{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T10:10:28Z","timestamp":1725531028059},"publisher-location":"Berlin, Heidelberg","reference-count":44,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642014390"},{"type":"electronic","value":"9783642014406"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-01440-6_27","type":"book-chapter","created":{"date-parts":[[2009,4,28]],"date-time":"2009-04-28T08:45:40Z","timestamp":1240908340000},"page":"348-369","source":"Crossref","is-referenced-by-count":1,"title":["Hardening Botnet by a Rational Botmaster"],"prefix":"10.1007","author":[{"given":"Zonghua","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruo","family":"Ando","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Youki","family":"Kadobayashi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"27_CR1","doi-asserted-by":"crossref","unstructured":"Akiyama, M., Kawamoto, T., Shimamura, M., et al.: A proposal of metrics for botnent detection based on its cooperative behavior. In: Proc.\u00a0of the International Symposium on Applications and Internet Workshops (SAINTW 2007) (2007)","DOI":"10.1109\/SAINT-W.2007.14"},{"key":"27_CR2","unstructured":"Barford, P., Yegneswaran, V.: An inside look at botnets. In: Proc.\u00a0of Special workshop on malware detection, Advances in Information Security (2006)"},{"key":"27_CR3","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology \u2013 EUROCRPYT 2003","author":"M. Bellare","year":"2003","unstructured":"Bellare, M., Micciancio, D., Warinschi, B.: Foundations of Group Signatures: Formal Definitions, Simplified Requirements, and a Construction Based on Gerneral Assumptions. In: Biham, E. (ed.) EUROCRYPT 2003. LNCS, vol.\u00a02656. Springer, Heidelberg (2003)"},{"key":"27_CR4","unstructured":"Bethencourt, J., Franklin, J., Vernon, M.: Mapping Internet Sensors With Probe Response Attacks. In: Proc.\u00a0of USENIX Security Symposium (2005)"},{"key":"27_CR5","doi-asserted-by":"crossref","unstructured":"Borders, K., Zhao, X., Prakash, A.: Siren: catching evasive malware. In: Proc.\u00a0of IEEE Symposium on Security and Privacy (S&P 2006) (2006)","DOI":"10.1109\/SP.2006.37"},{"issue":"4","key":"27_CR6","doi-asserted-by":"publisher","first-page":"824","DOI":"10.1145\/4221.214134","volume":"32","author":"G. Bracha","year":"1985","unstructured":"Bracha, G., Toueg, S.: Asynchronous concensus and broadcast protocols. Journal of the ACM\u00a032(4), 824\u2013840 (1985)","journal-title":"Journal of the ACM"},{"key":"27_CR7","unstructured":"Brumley, D.: Tracking hackers on IRC, http:\/\/www.indonesiajakarta.org\/home\/"},{"key":"27_CR8","unstructured":"Caballero, J., Venkataraman, S., Poosankam, P., et al.: FiG: Automatic Fingerprint Generation. In: Proc.\u00a0of NDSS (Feburary 2007)"},{"key":"27_CR9","doi-asserted-by":"crossref","unstructured":"Cachin, C., Kursawe, K., Shoup, V.: Random Oracles in Constantinople: Practical Asynchronous Byzantine Agreement Using Cryptography. In: Proc.\u00a0of the 19th Annual Symposium on Principles of Distributed Computing (2000)","DOI":"10.1145\/343477.343531"},{"key":"27_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/3-540-46416-6_22","volume-title":"Advances in Cryptology - EUROCRYPT \u201991","author":"D. Chaum","year":"1991","unstructured":"Chaum, D., van Heyst, E.: Group signatures. In: Davies, D.W. (ed.) EUROCRYPT 1991. LNCS, vol.\u00a0547, pp. 257\u2013265. Springer, Heidelberg (1991)"},{"key":"27_CR11","unstructured":"Cooke, E., Jahanian, F., McPherson, D.: The Zombie roundup: understanding, detecting, and disrupting botnets. In: Proc.\u00a0of the Steps to Reducing Unwanted Traffic on the Internet on Steps to Reducing Unwanted Traffic on the Internet (SRUTI 2005) (2005)"},{"key":"27_CR12","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S.A., et al.: Semantics-aware malware detection. In: Proc.