{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T09:37:24Z","timestamp":1648805844487},"reference-count":22,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2013,7,1]],"date-time":"2013-07-01T00:00:00Z","timestamp":1372636800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J. Comput. Sci. Technol."],"published-print":{"date-parts":[[2013,7]]},"DOI":"10.1007\/s11390-013-1361-1","type":"journal-article","created":{"date-parts":[[2013,7,4]],"date-time":"2013-07-04T09:42:41Z","timestamp":1372930961000},"page":"605-615","source":"Crossref","is-referenced-by-count":0,"title":["Mining Botnets and Their Evolution Patterns"],"prefix":"10.1007","volume":"28","author":[{"given":"Jaehoon","family":"Choi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jaewoo","family":"Kang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinseung","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chihwan","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingsong","family":"Jin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sunwon","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinsun","family":"Uh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,7,5]]},"reference":[{"issue":"4","key":"1361_CR1","doi-asserted-by":"crossref","first-page":"291","DOI":"10.1145\/1151659.1159947","volume":"36","author":"A Ramachandran","year":"2006","unstructured":"Ramachandran A, Feamster N. Understanding the network-level behavior of spammers. ACM SIGCOMM Computer Communication Review, 2006, 36(4): 291\u2013302.","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"1361_CR2","unstructured":"Goebel J, Holz T. Rishi: Identify bot contaminated hosts by IRC nickname evaluation. In Proc. the 1st Workshop on Hot Topics in Understanding Botnets, Apr. 2007."},{"key":"1361_CR3","unstructured":"Karasaridis A, Rexroad B, Hoeflin D. Wide-scale botnet detection and characterization. In Proc. the 1st Workshop on Hot Topics in Understanding Botnets, Apr. 2007."},{"issue":"2","key":"1361_CR4","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1109\/MSECP.2003.1193207","volume":"1","author":"L Spitzner","year":"2003","unstructured":"Spitzner L. The honeynet project: Trapping the hackers. IEEE Security and Privacy, 2003, 1(2): 15\u201323.","journal-title":"IEEE Security and Privacy"},{"issue":"5","key":"1361_CR5","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1145\/1095809.1095825","volume":"39","author":"M Vrable","year":"2005","unstructured":"Vrable M, Ma J, Chen J et al. Scalability, fidelity, and containment in the Potemkin virtual honeyfarm. ACM SIGOPS Operating Systems Review, 2005, 39(5): 148\u2013162.","journal-title":"ACM SIGOPS Operating Systems Review"},{"key":"1361_CR6","unstructured":"Cho C Y, Caballero J, Grier C et al. Insights from the inside: A view of botnet management from infiltration. In Proc. the 3rd USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET), Apr. 2010."},{"issue":"2","key":"1361_CR7","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1109\/TDSC.2008.35","volume":"7","author":"P Wang","year":"2010","unstructured":"Wang P, Sparks S, Zou C C. An advanced hybrid peer-to-peer botnet. IEEE Transactions on Dependable and Secure Computing, 2010, 7(2): 113\u2013127.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"1361_CR8","unstructured":"Hu X, Knysz M, Shin K G. Rb-seeker: Auto-detection of redirection botnets. In Proc. Symp. Network and Distributed System Security, Feb. 2009."},{"key":"1361_CR9","doi-asserted-by":"crossref","unstructured":"Ramachandran A, Feamster N, Vempala S. Filtering spam with behavioral blacklisting. In Proc. the 14th ACM Conference on Computer and Communications Security, Oct. 2007, pp.342-351.","DOI":"10.1145\/1315245.1315288"},{"key":"1361_CR10","doi-asserted-by":"crossref","unstructured":"Duan Z, Chen P, Sanchez F, Dong Y, Stephenson M, Barker J. Detecting spam zombies by monitoring outgoing messages. In Proc. INFOCOM, Apr. 2009, pp.1764-1772.","DOI":"10.1109\/INFCOM.2009.5062096"},{"key":"1361_CR11","unstructured":"John J P, Moshchuk A, Gribble S D, Krishnamurthy A. Studying spamming botnets using Botlab. In Proc. the 6th USENIX Symposium on Networked Systems Design and Implementation, Apr. 2009, pp.291-306."