{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,7]],"date-time":"2024-09-07T15:01:41Z","timestamp":1725721301775},"publisher-location":"Berlin, Heidelberg","reference-count":28,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642376818"},{"type":"electronic","value":"9783642376825"}],"license":[{"start":{"date-parts":[[2013,1,1]],"date-time":"2013-01-01T00:00:00Z","timestamp":1356998400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-37682-5_6","type":"book-chapter","created":{"date-parts":[[2013,4,2]],"date-time":"2013-04-02T21:48:15Z","timestamp":1364939295000},"page":"65-77","source":"Crossref","is-referenced-by-count":7,"title":["DNS Tunneling for Network Penetration"],"prefix":"10.1007","author":[{"given":"Daan","family":"Raman","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bjorn","family":"De Sutter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bart","family":"Coppens","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stijn","family":"Volckaert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Koen","family":"De Bosschere","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pieter","family":"Danhieux","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erik","family":"Van Buggenhout","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","unstructured":"Amon, C., Shinder, T.W., Carasik-Henmi, A.: The Best Damn Firewall Book Period, 2nd edn. Syngress Publishing (2007)"},{"key":"6_CR2","unstructured":"AnalogBit: tcp-over-dns, \n                    \n                      http:\/\/analogbit.com\/software\/tcp-over-dns"},{"key":"6_CR3","unstructured":"Beardsley, T.: Weekly Metasploit Update: DNS payloads, Exploit-DB, and More. Rapid7 Blog Post (March 2012), \n                    \n                      https:\/\/community.rapid7.com\/community\/metasploit\/blog\/2012\/03\/28\/metasploit-update"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Binsalleeh, H., Youssef, A.: An implementation for a worm detection and mitigation system. In: Proc. 24th Biennial Symposium on Communications, pp. 54\u201357 (June 2008)","DOI":"10.1109\/BSC.2008.4563204"},{"key":"6_CR5","unstructured":"Born, K., Gustafson, D.: Detecting DNS tunnels using character frequency analysis. In: Proceedings of the 9th Annual Security Conference (April 2010)"},{"key":"6_CR6","unstructured":"Bowes, R.: DNS Cat, \n                    \n                      http:\/\/www.skullsecurity.org\/wiki\/index.php\/Dnscat"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Choi, H., Lee, H., Lee, H., Kim, H.: Botnet detection by monitoring group activities in DNS traffic. In: Proc. 7th IEEE Int. Conf. on Computer and Information Technology, pp. 715\u2013720 (2007)","DOI":"10.1109\/CIT.2007.90"},{"key":"6_CR8","unstructured":"Di Pietro, R., Mancini, L.V.: Intrusion Detection Systems, 1st edn. Springer Publishing Company, Incorporated (2008)"},{"key":"6_CR9","unstructured":"Fewer, S.: Reflective DLL injection. Technical Report, Harmony Security (2008)"},{"key":"6_CR10","unstructured":"ICANN Security and Stability Advisory Committee: SSAC advisory on fast flux hosting and DNS (2008)"},{"key":"6_CR11","unstructured":"Kaminsky, D.: OzymanDNS, \n                    \n                      http:\/\/en.cship.org\/wiki\/OzymanDNS"},{"key":"6_CR12","unstructured":"Kryo: iodine, \n                    \n                      http:\/\/code.kryo.se\/iodine"},{"key":"6_CR13","unstructured":"Levine, J.: Linkers & Loaders. Morgan Kaufmann Publishers (2000)"},{"key":"6_CR14","unstructured":"Microsoft Corporation: ASCII and hex representation of NetBIOS names, \n                    \n                      http:\/\/support.microsoft.com\/kb\/194203"},{"key":"6_CR15","doi-asserted-by":"crossref","unstructured":"Mockapetris, P.: RFC 1034 Domain Names - Concepts and Facilities. The Internet Engineering Task Force, Network Working Group (November 1987)","DOI":"10.17487\/rfc1034"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Mockapetris, P.: RFC 1035 Domain Names - Implementation and Specification. The Internet Engineering Task Force, Network Working Group (November 1987)","DOI":"10.17487\/rfc1035"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Nazario, J., Holz, T.: As the net churns: Fast-flux botnet observations. In: Proc. 3rd International Conference on Malicious and Unwanted Software, pp. 24\u201331 (October 2008)","DOI":"10.1109\/MALWARE.2008.4690854"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"Postel, J.: RFC 768 User Datagram Protocol. The Internet Engineering Task Force (August 1980)","DOI":"10.17487\/rfc0768"},{"key":"6_CR19","unstructured":"Rapid7: Metasploit framework, \n                    \n                      http:\/\/www.metasploit.com"},{"key":"6_CR20","unstructured":"Rapid7: Metasploit pro user guide, \n                    \n                      http:\/\/community.rapid7.com\/docs\/DOC-1501"},{"key":"6_CR21","volume-title":"The Stuxnet Computer Worm and Industrial Control System Security","author":"J.C. Rebane","year":"2011","unstructured":"Rebane, J.C.: The Stuxnet Computer Worm and Industrial Control System Security. Nova Science Publishers, Inc., Commack (2011)"},{"key":"6_CR22","unstructured":"Shin, H.J.: A DNS anomaly detection and analysis system. NANOG 40 (June 2007)"},{"key":"6_CR23","unstructured":"\u201cskape\u201d, Turkulainen, J.: Remote library injection. Technical Report, nologin (2004)"},{"key":"6_CR24","unstructured":"The SPF Council: Sender policy framework, \n                    \n                      http:\/\/www.openspf.org\/"},{"key":"6_CR25","unstructured":"van der Heide, H., Barendregt, N.: DNS anomaly detection. Technical Report, Universiteit van Amsterdam (2011)"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Villamarin-Salomon, R., Brustoloni, J.: Identifying botnets using anomaly detection techniques applied to DNS traffic. In: Proc. 5th IEEE Consumer Communications and Networking Conference, pp. 476\u2013481 (January 2008)","DOI":"10.1109\/ccnc08.2007.112"},{"issue":"18","key":"6_CR27","doi-asserted-by":"crossref","first-page":"3858","DOI":"10.5897\/SRE11.439","volume":"6","author":"Z. Whang","year":"2011","unstructured":"Whang, Z., Tseng, S.S.: Anomaly detection of domain name system (DNS) query traffic at top level domain servers. Scientific Research and Essays\u00a06(18), 3858\u20133872 (2011)","journal-title":"Scientific Research and Essays"},{"key":"6_CR28","unstructured":"Whyte, D., Kranakis, E., van Oorschot, P.: DNS-based detection of scanning worms in an enterprise network. In: Proc. of the 12th Annual Network and Distributed System Security Symposium, pp. 181\u2013195 (2005)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology \u2013 ICISC 2012"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-37682-5_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T21:32:43Z","timestamp":1558301563000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-37682-5_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642376818","9783642376825"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-37682-5_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}