{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T12:36:36Z","timestamp":1779194196272,"version":"3.51.4"},"reference-count":231,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Commun. Surv. Tutorials"],"published-print":{"date-parts":[[2016]]},"DOI":"10.1109\/comst.2015.2497690","type":"journal-article","created":{"date-parts":[[2015,11,4]],"date-time":"2015-11-04T19:52:09Z","timestamp":1446666729000},"page":"1197-1227","source":"Crossref","is-referenced-by-count":112,"title":["Darknet as a Source of Cyber Intelligence: Survey, Taxonomy, and Characterization"],"prefix":"10.1109","volume":"18","author":[{"given":"Claude","family":"Fachkha","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref170","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029624"},{"key":"ref171","doi-asserted-by":"publisher","DOI":"10.1117\/12.500849"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.1145\/1103626.1103638"},{"key":"ref173","article-title":"Worm hotspots: Explaining non-uniformity in worm targeting behavior","author":"cooke","year":"2004"},{"key":"ref176","doi-asserted-by":"publisher","DOI":"10.1145\/1103626.1103637"},{"key":"ref175","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330150"},{"key":"ref178","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_13"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.857113"},{"key":"ref168","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15257-3_12"},{"key":"ref169","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2008.205"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1216370.1216373"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1269880.1269883"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCEE.2008.106"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.106"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.59"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.08.003"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.38"},{"key":"ref35","article-title":"Honeytokens: The other honeypot","author":"spitzner","year":"2003"},{"key":"ref34","article-title":"Grays anatomy: Dissecting scanning activities using IP gray space analysis","author":"jin","year":"0","journal-title":"Proc of SysML"},{"key":"ref181","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2011.2161288"},{"key":"ref180","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2008.ECP.387"},{"key":"ref185","article-title":"Honeypot traces forensics : The observation view point matters","author":"pham","year":"2009"},{"key":"ref184","first-page":"2","article-title":"Modeling botnet propagation using time zones","volume":"6","author":"dagon","year":"0","journal-title":"Proc NDSS"},{"key":"ref183","doi-asserted-by":"publisher","DOI":"10.1145\/948134.948136"},{"key":"ref182","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2005.31"},{"key":"ref189","first-page":"49","article-title":"Revealing botnet membership using DNSBL counter-intelligence","author":"ramachandran","year":"0","journal-title":"USENIX Steps to Reducing Unwanted Traffic on the Internet"},{"key":"ref188","first-page":"139","article-title":"Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection","author":"gu","year":"0","journal-title":"Proc 17th Conf Security Symp"},{"key":"ref187","first-page":"6","article-title":"The Zombie roundup: Understanding, detecting, and disrupting botnets","author":"cooke","year":"0","journal-title":"Proc Steps to Reducing Unwanted Traffic on the Internet Workshop (SRUTI '05)"},{"key":"ref186","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2008.35"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/174194.174199"},{"key":"ref27","first-page":"111","article-title":"Exit from hell? Reducing the impact of amplification DDoS attacks","author":"k\u00fchrer","year":"0","journal-title":"Proc 23rd USENIX Secur Symp (USENIX Secur )"},{"key":"ref179","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2010.5502463"},{"key":"ref29","article-title":"The spread of the sapphire\/slammer worm","author":"moore","year":"2003"},{"key":"ref20","first-page":"1","article-title":"A virtual honeypot framework","volume":"173","author":"provos","year":"0","journal-title":"Proc Usenix Secur Symp"},{"key":"ref22","first-page":"65","article-title":"An internet-wide view of internet-wide scanning","author":"durumeric","year":"0","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref21","author":"liston","year":"2014","journal-title":"LaBrea Sticky Honeypot and IDS"},{"key":"ref24","first-page":"8","article-title":"The dark oracle: Perspective-aware unused and unreachable address discovery","volume":"6","author":"cooke","year":"0","journal-title":"Proc NSDI"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/2398776.2398778"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23233"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2014.6814019"},{"key":"ref50","year":"2009","journal-title":"Port Scanning Techniques"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"ref154","first-page":"21","article-title":"Internet attack knowledge discovery via clusters and cliques of attack traces","volume":"1","author":"clark","year":"2006","journal-title":"J Inf Assur Secur"},{"key":"ref153","article-title":"Opportunistic measurement: Extracting insight from spurious traffic","author":"casado","year":"0","journal-title":"Proc the 4th ACM Workshop on Hot Topics in Networks (HotNets-IV)"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2010.5447920"},{"key":"ref155","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2013.6641050"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.1109\/ICIMP.2009.8"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2008.308"},{"key":"ref151","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2013.6566977"},{"key":"ref146","first-page":"11","author":"thonnard","year":"0","journal-title":"Proc