{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T03:18:48Z","timestamp":1743045528208,"version":"3.40.3"},"publisher-location":"Boston, MA","reference-count":42,"publisher":"Springer US","isbn-type":[{"type":"print","value":"9781441901392"},{"type":"electronic","value":"9781441901408"}],"license":[{"start":{"date-parts":[[2009,9,30]],"date-time":"2009-09-30T00:00:00Z","timestamp":1254268800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2009,9,30]],"date-time":"2009-09-30T00:00:00Z","timestamp":1254268800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-1-4419-0140-8_6","type":"book-chapter","created":{"date-parts":[[2009,10,3]],"date-time":"2009-10-03T11:41:32Z","timestamp":1254570092000},"page":"103-136","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Assessing Cybercrime Through the Eyes of the WOMBAT"],"prefix":"10.1007","author":[{"given":"Marc","family":"Dacier","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Corrado","family":"Leita","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Olivier","family":"Thonnard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hau","family":"Van Pham","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,9,30]]},"reference":[{"key":"6_CR1","unstructured":"ALMODE Security. Home page of disco at at http:\/\/www.altmode.com\/disco\/."},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"P. Baecher, M. Koetter, T. Holz, M. Dornseif, and F. Freiling. The Nepenthes Platform: An Efficient Approach to Collect Malware. Proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection (RAID), September 2006.","DOI":"10.1007\/11856214_9"},{"key":"6_CR3","unstructured":"U. Bayer, C. Kruegel, and E. Kirda. TTAnalyze: A Tool for Analyzing Malware. PhD thesis, Master\u2019s Thesis, Technical University of Vienna, 2005."},{"key":"6_CR4","volume-title":"Handbook of Combinatorial Optimization","author":"I. Bomze","year":"1999","unstructured":"I. Bomze, M. Budinich, P. Pardalos, and M. Pelillo. The maximum clique problem. In Handbook of Combinatorial Optimization, volume 4. Kluwer Academic Publishers, Boston, MA, 1999."},{"key":"6_CR5","unstructured":"F. M. C. R. Center. Web security trends report q1\/2008, http:\/\/www.finjan.com\/content.aspx?id=827, sep 2008."},{"key":"6_CR6","unstructured":"CERT. Advisory CA-2003-20 W32\/ Blaster worm, August 2003."},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Z. Chen, L. Gao, and K. Kwiat. Modeling the spread of active worms. In Proceedings of IEEE INFOCOM, 2003.","DOI":"10.1109\/INFCOM.2003.1209211"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"M. P. Collins, T. J. Shimeall, S. Faber, J. Janies, R. Weaver, M. D. Shon, and J. Kadane. Using uncleanliness to predict future botnet addresses. In IMC \u201907: Proceedings of the 7th ACM SIGCOMM conference on Internet measurement, pages 93\u2013104, New York, NY, USA, 2007. ACM.","DOI":"10.1145\/1298306.1298319"},{"key":"6_CR9","doi-asserted-by":"crossref","unstructured":"E. Cooke, M. Bailey, Z. M. Mao, D. Watson, F. Jahanian, and D. McPherson. Toward understanding distributed blackhole placement. In WORM \u201904: Proceedings of the 2004 ACM workshop on Rapid malcode, pages 54\u201364, New York, NY, USA, 2004. ACM Press.","DOI":"10.1145\/1029618.1029627"},{"key":"6_CR10","doi-asserted-by":"crossref","unstructured":"J. Crandall, S. Wu, and F. Chong. Experiences using Minos as a tool for capturing and analyzing novel worms for unknown vulnerabilities. Proceedings of GI SIG SIDAR Conference on Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA), 2005.","DOI":"10.1007\/11506881_3"},{"key":"6_CR11","unstructured":"M. Dacier, F. Pouget, and H. Debar. Attack processes found on the internet. In NATO Symposium IST-041\/RSY-013, Toulouse, France, April 2004."