{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T06:57:22Z","timestamp":1788245842428,"version":"build-2803163510"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2019,10,23]],"date-time":"2019-10-23T00:00:00Z","timestamp":1571788800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2019,10,23]],"date-time":"2019-10-23T00:00:00Z","timestamp":1571788800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2020,10]]},"DOI":"10.1007\/s10207-019-00475-6","type":"journal-article","created":{"date-parts":[[2019,10,23]],"date-time":"2019-10-23T16:36:33Z","timestamp":1571848593000},"page":"567-577","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":108,"title":["A novel graph-based approach for IoT botnet detection"],"prefix":"10.1007","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2710-5326","authenticated-orcid":false,"given":"Huy-Trung","family":"Nguyen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Quoc-Dung","family":"Ngo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Van-Hoang","family":"Le","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,10,23]]},"reference":[{"issue":"9","key":"475_CR1","doi-asserted-by":"publisher","first-page":"2796","DOI":"10.3390\/s18092796","volume":"18","author":"M Burhan","year":"2018","unstructured":"Burhan, M., Rehman, R.A., Khan, B., Kim, B.-S.: IoT elements, layered architectures and security issues: a comprehensive survey. Sensors 18(9), 2796 (2018)","journal-title":"Sensors"},{"issue":"9","key":"475_CR2","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1016\/S1361-3723(15)30084-1","volume":"2015","author":"C Tankard","year":"2015","unstructured":"Tankard, C.: Digital pathways, the security issues of the internet of things. Comput Fraud Secur 2015(9), 11\u201314 (2015)","journal-title":"Comput Fraud Secur"},{"key":"475_CR3","unstructured":"Gartner. \nhttps:\/\/www.gartner.com\/newsroom\/id\/3291817\n\n. Accessed 10 Feb 2019"},{"key":"475_CR4","unstructured":"New trends in the world of IoT threats. \nhttps:\/\/securelist.com\/new-trends-in-the-world-of-iot-threats\/87991\n\n. Accessed 10 May 2019"},{"key":"475_CR5","unstructured":"Angrishi, K.: Turning Internet of Things (IoT) into Internet of Vulnerabilities (IoV): IoT Botnets, preprint (2017). \narXiv:1702.03681"},{"key":"475_CR6","volume-title":"DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation. Journal Security and Communication Networks","author":"Michele De Donno","year":"2018","unstructured":"De Donno, Michele, Dragon, Nicola, Giaretta, Alberto: DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation. Journal Security and Communication Networks. Wiley, London (2018)"},{"key":"475_CR7","first-page":"522","volume":"24","author":"YMP Pa","year":"2016","unstructured":"Pa, Y.M.P., Suzuki, S., Yoshioka, K., Matsumoto, T., Kasama, T., Rossow, C.: IoTPOT: a novel honenypot for revealing current IoT threats. J. Inf. Process. 24, 522\u2013533 (2016)","journal-title":"J. Inf. Process."},{"key":"475_CR8","doi-asserted-by":"crossref","unstructured":"Tran, N.-P. et al.: Towards malware detection in routers with C500-toolkit. In: 5th International Conference on Information and Communication Technology (ICoIC7). IEEE, pp. 1\u20135 (2017)","DOI":"10.1109\/ICoICT.2017.8074691"},{"key":"475_CR9","unstructured":"Hampton, N., Szewczyk, P.: A survey and method for analysing SOHO router firmware currency. In: 13th Australian Information Security Management Conference, pp. 11-27 (2015)"},{"key":"475_CR10","doi-asserted-by":"crossref","unstructured":"Alhanahnah, M., Lin, Q., Yan, Q.: Efficient signature generation for classifying cross-architecture IoT malware. In: Conference on Communications and Network Security (CNS). IEEE, pp. 1\u20139 (2018)","DOI":"10.1109\/CNS.2018.8433203"},{"key":"475_CR11","doi-asserted-by":"crossref","unstructured":"Isawa, R.: Evaluating disassembly-code based similarity between IoT malware samples. In: 2018 13th Asia Joint Conference on Information Security (AsiaJCIS). IEEE, pp. 89\u201394 (2018)","DOI":"10.1109\/AsiaJCIS.2018.00023"},{"key":"475_CR12","doi-asserted-by":"crossref","unstructured":"Su, J., Vasconcellos D., Prasad, S., Sgandurra, D., Feng, Y., Sakurai, K.:Lightweight classification of IoT malware based on image recognition. In: 2018 42nd Annual Computer Software and Applications Conference (COMPSAC). IEEE, pp. 664\u2013669 (2018)","DOI":"10.1109\/COMPSAC.2018.10315"},{"key":"475_CR13","doi-asserted-by":"crossref","unstructured":"Chang, K.