{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T01:10:03Z","timestamp":1748999403248,"version":"3.41.0"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2016,7,12]],"date-time":"2016-07-12T00:00:00Z","timestamp":1468281600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2017,10]]},"DOI":"10.1007\/s10207-016-0342-0","type":"journal-article","created":{"date-parts":[[2016,7,12]],"date-time":"2016-07-12T05:11:27Z","timestamp":1468300287000},"page":"459-473","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Spatio-Temporal malware and country clustering algorithm: 2012 IIJ MITF case study"],"prefix":"10.1007","volume":"16","author":[{"given":"Khamphao","family":"Sisaat","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Surin","family":"Kittitornkun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hiroaki","family":"Kikuchi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chaxiong","family":"Yukonhiatou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Masato","family":"Terada","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hiroshi","family":"Ishii","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,7,12]]},"reference":[{"key":"342_CR1","unstructured":"Symantec, Internet Security Threat Report, vol. 20, p. 119 (2015)"},{"issue":"1","key":"342_CR2","first-page":"68","volume":"6","author":"N Singh","year":"2015","unstructured":"Singh, N., Khurmi, S.S.: Malware analysis, clustering and classification: a literature review. Int. J. Comput. Sci. Technol. 6(1), 68\u201372 (2015)","journal-title":"Int. J. Comput. Sci. Technol."},{"issue":"2","key":"342_CR3","doi-asserted-by":"publisher","first-page":"56","DOI":"10.4236\/jis.2014.52006","volume":"5","author":"E Gandotra","year":"2014","unstructured":"Gandotra, E., Bansal, D., Sofat, S.: Malware analysis and classification: a survey. J. Inf. Secur. 5(2), 56\u201364 (2014). doi: 10.4236\/jis.2014.52006","journal-title":"J. Inf. Secur."},{"key":"342_CR4","unstructured":"McAfee, A Look at One Day of Malware Samples, http:\/\/blogs.mcafee.com\/mcafee-labs\/a-look-at-one-day-of-malware-samples . Accessed Feb 2014 (2011)"},{"key":"342_CR5","unstructured":"Perdisci, R., Lee, W., Feamster, N.: Behavioral clustering of http-based malware and signature generation using malicious network traces. In: NSDI\u201910 Proceedings of the 7th USENIX Conference on Networked Systems Design and Implementation, p. 14 (2010)"},{"key":"342_CR6","first-page":"21","volume":"1","author":"F Pouget","year":"2006","unstructured":"Pouget, F., Dacier, M., Zimmerman, J., Clark, A., Mohay, G.: Internet attack knowledge discovery via clusters and cliques of attack traces. J. Inf. Assur. Secur. 1, 21\u201332 (2006)","journal-title":"J. Inf. Assur. Secur."},{"key":"342_CR7","unstructured":"Wicherski, G.: pehash: A novel approach to fast malware clustering. In: LEET\u201909 Proceedings of the 2nd USENIX Conference on Large-scale Exploits and Emergent Threats: Botnets, Spyware, Worms, and More, p. 8 (2009)"},{"key":"342_CR8","doi-asserted-by":"crossref","unstructured":"Apel, M., Bockermann, C., Meier, M.: Measuring similarity of malware behavior. In: The 5th LCN Workshop on Security in Communications Networks (SICK 2009), pp. 891\u2013898 (2009)","DOI":"10.1109\/LCN.2009.5355037"},{"key":"342_CR9","unstructured":"Bayer, U., Comparetti, P.\u00a0M., Hlauschek, C., Kruegel, C., Kirda, E.: Scalable, behavior-based malware clustering. In: Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS 2009), p. 18 (2009)"},{"issue":"3","key":"342_CR10","doi-asserted-by":"publisher","first-page":"502","DOI":"10.1016\/j.comcom.2010.04.007","volume":"34","author":"W Lu","year":"2011","unstructured":"Lu, W., Rammidi, G., Ghorbani, A.A.: Clustering botnet communication traffic based on n-gram feature selection. Comput. Commun. 34(3), 502\u2013514 (2011). doi: 10.1016\/j.comcom.2010.04.007","journal-title":"Comput. Commun."},{"issue":"1","key":"342_CR11","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1016\/j.comnet.2011.07.018","volume":"56","author":"H Choi","year":"2012","unstructured":"Choi, H., Lee, H.: Identifying botnets by capturing group activities in dns traffic. Comput. Netw. 56(1), 20\u201333 (2012). doi: 10.1016\/j.comnet.2011.07.018","journal-title":"Comput. Netw."