{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T17:03:18Z","timestamp":1783184598032,"version":"3.54.6"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/3.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2018]]},"DOI":"10.1109\/access.2018.2846740","type":"journal-article","created":{"date-parts":[[2018,6,13]],"date-time":"2018-06-13T18:51:00Z","timestamp":1528915860000},"page":"38947-38958","source":"Crossref","is-referenced-by-count":64,"title":["BotDet: A System for Real Time Botnet Command and Control Traffic Detection"],"prefix":"10.1109","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3702-3866","authenticated-orcid":false,"given":"Ibrahim","family":"Ghafir","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vaclav","family":"Prenosil","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1058-0996","authenticated-orcid":false,"given":"Mohammad","family":"Hammoudeh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thar","family":"Baker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2127-1235","authenticated-orcid":false,"given":"Sohail","family":"Jabbar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shehzad","family":"Khalid","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sardar","family":"Jaf","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.144"},{"key":"ref33","year":"2015","journal-title":"The Inevitable Move&#x2014;64-Bit Zeus Enhanced With Tor"},{"key":"ref32","year":"2017","journal-title":"New_Connection Event"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/GCCT.2015.7342657"},{"key":"ref30","year":"2015","journal-title":"DNS Fast Flux&#x2014;Analysis and Detection"},{"key":"ref37","year":"2017","journal-title":"x509_Certificate Event"},{"key":"ref36","year":"2017","journal-title":"Intelligence Framework"},{"key":"ref35","first-page":"27","article-title":"Malicious SSL certificate detection: A step towards advanced persistent threat defence","author":"ghafir","year":"2017","journal-title":"Proc Int Conf Future Netw Distrib Syst"},{"key":"ref34","year":"2015","journal-title":"Detecting Tor Communication in Network Traffic"},{"key":"ref28","year":"2015","journal-title":"Analysis of CTU-MALWARE-Capture-1 (ZBOT OOWO)"},{"key":"ref27","author":"kowalski","year":"2015","journal-title":"Tor Network Status"},{"key":"ref29","year":"2015","journal-title":"Botnet Malware Pcaps"},{"key":"ref2","year":"2018","journal-title":"US Department of Health and Human Services report"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.5220\/0005968201330146"},{"key":"ref20","first-page":"46","article-title":"User traffic profile for traffic reduction and effective botnet C&C detection","volume":"16","author":"balram","year":"2014","journal-title":"IJ Network Security"},{"key":"ref22","article-title":"Automatically generating models for botnet detection","volume":"5789","author":"wurzinger","year":"2009","journal-title":"Computers and Security"},{"key":"ref21","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-23496-5_17","article-title":"Detection and classification of different botnet C&C channels","volume":"6906","author":"fedynyshyn","year":"2011","journal-title":"Autonomic and Trusted Computing"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"ref23","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-04342-0_17","article-title":"Exploiting temporal persistence to detect covert botnet channels","volume":"5758","author":"giroire","year":"2009","journal-title":"Recent Advances Intrusion Detection"},{"key":"ref26","year":"2018","journal-title":"RT Request Tracker"},{"key":"ref25","year":"2015","journal-title":"The Bro Network Security Monitor"},{"key":"ref50","year":"2016","journal-title":"Input Framework"},{"key":"ref51","year":"2015","journal-title":"Detecting Tor Communication in Network Traffic"},{"key":"ref52","year":"2015","journal-title":"Network Tracing"},{"key":"ref10","article-title":"Net pioneer predicts overwhelming botnet surge","author":"sturgeon","year":"2007"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/NCA.2009.56"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2014.1410"},{"key":"ref12","article-title":"BotSniffer: Detecting botnet command and control channels in network traffic","author":"gu","year":"2008","journal-title":"Proc 15th Annu Netw Distrib Syst Secur Symp"},{"key":"ref13","author":"kumar","year":"2013","journal-title":"Nepenthes Honeypots Based Botnet Detection"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1002\/sec.800"},{"key":"ref15","author":"behal","year":"2010","journal-title":"Signature-Based Botnet Detection and Prevention"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAIE.2011.6162198"},{"key":"ref17","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1016\/j.jnca.2012.05.003","article-title":"A survey of intrusion detection techniques in cloud","volume":"36","author":"modi","year":"2013","journal-title":"J Netw Comput Appl"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2012.09.004"},{"key":"ref19","article-title":"Implementation of signature-based detection system using snort in windows","volume":"3","author":"agarwal","year":"2014","journal-title":"Int J Innov Adv Comput Sci"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1132026.1132027"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1810891.1810904"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2002-101-205"},{"key":"ref5","article-title":"Detecting targeted attacks using shadow honeypots","author":"anagnostakis","year":"2005","journal-title":"Usenix Security"},{"key":"ref8","article-title":"Know your enemy: Tracking botnets","author":"bacher","year":"2005"},{"key":"ref7","first-page":"1","article-title":"Cyber threat landscape faced by financial and insurance industry","author":"choo","year":"2011"},{"key":"ref49","year":"2017","journal-title":"Connection_Established Event"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2018.01.036"},{"key":"ref46","author":"jagerman","year":"2014","journal-title":"The fifteen year struggle of decentralizing privacy-enhancing technology"},{"key":"ref45","article-title":"Analysis of the Tor browser and its security vulnerabilities","author":"kapadia","year":"2014"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2014.1411"},{"key":"ref47","author":"kowalski","year":"2017","journal-title":"Tor Network Status"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW.2014.20"},{"key":"ref41","year":"2017","journal-title":"DNS_Message Event"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-014-0256-7"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/2516760.2516773"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8274985\/08384239.pdf?arnumber=8384239","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,26]],"date-time":"2022-01-26T12:51:14Z","timestamp":1643201474000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8384239\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"references-count":52,"URL":"https:\/\/doi.org\/10.1109\/access.2018.2846740","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}