-C., Tso, R., Tsai, M.-C.: IoT sandbox: to analysis IoT malware Zollard. In: Proceedings of the Second International Conference on Internet of things and Cloud Computing. ACM, pp. 4\u201312 (2017)","DOI":"10.1145\/3018896.3018898"},{"key":"475_CR14","doi-asserted-by":"crossref","unstructured":"McDermott, C.D., Majdani, F., Petrovski, A.V.: Botnet detection in the internet of things using deep learning approaches. In: International Joint Conference on Neural Networks (IJCNN). IEEE, pp. 1\u20138 (2018)","DOI":"10.1109\/IJCNN.2018.8489489"},{"key":"475_CR15","doi-asserted-by":"crossref","unstructured":"Nath, H.V., Mehtre, B.M.: Static malware analysis using machine learning methods. In: Security in Computer Networks and Distributed Systems (SNDS). Springer, Berlin, pp. 440\u2013450 (2014)","DOI":"10.1007\/978-3-642-54525-2_39"},{"key":"475_CR16","doi-asserted-by":"crossref","unstructured":"Kang, B., Yang, J., So, J., Kim, C.Y.: Detecting trigger-based behaviors in botnet malware. In: Proceedings of the 2015 Conference on research in Adaptive and Convergent Systems. ACM, pp. 274\u2013279 (2015)","DOI":"10.1145\/2811411.2811485"},{"issue":"2","key":"475_CR17","doi-asserted-by":"publisher","first-page":"138","DOI":"10.14429\/dsj.66.9701","volume":"66","author":"A Kapoor","year":"2016","unstructured":"Kapoor, A., Dhavale, S.: Control flow graph based multiclass malware detection using bi-normal separation. Def. Sci. J. 66(2), 138\u2013145 (2016)","journal-title":"Def. Sci. J."},{"key":"475_CR18","doi-asserted-by":"crossref","unstructured":"Cozzi, E., Graziano, M., Fratantonio, Y., Balzarotti, D.: Understanding Linux Malware. In: Symposium on Security and Privacy. IEEE, pp. 870\u2013884 (2018)","DOI":"10.1109\/SP.2018.00054"},{"issue":"1","key":"475_CR19","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1109\/TSUSC.2018.2809665","volume":"4","author":"A Azmoodeh","year":"2018","unstructured":"Azmoodeh, A., Dehghantanha, A., Choo, K.K.R.: Robust malware detection for internet of (battlefield) things devices using deep eigenspace learning. IEEE Trans. Sustain. Comput. 4(1), 88\u201395 (2018)","journal-title":"IEEE Trans. Sustain. Comput."},{"issue":"2","key":"475_CR20","doi-asserted-by":"publisher","first-page":"646","DOI":"10.1016\/j.jnca.2012.10.004","volume":"36","author":"R Islam","year":"2013","unstructured":"Islam, R., Tian, R., Batten, L.M., Versteeg, S.: Classification of malware based on integrated static and dynamic features. J Netw. Comput. Appl. 36(2), 646\u2013656 (2013)","journal-title":"J Netw. Comput. Appl."},{"key":"475_CR21","doi-asserted-by":"crossref","unstructured":"Nguyen, H.T., Ngo, Q.D., Le, V.H.: IoT botnet detection approach based on PSI-graph and DGCNN classifier. In: International Conference on Information Communication and Signal Processing (ICICSP). IEEE, pp. 118\u2013122 (2018)","DOI":"10.1109\/ICICSP.2018.8549713"},{"key":"475_CR22","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1016\/j.future.2018.03.007","volume":"85","author":"H HaddadPajouh","year":"2018","unstructured":"HaddadPajouh, H., Dehghantanha, A., Khayami, R., Choo, K.K.R.: A deep recurrent neural network based approach for internet of things malware threat hunting. Future Gener. Comput. Syst. 85, 88\u201388 (2018)","journal-title":"Future Gener. Comput. Syst."},{"key":"475_CR23","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., Manjunath, B.S.: Malware images: visualization and automatic classification. In: Proceedings of the 8th International Symposium on Visualization for Cyber Security. ACM, pp. 4\u201311 (2011)","DOI":"10.1145\/2016904.2016908"},{"key":"475_CR24","doi-asserted-by":"crossref","unstructured":"Jung, B., Kim, T., Im, E.G.: Malware classification using byte sequence information. In: Proceedings of the Conference on Research in Adaptive and Convergent Systems. ACM, pp. 143\u2013148 (2018)","DOI":"10.1145\/3264746.3264775"},{"key":"475_CR25","doi-asserted-by":"crossref","unstructured":"Hachem, N., et al., Botnets: lifecycle and taxonomy. In: 2011 Conference on Network and Information Systems Security. IEEE, pp. 1\u20138 (2011)","DOI":"10.1109\/SAR-SSI.2011.5931395"},{"issue":"2","key":"475_CR26","doi-asserted-by":"publisher","first-page":"378","DOI":"10.1016\/j.comnet.2012.07.021","volume":"57","author":"SSC Silva","year":"2013","unstructured":"Silva, S.S.C., et al.: Botnets: a survey. Comput. Netw. 57(2), 378\u2013403 (2013)","journal-title":"Comput. Netw."