<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>When Side-channel Meets Malware</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Duy-Phuc Pham</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Damien Marion</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Annelie Heuser</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Univ Rennes</institution>
          ,
          <addr-line>CNRS, Inria, IRISA Rennes</addr-line>
          ,
          <country country="FR">France</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2023</year>
      </pub-date>
      <fpage>71</fpage>
      <lpage>77</lpage>
      <abstract>
        <p>The Internet of Things (IoT) is a collection of interconnected devices, each becoming increasingly complicated and numerous. They frequently employ modified hardware and software without taking security risks into account, which makes them a target for cybercriminals, especially malware and rootkit crafter. In this extended abstract, we will present two strategies for exploiting electromagnetic side channels to address two issues: rootkit detection dificulties and malware categorization challenges in the presence of obfuscations. Both tactics center on IoT devices, target ARM (raspberry-Pi) and MIPS (CI.20) architectures, and use machine/deep learning techniques. These results were published at, ∙ ACSAC-2021: “Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware Classification” [1] (with an extended version presented at hardwear.io'22 USA), ∙ RAID-2022: “ULTRA: Ultimate Rootkit Detection over the Air”[2].</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Malware classification</kwd>
        <kwd>obfuscation</kwd>
        <kwd>side-channel analysis</kwd>
        <kwd>rootkit detection</kwd>
        <kwd>SDR (software defined radio)</kwd>
        <kwd>machine learning/deep learning</kwd>
        <kwd>Electromagnetic</kwd>
        <kwd>IoT devices</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>show that we are able to classify altered malware samples with unseen obfuscation techniques
during the training phase, and to determine what kind of obfuscations were applied to the
binary, which makes our approach particularly useful for malware analysts.
• Targets: Raspberry Pi 2B (ARM processor), CI20 (MIPS processor),
• Acquisition: Picoscope 6407, H-Field Probe (Langer RF-R 0.3-3), connected to a H-Field
Probe (Langer RF-R 0.3-3), where the EM signal is amplified using a Langer PA-303 +30dB
(Fig. 1).
• Samples, labels, number of traces: all information available in tabular 3.
• code:</p>
      <p>→ https://github.com/ahma-hub
• data:</p>
      <p>→ https://zenodo.org/record/5414107
• talk at hardwear.io’22 USA of an extended version (with a additional target board CI20
embedded a MIPS processor):
→ https://m.youtube.com/watch?v=oCohqwfUpsQ&amp;feature=youtu.be
State-of-the-art A summary of the state-of-the-art, regarding malware analysis througth
side-channel is available in Tab. 1.
2. ULTRA: Ultimate Rootkit Detection over the Air
We suggest the ULTRA framework, which operates outside of the “box” (literal device) and
requires no resources from the target device, , as visible on Figure 2, to identify rootkits efectively
and eficiently. A software-defined radio is used by ULTRA to measure electromagnetic emission,
preprocess signals, and then detect and categorize rootkit activities. ULTRA baits the rootkit
to elicit action. We focus on two IoT devices with ARM and MIPS architectures as use cases.
During the ofline learning phase, the suggested method produced encouraging results with high
accuracy for detecting both known and unknown rootkits. The classification of rootkit families
and distinctive variants, obfuscated rootkits, probe dislocation, benign noise (kernel) activities,
and comparison with software-based solutions are all part of our experimental investigation.</p>
    </sec>
    <sec id="sec-2">
      <title>Setup description</title>
      <p>• Targets: Raspberry Pi 2B (ARM processor), CI20 (MIPS processor),
• Acquisition: SDR (software define radio, hackRF), H-Field Probe (Langer RF-R 0.3-3),
connected to a H-Field Probe (Langer RF-R 0.3-3), where the EM signal is amplified using
a Langer PA-303 +30dB (Fig. 2).</p>
    </sec>
    <sec id="sec-3">
      <title>Resources</title>
      <p>• code:</p>
      <p>→ https://gitlab.com/ultra-RK/ultra
• data:</p>
      <p>→ https://zenodo.org/record/5902451
State-of-th-art A summary of the state-of-the-art, regarding rootkit detection by side-channel
is available in Tab. 2.
