{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,5]],"date-time":"2025-12-05T12:11:40Z","timestamp":1764936700739},"reference-count":19,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2014,1,21]],"date-time":"2014-01-21T00:00:00Z","timestamp":1390262400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Soft Comput"],"published-print":{"date-parts":[[2014,9]]},"DOI":"10.1007\/s00500-013-1218-0","type":"journal-article","created":{"date-parts":[[2014,1,20]],"date-time":"2014-01-20T02:18:23Z","timestamp":1390184303000},"page":"1757-1770","source":"Crossref","is-referenced-by-count":11,"title":["Network security management with traffic pattern clustering"],"prefix":"10.1007","volume":"18","author":[{"given":"Tao-Wei","family":"Chiou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shi-Chun","family":"Tsai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi-Bing","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,1,21]]},"reference":[{"key":"1218_CR1","unstructured":"Antonakakis M, Perdisci R, Dagon D, Lee W, Feamster N (2010) Building a dynamic reputation system for DNS. In: USENIX security symposium, pp 273\u2013290"},{"key":"1218_CR2","unstructured":"Antonakakis M, Perdisci R, Nadji Y, Vasiloglou N, Abu-Nimeh S, Lee W, Dagon D (2012) From throw-away traffic to bots: detecting the rise of DGA-based malware. In: Proceedings of the 21st USENIX security symposium"},{"key":"1218_CR3","unstructured":"Bilge L, Kirda E, Kruegel C, Balduzzi M (2011) Exposure: finding malicious domains using passive DNS analysis. In: 18th Annual network and distributed system security symposium,6\u20139 Feb 2011. San Diego, CA, USA"},{"key":"1218_CR4","unstructured":"Cheetham AH, Hazel JE (1969) Binary (presence\u2013absence) similarity coefficients. J Paleontol 43(5): 1130\u20131136"},{"key":"1218_CR5","doi-asserted-by":"crossref","unstructured":"Choi H, Lee H (2012) Identifying botnets by capturing group activities in DNS traffic. Comput Netw, vol 56, pp 20\u201333","DOI":"10.1016\/j.comnet.2011.07.018"},{"key":"1218_CR6","doi-asserted-by":"crossref","unstructured":"Dietrich C, Rossow C, Freiling F, Bos H, van Steen M, Pohlmann N (2011) On botnets that use DNS for command and control. In: Seventh European conference on computer network defense (EC2ND), pp 9\u201316","DOI":"10.1109\/EC2ND.2011.16"},{"key":"1218_CR7","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/j.neucom.2012.11.050","volume":"122","author":"U Fiore","year":"2013","unstructured":"Fiore U, Palmieri F, Castiglione A, De Santis A (2013) Network anomaly detection with the restricted Boltzmann machine. Neurocomputing 122:13\u201323","journal-title":"Neurocomputing"},{"key":"1218_CR8","unstructured":"Freund Y, Mason L (1999) The alternating decision tree learning algorithm. In: ICML, vol 99, pp 124\u2013133"},{"key":"1218_CR9","volume-title":"Data mining, concepts and techniques","author":"J Han","year":"2012","unstructured":"Han J, Kamber M, Pei J (2012) Data mining, concepts and techniques, 3rd edn. Morgan Kaufmann, San Francisco","edition":"3"},{"key":"1218_CR10","unstructured":"Horowitz E, Sahni S, Mehta DP (2006) Fundamentals of data structures in C++, 2nd edn. Silicon Press, Summit"},{"key":"1218_CR11","doi-asserted-by":"crossref","unstructured":"Kang U, Tsourakakis CE, Christos F (2009) PEGASUS: a peta-scale graph mining system\u2014implementation and observations. In: IEEE ICDM 2009, pp 229\u2013238","DOI":"10.1109\/ICDM.2009.14"},{"issue":"4","key":"1218_CR12","first-page":"21","volume":"3","author":"S Kiyomoto","year":"2012","unstructured":"Kiyomoto S, Fukushima K, Miyake Y (2012) Design of categorization mechanism for disaster-information-gathering system. J Wirel Mob Netw Ubiquitous Comput Dependable Appl 3(4):21\u201334","journal-title":"J Wirel Mob Netw Ubiquitous Comput Dependable Appl"},{"key":"1218_CR13","unstructured":"Lutkebohle I (2013) English letter frequency counts: Mayzner revisited"},{"key":"1218_CR14","doi-asserted-by":"crossref","unstructured":"Luxburg UV (2007) A tutorial on spectral clustering. Stat Comput 17(4): 395\u2013416","DOI":"10.1007\/s11222-007-9033-z"},{"issue":"6","key":"1218_CR15","doi-asserted-by":"crossref","first-page":"761","DOI":"10.1016\/j.comnet.2008.12.015","volume":"53","author":"F Palmieri","year":"2009","unstructured":"Palmieri F, Fiore U (2009) A nonlinear, recurrence-based approach to traffic classification. Comput Netw 53(6):761\u2013773","journal-title":"Comput Netw"},{"key":"1218_CR16","unstructured":"Porras P, Saidi H, Yegneswaran V (2009) Conficker analysis. SRI International, Menlo Park"},{"key":"1218_CR17","doi-asserted-by":"crossref","unstructured":"Stone-Gross B, Cova M, Cavallaro L, Gilbert B, Szydlowski M, Kemmerer R, Kruegel C, Vigna G (2009) Your botnet is my botnet: analysis of a botnet takeover. In: Proceedings of the 16th ACM conference on computer and communication security. ACM, New York, pp 635\u2013647","DOI":"10.1145\/1653662.1653738"},{"key":"1218_CR18","doi-asserted-by":"crossref","unstructured":"Xu K, Wang F, Gu L (2011) Network-aware behavior clustering of internet end hosts. In: IEEE INFOCOM 2011, pp 2078\u20132086","DOI":"10.1109\/INFCOM.2011.5935017"},{"key":"1218_CR19","doi-asserted-by":"crossref","unstructured":"Yadav S, Reddy A, Ranjan S (2010) Detecting algorithmically generated malicious domain names, In: Proceedings of the 10th ACM SIGCOMM conference on internet measurement, pp 48\u201361","DOI":"10.1145\/1879141.1879148"}],"container-title":["Soft Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00500-013-1218-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00500-013-1218-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00500-013-1218-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,6]],"date-time":"2019-08-06T16:34:24Z","timestamp":1565109264000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00500-013-1218-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,1,21]]},"references-count":19,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2014,9]]}},"alternative-id":["1218"],"URL":"https:\/\/doi.org\/10.1007\/s00500-013-1218-0","relation":{},"ISSN":["1432-7643","1433-7479"],"issn-type":[{"value":"1432-7643","type":"print"},{"value":"1433-7479","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,1,21]]}}}