{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T15:51:01Z","timestamp":1785858661754,"version":"3.56.0"},"reference-count":62,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2014,6,21]],"date-time":"2014-06-21T00:00:00Z","timestamp":1403308800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2015,2]]},"DOI":"10.1007\/s10207-014-0248-7","type":"journal-article","created":{"date-parts":[[2014,6,20]],"date-time":"2014-06-20T05:27:39Z","timestamp":1403242059000},"page":"15-33","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":89,"title":["The MALICIA dataset: identification and analysis of drive-by download operations"],"prefix":"10.1007","volume":"14","author":[{"given":"Antonio","family":"Nappa","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M. Zubair","family":"Rafique","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Juan","family":"Caballero","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2014,6,21]]},"reference":[{"key":"248_CR1","unstructured":"Allatori java obfuscator. http:\/\/www.allatori.com\/"},{"key":"248_CR2","unstructured":"Anderson, D.S., Fleizach, C., Savage, S., Voelker, G.M.: Spamscatter: characterizing internet scam hosting infrastructure. In: USENIX Security Symposium, Boston, MA (August 2007)"},{"key":"248_CR3","unstructured":"An overview of exploit packs (update 20) Jan (2014) http:\/\/contagiodump.blogspot.com.es\/2010\/06\/overview-of-exploit-packs-update.html"},{"key":"248_CR4","doi-asserted-by":"crossref","unstructured":"Bailey, M., Oberheide, J., Andersen, J., Mao, Z., Jahanian, F., Nazario, J.: Automated classification and analysis of internet malware. In: International Symposium on Recent Advances in Intrusion Detection, Queensland, Australia (September 2007)","DOI":"10.1007\/978-3-540-74320-0_10"},{"key":"248_CR5","unstructured":"Bayer, U., Comparetti, P.M., Hlauschek, C., Kruegel, C., Kirda, E.: Scalable, behavior-based malware clustering. In: Network and Distributed System Security Symposium, San Diego, CA (February 2009)"},{"key":"248_CR6","unstructured":"Bfk: Passive dns replication. http:\/\/www.bfk.de\/bfk_dnslogger.html"},{"key":"248_CR7","unstructured":"Caballero, J., Grier, C., Kreibich, C., Paxson, V.: Measuring pay-per-install: the commoditization of malware distribution. In: USENIX Security Symposium, San Francisco, CA (August 2011)"},{"key":"248_CR8","unstructured":"Caida: As Ranking (October 2012). http:\/\/as-rank.caida.org"},{"key":"248_CR9","doi-asserted-by":"crossref","unstructured":"Canali, D., Balzarotti, D., Francillon, A.: The role of web hosting providers in detecting compromised websites. In: International World Wide Web Conference, Rio de Janeiro, Brazil (May 2013)","DOI":"10.1145\/2488388.2488405"},{"key":"248_CR10","unstructured":"Cho, C.Y., Caballero, J., Grier, C., Paxson, V., Song, D.: Insights from the inside: A view of botnet management from infiltration. In: USENIX Workshop on Large-Scale Exploits and Emergent Threats. San Jose, CA, April (2010)"},{"key":"248_CR11","doi-asserted-by":"crossref","unstructured":"Cova, M., Kruegel, C., Vigna, G.: Detection and analysis of drive-by-download attacks and malicious javascript code. In: International World Wide Web Conference, Raleigh, NC (April 2010)","DOI":"10.1145\/1772690.1772720"},{"key":"248_CR12","doi-asserted-by":"crossref","unstructured":"Crocker, D.: Mailbox Names for Common Services, Roles and Functions. RFC 2142 (May 1997)","DOI":"10.17487\/rfc2142"},{"key":"248_CR13","unstructured":"Curtsinger, C., Livshits, B., Zorn, B., Seifert, C.: Zozzle: low-overhead mostly static javascript malware detection. In: USENIX Security Symposium, San Francisco, CA (August 2011)"},{"key":"248_CR14","unstructured":"Cool exploit kit\u2014a new browser exploit pack. http:\/\/malware.dontneedcoffee.com\/2012\/10\/newcoolek.html\/"},{"key":"248_CR15","doi-asserted-by":"crossref","unstructured":"Daigle, L.: Whois Protocol Specification. RFC 3912 (September 2004)","DOI":"10.17487\/rfc3912"},{"key":"248_CR16","doi-asserted-by":"crossref","unstructured":"Dunn, J.C.: Well-separated clusters and optimal fuzzy partitions. J. Cybern. 