Comparison with related works on kernel-level or user-level rootkit (user RK) detection using diferent
side-channel analysis techniques: HPC, DMA, Power consumption (Power) and EM.</p>
      <p>Article</p>
      <p>WnP</p>
      <p>Baits</p>
      <p>ML</p>
      <p>DL
Classification
✗
✗
✗
✗
✗
✗
✗
✗
✗
✗
✗</p>
      <p>Sample
size
8
5
4
12
23
5
5
9
3. Ongoing Next-steps
Currently, we are focusing on the reproducibility of our results. First, we are in contact with
researchers that are building the same setup. Second, we built student projects to make the
ULTRA framework more portable using a Jetson Nano board that embeds a GPU. Finally, we
are collaborating to improve the classification step.
Acknowledgments
The work was supported by the French Agence Nationale de la Recherche (ANR) under reference
ANR-18-CE39-0001 (AHMA). We thank our colleague Ronan Lashermes and Olivier Zendra
who provided hardware and side-channel insights and greatly assisted this work.
] ] ] ]
* * + +
[ [ [ [
] ] ] ] ]
[* [* [* [+ [* ] ] ]* ]* ]+ ]* ]* ]* ]+ en ign</p>
      <p>y y y y * + [ [ [ [ [ [ [ c t
rcaynn []*rcy rcann rcann rcann rcann itt[ok itt[ok litseh litseh litseh litseh litseh ][* litseh litseh ignn ignn ignn ignn tsao tseeh
s t
o a o o o o o o a a a a a e ab ab eb eb eb eb r .
g n g g g g r r b b b b b lit fe sp
e e
r r
(
r i n
lttsceeaagbxuE ra34odnm iiram iireaaa_qoddpum liiiitrrzeaa_vum fliiittreaa_nm iif-rcabm fliitt-rceaaanm ii-rsabum ii-raxpum rcagoynn -rcaxgoypunn --rsceaaxgoypunn -rsceaagoynn -rsceagodynn --rsceaxgodypunn liitrrzceaa2_vgoyunn flttrceaa_goynnn frcca_bgoynn rsca_bgoyunn flttrcceaa_goynnn rceaaa_gqooddypunn iitttra__ookKm iiittrs_ookkn litseabh liftscea_bbh fllitttseeaa_bhn litsea_xbpuh litseeaaa_bqoddpuh lflitttsceeaa_bhhn litssea_bbuh lliiittrszeeaa_bvuh liaaodypu rrrcceeaaodm ittrceeakpu iceeevooddn .lcceeaouhhnnTm iittrseeaagphhnn
sg m irm go sab scea irgn
ta tr du
d
n</p>
      <p>y y y y y y y y y y y
ilaym iegnn iira iira iira ira iira ia iira iira rcaonn rcaonn rcaonn rcaonn rcaonn rcaonn rcaonn rcaynn rcaonn rcaonn rcaonn rcaonn ita_K iisn litseah litseah litseah litseah litseah liteh litseah litseah iegnn iegnn iegnn iegnn lreaaw eebun itrraon
F b m m m i m ir m m g g g g g g g o g g g g m k b b b b b sa b b b b b b m sa f
m m g b ll h %</p>
      <p>e
+ .k u e
iissreeaannm a34odnm .iirraa7m iireaaa_qoddpu Pliiiitrrzeaa_vurocfliittreaa_neediif-rcabingfliitt-rceaansoii-rsabufthii-raxpme30rcaoynnth C-rcaxgoypnn&amp;E--sceaxgopunSA-rsceagoynR-rsceagoynn(20--sexgopunn23)irrca_oynnV flttrceaa_oynn frcca_boynn rsca_boyunn flttrcceaa_oynnn rcaaa_ooddypnn ..it-a459177_vK ..ii--s914577vn+ litseah liftscea_bh fllitttseeaa_hn litsea_xpuh litseaaa_qoddph fllitttsceeaa_hn litssea_buh lliiittrszeaa_vuh liaaodyu rrcceeaaodm 7itrceeakpu7 iceevooddn :ltreaaagwmM ltsceeaaphhm lrssseeaapum
B r m m m m m m m u g u a a d d g g g g g g m k b b b b b b b b p r t e 3
e e e e e e e e e e e
a a a a a a a re ra ra ra ra
r r r r r r r
u e
q iz
a l
p a
fu od tru n f en b x x x
bO ad iv tte cb tt su pu pu pu
lfa lfa</p>
      <p>c
s
g d
a e
t k
r c
e a</p>
      <p>p
k _
c t
a o
P n
d
e
z
i
l
a
u
t u
ir irg itr
V o v
d d d
e e e
k k k
c c c
d a d d a a d
e p e e p p e
k _ k k _ _ k
c t c c t t c
a o a a o o a
p n p p n n p
n p
tru n f b tte od
i te c u fla d
v t b s c a</p>
      <p>lfa
e
u e
aq liz
p a
n o u
f te x d en b tr
c t p d t u i
b fla u a t s v
lfa
c
y m
b a</p>
      <p>s</p>
      <p>p r
n s
g re fo
iebn (][* 20%</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>D.</given-names>
            <surname>Pham</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Marion</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mastio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Heuser</surname>
          </string-name>
          ,
          <article-title>Obfuscation revealed: Leveraging electromagnetic signals for obfuscated malware classification</article-title>
          , in: ACSAC '21: Annual Computer Security Applications Conference, Virtual Event, USA, December 6 -
          <issue>10</issue>
          ,
          <year>2021</year>
          , ACM,
          <year>2021</year>
          , pp.
