{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T23:22:08Z","timestamp":1780356128823,"version":"3.54.1"},"reference-count":49,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T00:00:00Z","timestamp":1648771200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T00:00:00Z","timestamp":1648771200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2022,7]]},"DOI":"10.1007\/s10922-022-09655-7","type":"journal-article","created":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T15:26:27Z","timestamp":1648826787000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["A Deep Learning Approach for Botnet Detection Using Raw Network Traffic Data"],"prefix":"10.1007","volume":"30","author":[{"given":"Mohaddeseh","family":"Shahhosseini","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0080-2743","authenticated-orcid":false,"given":"Hoda","family":"Mashayekhi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohsen","family":"Rezvani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,4,1]]},"reference":[{"key":"9655_CR1","unstructured":"Abadi, M., Barham, P., Chen, J., Chen, Z., Davis, A., Dean, J., Devin, M., Ghemawat, S., Irving, G., Isard, M.: Tensorflow: A system for large-scale machine learning. In: 12th {USENIX} symposium on operating systems design and implementation ({OSDI} 16). Pp. 265\u2013283 (2016)"},{"key":"9655_CR2","unstructured":"Beigi, E.B., Jazi, H.H., Stakhanova, N., Ghorbani, A.: A Towards effective feature selection in machine learning-based botnet detection approaches. In: 2014 IEEE Conference on Communications and Network Security. IEEE, pp. 247\u2013255 (2014)"},{"issue":"8","key":"9655_CR3","doi-asserted-by":"publisher","first-page":"1798","DOI":"10.1109\/TPAMI.2013.50","volume":"35","author":"Y Bengio","year":"2013","unstructured":"Bengio, Y., Courville, A., Vincent, P.: Representation learning: A review and new perspectives. IEEE Trans. Pattern Anal. Mach. Intell. 35(8), 1798\u20131828 (2013)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"9655_CR4","doi-asserted-by":"publisher","first-page":"502","DOI":"10.1016\/j.pisc.2016.05.008","volume":"8","author":"A Bijalwan","year":"2016","unstructured":"Bijalwan, A., Chand, N., Pilli, E.S., Krishna, C.R.: Botnet analysis using ensemble classifier. Perspect. Sci. 8, 502\u2013504 (2016)","journal-title":"Perspect. Sci."},{"key":"9655_CR5","doi-asserted-by":"crossref","unstructured":"Celik, Z.B., Walls, R.J., McDaniel, P., Swami, A. Malware traffic detection using tamper-resistant features. In: MILCOM 2015\u20132015 IEEE Military Communications Conference, pp. 330\u2013335 (2015)","DOI":"10.1109\/MILCOM.2015.7357464"},{"issue":"5","key":"9655_CR6","doi-asserted-by":"crossref","first-page":"e3999","DOI":"10.1002\/ett.3999","volume":"32","author":"X Dong","year":"2021","unstructured":"Dong, X., Dong, C., Chen, Z., Cheng, Y., Chen, B.: BotDetector: An extreme learning machine-based Internet of Things botnet detection model. Trans. Emerg. Telecommun. Technol. 32(5), e3999 (2021)","journal-title":"Trans. Emerg. Telecommun. Technol."},{"issue":"5","key":"9655_CR7","doi-asserted-by":"publisher","first-page":"2670","DOI":"10.1016\/j.eswa.2014.11.009","volume":"42","author":"AS Eesa","year":"2015","unstructured":"Eesa, A.S., Orman, Z., Brifcani, A.M.A.: A novel feature-selection approach based on the cuttlefish optimization algorithm for intrusion detection systems. Expert Syst. Appl. 42(5), 2670\u20132679 (2015)","journal-title":"Expert Syst. Appl."