{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,2]],"date-time":"2026-08-02T12:28:09Z","timestamp":1785673689158,"version":"3.56.0"},"publisher-location":"Cham","reference-count":15,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319691541","type":"print"},{"value":"9783319691558","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-69155-8_13","type":"book-chapter","created":{"date-parts":[[2017,10,10]],"date-time":"2017-10-10T05:43:16Z","timestamp":1507614196000},"page":"169-181","source":"Crossref","is-referenced-by-count":14,"title":["Network Behavioral Analysis for Zero-Day Malware Detection \u2013 A Case Study"],"prefix":"10.1007","author":[{"given":"Karim","family":"Ganame","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marc Andr\u00e9","family":"Allaire","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ghassen","family":"Zagdene","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Oussama","family":"Boudar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,10,11]]},"reference":[{"issue":"1","key":"13_CR1","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/s11416-008-0092-2","volume":"6","author":"A Gazet","year":"2010","unstructured":"Gazet, A.: Comparative analysis of various ransomware virii. J. Comput. Virol. 6(1), 77\u201390 (2010)","journal-title":"J. Comput. Virol."},{"key":"13_CR2","unstructured":"CDS Compromise Detection System. https:\/\/www.streamscan.io\/cds Accessed 07 Aug 2017"},{"key":"13_CR3","unstructured":"Microsoft Security Bulletin MS17-010. https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx"},{"key":"13_CR4","unstructured":"Simple Message Bloc. https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa365233(v=vs.85).aspx . Accessed 07 Aug 2017"},{"key":"13_CR5","unstructured":"EthernalBlue: https:\/\/packetstormsecurity.com\/files\/142169\/ETERNALBLUE-2.2.0-Windows-2008-R2-SMBv1-Zero-Day-Exploit.html . Accessed 07 Aug 2017"},{"key":"13_CR6","unstructured":"TOR: https:\/\/www.torproject.org\/about\/overview.html.en . Accessed 07 Aug 2017"},{"key":"13_CR7","unstructured":"Antonakakis, M., et al.: From Throw-Away traffic to bots: detecting the rise of DGA-Based malware. USENIX security symposium, Vol. 12 (2012)"},{"key":"13_CR8","unstructured":"Wireshark. https:\/\/www.wireshark.org . Accessed 07 Aug 2017"},{"key":"13_CR9","unstructured":"TCPDUMP: www.tcpdump.org"},{"key":"13_CR10","unstructured":"SNORT Intrusion Detection System. https:\/\/www.snort.org\/ . Accessed 07 Aug 2017"},{"key":"13_CR11","unstructured":"Alienvault Detecting WannaCry Ransomware. http:\/\/www.infosec-cloud.com\/wp-content\/uploads\/2017\/05\/AlienVault-Detect-WannaCry-Ransomware-white-paper.pdf . Accessed 07 Aug 2017"},{"key":"13_CR12","unstructured":"McAfee Labs Threat Advisory, Ransom-WannaCry. https:\/\/kc.mcafee.com\/resources\/sites\/MCAFEE\/content\/live\/PRODUCT_DOCUMENTATION\/27000\/PD27077\/en_US\/McAfee_Labs_WannaCry_May_24.pdf . Accessed 07 Aug 2017"},{"key":"13_CR13","unstructured":"FireEeye Endpoint Security Detect Prevent WannaCry. https:\/\/www.fireeye.com\/blog\/products-and-services\/2017\/05\/fireeye-endpoint-security-detect-prevent-wannacry.html"},{"key":"13_CR14","doi-asserted-by":"crossref","unstructured":"Zhao, D., Traore, I.: P2P botnet detection through malicious fast flux network identification. In: 7th International Conference on P2P, Parallel, Grid, Cloud, and Internet Computing -3PGCIC 2012, 12\u201314, Victoria, BC, Canada, November 2012","DOI":"10.1109\/3PGCIC.2012.48"},{"key":"13_CR15","unstructured":"Gu, G., et al.: BotMiner: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: USENIX Security Symposium, Vol. 5(2) (2008)"}],"container-title":["Lecture Notes in Computer Science","Intelligent, Secure, and Dependable Systems in Distributed and Cloud Environments"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-69155-8_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,4]],"date-time":"2019-10-04T07:52:09Z","timestamp":1570175529000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-69155-8_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319691541","9783319691558"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-69155-8_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}