{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T09:32:52Z","timestamp":1742981572863,"version":"3.40.3"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030916244"},{"type":"electronic","value":"9783030916251"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-91625-1_8","type":"book-chapter","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T00:03:08Z","timestamp":1636761788000},"page":"133-152","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Gollector: Measuring Domain Name Dark Matter from Different Vantage Points"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4245-9798","authenticated-orcid":false,"given":"Kaspar","family":"Hageman","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5688-6432","authenticated-orcid":false,"given":"Ren\u00e9 Rydhof","family":"Hansen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1903-2921","authenticated-orcid":false,"given":"Jens Myrup","family":"Pedersen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"8_CR1","unstructured":"Comodo SSL affiliate the recent RA compromise. https:\/\/blog.comodo.com\/other\/the-recent-ra-compromise\/. Accessed 23 July 2021"},{"key":"8_CR2","unstructured":"DNSdumpster. https:\/\/dnsdumpster.com\/. Accessed 10 July 2021"},{"key":"8_CR3","unstructured":"DSNRecon. https:\/\/github.com\/darkoperator\/dnsrecon. Accessed 10 July 2021"},{"key":"8_CR4","unstructured":"Magento. https:\/\/magento.com\/. Accessed 27 July 2021"},{"key":"8_CR5","unstructured":"OWASP\/Amass. https:\/\/github.com\/OWASP\/Amass. Accessed 10 July 2021"},{"key":"8_CR6","unstructured":"Subfinder. https:\/\/github.com\/projectdiscovery\/subfinder. Accessed 10 July 2021"},{"key":"8_CR7","unstructured":"Sublist3r. https:\/\/github.com\/aboul3la\/Sublist3r. Accessed 10 July 2021"},{"key":"8_CR8","unstructured":"The most popular subdomains on the internet (2016). https:\/\/bitquark.co.uk\/blog\/2016\/02\/29\/the_most_popular_subdomains_on_the_internet. Accessed 27 July 2021"},{"key":"8_CR9","unstructured":"About Splunk stream (2020). https:\/\/docs.splunk.com\/Documentation\/StreamApp\/7.3.0\/DeployStreamApp\/AboutSplunkStream. Accessed 10 July 2021"},{"key":"8_CR10","unstructured":"Openintel - current coverage (2020). https:\/\/openintel.nl\/coverage\/. Accessed 10 July 2021"},{"key":"8_CR11","unstructured":"Using GeoIP with BIND 9 (2020). https:\/\/kb.isc.org\/docs\/aa-01149. Accessed 10 July 2021"},{"key":"8_CR12","unstructured":"About zone file access (2021). https:\/\/www.icann.org\/resources\/pages\/zfa-2013-06-28-en. Accessed 30 Aug 2021"},{"key":"8_CR13","unstructured":"Centralized zone data service (2021). https:\/\/czds.icann.org\/. Accessed 30 Aug 2021"},{"key":"8_CR14","unstructured":"List of top-level domains (2021). https:\/\/www.icann.org\/resources\/pages\/tlds-2012-02-25-en. Accessed 30 Aug 2021"},{"key":"8_CR15","unstructured":"Project sonar (2021). https:\/\/opendata.rapid7.com\/about\/. Accessed 10 July 2021"},{"key":"8_CR16","unstructured":"Public suffix list (2021). https:\/\/publicsuffix.org\/. Accessed 10 July 2021"},{"key":"8_CR17","unstructured":"value (2021). https:\/\/documentation.cpanel.net\/display\/CKB\/Service+Subdomains+Explanation. Accessed 30 Aug 2021"},{"key":"8_CR18","doi-asserted-by":"publisher","unstructured":"van Adrichem, N.L.M., et al.: A measurement study of DNSSEC misconfigurations. Secur. Inform. 4(1) (2015). https:\/\/doi.org\/10.1186\/s13388-015-0023-y","DOI":"10.1186\/s13388-015-0023-y"},{"key":"8_CR19","doi-asserted-by":"publisher","unstructured":"Aitchison, R.: DNS techniques, pp. 163\u2013207. Apress, Berkeley (2011). https:\/\/doi.org\/10.1007\/978-1-4302-3049-6_8","DOI":"10.1007\/978-1-4302-3049-6_8"},{"issue":"7","key":"8_CR20","doi-asserted-by":"publisher","first-page":"1541","DOI":"10.1007\/s00521-015-2128-0","volume":"28","author":"K Alieyan","year":"2017","unstructured":"Alieyan, K., Almomani, A., Manasrah, A., Kadhum, M.M.: A survey of botnet detection based on DNS. Neural Comput. Appl. 28(7), 1541\u20131558 (2017). https:\/\/doi.org\/10.1007\/s00521-015-2128-0","journal-title":"Neural Comput. Appl."