{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T00:28:19Z","timestamp":1766449699354},"publisher-location":"Berlin, Heidelberg","reference-count":31,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642155116"},{"type":"electronic","value":"9783642155123"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-15512-3_23","type":"book-chapter","created":{"date-parts":[[2010,8,31]],"date-time":"2010-08-31T08:27:39Z","timestamp":1283243259000},"page":"442-463","source":"Crossref","is-referenced-by-count":23,"title":["An Analysis of Rogue AV Campaigns"],"prefix":"10.1007","author":[{"given":"Marco","family":"Cova","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Corrado","family":"Leita","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Olivier","family":"Thonnard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marc","family":"Dacier","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"23_CR1","unstructured":"Microsoft Security Intelligence Report, volume 7. Technical report, Microsoft (2009)"},{"key":"23_CR2","volume-title":"Aggregation Functions: A Guide for Practitioners","author":"G. Beliakov","year":"2007","unstructured":"Beliakov, G., Pradera, A., Calvo, T.: Aggregation Functions: A Guide for Practitioners. Springer, Berlin (2007)"},{"key":"23_CR3","doi-asserted-by":"crossref","unstructured":"Bellovin, S.: A Technique for Counting NATted Hosts. In: Proc. of the Internet Measurement Conference (2002)","DOI":"10.1145\/637201.637243"},{"key":"23_CR4","doi-asserted-by":"crossref","unstructured":"Correll, S.P., Corrons, L.: The business of rogueware. Technical Report, PandaLabs (July 2009)","DOI":"10.1007\/978-3-642-16120-9_4"},{"key":"23_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-642-10772-6_3","volume-title":"Information Systems Security","author":"M. Dacier","year":"2009","unstructured":"Dacier, M., Pham, V., Thonnard, O.: The WOMBAT Attack Attribution method: some results. In: Prakash, A., Sen Gupta, I. (eds.) ICISS 2009. LNCS, vol.\u00a05905, pp. 19\u201337. Springer, Heidelberg (2009)"},{"key":"23_CR6","doi-asserted-by":"crossref","unstructured":"Daigle, L.: WHOIS protocol specification. RFC 3912 (September 2004)","DOI":"10.17487\/rfc3912"},{"key":"23_CR7","unstructured":"Fossi, M., Johnson, E., Turner, D., Mack, T., Blackbird, J., McKinney, D., Low, M.K., Adams, T., Laucht, M.P., Gough, J.: Symantec Report on the Underground Economy. Technical Report, Symantec (2008)"},{"key":"23_CR8","unstructured":"Fossi, M., Turner, D., Johnson, E., Mack, T., Adams, T., Blackbird, J., Low, M.K., McKinney, D., Dacier, M., Keromytis, A., Leita, C., Cova, M., Overton, J., Thonnard, O.: Symantec report on rogue security software. Whitepaper, Symantec (October 2009)"},{"key":"23_CR9","unstructured":"Franklin, J., Paxson, V., Perrig, A., Savage, S.: An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants. In: Proc. of the ACM Conference on Computer and Communications Security (2007)"},{"key":"23_CR10","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1145\/1719030.1719050","volume-title":"Proc. of the 2009 New Security Paradigms Workshop (NSPW)","author":"C. Herley","year":"2009","unstructured":"Herley, C.: So long, and no thanks for the externalities: the rational rejection of security advice by users. In: Proc. of the 2009 New Security Paradigms Workshop (NSPW), pp. 133\u2013144. ACM, New York (2009)"},{"key":"23_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-04444-1_1","volume-title":"Computer Security \u2013 ESORICS 2009","author":"T. Holz","year":"2009","unstructured":"Holz, T., Engelberth, M., Freiling, F.: Learning More about the Underground Economy: A Case-Study of Keyloggers and Dropzones. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol.\u00a05789, pp. 1\u201318. Springer, Heidelberg (2009)"},{"key":"23_CR12","unstructured":"Holz, T., Steiner, M., Dahl, F., Biersack, E., Freiling, F.: Measurements and Mitigation of Peer-to-Peer-based Botnets: A Case Study on Storm Worm. In: Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (2008)"},{"key":"23_CR13","doi-asserted-by":"crossref","unstructured":"Kanich, C., Kreibich, C., Levchenko, K., Enright, B., Voelker, G., Paxson, V., Savage, S.: Spamalytics: An Empirical Analysis of Spam Marketing Conversion. In: Proc. of the ACM Conference on Computer and Communications Security (2008)","DOI":"10.1145\/1455770.1455774"},{"key":"23_CR14","unstructured":"Krebs, B.: Massive Profits Fueling Rogue Antivirus Market. In: Washington Post (2009)"},{"key":"23_CR15","unstructured":"McGrath, K., Gupta, M.: Behind Phishing: An Examination of Phisher Modi Operandi. In: Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (2008)"},{"key":"23_CR16","doi-asserted-by":"crossref","unstructured":"Moore, T., Clayton, R.: Examining the Impact