{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T10:50:52Z","timestamp":1778151052219,"version":"3.51.4"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030109967","type":"print"},{"value":"9783030109974","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-10997-4_21","type":"book-chapter","created":{"date-parts":[[2019,1,17]],"date-time":"2019-01-17T12:30:23Z","timestamp":1547728223000},"page":"341-355","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Using Reinforcement Learning to Conceal Honeypot Functionality"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8722-2009","authenticated-orcid":false,"given":"Seamus","family":"Dowling","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Schukat","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Enda","family":"Barrett","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,1,18]]},"reference":[{"issue":"3","key":"21_CR1","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1145\/174194.174199","volume":"23","author":"SM Bellovin","year":"1993","unstructured":"Bellovin, S.M.: Packets found on an internet. ACM SIGCOMM Comput. Commun. Rev. 23(3), 26\u201331 (1993)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"21_CR2","first-page":"1","volume":"9","author":"YMP Pa","year":"2015","unstructured":"Pa, Y.M.P., Suzuki, S., Yoshioka, K., Matsumoto, T., Kasama, T., Rossow, C.: IoTPOT: analysing the rise of IoT compromises. EMU 9, 1 (2015)","journal-title":"EMU"},{"key":"21_CR3","doi-asserted-by":"crossref","unstructured":"Watson, D., Riden, J.: The honeynet project: data collection tools, infrastructure, archives and analysis. In: WOMBAT Workshop on 2008 IEEE Information Security Threats Data Collection and Sharing. WISTDCS 2008, pp. 24\u201330 (2008)","DOI":"10.1109\/WISTDCS.2008.11"},{"key":"21_CR4","unstructured":"Provos, N., et al.: A virtual honeypot framework. In: USENIX Security Symposium, vol. 173, pp. 1\u201314 (2004)"},{"issue":"1","key":"21_CR5","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSECP.2004.1264861","volume":"2","author":"N Krawetz","year":"2004","unstructured":"Krawetz, N.: Anti-honeypot technology. IEEE Secur. Priv. 2(1), 76\u201379 (2004)","journal-title":"IEEE Secur. Priv."},{"issue":"7","key":"21_CR6","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MC.2017.201","volume":"50","author":"C Kolias","year":"2017","unstructured":"Kolias, C., Kambourakis, G., Stavrou, A., Voas, J.: DDoS in the IoT: Mirai and other botnets. Computer 50(7), 80\u201384 (2017)","journal-title":"Computer"},{"key":"21_CR7","volume-title":"Honeypots: Tracking Hackers","author":"L Spitzner","year":"2003","unstructured":"Spitzner, L.: Honeypots: Tracking Hackers, vol. 1. Addison-Wesley, Reading (2003)"},{"key":"21_CR8","unstructured":"Zhang, F., et al.: Honeypot: a supplemented active defense system for network security. In: 2003 Proceedings of the Fourth International Conference on Parallel and Distributed Computing, Applications and Technologies. PDCAT-2003, pp. 231\u2013235. IEEE (2003)"},{"key":"21_CR9","unstructured":"Spitzner, L.: Honeytokens: the other honeypot (2003). https:\/\/www.symantec.com\/connect\/articles\/honeytokens-other-honeypots. Accessed 17 Feb 2014"},{"key":"21_CR10","unstructured":"Seifert, C., Welch, I., Komisarczuk, P.: Taxonomy of honeypots. Technical report CS-TR-06\/12, School of Mathematical and Computing Sciences, Victoria University of Wellington, June 2006"},{"key":"21_CR11","unstructured":"Kuwatly, I., et al.: A dynamic honeypot design for intrusion detection. In: 2004 Proceedings of The IEEE\/ACS International Conference on Pervasive Services. ICPS 2004, pp. 95\u2013104. IEEE (2004)"},{"key":"21_CR12","unstructured":"Prasad, R., Abraham, A.: Hybrid framework for behavioral prediction of network attack using honeypot and dynamic rule creation with different context for dynamic blacklisting. In: 2010 Second International Conference on Communication Software and Networks. ICCSN 2010, pp. 471\u2013476. IEEE (2010)"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Jicha, A., Patton, M., Chen, H.: SCADA honeypots: an indepth analysis of Conpot. In: 2016 IEEE Conference on Intelligence and Security Informatics (ISI) 2016","DOI":"10.1109\/ISI.2016.7745468"},{"issue":"4","key":"21_CR14","doi-asserted-by":"publisher","first-page":"2768","DOI":"10.1109\/COMST.2017.2749442","volume":"19","author":"G Vormayr","year":"2017","unstructured":"Vormayr, G., Zseby, T., Fabini, J.: Botnet communication patterns. IEEE Commun. Surv. Tutor. 19(4), 2768\u20132796 (2017)","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"1","key":"21_CR15","first-page":"30","volume":"4","author":"P Wang","year":"2010","unstructured":"Wang, P., et al.: Honeypot detection in advanced botnet attacks. Int. J. Inf. Comput. Secur. 4(1), 30\u201351 (2010)","journal-title":"Int. J. Inf. Comput. Secur."},{"key":"21_CR16","unstructured":"Holz, T., Raynal, F.: Detecting honeypots and other suspicious environments. In: 2005 Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop. IAW 2005, pp. 29\u201336. IEEE (2005)"},{"key":"21_CR17","unstructured":"Antonakakis, M., et al.: Understanding the Mirai botnet. In: USENIX Security Symposium, pp. 1092\u20131110 (2017)"},{"key":"21_CR18","unstructured":"Valli, C., Rabadia, P., Woodward, A.: Patterns and patter-an investigation into SSH activity using kippo honeypots (2013)"},{"key":"21_CR19","unstructured":"Not capturing any Mirai samples. https:\/\/github.com\/micheloosterhof\/cowrie\/issues\/411. Accessed 02 Feb 2018"},{"key":"21_CR20","unstructured":"SSH Mirai-like bot. https:\/\/pastebin.com\/NdUbbL8H. Accessed 28 Nov 2017"},{"issue":"2","key":"21_CR21","doi-asserted-by":"publisher","first-page":"898","DOI":"10.1109\/SURV.2013.091213.00134","volume":"16","author":"S Khattak","year":"2014","unstructured":"Khattak, S., et al.: A taxonomy of botnet behavior, detection, and defense. IEEE Commun. Surv. Tutor. 