{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T12:17:42Z","timestamp":1783340262632,"version":"3.54.6"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:00:00Z","timestamp":1778457600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:00:00Z","timestamp":1778457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Ministry of Science and Technology of Vietnam","award":["KC.01.04\/21-30"],"award-info":[{"award-number":["KC.01.04\/21-30"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1007\/s10922-026-10081-2","type":"journal-article","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T05:19:15Z","timestamp":1778476755000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["DgaDetector: Leveraging DNS Analysis for DGA-Based Bot Identification"],"prefix":"10.1007","volume":"34","author":[{"given":"Van","family":"Tong","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hieu","family":"Mac","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hung","family":"Pham","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Khanh","family":"Nguyen Quoc","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tien Tuan Anh","family":"Dinh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Duc","family":"Tran","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,11]]},"reference":[{"key":"10081_CR1","unstructured":"Antonakakis, M., Perdisci, R., Nadji, Y., Vasiloglou, N., Abu-Nimeh, S., Lee, W., Dagon, D.: From throw-away traffic to bots: Detecting the rise of dga-based malware. In: Proceedings of the 21st USENIX Security Symposium, pp. 491\u2013506 (2012)"},{"key":"10081_CR2","doi-asserted-by":"publisher","first-page":"2401","DOI":"10.1016\/j.neucom.2017.11.018","volume":"275","author":"D Tran","year":"2018","unstructured":"Tran, D., Mac, H., Tong, V., Tran, H.A., Nguyen, L.G.: A lstm based framework for handling multiclass imbalance in dga botnet detection. Neurocomputing 275, 2401\u20132413 (2018)","journal-title":"Neurocomputing"},{"key":"10081_CR3","doi-asserted-by":"crossref","unstructured":"Nguyen\u00a0Quoc, K., Bui, T., Le, D., Tran, D., Nguyen, T., Nguyen, H.T.: Detecting dga botnet based on malware behavior analysis. In: Proceedings of the 11th International Symposium on Information and Communication Technology, pp. 158\u2013164 (2022)","DOI":"10.1145\/3568562.3568590"},{"key":"10081_CR4","doi-asserted-by":"publisher","first-page":"91759","DOI":"10.1109\/ACCESS.2019.2927075","volume":"7","author":"J Peck","year":"2019","unstructured":"Peck, J., Nie, C., Sivaguru, R., Grumer, C., Olumofin, F., Yu, B., Nascimento, A., De Cock, M.: Charbot: A simple and effective method for evading dga classifiers. IEEE Access 7, 91759\u201391771 (2019)","journal-title":"IEEE Access"},{"key":"10081_CR5","doi-asserted-by":"crossref","unstructured":"Schiavoni, S., Maggi, F., Cavallaro, L., Zanero, S.: Phoenix: Dga-based botnet tracking and intelligence. In: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 192\u2013211 (2014). Springer","DOI":"10.1007\/978-3-319-08509-8_11"},{"key":"10081_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2016.10.001","volume":"64","author":"T-S Wang","year":"2017","unstructured":"Wang, T.-S., Lin, H.-T., Cheng, W.-T., Chen, C.-Y.: Dbod: Clustering and detecting dga-based botnets using dns traffic analysis. Computers & Security 64, 1\u201315 (2017)","journal-title":"Computers & Security"},{"key":"10081_CR7","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/j.diin.2018.12.005","volume":"28","author":"M Singh","year":"2019","unstructured":"Singh, M., Singh, M., Kaur, S.: Detecting bot-infected machines using dns fingerprinting. Digit. Investig. 28, 14\u201333 (2019)","journal-title":"Digit. Investig."