{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T11:40:39Z","timestamp":1742989239418,"version":"3.40.3"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030884178"},{"type":"electronic","value":"9783030884185"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-88418-5_35","type":"book-chapter","created":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T21:04:30Z","timestamp":1632949470000},"page":"736-756","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["MORTON: Detection of Malicious Routines in Large-Scale DNS Traffic"],"prefix":"10.1007","author":[{"given":"Yael","family":"Daihes","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hen","family":"Tzaban","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Asaf","family":"Nadler","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Asaf","family":"Shabtai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,30]]},"reference":[{"key":"35_CR1","unstructured":"Stefana Gal -Software Engineer, Bitdefender ATD Team: Who iserik: A resurface of an advanced persistent adware? https:\/\/www.bitdefender.com\/files\/News\/CaseStudies\/study\/284\/Bitdefender-WhitePaper-Erik-CREA3910-en-EN-GenericUse.pdf"},{"key":"35_CR2","unstructured":"Agency, N.S.: Adopting Encrypted DNS in Enterprise Environments. https:\/\/media.defense.gov\/2021\/Jan\/14\/2002564889\/-1\/-1\/0\/CSI_ADOPTING_ENCRYPTED_DNS_U_OO_102904_21.PDF (2021)"},{"key":"35_CR3","doi-asserted-by":"crossref","unstructured":"Alina, O., Li, Z., Norris, R., Bowers, K.: MADE: security analytics for enterprise threat detection. In: Proceedings of the 34th Annual Computer Security Applications Conference, pp. 124\u2013136. ACM (2018)","DOI":"10.1145\/3274694.3274710"},{"key":"35_CR4","unstructured":"Meshkov, A.: AdGuard Research: Fake ad blockers 2: Now with cookies and ad fraud. https:\/\/adguard.com\/en\/blog\/fake-ad-blockers-part-2.html"},{"issue":"3","key":"35_CR5","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1145\/357830.357849","volume":"3","author":"S Axelsson","year":"2000","unstructured":"Axelsson, S.: The base-rate fallacy and the difficulty of intrusion detection. ACM Trans. Inf. Syst. Secur. (TISSEC) 3(3), 186\u2013205 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"35_CR6","doi-asserted-by":"crossref","unstructured":"Bilge, L., Balzarotti, D., Robertson, W., Kirda, E., Kruegel, C.: Disclosure: detecting botnet command and control servers through large-scale netflow analysis. In: Proceedings of the 28th Annual Computer Security Applications Conference, pp. 129\u2013138 (2012)","DOI":"10.1145\/2420950.2420969"},{"key":"35_CR7","unstructured":"Cobalt Strike.com: Cobalt strike release notes. https:\/\/www.cobaltstrike.com\/releasenotes.txt"},{"key":"35_CR8","unstructured":"Elfeky, M.G., Aref, W.G., Elmagarmid, A.K.: WARP: time warping for periodicity detection. In: Fifth IEEE International Conference on Data Mining (ICDM 2005), p. 8. IEEE (2005)"},{"key":"35_CR9","unstructured":"FireEye: Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor (2020). https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html"},{"key":"35_CR10","doi-asserted-by":"crossref","unstructured":"Gao, H., et al.: An empirical reexamination of global DNs behavior. In: Proceedings of the ACM SIGCOMM 2013 Conference on SIGCOMM, pp. 267\u2013278 (2013)","DOI":"10.1145\/2486001.2486018"},{"key":"35_CR11","doi-asserted-by":"crossref","unstructured":"Haffey, M., Arlitt, M., Williamson, C.: Modeling, analysis, and characterization of periodic traffic on a campus edge network. In: 2018 IEEE 26th International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems (MASCOTS), pp. 170\u2013182. IEEE (2018)","DOI":"10.1109\/MASCOTS.2018.00025"},{"key":"35_CR12","unstructured":"Holz, T., Gorecki, C., Rieck, K., Freiling, F.C.: Measuring and detecting fast-flux service networks. In: NDSS (2008)"},{"key":"35_CR13","doi-asserted-by":"crossref","unstructured":"Hu, X., et al.: BAYWATCH: robust beaconing detection to identify infected hosts in large-scale enterprise networks. In: 2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 479\u2013490. IEEE (2016)","DOI":"10.1109\/DSN.2016.50"},{"key":"35_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"695","DOI":"10.1007\/978-3-642-45062-4_98","volume-title":"Pattern Recognition and Machine Intelligence","author":"N Hubballi","year":"2013","unstructured":"Hubballi, N., Goyal, D.: FlowSummary: summarizing network flows for communication periodicity detection. In: Maji, P., Ghosh, A., Murty, M.N., Ghosh, K., Pal, S.K. (eds.) PReMI 2013. LNCS, vol. 8251, pp. 695\u2013700. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-45062-4_98"},{"key":"35_CR15","unstructured":"Huynh, N.A.: Frequency analysis and online learning in malware detection. Ph.D. thesis, Nanyang Technological University (2019)"},{"key":"35_CR16","doi-asserted-by":"crossref","unstructured":"Invernizzi, L., et al.: Nazca: detecting malware distribution in large-scale networks. In: NDSS, vol. 14, pp. 23\u201326. Citeseer (2014)","DOI":"10.14722\/ndss.2014.23269"},{"key":"35_CR17","unstructured":"Johnson, J.: Purple team: About beacons, https:\/\/ci.security\/resources\/news\/article\/purple-team-about-beacons"},{"key":"35_CR18","doi-asserted-by":"crossref","unstructured":"Jiang, J., Yin, Q., Shi, Z., Li, M., Lv, B.: A new c&c channel detection framework using heuristic rule and transfer learning. In: 2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC), pp. 1\u20139. IEEE (2019)","DOI":"10.1109\/IPCCC47392.2019.8958732"},{"key":"35_CR19","doi-asserted-by":"crossref","unstructured":"Jin, H., Song, Q., Hu, X.: Auto-Keras: an efficient neural architecture search system. In: Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 1946\u20131956 (2019)","DOI":"10.1145\/3292500.3330648"},{"issue":"11","key":"35_CR20","doi-asserted-by":"publisher","first-page":"2375","DOI":"10.3390\/app9112375","volume":"9","author":"RU Khan","year":"2019","unstructured":"Khan, R.U., Zhang, X., Kumar, R., Sharif, A., Golilarz, N.A., Alazab, M.: An adaptive multi-layer botnet detection technique using machine learning classifiers. Appl. Sci. 9(11), 2375 (2019)","journal-title":"Appl. Sci."},{"key":"35_CR21","doi-asserted-by":"crossref","unstructured":"Kolodenker, E., Koch, W., Stringhini, G., Egele, M.: PayBreak: defense against cryptographic ransomware. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 599\u2013611 (2017)","DOI":"10.1145\/3052973.3053035"},{"key":"35_CR22","doi-asserted-by":"crossref","unstructured":"Kotzias, P., Bilge, L., Vervier, P.A., Caballero, J.: Mind your own business: a longitudinal study of threats and vulnerabilities in enterprises. In: NDSS (2019)","DOI":"10.14722\/ndss.2019.23522"},{"key":"35_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-319-11379-1_1","volume-title":"Research in Attacks, Intrusions and Defenses","author":"M K\u00fchrer","year":"2014","unstructured":"K\u00fchrer, M., Rossow, C., Holz, T.: Paint it black: evaluating the effectiveness of malware blacklists. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) RAID 2014. LNCS, vol. 8688, pp. 1\u201321. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_1"},{"issue":"4","key":"35_CR24","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1504\/IJAIP.2020.106030","volume":"15","author":"AM Manasrah","year":"2020","unstructured":"Manasrah, A.M., Domi, W.B., Suppiah, N.N.: Botnet detection based on DNs traffic similarity. Int. J. Adv. Intell. Paradigms 15(4), 357\u2013387 (2020)","journal-title":"Int. J. Adv. Intell. Paradigms"},{"issue":"253","key":"35_CR25","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1080\/01621459.1951.10500769","volume":"46","author":"FJ Massey Jr","year":"1951","unstructured":"Massey, F.J., Jr.: The Kolmogorov-Smirnov test for goodness of fit. J. Am. Stat. Assoc. 46(253), 68\u201378 (1951)","journal-title":"J. Am. Stat. Assoc."},{"key":"35_CR26","unstructured":"MITRE ATT&CK: MITRE ATT&CK tactics and techniques for enterprise. https:\/\/attack.mitre.org\/matrices\/enterprise\/"},{"key":"35_CR27","unstructured":"MITRE ATT&CK: Multi-stage channels technique. https:\/\/attack.mitre.org\/techniques\/T1104\/"},{"key":"35_CR28","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1016\/j.cose.2018.09.006","volume":"80","author":"A Nadler","year":"2019","unstructured":"Nadler, A., Aminov, A., Shabtai, A.: Detection of malicious and low throughput data exfiltration over the DNs protocol. Comput. Secur. 80, 36\u201353 (2019)","journal-title":"Comput. Secur."},{"key":"35_CR29","unstructured":"Plohmann, D., Yakdan, K., Klatt, M., Bader, J., Gerhards-Padilla, E.: A comprehensive measurement study of domain generating malware. In: 25th $$\\{USENIX\\}$$ Security Symposium ($$\\{USENIX\\}$$ Security 16), pp. 263\u2013278 (2016)"},{"issue":"1","key":"35_CR30","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1016\/S1361-3723(19)30010-7","volume":"2019","author":"D Rendell","year":"2019","unstructured":"Rendell, D.: Understanding the evolution of malware. Comput. Fraud Secur. 2019(1), 17\u201319 (2019)","journal-title":"Comput. Fraud Secur."