{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:55:26Z","timestamp":1773510926475,"version":"3.50.1"},"publisher-location":"Boston, MA","reference-count":37,"publisher":"Springer US","isbn-type":[{"value":"9780387687667","type":"print"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-0-387-68768-1_1","type":"book-chapter","created":{"date-parts":[[2007,10,22]],"date-time":"2007-10-22T11:27:09Z","timestamp":1193052429000},"page":"1-24","source":"Crossref","is-referenced-by-count":108,"title":["Botnet Detection Based on Network Behavior"],"prefix":"10.1007","author":[{"given":"W. Timothy","family":"Strayer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Lapsely","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert","family":"Walsh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carl","family":"Livadas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"1_CR1","unstructured":"US-CERT Vulnerability Notes Database. http:\/\/www.kb.cert.org\/vuls\/."},{"key":"1_CR2","unstructured":"Paul Barford and Vinod Yegneswaran. An inside look at botnets (to appear in series: Advances in information security, springer), 2006."},{"key":"1_CR3","doi-asserted-by":"crossref","unstructured":"A. Blum, D. Song, and S. Venkataraman. Detection of interactive stepping stones: Algorithms and confidence bounds. In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID \u201904), September 2004.","DOI":"10.1007\/978-3-540-30143-1_14"},{"key":"1_CR4","unstructured":"David Dagon, Cliff Zou, and Wenke Lee. Modeling botnet propagation using time zones. In Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS \u201906), February 2006."},{"key":"1_CR5","unstructured":"Defense Security Service. Memorandum for facility security officers: Foreign-based threat to defense contractor unclassified networks, October 18, 2005."},{"key":"1_CR6","doi-asserted-by":"crossref","unstructured":"Christian Dewes, Arne Wichmann, and Anja Feldmann. An analysis of internet chat systems. In IMC \u201903: Proceedings of the 3rd ACM SIGCOMM conference on Internet measurement, pages 51\u201364, New York, NY, USA, 2003. ACM Press.","DOI":"10.1145\/948205.948214"},{"key":"1_CR7","doi-asserted-by":"crossref","unstructured":"David L. Donoho, Ana Georgina Flesia, Umesh Shankar, Vern Paxson, Jason Coit, and Stuart Staniford. Multiscale stepping-stone detection: Detecting pairs of jittered interactive streams by exploiting maximum tolerable delay. In Proc. International Symposium on Recent Advances in Intrusion Detection, pages 17\u201335, October 2002.","DOI":"10.1007\/3-540-36084-0_2"},{"key":"1_CR8","unstructured":"Richard O. Duda, Peter E. Hart, and David G. Stork. Pattern Classification. John Wiley & Sons, Inc., 2 edition, 2001."},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"T. He and L. Tong. Detecting encrypted stepping-stone connections. IEEE Transactions on Signal Processing, 2007.","DOI":"10.1109\/TSP.2006.890881"},{"issue":"3","key":"1_CR10","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSP.2005.58","volume":"3","author":"Holz. Thorsten","year":"2005","unstructured":"Thorsten Holz. A Short Visit to the Bot Zoo. IEEE Security & Privacy, 3(3):76\u201379, May 2005.","journal-title":"IEEE Security & Privacy"},{"key":"1_CR11","unstructured":"Kevin J. Houle and George M. Weaver. Trends in denial of service technology. CERT Coordination Center, October 2001."},{"key":"1_CR12","doi-asserted-by":"crossref","unstructured":"A. Householder, Art Manion, Linda Pesante, George M. Weaver, and Rob Thomas. Managing the threat of denial-of-service attacks. CERT Coordination Center, October 2001.","DOI":"10.21236\/ADA636482"},{"key":"1_CR13","unstructured":"S. Kandula, D. Katabi, M. Jacob, and A. Berger. Botz-4-sale: Surviving organized ddos attacks that mimic flash crowds. In Proceedings of the 2nd Symposium on Networked Systems Design and Implementation, May 2005."