{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T23:23:13Z","timestamp":1768778593139,"version":"3.49.0"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2019,1,18]],"date-time":"2019-01-18T00:00:00Z","timestamp":1547769600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100013410","name":"INCIBE","doi-asserted-by":"crossref","award":["INCIBEI-2015-27353"],"award-info":[{"award-number":["INCIBEI-2015-27353"]}],"id":[{"id":"10.13039\/501100013410","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100013410","name":"INCIBE","doi-asserted-by":"crossref","award":["INCIBEI-2015-27352"],"award-info":[{"award-number":["INCIBEI-2015-27352"]}],"id":[{"id":"10.13039\/501100013410","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Soft Comput"],"published-print":{"date-parts":[[2020,4]]},"DOI":"10.1007\/s00500-018-03703-8","type":"journal-article","created":{"date-parts":[[2019,1,18]],"date-time":"2019-01-18T13:38:00Z","timestamp":1547818680000},"page":"5517-5537","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["Scalable detection of botnets based on DGA"],"prefix":"10.1007","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5267-2392","authenticated-orcid":false,"given":"Mattia","family":"Zago","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7768-9665","authenticated-orcid":false,"given":"Manuel","family":"Gil P\u00e9rez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5532-6604","authenticated-orcid":false,"given":"Gregorio","family":"Mart\u00ednez P\u00e9rez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,1,18]]},"reference":[{"key":"3703_CR1","unstructured":"Abakumov A (2016) andrewaeva\/DGA. URL \nhttps:\/\/github.com\/andrewaeva\/DGA"},{"key":"3703_CR2","doi-asserted-by":"publisher","unstructured":"Abbink J, Doerr C (2017) Popularity-based detection of domain generation algorithms. In: 12th international conference on availability, reliability and security, pp 79:1\u201379:8. \nhttps:\/\/doi.org\/10.1145\/3098954.3107008","DOI":"10.1145\/3098954.3107008"},{"issue":"10","key":"3703_CR3","doi-asserted-by":"publisher","first-page":"1533","DOI":"10.1109\/TASLP.2014.2339736","volume":"22","author":"O Abdel-Hamid","year":"2014","unstructured":"Abdel-Hamid O, Mohamed Ar, Jiang H, Deng L, Penn G, Yu D (2014) Convolutional neural networks for speech recognition. IEEE\/ACM Trans Audio Speech Lang Process 22(10):1533\u20131545. \nhttps:\/\/doi.org\/10.1109\/TASLP.2014.2339736","journal-title":"IEEE\/ACM Trans Audio Speech Lang Process"},{"key":"3703_CR4","doi-asserted-by":"publisher","unstructured":"Ahluwalia A, Traore I, Ganame K, Agarwal N (2017) Detecting broad length algorithmically generated domains. In: Intelligent, secure, and dependable systems in distributed and cloud environments, chap.\u00a02, pp 19\u201334. Springer International Publishing. \nhttps:\/\/doi.org\/10.1007\/978-3-319-69155-8_2","DOI":"10.1007\/978-3-319-69155-8_2"},{"issue":"7","key":"3703_CR5","doi-asserted-by":"publisher","first-page":"1541","DOI":"10.1007\/s00521-015-2128-0","volume":"28","author":"K Alieyan","year":"2017","unstructured":"Alieyan K, ALmomani A, Manasrah A, Kadhum MM (2017) A survey of botnet detection based on DNS. Neural Comput Appl 28(7):1541\u20131558. \nhttps:\/\/doi.org\/10.1007\/s00521-015-2128-0","journal-title":"Neural Comput Appl"},{"issue":"2","key":"3703_CR6","doi-asserted-by":"publisher","first-page":"96","DOI":"10.4018\/IJCAC.2018040105","volume":"8","author":"A Almomani","year":"2018","unstructured":"Almomani A, Alauthman M, Albalas F, Dorgham O, Obeidat A (2018) An online intrusion detection system