<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>On the Time Series of Antivirus Testing Procedures</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>László Bognár</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Antal Joós</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Bálint Nagy</string-name>
          <email>nagyb@uniduna.hu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Proceedings of the 1</institution>
        </aff>
      </contrib-group>
      <fpage>77</fpage>
      <lpage>89</lpage>
      <abstract>
        <p>In this work, a so-called “Time Evolution Model” is suggested to help categorize files of a sample set used in antivirus testing procedures. The basic time-dependent variable of this model is the Ratio of the Infected files within an investigated Time Window. To estimate the main characteristics of the time series describing the change of the Ratio values related to a specific file, a nonlinear, exponential curve fitting method is used. The free parameters of the model were determined by numerical searching algorithms. The effectiveness and the reliability of the model is also demonstrated by several real-word and numerically simulated examples.</p>
      </abstract>
      <kwd-group>
        <kwd>Vulnerability</kwd>
        <kwd>probability</kwd>
        <kwd>relative frequency</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        As business and people rely more and more on computer related devices (including
smart devices and the IoT), they are increasingly vulnerable to cyber-attacks [
        <xref ref-type="bibr" rid="ref15 ref3">3,
15</xref>
        ]. These attacks include threats of social networks [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] data phishing, malicious
Copyright © 2021 for this paper by its authors. Use permitted under Creative Commons License
Attribution 4.0 International (CC BY 4.0).
programs [17], etc. The defense against malware is composed of malware detectors,
systems that investigate malicious objects (mainly files and URLs). Several
malware detection techniques and methods to investigate the vulnerability of systems
are introduced in the literature [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>
        Security solution testers use malicious files (sample set) coming from diferent
sources to determine whether the defense is able to detect these files as malicious
or not [
        <xref ref-type="bibr" rid="ref13 ref15 ref2 ref7 ref9">2, 7, 9, 13, 15</xref>
        ].
      </p>
      <p>One of the most important parts of the testing procedure influencing the
reliability of the procedure is the correct and relevant selection of the used sample
set.</p>
      <p>
        How to correctly classify samples of a sample set is one the major issues for
security solution testers to ensure their service to be reliable and to be able to
give relevant recommendations for their client about the capabilities of security
solutions [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Evaluating the eficiency of diferent antiviruses (AV), diferent
antivirus vendors or even testing the level of security in a corporation requires reliable
information about the samples [
        <xref ref-type="bibr" rid="ref8">1, 8</xref>
        ].
      </p>
      <p>
        Besides the main question whether a given object (file/URL) (abbreviated only
ifle in what follows) in a sample set is “ Infected ” or “ Noninfected ” [
        <xref ref-type="bibr" rid="ref11 ref4">4, 11</xref>
        ], in case
of the infected files the “freshness” of the infection is also an important issue. The
starting time of operation of a malware is essential for categorizing the malware as
“ New ” or “ Old ”.
      </p>
      <p>
        Sample selection can be broken down into three phases [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]:
• Collection
• Validation
• Classification
In this paper the classification phase is in focus, however some aspects of the
validation phase are also incorporated. It is assumed that the collection was correct,
and the sample consists of real-world, prevalent, fresh, diverse files collected
independently.
