{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T04:31:42Z","timestamp":1769920302620,"version":"3.49.0"},"reference-count":30,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2017,7,3]],"date-time":"2017-07-03T00:00:00Z","timestamp":1499040000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Process Lett"],"published-print":{"date-parts":[[2018,12]]},"DOI":"10.1007\/s11063-017-9666-7","type":"journal-article","created":{"date-parts":[[2017,7,3]],"date-time":"2017-07-03T04:41:12Z","timestamp":1499056872000},"page":"1347-1357","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":84,"title":["Malicious Domain Name Detection Based on Extreme Machine Learning"],"prefix":"10.1007","volume":"48","author":[{"given":"Yong","family":"Shi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1463-1554","authenticated-orcid":false,"given":"Gong","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juntao","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,7,3]]},"reference":[{"key":"9666_CR1","first-page":"50","volume":"4","author":"I Ghafir","year":"2014","unstructured":"Ghafir I, Prenosil V (2014) Advanced persistent threat attack detection: an overview. Int J Adv Comput Netw Secur 4:50\u201354","journal-title":"Int J Adv Comput Netw Secur"},{"key":"9666_CR2","doi-asserted-by":"crossref","unstructured":"Li M, Huang W, Wang Y, Fan W, Li J (2016) The study of APT attack stage model. In: 2016 IEEE\/ACIS 15th international conference on computer and information science (ICIS), pp 1\u20135","DOI":"10.1109\/ICIS.2016.7550947"},{"key":"9666_CR3","unstructured":"Li F APT attribution and DNS profiling. http:\/\/www.blackhat.com\/docs\/us-14\/materials\/us-14-Li-APT-Attribution-And-DNS-Profiling-WP.pdf"},{"key":"9666_CR4","first-page":"116","volume":"3","author":"S Soltani","year":"2014","unstructured":"Soltani S, Seno SAH, Nezhadkamali M, Budiarto R (2014) A survey on real world botnets and detection mechanisms. Int J Inf Netw Secur 3:116\u2013127","journal-title":"Int J Inf Netw Secur"},{"key":"9666_CR5","doi-asserted-by":"crossref","unstructured":"Grill M, Nikolaev I, Valeros V, Rehak M (2015) Detecting DGA malware using NetFlow. In: 2015 IFIP\/IEEE international symposium on integrated network management (IM). IEEE, pp 1304\u20131309","DOI":"10.1109\/INM.2015.7140486"},{"key":"9666_CR6","doi-asserted-by":"crossref","first-page":"794","DOI":"10.1587\/transcom.E95.B.794","volume":"95","author":"K Sato","year":"2012","unstructured":"Sato K, Ishibashi K, Toyono T, Miyake N (2012) Extending black domain name list by using co-occurrence relation between DNS queries. IEICE Trans Commun 95:794\u2013802","journal-title":"IEICE Trans Commun"},{"key":"9666_CR7","unstructured":"Zhang S (2014) Detecting malware domains on DNS traffic. Master Thesis, Shanghai Jiaotong University"},{"key":"9666_CR8","doi-asserted-by":"crossref","unstructured":"Shi L, Lin D, Fang CV, Zhai Y (2015) A hybrid learning from multi-behavior for malicious domain detection on enterprise network. In: 2015 IEEE international conference on data mining workshop (ICDMW). pp 987\u2013996","DOI":"10.1109\/ICDMW.2015.38"},{"key":"9666_CR9","doi-asserted-by":"crossref","first-page":"2115","DOI":"10.1109\/TMM.2016.2581483","volume":"18","author":"Y Gao","year":"2016","unstructured":"Gao Y, Zhen Y, Li H, Chua TS (2016) Filtering of brand-related microblogs using social-smooth multiview embedding. IEEE Trans Multimed 18:2115\u20132126","journal-title":"IEEE Trans Multimed"},{"key":"9666_CR10","doi-asserted-by":"crossref","unstructured":"Manadhata PK, Yadav S, Rao P, Horne W (2014) Detecting malicious domains via graph inference. In: European symposium on research in computer security. Springer, pp 1\u201318","DOI":"10.1145\/2666652.2666659"},{"key":"9666_CR11","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1016\/j.comcom.2014.04.013","volume":"49","author":"J Lee","year":"2014","unstructured":"Lee J, Lee H (2014) GMAD: graph-based malware activity detection by DNS traffic analysis. Comput Commun 49:33\u201347","journal-title":"Comput Commun"},{"key":"9666_CR12","doi-asserted-by":"crossref","unstructured":"Chau DH, Nachenberg C, Wilhelm J, Wright A, Faloutsos C (2010) Polonium: Tera-scale graph mining for malware detection. In: Acm sigkdd conference on knowledge discovery and data mining","DOI":"10.1137\/1.9781611972818.12"},{"key":"9666_CR13","doi-asserted-by":"crossref","unstructured":"Gao Y, Zhang H, Zhao X, Yan S (2017) Event classification in microblog via social tracking. ACM Trans Intell Syst Technol 8:1\u201314","DOI":"10.1145\/2967502"},{"key":"9666_CR14","doi-asserted-by":"crossref","first-page":"5427","DOI":"10.1109\/TIP.2016.2607421","volume":"25","author":"G Ding","year":"2016","unstructured":"Ding G, Guo Y, Zhou J, Gao Y (2016) Large-scale cross-modality search via collective matrix factorization hashing. IEEE Trans Image Process 25:5427\u20135440","journal-title":"IEEE