{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T15:19:45Z","timestamp":1759331985310,"version":"3.40.3"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030900182"},{"type":"electronic","value":"9783030900199"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-90019-9_24","type":"book-chapter","created":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T18:47:48Z","timestamp":1635878868000},"page":"476-496","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Using NetFlow to Measure the Impact of Deploying DNS-based Blacklists"],"prefix":"10.1007","author":[{"given":"Martin","family":"Fejrskov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jens Myrup","family":"Pedersen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emmanouil","family":"Vasilomanolakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,11,3]]},"reference":[{"key":"24_CR1","doi-asserted-by":"crossref","unstructured":"Bermudez, I.N., Mellia, M., Munaf\u00f2, M.M., Keralapura, R., Nucci, A.: DNS to the rescue: discerning content and services in a tangled web. In: IMC: Internet Measurement Conference (2012). https:\/\/doi.org\/10.1145\/2398776.2398819","DOI":"10.1145\/2398776.2398819"},{"key":"24_CR2","unstructured":"Bouwman, X., Griffioen, H., Egbers, J., Doerr, C., Klievink, B., van Eeten, M.: A different cup of TI? The added value of commercial threat intelligence. In: USENIX Security Symposium (2020). https:\/\/www.usenix.org\/system\/files\/sec20-bouwman.pdf"},{"key":"24_CR3","unstructured":"Cisco umbrella: better intelligence drives better security (2020). https:\/\/umbrella.cisco.com\/solutions\/reduce-security-infections"},{"key":"24_CR4","unstructured":"Connery, H.: DNS: response policy zone (2012). https:\/\/dnsrpz.info\/spamhaus-rpz-case-study.pdf"},{"key":"24_CR5","doi-asserted-by":"crossref","unstructured":"Duffield, N., Lund, C., Thorup, M.: Properties and prediction of flow statistics from sampled packet streams. In: IMW: ACM SIGCOMM Internet Measurement Workshop (2002). https:\/\/doi.org\/10.1145\/637201.637225","DOI":"10.1145\/637201.637225"},{"key":"24_CR6","doi-asserted-by":"crossref","unstructured":"Fejrskov, M., Pedersen, J.M., Vasilomanolakis, E.: Cyber-security research by ISPs: a NetFlow and DNS anonymization policy. In: International Conference on Cyber Security And Protection Of Digital Services (2020). https:\/\/doi.org\/10.1109\/CyberSecurity49315.2020.9138869","DOI":"10.1109\/CyberSecurity49315.2020.9138869"},{"key":"24_CR7","doi-asserted-by":"crossref","unstructured":"Foremski, P., Callegari, C., Pagano, M.: DNS-class: immediate classification of IP flows using DNS. In: ACM Int. J. Netw. Manage. (2014). https:\/\/doi.org\/10.1002\/nem.1864","DOI":"10.1002\/nem.1864"},{"key":"24_CR8","doi-asserted-by":"publisher","unstructured":"Griffioen, H., Booij, T., Doerr, C.: Quality Evaluation of Cyber Threat Intelligence Feeds. In: Conti, M., Zhou, J., Casalicchio, E., Spognardi, A. (eds.) ACNS 2020. LNCS, vol. 12147, pp. 277\u2013296. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-57878-7_14","DOI":"10.1007\/978-3-030-57878-7_14"},{"key":"24_CR9","doi-asserted-by":"crossref","unstructured":"Jung, J., Sit, E.: An empirical study of spam traffic and the use of DNS black lists. In: IMC: Internet Measurement Conference (2004). https:\/\/doi.org\/10.1145\/1028788.1028838","DOI":"10.1145\/1028788.1028838"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"K\u00fchrer, M., Rossow, C., Holz, T.: Paint it black: evaluating the effectiveness of malware blacklists. In: RAID: Research in Attacks Intrusions and Defenses (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_1","DOI":"10.1007\/978-3-319-11379-1_1"},{"key":"24_CR11","unstructured":"Li, V.G., Dunn, M., Pearce, P., McCoy, D., Voelker, G.M., Savage, S., Levchenko, K.: Reading the tea leaves: a comparative analysis of threat intelligence. In: USENIX Security Symposium (2019). https:\/\/www.usenix.org\/system\/files\/sec19-li-vector_guo.pdf"},{"key":"24_CR12","unstructured":"MXToolbox: blacklist check (2021). https:\/\/mxtoolbox.com\/blacklists.aspx"},{"key":"24_CR13","doi-asserted-by":"crossref","unstructured":"Ramachandran, A., Feamster, N.: Understanding the network-level behavior of spammers. In: ACM SIGCOMM Computer Communication Review (2006). https:\/\/doi.org\/10.1145\/1159913.1159947","DOI":"10.1145\/1159913.1159947"},{"key":"24_CR14","doi-asserted-by":"crossref","unstructured":"Satoh, A., Nakamura, Y., Fukuda, Y., Sasai, K., Kitagata, G.: A cause-based classification approach for malicious DNS queries detected through blacklists. IEEE Access (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2944203","DOI":"10.1109\/ACCESS.2019.2944203"},{"key":"24_CR15","unstructured":"Sheng, S., Wardman, B., Warner, G., Cranor, L., Hong, J., Zhang, C.: An empirical analysis of phishing blacklists. In: CEAS: Conference on Email and Anti-Spam (2009). https:\/\/doi.org\/10.1184\/R1\/6469805.V1"},{"key":"24_CR16","doi-asserted-by":"crossref","unstructured":"Sinha, S., Bailey, M., Jahanian, F.: Shades of grey: On the effectiveness of reputation-based \"blacklists\". MALWARE: International Conference on Malicious and Unwanted Software (2008), https:\/\/doi.org\/10.1109\/MALWARE.2008.4690858","DOI":"10.1109\/MALWARE.2008.4690858"},{"key":"24_CR17","unstructured":"Spacek, S., Lastovicka, M., Horak, M., Plesnik, T.: Current Issues of Malicious Domains Blocking. IFIP\/IEEE International Symposium on Integrated Network Management (2019), https:\/\/ieeexplore.ieee.org\/document\/8717891"},{"key":"24_CR18","unstructured":"Telenor Norway: Stanset over 80.000 bes\u00f8k p\u00e5 falske nettsider p\u00e5 \u00e9n m\u00e5ned (2020), https:\/\/www.mynewsdesk.com\/no\/telenor\/pressreleases\/stanset-over-80-dot-000-besoek-paa-falske-nettsider-paa-en-maaned-2986773"},{"key":"24_CR19","unstructured":"Wikipedia: Domain Name System-based Blackhole List (2020), https:\/\/en.wikipedia.org\/wiki\/Domain_Name_System-based_Blackhole_List"},{"key":"24_CR20","doi-asserted-by":"publisher","unstructured":"Wilde, N., Jones, L., Lopez, R., Vaughn, T.: A DNS RPZ Firewall and Current American DNS Practice. In: Kim, K.J., Baek, N. (eds.) ICISA 2018. LNEE, vol. 514, pp. 259\u2013265. Springer, Singapore (2019). https:\/\/doi.org\/10.1007\/978-981-13-1056-0_27","DOI":"10.1007\/978-981-13-1056-0_27"},{"key":"24_CR21","unstructured":"Williamson, R.: What do Canada and New Zealand have in common? (2020), https:\/\/internetnz.nz\/blog\/dns-firewall-what-do-canada-and-new-zealand-have-in-common\/"},{"key":"24_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1007\/978-3-642-36516-4_22","volume-title":"Passive and Active Measurement","author":"J Zhang","year":"2013","unstructured":"Zhang, J., Chivukula, A., Bailey, M., Karir, M., Liu, M.: Characterization of Blacklists and Tainted Network Traffic. In: Roughan, M., Chang, R. (eds.) PAM 2013. LNCS, vol. 7799, pp. 218\u2013228. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-36516-4_22"},{"key":"24_CR23","doi-asserted-by":"crossref","unstructured":"Zhauniarovich, Y., Khalil, I., Yu, T., Dacier, M.: A survey on malicious domains detection through DNS data analysis. ACM Computing Surveys (2018), https:\/\/doi.org\/10.1145\/3191329","DOI":"10.1145\/3191329"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-90019-9_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T18:59:18Z","timestamp":1635879558000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-90019-9_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030900182","9783030900199"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-90019-9_24","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"3 November 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2021\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confy +","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"143","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"56","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}