos sospechosos. A pesar de que el sandboxing es una técnica poderosa para desarrollar análisis de malware, esta requiere que un analista de malware desarrolle un análisis riguroso de los resultados para determinar la naturaleza de la muestra: goodware o malware. Este artículo propone dos modelos de aprendizaje automáticos capaces de clasificar muestras con base a un análisis de firmas o permisos extraídos por medio de Cuckoo sandbox, Androguard y VirusTotal. En este artículo también se presenta una propuesta de arquitectura de centinela IoT que protege dispositivos IoT, usando uno de los modelos de aprendizaje automáticos desarrollados anteriormente. Finalmente, diferentes enfoques y perspectivas acerca del uso de sandboxing y aprendizaje automático por parte de agencias de seguridad del Estado también son aportados.]]></p></abstract>
<kwd-group>
<kwd lng="es"><![CDATA[Cuckoo sandbox]]></kwd>
<kwd lng="es"><![CDATA[ciencia de datos]]></kwd>
<kwd lng="es"><![CDATA[aprendizaje de máquina]]></kwd>
<kwd lng="es"><![CDATA[análisis de malware]]></kwd>
<kwd lng="es"><![CDATA[sandboxing]]></kwd>
<kwd lng="en"><![CDATA[Cuckoo sandbox]]></kwd>
<kwd lng="en"><![CDATA[data science]]></kwd>
<kwd lng="en"><![CDATA[machine learning]]></kwd>
<kwd lng="en"><![CDATA[malware analysis]]></kwd>
<kwd lng="en"><![CDATA[sandboxing]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<label>1</label><nlm-citation citation-type="">
<collab>Kaspersky</collab>
<source><![CDATA[Kaspersky Lab detects 360,000 new malicious files daily - up 11.5% from 2016]]></source>
<year>2014</year>
</nlm-citation>
</ref>
<ref id="B2">
<label>2</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Sikorski]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Honig]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<source><![CDATA[Practical Malware Analysis: a Hands-On Guide to Dissecting Malicious Software]]></source>
<year>2012</year>
<publisher-name><![CDATA[No Starch Press]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B3">
<label>3</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ehrenfeld]]></surname>
<given-names><![CDATA[J. M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[WannaCry, Cybersecurity and Health Information Technology: A Time to Act]]></article-title>
<source><![CDATA[J. Med. Syst.]]></source>
<year>2017</year>
<volume>41</volume>
<numero>7</numero>
<issue>7</issue>
<page-range>104</page-range></nlm-citation>
</ref>
<ref id="B4">
<label>4</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Miettinen]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Marchal]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Hafeez]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Asokan]]></surname>
<given-names><![CDATA[N.]]></given-names>
</name>
<name>
<surname><![CDATA[Sadeghi]]></surname>
<given-names><![CDATA[A.-R.]]></given-names>
</name>
<name>
<surname><![CDATA[Tarkoma]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
</person-group>
<source><![CDATA[IoT SENTINEL: Automated Device-Type Identification for Security Enforcement in IoT]]></source>
<year>2017</year>
<conf-name><![CDATA[ 37thInternational Conference on Distributed Computing Systems (ICDCS)]]></conf-name>
<conf-date>2017</conf-date>
<conf-loc> </conf-loc>
<page-range>2177-84</page-range></nlm-citation>
</ref>
<ref id="B5">
<label>5</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Wang]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Ding]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Guo]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Cui]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A Malware Detection Method Based on Sandbox, Binary Instrumentation and Multidimensional Feature Extraction]]></article-title>
<source><![CDATA[Advances on Broad-Band Wireless Computing, Communication and Applications]]></source>
<year>2018</year>
<page-range>427-38</page-range></nlm-citation>
</ref>
<ref id="B6">
<label>6</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Santos]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Devesa]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Brezo]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
<name>
<surname><![CDATA[Nieves]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Bringas]]></surname>
<given-names><![CDATA[P. G.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[OPEM: A static-dynamic approach for machine- learning-based malware detection]]></article-title>
<source><![CDATA[Advances in Intelligent Systems and Computing]]></source>
<year>2013</year>
<volume>189</volume>
<page-range>271-80</page-range><publisher-name><![CDATA[AISC]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B7">