Trans Image Process"},{"key":"9666_CR15","doi-asserted-by":"crossref","first-page":"179","DOI":"10.3103\/S0278641916040051","volume":"40","author":"IV Mashechkin","year":"2016","unstructured":"Mashechkin IV, Petrovskii MI, Tsarev DV (2016) Machine learning methods for analyzing user behavior when accessing text data in information security problems. Mosc Univ Comput Math Cybern 40:179\u2013184","journal-title":"Mosc Univ Comput Math Cybern"},{"key":"9666_CR16","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1109\/CC.2013.6674213","volume":"10","author":"Z Futai","year":"2013","unstructured":"Futai Z, Siyu Z, Weixiong R (2013) Hybrid detection and tracking of fast-flux botnet on domain name system traffic. China Commun 10:81\u201394","journal-title":"China Commun"},{"key":"9666_CR17","unstructured":"Bilge L, Kirda E, Kruegel C, Balduzzi M (2011) EXPOSURE: finding malicious domains using passive DNS analysis. In: Network and distributed system security symposium"},{"key":"9666_CR18","first-page":"139","volume":"3","author":"P Amini","year":"2014","unstructured":"Amini P, Azmi R, Araghizadeh M (2014) Botnet detection using NetFlow and clustering. Adv Comput Sci Int J 3:139\u2013149","journal-title":"Adv Comput Sci Int J"},{"key":"9666_CR19","doi-asserted-by":"crossref","first-page":"1048","DOI":"10.3923\/itj.2012.1048.1055","volume":"11","author":"X Yu","year":"2012","unstructured":"Yu X, Zhang B, Kang L, Chen J (2012) Fast-flux botnet detection based on weighted svm. Inf Technol J 11:1048\u20131055","journal-title":"Inf Technol J"},{"key":"9666_CR20","doi-asserted-by":"crossref","unstructured":"Lasota K, Kozakiewicz A (2011) Analysis of the similarities in malicious DNS domain names. In: International conference on secure and trust computing, data management, and application, 1006","DOI":"10.1007\/978-3-642-22365-5_1"},{"key":"9666_CR21","doi-asserted-by":"crossref","unstructured":"Ma J, Saul LK, Savage S, Voelker GM (2009) Beyond blacklists: learning to detect malicious web sites from suspicious URLs. In: Proceedings of the 15th ACM SIGKDD international conference on knowledge discovery and data mining, pp 1245\u20131254","DOI":"10.1145\/1557019.1557153"},{"key":"9666_CR22","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1145\/584091.584093","volume":"5","author":"CE Shannon","year":"2001","unstructured":"Shannon CE (2001) A mathematical theory of communication. ACM SIGMOBILE Mob Comput Commun Rev 5:3\u201355","journal-title":"ACM SIGMOBILE Mob Comput Commun Rev"},{"key":"9666_CR23","doi-asserted-by":"crossref","unstructured":"Passerini E, Paleari R, Martignoni L, Bruschi D (2008) Fluxor: detecting and monitoring fast-flux service networks. In: International conference on detection of intrusions and malware, and vulnerability assessment. pp 186\u2013206","DOI":"10.1007\/978-3-540-70542-0_10"},{"key":"9666_CR24","unstructured":"Brisco T DNS support for load balancing. https:\/\/tools.ietf.org\/html\/rfc1794"},{"key":"9666_CR25","unstructured":"ICANN WHOIS: WHOIS Search. https:\/\/whois.icann.org\/en"},{"key":"9666_CR26","doi-asserted-by":"crossref","first-page":"489","DOI":"10.1016\/j.neucom.2005.12.126","volume":"70","author":"GB Huang","year":"2006","unstructured":"Huang GB, Zhu QY, Siew CK (2006) Extreme learning machine: theory and applications. Neurocomputing 70:489\u2013501","journal-title":"Neurocomputing"},{"key":"9666_CR27","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1007\/s12559-015-9333-0","volume":"7","author":"GB Huang","year":"2015","unstructured":"Huang GB (2015) What are extreme learning machines? Filling the gap between Frank Rosenblatt\u2019s dream and John von Neumann\u2019s puzzle. Cogn Comput 7:263\u2013278","journal-title":"Cogn Comput"},{"key":"9666_CR28","unstructured":"Website Traffic, Statistics and Analytics\u2014Alexa. http:\/\/www.alexa.com\/siteinfo"},{"key":"9666_CR29","unstructured":"Malicious Domain List. https:\/\/www.malwaredomainlist.com\/"},{"key":"9666_CR30","unstructured":"PhishTank\u2014Join the fight against phishing. http:\/\/www.alexa.com\/"}],"container-title":["Neural Processing Letters"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11063-017-9666-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11063-017-9666-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11063-017-9666-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,28]],"date-time":"2019-09-28T02:32:27Z","timestamp":1569637947000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11063-017-9666-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,7,3]]},"references-count":30,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,12]]}},"alternative-id":["9666"],"URL":"https:\/\/doi.org\/10.1007\/s11063-017-9666-7","relation":{},"ISSN":["1370-4621","1573-773X"],"issn-type":[{"value":"1370-4621","type":"print"},{"value":"1573-773X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,7,3]]}}}