{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,6,15]],"date-time":"2024-06-15T17:11:46Z","timestamp":1718471506051},"reference-count":50,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2016,9,30]],"date-time":"2016-09-30T00:00:00Z","timestamp":1475193600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"name":"ICTR&D"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,2]]},"DOI":"10.1007\/s11416-016-0286-y","type":"journal-article","created":{"date-parts":[[2016,9,30]],"date-time":"2016-09-30T02:57:16Z","timestamp":1475204236000},"page":"21-38","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Diagnosing bot infections using Bayesian inference"],"prefix":"10.1007","volume":"14","author":[{"given":"Ayesha Binte","family":"Ashfaq","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zainab","family":"Abaid","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maliha","family":"Ismail","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad Umar","family":"Aslam","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Affan A.","family":"Syed","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Syed Ali","family":"Khayam","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,30]]},"reference":[{"key":"286_CR1","unstructured":"Bencsth, B., Pk, G., Buttyn, L., Flegyhzi, M.: Duqu: analysis, detection, and lessons learned. In: 2012 ACM European Workshop on System Security (EuroSec), vol. 2012 (2012)"},{"key":"286_CR2","unstructured":"Falliere, N., Murchu, L.O., Chien, E.: W32. stuxnet dossier. In: White Paper, Symantec Corp., Security Response, 2011, online 5 June (2013)"},{"key":"286_CR3","unstructured":"Gu, G., Porras, P., Yegneswaran, V., Fong, M., Lee, W.: Bothunter: detecting malware infection through ids-driven dialog correlation, In: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, SS\u201907. USENIX Association, Berkeley, pp. 12:1\u201312:16 (2007). http:\/\/dl.acm.org\/citation.cfm?id=1362903.1362915"},{"key":"286_CR4","doi-asserted-by":"crossref","unstructured":"Khattak, S., Ahmed, Z., Syed, A. A., Khayam, S.A.: Poster: Botflex: a community-driven tool for botnet detection, online 17 May (2013)","DOI":"10.1145\/2508859.2512507"},{"key":"286_CR5","doi-asserted-by":"crossref","DOI":"10.1007\/978-0-387-68282-2","volume-title":"Bayesian Networks and Decision Graphs","author":"FV Jensen","year":"2007","unstructured":"Jensen, F.V., Nielsen, T.D.: Bayesian Networks and Decision Graphs. Springer, New York (2007)"},{"key":"286_CR6","doi-asserted-by":"publisher","unstructured":"Sommer, R., Paxson, V.: Outside the closed world: on using machine learning for network intrusion detection, In: 2010 IEEE Symposium on Security and Privacy (SP), pp. 305\u2013316. doi: 10.1109\/SP.2010.25","DOI":"10.1109\/SP.2010.25"},{"key":"286_CR7","unstructured":"Ramay, N.R., Khattak, S., Syed, A.A., Khayam, S.A.: Poster: Bottleneck: a generalized, flexible, and extensible framework for botnet defense, online 13 April (2013)"},{"key":"286_CR8","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1007\/BF00994110","volume":"9","author":"G Cooper","year":"1992","unstructured":"Cooper, G., Herskovits, E.: A bayesian method for the induction of probabilistic networks from data. Mach. Learn. 9, 309\u2013347 (1992). doi: 10.1007\/BF00994110","journal-title":"Mach. Learn."},{"key":"286_CR9","doi-asserted-by":"crossref","unstructured":"Cheng, J., Greiner, R.: Learning Bayesian belief network classifiers: algorithm and systems. In: Stroulia, E., Matwin, S. (eds.) Advances in Artificial Intelligence. Lecture Notes in Computer Science, vol. 2056, pp. 141\u2013151. Springer, Berlin, Heidelberg (2001)","DOI":"10.1007\/3-540-45153-6_14"},{"key":"286_CR10","unstructured":"Netica programers library reference manual. http:\/\/www.norsys.com\/netica-j\/docs\/NeticaJ_Man.pdf , online 20 May (2013)"},{"key":"286_CR11","doi-asserted-by":"crossref","unstructured":"Spiegelhalter, D. J., Dawid, A.P., Lauritzen, S.L., Cowell, R.G.: Bayesian analysis in expert systems. Stat. Sci. 219\u2013247 (1993)","DOI":"10.1214\/ss\/1177010888"},{"key":"286_CR12","volume-title":"Probabilistic Reasoning in Intelligent Systems: Networks of Plausible Inference","author":"J Pearl","year":"1988","unstructured":"Pearl, J.: Probabilistic Reasoning in Intelligent Systems: Networks of Plausible Inference. Morgan Kaufmann, New York (1988)"},{"key":"286_CR13","unstructured":"Conficker: https:\/\/mil.fireeye.com\/edp.php?sname=Bot.Conficker , online June (2013)"},{"key":"286_CR14","unstructured":"Inside the storm: https:\/\/www.blackhat.com\/presentations\/bh-usa-08\/Stewart\/BH_US_08_Stewart_Protocols_of_the_Storm.pdf"},{"key":"286_CR15","unstructured":"Roesch, M., et al.: Snort-lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration, Seattle, Washington, pp. 229\u2013238 (1999)"},{"key":"286_CR16","unstructured":"Bro: http:\/\/www.bro.org\/ , online 10 April (2013)"},{"key":"286_CR17","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Mutz, D., Robertson, W., Valeur, F.: Bayesian event classification for intrusion detection. In: 19th Annual Proceedings Computer Security Applications Conference, pp. 14\u201323. IEEE, New York (2003)","DOI":"10.1109\/CSAC.2003.1254306"},{"key":"286_CR18","unstructured":"Cert-polaska: http:\/\/www.cert.pl\/PDF\/Report_Virut_EN.pdf , online 25 February (2013)"},{"key":"286_CR19","unstructured":"Nayatel: http:\/\/www.nayatel.pk\/index.php , online April (2013)"},{"key":"286_CR20","unstructured":"Team cymru: https:\/\/www.team-cymru.org\/ , online April (2013)"},{"key":"286_CR21","unstructured":"The ICSI networking and security group. http:\/\/www.icir.org\/ , online 13 May (2013)"},{"key":"286_CR22","unstructured":"Bottleneck: http:\/\/sysnet.org.pk\/w\/Code_and_Tools#Bottleneck , online 15 June (2013)"},{"key":"286_CR23","unstructured":"Stewart, J.: Inside the storm: protocols and encryption of the storm botnet. In: Black Hat Technical Security Conference, New York (2008)"},{"key":"286_CR24","unstructured":"Emerging threats malware rulesets: http:\/\/www.emergingthreats.net , online 5 August (2013)"},{"key":"286_CR25","unstructured":"Poole, D., Mackworth, A.: Artificial intelligence: foundations of computational agents, online November (2013)"},{"key":"286_CR26","unstructured":"Netica-j reference manual\u2014Norsys Software Corp. http:\/\/www.norsys.com\/downloads\/NeticaJ_Man_418.pdf , online 16 September (2013)"},{"key":"286_CR27","unstructured":"Costa, E., Lorena, A., Carvalho, A., Freitas, A.: A review of performance evaluation measures for hierarchical classifiers. In: Evaluation Methods for Machine Learning II: Papers from the AAAI-2007 Workshop, pp. 1\u20136 (2007)"},{"key":"286_CR28","unstructured":"lozano, J.A., Santaf, G., Inza, I.: Classier performance evaluation and comparison. In: International Conference on Machine Learning and Applications (ICMLA 2010). http:\/\/www.icmla-conference.org\/icmla10\/CFP_Tutorial_files\/jose.pdf"},{"key":"286_CR29","unstructured":"Han, J., Kamber, M., Pei, J.: Data Mining Concepts and Techniques, 3rd edn. http:\/\/www.amazon.de\/Data-Mining-Concepts-Techniques-Management\/dp\/0123814790\/ref=tmm_hrd_title_0?ie=UTF8&qid=1366039033&sr=1-1 (2012)"},{"key":"286_CR30","doi-asserted-by":"crossref","unstructured":"Invernizzi, L., Miskovic, S., Torres, R., Saha, S., Lee, S., Mellia, M., Kruegel, C., Vigna, G.: Nazca: detecting malware distribution in large-scale networks. In: Proceedings of the Network and Distributed System Security Symposium (NDSS) (2014)","DOI":"10.14722\/ndss.2014.23269"},{"key":"286_CR31","unstructured":"Kapravelos, A., Shoshitaishvili, Y., Cova, M., Kruegel, C., Vigna, G.: Revolver: an automated approach to the detection of evasive web-based malware. In: USENIX Security, Citeseer, pp. 637\u2013652 (2013)"},{"key":"286_CR32","doi-asserted-by":"crossref","unstructured":"Chinchani, R., Van Den Berg, E.: A fast static analysis approach to detect exploit code inside network flows. In: Recent Advances in Intrusion Detection. Springer, New York, pp. 284\u2013308 (2006)","DOI":"10.1007\/11663812_15"},{"key":"286_CR33","doi-asserted-by":"crossref","unstructured":"Baldoni, R., Di Luna, G.A., Querzoni, L.: Collaborative detection of coordinated port scans. In: Distributed Computing and Networking. Springer, New York, pp. 102\u2013117 (2013)","DOI":"10.1007\/978-3-642-35668-1_8"},{"key":"286_CR34","doi-asserted-by":"crossref","unstructured":"Muelder, C., Ma, K.