{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T21:44:31Z","timestamp":1765057471443},"publisher-location":"Berlin, Heidelberg","reference-count":32,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540705413"},{"type":"electronic","value":"9783540705420"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-70542-0_10","type":"book-chapter","created":{"date-parts":[[2008,8,12]],"date-time":"2008-08-12T16:07:43Z","timestamp":1218557263000},"page":"186-206","source":"Crossref","is-referenced-by-count":63,"title":["FluXOR: Detecting and Monitoring Fast-Flux Service Networks"],"prefix":"10.1007","author":[{"given":"Emanuele","family":"Passerini","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roberto","family":"Paleari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenzo","family":"Martignoni","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Danilo","family":"Bruschi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"10_CR1","first-page":"375","volume-title":"Proceedings of the 14th ACM conference on Computer and communications security (CCS 2007)","author":"J. Franklin","year":"2007","unstructured":"Franklin, J., Perrig, A., Paxson, V., Savage, S.: An inquiry into the nature and causes of the wealth of internet miscreants. In: Proceedings of the 14th ACM conference on Computer and communications security (CCS 2007), pp. 375\u2013388. ACM, New York (2007)"},{"key":"10_CR2","volume-title":"The Art of Computer Virus Research and Defense","author":"P. Sz\u00f6r","year":"2005","unstructured":"Sz\u00f6r, P.: The Art of Computer Virus Research and Defense. Addison Wesley Professional, Reading (2005)"},{"key":"10_CR3","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: My Botnet is Bigger than Yours (Maybe, Better than Yours): Why Size Estimates Remain Challenging. In: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets (HotBots 2007), Berkeley, CA, USA. USENIX Association (2007)"},{"key":"10_CR4","unstructured":"Furst, M.: Expert: Botnets No. 1 Emerging Internet Threat. CNN Technology (2006)"},{"key":"10_CR5","unstructured":"Markoff, J.: Attack of the Zombie Computers Is a Growing Threat, Experts Say. The New York Times (January 2007)"},{"key":"10_CR6","unstructured":"Corporation, F.S.: Malware Information Pages: Warezov (2006), http:\/\/www.f-secure.com\/v-descs\/warezov.shtml"},{"key":"10_CR7","unstructured":"Porras, P., Saidi, H., Yegneswaran, V.: A Multi-perspective Analysis of the Storm (Peacomm) Worm. Technical report, SRI International (October 2007)"},{"key":"10_CR8","unstructured":"The Honeynet Project & Research Alliance: Know Your Enemy: Fast-Flux Service Networks (2007)"},{"key":"10_CR9","unstructured":"Gaudin, S.: Storm Worm Erupts Into Worst Virus Attack In 2 Years (2007)"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Dagon, D., Gu, G., Lee, C., Lee, W.: A taxonomy of botnet structures. In: Proceedings of the 23 Annual Computer Security Applications Conference (ACSAC 2007) (December 2007)","DOI":"10.1109\/ACSAC.2007.44"},{"key":"10_CR11","unstructured":"Goebel, J., Holz, T.: Rishi: identify bot contaminated hosts by irc nickname evaluation. In: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets (HotBots 2007), Berkeley, CA, USA. USENIX Association (2007)"},{"key":"10_CR12","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: BotHunter: Detecting malware infection through ids-driven dialog correlation. In: Proceedings of the 16th USENIX Security Symposium (Security 2007) (August 2007)"},{"key":"10_CR13","unstructured":"Karasaridis, A., Rexroad, B., Hoeflin, D.: Wide-scale botnet detection and characterization. In: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets (HotBots 2007), Berkeley, CA, USA. USENIX Association (2007)"},{"key":"10_CR14","unstructured":"Dagon, D., Zou, C., Lee, W.: Modeling botnet propagation using time zones. In: Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS 2006) (2006)"},{"key":"10_CR15","unstructured":"Ramachandran, A., Feamster, N., Dagon, D.: Revealing botnet membership using dnsbl counter-intelligence. In: Proceedings of the 2nd conference on Steps to Reducing Unwanted Traffic on the Internet (SRUTI 2006), Berkeley, CA, USA. USENIX Association (2006)"},{"key":"10_CR16","unstructured":"Cooke, E., Jahanian, F., Mcpherson, D.: The Zombie Roundup: Understanding, Detecting, and Disrupting Botnets. In: Workshop on Steps to Reducing Unwanted Traffic on the Internet (SRUTI), pp. 39\u201344 (June 2005)"},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"Mockapetris, P.: Domain names \u2013 concepts and facilites. RFC 1034, Internet Engineering Task Force (November 