},{"key":"475_CR27","doi-asserted-by":"crossref","unstructured":"Sudhakar, K., Kumar, S.: Botnet detection techniques and research challenges. In: International Conference on Advances in Energy-Efficient Computing and Communication (2019)","DOI":"10.1109\/ICRAECC43874.2019.8995028"},{"issue":"1","key":"475_CR28","first-page":"55","volume":"10","author":"E Khoshhalpour","year":"2018","unstructured":"Khoshhalpour, E., Shahriari, H.R.: BotRevealer: behavioral detection of botnets based on botnetlife-cycle. ISC Int. J. Inf. Secur. 10(1), 55\u201361 (2018)","journal-title":"ISC Int. J. Inf. Secur."},{"key":"475_CR29","doi-asserted-by":"crossref","unstructured":"Prokofiev, A.O. et al.: A method to detect internet of things botnets. In: Conference of Russian Young Researchers in Electrical and Electronic Engineering (EIConRus). IEEE, pp. 105\u2013108 (2018)","DOI":"10.1109\/EIConRus.2018.8317041"},{"key":"475_CR30","unstructured":"Narayanan, A. et al.: graph2vec: Learning Distributed Representations of Graphs, preprint (2017). \narXiv:1707.05005"},{"issue":"1","key":"475_CR31","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/s11416-012-0175-y","volume":"9","author":"M Xu","year":"2013","unstructured":"Xu, M., et al.: A similarity metric method of obfuscated malware using function-call graph. J. Comput. Virol. Hacking Tech. 9(1), 35\u201347 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"475_CR32","unstructured":"Detect-It-Easy. \nhttps:\/\/github.com\/horsicq\/Detect-It-Easy\n\n. Accessed 12 Feb 2019"},{"key":"475_CR33","unstructured":"The Ultimate Packer for eXecutables. \nhttps:\/\/github.com\/upx\n\n. Accessed 12 Feb 2019"},{"key":"475_CR34","volume-title":"The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler","author":"C Eagle","year":"2011","unstructured":"Eagle, C.: The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler. William Pollock, Clifton (2011)"},{"key":"475_CR35","unstructured":"Shang, S., Zheng, N., Xu, J., Xu, M., Zhang, H.: Detecting malware variants via function-call graph similarity. In: International Conference on Malicious and Unwanted Software. IEEE, pp. 113\u2013120 (2010)"},{"key":"475_CR36","doi-asserted-by":"crossref","unstructured":"Hallman, R., Bryan, J., Palavicini, G., Divita, J., Romero-Mariona, J.: IoDDoS-the internet of distributed denial of sevice attacks. In: Proceedings of the 2nd International Conference on Internet of Things, Big Data and Security (IoTBDS), pp. 47\u201358 (2017)","DOI":"10.5220\/0006246600470058"},{"key":"475_CR37","unstructured":"Le, Q., Mikolov, T.: Distributed Representations of Sentences and Documents. In: Proceedings of the 31st International Conference on Machine Learning, pp. 1188\u20131196 (2014)"},{"key":"475_CR38","unstructured":"DeepBench. \nhttps:\/\/github.com\/baidu-research\/DeepBench\n\n. Accessed 10 Feb 2019"},{"key":"475_CR39","doi-asserted-by":"crossref","unstructured":"Kim, Y.: Convolutional neural networks for sentence classification. In: Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (EMNLP). Association for Computational Linguistics, pp. 1746\u20131751 (2014)","DOI":"10.3115\/v1\/D14-1181"},{"key":"475_CR40","unstructured":"VirusShare. \nhttps:\/\/virusshare.com\n\n. Accessed 13 Jan 2019"},{"key":"475_CR41","unstructured":"Firmware Analysis Toolkit. \nhttps:\/\/github.com\/ReFirmLabs\/binwalk\n\n. Accessed 13 Jan 2019"},{"key":"475_CR42","unstructured":"OpenWrt. \nhttps:\/\/openwrt.org\/\n\n. Accessed 13 Jan 2019"},{"key":"475_CR43","unstructured":"Pytorch. \nhttps:\/\/github.com\/pytorch\/pytorch\n\n. Accessed 13 Jan 2019"},{"key":"475_CR44","unstructured":"VirusTotal. \nhttps:\/\/www.virustotal.com\n\n. Accessed 14 Jan 2019"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-019-00475-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-019-00475-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-019-00475-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,21]],"date-time":"2020-10-21T23:30:18Z","timestamp":1603323018000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-019-00475-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,10,23]]},"references-count":44,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2020,10]]}},"alternative-id":["475"],"URL":"https:\/\/doi.org\/10.1007\/s10207-019-00475-6","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,10,23]]},"assertion":[{"value":"23 October 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}