{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T12:20:54Z","timestamp":1725538854018},"publisher-location":"Berlin, Heidelberg","reference-count":44,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642052835"},{"type":"electronic","value":"9783642052842"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-05284-2_11","type":"book-chapter","created":{"date-parts":[[2009,10,13]],"date-time":"2009-10-13T08:06:00Z","timestamp":1255421160000},"page":"185-206","source":"Crossref","is-referenced-by-count":16,"title":["Using Failure Information Analysis to Detect Enterprise Zombies"],"prefix":"10.1007","author":[{"given":"Zhaosheng","family":"Zhu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"11_CR1","unstructured":"Data clustering, http:\/\/www.let.rug.nl\/~kleiweg\/clustering\/"},{"key":"11_CR2","unstructured":"Entropy, http:\/\/en.wikipedia.org\/wiki\/Information_entropy"},{"key":"11_CR3","unstructured":"Gnu wget, http:\/\/www.gnu.org\/software\/wget\/"},{"key":"11_CR4","unstructured":"Kademlia, http:\/\/en.wikipedia.org\/wiki\/Kademlia"},{"key":"11_CR5","unstructured":"L7-filter: Application Layer Packet Classifier for Linux, http:\/\/l7-filter.sourceforge.net\/"},{"key":"11_CR6","unstructured":"Offensive Computing, Community Malicious code research and analysis, http:\/\/www.offensivecomputing.net\/"},{"key":"11_CR7","unstructured":"Simple Exponential Smoothing, http:\/\/en.wikipedia.org\/wiki\/Exponential_smoothing"},{"key":"11_CR8","unstructured":"Wireshark: The World\u2019s Most Popular Network Protocol Analyzer, http:\/\/www.wireshark.org\/"},{"key":"11_CR9","unstructured":"WEKA-Machine Learning Software in Java (2008), http:\/\/weka.wiki.sourceforge.net\/Primer-?token=2b7a093d07966047b281eeec0da1b9fd"},{"key":"11_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1007\/978-3-540-74320-0_10","volume-title":"Recent Advances in Intrusion Detection","author":"M. Bailey","year":"2007","unstructured":"Bailey, M., Oberheide, J., Andersen, J., Mao, Z.M., Jahanian, F., Nazario, J.: Automated classification and analysis of internet malware. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol.\u00a04637, pp. 178\u2013197. Springer, Heidelberg (2007)"},{"key":"11_CR11","unstructured":"Bayer, U., Comparetti, P.M., Hlauscheck, C., Kruegel, C., Kirda, E.: Scalable, behavior-based malware clustering. In: Network and Distributed System Security Symposium, NDSS (2009)"},{"key":"11_CR12","unstructured":"Dagon, D., Zou, C., Lee, W.: Modeling botnet propagation using time zones. In: Network and Distributed System Security Symposium, NDSS (2006)"},{"key":"11_CR13","doi-asserted-by":"crossref","unstructured":"Moore, D., Shannon, C., Brown, J.: Code-Red: A case study on the spread and victims of an Internet worm. In: Proceedings of the Internet Measurement Workshop (2002)","DOI":"10.1145\/637201.637244"},{"key":"11_CR14","unstructured":"Debar, H.: An Introduction to Intrusion Detection Systems. In: Proceedings of Connect (2000)"},{"key":"11_CR15","doi-asserted-by":"crossref","unstructured":"Estan, C., Savage, S., Varghese, G.: Automatically Inferring Patterns of Resource Consumption in Network Traffic. In: Proceedings of ACM SIGCOMM (2003)","DOI":"10.1145\/863955.863972"},{"key":"11_CR16","unstructured":"F-Secure. Kapersky Security Bulletin 2008: Malware Evolution January - June 2008 (2008), http:\/\/www.viruslist.com\/analysis?pubid=204792034"},{"key":"11_CR17","unstructured":"F-Secure. Calculating the Size of the Downadup Outbreak (2009), http:\/\/www.f-secure.com\/weblog\/archives\/00001584.html"},{"key":"11_CR18","unstructured":"Fitzgerald, P.: Downadup: Geolocation, Fingerprinting and Piracy (2009), https:\/\/forums.symantec.com\/t5\/Malicious-Code\/Downadup-Geo-location-Fingerprinting-and-Piracy\/ba-p\/380993"},{"key":"11_CR19","unstructured":"Gianvecchio, S., Xie, M., Wu, Z., Wang, H.: Measurement and classification of humans and bots in internet. In: USENIX Security (2008)"},{"key":"11_CR20","unstructured":"Goebel, J., Holz, T.: Rishi: Identify bot contaminated hosts by irc nickname evaluation. In: Hot Topics in Understanding Botnets (HotBots) (2007)"},{"key":"11_CR21","unstructured":"Grizzard, J.B., Sharma, V., Nunnery, C., Kang, B.B.: Peer-to-peer botnets: Overview and case study. In: Hot Topics in Understanding Botnets (HotBots) (2007)"},{"key":"11_CR22","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection. In: Proceedings of the 17th USENIX Security Symposium (2008)"},{"key":"11_CR23","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: BotHunter: Detecting malware infection through IDS-driven dialog correlation. In: Proceedings of 16th USENIX Security Symposium (2007)"},{"key":"11_CR24","unstructured":"Gu, G., Zhang, J., Lee, W.: Botsniffer: Detecting botnet command and control channels in network traffic. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium, NDSS 2008 (2008)"},{"key":"11_CR25","unstructured":"Holz, T., Gorecki, C., Rieck, K., Freiling, F.C.: Measuring and detecting fast-flux service networks. In: NDSS (2008)"},{"key":"11_CR26","unstructured":"SRI International. Malware Threat Center (2008), http:\/\/mtc.sri.org"},{"key":"11_CR27","doi-asserted-by":"crossref","unstructured":"Javitz, H., Valdes, A.: The SRI IDES statistical anomaly detector. In: Proceedings of IEEE Symposium on Research in Security and Privacy (1991)","DOI":"10.1109\/RISP.1991.130799"},{"key":"11_CR28","doi-asserted-by":"crossref","unstructured":"Jung, J., Paxson, V., Berger, A.W., Balakrishnan, H.: Fast portscan detection using sequential hypothesis testing. In: Proceedings of the IEEE Symposium on Security and Privacy (2004)","DOI":"10.1109\/SECPRI.2004.1301325"},{"key":"11_CR29","doi-asserted-by":"crossref","unstructured":"Kandula, S., Chandra, R., Katabi, D.: What\u2019s going on? Learning communication rules in edge networks. In: Sigcomm (2008)","DOI":"10.1145\/1402958.1402970"},{"key":"11_CR30","doi-asserted-by":"crossref","unstructured":"Livadas, C., Walsh, R., Lapsley, D., Strayer, W.T.: Using machine learning techniques to identify botnet traffic. In: Proc. IEEE LCN Workshop on Network Security, WoNS 2006 (2006)","DOI":"10.1109\/LCN.2006.322210"},{"key":"11_CR31","unstructured":"Trend Micro. Trend Micro Threat Roundup and Forecast - 1H 2008 (2008), http:\/\/us.trendmicro.com\/us\/threats\/enterprise\/security-library\/threat-reports\/index.html"},{"key":"11_CR32","unstructured":"Microsoft. Microsoft Security Bulletin MS08-067 \u2013 Critical (2008), http:\/\/www.microsoft.com\/technet\/security\/Bulletin\/MS08-067.mspx"},{"key":"11_CR33","doi-asserted-by":"crossref","unstructured":"Moore, D., Voelker, G.M., Savage, S.: Inferring internet denial-of-service activity. In: Proceedings of the 10th Usenix Security Symposium (2001)","DOI":"10.21236\/ADA400003"},{"key":"11_CR34","doi-asserted-by":"crossref","unstructured":"Pang, R., Allman, M., Bennett, M., Lee, J., Paxson, V., Tierney, B.: A first look at modern enterprise traffic. In: IMC (2005)","DOI":"10.1145\/1330107.1330110"},{"key":"11_CR35","doi-asserted-by":"crossref","unstructured":"Pang, R., Yegneswaran, V., Barford, P., Paxson, V., Peterson, L.: Characteristics of Internet background radiation. In: Proceedings of the 4th ACM SIGCOMM Internet Measurement Conference (2004)","DOI":"10.1145\/1028788.1028794"},{"key":"11_CR36","unstructured":"Paxson, V.: Bro: A system for detecting network intruders in real-time. In: Proceedings of the 7th USENIX Security Symposium, San Antonio, TX (January 1998)"},{"key":"11_CR37","doi-asserted-by":"crossref","unstructured":"Rousseeuw, P.: Silhouettes: a graphical aid to the interpretation and validation of cluster analysis. Journal of Computational and Applied Mathematics\u00a020 (1987)","DOI":"10.1016\/0377-0427(87)90125-7"},{"key":"11_CR38","doi-asserted-by":"crossref","unstructured":"Plonka, D., Barford, P.: Context-aware clustering of dns query traffic. In: Proceedings of ACM Internet Measurement Conference (2008)","DOI":"10.1145\/1452520.1452547"},{"key":"11_CR39","doi-asserted-by":"crossref","unstructured":"Plonka, D., Barford, P.: Context-aware Clustering of DNS Query Traffic. In: Proceedings of the 8th ACM SIGCOMM Internet Measurement Conference (2008)","DOI":"10.1145\/1452520.1452547"},{"key":"11_CR40","doi-asserted-by":"crossref","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: Proceedings of the 6th ACM SIGCOMM Internet Measurement Conference (2006)","DOI":"10.1145\/1177080.1177086"},{"key":"11_CR41","unstructured":"Roesch, M.: The SNORT Network Intrusion Detection System (2002), http:\/\/www.snort.org"},{"key":"11_CR42","unstructured":"Vogt, R., Aycock, J., Jacobson Jr., M.J.: Army of botnets. In: Network and Distributed System Security Symposium, NDSS (2008)"},{"key":"11_CR43","unstructured":"Yegneswaran, V., Porras, P., Saidi, H., Sharif, M., Narayanan, A.: SRI\u2019s Multiperspective Malware Infection Analysis Page (2009), http:\/\/www.cyber-ta.org\/releases\/malware-analysis\/public\/"},{"key":"11_CR44","doi-asserted-by":"crossref","unstructured":"Zdrnja, B., Brownlee, N., Wessels, D.: Passive Monitoring of DNS Anomalies (2007)","DOI":"10.1007\/978-3-540-73614-1_8"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-05284-2_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,23]],"date-time":"2019-05-23T00:16:22Z","timestamp":1558570582000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-05284-2_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642052835","9783642052842"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-05284-2_11","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2009]]}}}