{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T14:19:13Z","timestamp":1761401953154},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319788128"},{"type":"electronic","value":"9783319788135"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78813-5_20","type":"book-chapter","created":{"date-parts":[[2018,4,10]],"date-time":"2018-04-10T10:03:21Z","timestamp":1523354601000},"page":"397-417","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Understanding Adversarial Strategies from Bot Recruitment to Scheduling"],"prefix":"10.1007","author":[{"given":"Wentao","family":"Chang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aziz","family":"Mohaisen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"An","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Songqing","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,4,11]]},"reference":[{"key":"20_CR1","unstructured":"Wikipedia: Hacktivism (2014). http:\/\/bit.ly\/1kM2Vos"},{"key":"20_CR2","unstructured":"Wikipedia: Operation Israel (2014). http:\/\/bit.ly\/1noDUlI"},{"key":"20_CR3","unstructured":"Symantec Security Response: Four years of darkseoul cyberattacks against South Korea continue on anniversary of Korean war, June 2013. http:\/\/bit.ly\/1fbGlFm"},{"key":"20_CR4","unstructured":"Bank Info Security: Opusa threatens banks, government, May 2013. http:\/\/bit.ly\/1kP3Urt"},{"key":"20_CR5","unstructured":"McDougall, P.: Microsoft: Kelihos ring sold \u2018botnet-as-a-service\u2019, September 2011. http:\/\/ubm.io\/MtCSr7"},{"key":"20_CR6","unstructured":"Vicario, M.: Four ways cybercriminals profit from botnets, November 2010. http:\/\/bit.ly\/1e1SIiP"},{"key":"20_CR7","unstructured":"Wang, A., Mohaisen, A., Chang, W., Chen, S.: Delving into internet DDoS attacks by botnets. In: IEEE DSN 2015 (2015)"},{"key":"20_CR8","unstructured":"Ioannidis, J., Bellovin, S.: Implementing pushback: router-based defense against DDoS attacks (2002)"},{"key":"20_CR9","unstructured":"Chen, Y., Kwok, Y., Hwang, K.: MAFIC: adaptive packet dropping for cutting malicious flows to push back DDoS attacks. In: ICDCS 2005 (2005)"},{"key":"20_CR10","doi-asserted-by":"crossref","unstructured":"Kang, M., Gligor, V.D.: Routing bottlenecks in the internet: causes, exploits, and countermeasures. In: Proceedings of ACM SIGSAC 2014 (2014)","DOI":"10.1145\/2660267.2660299"},{"key":"20_CR11","unstructured":"Wikipedia: Carna botnet (2014). http:\/\/bit.ly\/1slx1E6"},{"key":"20_CR12","unstructured":"Starr, M.: Fridge caught sending spam emails in botnet attack (2014). http:\/\/bit.ly\/1j5Jac1"},{"key":"20_CR13","doi-asserted-by":"crossref","unstructured":"Thomas, M., Mohaisen, A.: Kindred domains: detecting and clustering botnet domains using DNS traffic. In: Proceedings of WWW 2014 (2014)","DOI":"10.1145\/2567948.2579359"},{"key":"20_CR14","unstructured":"Andrade, M., Vlajic, N.: Dirt jumper: a key player in today\u2019s botnet-for-DDoS market. In: WorldCIS 2012 (2012)"},{"issue":"2","key":"20_CR15","doi-asserted-by":"crossref","first-page":"347","DOI":"10.1016\/j.physa.2010.10.001","volume":"390","author":"L Song","year":"2011","unstructured":"Song, L., Jin, Z., Sun, G.: Modeling and analyzing of botnet interactions. Proc. Phys. A 390(2), 347\u2013358 (2011)","journal-title":"Proc. Phys. A"},{"issue":"1","key":"20_CR16","first-page":"175","volume":"6","author":"Z Li","year":"2011","unstructured":"Li, Z., Goyal, A., Chen, Y., Paxson, V.: Towards situational awareness of large-scale botnet probing events. IEEE TIFS 6(1), 175\u2013188 (2011)","journal-title":"IEEE TIFS"},{"key":"20_CR17","doi-asserted-by":"crossref","unstructured":"Wang, P., Sparks, S., Zou, C.: An advanced hybrid peer-to-peer botnet. TDSC (2010)","DOI":"10.1007\/978-3-642-04117-4_18"},{"key":"20_CR18","unstructured":"Cho, C., Caballero, J., Grier, C., Paxson, V., Song, D.: Insights from the inside: a view of botnet management from infiltration. LEET (2010)"},{"key":"20_CR19","doi-asserted-by":"crossref","unstructured":"Binsalleeh, H., Ormerod, T., Boukhtouta, A., Sinha, P., Youssef, A., Debbabi, M., Wang, L.: On the analysis of the Zeus botnet crimeware toolkit. In: IEEE PST 2010 (2010)","DOI":"10.1109\/PST.2010.5593240"},{"key":"20_CR20","doi-asserted-by":"crossref","unstructured":"Caballero, J., Poosankam, P., Kreibich, C., Song, D.: Dispatcher: enabling active botnet infiltration using automatic protocol reverse-engineering. In: Proceedings of ACM CCS 2009 (2009)","DOI":"10.1145\/1653662.1653737"},{"key":"20_CR21","doi-asserted-by":"crossref","unstructured":"Lee, C.P., Dagon, D., Gu, G., Lee, W.: A taxonomy of botnet structures. In: Proceedings of ACM ACSCA 2007 (2007)","DOI":"10.1109\/ACSAC.2007.4413000"},{"key":"20_CR22","doi-asserted-by":"crossref","unstructured":"Jing, L., Yang, X., Kaveh, G., Hongmei, D.: Botnet: classification, attacks, detection, tracing, and preventive measures. JWCN (2009)","DOI":"10.1155\/2009\/692654"},{"key":"20_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1007\/978-3-319-08509-8_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Mohaisen","year":"2014","unstructured":"Mohaisen, A., Alrawi, O.: AV-Meter: an evaluation of antivirus scans and labels. In: Dietrich, S. (ed.) DIMVA 2014. LNCS, vol. 8550, pp. 112\u2013131. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-08509-8_7"},{"key":"20_CR24","doi-asserted-by":"crossref","unstructured":"Stone-Gross, B., Cova, M., Cavallaro, L., Gilbert, B., Szydlowski, M., Kemmerer, R., Kruegel, C., Vigna, G.: Your botnet is my botnet: analysis of a botnet takeover. In: Proceedings of ACM CCS 2009 (2009)","DOI":"10.1145\/1653662.1653738"},{"key":"20_CR25","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W., et al.: Botminer: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: Proceedings of USENIX Security 2008 (2008)"},{"key":"20_CR26","unstructured":"Digital Envoy: Digital element services. http:\/\/www.digitalenvoy.net\/"},{"key":"20_CR27","doi-asserted-by":"crossref","unstructured":"Xie, Y., Yu, F., Achan, K., Panigrahy, R., Hulten, G., Osipkov, I.: Spamming botnets: signatures and characteristics. In: SIGCOMM 2008 (2008)","DOI":"10.1145\/1402958.1402979"},{"key":"20_CR28","doi-asserted-by":"crossref","unstructured":"Maertens, M., Asghari, H., van Eeten, M., van Mieghem, P.: A time-dependent SIS-model for long-term computer worm evolution. In: Proceedings of IEEE CNS 2016 (2016)","DOI":"10.1109\/CNS.2016.7860487"},{"key":"20_CR29","unstructured":"Rajab, M., Zarfoss, J., Monrose, F., Terzis, A.: My botnet is bigger than yours (maybe, better than yours): why size estimates remain challenging. In: Proceedings of USENIX HotBots 2007 (2007)"},{"issue":"4","key":"20_CR30","doi-asserted-by":"publisher","first-page":"301","DOI":"10.1145\/1282427.1282415","volume":"37","author":"Yinglian Xie","year":"2007","unstructured":"Xie, Y., Yu, F., Achan, K., Gillum, E., Goldszmidt, M., Wobber, T.: How dynamic are IP addresses? In: ACM SIGCOMM CCR 2007 (2007)","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"20_CR31","unstructured":"Caballero, J., Grier, C., Kreibich, C., Paxson, V.: Measuring pay-per-install: the commoditization of malware distribution. In: Proceedings of USENIX Security 2011 (2011)"},{"key":"20_CR32","unstructured":"Bacher, P., Holz, T., Kotter, M., Wicherski, G.: Know your enemy: tracking botnets (2005)"},{"key":"20_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/11856214_9","volume-title":"Recent Advances in Intrusion Detection","author":"P Baecher","year":"2006","unstructured":"Baecher, P., Koetter, M., Holz, T., Dornseif, M., Freiling, F.: The nepenthes platform: an efficient approach to collect malware. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol. 4219, pp. 165\u2013184. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11856214_9"},{"key":"20_CR34","doi-asserted-by":"crossref","unstructured":"Abu Rajab, M., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: IMC 2006 (2006)","DOI":"10.1145\/1177080.1177086"},{"key":"20_CR35","unstructured":"Karasaridis, A., Rexroad, B., Hoeflin, D.: Wide-scale botnet detection and characterization. In: Proceedings of USENIX HotBots 2007 (2007)"},{"key":"20_CR36","doi-asserted-by":"publisher","unstructured":"Barford, P., Yegneswaran, V.: An inside look at botnets. In: Christodorescu, M., Jha, S., Maughan, D., Song, D., Wang, C. (eds.) Proceedings of Malware Detection. ADIS, vol. 27, pp. 171\u2013191. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-0-387-44599-1_8","DOI":"10.1007\/978-0-387-44599-1_8"},{"key":"20_CR37","unstructured":"Holz, T., Steiner, M., Dahl, F., Biersack, E., Freiling, F.C.: Measurements and mitigation of peer-to-peer-based botnets: a case study on storm worm. In: USENIX LEET 2008 (2008)"},{"key":"20_CR38","doi-asserted-by":"crossref","unstructured":"Shin, S., Gu, G.: Conficker and beyond: a large-scale empirical study. In: Proceedings of ACM ACSAC 2010 (2010)","DOI":"10.1145\/1920261.1920285"},{"key":"20_CR39","doi-asserted-by":"crossref","unstructured":"Chang, W., Mohaisen, A., Wang, A., Chen, S.: Measuring botnets in the wild: some new trends. In: ACM ASIACCS 2015 (2015)","DOI":"10.1145\/2714576.2714637"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78813-5_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,5]],"date-time":"2024-07-05T21:44:32Z","timestamp":1720215872000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-78813-5_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319788128","9783319788135"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78813-5_20","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2018]]}}}