16(2), 898\u2013924 (2014)","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"4","key":"21_CR22","first-page":"159","volume":"22","author":"O Hayatle","year":"2013","unstructured":"Hayatle, O., Otrok, H., Youssef, A.: A Markov decision process model for high interaction honeypots. Inf. Secur. J.: A Global Perspect. 22(4), 159\u2013170 (2013)","journal-title":"Inf. Secur. J.: A Global Perspect."},{"issue":"2","key":"21_CR23","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1002\/sec.737","volume":"7","author":"A Ghourabi","year":"2014","unstructured":"Ghourabi, A., Abbes, T., Bouhoula, A.: Characterization of attacks collected from the deployment of Web service honeypot. Secur. Commun. Netw. 7(2), 338\u2013351 (2014)","journal-title":"Secur. Commun. Netw."},{"key":"21_CR24","doi-asserted-by":"crossref","unstructured":"Goseva-Popstojanova, K., Anastasovski, G., Pantev, R.: Using multiclass machine learning methods to classify malicious behaviors aimed at web systems. In: 2012 IEEE 23rd International Symposium on Software Reliability Engineering (ISSRE), pp. 81\u201390. IEEE (2012)","DOI":"10.1109\/ISSRE.2012.30"},{"issue":"3","key":"21_CR25","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1007\/s11416-010-0150-4","volume":"7","author":"G Wagener","year":"2011","unstructured":"Wagener, G., Dulaunoy, A., Engel, T., et al.: Heliza: talking dirty to the attackers. J. Comput. Virol. 7(3), 221\u2013232 (2011)","journal-title":"J. Comput. Virol."},{"key":"21_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"741","DOI":"10.1007\/978-3-642-05118-0_51","volume-title":"Stabilization, Safety, and Security of Distributed Systems","author":"G Wagener","year":"2009","unstructured":"Wagener, G., State, R., Dulaunoy, A., Engel, T.: Self adaptive high interaction honeypots driven by game theory. In: Guerraoui, R., Petit, F. (eds.) SSS 2009. LNCS, vol. 5873, pp. 741\u2013755. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-05118-0_51"},{"key":"21_CR27","doi-asserted-by":"crossref","unstructured":"Pauna, A., Bica, I.: RASSH-reinforced adaptive SSH honeypot. In: 2014 10th International Conference on Communications (COMM), pp. 1\u20136. IEEE (2014)","DOI":"10.1109\/ICComm.2014.6866707"},{"issue":"Feb","key":"21_CR28","first-page":"743","volume":"11","author":"T Schaul","year":"2010","unstructured":"Schaul, T., et al.: PyBrain. J. Mach. Learn. Res. 11(Feb), 743\u2013746 (2010)","journal-title":"J. Mach. Learn. Res."},{"key":"21_CR29","unstructured":"Initial analysis of four million login attempts. http:\/\/www.honeynet.org\/node\/1328. Accessed 17 Nov 2017"},{"key":"21_CR30","doi-asserted-by":"crossref","unstructured":"Dowling, S., Schukat, M., Melvin, H.: A ZigBee honeypot to assess IoT cyberattack behaviour. In: 2017 28th Irish Signals and Systems Conference (ISSC), pp. 1\u20136. IEEE (2017)","DOI":"10.1109\/ISSC.2017.7983603"},{"issue":"2","key":"21_CR31","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1080\/23742917.2018.1495375","volume":"2","author":"Seamus Dowling","year":"2018","unstructured":"Dowling, S., Schukat, M., Barrett, E.: Improving adaptive honeypot functionality with efficient reinforcement learning parameters for automated malware. J. Cyber Secur. Technol. 1\u201317 (2018) https:\/\/doi.org\/10.1080\/23742917.2018.1495375","journal-title":"Journal of Cyber Security Technology"},{"key":"21_CR32","unstructured":"An adaptive honeypot using reinforcement learning implementation. https:\/\/github.com\/sosdow\/RLHPot. Accessed 19 Dec 2017"},{"issue":"10","key":"21_CR33","first-page":"63","volume":"4","author":"ML Bringer","year":"2012","unstructured":"Bringer, M.L., Chelmecki, C.A., Fujinoki, H.: A survey: recent advances and future trends in honeypot research. Int. J. Comput. Netw. Inf. Secur. 4(10), 63 (2012)","journal-title":"Int. J. Comput. Netw. Inf. Secur."}],"container-title":["Lecture Notes in Computer Science","Machine Learning and Knowledge Discovery in Databases"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-10997-4_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,17]],"date-time":"2024-01-17T01:38:53Z","timestamp":1705455533000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-10997-4_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030109967","9783030109974"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-10997-4_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"18 January 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dublin","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ireland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 September 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 September 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ecmlpkdd2018.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"CMT","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"535","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"131","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"17","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}