},{"key":"35_CR31","unstructured":"Caragay, R., Cureg, F., Lagrazon, I., Mendoza, E., Yaneza, J.: (Threats Analysts): Exposing modular adware: How dealply, iserik, and managex persist in systems. https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/exposing-modular-adware-how-dealply-iserik-and-managex-persist-in-systems"},{"key":"35_CR32","doi-asserted-by":"crossref","unstructured":"Schales, D.L., Hu, X., Jang, J., Sailer, R., Stoecklin, M.P., Wang, T.: FCCE: highly scalable distributed feature collection and correlation engine for low latency big data analytics. In: 2015 IEEE 31st International Conference on Data Engineering, pp. 1316\u20131327. IEEE (2015)","DOI":"10.1109\/ICDE.2015.7113379"},{"key":"35_CR33","unstructured":"Shalaginov, A., Franke, K., Huang, X.: Malware beaconing detection by mining large-scale DNs logs for targeted attack identification. In: 18th International Conference on Computational Intelligence in Security Information Systems. WASET (2016)"},{"key":"35_CR34","doi-asserted-by":"crossref","unstructured":"Sharif, M., Urakawa, J., Christin, N., Kubota, A., Yamada, A.: Predicting impending exposure to malicious content from user behavior. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 1487\u20131501 (2018)","DOI":"10.1145\/3243734.3243779"},{"key":"35_CR35","doi-asserted-by":"crossref","unstructured":"Sidi, L., Mirsky, Y., Nadler, A., Elovici, Y., Shabtai, A.: Helix: DGA domain embeddings for tracking and exploring botnets. In: Proceedings of the 29th ACM International Conference on Information & Knowledge Management, pp. 2741\u20132748 (2020)","DOI":"10.1145\/3340531.3416022"},{"key":"35_CR36","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1016\/j.cose.2019.05.019","volume":"86","author":"M Singh","year":"2019","unstructured":"Singh, M., Singh, M., Kaur, S.: Issues and challenges in DNs based botnet detection: a survey. Comput. Secur. 86, 28\u201352 (2019)","journal-title":"Comput. Secur."},{"key":"35_CR37","doi-asserted-by":"crossref","unstructured":"Sivakorn, S., et al.: Countering malicious processes with process-DNs association. In: NDSS (2019)","DOI":"10.14722\/ndss.2019.23012"},{"issue":"6","key":"35_CR38","doi-asserted-by":"publisher","first-page":"379","DOI":"10.17706\/IJCCE.2015.4.6.379-389","volume":"4","author":"MC Tran","year":"2015","unstructured":"Tran, M.C., Nakamura, Y.: In-host communication pattern observed for suspicious http-based auto-ware detection. Int. J. Comput. Commun. Eng. 4(6), 379 (2015)","journal-title":"Int. J. Comput. Commun. Eng."},{"key":"35_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1007\/978-3-319-99073-6_22","volume-title":"Computer Security","author":"T Urban","year":"2018","unstructured":"Urban, T., Tatang, D., Holz, T., Pohlmann, N.: Towards understanding privacy implications of adware and potentially unwanted programs. In: Lopez, J., Zhou, J., Soriano, M. (eds.) ESORICS 2018. LNCS, vol. 11098, pp. 449\u2013469. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-99073-6_22"},{"key":"35_CR40","doi-asserted-by":"crossref","unstructured":"Welzel, A., Rossow, C., Bos, H.: On measuring the impact of DDoS botnets. In: Proceedings of the Seventh European Workshop on System Security, pp. 1\u20136 (2014)","DOI":"10.1145\/2592791.2592794"},{"key":"35_CR41","doi-asserted-by":"crossref","unstructured":"Yeh, Y.R., Tu, T.C., Sun, M.K., Pi, S.M., Huang, C.Y.: A malware beacon of botnet by local periodic communication behavior. In: 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC), vol. 2, pp. 653\u2013657. IEEE (2018)","DOI":"10.1109\/COMPSAC.2018.10313"},{"issue":"4","key":"35_CR42","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3191329","volume":"51","author":"Y Zhauniarovich","year":"2018","unstructured":"Zhauniarovich, Y., Khalil, I., Yu, T., Dacier, M.: A survey on malicious domains detection through DNs data analysis. ACM Comput. Surveys (CSUR) 51(4), 1\u201336 (2018)","journal-title":"ACM Comput. Surveys (CSUR)"},{"key":"35_CR43","unstructured":"Zhu, S., et al.: Measuring and modeling the label dynamics of online anti-malware engines. In: 29th $$\\{USENIX\\}$$ Security Symposium ($$\\{USENIX\\}$$ Security 20), pp. 2361\u20132378 (2020)"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2021"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-88418-5_35","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T01:12:34Z","timestamp":1725844354000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-88418-5_35"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030884178","9783030884185"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-88418-5_35","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"30 September 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Darmstadt","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 October 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2021.athene-center.de\/index.php","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"351","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"71","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.07","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6.06","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}