{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,2]],"date-time":"2025-10-02T06:02:25Z","timestamp":1759384945186,"version":"3.37.3"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2017,10,9]],"date-time":"2017-10-09T00:00:00Z","timestamp":1507507200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2018,7]]},"DOI":"10.1007\/s10922-017-9436-x","type":"journal-article","created":{"date-parts":[[2017,10,9]],"date-time":"2017-10-09T11:53:18Z","timestamp":1507549998000},"page":"616-639","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Cluster Ensemble with Link-Based Approach for Botnet Detection"],"prefix":"10.1007","volume":"26","author":[{"given":"Long","family":"Mai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2068-633X","authenticated-orcid":false,"given":"Dong Kun","family":"Noh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,10,9]]},"reference":[{"key":"9436_CR1","unstructured":"http:\/\/www.symantec.com\/"},{"key":"9436_CR2","unstructured":"http:\/\/www.mcafee.com\/"},{"key":"9436_CR3","unstructured":"Gu, G., Porras, P.A., Yegneswaran, V., Fong, M.W., Lee, W.: Bothunter: detecting malware infection through ids-driven dialog correlation. In: Usenix Security, vol. 7, pp. 1\u201316 (2007)"},{"key":"9436_CR4","first-page":"229","volume":"99","author":"M Roesch","year":"1999","unstructured":"Roesch, M., et al.: Snort: lightweight intrusion detection for networks. LISA 99, 229\u2013238 (1999)","journal-title":"LISA"},{"issue":"3","key":"9436_CR5","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1109\/SURV.2010.032210.00054","volume":"12","author":"A Sperotto","year":"2010","unstructured":"Sperotto, A., Schaffrath, G., Sadre, R., Morariu, C., Pras, A., Stiller, B.: An overview of ip flow-based intrusion detection. IEEE Commun. Surv. Tutor. 12(3), 343\u2013356 (2010)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"9436_CR6","doi-asserted-by":"crossref","unstructured":"Stevanovic, M., Pedersen, J.M.: An efficient flow-based botnet detection using supervised machine learning. In: 2014 International Conference on Computing, Networking and Communications (ICNC), pp. 797\u2013801. IEEE (2014)","DOI":"10.1109\/ICCNC.2014.6785439"},{"key":"9436_CR7","doi-asserted-by":"crossref","unstructured":"Haddadi, F., Zincir-Heywood, A.N.: Botnet detection system analysis on the effect of botnet evolution and feature representation. In: Proceedings of the Companion Publication of the 2015 Annual Conference on Genetic and Evolutionary Computation, pp. 893\u2013900. ACM (2015)","DOI":"10.1145\/2739482.2768435"},{"issue":"8","key":"9436_CR8","doi-asserted-by":"crossref","first-page":"1796","DOI":"10.1109\/TCYB.2015.2490802","volume":"46","author":"OY Al-Jarrah","year":"2016","unstructured":"Al-Jarrah, O.Y., Alhussein, O., Yoo, P.D., Muhaidat, S., Taha, K., Kim, K.: Data randomization and cluster-based partitioning for botnet intrusion detection. IEEE Trans. Cybern. 46(8), 1796\u20131806 (2016)","journal-title":"IEEE Trans. Cybern."},{"key":"9436_CR9","volume-title":"Data Mining: Practical Machine Learning Tools and Techniques","author":"IH Witten","year":"2005","unstructured":"Witten, I.H., Frank, E.: Data Mining: Practical Machine Learning Tools and Techniques. Morgan Kaufmann, Los Altos (2005)"},{"issue":"12","key":"9436_CR10","doi-asserted-by":"crossref","first-page":"2396","DOI":"10.1109\/TPAMI.2011.84","volume":"33","author":"N Iam-On","year":"2011","unstructured":"Iam-On, N., Boongoen, T., Garrett, S., Price, C.: A link-based approach to the cluster ensemble problem. IEEE Trans. Pattern Anal. Mach. Intell. 33(12), 2396\u20132409 (2011)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"9436_CR11","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1016\/j.cose.2013.04.007","volume":"39","author":"D Zhao","year":"2013","unstructured":"Zhao, D., Traore, I., Sayed, B., Lu, W., Saad, S., Ghorbani, A., Garant, D.: Botnet detection based on traffic behavior analysis and flow intervals. Comput. Secur. 