{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:40:58Z","timestamp":1785512458159,"version":"3.56.0"},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642137075","type":"print"},{"value":"9783642137082","type":"electronic"}],"license":[{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-13708-2_30","type":"book-chapter","created":{"date-parts":[[2010,6,23]],"date-time":"2010-06-23T07:56:06Z","timestamp":1277279766000},"page":"511-528","source":"Crossref","is-referenced-by-count":48,"title":["Social Network-Based Botnet Command-and-Control: Emerging Threats and Countermeasures"],"prefix":"10.1007","author":[{"given":"Erhan J.","family":"Kartaltepe","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jose Andre","family":"Morales","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shouhuai","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ravi","family":"Sandhu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"30_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1007\/978-3-540-85886-7_10","volume-title":"Information Security","author":"E. Athanasopoulos","year":"2008","unstructured":"Athanasopoulos, E., Makridakis, A., Antonatos, S., Antoniades, D., Ioannidis, S., Anagnostakis, K., Markatos, E.: Antisocial networks: Turning a social network into a botnet. In: Wu, T.-C., Lei, C.-L., Rijmen, V., Lee, D.-T. (eds.) ISC 2008. LNCS, vol.\u00a05222, pp. 146\u2013160. Springer, Heidelberg (2008)"},{"key":"30_CR2","unstructured":"Balatzar, J., Costoya, J., Flores, R.: The real face of koobface: The largest web 2.0 botnet explained. Technical report, Trend Micro (2009)"},{"key":"30_CR3","unstructured":"Binkley, J.R., Singh, S.: An algorithm for anomaly-based botnet detection. In: Proc. Reducing Unwanted Traffic on the Internet, SRUTI \u201906 (2006)"},{"key":"30_CR4","unstructured":"Chapman, M., Davida, G.I.: Plausible deniability using automated linguistic stegonagraphy. In: Conference on Infrastructure Security (October 2002)"},{"key":"30_CR5","unstructured":"Cheng, A., Evans, M.: Inside twitter: An in-depth look inside the twitter world, \n                    \n                      http:\/\/www.sysomos.com\/insidetwitter"},{"key":"30_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1007\/978-3-540-74320-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"M. Collins","year":"2007","unstructured":"Collins, M., Reiter, M.: Hit-list worm detection and bot identification in large networks using protocol graphs. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol.\u00a04637, pp. 276\u2013295. Springer, Heidelberg (2007)"},{"key":"30_CR7","doi-asserted-by":"crossref","unstructured":"Collins, M., Shimeall, T., Faber, S., Janies, J., Weaver, R., De Shon, M., Kadane, J.: Using uncleanliness to predict future botnet addresses. In: Proc. IMC \u201907 (2007)","DOI":"10.1145\/1298306.1298319"},{"key":"30_CR8","unstructured":"Cooke, E., Jahanian, F., McPherson, D.: The zombie roundup: understanding, detecting, and disrupting botnets. In: Proc. SRUTI \u201905 (2005)"},{"key":"30_CR9","unstructured":"Microsoft Corporation. Network monitor 3.3, \n                    \n                      http:\/\/go.microsoft.com\/fwlink\/?LinkID=103158&clcid=0x409"},{"key":"30_CR10","unstructured":"CWSandbox.org. Cwsandbox\u2014behavior-based malware analysis, \n                    \n                      http:\/\/www.cwsandbox.org"},{"key":"30_CR11","doi-asserted-by":"crossref","unstructured":"Dagon, D., Gu, G., Lee, C., Lee, W.: A taxonomy of botnet structures. In: Choi, L., Paek, Y., Cho, S. (eds.) ACSAC 2007. LNCS, vol.\u00a04697, Springer, Heidelberg (2007)","DOI":"10.1109\/ACSAC.2007.4413000"},{"key":"30_CR12","unstructured":"DigiNinja. Kreiosc2: Poc using twitter as its command and control channel, \n                    \n                      http:\/\/www.digininja.org"},{"key":"30_CR13","unstructured":"Easton, T., Johnson, K.: Social zombies. In: DEFCON \u201909 (2009)"},{"key":"30_CR14","unstructured":"Goebel, J., Holz, T.: Rishi: identify bot contaminated hosts by irc nickname evaluation. In: Proc. HotBots \u201907 (2007)"},{"key":"30_CR15","unstructured":"Grizzard, J.B., Sharma, V., Nunnery, C., Kang, B.B., Dagon, D.: Peer-to-peer botnets: overview and case study. In: Proc. HotBots \u201907 (2007)"},{"key":"30_CR16","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: BotMiner: Clustering analysis of network traffic for protocol- and structure-independent botnet detection. In: Security \u201908 (2008)"},{"key":"30_CR17","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: BotHunter: Detecting malware infection through ids-driven dialog correlation. In: USENIX Security \u201907 (2007)"},{"key":"30_CR18","unstructured":"Gu, G., Zhang, J., Lee, W.: BotSniffer: Detecting botnet command and control channels in network traffic. In: Proc. NDSS \u201908 (2008)"},{"key":"30_CR19","unstructured":"Holz, T., Steiner, M., Dahl, F., Biersack, E., Freiling, F.: Measurements and mitigation of peer-to-peer-based botnets: a case study on storm worm. In: LEET \u201908 (2008)"},{"key":"30_CR20","unstructured":"Hu, X., Knysz, M., Shin, K.G.: Rb-seeker: Auto-detection of redirection botnets. In: Proc. NDSS \u201909 (2009)"},{"key":"30_CR21","doi-asserted-by":"crossref","unstructured":"Finjan\u00a0Software Inc. Web security trends report q4 2007. Technical report, Finjan Software Inc. (2007), \n                    \n                      http:\/\/www.finjan.com\/Content.aspx?id=827","DOI":"10.1016\/S1754-4548(07)70080-3"},{"key":"30_CR22","unstructured":"John, J., Moshchuk, A., Gribble, S., Krishnamurthy, A.: Studying spamming botnets using botlab. In: Proc. NSDI \u201909 (2009)"},{"key":"30_CR23","unstructured":"Karasaridis, A., Rexroad, B., Hoeflin, D.: Wide-scale botnet detection and characterization. In: Proc. HotBots \u201907 (2007)"},{"key":"30_CR24","doi-asserted-by":"crossref","unstructured":"Morales, J.A., Clarke, P.J., Deng, Y., Kibria, B.G.: Identification of file infecting viruses through detection of self-reference replication. Journal in Computer Virology (2008)","DOI":"10.1007\/s11416-008-0101-5"},{"key":"30_CR25","unstructured":"Nazario, J.: Twitter based botnet command and control (2009), \n                    \n                      http:\/\/asert.arbornetworks.com\/2009\/08\/twitter-based-botnet-command-channel"},{"key":"30_CR26","doi-asserted-by":"crossref","unstructured":"Nazario, J., Holz, T.: As the net churns: Fast-flux botnet observations. In: Proc. MALWARE \u201908 (2008)","DOI":"10.1109\/MALWARE.2008.4690854"},{"key":"30_CR27","unstructured":"PassMark.com. Passmark performancetest 7.0, \n                    \n                      http:\/\/www.passmark.com\/products\/pt.htm"},{"key":"30_CR28","unstructured":"Poland, S.: How to create a twitter bot (2007), \n                    \n                      http:\/\/blog.stevepoland.com\/how-to-create-a-twitter-bot\/"},{"key":"30_CR29","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: Proc. IMC \u201906 (2006)"},{"key":"30_CR30","unstructured":"Singh, K., Srivastava, A., Giffin, J., Lee, W.: Evaluating email\u2019s feasibility for botnet command and control. In: Proc. DSN"},{"key":"30_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/978-3-540-73614-1_6","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"E. Stinson","year":"2007","unstructured":"Stinson, E., Mitchell, J.C.: Characterizing bots\u2019 remote control behavior. In: H\u00e4mmerli, B.M., Sommer, R. (eds.) DIMVA 2007. LNCS, vol.\u00a04579, pp. 89\u2013108. Springer, Heidelberg (2007)"},{"key":"30_CR32","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Symantec Press (2005)"},{"key":"30_CR33","unstructured":"Weka 3 data mining software, \n                    \n                      http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/"},{"key":"30_CR34","doi-asserted-by":"crossref","unstructured":"Xie, Y., Yu, F., Achan, K., Panigrahy, R., Hulten, G., Osipkov, I.: Spamming botnets: signatures and characteristics. In: Proc. SIGCOMM \u201908, pp. 171\u2013182 (2008)","DOI":"10.1145\/1402958.1402979"},{"key":"30_CR35","unstructured":"Zhao, Y., Xie, Y., Yu, F., Ke, Q., Yu, Y., Chen, Y., Gillum, E.: Botgraph: large scale spamming botnet detection. In: Proc. NSDI \u201909 (2009)"},{"key":"30_CR36","doi-asserted-by":"crossref","unstructured":"Zhu, Z., Yegneswaran, V., Chen, Y.: Using failure information analysis to detect enterprise zombies. In: Proc. Securecomm \u201909 (2009)","DOI":"10.1007\/978-3-642-05284-2_11"},{"key":"30_CR37","unstructured":"Zhuang, L., Dunagan, J., Simon, D., Wang, H., Osipkov, I., Hulten, G., Tygar, J.: Characterizing botnets from email spam records. In: Proc. LEET \u201908 (2008)"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-13708-2_30","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T15:08:37Z","timestamp":1558278517000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-13708-2_30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642137075","9783642137082"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-13708-2_30","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}