<label>7</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Burnap]]></surname>
<given-names><![CDATA[P.]]></given-names>
</name>
<name>
<surname><![CDATA[French]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Turner]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
<name>
<surname><![CDATA[Jones]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Malware classification using self organising feature maps and machine activity data]]></article-title>
<source><![CDATA[Comput. Secur.]]></source>
<year>2018</year>
<volume>73</volume>
<page-range>399-410</page-range></nlm-citation>
</ref>
<ref id="B8">
<label>8</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Donaldson]]></surname>
<given-names><![CDATA[S. E.]]></given-names>
</name>
<name>
<surname><![CDATA[Siegel]]></surname>
<given-names><![CDATA[S. G.]]></given-names>
</name>
<name>
<surname><![CDATA[Williams]]></surname>
<given-names><![CDATA[C. K.]]></given-names>
</name>
<name>
<surname><![CDATA[Aslam]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Defining the Cybersecurity Challenge]]></article-title>
<source><![CDATA[Enterprise Cybersecurity Study Guide: How to Build a Successful Cyberdefense Program Against Advanced Threats]]></source>
<year>2018</year>
<page-range>3-51</page-range><publisher-loc><![CDATA[Berkeley, CA ]]></publisher-loc>
<publisher-name><![CDATA[Apress]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B9">
<label>9</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ferrand]]></surname>
<given-names><![CDATA[O.]]></given-names>
</name>
</person-group>
<source><![CDATA[How to detect the Cuckoo Sandbox and hardening it? Keywords]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B10">
<label>10</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Teller]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Hayon]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<source><![CDATA[Enhancing Automated Malware Analysis Machines with Memory Analysis]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B11">
<label>11</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Messier]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<source><![CDATA[Network Forensics]]></source>
<year>2017</year>
<publisher-name><![CDATA[Wiley]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B12">
<label>12</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Oktavianto]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Muhardianto]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
</person-group>
<source><![CDATA[Cuckoo malware analysis: analyze malware using Cuckoo Sandbox]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B13">
<label>13</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Waller]]></surname>
<given-names><![CDATA[M. A.]]></given-names>
</name>
<name>
<surname><![CDATA[Fawcett]]></surname>
<given-names><![CDATA[S. E.]]></given-names>
</name>
</person-group>
<source><![CDATA[Data Science, Predictive Analytics, and Big Data: A Revolution That Will Transform Supply Chain Design and Management]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B14">
<label>14</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Provost]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
<name>
<surname><![CDATA[Fawcett]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
</person-group>
<source><![CDATA[Data Science for Business: What You Need to Know about Data Mining and Data-Analytic Thinking]]></source>
<year>2013</year>
<publisher-name><![CDATA[O&#8217;Reilly Media]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B15">
<label>15</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Nelson]]></surname>
<given-names><![CDATA[G. S.]]></given-names>
</name>
</person-group>
<source><![CDATA[The analytics lifecycle toolkit: a practical guide for an effective analytics capability]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B16">
<label>16</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Dietrich]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Heller]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Yang]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
</person-group>
<collab>EMC Education Services</collab>
<source><![CDATA[Data science and big data analytics: discovering, analyzing, visualizing and presenting data]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B17">
<label>17</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Dunning]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Friedman]]></surname>
<given-names><![CDATA[B. E.]]></given-names>
</name>
</person-group>
<source><![CDATA[Practical machine learning: a new look at anomaly detection]]></source>
<year>2014</year>