39, 2\u201316 (2013)","journal-title":"Comput. Secur."},{"issue":"2","key":"9436_CR12","doi-asserted-by":"crossref","first-page":"378","DOI":"10.1016\/j.comnet.2012.07.021","volume":"57","author":"SSC Silva","year":"2013","unstructured":"Silva, S.S.C., Silva, R.M.P., Pinto, R.C.G., Salles, R.M.: Botnets: a survey. Comput. Netw. 57(2), 378\u2013403 (2013)","journal-title":"Comput. Netw."},{"key":"9436_CR13","doi-asserted-by":"crossref","unstructured":"Saad, S., Traore, I., Ghorbani, A., Sayed, B., Zhao, D., Lu, W., Felix, J., Hakimian, P.: Detecting p2p botnets through network behavior analysis and machine learning. In: 2011 Ninth Annual International Conference on Privacy, Security and Trust (PST), pp. 174\u2013180. IEEE (2011)","DOI":"10.1109\/PST.2011.5971980"},{"issue":"3","key":"9436_CR14","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"Shiravi, A., Shiravi, H., Tavallaee, M., Ghorbani, A.A.: Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput. Secur. 31(3), 357\u2013374 (2012)","journal-title":"Comput. Secur."},{"key":"9436_CR15","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garcia","year":"2014","unstructured":"Garcia, S., Grill, M., Stiborek, J., Zunino, A.: An empirical comparison of botnet detection methods. Comput. Secur. 45, 100\u2013123 (2014)","journal-title":"Comput. Secur."},{"issue":"4","key":"9436_CR16","doi-asserted-by":"crossref","first-page":"1390","DOI":"10.1109\/JSYST.2014.2364743","volume":"10","author":"F Haddadi","year":"2016","unstructured":"Haddadi, F., Zincir-Heywood, A.N.: Benchmarking the effect of flow exporters and protocol filters on botnet traffic classification. IEEE Sys. J. 10(4), 1390\u20131401 (2016)","journal-title":"IEEE Sys. J."},{"issue":"8","key":"9436_CR17","doi-asserted-by":"crossref","first-page":"651","DOI":"10.1016\/j.patrec.2009.09.011","volume":"31","author":"AK Jain","year":"2010","unstructured":"Jain, A.K.: Data clustering: 50 years beyond k-means. Pattern Recogn. Lett. 31(8), 651\u2013666 (2010)","journal-title":"Pattern Recogn. Lett."},{"key":"9436_CR18","doi-asserted-by":"crossref","unstructured":"Kuncheva, L.I., Hadjitodorov, S.T.: Using diversity in cluster ensembles. In: 2004 IEEE International Conference on Systems, Man and Cybernetics, vol.\u00a02, pp. 1214\u20131219. IEEE (2004)","DOI":"10.1109\/ICSMC.2004.1399790"},{"issue":"Dec","key":"9436_CR19","first-page":"583","volume":"3","author":"A Strehl","year":"2002","unstructured":"Strehl, A., Ghosh, J.: Cluster ensembles\u2014a knowledge reuse framework for combining multiple partitions. J. Mach. Learn. Res. 3(Dec), 583\u2013617 (2002)","journal-title":"J. Mach. Learn. Res."},{"issue":"12","key":"9436_CR20","doi-asserted-by":"crossref","first-page":"1866","DOI":"10.1109\/TPAMI.2005.237","volume":"27","author":"A Topchy","year":"2005","unstructured":"Topchy, A., Jain, A.K., Punch, W.: Clustering ensembles: models of consensus and weak partitions. IEEE Trans. Pattern Anal. Mach. Intell. 27(12), 1866\u20131881 (2005)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"11","key":"9436_CR21","doi-asserted-by":"crossref","first-page":"1798","DOI":"10.1109\/TPAMI.2006.226","volume":"28","author":"LI Kuncheva","year":"2006","unstructured":"Kuncheva, L.I., Vetrov, D.P.: Evaluation of stability of k-means cluster ensembles with respect to random initialization. IEEE Trans. Pattern Anal. Mach. Intell. 28(11), 1798\u20131808 (2006)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"3","key":"9436_CR22","doi-asserted-by":"crossref","first-page":"128","DOI":"10.1002\/sam.10008","volume":"1","author":"XZ Fern","year":"2008","unstructured":"Fern, X.Z., Lin, W.: Cluster ensemble selection. Stat. Anal. Data Min. 1(3), 128\u2013141 (2008)","journal-title":"Stat. Anal. Data Min."