to cloud computing based on Neucube algorithms. Int J Cloud Appl Comput 8(2):96\u2013112. \nhttps:\/\/doi.org\/10.4018\/IJCAC.2018040105","journal-title":"Int J Cloud Appl Comput"},{"key":"3703_CR7","doi-asserted-by":"publisher","unstructured":"Anderson HS, Woodbridge J, Filar B (2016) DeepDGA: adversarially-tuned domain generation and detection. In: 2016 ACM workshop on artificial intelligence and security, pp 13\u201321. \nhttps:\/\/doi.org\/10.1145\/2996758.2996767","DOI":"10.1145\/2996758.2996767"},{"key":"3703_CR8","unstructured":"Antonakakis M, Perdisci R, Nadji Y, Vasiloglou N, Abu-Nimeh S, Lee W, Dagon D (2012) From throw-away traffic to bots: detecting the rise of DGA-based malware. In: 21st USENIX security symposium, pp 491\u2013506. Bellevue, WA. URL \nhttps:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/antonakakis"},{"key":"3703_CR9","unstructured":"Bader J. Domain Generation Algorithms. URL \nhttps:\/\/github.com\/baderj\/domain_generation_algorithms"},{"key":"3703_CR10","doi-asserted-by":"publisher","unstructured":"Baruch M, David G (2018) Domain generation algorithm detection using machine learning methods. In: Cyber security: power and technology, pp 133\u2013161. Springer International Publishing. \nhttps:\/\/doi.org\/10.1007\/978-3-319-75307-2_9","DOI":"10.1007\/978-3-319-75307-2_9"},{"key":"3703_CR11","doi-asserted-by":"publisher","unstructured":"Berger A, Gansterer WN (2013) Modeling DNS agility with DNSMap. In: 2013 proceedings IEEE INFOCOM, pp 3153\u20133158. \nhttps:\/\/doi.org\/10.1109\/INFCOM.2013.6567130","DOI":"10.1109\/INFCOM.2013.6567130"},{"key":"3703_CR12","doi-asserted-by":"publisher","unstructured":"Biglar Beigi E, Hadian Jazi H, Stakhanova N, Ghorbani AA (2014) Towards effective feature selection in machine learning-based botnet detection approaches. In: 2014 IEEE conference on communications and network security, pp 247\u201325. \nhttps:\/\/doi.org\/10.1109\/CNS.2014.6997492","DOI":"10.1109\/CNS.2014.6997492"},{"issue":"4","key":"3703_CR13","doi-asserted-by":"publisher","first-page":"14:1","DOI":"10.1145\/2584679","volume":"16","author":"L Bilge","year":"2014","unstructured":"Bilge L, Sen S, Balzarotti D, Kirda E, Kruegel C (2014) Exposure: a passive DNS analysis service to detect and report malicious domains. ACM Trans Inf Syst Secur 16(4):14:1\u201314:28. \nhttps:\/\/doi.org\/10.1145\/2584679","journal-title":"ACM Trans Inf Syst Secur"},{"key":"3703_CR14","volume-title":"Pattern recognition and machine learning","author":"C Bishop","year":"2006","unstructured":"Bishop C (2006) Pattern recognition and machine learning. Springer, Berlin"},{"key":"3703_CR15","doi-asserted-by":"publisher","unstructured":"Bisio F, Saeli S, Lombardo P, Bernardi D, Perotti A, Massa D (2017) Real-time behavioral DGA detection through machine learning. In: 2017 international carnahan conference on security technology, pp 1\u20136. \nhttps:\/\/doi.org\/10.1109\/CCST.2017.8167790","DOI":"10.1109\/CCST.2017.8167790"},{"key":"3703_CR16","doi-asserted-by":"publisher","unstructured":"Bugiel S, N\u00fcrnberger S, P\u00f6ppelmann T, Sadeghi AR, Schneider T (2011) AmazonIA: when elasticity snaps back. In: 18th ACM conference on computer and communications security, pp 389\u2013400. \nhttps:\/\/doi.org\/10.1145\/2046707.2046753","DOI":"10.1145\/2046707.2046753"},{"key":"3703_CR17","unstructured":"Dem\u0161ar J, Curk T, Erjavec A, Gorup \u010c, Ho\u010devar T, Milutinovi\u010d M, Mo\u017eina M, Polajnar M, Toplak M, Stari\u010d A, \u0160tajdohar M, Umek L, \u017dagar L, \u017dbontar J, \u017ditnik M, Zupan B (2013) Orange: data mining toolbox in Python. J Mach Learn Res 14:2349\u20132353. URL \nhttp:\/\/jmlr.org\/papers\/v14\/demsar13a.html"},{"key":"3703_CR18","unstructured":"Fran E, Hall MA, Witten IH (2016) The WEKA Workbench. Tech. rep. URL \nhttps:\/\/www.cs.waikato.ac.nz\/ml\/weka"},{"issue":"6","key":"3703_CR19","doi-asserted-by":"publisher","first-page":"1430","DOI":"10.1109\/TIFS.2017.2668361","volume":"12","author":"Y Fu","year":"2017","unstructured":"Fu Y, Yu L, Hambolu O, Ozcelik I, Husain B, Sun J, Sapra K, Du D, Beasley CT, Brooks RR (2017) Stealthy domain generation algorithms. IEEE Trans Inf Forensics Secur 12(6):1430\u20131443. \nhttps:\/\/doi.org\/10.1109\/TIFS.2017.2668361","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"3703_CR20","doi-asserted-by":"publisher","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garc\u00eda","year":"2014","unstructured":"Garc\u00eda S, Grill M, Stiborek J, Zunino A (2014) An empirical comparison of botnet detection methods. Comput Secur 45:100\u2013123. \nhttps:\/\/doi.org\/10.1016\/j.cose.2014.05.011","journal-title":"Comput Secur"},{"key":"3703_CR21","doi-asserted-by":"publisher","unstructured":"Grill M, Nikolaev I, Valeros V, Rehak M (2015) Detecting DGA malware using NetFlow. In: 2015 IFIP\/IEEE international symposium on integrated network management, pp 1304\u20131309. \nhttps:\/\/doi.org\/10.1109\/INM.2015.7140486","DOI":"10.1109\/INM.2015.7140486"},{"key":"3703_CR22","doi-asserted-by":"crossref","unstructured":"Gupta B, Agrawal DP, Yamaguchi S (eds) (2016) Handbook of research on modern cryptographic solutions for computer and cyber security, 1st edn. IGI Global","DOI":"10.4018\/978-1-5225-0105-3"},{"key":"3703_CR23","doi-asserted-by":"publisher","unstructured":"Han C, Zhang Y (2017) CODDULM: an approach for detecting C&C domains of DGA on passive DNS traffic. In: 2017 6th international conference on computer science and network technology, pp 385\u2013388. \nhttps:\/\/doi.org\/10.1109\/ICCSNT.2017.8343724","DOI":"10.1109\/ICCSNT.2017.8343724"},{"key":"3703_CR24","volume-title":"Neural networks: a comprehensive foundation","author":"S Haykin","year":"1998","unstructured":"Haykin S (1998) Neural networks: a comprehensive foundation, 2nd edn. Prentice Hall PTR, Upper Saddle River","edition":"2"},{"key":"3703_CR25","unstructured":"Holz T, Steiner M, Dahl F, Biersack E, Freiling F (2008) Measurements and mitigation of peer-to-peer-based Botnets: a case study on storm worm. In: USENIX security 2008. URL \nhttps:\/\/www.usenix.org\/conference\/leet-08\/measurements-and-mitigation-peer-peer-based-botnets-case-study-storm-worm"},{"issue":"1","key":"3703_CR26","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1016\/j.aci.2016.03.001","volume":"13","author":"SA Hussain","year":"2017","unstructured":"Hussain SA, Fatima M, Saeed A, Raza I, Shahzad RK (2017) Multilevel classification of security concerns in cloud computing. Appl Comput Inform 13(1):57\u201365. \nhttps:\/\/doi.org\/10.1016\/j.aci.2016.03.001","journal-title":"Appl Comput Inform"},{"key":"3703_CR27","doi-asserted-by":"publisher","unstructured":"Kintis P, Miramirkhani N, Lever C, Chen Y, Romero-G\u00f3mez R, Pitropakis N, Nikiforakis N, Antonakakis M (2017) Hiding in plain sight: a longitudinal study of combosquatting abuse. In: ACM SIGSAC conference on computer and communications security, pp 569\u2013586. \nhttps:\/\/doi.org\/10.1145\/3133956.3134002","DOI":"10.1145\/3133956.3134002"},{"key":"3703_CR28","doi-asserted-by":"publisher","unstructured":"K\u00fchrer M, Rossow C, Holz T (2014) Paint it black: evaluating the effectiveness