{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:08:34Z","timestamp":1783764514476,"version":"3.55.0"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319691541","type":"print"},{"value":"9783319691558","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-69155-8_4","type":"book-chapter","created":{"date-parts":[[2017,10,10]],"date-time":"2017-10-10T05:43:16Z","timestamp":1507614196000},"page":"55-62","source":"Crossref","is-referenced-by-count":11,"title":["Detecting Command and Control Channel of Botnets in Cloud"],"prefix":"10.1007","author":[{"given":"Wei","family":"Lu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mark","family":"Miller","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ling","family":"Xue","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,10,11]]},"reference":[{"key":"4_CR1","unstructured":"Symantec. \nhttp:\/\/www.symantec.com\/security_response\/publications\/threatreport.jsp\n\n. Accessed 1 June 2017"},{"key":"4_CR2","unstructured":"Rajab, M., Zarfoss, J., Monrose, F., Terzis, A.: My botnet is bigger than yours (maybe, better than yours): why size estimates remain challenging. In: Proceedings of the 1st Workshop on Hot Topics in Understanding Botnets (HotBots 2007), 10 April 2007 (2007)"},{"key":"4_CR3","unstructured":"Uses of botnets, The Honeynet Project. \nhttps:\/\/www.honeynet.org\/node\/52"},{"key":"4_CR4","unstructured":"Sinit. \nhttp:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2003-100910-5701-99\n\n. Accessed 1 Apr 2017"},{"key":"4_CR5","unstructured":"Nugache. \nhttp:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2006-043016-0900-99\n\n. Accessed 1 Apr 2017"},{"key":"4_CR6","unstructured":"Phatbot. \nhttp:\/\/www.symantec.com\/security_response\/attacksignatures\/detail.jsp?asid=20658\n\n. Accessed 1 Apr 2017"},{"key":"4_CR7","unstructured":"Peacomm. \nhttp:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2007-011917-1403-99\n\n. Accessed 1 Apr 2017"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, pp. 41\u201352 (2006)","DOI":"10.1145\/1177080.1177086"},{"key":"4_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/11856214_9","volume-title":"Recent Advances in Intrusion Detection","author":"P Baecher","year":"2006","unstructured":"Baecher, P., Koetter, M., Holz, T., Dornseif, M., Freiling, F.: The nepenthes platform: an efficient approach to collect malware. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol. 4219, pp. 165\u2013184. Springer, Heidelberg (2006). doi:\n10.1007\/11856214_9"},{"key":"4_CR10","unstructured":"Yegneswaran, V., Barford, P., Paxson, V.: Using honeynets for internet situational awareness. In: Proceedings of the 4th Workshop on Hot Topics in Networks, College Park, MD (2005)"},{"key":"4_CR11","series-title":"Advances in Information Security","isbn-type":"print","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1007\/11555827_19","volume-title":"Botnet Detection","author":"Z Li","year":"2008","unstructured":"Li, Z., Goyal, A., Chen, Y.: Honeynet-based botnet scan traffic analysis. In: Lee, W., Wang, C., Dagon, D. (eds.) Botnet Detection. ADIS, vol. 36, pp. 25\u201344. Springer, Heidelberg (2008). doi:\n10.1007\/11555827_19\n\n. ISBN 978-0-387-68766-7","ISBN":"https:\/\/id.crossref.org\/isbn\/9780387687667"},{"key":"4_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/11555827_19","volume-title":"Computer Security \u2013 ESORICS 2005","author":"FC Freiling","year":"2005","unstructured":"Freiling, F.C., Holz, T., Wicherski, G.: Botnet tracking: exploring a root-cause methodology to prevent distributed denial-of-service attacks. In: de Capitani di Vimercati, S., Syverson, P., Gollmann, D. (eds.) ESORICS 2005. LNCS, vol. 3679, pp. 319\u2013335. Springer, Heidelberg (2005). doi:\n10.1007\/11555827_19"},{"key":"4_CR13","unstructured":"Holz, T., Steiner, M., Dahl, F., Biersack, E., Freiling, F.: Measurements and mitigation of peer-to-peer-based botnets: a case study on storm worm. In: Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats, San Francisco, California (2008)"},{"key":"4_CR14","doi-asserted-by":"crossref","unstructured":"Strayer, T., Walsh, R., Livadas, C., Lapsley, D.: Detecting botnets with tight command and control. In: Proceedings 2006 31st IEEE Conference on Local Computer Networks, pp. 195\u2013202 (2006)","DOI":"10.1109\/LCN.2006.322100"},{"key":"4_CR15","series-title":"Advances in Information Security","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-0-387-68768-1_1","volume-title":"Botnet Detection","author":"WT Strayer","year":"2008","unstructured":"Strayer, W.T., Lapsely, D., Walsh, R., Livadas, C.: Botnet detection based on network behavior. In: Lee, W., Wang, C., Dagon, D. (eds.) Botnet Detection. ADIS, vol. 36, pp. 1\u201324. Springer, Heidelberg (2008). doi:\n10.1007\/978-0-387-68768-1_1"},{"key":"4_CR16","doi-asserted-by":"crossref","unstructured":"Livadas, C., Walsh, R., Lapsley, D., Strayer, T.: Using machine learning techniques to identify botnet traffic. In: Proceedings 2006 31st IEEE Conference on Local Computer Networks, pp. 967\u2013974, November 2006","DOI":"10.1109\/LCN.2006.322210"},{"key":"4_CR17","unstructured":"Goebel, J., Holz, T.: Rishi: identify bot contaminated hosts by IRC nickname evaluation. In: Proceedings of USENIX HotBots 2007 (2007)"},{"key":"4_CR18","unstructured":"Karasaridis, A., Rexroad, B., Hoeflin, D.: Wide-scale botnet detection and characterization. In: Proceedings of the 1st Conference on 1st Workshop on Hot Topics in Understanding Botnets, Cambridge, MA (2007)"},{"key":"4_CR19","unstructured":"Binkley, J.R., Singh, S.: An algorithm for anomaly-based botnet detection. In: USENIX SRUTI: 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet (2006)"},{"key":"4_CR20","unstructured":"Gu, G.F., Zhang, J.J., Lee, W.K.: BotSniffer: detecting botnet command and control channels in network traffic. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium, San Diego, CA, February 2008"},{"key":"4_CR21","unstructured":"Gu, G.F., Perdisci, R., Zhang, J.J., Lee, W.K.: BotMiner: clustering analysis of network traffic for protocol- and structure-independent botnet detection. In: Proceedings of the 17th USENIX Security Symposium (Security 2008), San Jose, CA (2008)"},{"key":"4_CR22","unstructured":"Klijnsma, Y.: Large botnet cause of recent Tor network overload. \nhttp:\/\/blog.fox-it.com\/2013\/09\/05\/largebotnet-cause-of-recent-tor-network-overload\/\n\n. Fox-It, 5 September 2013"},{"key":"4_CR23","unstructured":"Clark, K.P., Warnier, M., Brazier, F.M.T.: Botclouds - the future of cloud-based botnets? In: Leymann, F., Ivanov, I., van Sinderen, M.J., Shishkov, B.B. (eds.) Proceedings of the 1st International Conference on Cloud Computing and Services Science (CLOSER 2011), pp. 597\u2013603. Science and Technology Publications (2011)"},{"key":"4_CR24","first-page":"1","volume":"8","author":"M Torkashvan","year":"2015","unstructured":"Torkashvan, M., Haghighi, H.: CBC2 a cloud-based botnet command and control. Ind. J. Sci. Technol. 8, 1\u201315 (2015)","journal-title":"Ind. J. Sci. Technol."}],"container-title":["Lecture Notes in Computer Science","Intelligent, Secure, and Dependable Systems in Distributed and Cloud Environments"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-69155-8_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,10,10]],"date-time":"2017-10-10T05:44:15Z","timestamp":1507614255000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-69155-8_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319691541","9783319691558"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-69155-8_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}