},{"key":"6_CR12","unstructured":"M. Dacier, F. Pouget, and H. Debar. Honeypots, a practical mean to validate malicious fault assumptions. In Proceedings of the 10th Pacific Ream Dependable Computing Conference (PRDC04), Tahiti, February 2004."},{"key":"6_CR13","unstructured":"M. Dacier, F. Pouget, and H. Debar. Leurre.com: On the advantages of deploying a large scale distributed honeypot platform. In Proceedings of the E-Crime and Computer Conference 2005 (ECCE\u201905), Monaco, March 2005."},{"key":"6_CR14","unstructured":"DShield. Distributed Intrusion Detection System, www.dshield.org, 2007."},{"key":"6_CR15","unstructured":"F-Secure. Malware information pages: Allaple.a, http:\/\/www.f-secure.com\/v-descs\/allaplea.shtml, December 2006."},{"key":"6_CR16","unstructured":"A. Jain and R. Dubes. Algorithms for Clustering Data. Prentice-Hall advanced reference series, 1988."},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"C. Leita and M. Dacier. Sgnet: a worldwide deployable framework to support the analysis of malware threat models. In Proceedings of the 7th European Dependable Computing Conference (EDCC 2008), May 2008.","DOI":"10.1109\/EDCC-7.2008.15"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"C. Leita and M. Dacier. SGNET: Implementation Insights. In IEEE\/IFIP Network Operations and Management Symposium, April 2008.","DOI":"10.1109\/NOMS.2008.4575282"},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"C. Leita, M. Dacier, and F. Massicotte. Automatic handling of protocol ependencies and reaction to 0-day attacks with ScriptGen based honeypots. In RAID 2006, 9th International Symposium on Recent Advances in Intrusion Detection, September 20-22, 2006, Hamburg, Germany - Also published as Lecture Notes in Computer Science Volume 4219\/2006, Sep 2006.","DOI":"10.1007\/11856214_10"},{"key":"6_CR20","unstructured":"C. Leita, K. Mermoud, and M. Dacier. Scriptgen: an automated script generation tool for honeyd. In Proceedings of the 21st Annual Computer Security Applications Conference, December 2005."},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"C. Leita, V. Pham, . Thonnard, E. Ramirez-Silva, F. Pouget, E. Kirda, and M. Dacier. The Leurre.com Project: Collecting Internet Threats Information using a Worldwide Distributed Honeynet. In 1st WOMBAT open workshop, April 2008.","DOI":"10.1109\/WISTDCS.2008.8"},{"key":"6_CR22","unstructured":"Maxmind Product. Home page ot the maxmind company at http:\/\/www.maxmind.com."},{"key":"6_CR23","unstructured":"D. Moore, C. Shannon, G. Voelker, and S. Savage. Network telescopes: Technical report. CAIDA, April, 2004."},{"issue":"3","key":"6_CR24","doi-asserted-by":"publisher","first-page":"443","DOI":"10.1016\/0022-2836(70)90057-4","volume":"48","author":"S. Needleman","year":"1970","unstructured":"S. Needleman and C. Wunsch. A general method applicable to the search for similarities in the amino acid sequence of two proteins. J Mol Biol. 48(3):443-53, 1970.","journal-title":"J Mol Biol"},{"key":"6_CR25","unstructured":"Netgeo Product. Home page of the netgeo company at http:\/\/www.netgeo.com\/."},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"V.-H. Pham and M. Dacier. Honeypot traces forensics: The observation view point matters. Technical report, EURECOM, 2009.","DOI":"10.1109\/NSS.2009.46"},{"key":"6_CR27","unstructured":"V.-H. Pham, M. Dacier, G. Urvoy Keller, and T. En Najjary. The quest for multi-headed worms. In DIMVA 2008, 5th Conference on Detection of Intrusions and Malware & Vulnerability Assessment, July 10-11th, 2008, Paris, France, Jul 2008."