of malware blacklists. In: RAID 2014: research in attacks, intrusions and defenses, June, pp 1\u201321. Springer International Publishing. \nhttps:\/\/doi.org\/10.1007\/978-3-319-11379-1_1","DOI":"10.1007\/978-3-319-11379-1_1"},{"key":"3703_CR29","doi-asserted-by":"publisher","unstructured":"Leelasankar K, Chellappan C, Sivasankar P (2018) Handbook of research on network forensics and analysis techniques, chap. successful computer forensics analysis on the cyber attack Botnet, pp 266\u2013281. IGI Global. \nhttps:\/\/doi.org\/10.4018\/978-1-5225-4100-4.ch014","DOI":"10.4018\/978-1-5225-4100-4.ch014"},{"key":"3703_CR30","unstructured":"Lerner Z (2014) Microsoft the Botnet hunter: the role of public-private partnerships in mitigating Botnets. Harvard J Law Technol 28(1):237\u2013261. URL \nhttp:\/\/jolt.law.harvard.edu\/articles\/pdf\/v28\/28HarvJLTech237.pdf"},{"key":"3703_CR31","doi-asserted-by":"publisher","unstructured":"Lobato AGP, Lopez MA, Sanz IJ, Cardenas AA, Duarte OCMB, Pujolle G (2018) An Adaptive real-time architecture for zero-day threat detection. In: 2018 IEEE international conference on communications (ICC), pp 1\u20136. \nhttps:\/\/doi.org\/10.1109\/ICC.2018.8422622","DOI":"10.1109\/ICC.2018.8422622"},{"key":"3703_CR32","doi-asserted-by":"publisher","unstructured":"Luo X, Wang L, Xu Z, Yang J, Sun M, Wang J (2017) DGASensor: fast detection for DGA-based malwares. In: 5th international conference on communications and broadband networking, pp 47\u201353. \nhttps:\/\/doi.org\/10.1145\/3057109.3057112","DOI":"10.1145\/3057109.3057112"},{"key":"3703_CR33","doi-asserted-by":"publisher","unstructured":"Mac H, Tran D, Tong V, Nguyen LG, Tran HA (2017) DGA Botnet detection using supervised learning methods. In: 8th international symposium on information and communication technology, pp 211\u2013218. \nhttps:\/\/doi.org\/10.1145\/3155133.3155166","DOI":"10.1145\/3155133.3155166"},{"key":"3703_CR34","unstructured":"Majestic-12 Ltd: The Majestic Million (2018) URL \nhttps:\/\/majestic.com\/reports\/majestic-million"},{"key":"3703_CR35","unstructured":"Malware Domain List (2009) URL \nhttps:\/\/www.malwaredomainlist.com\/mdl.php"},{"key":"3703_CR36","doi-asserted-by":"publisher","unstructured":"Mantovani RG, Rossi AL, Vanschoren J, Bischl B, Carvalho AC (2015) To tune or not to tune: recommending when to adjust SVM hyper-parameters via meta-learning. In: Proceedings of the international joint conference on neural networks, vol 2015-September, pp 1\u20138. \nhttps:\/\/doi.org\/10.1109\/IJCNN.2015.7280644","DOI":"10.1109\/IJCNN.2015.7280644"},{"key":"3703_CR37","doi-asserted-by":"crossref","unstructured":"Mell P, Grance T (2011) The NIST definition of cloud computing, NIST Special Publication 800-145. URL \nhttp:\/\/faculty.winthrop.edu\/domanm\/csci411\/Handouts\/NIST.pdf","DOI":"10.6028\/NIST.SP.800-145"},{"key":"3703_CR38","doi-asserted-by":"publisher","unstructured":"Mowbray M, Hagen J (2014) Finding domain-generation algorithms by looking at length distribution. In: 2014 IEEE international symposium on software reliability engineering workshops, pp 395\u2013400. \nhttps:\/\/doi.org\/10.1109\/ISSREW.2014.20","DOI":"10.1109\/ISSREW.2014.20"},{"issue":"2","key":"3703_CR39","doi-asserted-by":"publisher","first-page":"1361","DOI":"10.1109\/COMST.2017.2781126","volume":"20","author":"P Nespoli","year":"2018","unstructured":"Nespoli P, Papamartzivanos D, Mrmol FG, Kambourakis G (2018) Optimal countermeasures selection against cyber attacks: a comprehensive survey on reaction frameworks. IEEE Commun Surv Tutor 