{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:51:10Z","timestamp":1771699870761,"version":"3.50.1"},"publisher-location":"Boston, MA","reference-count":40,"publisher":"Springer US","isbn-type":[{"value":"9780387327204","type":"print"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-0-387-44599-1_8","type":"book-chapter","created":{"date-parts":[[2007,3,4]],"date-time":"2007-03-04T15:35:08Z","timestamp":1173022508000},"page":"171-191","source":"Crossref","is-referenced-by-count":62,"title":["An Inside Look at Botnets"],"prefix":"10.1007","author":[{"given":"Paul","family":"Barford","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"8_CR1","unstructured":"C. Associates. GTBotl. http:\/\/www3.ca.com\/securityadvisor\/pest\/pestaspx?id=453073312, 1998."},{"key":"8_CR2","unstructured":"M. Bailey, E. Cooke, F. Jahanian, J. Nazario, and D. Watson. The Internet Motion Sensor: A Distributed Blackhole Monitoring System. In Proceedings of the Network and Distributed Security Symposium, San Diego, CA, January 2005."},{"key":"8_CR3","unstructured":"P. Barford. The Wisconsin Advanced Internet Laboratory. http:\/\/wail.cs.wisc.edu, 2005."},{"key":"8_CR4","unstructured":"J. Canavan. The evolution of irc bots. In Proceedings of Wrus Bulletin Conference 2005,October 2005."},{"key":"8_CR5","unstructured":"E. Cooke, E Jahanian, and D. McPherson. The zombie roundup: Understanding, detecting and disrupting botnets. In Proceedings of Usenix Workshop on Stepts to Reducing Unwanted TrafJic on the Internet (SRUTI\u2019 05), Cambridge, MA, July 2005."},{"key":"8_CR6","unstructured":"P. Cousot, R. Cousot, J. Feret, L. Mauborgne, A. Mine, D. Monniaux, and X. Rival. The Astree Static Analyzer. http:\/\/www.astree.ens.fr, 2005."},{"key":"8_CR7","unstructured":"Coverity. Coverity Prevent. http:\/\/www.coverity.com, 2005."},{"key":"8_CR8","unstructured":"DETER. A laboratory for security research. http:\/\/www.isi.edu\/deter, 2005."},{"key":"8_CR9","unstructured":"D. Dietrich. Distributed Denial of Service (DDoS) Attacks\/tools. http:\/\/staff.washington.edu\/dittricNmisc\/ddos\/, 2005."},{"key":"8_CR10","unstructured":"J. Evers. Dutch Police Nab Suspected Bot Herders. CNET News.com, October 2005."},{"key":"8_CR11","unstructured":"F-Secure Corporation\u2019s Data Security Summary for 2004. http:\/\/www.f-secure.com\/2004, 2004."},{"key":"8_CR12","unstructured":"German Honeynet Project. Tracking Botnets. http:\/\/]www.honeynet.org\/papers\/bots, 2005."},{"key":"8_CR13","unstructured":"A. Gostev. Malware Evolution: January-March, 2005. http:\/\/www.viruslist.com, 2005."},{"key":"8_CR14","unstructured":"M. Handley, C. Kreibich, and V. Paxson. Network Intrusion Detection: Evasion, Traftic Normalization, and End-to-End Protocol Semantics. In Proceedings of the USENIX Security Symposium, Washington, DC, August 2001."},{"key":"8_CR15","unstructured":"The Honeynet Project. http\/\/project.honeynet.org, 2003."},{"key":"8_CR16","unstructured":"Honeynet Scan of the Month 32. http:\/\/www.honeynet.org\/scans\/scan32\/, 2005."},{"key":"8_CR17","unstructured":"IDA Pro. http:\/\/www.datarescue.com, 2005."},{"key":"8_CR18","unstructured":"S. Kandula, D. Katabi, M. Jacob, and A. Berger. Botz-4-Sale: Surviving Organized DDos Attacks That Mimic Flash Crowds. In Proceedings of the USENIX Symposium on Network Systems Design and Implementation, Boston, MA, May 2005."},{"key":"8_CR19","unstructured":"D. Kawamoto. Bots Slim Down to get Tough. CNET News.com, November 2005."},{"key":"8_CR20","unstructured":"A. Kumar, V. Paxson, and N. Weaver. Exploiting underlying structure for detailed reconstruction of an internet scale event. In Proceedings of ACM Internet Measurement Conference, November 2002."},{"key":"8_CR21","unstructured":"McAfee. W32-Spybot.worm. http\/\/vil.nai.com\/vil\/content\/v.100282.htm, 2003."},{"key":"8_CR22","unstructured":"Metasploit. http:\/\/www.metasploit.com, 2005."