4(1), 95\u2013104 (1974)","DOI":"10.1080\/01969727408546059"},{"key":"248_CR17","doi-asserted-by":"crossref","unstructured":"Falk, J.: Complaint Feedback Loop Operational Recommendations. RFC 6449 (November 2011)","DOI":"10.17487\/rfc6449"},{"key":"248_CR18","doi-asserted-by":"crossref","unstructured":"Falk, J., Kucherawy, M.: Creation and Use of Email Feedback Reports: An Applicability Statement for the Abuse Reporting Format (arf). RFC 6650 (June 2012)","DOI":"10.17487\/rfc6650"},{"key":"248_CR19","doi-asserted-by":"crossref","unstructured":"Grier, C., Ballard, L., Caballero, J., Chachra, N., Dietrich, C.J., Levchenko, K., Mavrommatis, P., McCoy, D., Nappa, A., Pitsillidis, A., Provos, N., Rafique, M.Z. Rajab, M.A., Rossow, C., Thomas, K., Paxson, V., Savage, S., Voelker, G.M.: Manufacturing compromise: the emergence of exploit-as-a-service. In: ACM Conference on Computer and Communications Security, Raleigh, NC (October 2012)","DOI":"10.1145\/2382196.2382283"},{"key":"248_CR20","doi-asserted-by":"crossref","unstructured":"Jang, J., Brumley, D., Venkataraman, S.: Bitshred: feature hashing malware for scalable triage and semantic analysis. In: ACM Conference on Computer and Communications Security. Chicago, IL (October 2011)","DOI":"10.1145\/2046707.2046742"},{"key":"248_CR21","unstructured":"John, J.P., Moshchuk, A., Gribble, S.D., Krishnamurthy, A.: Studying spamming botnets using Botlab. In: Symposium on Networked System Design and Implementation, Boston, MA (April 2009)"},{"key":"248_CR22","doi-asserted-by":"crossref","DOI":"10.1002\/9780470316801","volume-title":"Finding Groups in Data: An Introduction to Cluster Analysis","author":"L Kaufman","year":"1990","unstructured":"Kaufman, L., Rousseeuw, P.J.: Finding Groups in Data: An Introduction to Cluster Analysis, vol. 4. Wiley, New York (1990)"},{"key":"248_CR23","unstructured":"Krawetz, N.: Average Perceptual Hash (May 2011). http:\/\/www.hackerfactor.com\/blog\/index.php?\/archives\/432-Looks-Like-It.html"},{"key":"248_CR24","doi-asserted-by":"crossref","unstructured":"Kreibich, C., Weaver, N., Kanich, C., Cui, W., Paxson, V.: GQ: Practical containment for measuring modern malware systems. In: Internet Measurement Conference, Berlin, Germany (November 2011)","DOI":"10.1145\/2068816.2068854"},{"key":"248_CR25","unstructured":"Li, Z., Alrwais, S., Xie, Y., Yu, F., Wang, X.: Finding the linchpins of the dark web: a study on topologically dedicated hosts on malicious web infrastructures. In: IEEE Symposium on Security and Privacy, San Francisco, CA (May 2013)"},{"key":"248_CR26","unstructured":"Love vps http:\/\/www.lovevps.com\/"},{"key":"248_CR27","unstructured":"Malicia project http:\/\/malicia-project.com\/"},{"key":"248_CR28","unstructured":"Malware domain list http:\/\/malwaredomainlist.com\/"},{"key":"248_CR29","unstructured":"Morrison, T.: How Hosting Providers can Battle Fraudulent Sign-ups (October 2012). http:\/\/www.spamhaus.org\/news\/article\/687\/how-hosting-providers-can-battle-fraudulent-sign-ups"},{"key":"248_CR30","unstructured":"Moshchuk, A., Bragin, T., Gribble, S.D., Levy, H.M.: A crawler-based study of spyware on the web. In: Network and Distributed System Security Symposium, San Diego, CA (February 