      </p>
      <p>The sample validation process essentially is series of tests to make sure that the
sample is functional (has working malicious function). There are several methods
trying to validate samples: reverse engineering, usage of automated tools or by
using various specialized tools (e.g. sandboxes) to check file integrity or functionality.</p>
      <p>Best practices show that validation is most valuable when it is based on sample
functionality, but these methods are not applicable to all sample types and may
need enormous eforts to pursue these kinds of activities on a daily basis with huge
number of files.</p>
      <p>In this paper a so-called “ Time Evolution Model ” is suggested to help categorize
each file or even a whole sample set (also called as feed).</p>
      <p>The basic time-dependent variable of this model is the Ratio of the “ Yes”
decisions to the question: Is this file infected? The answers come from the members
of a set of antimalware where most of these members showed reliable operations in
the past in malware detection.</p>
      <p>After the appearance of a new malware it takes less or more time for the diferent
antimalware to detect the fact of infection. Some antimalware is simply not able to
recognize some specific infections. (Possibly due to some validation issue.) Hence
the ratio of “ Yes” decisions is gradually increasing in time and reaches the state
when the increase and the variation of the Ratio value is small enough to establish
this Ratio as the steady state value of the time evolution.</p>
      <p>The main goal of this study is to establish the main characteristics of these time
functions. A nonlinear curve fitting method is used to fit a smooth time function
on the observed Ratio data to estimate the steady state value (called Asymptote),
the Start Time (starting time of operation) and the Slope at the Start Time for
each file in a feed. These parameters can be used later to classify a file belonging
to a certain category (“ Old ”, “ New ”, “ Infected ”, “ Noninfected ”, etc.).</p>
      <p>For this estimation past Ratio data within a Time Window are used. The Time
Window ends at the moment of investigation (“Today”) and goes back in time.
Obviously, the length of time, how far the Time Window goes back, has influence
on the estimation. It is also investigated.</p>
      <p>The reliability of the “Yes” decisions of the antiviruses is crucial. In this study
it is assumed that the antimalware set consists of properly selected members. The
process of selection resulting in a reliable set is discussed elsewhere.</p>
    </sec>
    <sec id="sec-2">
      <title>2. General Features of the Time History of Malware</title>
    </sec>
    <sec id="sec-3">
      <title>Detections</title>
      <p>As an example, in Table 1 the results of classifications for a sample of files are
summarized.
. . .</p>
      <p>AV 100</p>
      <p>Yes
No
#AV
97
93
#Yes 
34
43
Yes
Yes
No
Yes
No
No
Yes</p>
      <p>The cells of the table show the  /  results of classifications for   =
1000 diferent files by   = 100 antiviruses for 17 days. Typically, not all files
are checked by all  on all days, so some cells contain no data. In the Ratio
column the ratio of the number of   -es (#  ) and the number of nonempty
cells (# ) in the given row is calculated.</p>
      <p>The time evolution of the Ratio variables is better representable by time series
graphs. In Figure 1 typical graphs for diferent files are shown where the diferent
ifles are in diferent phases of antimalware detection. In Figure 2 those files are
selected which can be considered as “ Old ” infected files.</p>
      <p>Here the values of the Ratio variable show little fluctuation around diferent
“imaginary”, almost horizontal lines for the diferent files. This steady state
feature forecasts not much change in the future, so these steady state Ratio values
can be the basis for classifying the diferent files. Depending on the purpose of
classification diferent threshold values can be decided in advance to categorize the
ifles. If only two categories are used, above some predefined   value
(e.g.   = 0.7) a file can be taken as an “ Infected ” file, otherwise as
“ Noninfected ”. Sometimes three categories are better to use: “ Infected ”, “
Noninfected ”, “ Gray ”. In this case two threshold values   and   (e.g.
  = 0.7 and   = 0.4) can divide the zero-one interval into
three diferent classification categories. The details for establishing these threshold
values are not discussed here.</p>
      <p>In Figure 3 and in Figure 4 the situations are diferent. Both figures suggest
that the gradual increases of the Ratio values have not been finished, the infections
are “ New ”, they have been detected recently. These forecast additional increases
in Ratio values, so the steady state Ratio values are in questions. In Figure 3 the
graphs suggest the Start Time-s of the infection outside the Time Window while
the graphs in Figure 4 suggest them inside.</p>
    </sec>
    <sec id="sec-4">
      <title>3. The Time Evolution Model</title>
      <p>To estimate the main characteristics of the time series describing the change of
the Ratio values related to a specific file, nonlinear curve fitting method is used.
