{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,15]],"date-time":"2026-04-15T20:52:07Z","timestamp":1776286327835,"version":"3.50.1"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2017,7,26]],"date-time":"2017-07-26T00:00:00Z","timestamp":1501027200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Peer-to-Peer Netw. Appl."],"published-print":{"date-parts":[[2018,9]]},"DOI":"10.1007\/s12083-017-0586-0","type":"journal-article","created":{"date-parts":[[2017,7,26]],"date-time":"2017-07-26T01:51:17Z","timestamp":1501033877000},"page":"848-861","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Analysis of P2P, IRC and HTTP traffic for botnets detection"],"prefix":"10.1007","volume":"11","author":[{"given":"Basil","family":"AsSadhan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abdulmuneem","family":"Bashaiwth","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jalal","family":"Al-Muhtadi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saleh","family":"Alshebeili","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,7,26]]},"reference":[{"key":"586_CR1","unstructured":", Porras P, Stoll J, Lee W (2009) Active botnet probing to identify obscure command and control channels. In annual computer security applications conference (ACSAC '09). Honolulu.Gu G, Yegneswaran V, Porras P, Stoll J, Lee W (2009) Active botnet probing to identify obscure command and control channels. In annual computer security applications conference (ACSAC '09). Honolulu"},{"key":"586_CR2","doi-asserted-by":"crossref","unstructured":"Silva S, Silva R, Pinto R, Salles R (2013) Botnets: a survey. Comput Netw 57","DOI":"10.1016\/j.comnet.2012.07.021"},{"key":"586_CR3","unstructured":"Demarest J (2014) Taking down botnets: public and private efforts to disrupt and dismantle cybercriminal networks. In U.S. senate, committee on the judiciary, subcommittee on crime and terrorism. Washington"},{"key":"586_CR4","unstructured":"FBI (2013) FBI Statement on Botnet Operation Available: http:\/\/www.fbi.gov\/news\/news_blog\/botnets-101\/fbi-statement-on-botnet-operation"},{"key":"586_CR5","volume-title":"Security threat report 2014","author":"SOPHOS","year":"2014","unstructured":"SOPHOS (2014) Security threat report 2014. Smarter, Shadier, Stealthier Malware"},{"key":"586_CR6","doi-asserted-by":"crossref","unstructured":"Ha D, Yan G, Eidenbenz S, Ngo H (2009) On the effectiveness of structural detection and defense against P2P-based botnets. In IEEE\/IFIP international conference on dependable systems & networks (DSN). Lisbon","DOI":"10.1109\/DSN.2009.5270322"},{"key":"586_CR7","doi-asserted-by":"crossref","unstructured":"Zeidanloo HR, Zadeh MJ, Safari M, Zamani M (2010) A taxonomy of botnet detection techniques. In 3rd IEEE international conference on computer science and information technology (ICCSIT). Chengdu","DOI":"10.1109\/ICCSIT.2010.5563555"},{"key":"586_CR8","unstructured":"Tao C, Futai Z (2012) Detecting HTTP botnet with clustering network traffic. In 8th international conference on wireless communications, networking and mobile computing (WiCOM), 2012. Shanghai"},{"key":"586_CR9","volume-title":"IRC botnets alive","author":"N Singh","year":"2015","unstructured":"Singh N (2015) IRC botnets alive. Evolving, Effective &"},{"key":"586_CR10","unstructured":"Vijayan J (2015) IRC botnets are not quite dead yet"},{"key":"586_CR11","volume-title":"Bots and botnets: an overview of characteristics, detection and challenges. In IEEE international conference on control system","author":"M Eslahi","year":"2012","unstructured":"Eslahi M, Salleh R, Anuar NB (2012) Bots and botnets: an overview of characteristics, detection and challenges. In IEEE international conference on control system. Computing and Engineering, Penang"},{"key":"586_CR12","unstructured":"Zhuge J, Han X, Guo J, Zou W, Holz T, Zhou Y (2007) Characterizing the IRC-based botnet phenomenon. China Honeynet Technical Report"},{"key":"586_CR13","doi-asserted-by":"crossref","unstructured":"Rodr\u00edguez-G\u00f3mez R, Maci\u00e1-Fern\u00e1ndez G, Garc\u00eda-Teodoro P, Steiner M, Balzarotti D (2014) Resource monitoring for the detection of parasite P2P botnets. Comput Netw 70","DOI":"10.1016\/j.comnet.2014.05.016"},{"key":"586_CR14","doi-asserted-by":"crossref","first-page":"1209","DOI":"10.1007\/s12083-016-0440-9","volume":"9","author":"S Garg","year":"2016","unstructured":"Garg S, Peddoju SK, Sarje AK (2016) Scalable P2P bot detection system based on network data stream. Peer-to-Peer Networking and Applications 9:1209\u20131225","journal-title":"Peer-to-Peer Networking and Applications"},{"key":"586_CR15","doi-asserted-by":"crossref","first-page":"320","DOI":"10.1007\/s12083-012-0150-x","volume":"7","author":"H Jiang","year":"2014","unstructured":"Jiang H, Shao X (2014) Detecting P2P botnets by discovering flow dependency in C&C traffic. Peer-to-Peer Networking and Applications 7:320\u2013331","journal-title":"Peer-to-Peer Networking and Applications"},{"key":"586_CR16","doi-asserted-by":"crossref","unstructured":"Choi H, Lee H (2012) Identifying botnets by capturing group activities in DNS traffic. Comput Netw 56","DOI":"10.1016\/j.comnet.2011.07.018"},{"key":"586_CR17","unstructured":"Schiller CA, Binkley J, Harley