<publisher-name><![CDATA[O&#8217;Reilly Media]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B18">
<label>18</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Chen]]></surname>
<given-names><![CDATA[H.]]></given-names>
</name>
<name>
<surname><![CDATA[Chiang]]></surname>
<given-names><![CDATA[R. H. L.]]></given-names>
</name>
<name>
<surname><![CDATA[Storey]]></surname>
<given-names><![CDATA[V. C.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Business Intelligence and Analytics: From Big Data to Big Impact]]></article-title>
<source><![CDATA[MIS Quarterly]]></source>
<year>2012</year>
<volume>36</volume>
<page-range>1165-88</page-range><publisher-name><![CDATA[Management Information Systems Research Center, University of Minnesota]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B19">
<label>19</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Sebastian-Coleman]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
</person-group>
<source><![CDATA[Navigating the Labyrinth: An Executive Guide to Data Management]]></source>
<year>2018</year>
<publisher-name><![CDATA[Technics Publications]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B20">
<label>20</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[L&#8217;heureux]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Grolinger]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
<name>
<surname><![CDATA[Yamany]]></surname>
<given-names><![CDATA[H. F. El]]></given-names>
</name>
<name>
<surname><![CDATA[Capretz]]></surname>
<given-names><![CDATA[M. A. M.]]></given-names>
</name>
<name>
<surname><![CDATA[L&#8217;heureux]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Grolinger]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
</person-group>
<source><![CDATA[Machine Learning with Big Data: Challenges and Approaches 4 PUBLICATIONS 100 CITATIONS SEE PROFILE]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B21">
<label>21</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kaluza]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
</person-group>
<source><![CDATA[Instant Weka how-to: implement cutting-edge data mining aspects in Weka to your applications]]></source>
<year>2013</year>
<publisher-name><![CDATA[Packt Pub]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B22">
<label>22</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Tao]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Member]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Tang]]></surname>
<given-names><![CDATA[X.]]></given-names>
</name>
<name>
<surname><![CDATA[Member]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Li]]></surname>
<given-names><![CDATA[X.]]></given-names>
</name>
<name>
<surname><![CDATA[Wu]]></surname>
<given-names><![CDATA[X.]]></given-names>
</name>
</person-group>
<source><![CDATA[Asymmetric Bagging and Random Subspace for Support Vector Machines-Based Relevance Feedback in Image Retrieval]]></source>
<year></year>
</nlm-citation>
</ref>
<ref id="B23">
<label>23</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Anthon]]></surname>
<given-names><![CDATA[J. M. G.]]></given-names>
</name>
<name>
<surname><![CDATA[Viera]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<source><![CDATA[Understanding interobserver agreement: the kappa statistic]]></source>
<year>2005</year>
</nlm-citation>
</ref>
<ref id="B24">
<label>24</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Willmott]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Matsuura]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Advantages of the mean absolute error (MAE) over the root mean square error (RMSE) in assessing average model performance]]></article-title>
<source><![CDATA[Clim. Res.]]></source>
<year>2005</year>
<volume>30</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>79-82</page-range></nlm-citation>
</ref>
<ref id="B25">
<label>25</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Lippmann]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<source><![CDATA[Validating and Restoring Defense in Depth Using Attack Graphs]]></source>
<year>2006</year>
<conf-name><![CDATA[ MILCOM]]></conf-name>
<conf-date>2006</conf-date>
<conf-loc> </conf-loc>
<page-range>1-10</page-range></nlm-citation>
</ref>
<ref id="B26">
<label>26</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Snapp]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
</person-group>
<source><![CDATA[DIDS (Distributed Intrusion Detection System) - Motivation, Architecture, and An Early Prototype]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B27">
<label>27</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mansoori]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Welch]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Fu]]></surname>
