{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T10:47:43Z","timestamp":1785235663487,"version":"3.55.0"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2017,8,31]],"date-time":"2017-08-31T00:00:00Z","timestamp":1504137600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,8]]},"DOI":"10.1007\/s11416-017-0306-6","type":"journal-article","created":{"date-parts":[[2017,8,31]],"date-time":"2017-08-31T01:49:47Z","timestamp":1504144187000},"page":"195-211","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":173,"title":["Deciphering malware\u2019s use of TLS (without decryption)"],"prefix":"10.1007","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4185-5801","authenticated-orcid":false,"given":"Blake","family":"Anderson","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Subharthi","family":"Paul","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"McGrew","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,8,31]]},"reference":[{"key":"306_CR1","doi-asserted-by":"crossref","unstructured":"Anderson, B., McGrew, D.: Identifying encrypted malware traffic with contextual flow data. In: ACM Workshop on Artificial Intelligence and Security (AISec), pp. 35\u201346 (2016)","DOI":"10.1145\/2996758.2996768"},{"key":"306_CR2","doi-asserted-by":"crossref","unstructured":"Anderson, B., McGrew, D.: Machine learning for encrypted malware traffic classification: accounting for noisy labels and non-stationarity. In: ACM SIGKDD International Conference on Knowledge Discovery in Data Mining (KDD), pp 1723\u20131732 (2017)","DOI":"10.1145\/3097983.3098163"},{"key":"306_CR3","doi-asserted-by":"crossref","unstructured":"Anderson, B., Storlie, C., Lane, T.: Multiple Kernel learning clustering with an application to malware. In: 12th International Conference on Data Mining (ICDM), pp. 804\u2013809. IEEE (2012)","DOI":"10.1109\/ICDM.2012.75"},{"key":"306_CR4","unstructured":"Antonakakis, M., Perdisci, R., Nadji, Y., Vasiloglou, N., Abu-Nimeh, S., Lee, W., Dagon, D.: From throw-away traffic to bots: detecting the rise of DGA-based malware. In: USENIX Security Symposium, pp. 491\u2013506 (2012)"},{"key":"306_CR5","unstructured":"Bayer, U., Comparetti, P M., Hlauschek, C., Kruegel, C., Kirda, E.: Scalable, Behavior-based malware clustering. In: Proceedings of the Network and Distributed System Security Symposium (NDSS), vol. 9, pp. 8\u201311 (2009)"},{"key":"306_CR6","doi-asserted-by":"crossref","unstructured":"Bilge, L., Balzarotti, D., Robertson W., Kirda, E., Kruegel, C.: Disclosure: detecting botnet command and control servers through large-scale netflow analysis. In: 28th Annual Computer Security Applications Conference, pp. 129\u2013138. ACM (2012)","DOI":"10.1145\/2420950.2420969"},{"issue":"1","key":"306_CR7","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1109\/MSP.2009.12","volume":"7","author":"F Callegati","year":"2009","unstructured":"Callegati, F., Cerroni, W., Ramilli, M.: Man-in-the-middle attack to the HTTPS protocol. IEEE Security & Privacy 7(1), 78\u201381 (2009)","journal-title":"IEEE Security & Privacy"},{"key":"306_CR8","unstructured":"Cisco Talos: IP Blacklist Feed. http:\/\/www.talosintel.com\/feeds\/ip-filter.blf (2016)"},{"key":"306_CR9","doi-asserted-by":"crossref","unstructured":"Dierks, T., Rescorla, E.: The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246 (2008)","DOI":"10.17487\/rfc5246"},{"key":"306_CR10","doi-asserted-by":"crossref","unstructured":"Dietterich, T G.: Approximate statistical tests for comparing supervised classification learning algorithms. Neural Comput. 10(7), 1895\u20131923 (1998)","DOI":"10.1162\/089976698300017197"},{"key":"306_CR11","doi-asserted-by":"crossref","unstructured":"Dietterich, T.G.: Ensemble methods in machine learning. In: Multiple Classifier Systems, pp. 1\u201315. Springer, Berlin (2000)","DOI":"10.1007\/3-540-45014-9_1"},{"key":"306_CR12","unstructured":"Durumeric, Z., Wustrow, E., Halderman, J.A.: ZMap: fast internet-wide scanning and its security applications. In: USENIX Security Symposium, pp. 605\u2013620 (2013)"},{"key":"306_CR13","doi-asserted-by":"crossref","unstructured":"Holz, R., Amann J., Mehani, O., Wachs, M., Kaafar, M.A.: TLS in the Wild: an internet-wide analysis of TLS-based protocols for electronic communication. In: Proceedings of the Network and Distributed System Security Symposium (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23055"},{"issue":"8","key":"306_CR14","first-page":"1519","volume":"8","author":"K Koh","year":"2007","unstructured":"Koh, K., Kim, S.J., Boyd, S.P.: An interior-point method for large-scale l1-regularized logistic regression. J. Mach. Learn. Res. 8(8), 1519\u20131555 (2007)","journal-title":"J. Mach. Learn. Res."},{"issue":"6","key":"306_CR15","doi-asserted-by":"crossref","first-page":"957","DOI":"10.1109\/TPAMI.2005.127","volume":"27","author":"B Krishnapuram","year":"2005","unstructured":"Krishnapuram, B., Carin, L., Figueiredo, M.A., Hartemink, A.J.: Sparse multinomial logistic regression: fast algorithms and generalization bounds. IEEE Trans. Pattern Anal. Mach. Intell. 