2006)"},{"key":"248_CR31","unstructured":"New Dutch Notice-and-Take-Down Code Raises Questions (October 2008). http:\/\/www.edri.org\/book\/export\/html\/1619"},{"key":"248_CR32","doi-asserted-by":"crossref","unstructured":"Nappa, A., Rafique, M.Z., Caballero, J.: Driving in the cloud: an analysis of drive-by download operations and abuse reporting. In: SIG SIDAR Conference on Detection of Intrusions and Malware & Vulnerability Assessment, Berlin, Germany (July 2013)","DOI":"10.1007\/978-3-642-39235-1_1"},{"key":"248_CR33","unstructured":"Nelms, T., Perdisci, R., Ahamad, M.: Execscent: mining for new c&c domains in live networks with adaptive control protocol templates. In: USENIX Security Symposium, Washington, DC (August 2013)"},{"key":"248_CR34","unstructured":"Perdisci, R., Lee, W., Feamster, N.: Behavioral clustering of http-based malware and signature generation using malicious network traces. In: Symposium on Networked System Design and Implementation, San Jose, CA (April 2010)"},{"key":"248_CR35","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Vamo, M.U.: Towards a fully automated malware clustering validity analysis. In: Annual Computer Security Applications Conference, Orlando, FL (December 2012)","DOI":"10.1145\/2420950.2420999"},{"key":"248_CR36","unstructured":"Polychronakis, M., Mavrommatis, P., Provos, N.: Ghost turns zombie: exploring the life cycle of web-based malware. In: USENIX Workshop on Large-Scale Exploits and Emergent Threats, San Francisco, CA (April 2008)"},{"key":"248_CR37","unstructured":"Provos, N., Mavrommatis, P., Rajab, M.A., Monrose, F.: All your iframes point to us. In: USENIX Security Symposium, San Jose, CA (July 2008)"},{"key":"248_CR38","unstructured":"Provos, N., McNamee, D., Mavrommatis, P., Wang, K., Modadugu, N.: The ghost in the browser: analysis of Web-based malware. In: USENIX Workshop on Hot Topics on Understanding Botnets, Cambridge, UK (April 2007)"},{"key":"248_CR39","doi-asserted-by":"crossref","unstructured":"Rafique, M.Z., Caballero, J.: Firma: Malware clustering and network signature generation with mixed network behaviors. In: International Symposium on Recent Advances in Intrusion Detection, St. Lucia (October 2013)","DOI":"10.1007\/978-3-642-41284-4_8"},{"key":"248_CR40","doi-asserted-by":"crossref","unstructured":"Rafique, M.Z., Huygens, C., Caballero, J.: Network Dialog Minimization and Network Dialog Diffing: Two Novel Primitives for Network Security Applications. Technical Report TR-IMDEA-SW-2014-001, IMDEA Software Institute, Madrid, Spain (March 2014). https:\/\/software.imdea.org\/~juanca\/papers\/TR-IMDEA-SW-2014-001.pdf","DOI":"10.1145\/2664243.2664261"},{"key":"248_CR41","unstructured":"Rieck, K., Holz, T., Willems, C., D\u00fcssel, P., Laskov, P.: Learning and classification of malware behavior. In: SIG SIDAR Conference on Detection of Intrusions and Malware & Vulnerability Assessment, Paris, France (July 2008)"},{"key":"248_CR42","doi-asserted-by":"crossref","unstructured":"Rossow, C., Dietrich, C.J.: Provex: Detecting botnets with encrypted command and control channels. In: SIG SIDAR Conference on Detection of Intrusions and Malware & Vulnerability Assessment, Berlin, Germany (July 2013)","DOI":"10.1007\/978-3-642-39235-1_2"},{"key":"248_CR43","doi-asserted-by":"crossref","unstructured":"Rossow, C., Dietrich, C.J., Bos, H., Cavallaro, L., van Steen, M., Freiling, F.C., Pohlmann, N.: Sandnet: network traffic analysis of malicious software. In: Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, Salzburg, Austria (April 