\u00a0of IEEE Symposium on Security and Privacy (S&P 2005) (2002)","DOI":"10.1109\/SP.2005.20"},{"key":"27_CR13","unstructured":"Dagon, D., Zou, C.C., Lee, W.: Modeling botnet propagation using time zones. In: Proc.\u00a0of Network and Distributed System Security Symposium(NDSS 2006) (2006)"},{"key":"27_CR14","doi-asserted-by":"crossref","unstructured":"Dagon, D., Gu, G., Lee, C.P., Lee, W.: A taxonomy of botnet structures. In: Proc.\u00a0of the Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007) (December 2007)","DOI":"10.1109\/ACSAC.2007.44"},{"key":"27_CR15","unstructured":"Dagon, D., Provos, N., Christopher, P., Lee, W.: Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority. In: Proc.\u00a0of Network and Distributed System Security Symposium(NDSS 2008) (Feburary 2008)"},{"key":"27_CR16","doi-asserted-by":"crossref","unstructured":"Dutertre, B., Crettaz, V., Stavridou, V.: Intrusion-Tolerant Enclaves. In: Proc.\u00a0of IEEE Symposium on Security and Privacy (S&P 2002) (2002)","DOI":"10.1109\/SECPRI.2002.1004373"},{"key":"27_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/11555827_19","volume-title":"Computer Security \u2013 ESORICS 2005","author":"F.C. Freiling","year":"2005","unstructured":"Freiling, F.C., Holz, T., Wicherski, G.: Botnet tracking: Exploring a root-cause methodology to prevent distributed denial-of-service attacks. In: di Vimercati, S., Syverson, P.F., Gollmann, D. (eds.) ESORICS 2005. LNCS, vol.\u00a03679, pp. 319\u2013335. Springer, Heidelberg (2005)"},{"key":"27_CR18","unstructured":"Friess, N., Aycock, J., Vogt, R.: Black Market Botnets. In: MIT Spam Conference, 2008, pp.\u00a01\u20138 (2008)"},{"issue":"1","key":"27_CR19","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1109\/MC.2005.26","volume":"38","author":"D. Geer","year":"2005","unstructured":"Geer, D.: Malicious bots threaten network security. IEEE Computer\u00a038(1), 18\u201320 (2005)","journal-title":"IEEE Computer"},{"key":"27_CR20","unstructured":"Gu, G., Zhang, J., Lee, W.: BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In: Proc.\u00a0of Network and Distributed System Security Symposium (NDSS 2008) (2008)"},{"key":"27_CR21","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnent Detection. In: Proc.\u00a0of the the USENIX Security Symposium (Security 2008) (August 2008)"},{"key":"27_CR22","unstructured":"Grizzard, J.B., Sharam, V., et al.: Peer-to-Peer Botnets: Overview and Case Study. In: Proc.\u00a0of the First Workshop on HotTopics in Understanding Botnets (HotBots 2007) (April 2007)"},{"key":"27_CR23","unstructured":"Holz, T., Raynal, F.: Defeating Honeypots: System Issues (Part 1,2). SecurityFocus InFocus Article (September 2004)"},{"key":"27_CR24","unstructured":"Holz, T., Gorecki, C., Rieck, K., Freiling, F.: Measuring and Detecting Fast-Flux Service Networks. In: Proc.\u00a0 of the 2008 Network and Distributed System Security Symposium (NDSS 2008) (Feburary 2008)"},{"key":"27_CR25","unstructured":"http:\/\/www.uscert.gov\/reading_room\/IPv6Malware-Tunneling.pdf"},{"key":"27_CR26","unstructured":"Kruegel, C., Kirda, E., Mutz, D., et al.: Automating mimicry attacks using static binary analysis. In: Proc.\u00a0of the 14th USENIX Security Symposium (2005)"},{"issue":"1","key":"27_CR27","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSECP.2004.1264861","volume":"2","author":"N. Krawetz","year":"2004","unstructured":"Krawetz, N.: Anti-Honeypot Technology. IEEE Security& Privacy Magazine\u00a02(1), 76\u201379 (2004)","journal-title":"IEEE Security& Privacy Magazine"},{"issue":"1","key":"27_CR28","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1145\/242857.242869","volume":"40","author":"C. Nachenberg","year":"1997","unstructured":"Nachenberg, C.: Computer virus-antivirus coevolution. Communiations of the ACM\u00a040(1), 46\u201351 (1997)","journal-title":"Communiations of the ACM"},{"key":"27_CR29","unstructured":"Newsome, J., Karp, B., Song, D.: Polygraph: Automatic Signature Generation for Polymorphic Worms. In: Proc.of IEEE Symposium on Security and Privacy (S&P 2005) (May 2005)"},{"key":"27_CR30","unstructured":"Oudot, L., Holz, T.: Defeating Honeypots: Network Issues (Part 1, 2). SecurityFocus InFocus Article (September\u00a02004)"},{"key":"27_CR31","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Dagon, D., Lee, W., et al.: Misleading worm signature generator using deliberate noise ijnection. In: Proc.