},{"key":"1_CR14","unstructured":"Anestis Karasaridis, Brian Rexroad, and David Hoeflin. Wide-scale botnet detection and characterization. In Proceedings of the First Workshop on Hot Topics in Understanding Botnets, April 2007."},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"David Kotz and Tristan Henderson. CRAWDAD: A Community Resource for Archiving Wireless Data at Dartmouth. IEEE Pervasive Computing, 4(4), oct-dec 2006.","DOI":"10.1109\/MPRV.2005.75"},{"issue":"4","key":"1_CR16","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1109\/MSECP.2003.1219071","volume":"1","author":"Levy. Elias","year":"2003","unstructured":"Elias Levy. The Making of a Spam Zombie Army. IEEE Security & Privacy, 1(4):58\u201359, July 2003.","journal-title":"IEEE Security & Privacy"},{"key":"1_CR17","doi-asserted-by":"crossref","unstructured":"Carl Livadas, Robert Walsh, David Lapsley, and W. Timothy Strayer. Using Machine Learning Techniques to Identify Botnet Traffic. In Proceedings of the 2nd IEEE LCN Workshop on Network Security, 2006.","DOI":"10.1109\/LCN.2006.322210"},{"issue":"5","key":"1_CR18","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1109\/MSECP.2003.1236244","volume":"1","author":"McCarty. Bill","year":"2003","unstructured":"Bill McCarty. Automated Identity Theft. IEEE Security & Privacy, 1(5):89\u201392, September 2003.","journal-title":"IEEE Security & Privacy"},{"issue":"4","key":"1_CR19","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1109\/MSECP.2003.1219079","volume":"1","author":"McCarty. Bill","year":"2003","unstructured":"Bill McCarty. Botnets: Big and Bigger. IEEE Security & Privacy, 1(4):87\u201390, July 2003.","journal-title":"IEEE Security & Privacy"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Andrew W. Moore and Denis Zuev. Internet traffic classification using bayesian analysis techniques. In SIGMETRICS \u201905: Proceedings of the 2005 ACM SIGMETRICS international conference on Measurement and modeling of computer systems, pages 50\u201360, New York, NY, USA, 2005. ACM Press.","DOI":"10.1145\/1064212.1064220"},{"key":"1_CR21","unstructured":"21. R. Naraine. Botnet hunters search for \u2018command and control\u2019 servers. eWeek, June 17, 2005."},{"key":"1_CR22","unstructured":"National Infrastructure Security Coordination Center. Targeted trojan email attacks. NISCC Briefing 08\/2005, June 16, 2005."},{"key":"1_CR23","unstructured":"Anirudh Ramachandran, Nick Feamster, and David Dagon. Revealing botnet membership using DNSBL counter-intelligence. In Proceedings of the 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet (SRUTI), 2006."},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Matthew Roughan, Subhabrata Sen, Oliver Spatscheck, and Nick Duffield. Class-ofservice mapping for qos: a statistical signature-based approach to ip traffic classification. In IMC \u201904: Proceedings of the 4th ACM SIGCOMM conference on Internet measurement, pages 135\u2013148, New York, NY, USA, 2004. ACM Press.","DOI":"10.1145\/1028788.1028805"},{"key":"1_CR25","doi-asserted-by":"crossref","unstructured":"Subhabrata Sen, Oliver Spatscheck, and Dongmei Wang. Accurate, scalable in-network identification of p2p traffic using application signatures. In WWW \u201904: Proceedings of the 13th international conference on World Wide Web, pages 512\u2013521, New York, NY, USA, 2004. ACM Press.","DOI":"10.1145\/988672.988742"},{"key":"1_CR26","doi-asserted-by":"crossref","unstructured":"Alex