-L., Bartoletti, T.: Interactive visualization for network and port scan detection. In: Recent Advances in Intrusion Detection. Springer, New York, pp. 265\u2013283 (2006)","DOI":"10.1007\/11663812_14"},{"key":"286_CR35","doi-asserted-by":"crossref","unstructured":"Zargar, S.T., Joshi, J., Tipper, D.: A survey of defense mechanisms against distributed denial of service (ddos) flooding attacks. IEEE Commun Surv Tutor 15(4), 2046\u20132069 (2013), online 28 May (2013)","DOI":"10.1109\/SURV.2013.031413.00127"},{"key":"286_CR36","doi-asserted-by":"crossref","unstructured":"Feinstein, L., Schnackenberg, D., Balupari, R., Kindred, D.: Statistical approaches to ddos attack detection and response. In: Proceedings of the DARPA Information Survivability Conference and Exposition, vol. 1. IEEE, New York, pp. 303\u2013314 (2003)","DOI":"10.1109\/DISCEX.2003.1194894"},{"key":"286_CR37","unstructured":"Zhao, Y., Xie, Y., Yu, F., Ke, Q., Yu, Y., Chen, Y., Gillum, E.: Botgraph: large scale spamming botnet detection. In: NSDI, vol. 9, pp. 321\u2013334 (2009)"},{"key":"286_CR38","unstructured":"Nelms, T., Perdisci, R., Ahamad, M.: Execscent: mining for new c&c domains in live networks with adaptive control protocol templates. In: USENIX Security, pp. 589\u2013604 (2013)"},{"issue":"2","key":"286_CR39","doi-asserted-by":"crossref","first-page":"487","DOI":"10.1016\/j.comnet.2012.06.022","volume":"57","author":"R Perdisci","year":"2013","unstructured":"Perdisci, R., Ariu, D., Giacinto, G.: Scalable fine-grained behavioral clustering of http-based malware. Comput. Netw. 57(2), 487\u2013500 (2013)","journal-title":"Comput. Netw."},{"key":"286_CR40","unstructured":"Goebel, J., Holz, T.: Rishi: identify bot contaminated hosts by IRC nickname evaluation. In: Proceedings of the First Conference on First Workshop on Hot Topics in Understanding Botnets, Cambridge, p. 8 (2007)"},{"key":"286_CR41","doi-asserted-by":"crossref","unstructured":"Saad, S., Traore, I., Ghorbani, A., Sayed, B., Zhao, D., Lu, W., Felix, J., Hakimian, P.: Detecting p2p botnets through network behavior analysis and machine learning. In: 2011 Ninth Annual International Conference on Privacy, Security and Trust (PST), pp. 174\u2013180. IEEE, New York (2011)","DOI":"10.1109\/PST.2011.5971980"},{"key":"286_CR42","doi-asserted-by":"crossref","unstructured":"Hsu, C.-H., Huang, C.-Y., Chen, K.-T.: Fast-flux bot detection in real time. In: Recent Advances in Intrusion Detection, pp. 464\u2013483. Springer, New York (2010)","DOI":"10.1007\/978-3-642-15512-3_24"},{"key":"286_CR43","unstructured":"Antonakakis, M., Perdisci, R., Nadji, Y., Vasiloglou, N., Abu-Nimeh, S., Lee, W., Dagon, D.: From throw-away traffic to bots: detecting the rise of DGA-based malware. In: Proceedings of the 21st USENIX Security Symposium (2012)"},{"key":"286_CR44","doi-asserted-by":"crossref","unstructured":"Khattak, S., Ramay, N., Khan, K., Syed, A., Khayam, S.: A taxonomy of botnet behavior, detection and defense. IEEE Commun. Surv. Tutor., online June (2014)","DOI":"10.1109\/SURV.2013.091213.00134"},{"key":"286_CR45","unstructured":"Fabian, M.A.R.J.Z., Terzis, M. A.: A multifaceted approach to understanding the botnet phenomenon. In: Proceedings of the 2006 ACM SIGCOMM Internet Measurement Conference (IMC), vol. 2006 (2006)"},{"key":"286_CR46","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W., et al.: Botminer: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: USENIX Security Symposium, pp. 139\u2013154 (2008)"},{"issue":"2","key":"286_CR47","doi-asserted-by":"crossref","first-page":"378","DOI":"10.1016\/j.comnet.2012.07.021","volume":"57","author":"SS Silva","year":"2013","unstructured":"Silva, S.S., Silva, R.M., Pinto, R.C., Salles, R.M.: Botnets: a survey. Comput. Netw. 57(2), 378\u2013403 (2013)","journal-title":"Comput. Netw."},{"key":"286_CR48","doi-asserted-by":"crossref","unstructured":"Hachem, N., Ben Mustapha, Y., Granadillo, G.G., Debar, H.: Botnets: lifecycle and taxonomy, In: 2011 Conference on Network and Information Systems Security (SAR-SSI), pp. 1\u20138. IEEE, New York (2011)","DOI":"10.1109\/SAR-SSI.2011.5931395"},{"key":"286_CR49","doi-asserted-by":"crossref","unstructured":"Lu, C., Brooks, R.: Botnet traffic detection using hidden markov models. In: Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence Research, p. 31. ACM, New York (2011)","DOI":"10.1145\/2179298.2179332"},{"key":"286_CR50","unstructured":"Kidmose, E.: Botnet detection using hidden Markov models. Master\u2019s thesis, Aalborg University (2014)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-016-0286-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0286-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0286-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,14]],"date-time":"2019-09-14T00:26:14Z","timestamp":1568420774000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-016-0286-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,9,30]]},"references-count":50,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,2]]}},"alternative-id":["286"],"URL":"https:\/\/doi.org\/10.1007\/s11416-016-0286-y","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,9,30]]}}}