{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T21:07:03Z","timestamp":1768424823937,"version":"3.49.0"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319712451","type":"print"},{"value":"9783319712468","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-71246-8_5","type":"book-chapter","created":{"date-parts":[[2017,12,29]],"date-time":"2017-12-29T09:03:20Z","timestamp":1514538200000},"page":"73-88","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["Malware Detection by Analysing Encrypted Network Traffic with Neural Networks"],"prefix":"10.1007","author":[{"given":"Paul","family":"Prasse","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luk\u00e1\u0161","family":"Machlica","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tom\u00e1\u0161","family":"Pevn\u00fd","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ji\u0159\u00ed","family":"Havelka","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tobias","family":"Scheffer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,12,30]]},"reference":[{"key":"5_CR1","unstructured":"Kogan, R.: Bedep trojan malware spread by the angler exploit kit gets political. SpiderLabs Blog (2015). https:\/\/www.trustwave.com\/Resources\/SpiderLabs-Blog\/Bedep-trojan-malware-spread-by-the-Angler-exploit-kit-gets-political\/"},{"key":"5_CR2","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/s11416-005-0002-9","volume":"1","author":"ME Karim","year":"2005","unstructured":"Karim, M.E., Walenstein, A., Lakhotia, A., Parida, L.: Malware phylogeny generation using permutations of code. J. Comput. Virol. 1, 13\u201323 (2005)","journal-title":"J. Comput. Virol."},{"key":"5_CR3","unstructured":"Gu, G., Zhang, J., Lee, W.: BotSniffer: detecting botnet command and control channels in network traffic. In: Proceedings of the Annual Network and Distributed System Security Symposium (2008)"},{"key":"5_CR4","unstructured":"Perdisci, R., Lee, W., Feamster, N.: Behavioral clustering of HTTP-based malware and signature generation using malicious network traces. In: Proceedings of the USENIX Conference on Networked Systems Design and Implementation (2010)"},{"key":"5_CR5","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1007\/978-3-319-23461-8_8","volume-title":"Machine Learning and Knowledge Discovery in Databases","author":"K Bartos","year":"2015","unstructured":"Bartos, K., Sofka, M.: Robust representation for domain adaptation in network security. In: Bifet, A., May, M., Zadrozny, B., Gavalda, R., Pedreschi, D., Bonchi, F., Cardoso, J., Spiliopoulou, M. (eds.) ECML PKDD 2015. LNCS (LNAI), vol. 9286, pp. 116\u2013132. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-23461-8_8"},{"key":"5_CR6","unstructured":"Aas, J.: Progress towards 100% HTTPS. Let\u2019s Encrypt (2016)"},{"key":"5_CR7","first-page":"1137","volume":"3","author":"Y Bengio","year":"2003","unstructured":"Bengio, Y., Ducharme, R., Vincent, P., Jauvin, C.: A neural probabilistic language model. J. Mach. Learn. Res. 3, 1137\u20131155 (2003)","journal-title":"J. Mach. Learn. Res."},{"key":"5_CR8","doi-asserted-by":"publisher","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter, S., Schmidhuber, J.: Long short-term memory. Neural Comput. 9, 1735\u20131780 (1997)","journal-title":"Neural Comput."},{"key":"5_CR9","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1109\/SURV.2008.080406","volume":"10","author":"T Nguyen","year":"2008","unstructured":"Nguyen, T., Armitage, G.: A survey of techniques for internet traffic classification using machine learning. IEEE Commun. Surv. Tutor. 10, 56\u201376 (2008)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"5_CR10","unstructured":"Nelms, T., Perdisci, R., Ahamad, M.: ExecScent: mining for new C&C domains in live networks with adaptive control protocol templates. In: Proceedings of the USENIX Security Symposium (2013)"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Kohout, J., Pevny, T.: Unsupervised detection of malware in persistent web traffic. In: Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing (2015)","DOI":"10.1109\/ICASSP.2015.7178272"},{"key":"5_CR12","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1007\/978-3-319-23461-8_6","volume-title":"Machine Learning and Knowledge Discovery in Databases","author":"V Franc","year":"2015","unstructured":"Franc, V., Sofka, M., Bartos, K.: Learning detector of malicious network traffic from weak labels. In: Bifet, A., May, M., Zadrozny, B., Gavalda, R., Pedreschi, D., Bonchi, F., Cardoso, J., Spiliopoulou, M. (eds.) ECML PKDD 2015. LNCS (LNAI), vol. 9286, pp. 85\u201399. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-23461-8_6"},{"key":"5_CR13","first-page":"2745","volume":"7","author":"CV Wright","year":"2006","unstructured":"Wright, C.V., Monrose, F., Masson, G.M.: On inferring application protocol behaviors in encrypted network traffic. J. Mach. Learn. Res. 7, 2745\u20132769 (2006)","journal-title":"J. Mach. Learn. Res."},{"key":"5_CR14","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1145\/1198255.1198257","volume":"37","author":"M Crotti","year":"2007","unstructured":"Crotti, M., Dusi, M., Gringoli, F., Salgarelli, L.: Traffic classification through simple statistical fingerprinting. ACM SIGCOMM Comput. Commun. Rev. 37, 5\u201316 (2007)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"5_CR15","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1016\/j.comnet.2008.09.010","volume":"53","author":"M Dusi","year":"2009","unstructured":"Dusi, M., Crotti, M., Gringoli, F., Salgarelli, L.: Tunnel hunter: detecting application-layer tunnels with statistical fingerprinting. Comput. Netw. 53, 81\u201397 (2009)","journal-title":"Comput. Netw."},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Kohout, J., Pevny, T.: Automatic discovery of web servers hosting similar applications. In: Proceedings of the IFIP\/IEEE International Symposium on Integrated Network Management (2015)","DOI":"10.1109\/INM.2015.7140487"},{"key":"5_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/978-3-319-31863-9_10","volume-title":"Intelligence and Security Informatics","author":"J Loko\u010d","year":"2016","unstructured":"Loko\u010d, J., Kohout, J., \u010cech, P., Skopal, T., Pevn\u00fd, T.: k-NN classification of malware in HTTPS traffic using the metric space approach. In: Chau, M., Wang, G.A., Chen, H. (eds.) PAISI 2016. LNCS, vol. 9650, pp. 131\u2013145. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-31863-9_10"},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"Pevny, T., Somol, P.: Discriminative models for multi-instance problems with tree structure. In: Proceedings of the International Workshop on Artificial Intelligence for Computer Security (2016)","DOI":"10.1145\/2996758.2996761"},{"key":"5_CR19","unstructured":"Prasse, P., Gruben, G., Machlika, L., Pevny, T., Sofka, M., Scheffer, T.: Malware detection by HTTPS traffic analysis. Technical report. urn: urn:nbn:de:kobv:517-opus4-100942 (2017)"},{"key":"5_CR20","doi-asserted-by":"crossref","unstructured":"Prasse, P., Machlica, L., Pevn\u00fd, T., Havelka, J., Scheffer, T.: Malware detection by analysing network traffic with neural networks. In: Proceedings of the Workshop on Traffic Measurements for Cybersecurity at the IEEE Symposium on Security and Privacy (2017)","DOI":"10.1109\/SPW.2017.8"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Staudemeyer, R., Omlin, C.: Evaluating performance of long short-term memory recurrent neural networks on intrusion detection data. In: Proceedings of the South African Institute for Computer Scientists and Information Technologists Conference (2013)","DOI":"10.1145\/2513456.2513490"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"Claise, B., Trammell, B., Aitken, P.: Specification of the IP flow information export (IPFIX) protocol for the exchange of flow information (2013). https:\/\/tools.ietf.org\/html\/rfc7011","DOI":"10.17487\/rfc7015"},{"key":"5_CR23","unstructured":"Cisco Systems: Cisco IOS NetFlow (2016). http:\/\/www.cisco.com\/c\/en\/us\/products\/ios-nx-os-software\/ios-netflow\/index.html"},{"key":"5_CR24","unstructured":"Blum, S.B., Lueker, J.: Transparent proxy server. US Patent 6,182,141 (2001)"},{"key":"5_CR25","unstructured":"Weimer, F.: Passive DNS replication. In: Proceedings of the FIRST Conference on Computer Security Incidents, p. 98 (2005)"},{"key":"5_CR26","unstructured":"Mikolov, T., Sutskever, I., Chen, K., Corrado, G., Dean, J.: Distributed representations of words and phrases and their compositionality. In: Advances in Neural Information Processing Systems (2013)"}],"container-title":["Lecture Notes in Computer Science","Machine Learning and Knowledge Discovery in Databases"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-71246-8_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,29]],"date-time":"2022-12-29T01:07:53Z","timestamp":1672276073000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-71246-8_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319712451","9783319712468"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-71246-8_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"30 December 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Skopje","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Macedonia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 September 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ecmlpkdd2017.ijs.si\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}