          <fpage>706</fpage>
          -
          <lpage>719</lpage>
          . URL: https://doi.org/10.1145/3485832.3485894. doi:
          <volume>10</volume>
          .1145/3485832. 3485894.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>D.</given-names>
            <surname>Pham</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Marion</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Heuser</surname>
          </string-name>
          ,
          <article-title>ULTRA: ultimate rootkit detection over the air</article-title>
          ,
          <source>in: 25th International Symposium on Research in Attacks, Intrusions and Defenses</source>
          ,
          <string-name>
            <surname>RAID</surname>
          </string-name>
          <year>2022</year>
          , Limassol, Cyprus,
          <source>October 26-28</source>
          ,
          <year>2022</year>
          , ACM,
          <year>2022</year>
          , pp.
          <fpage>232</fpage>
          -
          <lpage>251</lpage>
          . URL: https://doi.org/10. 1145/3545948.3545962. doi:
          <volume>10</volume>
          .1145/3545948.3545962.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S. S.</given-names>
            <surname>Clark</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ransford</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Rahmati</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Guineau</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Sorber</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Fu</surname>
          </string-name>
          , Wattsupdoc:
          <article-title>Power side channels to nonintrusively discover untargeted malware on embedded medical devices</article-title>
          ,
          <source>in: 2013 USENIX Workshop on Health Information Technologies (HealthTech 13)</source>
          , USENIX Association, Washington, D.C.,
          <year>2013</year>
          . URL: https://www.usenix.org/conference/ healthtech13/workshop-program/presentation/clark.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>H. A.</given-names>
            <surname>Khan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Sehatbakhsh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. N.</given-names>
            <surname>Nguyen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. L.</given-names>
            <surname>Callan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Yeredor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Prvulovic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Zajic</surname>
          </string-name>
          , Idea:
          <article-title>Intrusion detection through electromagnetic-signal analysis for critical embedded and cyber-physical systems</article-title>
          ,
          <source>IEEE Transactions on Dependable and Secure Computing</source>
          (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>1</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>N.</given-names>
            <surname>Sehatbakhsh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Nazari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Alam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Werner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Zajic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Prvulovic</surname>
          </string-name>
          , Remote:
          <article-title>Robust external malware detection framework by using electromagnetic signals</article-title>
          ,
          <source>IEEE Transactions on Computers</source>
          <volume>69</volume>
          (
          <year>2020</year>
          )
          <fpage>312</fpage>
          -
          <lpage>326</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>X.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Zhou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Harer</surname>
          </string-name>
          , G. Brown,
          <string-name>
            <given-names>S.</given-names>
            <surname>Qiu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Dou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Hinton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. A.</given-names>
            <surname>Gonzalez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Chin</surname>
          </string-name>
          ,
          <article-title>Deep learning-based classification and anomaly detection of side-channel signals</article-title>
          ,
          <source>in: Cyber Sensing</source>
          <year>2018</year>
          , volume
          <volume>10630</volume>
          ,
          <string-name>
            <surname>International</surname>
            <given-names>Society</given-names>
          </string-name>
          <source>for Optics and Photonics</source>
          ,
          <year>2018</year>
          , p.