},{"key":"9655_CR8","doi-asserted-by":"crossref","unstructured":"Felix, J., Joseph, C., Ghorbani, A.: A Group behavior metrics for P2P Botnet detection. In: International Conference on Information and Communications Security, Springer, 93\u2013104 (2012)","DOI":"10.1007\/978-3-642-34129-8_9"},{"key":"9655_CR9","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1016\/j.future.2020.09.004","volume":"115","author":"JTM Garre","year":"2021","unstructured":"Garre, J.T.M., P\u00e9rez, M.G., Ruiz-Mart\u00ednez, A.: A novel Machine Learning-based approach for the detection of SSH botnet infection. Future Gener. Comput. Syst. 115, 387\u2013396 (2021)","journal-title":"Future Gener. Comput. Syst."},{"key":"9655_CR10","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1613\/jair.4992","volume":"57","author":"Y Goldberg","year":"2016","unstructured":"Goldberg, Y.: A primer on neural network models for natural language processing. J. Artif. Intell. Res. 57, 345\u2013420 (2016)","journal-title":"J. Artif. Intell. Res."},{"key":"9655_CR11","volume-title":"Deep Learning","author":"I Goodfellow","year":"2016","unstructured":"Goodfellow, I., Bengio, Y., Courville, A., Bengio, Y.: Deep Learning, vol. 1. MIT Press, Cambridge (2016)"},{"key":"9655_CR12","volume-title":"Deep Learning with Keras","author":"A Gulli","year":"2017","unstructured":"Gulli, A., Pal, S.: Deep Learning with Keras. Packt Publishing Ltd, Birmingham (2017)"},{"key":"9655_CR13","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1016\/j.cose.2017.10.011","volume":"73","author":"T Hamed","year":"2018","unstructured":"Hamed, T., Dara, R., Kremer, S.C.: Network intrusion detection system based on recursive feature addition and bigram technique. Comput. Secur. 73, 137\u2013155 (2018)","journal-title":"Comput. Secur."},{"issue":"8","key":"9655_CR14","doi-asserted-by":"publisher","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter, S., Schmidhuber, J.: Long short-term memory. Neural Comput. 9(8), 1735\u20131780 (1997)","journal-title":"Neural Comput."},{"key":"9655_CR15","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-319-73951-9_7","volume-title":"Cyber Threat Intelligence","author":"S Homayoun","year":"2018","unstructured":"Homayoun, S., Ahmadzadeh, M., Hashemi, S., Dehghantanha, A., Khayami, R.: BoTShark: A deep learning approach for botnet traffic detection. In: Cyber Threat Intelligence, pp. 137\u2013153. Springer, New York (2018)"},{"key":"9655_CR16","doi-asserted-by":"crossref","unstructured":"Hossain, M. I., Eshrak, S., Auvik, M. J., Nasim, S. F., Rab, R., Rahman, A.: Efficient Feature Selection for Detecting Botnets based on Network Traffic and Behavior Analysis .In 7th International Conference on Networking, Systems and Security, pp. 56\u201362 (2020).","DOI":"10.1145\/3428363.3428378"},{"key":"9655_CR17","first-page":"1","volume":"13","author":"S Hosseini","year":"2021","unstructured":"Hosseini, S., Nezhad, A.E., Seilani, H.: Botnet detection using negative selection algorithm, convolution neural network and classification methods. Evol. Syst. 13, 1\u201315 (2021)","journal-title":"Evol. Syst."},{"issue":"2","key":"9655_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.5121\/ijdkp.2015.5201","volume":"5","author":"M Hossin","year":"2015","unstructured":"Hossin, M., Sulaiman, M.N.: A review on evaluation metrics for data classification evaluations. Int. J Data Mining Knowl. Manag. Process 5(2), 1 (2015)","journal-title":"Int. J Data Mining Knowl. Manag. Process"},{"key":"9655_CR19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.comcom.2014.04.012","volume":"49","author":"N Hubballi","year":"2014","unstructured":"Hubballi, N., Suryanarayanan, V.: False alarm minimization techniques in signature-based intrusion detection systems: A survey. Comput. Commun. 