\u00a0of IEEE Symposium on Security and Privacy (S&P 2006) (May 2006)","DOI":"10.1109\/SP.2006.26"},{"key":"27_CR32","unstructured":"Puri, R.: Bots &botnet: an overview (September 2004), http:\/\/www.sans.org\/reading_room\/whitepapers\/malicious\/1299.php"},{"key":"27_CR33","doi-asserted-by":"crossref","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A Multifaceted Approach to Understanding the Botnet Phenomenon. In: Proc.\u00a0of ACM SIGCOMM conference on Internet measurement (IMC 2006), pp. 41\u201352 (October 2006)","DOI":"10.1145\/1177080.1177086"},{"key":"27_CR34","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: My Botnet Is Bigger Than Yours (Maybe, Better Than Yours): Why Size Estimates Remain Challenging. In: Proc.\u00a0of Workshop on HotTopics in Understanding Botnets (HotBots 2007) (April 2007)"},{"key":"27_CR35","unstructured":"Shinoda, Y., Ikai, K., Itoh, M.: Vulnerabilities of Passive Internet Threat Monitors. In: Proc. of USENIX Security Symposium, pp. 209\u2013224 (August 2005)"},{"key":"27_CR36","unstructured":"Spitzner, L.: Honeypots: Are They Illegal? SecurityFocus InFocus Article (June 2003)"},{"key":"27_CR37","unstructured":"Internet Storm Center (ISC), http:\/\/isc.sans.org\/"},{"key":"27_CR38","unstructured":"CAIDA Telescope analysis, http:\/\/www.caida.org\/analysis\/security\/telescope\/"},{"key":"27_CR39","unstructured":"Vogt, R., Aycock, J., Jacobson Jr., M.J.: Army of Botnets. In: Proc.\u00a0of the 2007 Network and Distributed System Security Symposium (NDSS 2007) (2007)"},{"key":"27_CR40","unstructured":"Wang, P., Sparks, S., Zou, C.C.: An advanced hybrid peer-to-peer botnet. In: Proc.\u00a0of the First Workshop on HotTopics in Understanding Botnets (HotBots 2007) (2007)"},{"key":"27_CR41","doi-asserted-by":"crossref","unstructured":"Xie, Y., Yu, F., Achan, K., et al.: Spamming Botnet: Signatures and Characteristics. In: Proc.\u00a0of SIGCOMM 2008 (August 2008)","DOI":"10.1145\/1402958.1402979"},{"key":"27_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/978-3-540-70542-0_11","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"T.-F. Yen","year":"2008","unstructured":"Yen, T.-F., Reiter, M.K.: Traffic aggregation for malware detection. In: Zamboni, D. (ed.) DIMVA 2008. LNCS, vol.\u00a05137, pp. 207\u2013227. Springer, Heidelberg (2008)"},{"issue":"2","key":"27_CR43","first-page":"135","volume":"4","author":"Z. Zhang","year":"2007","unstructured":"Zhang, Z., Shen, H., Sang, Y.: A Brief Observation-Centric Analysis on Anomaly-based Intrusion Detection. International Journal of Network Security\u00a04(2), 135\u2013148 (2007)","journal-title":"International Journal of Network Security"},{"key":"27_CR44","doi-asserted-by":"crossref","unstructured":"Zou, C.C., Cunnigham, R.: Honeypot-aware advanced botnet construction and maintenance. In: Proc.\u00a0of Int.\u00a0Conf.\u00a0on Dependable Systems and Networks (DSN 2006) (2006)","DOI":"10.1109\/DSN.2006.38"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-01440-6_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,17]],"date-time":"2020-05-17T16:09:00Z","timestamp":1589731740000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-01440-6_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642014390","9783642014406"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-01440-6_27","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2009]]}}}