{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,3]],"date-time":"2025-06-03T00:35:11Z","timestamp":1748910911320},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319788159"},{"type":"electronic","value":"9783319788166"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78816-6_14","type":"book-chapter","created":{"date-parts":[[2018,4,23]],"date-time":"2018-04-23T23:02:48Z","timestamp":1524524568000},"page":"182-197","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Hiding Fast Flux Botnet in Plain Email\u00a0Sight"],"prefix":"10.1007","author":[{"given":"Zhi","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meilin","family":"Qin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mengqi","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chunfu","family":"Jia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,4,25]]},"reference":[{"key":"14_CR1","unstructured":"Symantec: internet security threat report for 2016 (2017). \nhttps:\/\/www.symantec.com\/zh\/cn\/security-center\/threat-report?inid=globalnav_scflyout_istr"},{"key":"14_CR2","unstructured":"APWG: global phishing survey for 2016 (2017). \nhttps:\/\/apwg.org\/apwg-news-center\/APWG-News\/"},{"key":"14_CR3","unstructured":"Kaspersky: DDoS attacks in Q2 2017 (2017). \nhttps:\/\/securelist.com\/ddos-attacks-in-q2-2017\/79241\/"},{"key":"14_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"511","DOI":"10.1007\/978-3-642-13708-2_30","volume-title":"Applied Cryptography and Network Security","author":"EJ Kartaltepe","year":"2010","unstructured":"Kartaltepe, E.J., Morales, J.A., Xu, S., Sandhu, R.: Social network-based botnet command-and-control: emerging threats and countermeasures. In: Zhou, J., Yung, M. (eds.) ACNS 2010. LNCS, vol. 6123, pp. 511\u2013528. Springer, Heidelberg (2010). \nhttps:\/\/doi.org\/10.1007\/978-3-642-13708-2_30"},{"key":"14_CR5","doi-asserted-by":"crossref","unstructured":"Yin, T., Zhang, Y., Li, S.: DR-SNBot: a social network-based botnet with strong destroy-resistance. In: IEEE International Conference on Networking, Architecture, and Storage, pp. 191\u2013199 (2014)","DOI":"10.1109\/NAS.2014.37"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"Singh, K., Srivastava, A., Giffin, J., Lee, W.: Evaluating email\u2019s feasibility for botnet command and control. In: IEEE International Conference on Dependable Systems and Networks with Ftcs and DCC, pp. 376\u2013385. IEEE, Anchorage, June 2008","DOI":"10.1109\/DSN.2008.4630106"},{"key":"14_CR7","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Shin, K.G., Hu, X.: Design of SMS commanded-and-controlled and P2P-structured mobile botnets. In: Proceedings of the Fifth ACM Conference on Security and Privacy in Wireless and Mobile Networks, WISEC 2012, pp. 137\u2013148, ACM, New York (2012)","DOI":"10.1145\/2185448.2185467"},{"key":"14_CR8","doi-asserted-by":"crossref","unstructured":"Stone-Gross, B., Cova, M., Cavallaro, L., Gilbert, B., Szydlowski, M., Kemmerer, R., Kruegel, C., Vigna, G.: Your botnet is my botnet: analysis of a botnet takeover. In: ACM Conference on Computer and Communications Security, CCS 2009, Chicago, Illinois, USA, , pp. 635\u2013647, November 2009","DOI":"10.1145\/1653662.1653738"},{"key":"14_CR9","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1016\/j.jnca.2016.08.016","volume":"74","author":"S Iqbal","year":"2016","unstructured":"Iqbal, S., Kiah, M.L.M., Dhaghighi, B., Hussain, M., Khan, S., Khan, M.K., Choo, K.-K.R.: On cloud security attacks: a taxonomy and intrusion detection and prevention as a service. J. Netw. Comput. Appl. 74, 98\u2013120 (2016)","journal-title":"J. Netw. Comput. Appl."},{"key":"14_CR10","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1016\/j.jnca.2016.01.001","volume":"67","author":"O Osanaiye","year":"2016","unstructured":"Osanaiye, O., Choo, K.-K.R., Dlodlo, M.: Distributed denial of service (DDoS) resilience in cloud: review and conceptual cloud ddos mitigation framework. J. Netw. Comput. Appl. 67, 147\u2013165 (2016)","journal-title":"J. Netw. Comput. Appl."