{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,7]],"date-time":"2025-04-07T04:04:22Z","timestamp":1743998662566,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642324970"},{"type":"electronic","value":"9783642324987"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-32498-7_47","type":"book-chapter","created":{"date-parts":[[2012,8,14]],"date-time":"2012-08-14T14:04:28Z","timestamp":1344953068000},"page":"624-638","source":"Crossref","is-referenced-by-count":8,"title":["A Collaborative Approach to Botnet Protection"],"prefix":"10.1007","author":[{"given":"Matija","family":"Stevanovic","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kasper","family":"Revsbech","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jens Myrup","family":"Pedersen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robin","family":"Sharp","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian Damsgaard","family":"Jensen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"47_CR1","unstructured":"Antonakakis, M., Perdisci, R., Dagon, D., Lee, W., Feamster, N.: Building a dynamic reputation system for DNS. In: Proceedings of the 19th USENIX Security Symposium (Security 2010). USENIX Association (August 2010)"},{"key":"47_CR2","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1016\/j.comnet.2011.07.018","volume":"56","author":"H. Choi","year":"2011","unstructured":"Choi, H., Lee, H.: Identifying botnets by capturing group activities in DNS traffic. Journal of Computer Networks\u00a056, 20\u201333 (2011)","journal-title":"Journal of Computer Networks"},{"key":"47_CR3","doi-asserted-by":"crossref","unstructured":"Cuppens, F., Mi\u00e8ge, A.: Alert correlation in a cooperative intrusion detection framework. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 202\u2013215 (May 2002)","DOI":"10.1109\/SECPRI.2002.1004372"},{"key":"47_CR4","series-title":"IFIP ACIT, ch.13","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/978-3-642-24212-0_13","volume-title":"Advances in Digital Forensics VII","author":"A. Flaglien","year":"2011","unstructured":"Flaglien, A., Franke, K., \u00c5rnes, A.: Identifying malware using cross-evidence correlation. In: Peterson, G., Shenoi, S. (eds.) Advances in Digital Forensics VII. IFIP ACIT, ch.13, vol.\u00a0361, pp. 169\u2013182. Springer, Boston (2011)"},{"key":"47_CR5","unstructured":"Goebel, J., Holz, T.: Rishi: Identifying bot-contaminated hosts by IRC nickname evaluation. In: HotBots 2007: Proceedings of the First USENIX Workshop on Hot Topics in Understanding Botnets, Cambridge, Mass. USENIX Association (June 2007)"},{"key":"47_CR6","unstructured":"Grizzard, J.B., Sharma, V., Nunnery, C., Kang, B.B., Dagon, D.: Peer-to-peer botnets; Overview and case study. In: HotBots 2007: Proceedings of the First USENIX Workshop on Hot Topics in Understanding Botnets, Cambridge, Mass. USENIX Association (June 2007)"},{"key":"47_CR7","unstructured":"Gu, G., Zhang, J., Lee, W.: BotSniffer: Detecting botnet command and control channels in network traffic. In: NDSS 2008: Proceedings of the 15th Annual Network and Distributed System Security Symposium, San Diego. Internet Society (February 2008)"},{"key":"47_CR8","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection. In: Proceedings of the 17th Conference on Security Symposium, pp. 139\u2013154 (2008)"},{"key":"47_CR9","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: BotHunter: Detecting malware infection through IDS-driven dialog correlation. In: Proceedings of the 16th USENIX Security Symposium, San Jose, California, pp. 167\u2013182. USENIX Association (July 2007)"},{"key":"47_CR10","unstructured":"Hogben, G. (ed.): Botnets: Detection, measurement, disinfection and defence. Tech. rep., ENISA (2011)"},{"key":"47_CR11","doi-asserted-by":"crossref","unstructured":"Jensen, C., Korsgaard, T.: Dynamics of trust evolution: Auto-configuration of disposiional trust dynamics. In: Proceedings of the International Conference on Security and Cryptography (SECRYPT 2008), Porto, Portugal, pp. 509\u2013517 (July 2008)","DOI":"10.5220\/0001921305090517"},{"key":"47_CR12","unstructured":"Karasaridis, A., Rexroad, B., Hoeflin, D.: Wide-scale botnet detection and characterization. In: HotBots 2007: Proceedings of the First USENIX Workshop on Hot Topics in Understanding Botnets, Cambridge, Mass. USENIX Association (June 2007)"},{"key":"47_CR13","doi-asserted-by":"publisher","first-page":"502","DOI":"10.1016\/j.comcom.2010.04.007","volume":"34","author":"W. Lu","year":"2011","unstructured":"Lu, W., Rammidi, G., Ghorbani, A.A.: Clustering botnet communication traffic based on n-gram feature selection. Computer Communications\u00a034, 502\u2013514 (2011)","journal-title":"Computer Communications"},{"key":"47_CR14","unstructured":"Marsh, S.: Formalizing Trust as a Computational Concept, PhD thesis, University of Stirling, Dept. of Computer Science and Mathematics (1994)"},{"key":"47_CR15","doi-asserted-by":"crossref","unstructured":"Masud, M.M., Al-Khateeb, T., Khan, L., Turaisingham, B., Hamlen, K.W.: Flow-based identification of botnet traffic by mining multiple log file. In: Proceedings of the International Conference on Distributed Frameworks and Applications (DFMA), Penang, Malaysia (2008)","DOI":"10.1109\/ICDFMA.2008.4784437"},{"key":"47_CR16","doi-asserted-by":"crossref","unstructured":"Ning, P., Cui, Y., Reeves, D.S.: Constructing attack scenarios through correlation of intrusion alerts. In: Proceedings of CCS 2002, pp. 245\u2013254. ACM (November 2002)","DOI":"10.1145\/586143.586144"},{"key":"47_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1007\/978-3-642-15512-3_19","volume-title":"Recent Advances in Intrusion Detection","author":"A.J. Oliner","year":"2010","unstructured":"Oliner, A.J., Kulkarni, A.V., Aiken, A.: Community Epidemic Detection Using Time-Correlated Anomalies. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol.\u00a06307, pp. 360\u2013381. Springer, Heidelberg (2010)"},{"key":"47_CR18","unstructured":"Porras, P., Saidi, H., Yegneswaran, V.: A multi-perspective analysis of the Storm (peacomm) worm. Tech. rep., SRI International (2007), http:\/\/www.cyber-ta.org\/pubs\/StormWorm\/report"},{"key":"47_CR19","unstructured":"Porras, P., Saidi, H., Yegneswaran, V.: Conficker C analysis. Tech. rep., SRI International (2009), http:\/\/mtc.sri.com\/Conficker\/addendumC\/index.html"},{"key":"47_CR20","unstructured":"Ramachandran, A., Feamster, N., Dagon, D.: Revealing botnet membership using DNSBL counter-intelligence. In: SRUTI 2006: Proceedings of the 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet, San Jose, California, pp. 49\u201354. USENIX Association (June 2006)"},{"key":"47_CR21","unstructured":"Roesch, M.: Snort\u00a0\u2013 lightweight intrusion detection for networks. In: Proceedings of Usenix LISA 1999. USENIX Association (1999)"},{"key":"47_CR22","doi-asserted-by":"crossref","unstructured":"Saad, S., Traore, I., Ghorbani, A., Sayed, B., Zhao, D., Lu, W., Felix, J., Hakimian, P.: Detecting P2P botnets through network behavior analysis and machine learning. In: 2011 Ninth Annual International Conference on Privacy, Security and Trust, Montreal. IEEE (July 2011)","DOI":"10.1109\/PST.2011.5971980"},{"key":"47_CR23","unstructured":"Setia, S., Roy, S., Jajodia, S.: Secure data aggregation in wireless sensor networks. In: Lopez, Zhou (eds.) Wireless Sensor Networks Security (2008)"},{"key":"47_CR24","unstructured":"Shin, S., Xu, Z., Gu, G.: EFFORT: Efficient and effective bot malware detection. In: Proceedings of 31st Annual IEEE Conference on Computer Communications (INFOCOM 2012), Orlando, Florida. IEEE (March 2012)"},{"key":"47_CR25","doi-asserted-by":"crossref","unstructured":"Sinclair, G., Nunnery, C., Kang, B.B.: The Waledac protocol: The how and why. In: Proceedings of International Conference on Malicious and Unwanted Software, MALWARE (2009)","DOI":"10.1109\/MALWARE.2009.5403015"},{"key":"47_CR26","doi-asserted-by":"crossref","unstructured":"Stinson, E., Mitchell, J.C.: Characterizing bots\u2019 remote control behavior. In: Lee, W., Wang, C., Dagon, D. (eds.) Botnet Detection, Advances in Information Security, vol.