},{"key":"10081_CR8","doi-asserted-by":"crossref","unstructured":"Singh, M., Singh, M., Kaur, S.: Identifying bot infection using neural networks on dns traffic. Journal of Computer Virology and Hacking Techniques, 1\u201315 (2023)","DOI":"10.1007\/s11416-023-00462-5"},{"key":"10081_CR9","unstructured":"Plohmann, D., Yakdan, K., Klatt, M., Bader, J., Padilla, E.: A comprehensive measurement study of domain generating malware. In: Proceedings of the 16th USENIX Security Symposium, pp. 263\u2013278 (2016)"},{"key":"10081_CR10","unstructured":"Sch\u00fcppen, S., Teubert, D., Herrmann, P., Meyer, U.: $$\\{$$FANCI$$\\}$$: Feature-based automated $$\\{$$NXDomain$$\\}$$ classification and intelligence. In: Proceedings of the 27th USENIX Security Symposium, pp. 1165\u20131181 (2018)"},{"key":"10081_CR11","doi-asserted-by":"crossref","unstructured":"Yu, B., Pan, J., Hu, J., Nascimento, A., De\u00a0Cock, M.: Character level based detection of dga domain names. In: Proceedings of the 2018 International Joint Conference on Neural Networks, pp. 1\u20138 (2018). IEEE","DOI":"10.1109\/IJCNN.2018.8489147"},{"key":"10081_CR12","doi-asserted-by":"crossref","unstructured":"Mac, H., Tran, D., Tong, V., Nguyen, L.G., Tran, H.A.: Dga botnet detection using supervised learning methods. In: Proceedings of the 8th International Symposium on Information and Communication Technology, pp. 211\u2013218 (2017)","DOI":"10.1145\/3155133.3155166"},{"key":"10081_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102549","volume":"113","author":"TA Tuan","year":"2022","unstructured":"Tuan, T.A., Long, H.V., Taniar, D.: On detecting and classifying dga botnets and their families. Comput. Security 113, 102549 (2022)","journal-title":"Comput. Security"},{"issue":"8","key":"10081_CR14","doi-asserted-by":"publisher","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter, S., Schmidhuber, J.: Long short-term memory. Neural Comput. 9(8), 1735\u20131780 (1997)","journal-title":"Neural Comput."},{"key":"10081_CR15","unstructured":"Woodbridge, J., Anderson, H.S., Ahuja, A., Grant, D.: Predicting domain generation algorithms with long short-term memory networks. arXiv preprint arXiv:1611.00791 (2016)"},{"issue":"20","key":"10081_CR16","doi-asserted-by":"publisher","first-page":"4205","DOI":"10.3390\/app9204205","volume":"9","author":"Y Qiao","year":"2019","unstructured":"Qiao, Y., Zhang, B., Zhang, W., Sangaiah, A.K., Wu, H.: Dga domain name classification method based on long short-term memory with attention mechanism. Appl. Sci. 9(20), 4205 (2019)","journal-title":"Appl. Sci."},{"key":"10081_CR17","doi-asserted-by":"crossref","unstructured":"Jiang, N., Cao, J., Jin, Y., Li, L.E., Zhang, Z.-L.: Identifying suspicious activities through dns failure graph analysis. In: Proceedings of the 18th IEEE International Conference on Network Protocols, pp. 144\u2013153 (2010). IEEE","DOI":"10.1109\/ICNP.2010.5762763"},{"key":"10081_CR18","doi-asserted-by":"crossref","unstructured":"Tu, T.D., Guang, C., Xin, L.Y.: Detecting bot-infected machines based on analyzing the similar periodic dns queries. In: Proceedings of 2015 International Conference on Communications, Management and Telecommunications, pp. 35\u201340 (2015). IEEE","DOI":"10.1109\/ComManTel.2015.7394256"},{"key":"10081_CR19","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1007\/s10207-016-0331-3","volume":"16","author":"M Stevanovic","year":"2017","unstructured":"Stevanovic, M., Pedersen, J.M., D\u2019Alconzo, A., Ruehrup, S.: A method for identifying compromised clients based on dns traffic analysis. Int. J. Inf. Secur. 16, 115\u2013132 (2017)","journal-title":"Int. J. Inf. Secur."},{"key":"10081_CR20","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1016\/j.diin.2014.11.001","volume":"12","author":"R Sharifnya","year":"2015","unstructured":"Sharifnya, R., Abadi, M.: Dfbotkiller: Domain-flux botnet detection based on the history of group activities and failures in dns traffic. Digit. Investig. 