},{"key":"14_CR11","unstructured":"Ollmann, G.: Botnet communication topologies. Retrieved September, vol. 30, p. 9 (2009)"},{"key":"14_CR12","unstructured":"Salusky, W., Danford, R.: Know your enemy: fast-flux service networks. Honeynet Proj., pp. 1\u201324 (2007)"},{"key":"14_CR13","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1007\/978-3-319-39207-3_8","volume-title":"Computer Networks","author":"O Pomorova","year":"2016","unstructured":"Pomorova, O., Savenko, O., Lysenko, S., Kryshchuk, A., Bobrovnikova, K.: Anti-evasion technique for the botnets detection based on the passive DNS monitoring and active DNS probing. In: Gaj, P., Kwiecie\u0144, A., Stera, P. (eds.) CN 2016. CCIS, vol. 608, pp. 83\u201395. Springer, Cham (2016). \nhttps:\/\/doi.org\/10.1007\/978-3-319-39207-3_8"},{"key":"14_CR14","first-page":"714","volume":"9","author":"R Perdisci","year":"2012","unstructured":"Perdisci, R., Corona, I., Giacinto, G.: Early detection of malicious flux networks via large-scale passive dns traffic analysis. IEEE Trans. Dependable Secure Comput. 9, 714\u2013726 (2012)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"14_CR15","unstructured":"Porras, P., Di, H., Yegneswaran, V.: A foray into conficker\u2019s logic and Rendezvous points. In: USENIX Conference on Large-Scale Exploits and Emergent Threats: Botnets, Spyware, Worms, and More, p. 7 (2009)"},{"key":"14_CR16","unstructured":"Antonakakis, M., Perdisci, R., Dagon, D., Lee, W., Feamster, N.: Building a dynamic reputation system for DNS. In: Proceedings of the 19th USENIX Conference on Security, USENIX Security 2010, p. 18. USENIX Association, Berkeley (2010)"},{"key":"14_CR17","unstructured":"Bilge, L., Kirda, E., Kruegel, C., Balduzzi, M.: Exposure: Finding malicious domains using passive dns analysis. In: Network and Distributed System Security Symposium, NDSS 2011, San Diego, California, USA, February 2011"},{"key":"14_CR18","unstructured":"Antonakakis, M., Perdisci, R., Lee, W., Nikolaos Vasiloglou, I., Dagon, D.: Detecting malware domains at the upper DNS hierarchy. In: USENIX Conference on Security, p. 27 (2011)"},{"key":"14_CR19","doi-asserted-by":"crossref","unstructured":"Guerid, H., Mittig, K., Serhrouchni, A.: Privacy-preserving domain-flux botnet detection in a large scale network. In: International Conference on Communication Systems and Networks, pp. 1\u20139 (2013)","DOI":"10.1109\/COMSNETS.2013.6465572"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Nguyen, T.-D., CAO, T.-D., Nguyen, L.-G.: DGA botnet detection using collaborative filtering and density-based clustering. In: Proceedings of the Sixth International Symposium on Information and Communication Technology, SoICT 2015, pp. 203\u2013209. ACM, New York (2015)","DOI":"10.1145\/2833258.2833310"},{"issue":"3","key":"14_CR21","doi-asserted-by":"publisher","first-page":"320","DOI":"10.1016\/j.comcom.2012.10.003","volume":"36","author":"Sangho Lee","year":"2013","unstructured":"Lee S., Kim, J.: Fluxing botnet command and control channels with URL shortening services. Elsevier Science Publishers B. V. (2013)","journal-title":"Computer Communications"},{"key":"14_CR22","unstructured":"Antonakakis, M., Perdisci, R., Nadji, Y., Vasiloglou, N., Abu-Nimeh, S., Lee, W., Dagon, D.: From throw-away traffic to bots: detecting the rise of DGA-based malware. In: USENIX Conference on Security Symposium, p. 24 (2011)"},{"issue":"6","key":"14_CR23","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1016\/j.compeleceng.2014.10.010","volume":"41","author":"M Yahyazadeh","year":"2015","unstructured":"Yahyazadeh, M., Abadi, M.: BotGrab: a negative reputation system for botnet detection. Comput. Electr. Eng. 41(6), 68\u201385 (2015)","journal-title":"Comput. Electr. Eng."},{"key":"14_CR24","doi-asserted-by":"crossref","unstructured":"Sharifnya, R., Abadi, M.: A novel reputation system to detect dga-based botnets. In: International Econference on Computer and Knowledge Engineering, pp. 417\u2013423 (2013)","DOI":"10.1109\/ICCKE.2013.6682860"},{"key":"14_CR25","doi-asserted-by":"crossref","unstructured":"Sharif, M., Lanzi, A., Giffin, J., Lee, W.: Automatic reverse engineering of malware emulators. In: 2009 30th IEEE Symposium on Security and Privacy, pp. 94\u2013109, May 2009","DOI":"10.1109\/SP.2009.27"},{"key":"14_CR26","unstructured":"Campbell, S., Chan, S., R. Lee, J.: Detection of fast flux service networks. In: Australasian Information Security Conference, pp. 57\u201366 (2011)"},{"key":"14_CR27","unstructured":"Holz, T., Gorecki, C., Rieck, K., Freiling, F.C.: Measuring and detecting fast-flux service networks. In: Network and Distributed System Security Symposium, NDSS 