<given-names><![CDATA[Q.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[YALIH, yet another low interaction honeyclient]]></article-title>
<source><![CDATA[Proc. Twelfth Australas. Inf. Secur. Conf]]></source>
<year>2014</year>
<volume>149</volume>
<page-range>7-15</page-range></nlm-citation>
</ref>
<ref id="B28">
<label>28</label><nlm-citation citation-type="">
<collab>Symantec Corporation</collab>
<source><![CDATA[ISTR Internet Security Threat Report]]></source>
<year>2018</year>
<publisher-loc><![CDATA[Mountain View, CA ]]></publisher-loc>
</nlm-citation>
</ref>
<ref id="B29">
<label>29</label><nlm-citation citation-type="">
<collab>S. Corporation</collab>
<source><![CDATA[ISTR Internet Security Threat Report Volume 23]]></source>
<year>2018</year>
<publisher-loc><![CDATA[Mountain View, CA ]]></publisher-loc>
</nlm-citation>
</ref>
<ref id="B30">
<label>30</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Yokoyama]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Sandprint: Fingerprinting malware sandboxes to provide intelligence for sandbox evasion]]></article-title>
<source><![CDATA[Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)]]></source>
<year>2016</year>
<volume>9854</volume>
<page-range>165-87</page-range><publisher-name><![CDATA[LNCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B31">
<label>31</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Harley]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Slade]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Gattiker]]></surname>
<given-names><![CDATA[U. E.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Polymorphism]]></article-title>
<source><![CDATA[Viruses Revealed: Understand and counter maliciosus software]]></source>
<year>2001</year>
<page-range>10</page-range><publisher-loc><![CDATA[United States ]]></publisher-loc>
<publisher-name><![CDATA[McGraw-Hill/Osborne]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B32">
<label>32</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Stephens]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Sandbox]]></article-title>
<person-group person-group-type="editor">
<name>
<surname><![CDATA[van Tilborg]]></surname>
<given-names><![CDATA[H. C. A.]]></given-names>
</name>
<name>
<surname><![CDATA[Jajodia]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
</person-group>
<source><![CDATA[Encyclopedia of Cryptography and Security]]></source>
<year>2011</year>
<page-range>1075-8</page-range><publisher-loc><![CDATA[Boston, MA ]]></publisher-loc>
<publisher-name><![CDATA[Springer US]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B33">
<label>33</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ed]]></surname>
<given-names><![CDATA[Gass S.I.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Machine Learning]]></article-title>
<source><![CDATA[Encyclopedia of Operations Research and Management Science]]></source>
<year>2013</year>
<page-range>909</page-range><publisher-loc><![CDATA[Boston, MA ]]></publisher-loc>
<publisher-name><![CDATA[Springer US]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B34">
<label>34</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Schreuders]]></surname>
<given-names><![CDATA[Z. C.]]></given-names>
</name>
<name>
<surname><![CDATA[McGill]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Payne]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[The state of the art of application restrictions and sandboxes: A survey of application-oriented access controls and their shortfalls]]></article-title>
<source><![CDATA[Comput. Secur]]></source>
<year>2013</year>
<volume>32</volume>
<page-range>219-41</page-range></nlm-citation>
</ref>
<ref id="B35">
<label>35</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Daniel]]></surname>
<given-names><![CDATA[D. P.]]></given-names>
</name>
<name>
<surname><![CDATA[Bovet]]></surname>
<given-names><![CDATA[P.]]></given-names>
</name>
<name>
<surname><![CDATA[Cesati]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<source><![CDATA[Understanding the Linux kernel]]></source>
<year>2002</year>
<publisher-loc><![CDATA[United States of America ]]></publisher-loc>
<publisher-name><![CDATA[O&#8217;Reilly]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B36">
<label>36</label><nlm-citation citation-type="">
<collab>CGFM</collab>
<source><![CDATA[Comando Conjunto Cibernético]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B37">
<label>37</label><nlm-citation citation-type="">
<collab>PONAL</collab>
<source><![CDATA[CSIRT - Equipo de Respuesta a Incidentes Informáticos]]></source>
<year></year>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