1987)","DOI":"10.17487\/rfc1034"},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"Mockapetris, P.: Domain names \u2013 implementation and specification. RFC 1035, Internet Engineering Task Force (November 1987)","DOI":"10.17487\/rfc1035"},{"key":"10_CR19","unstructured":"Kojm, T.: Clam AntiVirus, http:\/\/www.clamav.net"},{"key":"10_CR20","first-page":"338","volume-title":"Proceedings of the 11th Conference on Uncertainty in Artificial Intelligence","author":"G.H. John","year":"1995","unstructured":"John, G.H., Langley, P.: Estimating continuous distributions in Bayesian classifiers. In: Proceedings of the 11th Conference on Uncertainty in Artificial Intelligence, pp. 338\u2013345. Morgan Kaufmann, San Francisco (1995)"},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"Hawkinson, J., Bates, T.: Guidelines for creation, selection, and registration of an autonomous system (as). RFC 1930, Internet Engineering Task Force (March 1996)","DOI":"10.17487\/rfc1930"},{"key":"10_CR22","unstructured":"DomainTools.com: Domain Counts & Internet Statistics, http:\/\/www.domaintools.com\/internet-statistics\/"},{"key":"10_CR23","volume-title":"Proceedings of the Seventeenth International Florida Artificial Intelligence Research Society Conference","author":"H. Zhang","year":"2004","unstructured":"Zhang, H.: The Optimality of Na\u00efve Bayes. In: Proceedings of the Seventeenth International Florida Artificial Intelligence Research Society Conference. AAAI Press, Miami Beach (2004)"},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"Daigle, L.: WHOIS protocol specification. RFC 3912, Internet Engineering Task Force (March 2004)","DOI":"10.17487\/rfc3912"},{"key":"10_CR25","volume-title":"Data Mining: Practical machine learning tools and techniques","author":"I.H. Witten","year":"2005","unstructured":"Witten, I.H., Frank, E.: Data Mining: Practical machine learning tools and techniques, 2nd edn. Morgan Kaufmann, San Francisco (2005)","edition":"2"},{"key":"10_CR26","first-page":"1137","volume-title":"Proceedings of the Fourteenth International Joint Conference on Artificial Intelligence","author":"R. Kohavi","year":"1995","unstructured":"Kohavi, R.: A Study of Cross-Validation and Bootstrap for Accuracy Estimation and Model Selection. In: Proceedings of the Fourteenth International Joint Conference on Artificial Intelligence, pp. 1137\u20131145. Morgan Kaufmann, San Francisco (1995)"},{"key":"10_CR27","unstructured":"Holz, T., Gorecki, C., Freiling, F., Rieck, K.: Detection and Mitigation of Fast-Flux Service Networks. In: Proceeding of the 15th Annual Network & Distributed System Security Symposium (NDSS 2008) (February 2008)"},{"key":"10_CR28","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1145\/1177080.1177086","volume-title":"Proceedings of the 6th ACM SIGCOMM conference on Internet measurement (IMC 2006)","author":"M.A. Rajab","year":"2006","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: Proceedings of the 6th ACM SIGCOMM conference on Internet measurement (IMC 2006), pp. 41\u201352. ACM, New York (2006)"},{"key":"10_CR29","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/978-3-540-73614-1_6","volume-title":"Proceedings of the Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","author":"E. Stinson","year":"2007","unstructured":"Stinson, E., Mitchell, J.C.: Characterizing Bots\u2019 Remote Control Behavior. In: Proceedings of the Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 89\u2013108. Springer, Heidelberg (2007)"},{"key":"10_CR30","series-title":"Advances in Information Security","volume-title":"Malware Detection","author":"B. Paul","year":"2007","unstructured":"Paul, B., Vinod, Y.: An Inside Look at Botnets. In: Malware Detection. Advances in Information Security, vol.\u00a027. Springer, Heidelberg (2007)"},{"key":"10_CR31","unstructured":"Chiang, K., Lloyd, L.: A case study of the rustock rootkit and spam bot. In: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets (HotBots 2007), Berkeley, CA, USA. USENIX Association (2007)"},{"key":"10_CR32","unstructured":"Daswani, N., Stoppelman, M.: The anatomy of clickbot.a. In: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets (HotBots 2007), Berkeley, CA, USA. USENIX Association (2007)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-70542-0_10.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T05:07:30Z","timestamp":1605762450000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-70542-0_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540705413","9783540705420"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-70542-0_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[]}}