},{"key":"6_CR28","doi-asserted-by":"crossref","unstructured":"G. Portokalidis, A. Slowinska, and H. Bos. Argos: an emulator for fingerprinting zero-day attacks. Proc. ACM SIGOPS EUROSYS, 2006.","DOI":"10.1145\/1217935.1217938"},{"key":"6_CR29","unstructured":"F. Pouget, M. Dacier, and V. H. Pham. Understanding threats: a prerequisite to enhance survivability of computing systems. In IISW\u201904, International Infrastructure Survivability Workshop 2004, in conjunction with the 25th IEEE International Real-Time Systems Symposium (RTSS 04) December 5-8, 2004 Lisbonne, Portugal, Dec 2004."},{"key":"6_CR30","unstructured":"T. C. D. Project. http:\/\/www.cymru.com\/darknet\/."},{"key":"6_CR31","unstructured":"N. Provos. A virtual honeypot framework. In Proceedings of the 12th USENIX Security Symposium, pages 1\u201314, August 2004."},{"key":"6_CR32","unstructured":"M. Rajab, J. Zarfoss, F. Monrose, and A. Terzis. A multifaceted approach to understanding the botnet phenomenon. In ACM SIGCOMM\/USENIX Internet Measurement Conference, October 2006."},{"key":"6_CR33","unstructured":"E. Ramirez-Silva and M. Dacier. Empirical study of the impact of metasploit-related attacks in 4 years of attack traces. In 12th Annual Asian Computing Conference focusing on computer and network security (ASIAN07), December 2007."},{"key":"6_CR34","unstructured":"J. Riordan, D. Zamboni, and Y. Duponchel. Building and deploying billy goat, a worm detection system. In Proceedings of the 18th Annual FIRST Conference, 2006."},{"key":"6_CR35","unstructured":"I. M. Sensor. http:\/\/ims.eecs.umich.edu\/."},{"key":"6_CR36","unstructured":"TCPDUMP Project. Home page of the tcpdump project at http:\/\/www.tcpdump.org\/."},{"key":"6_CR37","unstructured":"The Metasploit Project. www.metasploit.org, 2007."},{"key":"6_CR38","unstructured":"O. Thonnard and M. Dacier. A framework for attack patterns\u2019 discovery in honeynet data. DFRWS 2008, 8th Digital Forensics Research Conference, August 11- 13, 2008, Baltimore, USA, 2008."},{"key":"6_CR39","doi-asserted-by":"crossref","unstructured":"O. Thonnard and M. Dacier. Actionable knowledge discovery for threats intelligence support using a multi-dimensional data mining methodology. In ICDM\u201908, 8th IEEE International Conference on Data Mining series, December 15-19, 2008, Pisa, Italy, Dec 2008.","DOI":"10.1109\/ICDMW.2008.78"},{"key":"6_CR40","first-page":"2579","volume":"9","author":"L. van der Maaten","year":"2008","unstructured":"L. van der Maaten and G. Hinton. Visualizing data using t-sne. Journal of Machine Learning Research, 9:2579\u20132605, November 2008.","journal-title":"Journal of Machine Learning Research"},{"key":"6_CR41","unstructured":"T. Werner. Honeytrap. http:\/\/honeytrap.mwcollect.org\/."},{"key":"6_CR42","unstructured":"M. Zalewski. Home page of p0f at http:\/\/lcamtuf.coredump.cx\/p0f.shtml."}],"container-title":["Advances in Information Security","Cyber Situational Awareness"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4419-0140-8_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,31]],"date-time":"2023-01-31T19:37:18Z","timestamp":1675193838000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-1-4419-0140-8_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,9,30]]},"ISBN":["9781441901392","9781441901408"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-1-4419-0140-8_6","relation":{},"ISSN":["1568-2633"],"issn-type":[{"type":"print","value":"1568-2633"}],"subject":[],"published":{"date-parts":[[2009,9,30]]},"assertion":[{"value":"30 September 2009","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}