49, 1\u201317 (2014)","journal-title":"Comput. Commun."},{"key":"9655_CR20","doi-asserted-by":"publisher","first-page":"109140","DOI":"10.1016\/j.measurement.2021.109140","volume":"176","author":"S Jagadeesan","year":"2021","unstructured":"Jagadeesan, S., Amutha, B.: An efficient botnet detection with the enhanced support vector neural network. Measurement 176, 109140 (2021)","journal-title":"Measurement"},{"key":"9655_CR21","doi-asserted-by":"crossref","unstructured":"Javaid, A., Niyaz, Q., Sun, W., Alam, M.: A deep learning approach for network intrusion detection system. In: Proceedings of the 9th EAI International Conference on Bio-inspired Information and Communications Technologies (formerly BIONETICS), 21\u201326 (2016)","DOI":"10.4108\/eai.3-12-2015.2262516"},{"issue":"4","key":"9655_CR22","doi-asserted-by":"publisher","first-page":"583","DOI":"10.3390\/sym11040583","volume":"11","author":"MA Khan","year":"2019","unstructured":"Khan, M.A., Karim, M., Kim, Y.: A scalable and hybrid intrusion detection system based on the convolutional-LSTM network. Symmetry 11(4), 583 (2019)","journal-title":"Symmetry"},{"key":"9655_CR23","doi-asserted-by":"crossref","unstructured":"Kheir, N., Wolley, C.: Botsuer: Suing stealthy p2p bots in network traffic through netflow analysis. In: International Conference on Cryptology and Network Security, Springer, 162\u2013178 (2013)","DOI":"10.1007\/978-3-319-02937-5_9"},{"key":"9655_CR24","doi-asserted-by":"crossref","unstructured":"Kim, K.: Aminanto ME Deep learning in intrusion detection perspective: Overview and further challenges. In: 2017 International Workshop on Big Data and Information Security (IWBIS). IEEE, 5\u201310 (2017)","DOI":"10.1109\/IWBIS.2017.8275095"},{"key":"9655_CR25","unstructured":"Kingma, D.P., Ba, J.: Adam: A method for stochastic optimization. http:\/\/arxiv.org\/abs\/14126980 (2014)"},{"key":"9655_CR26","doi-asserted-by":"crossref","unstructured":"Lashkari, A.H., Draper-Gil, G., Mamun, M.S.I., Ghorbani, A.: A Characterization of tor traffic using time based features. In: ICISSp, 253\u2013262 (2017)","DOI":"10.5220\/0005740704070414"},{"issue":"6","key":"9655_CR27","doi-asserted-by":"publisher","first-page":"790","DOI":"10.1016\/j.comnet.2008.11.016","volume":"53","author":"W Li","year":"2009","unstructured":"Li, W., Canini, M., Moore, A.W., Bolla, R.: Efficient application identification and the temporal and spatial stability of classification schema. Comput. Netw. 53(6), 790\u2013809 (2009)","journal-title":"Comput. Netw."},{"key":"9655_CR28","doi-asserted-by":"crossref","unstructured":"Liao, W.-H., Chang, C.-C.: Peer to peer botnet detection using data mining scheme. In: 2010 International Conference on Internet Technology and Applications, IEEE, 1\u20134 (2010)","DOI":"10.1109\/ITAPP.2010.5566407"},{"issue":"10","key":"9655_CR29","doi-asserted-by":"publisher","first-page":"1701","DOI":"10.3390\/s16101701","volume":"16","author":"T Ma","year":"2016","unstructured":"Ma, T., Wang, F., Cheng, J., Yu, Y., Chen, X.: A hybrid spectral clustering and deep neural network ensemble algorithm for intrusion detection in sensor networks. Sensors 16(10), 1701 (2016)","journal-title":"Sensors"},{"key":"9655_CR30","doi-asserted-by":"crossref","unstructured":"Meghdouri, F., V\u00e1zquez, F. I., & Zseby, T. (2020). Cross-Layer Profiling of Encrypted Network Data for Anomaly Detection. In 2020 IEEE 7th International Conference on Data Science and Advanced Analytics (DSAA) (469\u2013478). IEEE.","DOI":"10.1109\/DSAA49011.2020.00061"},{"issue":"2","key":"9655_CR31","first-page":"474","volume":"5","author":"S Miller","year":"2016","unstructured":"Miller, S., Busby-Earle, C.: The impact of different botnet flow feature subsets on prediction accuracy using supervised and unsupervised learning methods. Int. J. Internet Technol. Secur. Trans. 