{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T23:41:30Z","timestamp":1725493290126},"publisher-location":"Boston, MA","reference-count":22,"publisher":"Springer US","isbn-type":[{"type":"print","value":"9780387687667"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-0-387-68768-1_2","type":"book-chapter","created":{"date-parts":[[2007,10,22]],"date-time":"2007-10-22T11:27:09Z","timestamp":1193052429000},"page":"25-44","source":"Crossref","is-referenced-by-count":22,"title":["Honeynet-based Botnet Scan Traffic Analysis"],"prefix":"10.1007","author":[{"given":"Zhichun","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anup","family":"Goyal","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"unstructured":"M. Bailey et al. The Internet motion sensor: A distributed blackhole monitoring system. In Proc. of NDSS, 2005.","key":"2_CR1"},{"unstructured":"James Binkley and Suresh Singh. An algorithm for anomaly-based botnet detection. In Proceedings of Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI \u201906), 2006.","key":"2_CR2"},{"unstructured":"E. Cooke, F. Jahanian, and D. McPherson. The zombie roundup: Understanding, detecting, and disrupting botnets. In Proceedings of USENIX Workshop on Steps to Reducing Unwanted Traffic on the Internet, July 2005.","key":"2_CR3"},{"unstructured":"W. Cui et al. GQ: Realizing a system to catch worms in a quarter million places. Technical Report TR-06-004, ICSI, 2006.","key":"2_CR4"},{"unstructured":"D. Dagon, C. Zou, and W. Lee. Modeling botnet propagation using time zones. In Proceedings of the 13th Network and Distributed System Security Symposium (NDSS\u201906), 2006.","key":"2_CR5"},{"unstructured":"Neil Daswani, Michael Stoppelman, the Google Click Quality, and Inc Security Teams, Google. The anatomy of Clickbot.A. In USENIX First Workshop on Hot Topics in Understanding Botnets (HotBots), 2007.","key":"2_CR6"},{"unstructured":"Julian Grizzard, Vikram Sharma, Chris Nunnery, Brent ByungHoon Kang, and David Dagon. Peer-to-peer botnets: Overview and case study. In USENIX First Workshop on Hot Topics in Understanding Botnets (HotBots), 2007.","key":"2_CR7"},{"unstructured":"Christopher W. Hanna. Using snort to detect rogue irc bot programs, Oct 2004. http:\/\/www.giac.org\/certified_professionals\/practicals\/gsec\/4095.php.","key":"2_CR8"},{"doi-asserted-by":"crossref","unstructured":"J. Kannan et al. Semi-automated discovery of application session structure. In Proc. of ACM IMC, 2006.","key":"2_CR9","DOI":"10.1145\/1177080.1177096"},{"doi-asserted-by":"crossref","unstructured":"R. Pang et al. Characteristics of Internet background radiation. In Proc. of ACM IMC, 2004.","key":"2_CR10","DOI":"10.1145\/1028788.1028794"},{"doi-asserted-by":"crossref","unstructured":"V. Paxson. Bro: A system for detecting network intruders in real-time. Computer Networks, 31, 1999.","key":"2_CR11","DOI":"10.1016\/S1389-1286(99)00112-7"},{"unstructured":"The Honeynet Project and Research Alliance. Know your enemy: Tracking botnets. http:\/\/honeynet.org\/papers\/bots, March 2005.","key":"2_CR12"},{"unstructured":"N. Provos. A virtual honeypot framework. In Proc. of USENIX Security, 2004.","key":"2_CR13"},{"unstructured":"Niels Provos, Dean McNamee, Panayiotis Mavrommatis, Ke Wang, and Nagendra Modadugu. The ghost in the browser: Analysis of web-based malware. In USENIX First Workshop on Hot Topics in Understanding Botnets (HotBots), 2007.","key":"2_CR14"},{"doi-asserted-by":"crossref","unstructured":"Moheeb A. Rajab, Jay Zarfoss, Fabian Monrose, and Andreas Terzis. A multifaceted approach to understanding the botnet phenomenon. In Proc. of ACM\/USENIX IMC, 2006.","key":"2_CR15","DOI":"10.1145\/1177080.1177086"},{"doi-asserted-by":"crossref","unstructured":"Anirudh Ramachandran and Nick Feamster. Understanding the network-level behavior of spammers. In Proceedings of ACM SIGCOMM \u201906, September 2006.","key":"2_CR16","DOI":"10.1145\/1159913.1159947"},{"unstructured":"Anirudh Ramachandran, Nick Feamster, and David Dagon. Revealing botnet membership using DNSBL counter-intelligence. In Proceedings of Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI \u201906), 2006.","key":"2_CR17"},{"doi-asserted-by":"crossref","unstructured":"M. Vrable et al. Scalability, fidelity, and containment in the potemkin virtual honeyfarm. In Proc. of SOSP, 2005.","key":"2_CR18","DOI":"10.1145\/1095810.1095825"},{"unstructured":"V. Yegneswaran, Paul Barford, and Vern Paxson. Using honeynets for Internet situational awareness. In In Proc. of ACM Hotnets IV, 2005.","key":"2_CR19"},{"doi-asserted-by":"crossref","unstructured":"V. Yegneswaran et al. On the design and use of Internet sinks for network abuse monitoring. In Proc. of RAID, 2004.","key":"2_CR20","DOI":"10.1007\/978-3-540-30143-1_8"},{"unstructured":"Michal Zalewski. the new p0f. http:\/\/lcamtuf.coredump.cx\/p0f.shtml.","key":"2_CR21"},{"unstructured":"Cliff C. Zou et al. Monitoring and early warning for Internet worms. In Prof. of ACM CCS, 2003.","key":"2_CR22"}],"container-title":["Advances in Information Security","Botnet Detection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-0-387-68768-1_2.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,29]],"date-time":"2021-04-29T04:04:33Z","timestamp":1619669073000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-0-387-68768-1_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9780387687667"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-0-387-68768-1_2","relation":{},"subject":[]}}