\u00a036, pp. 45\u201364. Springer (2008)","DOI":"10.1007\/978-0-387-68768-1_3"},{"key":"47_CR27","doi-asserted-by":"crossref","unstructured":"Strayer, W.T., Lapsely, D., Walsh, R., Livadas, C.: Botnet detection based on network behaviour. In: Lee, W., Wang, C., Dagon, D. (eds.) Botnet Detection, Advances in Information Security, vol.\u00a036, pp. 1\u201324. Springer (2008)","DOI":"10.1007\/978-0-387-68768-1_1"},{"key":"47_CR28","unstructured":"Symantec Inc.: Symantec global internet security threat report, trends for 2010. Security Report XVI, Symantec Inc. (April 2011)"},{"key":"47_CR29","unstructured":"Symantec Inc.: Counterclank bot. Tech. rep., Symantec Inc. (2012), http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2012-012709-4046-99"},{"key":"47_CR30","doi-asserted-by":"crossref","unstructured":"Villamarin-Salomon, R., Brustoloni, J.C.: Identifying botnets using anomaly detection techniques applied to DNS traffic. In: Proceedings of 5th IEEE Consumer Communications and Networking Conference (CCNC 2008), pp. 476\u2013481 (2008)","DOI":"10.1109\/ccnc08.2007.112"},{"key":"47_CR31","doi-asserted-by":"crossref","unstructured":"Wang, H., Gong, Z.: Collaboration-based botnet detection architecture. In: Proceedings of 2nd International Conference on Intelligent Computational Technology and Automation, Zhangjiajie, China (2009)","DOI":"10.1109\/ICICTA.2009.326"},{"issue":"12","key":"47_CR32","first-page":"1655","volume":"6","author":"H. Wang","year":"2011","unstructured":"Wang, H., Hou, J., Gong, Z.: Botnet detection architecture based on heterogeneous multi-sensor information fusion. Journal of Networks\u00a06(12), 1655\u20131661 (2011)","journal-title":"Journal of Networks"},{"key":"47_CR33","unstructured":"Wang, P., Sparks, S., Zou, C.C.: An advanced hybrid peer-to-peer botnet. In: HotBots 2007: Proceedings of the First USENIX Workshop on Hot Topics in Understanding Botnets, Cambridge, Mass. USENIX Association (June 2007)"},{"key":"47_CR34","doi-asserted-by":"publisher","first-page":"1860","DOI":"10.1145\/1141277.1141717","volume-title":"Proceedings of ACM Symposium on Applied Computing (SAC)","author":"J. Weng","year":"2006","unstructured":"Weng, J., Miao, C., Goh, A.: Improving collaborative filtering with trust-based metrics. In: Proceedings of ACM Symposium on Applied Computing (SAC), pp. 1860\u20131864. ACM, New York (2006)"},{"key":"47_CR35","unstructured":"Zeng, Y., Hu, X., Shin, K.G.: Detection of botnets using combined host- and network-level information. In: Proceedings of 40th International Conference on Dependable Systems and Networks, DSN (2010)"},{"key":"47_CR36","doi-asserted-by":"crossref","unstructured":"Zhang, J., Perdisci, R., Lee, W., Sarfraz, U., Luo, X.: Detecting stealthy P2P botnets using statistical traffic fingerprints. In: 2011 IEEE\/IFIP 41st International Conference on Dependable Systems and Networks (DSN), Hong Kong, pp. 121\u2013132. IEEE\/IFIP (June 2011)","DOI":"10.1109\/DSN.2011.5958212"},{"key":"47_CR37","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Meratnia, N., Havinga, P.: Outlier detection techniques for wireless sensor networks: A survey. In: IEEE Communications Surveys and Tutorials (2010)","DOI":"10.4018\/978-1-60566-328-9.ch007"}],"container-title":["Lecture Notes in Computer Science","Multidisciplinary Research and Practice for Information Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-32498-7_47.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,6]],"date-time":"2025-04-06T21:50:15Z","timestamp":1743976215000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-32498-7_47"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642324970","9783642324987"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-32498-7_47","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2012]]}}}