12, 15\u201326 (2015)","journal-title":"Digit. Investig."},{"key":"10081_CR21","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1016\/j.comnet.2015.12.008","volume":"97","author":"J Kwon","year":"2016","unstructured":"Kwon, J., Lee, J., Lee, H., Perrig, A.: Psybog: A scalable botnet detection method for large-scale dns traffic. Comput. Netw. 97, 48\u201373 (2016)","journal-title":"Comput. Netw."},{"key":"10081_CR22","unstructured":"Zhang, H., Gharaibeh, M., Thanasoulas, S., Papadopoulos, C.: Botdigger: Detecting dga bots in a single network. In: Proceedings of the 2016 International Workshop on Traffic Monitoring and Analysis (2016)"},{"issue":"1","key":"10081_CR23","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-025-09994-1","volume":"34","author":"M To\u011fa\u00e7ar","year":"2026","unstructured":"To\u011fa\u00e7ar, M.: A novel approach to malware detection: Converting hardware memory data to 2d barcodes using mobile networks. J. Netw. Syst. Manage. 34(1), 1\u201330 (2026)","journal-title":"J. Netw. Syst. Manage."},{"key":"10081_CR24","doi-asserted-by":"crossref","unstructured":"Torrealba\u00a0Aravena, L., Casas, P., Bustos-Jim\u00e9nez, J., Capdehourat, G., Findrik, M.: Dom2vec-detecting dga domains through word embeddings and ai\/ml-driven lexicographic analysis. In: CNSM 2023 19th International Conference on Network and Service Management, Niagara Falls, Canada, 30 Oct.-2 Nov. 2023, Pp. 1-5. (2023). CNSM","DOI":"10.23919\/CNSM59352.2023.10327913"},{"key":"10081_CR25","doi-asserted-by":"crossref","unstructured":"T, A.L., Casas, P., Garc\u00eda, D., Bustos-Jim\u00e9nez, J., Bachmann, I.: Malicious domain names detection with deepdga, a hybrid character and word embeddings deep learning architecture. In: 2025 21st International Conference on Network and Service Management (CNSM), pp. 1\u20136 (2025). IEEE","DOI":"10.23919\/CNSM67658.2025.11297537"},{"issue":"4","key":"10081_CR26","doi-asserted-by":"publisher","first-page":"2922","DOI":"10.1109\/TNSE.2022.3173591","volume":"9","author":"J Ahmed","year":"2022","unstructured":"Ahmed, J., Gharakheili, H.H., Russell, C., Sivaraman, V.: Automatic detection of dga-enabled malware using sdn and traffic behavioral modeling. IEEE Transactions on Network Science and Engineering 9(4), 2922\u20132939 (2022)","journal-title":"IEEE Transactions on Network Science and Engineering"},{"issue":"4","key":"10081_CR27","doi-asserted-by":"publisher","first-page":"687","DOI":"10.1109\/TPAMI.2007.1010","volume":"29","author":"T Sim","year":"2007","unstructured":"Sim, T., Zhang, S., Janakiraman, R., Kumar, S.: Continuous verification using multimodal biometrics. IEEE Trans. Pattern Anal. Mach. Intell. 29(4), 687\u2013700 (2007)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10081_CR28","unstructured":"Altinok, A., Turk, M.: Temporal integration for continuous multimodal biometrics. In: Proceedings of the Workshop on Multimodal User Authentication, pp. 131\u2013137 (2003)"},{"key":"10081_CR29","doi-asserted-by":"crossref","unstructured":"Azzini, A., Marrara, S., Sassi, R., Scotti, F.: A fuzzy approach to multimodal biometric authentication. In: Proceedings of the 11th International Conference Knowledge-Based Intelligent Information and Engineering Systems, pp. 801\u2013808 (2007)","DOI":"10.1007\/978-3-540-74827-4_101"},{"issue":"1","key":"10081_CR30","doi-asserted-by":"publisher","first-page":"136","DOI":"10.1109\/TIFS.2012.2225048","volume":"8","author":"M Frank","year":"2012","unstructured":"Frank, M., Biedert, R., Ma, E., Martinovic, I., Song, D.: Touchalytics: On the applicability of touchscreen input as a behavioral biometric for continuous authentication. IEEE Trans. Inf. Forensics Secur. 