For each file a theoretical time function is fitted to the observed Ratio values. In
Figure 5 the notations are summarized.</p>
      <p>Malware Detection in Time
)
s
b
o
y
,(
y
o
i
t
a
R</p>
      <sec id="sec-4-1">
        <title>Asymptote</title>
        <sec id="sec-4-1-1">
          <title>Ratio Observed (yobs(t))</title>
        </sec>
      </sec>
      <sec id="sec-4-2">
        <title>Fitted Line (y(t))</title>
      </sec>
      <sec id="sec-4-3">
        <title>Ratio</title>
      </sec>
      <sec id="sec-4-4">
        <title>Increment (Δy)</title>
      </sec>
      <sec id="sec-4-5">
        <title>Time Window (Δt)</title>
      </sec>
      <sec id="sec-4-6">
        <title>Slope</title>
        <sec id="sec-4-6-1">
          <title>Start Time (tstart)</title>
        </sec>
        <sec id="sec-4-6-2">
          <title>First Time (tfirst)</title>
          <p>Age</p>
        </sec>
        <sec id="sec-4-6-3">
          <title>Last Time (tlast)</title>
        </sec>
      </sec>
      <sec id="sec-4-7">
        <title>Time (t)</title>
        <p>In what follows  
( ) or simply</p>
        <p>denotes the observed Ratio values in time.
(Sometimes the more precise</p>
        <p>
          (  ) is used since the observations are in discrete  
time instants.) The function  ( ) or simply  is the fitted function to be determined
as the best fitted function to the observed  
values. Hence
  ( ) =  ( ) +  ( )
(3.1)
where  ( ) is a random error term. The function  ( ) is searched in an exponential
form widely used in diferent growth models [
          <xref ref-type="bibr" rid="ref12 ref14">12, 14</xref>
          ],
where  1,  2 and  3 are free parameters to be determined. The method of least
squares can be used to determine the  1,  2,  3 free parameters. It requires the
minimization of the criterion
 ( ) =  1(1 −  − 2( − 3))
︁∑

 =1
 =
[ 
(  ) −  (  )]
2
where  is the number of observations within the Time Window.
        </p>
        <p>Unlike linear curve fitting, it is not possible to find analytical solution for the
least squares, instead numerical search procedures must be used. In the
examples presented here Matlab https://www.mathworks.com/products/matlab.html
software’s built in optimization procedures have been used.</p>
        <p>In the optimization the constrains</p>
        <p>1 ≤ 1 and  2 ≥ 0
category.</p>
        <p>The 
the beginning.
were applied.</p>
        <p>It is worth seeing that concrete “physical” meaning can be attributed to the
three free parameters in the model. The  1 value corresponds to the Asymptote
shown in Figure 5 Depending on the  1 value, a specific file can directly be classified
in to the “ Infected ” or “ Noninfected ” category.</p>
        <p>The parameter  3 is the Start Time when the infection begins.
Depending
on the  3 value, a specific file can directly be classified in to the “
Old ” or “ New ”
=  1 2 product gives the tangent of the angle at Start Time. This
Slope value may refer to the extent (the speed) of spread of a specific infection at</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>4. Examples for Curve Fitting</title>
      <p>Several samples, several real-world files’ time evolution models have been set up in
the present study. In Figure 6 some of them are presented where the final results
of the numerical search procedures for the  1,  2,  3 parameters are also shown.</p>
      <p>In all cases the present time (T“oday”) is denoted as   = 27. The Time
Window goes back to   = 1 and the time scale goes beyond   and   to
get some impression about the possible run of the curves in the past and in the
future. The diferent panels of the figure depict diferent detection situations. In
Figure 6b and in Figure 6d the graphs show more or less steady state situations
where Figure 6d reveals a “ Noninfected ” case when the detection started long time
before while the  1 = 0.428 value in Figure 6b refers to a rather uncertain case,
probably better to classify it as a “ Gray ” situation.</p>
      <p>In both, in Figure 6a and in Figure 6c the curves suggest further increases of
 values in time in “ Infected ” situations. However, the observed   values in
Figure 6c suggest less uncertainty in the estimated  1 = 0.682 Asymptote and in
the  3 = −3.018 Start Time values while the prediction for the  1 = 0.813 and the
 3 = −32.15 values in Figure 6a are probably more uncertain.</p>
    </sec>
    <sec id="sec-6">