2008, San Diego, California, USA, pp. 487\u2013492, February 2008"},{"key":"14_CR28","doi-asserted-by":"crossref","unstructured":"Yadav, S., Reddy, A.K.K., Reddy, A.L., Ranjan, S.: Detecting algorithmically generated malicious domain names. In: ACM SIGCOMM Conference on Internet Measurement 2010, Melbourne, Australia, pp. 48\u201361, November 2010","DOI":"10.1145\/1879141.1879148"},{"issue":"5","key":"14_CR29","doi-asserted-by":"publisher","first-page":"1663","DOI":"10.1109\/TNET.2012.2184552","volume":"20","author":"S Yadav","year":"2012","unstructured":"Yadav, S., Reddy, A.K.K., Reddy, A.L.N., Ranjan, S.: Detecting algorithmically generated domain-flux attacks with dns traffic analysis. IEEE\/ACM Trans. Netw. 20(5), 1663\u20131677 (2012)","journal-title":"IEEE\/ACM Trans. Netw."},{"issue":"12","key":"14_CR30","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1016\/j.diin.2014.11.001","volume":"12","author":"R Sharifnya","year":"2015","unstructured":"Sharifnya, R., Abadi, M.: Dfbotkiller: domain-flux botnet detection based on the history of group activities and failures in DNS traffic. Digit. Invest. 12(12), 15\u201326 (2015)","journal-title":"Digit. Invest."},{"key":"14_CR31","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"446","DOI":"10.1007\/978-3-642-31909-9_26","volume-title":"Security and Privacy in Communication Networks","author":"S Yadav","year":"2012","unstructured":"Yadav, S., Reddy, A.L.N.: Winning with DNS failures: strategies for faster botnet detection. In: Rajarajan, M., Piper, F., Wang, H., Kesidis, G. (eds.) SecureComm 2011. LNICST, vol. 96, pp. 446\u2013459. Springer, Heidelberg (2012). \nhttps:\/\/doi.org\/10.1007\/978-3-642-31909-9_26"},{"key":"14_CR32","doi-asserted-by":"crossref","unstructured":"Jiang, N., Cao, J., Jin, Y., Li, L.E., Zhang, Z.L.: Identifying suspicious activities through DNS failure graph analysis. In: The 18th IEEE International Conference on Network Protocols, pp. 144\u2013153, October 2010","DOI":"10.1109\/ICNP.2010.5762763"},{"key":"14_CR33","doi-asserted-by":"crossref","unstructured":"Gavrilut, D.T., Popoiu, G., Benchea, R.: Identifying DGA-based botnets using network anomaly detection. In: 2016 18th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC), pp. 292\u2013299, September 2016","DOI":"10.1109\/SYNASC.2016.053"},{"key":"14_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/978-3-319-08509-8_11","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"S Schiavoni","year":"2014","unstructured":"Schiavoni, S., Maggi, F., Cavallaro, L., Zanero, S.: Phoenix: DGA-based botnet tracking and intelligence. In: Dietrich, S. (ed.) DIMVA 2014. LNCS, vol. 8550, pp. 192\u2013211. Springer, Cham (2014). \nhttps:\/\/doi.org\/10.1007\/978-3-319-08509-8_11"},{"key":"14_CR35","doi-asserted-by":"crossref","unstructured":"Anderson, H.S., Woodbridge, J., Filar, B.: DeepDGA: adversarially-tuned domain generation and detection. In: ACM Workshop on Artificial Intelligence and Security, pp. 13\u201321 (2016)","DOI":"10.1145\/2996758.2996767"},{"key":"14_CR36","doi-asserted-by":"crossref","unstructured":"Golle, P.: Machine learning attacks against the Asirra CAPTCHA. In: ACM Conference on Computer and Communications Security, CCS 2008, Alexandria, Virginia, USA, pp. 535\u2013542, October 2008","DOI":"10.1145\/1455770.1455838"},{"key":"14_CR37","doi-asserted-by":"crossref","unstructured":"Yan, J., El Ahmad, A.S.: A low-cost attack on a microsoft CAPTCHA. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS 2008, pp. 543\u2013554. ACM, New York (2008)","DOI":"10.1145\/1455770.1455839"},{"key":"14_CR38","doi-asserted-by":"crossref","unstructured":"Zhu, B.B., Yan, J., Li, Q., Yang, C., Liu, J., Xu, N., Yi, M., Cai, K.: Attacks and design of image recognition CAPTCHAS. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS 2010, pp. 187\u2013200. ACM, New York (2010)","DOI":"10.1145\/1866307.1866329"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78816-6_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,4,23]],"date-time":"2018-04-23T23:09:51Z","timestamp":1524524991000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-78816-6_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319788159","9783319788166"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78816-6_14","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2018]]}}}