},{"key":"8_CR21","unstructured":"Behjat, A.: ISC spins off its security business unit (2013). https:\/\/www.isc.org\/blogs\/isc-spins-off-its-security-business-unit\/"},{"key":"8_CR22","unstructured":"Bharath: A penetration tester\u2019s guide to subdomain enumeration (2018). https:\/\/blog.appsecco.com\/a-penetration-testers-guide-to-sub-domain-enumeration-7d842d5570f6. Accessed 24 July 2021"},{"key":"8_CR23","unstructured":"Borges, E.: Wrong Bind configuration exposes the complete list of Russian TLD\u2019s to the Internet, March 2018. https:\/\/securitytrails.com\/blog\/russian-tlds. Accessed 30 Aug 2021"},{"key":"8_CR24","doi-asserted-by":"crossref","unstructured":"Eastlake, D., Panitz, A.: Reserved Top Level DNS Names, RFC ed. BCP 32, June 1999","DOI":"10.17487\/rfc2606"},{"key":"8_CR25","unstructured":"Edmonds, R.: ISC passive DNS architecture (2012). https:\/\/mirror.yongbok.net\/isc\/kb-files\/passive-dns-architecture.pdf"},{"key":"8_CR26","doi-asserted-by":"publisher","unstructured":"Hao, S., Kantchelian, A., Miller, B., Paxson, V., Feamster, N.: PREDATOR: proactive recognition and elimination of domain abuse at time-of-registration. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS 2016, pp. 1568\u20131579. Association for Computing Machinery, New York (2016). https:\/\/doi.org\/10.1145\/2976749.2978317","DOI":"10.1145\/2976749.2978317"},{"key":"8_CR27","doi-asserted-by":"publisher","unstructured":"Hohlfeld, O.: Operating a DNS-based active internet observatory. In: Proceedings of the ACM SIGCOMM 2018 Conference on Posters and Demos, SIGCOMM 2018, pp. 60\u201362. Association for Computing Machinery, New York (2018). https:\/\/doi.org\/10.1145\/3234200.3234239","DOI":"10.1145\/3234200.3234239"},{"key":"8_CR28","first-page":"241","volume":"37","author":"P Jaccard","year":"1901","unstructured":"Jaccard, P.: Distribution de la flore alpine dans le bassin des dranses et dans quelques r\u00e9gions voisines. Bull. Soc. Vaudoise. Sci. Nat. 37, 241\u2013272 (1901)","journal-title":"Bull. Soc. Vaudoise. Sci. Nat."},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Laurie, B., Langley, A., Kasper, E.: Certificate Transparency, RFC ed. RFC 6962, June 2013","DOI":"10.17487\/rfc6962"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"Mockapetris, P.: Domain Names - Implementation and Specification, RFC ed. STD 13, November 1987. http:\/\/www.rfc-editor.org\/rfc\/rfc1035.txt","DOI":"10.17487\/rfc1035"},{"key":"8_CR31","unstructured":"Pearce, P., et al.: Global measurement of DNS manipulation. In: 26th USENIX Security Symposium (USENIX Security 2017), pp. 307\u2013323. USENIX Association, Vancouver, August 2017. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/pearce"},{"key":"8_CR32","unstructured":"Prins, J.: DigiNotar certificate authority breach \u201coperation black tulip\u201d (2011). https:\/\/media.threatpost.com\/wp-content\/uploads\/sites\/103\/2011\/09\/07061400\/rapport-fox-it-operation-black-tulip-v1-0.pdf. Accessed 23 July 2021"},{"key":"8_CR33","doi-asserted-by":"crossref","unstructured":"Rescorla, E.: The Transport Layer Security (TLS) Protocol Version 1.3, RFC ed. RFC 8446, August 2018","DOI":"10.17487\/RFC8446"},{"issue":"6","key":"8_CR34","doi-asserted-by":"publisher","first-page":"1877","DOI":"10.1109\/JSAC.2016.2558918","volume":"34","author":"R van Rijswijk-Deij","year":"2016","unstructured":"van Rijswijk-Deij, R., Jonker, M., Sperotto, A., Pras, A.: A high-performance, scalable infrastructure for large-scale active DNS measurements. IEEE J. Sel. Areas Commun. 