      <title>5. Factors Influencing the Reliability of the Parameter Estimation</title>
      <p>It is obvious that the extent of uncertainty in the predicted  1,  2 and  3
parameters is dependent on the run of the observed   values. More precisely they are
influenced by the Δ( ) width, the location of the Time Window (relative to the
Time Start), and the spread of the   values (this can be characterized by the
( ) standard deviation in the model equation (3.1)).</p>
      <p>It needs further studies to establish confidence intervals for the  1,  2 and
 3 parameters. In this nonlinear curve fitting it is hopeless to get closed form
analytical solutions for these intervals but numerical simulation studies covering
the whole space of the influencing factors may help in determining them.</p>
      <p>In practice the question arises in the form: What is the minimal size of the
Time Window at a given file to get reliable estimates for the  parameters?</p>
      <p>To get some impression about the efects of the influencing factors, in Figure 7,
for two diferent files where the width of the</p>
      <p>Time Window is gradually widened.</p>
      <p>tfirst = 26
time to the malware’s start of operation good fit can be seen within the whole
Time Window. Hence the Start Time =  3 = 9.922 and the 
=  1 2 =
0.734 · 0.085 = 0.062 values can be regarded as good estimates. The value of
Asymptote =  1 = 0.731 holds more uncertainty, however, this Δ( ) = 20 wide
Time Window seems to be wide enough to produce a reliable Asymptote value to
classify the file as being “ Infected ”.</p>
      <p>In Figure 7a-c the fluctuations of the  parameter values can be seen as the
 
value approaches to the Time Start value.</p>
      <p>tfirst = 24
tfirst = 7</p>
      <p>tlast = 30</p>
      <p>In Figure 8 and in Figure 9 not a real world but a numerically simulated  
curve is used to illustrate the situation when the Start Time is outside the available
widest Time Window, so no chance to trace the  parameter values back to the
Start Time value.</p>
      <p>In Figure 9a the layout of the situation is summarized. The widest Time
Window is Δ( ) = 30 − 1 = 29 wide and within this window the   values have been
randomly simulated using the  = 0.9 −0.1( +10) deterministic function and the
normally distributed  random errors with zero mean and  ( ) = 0.015 standard
deviation.</p>
      <p>In Figure 9 the  ,   curves and the numerically searched  parameter values
are shown in case of four diferent Time Windows. It is worth seeing how far the
three numerically searched  parameters are from the deterministic  1 = 0.9,  2 =
0.1 ( = 0.9 · 0.1 = 0.09),  3 = −10 values.</p>
      <p>In Figure 9 the change of the  parameters is shown as the width of the Time
Window is gradually changing. It is worth following the tendencies of the change
backwards along the   axis. In Figure 9c and in Figure 9d as the   value is
decreasing from the   = 30 value (as the width of the Time Window is increasing)
the estimated Slope and  3 (Start Time) values are convincingly converging to their
deterministic values. After some fluctuation when the width of the Time Window
reaches the Δ( ) = 10 values the fluctuation becomes almost negligible. In Figure
9b the situation is even better. The estimated  1 parameter value (the Asymptote)
is very close to the deterministic  1 = 0.9 value even in the very narrow Time
Window cases. All these  1 values would classify the given file as being “ Infected ”.</p>
    </sec>
    <sec id="sec-7">
      <title>6. Conclusion</title>
      <p>In this paper a so called “Time Evolution Model” was suggested to help categorize
ifles of a sample set in antimalware testing procedures. The basic time dependent
variable of this model is the Ratio of the Infected files within an investigated Time
Window. To estimate the main characteristics of the time series describing the
change of the Ratio values related to a specific file, nonlinear, exponential curve
iftting method was used. The free parameters of the model were determined by
numerical searching algorithms, hence specific “physical” characteristics of the sample
set were calculated.</p>
      <p>The efectiveness and the reliability of the model was demonstrated by several
real-word and numerically simulated examples.</p>
      <p>Further studies are required to establish the extent of reliability of the model in
the whole parameter space and to give general recommendations for the minimal
size of the Time Window for reliable classifications.