C. Snoeren, Craig Partridge, Luis A. Sanchez, Christine E. Jones, Fabrice Tchakountio, Beverly Schwartz, Stephen T. Kent, and W. Timothy Strayer. Single-packet IP traceback. ACM\/IEEE Trans. on Networking, December 2002.","DOI":"10.1109\/TNET.2002.804827"},{"key":"1_CR27","doi-asserted-by":"crossref","unstructured":"W. Timothy Strayer, Christine Jones, Beverley Schwartz, Sarah Edwards, Walter Mil-liken, and Alden Jackson. Efficient multi-dimensional flow correlation. In Proceedings of the 32st IEEE Conference on Local Computer Networks (LCN\u201907), November 2007. Submitted for publication.","DOI":"10.1109\/LCN.2007.132"},{"key":"1_CR28","doi-asserted-by":"crossref","unstructured":"W. Timothy Strayer, Christine Jones, Beverly Schwartz, Joanne Mikkelson, and Carl Livadas. Architecture for Multi-Stage Network Attack Traceback. In Proceedings of the IEEE LCN Workshop on Network Security (WoNS 2005), Sydney, Australia, November 2005.","DOI":"10.1109\/LCN.2005.33"},{"key":"1_CR29","doi-asserted-by":"crossref","unstructured":"W. Timothy Strayer, Robert Walsh, Carl Livadas, and David Lapsley. Detecting Botnets with Tight Command and Control. In Proceedings of the 31st IEEE Conference on Local Computer Networks (LCN\u201906), November 2006.","DOI":"10.1109\/LCN.2006.322100"},{"key":"1_CR30","unstructured":"Symantec. Symantec Internet Security Threat Report. Trends for July \u2013 December 06, March 2007."},{"key":"1_CR31","unstructured":"The Honeynet Project. Know Your Enemy : Learning about Security Threats. Addison-Wesley Professional; 2 edition (May 17, 2004), March 2004."},{"key":"1_CR32","unstructured":"Rob Thormeyer. Hacker arrested for breaching dod systems with \u2018botnets\u2019. Government Computer News, November 4, 2005."},{"key":"1_CR33","doi-asserted-by":"crossref","unstructured":"Xinyuan Wang, Douglas S. Reeves, and S. Felix Wu. Inter-packet delay based correlation for tracing encrypted connections through stepping stones. In Proc. European Symposium on Research in Computer Security, pages 244\u2013263, October 2002.","DOI":"10.1007\/3-540-45853-0_15"},{"key":"1_CR34","volume-title":"Data Mining: Practical Machine Learning Tools and Techniques","author":"H.Witten Ian","year":"2005","unstructured":"Ian H. Witten and Eibe Frank. Data Mining: Practical Machine Learning Tools and Techniques (2nd Edition). Morgan Kaufmann, San Francisco, CA, 2005.","edition":"2nd Edition"},{"key":"1_CR35","doi-asserted-by":"crossref","unstructured":"Kunikazu Yoda and Hiroaki Etoh. Finding a connection chain for tracing intruders. In Proc. European Symposium on Research in Computer Security, pages 191\u2013205, October 2000.","DOI":"10.1007\/10722599_12"},{"key":"1_CR36","doi-asserted-by":"crossref","unstructured":"L. Zhang, A. G. Persaud, A. Johnson, and Y. Guan. Detection of stepping stone attacks under delay and chaff perturbations. In Proceedings of the 25th IEEE International Performance Computing and Communications Conference, April 2006.","DOI":"10.1109\/.2006.1629414"},{"key":"1_CR37","unstructured":"Yin Zhang and Vern Paxson. Detecting stepping stones. In Proc. USENIX Security Symposium \u201900, pages 171\u2013184, August 2000."}],"container-title":["Advances in Information Security","Botnet Detection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-0-387-68768-1_1.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,29]],"date-time":"2021-04-29T04:04:33Z","timestamp":1619669073000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-0-387-68768-1_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9780387687667"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-0-387-68768-1_1","relation":{},"subject":[]}}