{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T23:57:11Z","timestamp":1725580631015},"reference-count":27,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,10,4]],"date-time":"2021-10-04T00:00:00Z","timestamp":1633305600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,10,4]],"date-time":"2021-10-04T00:00:00Z","timestamp":1633305600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,10,4]]},"DOI":"10.1109\/cns53000.2021.9705029","type":"proceedings-article","created":{"date-parts":[[2022,2,10]],"date-time":"2022-02-10T20:28:04Z","timestamp":1644524884000},"page":"164-172","source":"Crossref","is-referenced-by-count":0,"title":["An uneven game of hide and seek: Hiding botnet CnC by encrypting IPs in DNS records"],"prefix":"10.1109","author":[{"given":"Martin","family":"Fejrskov","sequence":"first","affiliation":[{"name":"Technology, IP Network and Core Telenor A\/S,Aalborg,Denmark"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jens Myrup","family":"Pedersen","sequence":"additional","affiliation":[{"name":"Aalborg University,Cyber Security Group,Copenhagen,Denmark"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leon","family":"Bock","sequence":"additional","affiliation":[{"name":"Technische Universit&#x00E4;t Darmstadt,Telecooperation Lab,Darmstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emmanouil","family":"Vasilomanolakis","sequence":"additional","affiliation":[{"name":"Aalborg University,Cyber Security Group,Copenhagen,Denmark"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"year":"2017","key":"ref10","article-title":"Sage 2.0 comes with IP Generation Algorithm (IPGA)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.17487\/rfc3972"},{"key":"ref12","article-title":"A survey of network traffic anonymisation techniques and implementations","author":"dijkhuizen","year":"2018","journal-title":"ACM Computing Surveys"},{"article-title":"IP Flow Anonymization Support, RFC 6235","year":"2011","author":"boschi","key":"ref13"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-05445-7_19"},{"key":"ref15","article-title":"Prefix-preserving IP address anonymization: measurement-based security evaluation and a new cryptography-based scheme","author":"xu","year":"2002","journal-title":"IEEE International Conference on Network Protocols"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-77566-9_49"},{"year":"2019","key":"ref17","article-title":"Threat detection, Cisco Stealthwatch at work"},{"year":"2019","key":"ref18","article-title":"Cisco Umbrella Investigate"},{"year":"2019","key":"ref19","article-title":"Infoblox advanced DNS protection"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-38G"},{"key":"ref27","article-title":"Encrypted and covert DNS queries for botnets: Challenges and countermeasures","author":"patsakis","year":"2019","journal-title":"Computers & Security"},{"year":"2020","key":"ref3","article-title":"IANA IPv4 Special-Purpose Address Registry"},{"article-title":"FFX schemes","year":"2020","author":"buchanan","key":"ref6"},{"article-title":"FFX","year":"2018","author":"dyer","key":"ref5"},{"year":"2002","key":"ref8","article-title":"NetworkX algorithms, k clique communities"},{"article-title":"IGA: A python module for format- and semantics preserving encryption and decryption of IP addresses","year":"2021","author":"fejrskov","key":"ref7"},{"key":"ref2","article-title":"Semantics-Preserving Encryption for Computer Networking Related Data Types","author":"l\u00e1di","year":"2017","journal-title":"AIS International Symposium on Applied Informatics and Related Areas"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecurity49315.2020.9138869"},{"key":"ref1","article-title":"A Comprehensive Measurement Study of Domain Generating Malware","author":"plohmann","year":"2016","journal-title":"USENIX Security Symposium"},{"year":"2015","key":"ref20","article-title":"HP ArcSight DNS malware analytics datasheet"},{"article-title":"Detecting reflection attacks in DNS flows","year":"2013","author":"huistra","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2015.7140486"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2011.05.026"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3199478.3199505"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2014.03.002"},{"article-title":"Understanding and Controlling Unnamed Internet Traffic","year":"2017","author":"janbeglou","key":"ref25"}],"event":{"name":"2021 IEEE Conference on Communications and Network Security (CNS)","start":{"date-parts":[[2021,10,4]]},"location":"Tempe, AZ, USA","end":{"date-parts":[[2021,10,6]]}},"container-title":["2021 IEEE Conference on Communications and Network Security (CNS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9705016\/9705017\/09705029.pdf?arnumber=9705029","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,30]],"date-time":"2022-05-30T23:08:20Z","timestamp":1653952100000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9705029\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,4]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/cns53000.2021.9705029","relation":{},"subject":[],"published":{"date-parts":[[2021,10,4]]}}}