ACM SIGKDD Workshop CyberSecur Intell Informat"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2009.5168009"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1109\/CRISIS.2012.6378947"},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1109\/NPC.2008.81"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_8"},{"key":"ref58","article-title":"Global intrusion detection in the domino overlay system","author":"yegneswaran","year":"0","journal-title":"Proc NDSS"},{"key":"ref57","first-page":"1","article-title":"Greystar: Fast and accurate detection of SMS spam numbers in large cellular networks using gray phone space","author":"jiang","year":"0","journal-title":"Proc 22nd USENIX Secur Symp"},{"key":"ref56","year":"2013","journal-title":"The DDoS That Knocked Spamhaus Offline"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2398776.2398778"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/MINES.2011.61"},{"key":"ref53","year":"2009","journal-title":"Conficker\/Conflicker\/Downadup as seen from the UCSD Network Telescope"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2012.6320455"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CATCH.2009.40"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC.2011.5766474"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2012.04.002"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2012.04.018"},{"key":"ref164","article-title":"On the inference and prediction of DDoS campaigns","author":"fachkha","year":"2014","journal-title":"Wireless Communications and Mobile Computing"},{"key":"ref163","doi-asserted-by":"publisher","DOI":"10.1109\/NCA.2013.13"},{"key":"ref162","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.39"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1145\/2388576.2388587"},{"key":"ref160","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2012.09.010"},{"key":"ref4","year":"2014","journal-title":"Technical Details behind A 400Gbps NTP Amplification DDoS Attack"},{"key":"ref3","year":"2012","journal-title":"Flame Massive Cyber-Attack Discovered Researchers Say"},{"key":"ref6","article-title":"Shining light on dark address space","author":"labovitz","year":"2001"},{"key":"ref5","year":"2014","journal-title":"Testimony&#x2013;Taking Down Botnets"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/1132026.1132027"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1145\/2480362.2480517"},{"key":"ref7","article-title":"There be dragons","author":"bellovin","year":"0","journal-title":"Proc USENIX Summer"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.102913.00020"},{"key":"ref157","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2006.39"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2006.286376"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2013.6678928"},{"key":"ref46","year":"1998","journal-title":"Smurf IP Denial-of-Service Attacks"},{"key":"ref45","first-page":"63","article-title":"A survey: Recent advances and future trends in honeypot research","volume":"4","author":"fujinoki","year":"2012","journal-title":"Int J Comput Netw Secur"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879149"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/505659.505664"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxr035"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2008.4483668"},{"key":"ref44","article-title":"Taxonomy of honeypots","author":"seifert","year":"2006"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/PDCAT.2003.1236295"},{"key":"ref73","article-title":"Toward a model for source addresses of internet background radiation","author":"barford","year":"0","journal-title":"Proc Passive Active Measurements"},{"key":"ref72","first-page":"225","article-title":"On the effectiveness of distributed worm monitoring","author":"rajab","year":"0","journal-title":"Proc 14th USENIX Secur Symp"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2008.54"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2005.6"},{"key":"ref76","article-title":"Shedding light on the configuration of dark addresses","author":"sinha","year":"0","journal-title":"Proc Proc Netw Distrib Syst Secur Symp (NDSS&#x2019;07)"},{"key":"ref77","first-page":"209","article-title":"Vulnerabilities of passive internet threat monitors","author":"shinoda","year":"0","journal-title":"Proc 14th USENIX Secur Symp"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ATNAC.2007.4665254"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_11"},{"key":"ref78","article-title":"Mapping internet sensors with probe response attacks","author":"bethencourt","year":"0","journal-title":"Proc USENIX Security07"},{"key":"ref79","first-page":"8","article-title":"The dark oracle: Perspective-aware unused and unreachable address discovery","volume":"6","author":"cooke","year":"0","journal-title":"Proc NSDI"},{"key":"ref60","article-title":"Using honeynets for internet situational awareness","author":"yegneswaran","year":"2005"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/1016687.1016696"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1002\/sec.796"},{"key":"ref63","article-title":"A hybrid honeypot architecture for scalable network monitoring","author":"bailey","year":"2004"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330135"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_4"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-0140-8_6"},{"key":"ref67","first-page":"3","article-title":"Leurre.com: On the advantages of deploying a large scale distributed honeypot platform","author":"pouget","year":"0","journal-title":"Proc E-Crime Comput Conf (ECCE)"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15476-8_14"},{"key":"ref69","first-page":"1","author":"bailey","year":"0","journal-title":"Proc Network and Distributed System Security Symp (NDSS)"},{"key":"ref197","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-68768-1_2"},{"key":"ref198","article-title":"A statistical packet inspection for extraction of spoofed IP packets on darknet","author":"eto","year":"0","journal-title":"Proc Joint Workshop Inf Security"},{"key":"ref199","doi-asserted-by":"publisher","DOI":"10.1109\/WAINA.2011.111"},{"key":"ref193","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2013.09.008"},{"key":"ref194","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533063"},{"key":"ref195","doi-asserted-by":"publisher","DOI":"10.1145\/2382416.2382423"},{"key":"ref196","first-page":"250","article-title":"Misleading and defeating importance-scanning malware propagation","author":"gu","year":"0","journal-title":"3rd Int Conf Secur Privacy Commun Netw (SecureComm )"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1145\/1314389.1314398"},{"key":"ref94","year":"2014","journal-title":"Project Noah"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1145\/1159913.1159947"},{"key":"ref93","year":"2014","journal-title":"Arakis Project"},{"key":"ref191","first-page":"1","article-title":"Bothunter: Detecting malware infection through IDS-driven dialog correlation","volume":"7","author":"gu","year":"0","journal-title":"Proc USENIX Security07"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10684-2_63"},{"key":"ref192","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2013.9"},{"key":"ref91","article-title":"Tracking global threats with the internet motion sensor","author":"bailey","year":"0","journal-title":"32nd Meeting of the North American Network Operators Group"},{"key":"ref90","year":"2014"},{"key":"ref98","year":"2014","journal-title":"Japan CERT Coordination Center"},{"key":"ref99","year":"2014","journal-title":"The IUCC\/IDC Internet Telescope"},{"key":"ref96","year":"2014","journal-title":"Internet Background Noise (IBN)"},{"key":"ref97","year":"2014","journal-title":"Police Internet Activities Monitored"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/VCON.2010.13"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/2513456.2513504"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/WISTDCS.2008.14"},{"key":"ref83","year":"2009","journal-title":"ATLAS"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/1162666.1162677"},{"key":"ref89","year":"2014","journal-title":"About the Honeynet Project"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1145\/1978672.1978677"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/WISTDCS.2008.8"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1007\/1-4020-3381-8_13"},{"key":"ref88","article-title":"Building and deploying Billy Goat, a worm-detection system","author":"riordan","year":"2006"},{"key":"ref200","doi-asserted-by":"publisher","DOI":"10.1109\/ICN.2010.43"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2015.01.016"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663717"},{"key":"ref209","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.49"},{"key":"ref203","article-title":"Censorship and co-option of the internet infrastructure","author":"bailey","year":"2011"},{"key":"ref204","first-page":"447","article-title":"Gaining insight into as-level outages through analysis of internet background radiation","author":"benson","year":"0","journal-title":"Proc IEEE Conf Comput Commun Workshops (INFOCOM WKSHPS)"},{"key":"ref201","doi-asserted-by":"publisher","DOI":"10.1145\/1851275.1851237"},{"key":"ref202","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068818"},{"key":"ref207","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2009.5062023"},{"key":"ref208","doi-asserted-by":"publisher","DOI":"10.1109\/78.258082"},{"key":"ref205","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486017"},{"key":"ref206","doi-asserted-by":"publisher","DOI":"10.1109\/ICTEL.2008.4652715"},{"key":"ref211","doi-asserted-by":"publisher","DOI":"10.4018\/jdcf.2011040104"},{"key":"ref210","article-title":"A chi-square testing-based intrusion detection model","author":"abouzakhar","year":"0","journal-title":"Proc 4th Int Conf Cybercrime Forensics Educ Train"},{"key":"ref212","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32384-3_36"},{"key":"ref213","year":"2014","journal-title":"MAWI working group traffic archive"},{"key":"ref214","first-page":"4","article-title":"Hell of a handshake: Abusing TCP for reflective amplification DDoS attacks","author":"k\u00fchrer","year":"0","journal-title":"Proceedings of USENIX Workshop on Offensive Technologies (WOOT)"},{"key":"ref215","doi-asserted-by":"publisher","DOI":"10.1145\/2069216.2069227"},{"key":"ref216","first-page":"3","author":"joslyn","year":"0","journal-title":"1st Int Workshop Graph Data Manage Exp Syst"},{"key":"ref217","doi-asserted-by":"publisher","DOI":"10.1109\/IAW.2005.1495932"},{"key":"ref218","doi-asserted-by":"publisher","DOI":"10.1145\/1108590.1108604"},{"key":"ref219","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78243-8_17"},{"key":"ref220","doi-asserted-by":"publisher","DOI":"10.1145\/1179576.1179583"},{"key":"ref222","article-title":"L3dgeworld 2.3 input & output specifications","author":"parry","year":"2008"},{"key":"ref221","author":"harrop","year":"0","journal-title":"Proc of 5th ACM SIGCOMM workshop on Network and system support for games (NetGames '06)"},{"key":"ref229","first-page":"2070","article-title":"Stateful NAT64: Network address and protocol translation from IPv6 clients to IPv4 servers","author":"bagnulo","year":"0","journal-title":"IET PROC"},{"key":"ref228","year":"2015","journal-title":"CAIDA Visualization