},{"key":"342_CR12","doi-asserted-by":"crossref","unstructured":"Chandramohan, M., Tan, H.B.K., Shar, L.K.: Scalable malware clustering through coarse-grained behavior modeling. In: FSE\u201912 Proceedings of the ACM SIGSOFT 20th International Symposium on the Foundations of Software Engineering, p. 4 (2012)","DOI":"10.1145\/2393596.2393627"},{"key":"342_CR13","doi-asserted-by":"crossref","unstructured":"Rafique, M.Z., Caballero, J.: Firma: malware clustering and network signature generation with mixed network behaviors. In: Proceedings of the 16th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2013), pp. 144\u2013163 (2013)","DOI":"10.1007\/978-3-642-41284-4_8"},{"issue":"1","key":"342_CR14","doi-asserted-by":"publisher","first-page":"49","DOI":"10.7763\/JACN.2015.V3.141","volume":"3","author":"P Barthakur","year":"2015","unstructured":"Barthakur, P., Dahal, M., Ghose, M.K.: Clusibothealer: botnet detection through similarity analysis of clusters. J. Adv. Comput. Netw. 3(1), 49\u201355 (2015). doi: 10.7763\/JACN.2015.V3.141","journal-title":"J. Adv. Comput. Netw."},{"key":"342_CR15","doi-asserted-by":"crossref","unstructured":"Bailey, M., Oberheide, J., Andersen, J., Mao, Z.\u00a0M., Jahanian, F., Nazario, J.: Automated classification and analysis of internet malware. In: Proceedings of RAID (2007)","DOI":"10.1007\/978-3-540-74320-0_10"},{"key":"342_CR16","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Vamo, M.U.: Towards a fully automated malware clustering validity analysis. In: Annual Computer Security Applications Conference, pp. 329\u2013338 (2012)","DOI":"10.1145\/2420950.2420999"},{"key":"342_CR17","doi-asserted-by":"crossref","unstructured":"Yukonhiatou, C., Kittitornkun, S., Kikuchi, H., Sisaat, K., Terada, M., Ishii, H.: Clustering top 10 malware\/bots based on temporal behavior. In: International Conference on Information Technology and Electrical Engineering, pp. 62\u201367 (2013)","DOI":"10.1109\/ICITEED.2013.6676212"},{"key":"342_CR18","unstructured":"Hu, X., Bhatkar, S., Griffin, K., Shin, K.\u00a0G.: Mutantx-s: Scalable malware clustering based on static features. In: 2013 USENIX Annual Technical Conference (USENIX ATC\u201913), pp. 187\u2013198 (2013)"},{"key":"342_CR19","doi-asserted-by":"publisher","unstructured":"Biggio, B., Rieck, K., Ariu, D., Wressnegger, C., Corona, I., Giacinto, G., Roli, F.: Poisoning behavioral malware clustering. In: AISec\u201914 Proceedings of the 2014 Workshop on Artificial Intelligent and Security Workshop, pp. 27\u201336 (2014). doi: 10.1145\/2666652.2666666","DOI":"10.1145\/2666652.2666666"},{"key":"342_CR20","doi-asserted-by":"publisher","unstructured":"Thomas, M., Mohaisen, A.: Kindred domains: detecting and clustering botnet domains using dns traffic. In: WWW\u201914 Companion Proceedings of the 23rd International Conference on World Wide Web, pp. 707\u2013712 (2014). doi: 10.1145\/2567948.2579359","DOI":"10.1145\/2567948.2579359"},{"key":"342_CR21","doi-asserted-by":"publisher","unstructured":"Narra, U., Troia, F.D., Corrado, V.A., Austin, T.H., Stamp, M.: Clustering versus svm for malware detection. J. Comput. Virol. Hacking Tech. (2015). doi: 10.1007\/s11416-015-0253-z","DOI":"10.1007\/s11416-015-0253-z"},{"key":"342_CR22","doi-asserted-by":"crossref","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, p. 12 (2006)","DOI":"10.1145\/1177080.1177086"},{"key":"342_CR23","unstructured":"Trend Micro, Taxonomy of Botnet Threats, A Trend Micro White Paper (p. 15 pages, November 2006)"},{"issue":"2","key":"342_CR24","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1109\/TDSC.2008.35","volume":"7","author":"P Wang","year":"2010","unstructured":"Wang, P., Sparks, S., Zou, C.C.: An advanced hybrid peer-to-peer botnet. IEEE Trans. Dependable Secure Comput. 7(2), 113\u2013127 (2010). doi: 10.1109\/TDSC.2008.35","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"342_CR25","doi-asserted-by":"crossref","unstructured":"Rossow, C., Andriesse, D., Werner, T., Stone-Gross, B., Plohmann, D., Dietrich, C.J., Bos, H.: Sok: P2pwned\u2014modeling and evaluating the resilience of peer-to-peer botnets. In: IEEE Symposium on Security and Privacy, pp. 97\u2013111 (2013)","DOI":"10.1109\/SP.2013.17"},{"key":"342_CR26","unstructured":"Grizzard, J.B., Sharma, V., Nunnery, C., Kang, B.B., Dagon, D.: Peer-to-peer botnets: Overview and case study. In: Proceedings of the First Workshop on Hot Topics in Understanding Botnets, p. 8 (2007)"},{"key":"342_CR27","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection. In: Proceedings of the 17th Conference on Security Symposium, pp. 139\u2013154 (2008)"},{"key":"342_CR28","unstructured":"Internet Initiative Japan Inc., Malware Investigation Task Force, https:\/\/sect.iij.ad.jp\/en\/mitf.html . Accessed Jan 2014"},{"key":"342_CR29","unstructured":"IIJ, Internet Infrastructure Review, vol. 5 (2011)"},{"key":"342_CR30","unstructured":"MWS, Anti malware engineering workshop 2012 (MWS-2012), http:\/\/www.iwsec.org\/mws\/2012\/about.html . Accessed Apr 2014 (2012)"},{"key":"342_CR31","unstructured":"Pouget, F., Dacier, M.: Honeypot-based forensics. In: Proceeding of AusCERT Asia Pacific Information Technology Security Conference 2004 (AusCERT2004) (2004)"},{"key":"342_CR32","unstructured":"Hatada, M., Nakatsuru, Y., Akiyama, M., Miwa, S.: Datasets for anti-malware research\u2014mws 2010 datasets, IPSJ Malware Workshop (MWS 2010) (1\u20135) (2010)"},{"key":"342_CR33","unstructured":"Hatada, M., Nakatsuru, Y., Akiyama, M.: Datasets for anti-malware research\u2014mws 2011 datasets, IPSJ Malware Workshop (MWS 2011)\u00a0(1\u20135) (2011)"},{"key":"342_CR34","unstructured":"Dagon, D., Zou, C., Lee, W.: Modeling botnet propagation using time zones. In: Proceedings of the 13th Network and Distributed System Security Symposium NDSS, p. 15 (2006)"},{"key":"342_CR35","doi-asserted-by":"publisher","unstructured":"Sisaat, K., Kikuchi, H., Matsuo, S., Terada, M., Fujiwara, M., Kittitornkun, S.: Time zone correlation analysis of malware\/bot downloads. In: IEICE Transactions on Communications E96-B, No. 07, 1753\u20131763 (2013). doi: 10.1587\/transcom.E96.B.1753","DOI":"10.1587\/transcom.E96.B.1753"},{"key":"342_CR36","doi-asserted-by":"crossref","unstructured":"Mezzour, G., Carley, L.R., Carley, K.M.: Global mapping of cyber attacks, cmu-isr-14-111, p. 32 (2014)","DOI":"10.2139\/ssrn.2729302"},{"key":"342_CR37","unstructured":"Asghari, H., Ciere, M., van Eeten, M.J.: Post-mortem of a zombie: Conficker cleanup after six years. In: 24th USENIX Security Symposium (USENIX Security 15), pp. 1\u201316 (2015)"},{"key":"342_CR38","unstructured":"MaxMind, GeoIP Databases. http:\/\/www.maxmind.com\/en\/city?pkit_lang=en . Accessed Jan 2014"},{"key":"342_CR39","unstructured":"VirusTotal, http:\/\/www.virustotal.com\/ . Accessed Mar 2014"},{"key":"342_CR40","unstructured":"Bach Seat, Conficker Worm - Still Alive, http:\/\/rbach.net\/blog\/index.php\/conficker-worm-still-alive\/ . Accessed Oct 2015 (2014)"},{"key":"342_CR41","unstructured":"F-Secure, Threat Report H1 2014, https:\/\/www.f-secure.com\/documents\/996508\/1030743\/Threat_Report_H1_2014.pdf . Accessed Oct 2015 (2014)"},{"issue":"2","key":"342_CR42","doi-asserted-by":"publisher","first-page":"676","DOI":"10.1109\/TIFS.2011.2173486","volume":"7","author":"S Shin","year":"2012","unstructured":"Shin, S., Gu, G., Reddy, N., Lee, C.P.: A large-scale empirical study of conficker. IEEE Trans. Inf. Forensics Secur. 7(2), 676\u2013690 (2012). doi: 10.1109\/TIFS.2011.2173486","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"342_CR43","doi-asserted-by":"crossref","unstructured":"Moura, G.C.M., Lone, Q., Asghari, H., van Eeten, M.J.: Evaluating the impact of abusehub on botnet mitigation interim deliverable 1.0. Master\u2019s thesis, Delft University of Technology (2015)","DOI":"10.1109\/IFIPNetworking.2015.7145335"},{"key":"342_CR44","unstructured":"M3AAWG, Anti-Phishing Best Practices for ISPs and Mailbox Providers, Version 2.01 (2015)"},{"key":"342_CR45","unstructured":"TRIPWIRE, SOHO Wireless Router (IN)security (2014)"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-016-0342-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0342-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0342-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0342-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T00:39:01Z","timestamp":1748997541000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-016-0342-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,7,12]]},"references-count":45,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2017,10]]}},"alternative-id":["342"],"URL":"https:\/\/doi.org\/10.1007\/s10207-016-0342-0","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"type":"print","value":"1615-5262"},{"type":"electronic","value":"1615-5270"}],"subject":[],"published":{"date-parts":[[2016,7,12]]}}}