[1] S. Brown, J. Gommers, O. Serrano: From Cyber Security Information Sharing to Threat
Management, in: Proceedings of the 2nd ACM Workshop on Information Sharing and
Collab[17] H. Yin, D. Song, M. Egele, C. Kruegel, E. Kirda: Panorama: Capturing system-wide
information flow for malware detection and analysis , in: Jan. 2007, pp. 116–127,
doi: 10.1145/1315245.1315261.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>orative</surname>
            <given-names>Security</given-names>
          </string-name>
          ,
          <source>WISCS '15</source>
          , Denver, Colorado, USA: Association for Computing Machinery,
          <year>2015</year>
          , pp.
          <fpage>43</fpage>
          -
          <lpage>49</lpage>
          , isbn: 9781450338226, doi: 10.1145/2808128.2808133, url: https://doi.org/10.1145/2808128.2808133.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>I.</given-names>
            <surname>Burguera</surname>
          </string-name>
          ,
          <string-name>
            <given-names>U.</given-names>
            <surname>Zurutuza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Nadjm-Tehrani</surname>
          </string-name>
          :
          <article-title>Crowdroid: Behavior-Based Malware Detection System for Android</article-title>
          , in: Oct.
          <year>2011</year>
          , pp.
          <fpage>15</fpage>
          -
          <lpage>26</lpage>
          , isbn: 9781450310000, doi: 10.1145/2046614.2046619.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>K.-K. R. Choo</surname>
          </string-name>
          :
          <article-title>The cyber threat landscape: Challenges and future research directions</article-title>
          ,
          <source>Computers and Security 30.8</source>
          (
          <issue>2011</issue>
          ), pp.
          <fpage>719</fpage>
          -
          <lpage>731</lpage>
          , issn:
          <fpage>0167</fpage>
          -
          <lpage>4048</lpage>
          , doi: https://doi.org/10.1016/j.cose.
          <year>2011</year>
          .
          <volume>08</volume>
          .004, url: http://www.sciencedirect.com/science/article/pii/S0167404811001040.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Christodorescu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Jha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Seshia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Song</surname>
          </string-name>
          , R. Bryant:
          <string-name>
            <surname>Semantics-Aware Malware</surname>
          </string-name>
          Detection, in: June 2005, pp.
          <fpage>32</fpage>
          -
          <lpage>46</lpage>
          , isbn:
          <fpage>0</fpage>
          -
          <lpage>7695</lpage>
          -2339-0, doi: 10.1109/SP.
          <year>2005</year>
          .
          <volume>20</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Z. A.</given-names>
            <surname>Collier</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Linkov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. H.</given-names>
            <surname>Lambert</surname>
          </string-name>
          :
          <article-title>Four domains of cybersecurity: a risk-based systems approach to cyber decisions</article-title>
          ,
          <source>English, Environment Systems and Decisions 33.4</source>
          (
          <issue>2013</issue>
          ), pp.
          <fpage>469</fpage>
          -
          <lpage>470</lpage>
          , doi: 10.1007/s10669-013-9484-z.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>W.</given-names>
            <surname>Gharibi</surname>
          </string-name>
          , M. Shaabi: Cyber Threats In Social Networking Websites,
          <source>International Journal of Distributed and Parallel Systems</source>
          <volume>3</volume>
          (Feb.
          <year>2012</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>K.</given-names>
            <surname>Hadarics</surname>
          </string-name>
          ,
          <string-name>
            <surname>F.</surname>
          </string-name>
          <article-title>Leitold: Improving distributed vulnerability assessment model of cybersecurity</article-title>
          ,
          <source>Central and Eastern European eDem and eGov Days</source>
          <volume>331</volume>
          (
          <year>July 2018</year>
          ), pp.