          <fpage>1063006</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>H. A.</given-names>
            <surname>Khan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Sehatbakhsh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. N.</given-names>
            <surname>Nguyen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Prvulovic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. G.</given-names>
            <surname>Zajic</surname>
          </string-name>
          ,
          <article-title>Malware detection in embedded systems using neural network model for electromagnetic side-channel signals</article-title>
          ,
          <source>J. Hardware and Systems Security</source>
          <volume>3</volume>
          (
          <year>2019</year>
          )
          <fpage>305</fpage>
          -
          <lpage>318</lpage>
          . URL: https://doi.org/10.1007/ s41635-019-00074-w. doi:
          <volume>10</volume>
          .1007/s41635-019-00074-w.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>F.</given-names>
            <surname>Ding</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Luo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Hu</surname>
          </string-name>
          , L. Cheng, H. Xiao,
          <string-name>
            <given-names>R.</given-names>
            <surname>Ge</surname>
          </string-name>
          , Deeppower:
          <article-title>Non-intrusive and deep learning-based detection of iot malware using power side channels</article-title>
          ,
          <source>in: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>33</fpage>
          -
          <lpage>46</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>N.</given-names>
            <surname>Chawla</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Mukhopadhyay</surname>
          </string-name>
          ,
          <article-title>Machine learning in wavelet domain for electromagnetic emission based malware analysis</article-title>
          ,
          <source>IEEE Transactions on Information Forensics and Security</source>
          <volume>16</volume>
          (
          <year>2021</year>
          )
          <fpage>3426</fpage>
          -
          <lpage>3441</lpage>
          . doi:
          <volume>10</volume>
          .1109/TIFS.
          <year>2021</year>
          .
          <volume>3080510</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>X.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Karri</surname>
          </string-name>
          , Numchecker:
          <article-title>Detecting kernel control-flow modifying rootkits by using hardware performance counters</article-title>
          ,
          <source>in: 2013 50th ACM/EDAC/IEEE Design Automation Conference (DAC)</source>
          , IEEE,
          <year>2013</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>B.</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Evtyushkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Elwell</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Riley</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Cervesato</surname>
          </string-name>
          ,
          <article-title>On the detection of kernel-level rootkits using hardware performance counters</article-title>
          ,
          <source>in: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>483</fpage>
          -
          <lpage>493</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>X.</given-names>
            <surname>Jiang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Lora</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Chattopadhyay</surname>
          </string-name>
          ,
          <article-title>Eficient and trusted detection of rootkit in iot devices via ofline profiling and online monitoring</article-title>
          ,
          <source>in: Proceedings of the 2020 on Great Lakes Symposium on VLSI</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>433</fpage>
          -
          <lpage>438</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>N. L.</given-names>
            <surname>Petroni</surname>
          </string-name>
          Jr,
          <string-name>
            <given-names>T.</given-names>
            <surname>Fraser</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Molina</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W. A.</given-names>
            <surname>Arbaugh</surname>
          </string-name>
          ,
          <article-title>Copilot-a coprocessor-based kernel runtime integrity monitor</article-title>
          .,
          <source>in: USENIX security symposium</source>
          , San Diego, USA,
          <year>2004</year>
          , pp.
          <fpage>179</fpage>
          -
          <lpage>194</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Baliga</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Ganapathy</surname>
          </string-name>
          , L. Iftode,
          <article-title>Detecting kernel-level rootkits using data structure invariants</article-title>
          ,
          <source>IEEE Transactions on Dependable and Secure Computing</source>
          <volume>8</volume>
          (
          <year>2011</year>
          )
          <fpage>670</fpage>
          -
          <lpage>684</lpage>
          . doi:
          <volume>10</volume>
          .1109/TDSC.
          <year>2010</year>
          .
          <volume>38</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>P.</given-names>
            <surname>Luckett</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. T.</given-names>
            <surname>McDonald</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W. B.</given-names>
            <surname>Glisson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Benton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Dawson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B. A.</given-names>
            <surname>Doyle</surname>
          </string-name>
          ,
          <article-title>Identifying stealth malware using cpu power consumption and learning algorithms</article-title>
          ,
          <source>Journal of Computer Security</source>
          <volume>26</volume>
          (
          <year>2018</year>
          )
          <fpage>589</fpage>
          -
          <lpage>613</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>R.</given-names>
            <surname>Bridges</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. H.</given-names>
            <surname>Jiménez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Nichols</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Goseva-Popstojanova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Prowell</surname>
          </string-name>
          ,
          <article-title>Towards malware detection via cpu power consumption: Data collection design and analytics</article-title>
          ,
          <source>in: 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/12th IEEE International Conference On Big Data Science</source>
          And Engineering (TrustCom/BigDataSE), IEEE,
          <year>2018</year>
          , pp.
          <fpage>1680</fpage>
          -
          <lpage>1684</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>