5(2), 474\u2013485 (2016)","journal-title":"Int. J. Internet Technol. Secur. Trans."},{"key":"9655_CR32","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1016\/j.compeleceng.2017.02.013","volume":"61","author":"N Milosevic","year":"2017","unstructured":"Milosevic, N., Dehghantanha, A., Choo, K.-K.R.: Machine learning aided Android malware classification. Comput. Electr. Eng. 61, 266\u2013274 (2017)","journal-title":"Comput. Electr. Eng."},{"key":"9655_CR33","doi-asserted-by":"crossref","unstructured":"Qin, Q., Poularakis, K., & Tassiulas, L.: A Learning Approach with Programmable Data Plane towards IoT Security. In\u00a02020 IEEE 40th International Conference on Distributed Computing Systems (ICDCS), 410\u2013420 (2020)","DOI":"10.1109\/ICDCS47774.2020.00064"},{"key":"9655_CR34","volume-title":"C4.5: Programs for Machine Learning","author":"J Quinlan","year":"2014","unstructured":"Quinlan, J.: C4.5: Programs for Machine Learning. Morgan Kaufmann Publishers, Burlington (2014)"},{"key":"9655_CR35","doi-asserted-by":"crossref","unstructured":"Saad S, Traore I, Ghorbani A, Sayed B, Zhao D, Lu W, Felix J, Hakimian P (2011) Detecting P2P botnets through network behavior analysis and machine learning. In: 2011 Ninth annual international conference on privacy, security and trust, IEEE, 174\u2013180","DOI":"10.1109\/PST.2011.5971980"},{"key":"9655_CR36","doi-asserted-by":"crossref","unstructured":"Sharafaldin I, Lashkari AH, Ghorbani A (2018) A Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: ICISSP, 108\u2013116","DOI":"10.5220\/0006639801080116"},{"key":"9655_CR37","doi-asserted-by":"crossref","unstructured":"Shiravi A, Shiravi H, Tavallaee M, Ghorbani AA (2012) Toward developing a systematic approach to generate benchmark datasets for intrusion detection. computers & security 31 (3):357\u2013374","DOI":"10.1016\/j.cose.2011.12.012"},{"issue":"2","key":"9655_CR38","doi-asserted-by":"publisher","first-page":"378","DOI":"10.1016\/j.comnet.2012.07.021","volume":"57","author":"SS Silva","year":"2013","unstructured":"Silva, S.S., Silva, R.M., Pinto, R.C., Salles, R.M.: Botnets: A survey. Comput. Netw. 57(2), 378\u2013403 (2013)","journal-title":"Comput. Netw."},{"issue":"3","key":"9655_CR39","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1109\/MSEC.2019.2902347","volume":"17","author":"A Singla","year":"2019","unstructured":"Singla, A., Bertino, E.: How deep learning is making information security more intelligent. IEEE Secur. Priv. 17(3), 56\u201365 (2019)","journal-title":"IEEE Secur. Priv."},{"issue":"2","key":"9655_CR40","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1109\/TPDS.2013.146","volume":"25","author":"Z Tan","year":"2013","unstructured":"Tan, Z., Jamdagni, A., He, X., Nanda, P., Liu, R.P.: A system for denial-of-service attack detection based on multivariate correlation analysis. IEEE Trans. Parallel Distrib. Syst. 25(2), 447\u2013456 (2013)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"9655_CR41","doi-asserted-by":"crossref","unstructured":"Tegeler F, Fu X, Vigna G, Kruegel C (2012) Botfinder: Finding bots in network traffic without deep packet inspection. In: Proceedings of the 8th international conference on Emerging networking experiments and technologies, 349\u2013360","DOI":"10.1145\/2413176.2413217"},{"key":"9655_CR42","unstructured":"Van NT, Thinh TN (2017) An anomaly-based network intrusion detection system using deep learning. In: 2017 International Conference on System Science and Engineering (ICSSE), IEEE, 210\u2013214"},{"issue":"4","key":"9655_CR43","doi-asserted-by":"publisher","first-page":"2768","DOI":"10.1109\/COMST.2017.2749442","volume":"19","author":"G Vormayr","year":"2017","unstructured":"Vormayr, G., Zseby, T., Fabini, J.: Botnet communication patterns. IEEE Commun. Surv. Tutor. 