2011)","DOI":"10.1145\/1978672.1978682"},{"key":"248_CR44","unstructured":"Ssdsandbox. http:\/\/xml.ssdsandbox.net\/dnslookup-dnsdb"},{"key":"248_CR45","doi-asserted-by":"crossref","unstructured":"Shafranovich, Y., Levine, J., Kucherawy, M.: An Extensible Format for Email Feedback Reports. RFC 5965 (August 2010). Updated by RFC 6650","DOI":"10.17487\/rfc5965"},{"key":"248_CR46","doi-asserted-by":"crossref","unstructured":"Shue, C., Kalafut, A.J., Gupta, M.: Abnormally malicious autonomous systems and their internet connectivity. IEEE\/ACM Transactions of Networking 20(1), (2012)","DOI":"10.1109\/TNET.2011.2157699"},{"key":"248_CR47","unstructured":"Snort http:\/\/www.snort.org\/"},{"key":"248_CR48","doi-asserted-by":"crossref","unstructured":"Stone-Gross, B., Christopher, Kruegel, Almeroth, K., Moser, A., Kirda, E.: Fire: Finding rogue networks. In: Annual Computer Security Applications Conference, Honolulu, HI (December 2009)","DOI":"10.1109\/ACSAC.2009.29"},{"key":"248_CR49","unstructured":"Suricata http:\/\/suricata-ids.org\/"},{"key":"248_CR50","unstructured":"The spamhaus project (October 2012) http:\/\/www.spamhaus.org\/"},{"key":"248_CR51","unstructured":"Urlquery. http:\/\/urlquery.net\/"},{"key":"248_CR52","unstructured":"Virustotal. http:\/\/www.virustotal.com\/"},{"key":"248_CR53","unstructured":"Walls, R.J., Levine, B.N., Liberatore, M., Shields, C.: Effective digital forensics research is investigator-centric. In: USENIX Workshop on Hot Topics in Security, San Francisco, CA (August 2011)"},{"key":"248_CR54","unstructured":"Wang, Y.-M., Beck, D., Jiang, X., Roussev, R., Verbowski, C., Chen, S., King, S.: Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities. In: Network and Distributed System Security Symposium, San Diego, CA (February 2006)"},{"key":"248_CR55","unstructured":"Wepawet. https:\/\/wepawet.iseclab.org\/"},{"key":"248_CR56","unstructured":"Wyke, J.: The Zeroaccess Botnet: Mining and Fraud for Massive Financial Gain (September 2012). http:\/\/www.sophos.com\/en-us\/why-sophos\/our-people\/technical-papers\/zeroaccess-botnet.asp:x"},{"key":"248_CR57","unstructured":"X-arf: Network abuse reporting 2.0. http:\/\/x-arf.org\/"},{"key":"248_CR58","unstructured":"Xylitol: Blackhole exploit kits update to v2.0 (September 2011). http:\/\/malware.dontneedcoffee.com\/2012\/09\/blackhole2.0.html"},{"key":"248_CR59","unstructured":"Xylitol: Tracking Cyber Crime: Hands Up Affiliate (Ransomware) (December 2011). http:\/\/www.xylibox.com\/2011\/12\/tracking-cyber-crime-affiliate.html"},{"key":"248_CR60","unstructured":"Zauner, C.: Implementation and Benchmarking of Perceptual Image Hash Functions. Master\u2019s thesis, Upper Austria University of Applied Sciences, Hagenberg, Austria (July 2010)"},{"key":"248_CR61","unstructured":"Zelix klassmaster heavy duty protection. http:\/\/www.zelix.com\/klassmaster\/"},{"key":"248_CR62","doi-asserted-by":"crossref","unstructured":"Zhang, J., Seifert, C., Stokes, J. W., Lee, W.: Arrow: Generating signatures to detect drive-by downloads. In: International World Wide Web Conference, Hyderabad, India (April 2011)","DOI":"10.1145\/1963405.1963435"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0248-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-014-0248-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0248-7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,11]],"date-time":"2019-08-11T19:12:35Z","timestamp":1565550755000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-014-0248-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,6,21]]},"references-count":62,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,2]]}},"alternative-id":["248"],"URL":"https:\/\/doi.org\/10.1007\/s10207-014-0248-7","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,6,21]]}}}