20(2):1361\u20131396. \nhttps:\/\/doi.org\/10.1109\/COMST.2017.2781126","journal-title":"IEEE Commun Surv Tutor"},{"key":"3703_CR40","unstructured":"Netlab 360: DGA Families. URL \nhttp:\/\/data.netlab.360.com\/dga\/"},{"key":"3703_CR41","doi-asserted-by":"publisher","unstructured":"Nguyen TD, Cao TD, Nguyen LG (2015) DGA Botnet detection using collaborative filtering and density-based clustering. In: 6th international symposium on information and communication technology, pp 203\u2013209. \nhttps:\/\/doi.org\/10.1145\/2833258.2833310","DOI":"10.1145\/2833258.2833310"},{"key":"3703_CR42","unstructured":"OSINT: OSINT DGA List. URL \nhttp:\/\/osint.bambenekconsulting.com\/feeds\/"},{"key":"3703_CR43","doi-asserted-by":"publisher","unstructured":"Pelleg D, Moore A (2000) X-means: Extending K-Means with efficient estimation of the number of clusters. In: 7th international conference on machine learning pp 727\u2013734. \nhttps:\/\/doi.org\/10.1007\/3-540-44491-2_3","DOI":"10.1007\/3-540-44491-2_3"},{"key":"3703_CR44","unstructured":"Plohmann D (2015) DGArchive. URL \nhttps:\/\/dgarchive.caad.fkie.fraunhofer.de"},{"key":"3703_CR45","unstructured":"Plohmann D, Yakdan K, Klatt M, Bader J, Gerhards-Padilla E (2016) A comprehensive measurement study of domain generating malware. In: 25th USENIX security symposium, pp 263\u2013278. Austin, TX. URL \nhttps:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity16\/sec16_paper_plohmann.pdf"},{"key":"3703_CR46","doi-asserted-by":"publisher","unstructured":"Pu Y, Chen X, Pu Y, Shi J (2015) A clustering approach for detecting auto-generated Botnet domains. In: Applications and techniques in information security, pp 269\u2013279. \nhttps:\/\/doi.org\/10.1007\/978-3-662-48683-2_24","DOI":"10.1007\/978-3-662-48683-2_24"},{"key":"3703_CR47","unstructured":"Risk Analytics: DNS-BH-Malware Domain Blocklist (2007). URL \nhttp:\/\/www.malwaredomains.com"},{"issue":"4","key":"3703_CR48","doi-asserted-by":"publisher","first-page":"3:1","DOI":"10.1147\/JRD.2016.2557639","volume":"60","author":"DL Schales","year":"2016","unstructured":"Schales DL, Jang J, Wang T, Hu X, Kirat D, Wuest B, Stoecklin MP (2016) Scalable analytics to detect DNS misuse for establishing stealthy communication channels. IBM J Res Dev 60(4):3:1\u20133:14. \nhttps:\/\/doi.org\/10.1147\/JRD.2016.2557639","journal-title":"IBM J Res Dev"},{"key":"3703_CR49","doi-asserted-by":"publisher","unstructured":"Schiavoni S, Maggi F, Cavallaro L, Zanero S (2014) Phoenix: DGA-based Botnet tracking and intelligence. In: 11th international conference on detection of intrusions and malware, and vulnerability assessment, pp 192\u2013211. Springer International Publishing. \nhttps:\/\/doi.org\/10.1007\/978-3-319-08509-8_11","DOI":"10.1007\/978-3-319-08509-8_11"},{"issue":"4","key":"3703_CR50","doi-asserted-by":"publisher","first-page":"60","DOI":"10.4018\/IJCAC.2017100104","volume":"7","author":"A Sharieh","year":"2017","unstructured":"Sharieh A, Albdour L (2017) A heuristic approach for service allocation in cloud computing. Int J Cloud Appl Comput 7(4):60\u201374. \nhttps:\/\/doi.org\/10.4018\/IJCAC.2017100104","journal-title":"Int J Cloud Appl Comput"},{"key":"3703_CR51","doi-asserted-by":"publisher","unstructured":"Shi Y, Chen G, Li J (2017) Malicious domain name detection based on extreme machine learning. Neural Process Lett. \nhttps:\/\/doi.org\/10.1007\/s11063-017-9666-7","DOI":"10.1007\/s11063-017-9666-7"},{"key":"3703_CR52","doi-asserted-by":"publisher","unstructured":"Song WJ, Li B (2016) A method to detect machine generated domain names based on random forest algorithm. In: 