},{"key":"1361_CR12","unstructured":"Zhao Y, Xie Y, Yu F et al. Botgraph: Large scale spamming botnet detection. In Proc. the 6th USENIX Symposium on Networked Systems Design and Implementation, Apr. 2009, pp.321-334."},{"key":"1361_CR13","unstructured":"Li F, Hsieh M H. An empirical study of clustering behavior of spammers and group-based anti-spam strategies. In Proc. the 3rd Conference on Email and Anti-Spam, Jul. 2006."},{"key":"1361_CR14","unstructured":"Zhuang L, Dunagan J, Simon D R et al. Characterizing botnets from email spam records. In Proc. the 1st USENIX Workshop on Large-Scale Exploits and Emergent Threats, Apr. 2008, Article No.2."},{"issue":"4","key":"1361_CR15","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1145\/1402946.1402979","volume":"38","author":"Y Xie","year":"2008","unstructured":"Xie Y, Yu F, Achan K et al. Spamming botnets: Signatures and characteristics. ACM SIGCOMM Computer Communication Review, 2008, 38(4): 171\u2013182.","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"1361_CR16","unstructured":"Gu G, Perdisci R, Zhang J, Lee W. BotMiner: Clustering analysis of network traffic for protocol- and structure-independent botnet detection. In Proc. the 17th Conference on Security Symposium, Jul. 2008, pp.139-154."},{"key":"1361_CR17","unstructured":"Gu G, Porras P, Yegneswaran V, Fong M, Lee W. Bothunter: Detecting malware infection through IDS-driven dialog correlation. In Proc. the 16th USENIX Security Symposium on USENIX Security Symposium, May 2007, Article No.12."},{"key":"1361_CR18","unstructured":"Gu G, Zhang J, Lee W. BotSniffer: Detecting botnet command and control channels in network traffic. In Proc. the 15th Annual Network and Distributed System Security Symposium, Feb. 2008."},{"key":"1361_CR19","unstructured":"Kanich C, Levchenko K, Enright B et al. The Heisenbot uncertainty problem: Challenges in separating bots from chaff. In Proc. the 1st USENIX Workshop on Large-Scale Exploits and Emergent Threats, Apr. 2008, Article No. 10."},{"key":"1361_CR20","unstructured":"Rajab M A, Zarfoss J, Monrose F, Terzis A. My botnet is bigger than yours (maybe, better than yours): Why size estimates remain challenging. In Proc. the 1st Workshop on Hot Topics in Understanding Botnets, Apr. 2007."},{"key":"1361_CR21","unstructured":"Rubner Y, Tomasi C, Guibas L J. A metric for distributions with applications to image databases. In Proc. the 6th International Conference on Computer Vision, Jan. 1998, pp.59-66."},{"key":"1361_CR22","unstructured":"Choi J, Kang J, Lee J et al. Mining the global network of compromised machines. In Proc. the 4th International Conference on Emerging Databases-Technologies, Applications, and Theory, Aug. 2012."}],"container-title":["Journal of Computer Science and Technology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11390-013-1361-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11390-013-1361-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11390-013-1361-1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,17]],"date-time":"2019-07-17T03:41:20Z","timestamp":1563334880000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11390-013-1361-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,7]]},"references-count":22,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,7]]}},"alternative-id":["1361"],"URL":"https:\/\/doi.org\/10.1007\/s11390-013-1361-1","relation":{},"ISSN":["1000-9000","1860-4749"],"issn-type":[{"value":"1000-9000","type":"print"},{"value":"1860-4749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,7]]}}}