},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"D. Moore, V. Paxson, S. Savage, C. Shannon, S. Staniford, and N. Weaver. Inside the slammer worm. In Proceedings of IEEE Security and Privacy,July 2003.","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"8_CR24","doi-asserted-by":"crossref","unstructured":"D. Moore and C. Shannon. The Spread of the Witty Worm. http:\/\/-www.caida.org\/analysis\/security\/witty\/, 2004.","DOI":"10.1109\/MSP.2004.59"},{"key":"8_CR25","doi-asserted-by":"crossref","unstructured":"D. Moore, C. Shannon, and K. Claffy. Code red: A case study on the spread and victims of an internet worm. In Proceedings of ACM Internet Measurement Workshop, November 2002.","DOI":"10.1145\/637201.637244"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"R. Pang, V. Yegneswaran, P. Barford, V. Paxson, and L. Peterson. Characteristics of internet background radiation. In Proceedings ofACM Internet Measurement Conference,Taormina, Italy, October 2004.","DOI":"10.1145\/1028788.1028794"},{"key":"8_CR27","unstructured":"Regmon. http:\/\/www.sysinternals.com, 2005."},{"key":"8_CR28","unstructured":"California Man Charged in Botnet Attacks. Reuters, November 2005."},{"key":"8_CR29","unstructured":"B. Saha and A. Gairola. Botnet: An Overivew. CERT-In White Paper, CIWP-2005-05, June 2005."},{"key":"8_CR30","unstructured":"SoftICE Driver Suite. http:\/\/www.compuware.comlproducts\/driverstudio\/softicehtm, 2005."},{"key":"8_CR31","unstructured":"Sophos. Troj\/Agobot-A. http\/\/www.sophos.com\/virusinfo\/analyses\/trojagobota.html, 2002."},{"key":"8_CR32","unstructured":"Sophos. Troj\/SDBot. http\/\/www.sophos.com\/virusinfo\/analyses\/trojsdbot.html, 2002."},{"key":"8_CR33","unstructured":"Sophos virus analyses. http:\/\/www.sophos.com\/virusinfo\/analyses, 2005."},{"key":"8_CR34","unstructured":"S. Staniford, V. Paxson, and N. Weaver. How to Own the Internet in Your Spare Time. In Proceedings of the 11th USENIX Security Symposium, 2002."},{"key":"8_CR35","unstructured":"I. Thomson. Hackers Fight to Create Worlds Largest Botnet. http:\/\/www.vnunet.com, August 2005."},{"key":"8_CR36","unstructured":"J. Ullrich. Dshield. http:\/\/www.dshield.org, 2005."},{"key":"8_CR37","unstructured":"D. Verton. Organized Crime Invades Cyberspace. http:\/\/www.computenvorld.com, August 2004."},{"key":"8_CR38","volume-title":"Proceedings of ACM Symposium on Operating Systems Principles (SOSP)","author":"M. Vrable","year":"2005","unstructured":"M. Vrable, J. Ma, J. Chen, D. Moore, E. Vandekieft, A. Snoeren, G. Voelker, and S. Savage. Scalability, fidelity and containment in the potemkin virtual honeyfarm. In Proceedings of ACM Symposium on Operating Systems Principles (SOSP), Brighton, England, October 2005."},{"key":"8_CR39","volume-title":"Proceedings of Recent Advances on Intrusion Detection","author":"V. Yegneswaran","year":"2004","unstructured":"V. Yegneswaran, P. Barford, and D. Plonka. On the design and use of Internet sinks for network abuse monitoring. In Proceedings of Recent Advances on Intrusion Detection,Sophia, France, September 2004."},{"key":"8_CR40","doi-asserted-by":"crossref","unstructured":"V. Yegneswaran, P. Barford, and J. Ullrich. Internet intrusions: Global characteristics and prevalence. In Proceedings of ACM SIGMETRICS, San Diego, CA, June 2003.","DOI":"10.1145\/781027.781045"}],"container-title":["Advances in Information Security","Malware Detection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-0-387-44599-1_8.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,28]],"date-time":"2021-04-28T02:00:37Z","timestamp":1619575237000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-0-387-44599-1_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9780387327204"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-0-387-44599-1_8","relation":{},"subject":[]}}