of Website Take-down on Phishing. In: Proc. of the APWG eCrime Researchers Summit (2007)","DOI":"10.1145\/1299015.1299016"},{"key":"23_CR17","unstructured":"Moshchuk, A., Bragin, T., Gribble, S.D., Levy, H.M.: A Crawler-based Study of Spyware on the Web. In: Network and Distributed System Security Symposium, pp. 17\u201333 (2006)"},{"key":"23_CR18","unstructured":"O\u2019Dea, H.: The Modern Rogue \u2014 Malware With a Face. In: Proc. of the Virus Bulletin Conference (2009)"},{"key":"23_CR19","unstructured":"Provos, N., Mavrommatis, P., Rajab, M., Monrose, F.: All Your iFRAMEs Point to Us. In: Proc. of the USENIX Security Symposium (2008)"},{"key":"23_CR20","doi-asserted-by":"crossref","unstructured":"Rajab, M., Zarfoss, J., Monrose, F., Terzis, A.: A Multifaceted Approach to Understanding the Botnet Phenomenon. In: Proc. of the Internet Measurement Conference (2006)","DOI":"10.1145\/1177080.1177086"},{"key":"23_CR21","unstructured":"Rajab, M.A., Ballard, L., Mavrommatis, P., Provos, N., Zhao, X.: The Nocebo Effect on the Web: An Analysis of Fake Anti-Virus Distribution. In: Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (2010)"},{"key":"23_CR22","unstructured":"Ramachandran, A., Feamster, N., Dagon, D.: Revealing Botnet Membership Using DNSBL Counter-Intelligence. In: Proc. of the Workshop on Steps to Reducing Unwanted Traffic on the Internet, SRUTI (2006)"},{"key":"23_CR23","doi-asserted-by":"publisher","first-page":"390","DOI":"10.1126\/science.210.4468.390","volume":"210","author":"R.N. Shepard","year":"1980","unstructured":"Shepard, R.N.: Multidimensional scaling, tree fitting, and clustering. Science\u00a0210, 390\u2013398 (1980)","journal-title":"Science"},{"key":"23_CR24","doi-asserted-by":"crossref","unstructured":"Stone-Gross, B., Cova, M., Cavallaro, L., Gilbert, B., Szydlowski, M., Kemmerer, R., Kruegel, C., Vigna, G.: Your Botnet is My Botnet: Analysis of a Botnet Takeover. In: Proc. of the ACM Conference on Computer and Communications Security (2009)","DOI":"10.1145\/1653662.1653738"},{"key":"23_CR25","doi-asserted-by":"crossref","unstructured":"Thonnard, O.: A multi-criteria clustering approach to support attack attribution in cyberspace. PhD thesis, \u00c9cole Doctorale d\u2019Informatique, T\u00e9l\u00e9communications et \u00c9lectronique de Paris (March 2010)","DOI":"10.1145\/1882471.1882474"},{"key":"23_CR26","doi-asserted-by":"crossref","unstructured":"Thonnard, O., Mees, W., Dacier, M.: Addressing the attack attribution problem using knowledge discovery and multi-criteria fuzzy decision-making. In: KDD 2009, 15th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Workshop on CyberSecurity and Intelligence Informatics, Paris, France, June 28-July 1 (December 2009)","DOI":"10.1145\/1599272.1599277"},{"key":"23_CR27","series-title":"Cryptology and Information Security Series","first-page":"191","volume-title":"The Virtual Battlefield: Perspectives on Cyber Warfare","author":"O. Thonnard","year":"2009","unstructured":"Thonnard, O., Mees, W., Dacier, M.: Behavioral Analysis of Zombie Armies. In: Czossek, C., Geers, K. (eds.) The Virtual Battlefield: Perspectives on Cyber Warfare. Cryptology and Information Security Series, vol.\u00a03, pp. 191\u2013210. IOS Press, Amsterdam (2009)"},{"key":"23_CR28","unstructured":"Wang, Y.-M., Beck, D., Jiang, X., Roussev, R.: Automated Web Patrol with Strider HoneyMonkeys. Technical Report MSR-TR-2005-72, Microsoft Research (2005)"},{"key":"23_CR29","doi-asserted-by":"crossref","unstructured":"Xie, Y., Yu, F., Achan, K., Gillum, E., Goldszmidt, M., Wobber, T.: How Dynamic are IP Addresses? In: Proc. of the Conference of the ACM Special Interest Group on Data Communication, SIGCOMM (2007)","DOI":"10.1145\/1282380.1282415"},{"issue":"1","key":"23_CR30","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1109\/21.87068","volume":"18","author":"R. Yager","year":"1988","unstructured":"Yager, R.: On ordered weighted averaging aggregation operators in multicriteria decision-making. IEEE Trans. Syst. Man Cybern.\u00a018(1), 183\u2013190 (1988)","journal-title":"IEEE Trans. Syst. Man Cybern."},{"key":"23_CR31","unstructured":"Zhuang, L., Dunagan, J., Simon, D., Wang, H., Osipkov, I., Hulten, G., Tygar, J.: Characterizing Botnets from Email Spam Records. In: Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (2008)"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-15512-3_23.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,23]],"date-time":"2020-11-23T22:09:21Z","timestamp":1606169361000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-15512-3_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642155116","9783642155123"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-15512-3_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2010]]}}}