{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T14:11:23Z","timestamp":1785247883644,"version":"3.55.0"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032006264","type":"print"},{"value":"9783032006271","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-00627-1_20","type":"book-chapter","created":{"date-parts":[[2025,8,9]],"date-time":"2025-08-09T04:22:27Z","timestamp":1754713347000},"page":"409-419","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["C2 Beaconing Detection via\u00a0AI-Based Time-Series Analysis"],"prefix":"10.1007","author":[{"given":"Jeetesh","family":"Gupta","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jan","family":"Pfeifer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anum","family":"Talpur","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathias","family":"Fischer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,8,10]]},"reference":[{"key":"20_CR1","unstructured":"Active Countermeasures: RITA: real intelligence threat analytics (2025). https:\/\/www.activecountermeasures.com\/free-tools\/rita\/"},{"key":"20_CR2","doi-asserted-by":"crossref","unstructured":"Apruzzese, G., Marchetti, M., Colajanni, M., Zoccoli, G.G., Guido, A.: Identifying malicious hosts involved in periodic communications. In: 2017 IEEE 16th International Symposium on Network Computing and Applications (NCA) (2017)","DOI":"10.1109\/NCA.2017.8171326"},{"key":"20_CR3","doi-asserted-by":"crossref","unstructured":"Eisenberg, D.A., Alderson, D.L., Kitsak, M., Ganin, A., Linkov, I.: Network foundation for command and control (c2) systems: literature review. IEEE Access (2018)","DOI":"10.1109\/ACCESS.2018.2873328"},{"key":"20_CR4","doi-asserted-by":"crossref","unstructured":"Garcia, S., Grill, M., Stiborek, J., Zunino, A.: An empirical comparison of botnet detection methods. Comput. Secur. 45 (2014)","DOI":"10.1016\/j.cose.2014.05.011"},{"key":"20_CR5","unstructured":"Garcia, S., Parmisano, A., Erquiaga, M.J.: Iot-23: a labeled dataset with malicious and benign IoT network traffic. http:\/\/doi.org\/10.5281\/zenodo.4743746"},{"key":"20_CR6","unstructured":"Gardiner, J., Cova, M., Nagaraja, S.: Command and control: understanding, denying and detecting-a review of malware c2 techniques, detection and defences (2014). arXiv preprint arXiv:1408.1136"},{"key":"20_CR7","unstructured":"Garza, A., Mergenthaler-Canseco, M.: TimeGPT-1 (2023). arXiv preprint arXiv:2310.03589"},{"key":"20_CR8","doi-asserted-by":"crossref","unstructured":"Hochreiter, S.: Long short-term memory. Neural Comput. (1997)","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"20_CR9","doi-asserted-by":"crossref","unstructured":"Hu, X., et al.: Baywatch: robust beaconing detection to identify infected hosts in large-scale enterprise networks. In: 2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN) (2016)","DOI":"10.1109\/DSN.2016.50"},{"key":"20_CR10","unstructured":"Huynh, N.A., Ng, W.K., Ulmer, A., Kohlhammer, J.: Uncovering periodic network signals of cyber attacks. In: 2016 IEEE Symposium on Visualization for Cyber Security (VizSec) (2016)"},{"key":"20_CR11","unstructured":"Ioulianou, P., Vasilakis, V., Moscholios, I., Logothetis, M.: A signature-based intrusion detection system for the internet of things. Inf. Commun. Technol. Form (2018)"},{"key":"20_CR12","doi-asserted-by":"crossref","unstructured":"K\u00e4nzig, N., Meier, R., Gambazzi, L., Lenders, V., Vanbever, L.: Machine learning-based detection of C and C channels with a focus on the locked shields cyber defense exercise. In: 2019 11th International Conference on Cyber Conflict (CyCon). IEEE","DOI":"10.23919\/CYCON.2019.8756814"},{"key":"20_CR13","unstructured":"Lashkari, A.H., Draper-Gil, G., Mamun, M.S.I., Ghorbani, A.A.: Characterization of TOR traffic using time based features. In: Proceedings of the 3rd International Conference on Information System Security and Privacy (ICISSP) (2017)"},{"key":"20_CR14","doi-asserted-by":"crossref","unstructured":"Liu, Z., Yun, X., Zhang, Y., Wang, Y.: CCGA: clustering and capturing group activities for DGA-based botnets detection. In: 2019 18th IEEE International Conference On Trust, Security and Privacy in Computing and Communications\/13th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE)","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00027"},{"key":"20_CR15","unstructured":"L\u00f6ning, M., Bagnall, A., Ganesh, S., Kazakov, V., Lines, J., Kir\u00e1ly, F.J.: sktime: a unified interface for machine learning with time series (2019). arXiv preprint arXiv:1909.07872"},{"key":"20_CR16","doi-asserted-by":"crossref","unstructured":"Richer, T.J.: Entropy-based detection of botnet command and control. In: Proceedings of the Australasian Computer Science Week Multiconference (2017)","DOI":"10.1145\/3014812.3014889"},{"key":"20_CR17","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Ghorbani, A.A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: International Conference on Information Systems Security and Privacy (2018)","DOI":"10.5220\/0006639801080116"},{"key":"20_CR18","doi-asserted-by":"crossref","unstructured":"Talib, M.A., Nasir, Q., Nassif, A.B., Mokhamed, T., Ahmed, N., Mahfood, B.: APT beaconing detection: a systematic review. Comput. Secur. 122 (2022)","DOI":"10.1016\/j.cose.2022.102875"},{"key":"20_CR19","doi-asserted-by":"crossref","unstructured":"Vishvakarma, D.K., Bhatia, A., Riha, Z.: Detection of algorithmically generated domain names in botnets. In: Advanced Information Networking and Applications: Proceedings of the 33rd International Conference on Advanced Information Networking and Applications (AINA-2019), vol. 33. Springer","DOI":"10.1007\/978-3-030-15032-7_107"},{"key":"20_CR20","doi-asserted-by":"crossref","unstructured":"Wen, Q., He, K., Sun, L., Zhang, Y., Ke, M., Xu, H.: Robustperiod: Robust time-frequency mining for multiple periodicity detection. In: Proceedings of the 2021 International Conference on Management of Data (2021)","DOI":"10.1145\/3448016.3452779"},{"key":"20_CR21","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Dong, H., Nottingham, A., Buchanan, M., Brown, D.E., Sun, Y.: Global analysis with aggregation-based beaconing detection across large campus networks. In: Proceedings of the 39th Annual Computer Security Applications Conference (2023)","DOI":"10.1145\/3627106.3627126"}],"container-title":["Lecture Notes in Computer Science","Availability, Reliability and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00627-1_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T13:42:43Z","timestamp":1785246163000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00627-1_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032006264","9783032006271"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00627-1_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"10 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ARES","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Availability, Reliability and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ghent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ares-12025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.ares-conference.eu","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}