34(6), 1877\u20131888 (2016). https:\/\/doi.org\/10.1109\/JSAC.2016.2558918","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Schlyter, J.: DNS Security (DNSSEC) NextSECure (NSEC) RDATA Format, RFC ed. RFC 3845, August 2004","DOI":"10.17487\/rfc3845"},{"key":"8_CR36","doi-asserted-by":"publisher","unstructured":"Singh, M., Singh, M., Kaur, S.: Issues and challenges in DNS based botnet detection: a survey. Comput. Secur. 86, 28\u201352 (2019). https:\/\/doi.org\/10.1016\/j.cose.2019.05.019. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404819301117","DOI":"10.1016\/j.cose.2019.05.019"},{"key":"8_CR37","unstructured":"Szurdi, J., Kocso, B., Cseh, G., Spring, J., Felegyhazi, M., Kanich, C.: The long \u201ctaile\u201d of typosquatting domain names. In: 23rd USENIX Security Symposium (USENIX Security 2014), pp. 191\u2013206. USENIX Association, San Diego, August 2014. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/szurdi"},{"key":"8_CR38","doi-asserted-by":"publisher","unstructured":"van der Toorn, O., van Rijswijk-Deij, R., Geesink, B., Sperotto, A.: Melting the snow: using active DNS measurements to detect snowshoe spam domains. In: NOMS 2018\u20132018 IEEE\/IFIP Network Operations and Management Symposium, pp. 1\u20139 (2018). https:\/\/doi.org\/10.1109\/NOMS.2018.8406222","DOI":"10.1109\/NOMS.2018.8406222"},{"key":"8_CR39","doi-asserted-by":"publisher","unstructured":"VanderSloot, B., Amann, J., Bernhard, M., Durumeric, Z., Bailey, M., Halderman, J.A.: Towards a complete view of the certificate ecosystem. In: Proceedings of the 2016 Internet Measurement Conference, IMC 2016, pp. 543\u2013549. Association for Computing Machinery, New York (2016). https:\/\/doi.org\/10.1145\/2987443.2987462","DOI":"10.1145\/2987443.2987462"},{"key":"8_CR40","unstructured":"Weimer, F.: Passive DNS replication. In: FIRST Conference on Computer Security Incident (2005)"},{"key":"8_CR41","doi-asserted-by":"publisher","unstructured":"Wullink, M., Moura, G.C.M., M\u00fcller, M., Hesselman, C.: ENTRADA: a high-performance network traffic data streaming warehouse. In: NOMS 2016\u20132016 IEEE\/IFIP Network Operations and Management Symposium, pp. 913\u2013918 (2016). https:\/\/doi.org\/10.1109\/NOMS.2016.7502925","DOI":"10.1109\/NOMS.2016.7502925"},{"key":"8_CR42","doi-asserted-by":"publisher","unstructured":"Wullink, M., Muller, M., Davids, M., Moura, G.C.M., Hesselman, C.: ENTRADA: enabling DNS big data applications. In: 2016 APWG Symposium on Electronic Crime Research (eCrime), pp. 1\u201311 (2016). https:\/\/doi.org\/10.1109\/ECRIME.2016.7487939","DOI":"10.1109\/ECRIME.2016.7487939"}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-91625-1_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,19]],"date-time":"2021-11-19T00:12:32Z","timestamp":1637280752000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-91625-1_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030916244","9783030916251"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-91625-1_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"13 November 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NordSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nordic Conference on Secure IT Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 November 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 November 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nordsec2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/events.tuni.fi\/nordsec2021\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"11","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.83","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.47","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}