2016 international conference on information system and artificial intelligence, pp 509\u2013513. \nhttps:\/\/doi.org\/10.1109\/ISAI.2016.0114","DOI":"10.1109\/ISAI.2016.0114"},{"issue":"3","key":"3703_CR53","doi-asserted-by":"publisher","first-page":"964","DOI":"10.1016\/j.future.2016.11.031","volume":"78","author":"C Stergiou","year":"2018","unstructured":"Stergiou C, Psannis KE, Kim BG, Gupta B (2018) Secure integration of IoT and cloud computing. Future Gener Comput Syst 78(3):964\u2013975. \nhttps:\/\/doi.org\/10.1016\/j.future.2016.11.031","journal-title":"Future Gener Comput Syst"},{"key":"3703_CR54","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1016\/j.cose.2015.09.004","volume":"55","author":"M Stevanovic","year":"2015","unstructured":"Stevanovic M, Pedersen JM, D\u2019Alconzo A, Ruehrup S, Berger A (2015) On the ground truth problem of malicious DNS traffic analysis. Comput Secur 55:142\u2013158. \nhttps:\/\/doi.org\/10.1016\/j.cose.2015.09.004","journal-title":"Comput Secur"},{"issue":"2","key":"3703_CR55","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/s10207-016-0331-3","volume":"16","author":"M Stevanovic","year":"2017","unstructured":"Stevanovic M, Pedersen JM, D\u2019Alconzo A, Ruehrup S (2017) A method for identifying compromised clients based on DNS traffic analysis. Int J Inf Secur 16(2):115\u2013132. \nhttps:\/\/doi.org\/10.1007\/s10207-016-0331-3","journal-title":"Int J Inf Secur"},{"key":"3703_CR56","doi-asserted-by":"publisher","unstructured":"Thomas M, Mohaisen A (2014) Kindred domains: detecting and clustering Botnet domains using DNS traffic. In: 23rd international conference on World Wide Web, pp 707\u2013712. \nhttps:\/\/doi.org\/10.1145\/2567948.2579359","DOI":"10.1145\/2567948.2579359"},{"key":"3703_CR57","doi-asserted-by":"publisher","unstructured":"Tong V, Nguyen G (2016) A method for detecting DGA Botnet based on semantic and cluster analysis. In: 7th symposium on information and communication technology, pp 272\u2013277. \nhttps:\/\/doi.org\/10.1145\/3011077.3011112","DOI":"10.1145\/3011077.3011112"},{"key":"3703_CR58","doi-asserted-by":"publisher","first-page":"2401","DOI":"10.1016\/j.neucom.2017.11.018","volume":"275","author":"D Tran","year":"2018","unstructured":"Tran D, Mac H, Tong V, Tran HA, Nguyen LG (2018) A LSTM based framework for handling multiclass imbalance in DGA Botnet detection. Neurocomputing 275:2401\u20132413. \nhttps:\/\/doi.org\/10.1016\/j.neucom.2017.11.018","journal-title":"Neurocomputing"},{"issue":"14","key":"3703_CR59","doi-asserted-by":"publisher","first-page":"2338","DOI":"10.1002\/sec.1495","volume":"9","author":"D Truong","year":"2016","unstructured":"Truong D, Cheng G (2016) Detecting domain-flux botnet based on DNS traffic features in managed network. Secur Commun Netw 9(14):2338\u20132347. \nhttps:\/\/doi.org\/10.1002\/sec.1495","journal-title":"Secur Commun Netw"},{"key":"3703_CR60","doi-asserted-by":"publisher","unstructured":"Tu TD, Guang C, Xin LY (2015) Detecting Bot-infected machines based on analyzing the similar periodic DNS queries. In: 2015 international conference on communications, management and telecommunications, pp 35\u201340. \nhttps:\/\/doi.org\/10.1109\/ComManTel.2015.7394256","DOI":"10.1109\/ComManTel.2015.7394256"},{"issue":"3","key":"3703_CR61","doi-asserted-by":"publisher","first-page":"1265","DOI":"10.3233\/JIFS-169423","volume":"34","author":"R Vinayakumar","year":"2018","unstructured":"Vinayakumar R, Soman K, Poornachandran P, Sachin Kumar S (2018) Evaluating deep learning approaches to characterize and classify the DGAs at