          <fpage>385</fpage>
          -
          <lpage>393</lpage>
          , doi: 10.24989/ocg.v331.
          <fpage>32</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>W.</given-names>
            <surname>Jansen</surname>
          </string-name>
          : Directions in Security Metrics Research (Jan.
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>F.</given-names>
            <surname>Leitold</surname>
          </string-name>
          <article-title>: Testing protections against web threats</article-title>
          ,
          <source>in: 2011 6th International Conference on Malicious and Unwanted Software</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>20</fpage>
          -
          <lpage>26</lpage>
          , doi: 10.1109/MALWARE.
          <year>2011</year>
          .
          <volume>6112322</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>F.</given-names>
            <surname>Leitold</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.</surname>
          </string-name>
          <article-title>Hadarics: Measuring security risk in the cloud-enabled enterprise</article-title>
          , in: Oct.
          <year>2012</year>
          , pp.
          <fpage>62</fpage>
          -
          <lpage>66</lpage>
          , isbn:
          <fpage>978</fpage>
          -1-
          <fpage>4673</fpage>
          -4880-5, doi: 10.1109/MALWARE.
          <year>2012</year>
          .
          <volume>6461009</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Moser</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Kruegel</surname>
          </string-name>
          , E. Kirda:
          <article-title>Limits of Static Analysis for Malware Detection</article-title>
          , in: Twenty-Third Annual Computer Security Applications Conference (ACSAC
          <year>2007</year>
          ),
          <year>2007</year>
          , pp.
          <fpage>421</fpage>
          -
          <lpage>430</lpage>
          , doi: 10.1109/ACSAC.
          <year>2007</year>
          .
          <volume>21</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          <source>[12] J. Murray: Mathematical Biology I: An Introduction</source>
          , vol.
          <volume>1</volume>
          ,
          <string-name>
            <surname>Jan</surname>
          </string-name>
          .
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>F.</given-names>
            <surname>Osorio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Leitold</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mike</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Pickard</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Miladinov</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          <article-title>Arrott: Measuring the efectiveness of modern security products to detect and contain emerging threats - A consensus-based approach</article-title>
          , in: Oct.
          <year>2013</year>
          , pp.
          <fpage>27</fpage>
          -
          <lpage>34</lpage>
          , isbn:
          <fpage>978</fpage>
          -1-
          <fpage>4799</fpage>
          -2534-6, doi: 10.1109/MALWARE.
          <year>2013</year>
          .
          <volume>6703682</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>G.</given-names>
            <surname>Serazzi</surname>
          </string-name>
          ,
          <string-name>
            <surname>S.</surname>
          </string-name>
          <article-title>Zanero: Computer Virus Propagation Models</article-title>
          . In: vol.
          <volume>2965</volume>
          ,
          <string-name>
            <surname>Jan</surname>
          </string-name>
          .
          <year>2003</year>
          , pp.
          <fpage>26</fpage>
          -
          <lpage>50</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <source>[15] Symantec: Symantec Internet security threat report</source>
          <year>2019</year>
          , https://www.symantec.com/ content/dam/symantec/docs/reports/istr- 24- 2019- en.pdf/, [Online; accessed 2-Okt2020],
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>C. H.</given-names>
            <surname>Tseng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <surname>T.</surname>
          </string-name>
          <article-title>Juang: Proactive malware collection and classification system: How to collect and classify useful malware samples?</article-title>
          ,
          <source>in: 2014 International Conference on Information Science, Electronics and Electrical Engineering</source>
          , vol.
          <volume>3</volume>
          ,
          <issue>2014</issue>
          , pp.
          <fpage>1846</fpage>
          -
          <lpage>1849</lpage>
          , doi: 10.1109/InfoSEEE.
          <year>2014</year>
          .
          <volume>6946241</volume>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>