{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T13:02:20Z","timestamp":1742994140999,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":25,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642224232"},{"type":"electronic","value":"9783642224249"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-22424-9_9","type":"book-chapter","created":{"date-parts":[[2011,6,20]],"date-time":"2011-06-20T02:37:35Z","timestamp":1308537455000},"page":"144-163","source":"Crossref","is-referenced-by-count":11,"title":["An Assessment of Overt Malicious Activity Manifest in Residential Networks"],"prefix":"10.1007","author":[{"given":"Gregor","family":"Maier","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anja","family":"Feldmann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vern","family":"Paxson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robin","family":"Sommer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Vallentin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"9_CR1","unstructured":"AirJaldi Network, http:\/\/www.airjaldi.org"},{"key":"9_CR2","doi-asserted-by":"crossref","unstructured":"Bailey, M., Cooke, E., Jahanian, F., Xu, Y., Karir, M.: A survey of botnet technology and defenses. In: Proc. Cybersecurity Applications & Technology Conference for Homeland Security (2009)","DOI":"10.1109\/CATCH.2009.40"},{"key":"9_CR3","doi-asserted-by":"crossref","unstructured":"Carlinet, Y., Me, L., Debar, H., Gourhant, Y.: Analysis of computer infection risk factors based on customer network usage. In: Proc. SECUWARE Conference (2008)","DOI":"10.1109\/SECURWARE.2008.30"},{"key":"9_CR4","unstructured":"Conficker Working Group, http:\/\/www.confickerworkinggroup.org"},{"key":"9_CR5","unstructured":"Dagon, D., Provos, N., Lee, C.P., Lee, W.: Corrupted DNS resolution paths: The rise of a malicious resolution authority. In: Proc. Network and Distributed System Security Symposium, NDSS (2009)"},{"key":"9_CR6","unstructured":"Dreger, H., Feldmann, A., Mai, M., Paxson, V., Sommer, R.: Dynamic application-layer protocol analysis for network intrusion detection. In: Proc. USENIX Security Symposium (2006)"},{"key":"9_CR7","unstructured":"Emerging Threats, http:\/\/www.emergingthreats.net\/"},{"key":"9_CR8","unstructured":"Google. Google safe browsing API, http:\/\/code.google.com\/apis\/safebrowsing\/"},{"key":"9_CR9","unstructured":"Hao, S., Feamster, N., Gray, A., Syed, N., Krasser, S.: Detecting spammers with SNARE: spatio-temporal network-level automated reputation engine. In: Proc. USENIX Security Symposium (2009)"},{"key":"9_CR10","doi-asserted-by":"crossref","unstructured":"Jung, J., Paxson, V., Berger, A., Balakrishnan, H.: Fast portscan detection using sequential hypothesis testing. In: Proc. IEEE Symp. on Security and Privacy (2004)","DOI":"10.1109\/SECPRI.2004.1301325"},{"key":"9_CR11","doi-asserted-by":"crossref","unstructured":"Maier, G., Feldmann, A., Paxson, V., Allman, M.: On dominant characteristics of residential broadband internet traffic. In: Proc. Internet Measurement Conference, IMC (2009)","DOI":"10.1145\/1644893.1644904"},{"key":"9_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1007\/978-3-642-19260-9_4","volume-title":"Passive and Active Measurement","author":"G. Maier","year":"2011","unstructured":"Maier, G., Schneider, F., Feldmann, A.: NAT usage in residential broadband networks. In: Spring, N., Riley, G.F. (eds.) PAM 2011. LNCS, vol.\u00a06579, pp. 32\u201341. Springer, Heidelberg (2011)"},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"Maier, G., Sommer, R., Dreger, H., Feldmann, A., Paxson, V., Schneider, F.: Enriching network security analysis with time travel. In: Proc. ACM SIGCOMM Conference (2008)","DOI":"10.1145\/1402958.1402980"},{"key":"9_CR14","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/S1389-1286(99)00112-7","volume":"31","author":"V. Paxson","year":"1999","unstructured":"Paxson, V.: Bro: A system for detecting network intruders in real-time. Computer Networks Journal\u00a031, 23\u201324 (1999) Bro homepage, http:\/\/www.bro-ids.org","journal-title":"Computer Networks Journal"},{"key":"9_CR15","unstructured":"Porras, P., Saidi, H., Yegneswaran, V.: An analysis of Conficker\u2019s logic and rendezvous points. Tech. rep., SRI International (2009)"},{"key":"9_CR16","unstructured":"Provos, N., Mavrommatis, P., Rajab, M.A., Monrose, F.: All your iFRAMEs point to us. In: Proc. USENIX Security Symposium (2008)"},{"key":"9_CR17","doi-asserted-by":"crossref","unstructured":"Ramachandran, A., Feamster, N., Vempala, S.: Filtering spam with behavioral blacklisting. In: Proc. ACM Conf. on Computer and Communications Security, CCS (2007)","DOI":"10.1145\/1315245.1315288"},{"key":"9_CR18","unstructured":"Roesch, M.: Snort: Lightweight intrusion detection for networks. In: Proc. Systems Administration Conference, LISA (1999)"},{"key":"9_CR19","unstructured":"SORBS, http:\/\/www.au.sorbs.net"},{"key":"9_CR20","doi-asserted-by":"crossref","unstructured":"Stone-Gross, B., Kruegel, C., Almeroth, K., Moser, A., Kirda, E.: FIRE: FInding Rogue nEtworks. In: Proc. Computer Security Applications Conference, ACSAC (2009)","DOI":"10.1109\/ACSAC.2009.29"},{"key":"9_CR21","unstructured":"The Spamhaus Project, http:\/\/www.spamhaus.org"},{"key":"9_CR22","unstructured":"Universit\u00e4t Bonn, http:\/\/net.cs.uni-bonn.de\/wg\/cs\/applications\/containing-conficker\/"},{"key":"9_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-642-12334-4_19","volume-title":"Passive and Active Measurement","author":"R. Weaver","year":"2010","unstructured":"Weaver, R.: A probabilistic population study of the conficker-C botnet. In: Krishnamurthy, A., Plattner, B. (eds.) PAM 2010. LNCS, vol.\u00a06032, pp. 181\u2013190. Springer, Heidelberg (2010)"},{"key":"9_CR24","unstructured":"Wikipedia. Zlob trojan, http:\/\/en.wikipedia.org\/wiki\/Zlob_trojan"},{"key":"9_CR25","unstructured":"ZeuS Tracker, https:\/\/zeustracker.abuse.ch"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-22424-9_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,11]],"date-time":"2019-06-11T21:41:27Z","timestamp":1560289287000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-22424-9_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642224232","9783642224249"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-22424-9_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}