scale. J Intell Fuzzy Syst 34(3):1265\u20131276. \nhttps:\/\/doi.org\/10.3233\/JIFS-169423","journal-title":"J Intell Fuzzy Syst"},{"issue":"4","key":"3703_CR62","doi-asserted-by":"publisher","first-page":"2768","DOI":"10.1109\/COMST.2017.2749442","volume":"19","author":"G Vormayr","year":"2017","unstructured":"Vormayr G, Zseby T, Fabini J (2017) Botnet communication patterns. IEEE Commun Surv Tutor 19(4):2768\u20132796. \nhttps:\/\/doi.org\/10.1109\/COMST.2017.2749442","journal-title":"IEEE Commun Surv Tutor"},{"key":"3703_CR63","doi-asserted-by":"publisher","unstructured":"Watkins L, Beck S, Zook J, Buczak A, Chavis J, Robinson WH, Morales JA, Mishra S (2017) Using semi-supervised machine learning to address the big data problem in DNS networks. In: 2017 IEEE 7th annual computing and communication workshop and conference, pp 1\u20136. \nhttps:\/\/doi.org\/10.1109\/CCWC.2017.7868376","DOI":"10.1109\/CCWC.2017.7868376"},{"key":"3703_CR64","unstructured":"Woodbridge J, Anderson HS, Ahuja A, Grant D (2016) Predicting domain generation algorithms with long short-term memory networks. CoRR abs\/1611.0. URL \nhttp:\/\/arxiv.org\/abs\/1611.00791"},{"key":"3703_CR65","doi-asserted-by":"publisher","unstructured":"Xu S, Li S, Meng K, Wu L, Ding M (2017) An adaptive malicious domain detection mechanism with DNS traffic. In: 2017 VI international conference on network, communication and computing, pp 86\u201391. \nhttps:\/\/doi.org\/10.1145\/3171592.3171595","DOI":"10.1145\/3171592.3171595"},{"key":"3703_CR66","doi-asserted-by":"publisher","unstructured":"Yadav S, Reddy AKK, Reddy ALN, Ranjan S (2010) Detecting algorithmically generated malicious domain names. In: 10th ACM SIGCOMM conference on internet measurement, pp 48\u201361. \nhttps:\/\/doi.org\/10.1145\/1879141.1879148","DOI":"10.1145\/1879141.1879148"},{"key":"3703_CR67","doi-asserted-by":"publisher","unstructured":"Zhang S, Zhang X, Ou X (2014) After we knew it: empirical study and modeling of cost-effectiveness of exploiting prevalent known vulnerabilities across IaaS cloud. In: 9th ACM symposium on information, computer and communications security, pp 317\u2013328. \nhttps:\/\/doi.org\/10.1145\/2590296.2590300","DOI":"10.1145\/2590296.2590300"},{"key":"3703_CR68","unstructured":"Zhang H, Gharaibeh M, Thanasoulas S, Papadopoulos C (2016) BotDigger: detecting DGA Bots in a single network. Tech. rep., Colorado State University. URL \nhttp:\/\/www.cs.colostate.edu\/TechReports\/Reports\/2016\/tr16-101.pdf"}],"container-title":["Soft Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00500-018-03703-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00500-018-03703-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00500-018-03703-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,3,24]],"date-time":"2020-03-24T01:16:47Z","timestamp":1585012607000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00500-018-03703-8"}},"subtitle":["Efficient feature discovery process in machine learning techniques"],"short-title":[],"issued":{"date-parts":[[2019,1,18]]},"references-count":68,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2020,4]]}},"alternative-id":["3703"],"URL":"https:\/\/doi.org\/10.1007\/s00500-018-03703-8","relation":{},"ISSN":["1432-7643","1433-7479"],"issn-type":[{"value":"1432-7643","type":"print"},{"value":"1433-7479","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,1,18]]},"assertion":[{"value":"18 January 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"The authors declare that they do not have any conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}