19(4), 2768\u20132796 (2017)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"9655_CR44","doi-asserted-by":"crossref","unstructured":"Wang W, Fang B, Zhang Z, Li C (2009) A novel approach to detect IRC-based botnets. In: 2009 International Conference on Networks Security, Wireless Communications and Trusted Computing, IEEE, 408\u2013411","DOI":"10.1109\/NSWCTC.2009.72"},{"key":"9655_CR45","doi-asserted-by":"publisher","first-page":"1792","DOI":"10.1109\/ACCESS.2017.2780250","volume":"6","author":"W Wang","year":"2017","unstructured":"Wang, W., Sheng, Y., Wang, J., Zeng, X., Ye, X., Huang, Y., Zhu, M.: HAST-IDS: Learning hierarchical spatial-temporal features using deep neural networks to improve intrusion detection. IEEE Access 6, 1792\u20131806 (2017)","journal-title":"IEEE Access"},{"key":"9655_CR46","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1016\/j.compeleceng.2014.10.010","volume":"41","author":"M Yahyazadeh","year":"2015","unstructured":"Yahyazadeh, M., Abadi, M.: BotGrab: A negative reputation system for botnet detection. Comput. Electr. Eng. 41, 68\u201385 (2015)","journal-title":"Comput. Electr. Eng."},{"key":"9655_CR47","doi-asserted-by":"crossref","unstructured":"Yin C, Zhu Y, Liu S, Fei J, Zhang H (2018) An enhancing framework for botnet detection using generative adversarial networks. In: 2018 International Conference on Artificial Intelligence and Big Data (ICAIBD), IEEE, 228\u2013234","DOI":"10.1109\/ICAIBD.2018.8396200"},{"key":"9655_CR48","doi-asserted-by":"crossref","unstructured":"Yu Y, Long J, Cai Z (2017) Session-based network intrusion detection using a deep learning architecture. In: International Conference on Modeling Decisions for Artificial Intelligence, Springer, 144\u2013155","DOI":"10.1007\/978-3-319-67422-3_13"},{"issue":"3","key":"9655_CR49","doi-asserted-by":"publisher","first-page":"181","DOI":"10.26599\/BDMA.2020.9020003","volume":"3","author":"W Zhong","year":"2020","unstructured":"Zhong, W., Yu, N., Ai, C.: Applying big data based deep learning system to intrusion detection. Big Data Mining Anal. 3(3), 181\u2013195 (2020)","journal-title":"Big Data Mining Anal."}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-022-09655-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-022-09655-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-022-09655-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,21]],"date-time":"2024-09-21T12:35:25Z","timestamp":1726922125000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-022-09655-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,1]]},"references-count":49,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,7]]}},"alternative-id":["9655"],"URL":"https:\/\/doi.org\/10.1007\/s10922-022-09655-7","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,4,1]]},"assertion":[{"value":"7 September 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 December 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 February 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 April 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"44"}}