D, Evron G, Bradley T, Willems C, Cross M (2007) Botnets: the killer web app: Andrew Williams"},{"key":"586_CR18","unstructured":"Gu G, Zhang J, Lee W (2008) BotSniffer: detecting botnet command and control channels in network traffic. In the 15th network and distributed system security symposium (NDSS\u201908). San Diego"},{"key":"586_CR19","doi-asserted-by":"crossref","unstructured":"Jackson AW, Lapsley D, Jones C, Zatko M, Golubitsky C, Strayer WT (2009) SLINGbot: a system for live investigation of next generation botnets,\" in cybersecurity application and technologies conference for homeland security (CATCH). Washington","DOI":"10.1109\/CATCH.2009.26"},{"key":"586_CR20","doi-asserted-by":"crossref","unstructured":"Lippmann R, Haines J, Fried D, Korba J, Das K (2000) The 1999 DARPA off-line intrusion detection evaluation. In 3rd international workshop on recent advances in intrusion detection (RAID). New York","DOI":"10.1007\/3-540-39945-3_11"},{"key":"586_CR21","unstructured":"LBNL\/ICSI (2013) LBNL\/ICSI Enterprise Tracing Project Available: http:\/\/www.icir.org\/enterprise-tracing"},{"key":"586_CR22","doi-asserted-by":"crossref","unstructured":"Tarng W, Den L, Ou K, Chen M (2011) The analysis and identification of P2P Botnet\u2019s traffic flows. Int J Commun Netw Inf Secur 3","DOI":"10.17762\/ijcnis.v3i2.79"},{"key":"586_CR23","doi-asserted-by":"crossref","unstructured":"X. Yu, X. Dong, G. Yu, Y. Qin, D. Yue, and Y. Zhao, \"Online Botnet Detection Based on Incremental Discrete Fourier Transform,\" Journal of Networks, vol. 5, May, 2010","DOI":"10.4304\/jnw.5.5.568-576"},{"key":"586_CR24","volume-title":"Sanatkar H","author":"S Arshad","year":"2011","unstructured":"Arshad S, Abbaspour M, Kharrazi M (2011) Sanatkar H. An Anomaly-Based Botnet Detection Approach for Identifying Stealthy Botnets, In Computer Applications and Industrial Electronics (ICCAIE)"},{"key":"586_CR25","unstructured":"CISCO (2011) NetFlow Version 9 Flow-Record Format Available: http:\/\/www.cisco.com\/en\/US\/technologies\/tk648\/tk362\/technologies_white_paper09186a00800a3db9.html"},{"key":"586_CR26","volume-title":"A novel IRC botnet detection method based on packet size sequence","author":"X Ma","year":"2010","unstructured":"Ma X, Guan X, Tao J, Zheng Q, Guo Y, Liu L, Zhao S (2010) A novel IRC botnet detection method based on packet size sequence. In IEEE International Conference Communications (ICC), Cape Town"},{"issue":"4","key":"586_CR27","doi-asserted-by":"crossref","first-page":"435","DOI":"10.1016\/j.jare.2013.11.005","volume":"5","author":"B AsSadhan","year":"2014","unstructured":"AsSadhan B, Moura JMF (2014) An efficient method to detect periodic behavior in botnet traffic by analyzing control plane traffic. J Adv Res 5(4):435\u2013448","journal-title":"J Adv Res"},{"key":"586_CR28","volume-title":"Rishi: identify Dotcontaminated hosts by IRC nickname evaluation","author":"J Goebel","year":"2007","unstructured":"Goebel J, Holz T (2007) Rishi: identify Dotcontaminated hosts by IRC nickname evaluation. In First Workshop on Hot Topics in Understanding Botnets, Cambridge"},{"key":"586_CR29","unstructured":"Oppenheim AV, Schafer RW (2009) Discrete Time Signal Processing, 3rd edn edn Pearson"},{"key":"586_CR30","unstructured":"Stoica P (2005) Spectral analysis of signals. Randolph L. Moses, Ohio State University. Prentice hall."},{"key":"586_CR31","unstructured":"AsSadhan B (2009) Network traffic analysis through statistical signal processing methods. Carnegie Mellon Univ"},{"key":"586_CR32","unstructured":"Endace (2012) DAG 7.5G2 Card User Guide, Version"},{"key":"586_CR33","unstructured":"Endace (2009) Network tapping technical overview, Version"},{"key":"586_CR34","unstructured":"Pei Z, Xiao-hong H, Min-qi L, Chun-yu N, Yan M (2010) Fast restorable prefix-preserving IP address anonymization for IPv4\/IPv6. J China Univ Posts Telecommun 17"},{"key":"586_CR35","doi-asserted-by":"crossref","unstructured":"Fan J, Xu J, Ammar MH, Moon SB (2004) Prefix-preserving IP address anonymization measurement-based security evaluation and a new cryptography-based scheme. Int J Comput Telecommun Netw46.","DOI":"10.1016\/j.comnet.2004.03.033"},{"key":"586_CR36","unstructured":"Kumar SA (2012) Conficker botnet prevention: crypto-pan algorithm. Int J Eng Sci 1"},{"key":"586_CR37","unstructured":"Lapworth L (2013) The Perl Programming Language Available: http:\/\/www.perl.org"}],"container-title":["Peer-to-Peer Networking and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s12083-017-0586-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-017-0586-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-017-0586-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,24]],"date-time":"2023-08-24T18:10:11Z","timestamp":1692900611000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s12083-017-0586-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,7,26]]},"references-count":37,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2018,9]]}},"alternative-id":["586"],"URL":"https:\/\/doi.org\/10.1007\/s12083-017-0586-0","relation":{},"ISSN":["1936-6442","1936-6450"],"issn-type":[{"value":"1936-6442","type":"print"},{"value":"1936-6450","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,7,26]]}}}