},{"key":"9436_CR23","doi-asserted-by":"crossref","DOI":"10.1201\/b12207","volume-title":"Ensemble Methods: Foundations and Algorithms","author":"Z-H Zhou","year":"2012","unstructured":"Zhou, Z.-H.: Ensemble Methods: Foundations and Algorithms. CRC press, Boca Raton (2012)"},{"key":"9436_CR24","unstructured":"Beigi, E.B., Jazi, H.H., Stakhanova, N., Ghorbani, A.A.: Towards effective feature selection in machine learning-based botnet detection approaches. In: 2014 IEEE Conference on Communications and Network Security (CNS), pp. 247\u2013255. IEEE (2014)"},{"key":"9436_CR25","unstructured":"The honeynet project. French chapter. http:\/\/www.honeynet.org\/chapters\/france (2011)"},{"key":"9436_CR26","doi-asserted-by":"crossref","unstructured":"Szab\u00f3, G., Orincsay, D., Malomsoky, S., Szab\u00f3, I.: On the validation of traffic classification algorithms. In: International Conference on Passive and Active Network Measurement, pp. 72\u201381. Springer (2008)","DOI":"10.1007\/978-3-540-79232-1_8"},{"key":"9436_CR27","unstructured":"Lawrence Berkeley National Laboratory and ICSI: LBNL\/ICSI enterprise tracing project. LBNL enterprise trace repository. http:\/\/www.icir.org\/enterprise-tracing (2005)"},{"key":"9436_CR28","doi-asserted-by":"crossref","unstructured":"Claise, B.: Specification of the IP flow information export (IPFIX) protocol for the exchange of IP traffic flow information. Technical report (2008)","DOI":"10.17487\/rfc5101"},{"key":"9436_CR29","doi-asserted-by":"crossref","unstructured":"Sadasivan, G., Brownlee, N., Claise, B., Quittek, J.: Architecture for IP flow information export. RFC 5470 (2009)","DOI":"10.17487\/rfc5470"},{"key":"9436_CR30","unstructured":"https:\/\/sourceforge.net\/projects\/tranalyzer\/"},{"issue":"6","key":"9436_CR31","doi-asserted-by":"crossref","first-page":"451","DOI":"10.1016\/j.peva.2010.01.001","volume":"67","author":"M Soysal","year":"2010","unstructured":"Soysal, M., Schmidt, E.G.: Machine learning algorithms for accurate flow-based network traffic classification: evaluation and comparison. Perform. Eval. 67(6), 451\u2013467 (2010)","journal-title":"Perform. Eval."},{"issue":"1","key":"9436_CR32","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1002\/widm.8","volume":"1","author":"W-Y Loh","year":"2011","unstructured":"Loh, W.-Y.: Classification and regression trees. Wiley Interdiscip. Rev. Data Min. Knowl. Discov. 1(1), 14\u201323 (2011)","journal-title":"Wiley Interdiscip. Rev. Data Min. Knowl. Discov."},{"key":"9436_CR33","volume-title":"C4. 5: Programs for Machine Learning","author":"JR Quinlan","year":"2014","unstructured":"Quinlan, J.R.: C4. 5: Programs for Machine Learning. Elsevier, New York (2014)"},{"key":"9436_CR34","doi-asserted-by":"crossref","DOI":"10.1142\/9097","volume-title":"Data Mining with Decision Trees: Theory and Applications","author":"L Rokach","year":"2014","unstructured":"Rokach, L., Maimon, O.: Data Mining with Decision Trees: Theory and Applications. World Scientific, Singapore (2014)"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10922-017-9436-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-017-9436-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-017-9436-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,4]],"date-time":"2019-10-04T07:15:01Z","timestamp":1570173301000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10922-017-9436-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,10,9]]},"references-count":34,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,7]]}},"alternative-id":["9436"],"URL":"https:\/\/doi.org\/10.1007\/s10922-017-9436-x","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"type":"print","value":"1064-7570"},{"type":"electronic","value":"1573-7705"}],"subject":[],"published":{"date-parts":[[2017,10,9]]}}}