{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:31:01Z","timestamp":1759091461527},"publisher-location":"Berlin, Heidelberg","reference-count":23,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540397236"},{"type":"electronic","value":"9783540397250"}],"license":[{"start":{"date-parts":[[2006,1,1]],"date-time":"2006-01-01T00:00:00Z","timestamp":1136073600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11856214_9","type":"book-chapter","created":{"date-parts":[[2006,9,16]],"date-time":"2006-09-16T07:12:21Z","timestamp":1158390741000},"page":"165-184","source":"Crossref","is-referenced-by-count":132,"title":["The Nepenthes Platform: An Efficient Approach to Collect Malware"],"prefix":"10.1007","author":[{"given":"Paul","family":"Baecher","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Markus","family":"Koetter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thorsten","family":"Holz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maximillian","family":"Dornseif","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Felix","family":"Freiling","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"unstructured":"Anagnostakis, K., Sidiroglou, S., Akritidis, P., Xinidis, K., Markatos, E., Keromytis, A.: Detecting Targeted Attacks Using Shadow Honeypots. In: Proceedings of the 14th USENIX Security Symposium (2005)","key":"9_CR1"},{"unstructured":"Bailey, M., Cooke, E., Jahanian, F., Nazario, J., Watson, D.: The Internet Motion Sensor: A Distributed Blackhole Monitoring System. In: Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS 2005) (2005)","key":"9_CR2"},{"key":"9_CR3","volume-title":"Proceeedings of the 6th IEEE Information Assurance Workshop","author":"E. Balas","year":"2005","unstructured":"Balas, E., Viecco, C.: Towards a Third Generation Data Capture Architecture for Honeynets. In: Proceeedings of the 6th IEEE Information Assurance Workshop, West Point. IEEE, Los Alamitos (2005)"},{"unstructured":"Team Cymru: The Darknet Project. Internet (accessed 2006), \n                      \n                        http:\/\/www.cymru.com\/Darknet\/","key":"9_CR4"},{"unstructured":"Dagon, D., Zou, C., Lee, W.: Modeling Botnet Propagation Using Time Zones. In: Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS 2006) (2006)","key":"9_CR5"},{"key":"9_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/11555827_19","volume-title":"Computer Security \u2013 ESORICS 2005","author":"F.C. Freiling","year":"2005","unstructured":"Freiling, F.C., Holz, T., Wicherski, G.: Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks. In: di Vimercati, S.d.C., Syverson, P.F., Gollmann, D. (eds.) ESORICS 2005. LNCS, vol.\u00a03679, pp. 319\u2013335. Springer, Heidelberg (2005)"},{"issue":"3","key":"9_CR7","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSP.2005.58","volume":"3","author":"T. Holz","year":"2005","unstructured":"Holz, T.: A Short Visit to the Bot Zoo. IEEE Security & Privacy\u00a03(3), 76\u201379 (2005)","journal-title":"IEEE Security & Privacy"},{"issue":"6","key":"9_CR8","first-page":"18","volume":"30","author":"T. Holz","year":"2005","unstructured":"Holz, T.: Spying With Bots. USENIX; login\u00a030(6), 18\u201323 (2005)","journal-title":"USENIX ;login"},{"unstructured":"Jiang, X., Xu, D.: Collapsar: A vm-based architecture for network attack detention center. In: Proceedings of 13th USENIX Security Symposium (2004)","key":"9_CR9"},{"issue":"5","key":"9_CR10","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1109\/MSECP.2003.1236244","volume":"1","author":"B. McCarty","year":"2003","unstructured":"McCarty, B.: Automated Identity Theft. IEEE Security & Privacy\u00a01(5), 89\u201392 (2003)","journal-title":"IEEE Security & Privacy"},{"unstructured":"Moore, D., Shannon, C., Voelker, G.M., Savage, S.: Network Telescopes. Technical Report TR-2004-04, CAIDA (2004)","key":"9_CR11"},{"doi-asserted-by":"crossref","unstructured":"Moore, D., Voelker, G.M., Savage, S.: Inferring Internet Denial-of-Service Activity. In: Proceedings of the 10th USENIX Security Symposium (August 2001)","key":"9_CR12","DOI":"10.21236\/ADA400003"},{"doi-asserted-by":"crossref","unstructured":"Portokalidis, G.: Argos: An Emulator for Capturing Zero-Day Attacks. Internet (accessed 2006), \n                      \n                        http:\/\/www.few.vu.nl\/~porto\/argos\/","key":"9_CR13","DOI":"10.1145\/1217935.1217938"},{"unstructured":"Provos, N.: A Virtual Honeypot Framework. In: Proceedings of 13th USENIX Security Symposium, pp. 1\u201314 (2004)","key":"9_CR14"},{"unstructured":"Rajab, M.A., Terzis, A.: On the Effectiveness of Distributed Worm Monitoring. In: Proceedings of the 14th USENIX Security Symposium (2005)","key":"9_CR15"},{"unstructured":"Shinoda, Y., Ikai, K., Itoh, M.: Vulnerabilities of Passive Internet Threat Monitors. In: Proceedings of the 14th USENIX Security Symposium (2005)","key":"9_CR16"},{"doi-asserted-by":"crossref","unstructured":"Staniford, S., Moore, D., Paxson, V., Weaver, N.: The Top Speed of Flash Worms. In: ACM Workshop on Rapid Malcode (WORM) (2004)","key":"9_CR17","DOI":"10.1145\/1029618.1029624"},{"unstructured":"Symantec. Mantrap. Internet (accessed, 2006), \n                      \n                        http:\/\/www.symantec.com\/","key":"9_CR18"},{"unstructured":"Vanderavero, N., Brouckaert, X., Bonaventure, O., Le Charlier, B.: The HoneyTank: a scalable approach to collect malicious Internet traffic. In: Proceedings of the International Infrastructure Survivability Workshop (2004)","key":"9_CR19"},{"doi-asserted-by":"crossref","unstructured":"Vrable, M., Ma, J., Chen, J., Moore, D., Vandekieft, E., Snoeren, A.C., Voelker, G.M., Savage, S.: Scalability, Fidelity, and Containment in the Potemkin Virtual Honeyfarm. In: Proceedings of the ACM Symposium on Operating System Principles (SOSP) (2005)","key":"9_CR20","DOI":"10.1145\/1095810.1095825"},{"unstructured":"Wang, K.: Honeyclient. Internet (accessed, 2006), \n                      \n                        http:\/\/honeyclient.org","key":"9_CR21"},{"unstructured":"Wang, Y.-M., Beck, D., Verbowski, C., Chen, S., King, S., Jiang, X., Roussev, R.: Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities. In: Proceedings of the 13th Network and Distributed System Security Symposium (NDSS 2006) (2006)","key":"9_CR22"},{"key":"9_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1007\/978-3-540-30143-1_8","volume-title":"Recent Advances in Intrusion Detection","author":"V. Yegneswaran","year":"2004","unstructured":"Yegneswaran, V., Barford, P., Plonka, D.: On the Design and Use of Internet Sinks for Network Abuse Monitoring. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 146\u2013165. Springer, Heidelberg (2004)"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11856214_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T17:55:15Z","timestamp":1558288515000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11856214_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540397236","9783540397250"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/11856214_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2006]]}}}