27(6), 957\u2013968 (2005)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"306_CR16","unstructured":"Microsoft. Choose the right ciphersuites in SChannel. https:\/\/www.ssl.com\/how-to\/choose-the-right-cipher-suites-in-schannel-dll\/ (2016)"},{"key":"306_CR17","unstructured":"Microsoft. SChannel. https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ms678421%28v=vs.85%29.aspx (2016)"},{"key":"306_CR18","unstructured":"Most Internet Traffic will be Encrypted by Year End. Here\u2019s Why. http:\/\/fortune.com\/2015\/04\/30\/netflix-internet-traffic-encrypted\/ . Accessed 31 Oct 2016"},{"issue":"4","key":"306_CR19","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1109\/SURV.2008.080406","volume":"10","author":"TT Nguyen","year":"2008","unstructured":"Nguyen, T.T., Armitage, G.: A survey of techniques for internet traffic classification using machine learning. IEEE Commun. Surv. Tutor. 10(4), 56\u201376 (2008)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"306_CR20","doi-asserted-by":"crossref","unstructured":"Opderbeck, D.W., Hurwitz, J.G.: Apple v. FBI: Brief in Support of Neither Party in San Bernardino iPhone case. http:\/\/ssrn.com\/abstract=2746100 (2016)","DOI":"10.2139\/ssrn.2746100"},{"key":"306_CR21","doi-asserted-by":"crossref","unstructured":"Panchenko, A., Lanze, F., Zinnen, A., Henze, M., Pennekamp, J., Wehrle, K., Engel, T.: Website fingerprinting at internet scale. In: Proceedings of the Network and Distributed System Security Symposium (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23477"},{"key":"306_CR22","unstructured":"Perdisci, R., Lee, W., Feamster, N.: Behavioral clustering of HTTP-based malware and signature generation using malicious network traces. In: NSDI, pp. 391\u2013404 (2010)"},{"key":"306_CR23","unstructured":"Qualys. Qualys SSL Labs. https:\/\/www.ssllabs.com\/ssltest\/clients.html (2016)"},{"key":"306_CR24","doi-asserted-by":"crossref","unstructured":"Rieck, K., Holz, T., Willems, C., D\u00fcssel, P., Laskov, P.: Learning and classification of malware behavior. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 108\u2013125 (2008)","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"306_CR25","unstructured":"Roesch, M.: Snort\u2014lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration, LISA, pp. 229\u2013238. USENIX Association (1999)"},{"key":"306_CR26","unstructured":"Snort. Community Rules. https:\/\/www.snort.org\/downloads\/community\/community-rules.tar.gz (2016)"},{"key":"306_CR27","unstructured":"Vassilev, A.: Annex A: Approved Security Functions for FIPS PUB 140-2, Security Requirements for Cryptographic Modules. http:\/\/csrc.nist.gov\/publications\/fips\/fips140-2\/fips1402annexa.pdf (2016)"},{"key":"306_CR28","unstructured":"Virus Total. https:\/\/www.virustotal.com\/ (2016)"},{"key":"306_CR29","doi-asserted-by":"crossref","unstructured":"Wang, K., Cretu, G., Stolfo, S.J.: Anomalous payload-based worm detection and signature generation. In: International Symposium on Recent Advances in Intrusion Detection (RAID), pp. 227\u2013246. Springer, Berlin (2005)","DOI":"10.1007\/11663812_12"},{"key":"306_CR30","doi-asserted-by":"crossref","unstructured":"Wurzinger, P., Bilge, L., Holz, T., Goebel, J., Kruegel, C., Kirda, E.: Automatically generating models for botnet detection. In: Computer Security\u2013ESORICS 2009, pp. 232\u2013249. Springer (2009)","DOI":"10.1007\/978-3-642-04444-1_15"},{"key":"306_CR31","first-page":"1999","volume":"13","author":"G-X Yuan","year":"2012","unstructured":"Yuan, G.-X., Ho, C.-H., Lin, C.-J.: An improved GLMNET for L1-regularized logistic regression. J. Mach. Learn. Res. 13, 1999\u20132030 (2012)","journal-title":"J. Mach. Learn. Res."},{"key":"306_CR32","doi-asserted-by":"crossref","unstructured":"Zander, S., Nguyen, T., Armitage, G.: Automated traffic classification and application identification using machine learning. In: The 30th IEEE Conference on Local Computer Networks, pp. 250\u2013257. IEEE (2005)","DOI":"10.1109\/LCN.2005.35"},{"key":"306_CR33","unstructured":"Zeus Source Code. https:\/\/github.com\/Visgean\/Zeus"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-017-0306-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0306-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0306-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,2]],"date-time":"2019-10-02T19:50:19Z","timestamp":1570045819000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-017-0306-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,31]]},"references-count":33,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,8]]}},"alternative-id":["306"],"URL":"https:\/\/doi.org\/10.1007\/s11416-017-0306-6","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,8,31]]}}}