{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T07:08:10Z","timestamp":1750662490833,"version":"3.40.3"},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030708511"},{"type":"electronic","value":"9783030708528"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-70852-8_3","type":"book-chapter","created":{"date-parts":[[2021,3,2]],"date-time":"2021-03-02T18:03:11Z","timestamp":1614708191000},"page":"37-53","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Using Features of Encrypted Network Traffic to Detect Malware"],"prefix":"10.1007","author":[{"given":"Zeeshan","family":"Afzal","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anna","family":"Brunstrom","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Lindskog","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,3,3]]},"reference":[{"key":"3_CR1","doi-asserted-by":"crossref","unstructured":"Anderson, B., McGrew, D.A.: Identifying encrypted malware traffic with contextual flow data. In: Proceedings of the ACM Workshop on Artificial Intelligence and Security, Vienna, Austria, 28 October 2016, pp. 35\u201346 (2016)","DOI":"10.1145\/2996758.2996768"},{"issue":"3","key":"3_CR2","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/s11416-017-0306-6","volume":"14","author":"B Anderson","year":"2018","unstructured":"Anderson, B., Paul, S., McGrew, D.A.: Deciphering malware\u2019s use of TLS (without decryption). J. Comput. Virol. Hacking Tech. 14(3), 195\u2013211 (2018)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"3_CR3","unstructured":"Andreasen, F., Wang, E.: TLS 1.3 impact on network-based security. Internet-draft, RFC Editor, July 2019. https:\/\/tools.ietf.org\/html\/draft-camwinget-tls-use-cases-05"},{"key":"3_CR4","doi-asserted-by":"crossref","unstructured":"Bazuhair, W., Lee, W.: Detecting malign encrypted network traffic using Perlin noise and convolutional neural network. In: 10th Annual Computing and Communication Workshop and Conference, CCWC 2020, Las Vegas, NV, USA, 6\u20138 January 2020, pp. 200\u2013206. IEEE (2020)","DOI":"10.1109\/CCWC47524.2020.9031116"},{"key":"3_CR5","unstructured":"Cisco: Cisco encrypted traffic analytics (2019). https:\/\/www.cisco.com\/c\/en\/us\/solutions\/collateral\/enterprise-networks\/enterprise-network-security\/nb-09-encrytd-traf-anlytcs-wp-cte-en.html"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Durumeric, Z., et al.: The security impact of HTTPS interception. In: Proceedings of the 24th Annual Network and Distributed System Security Symposium, NDSS San Diego, California, USA, 26 February\u20131 March 2017 (2017)","DOI":"10.14722\/ndss.2017.23456"},{"key":"3_CR7","unstructured":"Erquiaga, M.J.: Malware capture facility project MCFP (2019). https:\/\/www.stratosphereips.org\/datasets-malware"},{"key":"3_CR8","unstructured":"Google: HTTPS encryption on the web. https:\/\/transparencyreport.google.com\/https\/overview. Accessed 29 October 2019"},{"key":"3_CR9","unstructured":"Gu, G., Porras, P.A., Yegneswaran, V., Fong, M.W.: Bothunter: detecting malware infection through IDS-driven dialog correlation. In: Proceedings of the 16th USENIX Security Symposium, Boston, MA, USA, 6\u201310 August (2007)"},{"issue":"2","key":"3_CR10","doi-asserted-by":"publisher","first-page":"721","DOI":"10.32604\/cmc.2019.05610","volume":"60","author":"J Liu","year":"2019","unstructured":"Liu, J., Zeng, Y., Shi, J., Yang, Y., Wang, R., He, L.: Maldetect: a structure of encrypted malware traffic detection. Comput. Mat. Continua 60(2), 721\u2013739 (2019)","journal-title":"Comput. Mat. Continua"},{"key":"3_CR11","unstructured":"McGrew, D., Anderson, B., Perricone, P., Hudson, B.: Joy (2019). https:\/\/github.com\/cisco\/joy"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"Moore, A.W., Zuev, D.: Internet traffic classification using Bayesian analysis techniques. In: Proceedings of the International Conference on Measurements and Modeling of Computer Systems, SIGMETRICS, Alberta, Canada, pp. 50\u201360 (2005)","DOI":"10.1145\/1064212.1064220"},{"key":"3_CR13","first-page":"2825","volume":"12","author":"F Pedregosa","year":"2011","unstructured":"Pedregosa, F., et al.: Scikit-learn: machine learning in Python. J. Mach. Learn. Res. 12, 2825\u20132830 (2011)","journal-title":"J. Mach. Learn. Res."},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Rescorla, E.: The Transport Layer Security (TLS) Protocol Version 1.3. RFC 8446, RFC Editor, August 2018. https:\/\/rfc-editor.org\/rfc\/rfc8446.txt","DOI":"10.17487\/RFC8446"},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Rescorla, E., Dierks, T.: The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246, RFC Editor, August 2008. https:\/\/rfc-editor.org\/rfc\/rfc5246.txt","DOI":"10.17487\/rfc5246"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Rieck, K., Holz, T., Willems, C., D\u00fcssel, P., Laskov, P.: Learning and classification of malware behavior. In: Proceedings of the Detection of Intrusions and Malware, and Vulnerability Assessment DIMVA, Paris, France, pp. 108\u2013125 (2008)","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"3_CR17","unstructured":"Saltzer, J.H., Reed, D.P., Clark, D.D.: End-to-end arguments in system design. In: Proceedings of the 2nd International Conference on Distributed Computing Systems, Paris, France, 1981. pp. 509\u2013512. IEEE Computer Society (1981)"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Ghorbani, A.A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th International Conference on Information Systems Security and Privacy, ICISSP, Funchal, Madeira - Portugal, 22\u201324 January 2018, pp. 108\u2013116 (2018)","DOI":"10.5220\/0006639801080116"},{"key":"3_CR19","unstructured":"St\u0159as\u00e1k, F.: Detection of HTTPS malware traffic. https:\/\/dspace.cvut.cz\/bitstream\/handle\/10467\/68528\/F3-BP-2017-Strasak-Frantisek-strasak_thesis_2017.pdf (2017)"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Tegeler, F., Fu, X., Vigna, G., Kruegel, C.: BotFinder: finding bots in network traffic without deep packet inspection. In: Proceedings of the Conference on emerging Networking Experiments and Technologies, CoNEXT 2012, Nice, France, 10\u201313 December, pp. 349\u2013360 (2012)","DOI":"10.1145\/2413176.2413217"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Wurzinger, P., Bilge, L., Holz, T., Goebel, J., Kruegel, C., Kirda, E.: Automatically generating models for botnet detection. In: Proceedings of the 14th European Symposium on Research in Computer Security ESORICS, Saint-Malo, France, 21\u201323 September, pp. 232\u2013249 (2009)","DOI":"10.1007\/978-3-642-04444-1_15"},{"key":"3_CR22","doi-asserted-by":"crossref","unstructured":"Zander, S., Nguyen, T., Armitage, G.: Automated traffic classification and application identification using machine learning. In: Proceedings of the 30th Annual IEEE Conference on Local Computer Networks (LCN), 15\u201317 November Sydney, Australia, pp. 250\u2013257 (2005)","DOI":"10.1109\/LCN.2005.35"}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-70852-8_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,3,2]],"date-time":"2021-03-02T18:06:45Z","timestamp":1614708405000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-70852-8_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030708511","9783030708528"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-70852-8_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"3 March 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NordSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nordic Conference on Secure IT Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 November 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 November 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nordsec2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/nordsec2020.on.liu.se\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"45","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"33% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3,5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}