8(1), 136\u2013148 (2012)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"10081_CR31","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1109\/5.18626","volume":"77","author":"LR Rabiner","year":"1989","unstructured":"Rabiner, L.R.: A tutorial on hidden markov models and selected applications in speech recognition. Proc. IEEE 77(2), 257\u2013286 (1989)","journal-title":"Proc. IEEE"},{"key":"10081_CR32","doi-asserted-by":"crossref","unstructured":"Katti, S., Rao, A.V.: Handbook Of The Poisson Distribution. Taylor & Francis (1968)","DOI":"10.1080\/00401706.1968.10490580"},{"key":"10081_CR33","unstructured":"Zhao, J., Huang, F., Lv, J., Duan, Y., Qin, Z., Li, G., Tian, G.: Do rnn and lstm have long memory? In: International Conference on Machine Learning, pp. 11365\u201311375 (2020). PMLR"},{"key":"10081_CR34","doi-asserted-by":"publisher","first-page":"128990","DOI":"10.1109\/ACCESS.2019.2940554","volume":"7","author":"H Zhao","year":"2019","unstructured":"Zhao, H., Chang, Z., Wang, W., Zeng, X.: Malicious domain names detection algorithm based on lexical analysis and feature quantification. IEEE Access 7, 128990\u2013128999 (2019)","journal-title":"IEEE Access"},{"key":"10081_CR35","doi-asserted-by":"crossref","unstructured":"Anderson, H.S., Woodbridge, J., Filar, B.: Deepdga: Adversarially-tuned domain generation and detection. In: Proceedings of the 2016 ACM Workshop On Artificial Intelligence And Security, pp. 13\u201321 (2016)","DOI":"10.1145\/2996758.2996767"},{"key":"10081_CR36","doi-asserted-by":"publisher","first-page":"161580","DOI":"10.1109\/ACCESS.2020.3020964","volume":"8","author":"L Sidi","year":"2020","unstructured":"Sidi, L., Nadler, A., Shabtai, A.: Maskdga: An evasion attack against dga classifiers and adversarial defenses. IEEE Access 8, 161580\u2013161592 (2020)","journal-title":"IEEE Access"},{"issue":"3","key":"10081_CR37","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1109\/34.667881","volume":"20","author":"J Kittler","year":"1998","unstructured":"Kittler, J., Hatef, M., Duin, R.P., Matas, J.: On combining classifiers. IEEE Trans. Pattern Anal. Mach. Intell. 20(3), 226\u2013239 (1998)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10081_CR38","unstructured":"Thakar, N., Amritaluru, P.K., Taneja, V.: System and Method To Detect Domain Generation Algorithm Malware And Systems Infected By Such Malware. Google Patents. US Patent 10,198,579 (2019)"},{"key":"10081_CR39","doi-asserted-by":"crossref","unstructured":"Hoffman, P.E., McManus, P.: DNS Queries over HTTPS (DoH). RFC Editor (2018). https:\/\/doi.org\/10.17487\/RFC8484 . https:\/\/www.rfc-editor.org\/info\/rfc8484","DOI":"10.17487\/RFC8484"},{"key":"10081_CR40","unstructured":"Huang, Q., Chang, D., Li, Z.: A comprehensive study of $$\\{$$DNS-over-HTTPS$$\\}$$ downgrade attack. In: 10th USENIX Workshop on Free and Open Communications on the Internet (FOCI 20) (2020)"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-026-10081-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-026-10081-2","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-026-10081-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T11:37:53Z","timestamp":1783337873000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-026-10081-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,11]]},"references-count":40,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2026,7]]}},"alternative-id":["10081"],"URL":"https:\/\/doi.org\/10.1007\/s10922-026-10081-2","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,11]]},"assertion":[{"value":"16 September 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 March 2026","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 April 2026","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 May 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"93"}}