Tools"},{"key":"ref227","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78243-8_10"},{"key":"ref226","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.12.003"},{"key":"ref225","doi-asserted-by":"publisher","DOI":"10.4304\/jnw.6.4.577-586"},{"key":"ref224","doi-asserted-by":"publisher","DOI":"10.1145\/1503370.1503377"},{"key":"ref223","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2010.5502264"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2009.2039492"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1109\/IAS.2009.298"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1007\/11758501_163"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1145\/1899503.1899544"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1111\/j.1468-0394.2010.00576.x"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-20320-6_74"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1007\/11422778_59"},{"key":"ref133","article-title":"Tracking global wide configuration errors","author":"francois","year":"0","journal-title":"MonAM'06 Proceedings of the IEEE\/IST Workshop on Monitoring Attack Detection and Mitigation"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2006.03.011"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1109\/ICCS.2008.4737333"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1109\/ICCITechnology.2013.6579538"},{"key":"ref230","first-page":"674","article-title":"Learning and teaching styles in engineering education","volume":"78","author":"felder","year":"1988","journal-title":"Eng Educ"},{"key":"ref231","year":"2014","journal-title":"LOIC"},{"key":"ref136","first-page":"1","article-title":"Activity monitoring for large honeynets and network telescopes","volume":"1","author":"fran\u00e7ois","year":"2008","journal-title":"Int J Adv Syst Meas"},{"key":"ref135","first-page":"30","article-title":"Learning more about attack patterns with honeypots","author":"holz","year":"0","journal-title":"Proc Sicherheit"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2008.330"},{"key":"ref137","first-page":"129","article-title":"Analysis of time-series correlations of packet arrivals to darknet and their size-and location-dependencies","volume":"28","author":"ohta","year":"2011","journal-title":"Soft Computing"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2008.50"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.1145\/781027.781045"},{"key":"ref141","first-page":"1","article-title":"Adaptive network intrusion detection system using a hybrid approach","author":"karthick","year":"0","journal-title":"Proc 4th Int Conf Commun Syst Netw (COMSNETS)"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-0140-8_5"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02490-0_71"},{"key":"ref2","year":"2010","journal-title":"Stuxnet Worm &#x2019;Targeted High-Value Iranian Assets&#x2019;"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2008.78"},{"key":"ref1","author":"doyle","year":"2006","journal-title":"Cybercrime An Overview of the Federal Computer Fraud and Abuse Statute and Related Federal Criminal Laws"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2008.05.012"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04342-0_33"},{"key":"ref108","year":"2014","journal-title":"DShield Community-Based Collaborative Firewall Log Correlation System"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.1109\/WISTDCS.2008.16"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_9"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/1217935.1217938"},{"key":"ref104","article-title":"SGNET: A distributed infrastructure to handle zero-day exploits","author":"leita","year":"2007"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.12"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1145\/2378956.2378965"},{"key":"ref111","year":"2014","journal-title":"An Introduction to the Simwood Darknet"},{"key":"ref112","year":"2014","journal-title":"The Darknet Mesh Project"},{"key":"ref110","year":"2008"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/2096149.2096154"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029627"},{"key":"ref12","year":"2015","journal-title":"CAIDA The UCSD Network Telescope"},{"key":"ref13","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1007\/3-540-44702-4_4","article-title":"Freenet: A distributed anonymous information storage and retrieval system","author":"clarke","year":"2001","journal-title":"Designing Privacy Enhancing Technologies"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2010.5461962"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/10941270_23"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/510726.510756"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2008.ECP.314"},{"key":"ref17","year":"2004","journal-title":"Team Cymru Community Services The Darknet Project"},{"key":"ref117","first-page":"42","article-title":"Estimating internet address space usage through passive measurements","author":"dainotti","year":"0","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"ref18","article-title":"Network telescopes: Technical report","author":"moore","year":"2004"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2005.46"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.79"},{"key":"ref114","first-page":"1","article-title":"A baseline study of potentially malicious activity across five network telescopes","author":"irwin","year":"0","journal-title":"Proc 5th Int Conf Cyber Conflict (CyCon)"},{"key":"ref113","article-title":"A framework for the application of network telescope sensors in a global IP network","author":"irwin","year":"2011"},{"key":"ref116","doi-asserted-by":"publisher","DOI":"10.1587\/transcom.E95.B.1915"},{"key":"ref115","first-page":"13","article-title":"Initial results from an IPv6 darknet","author":"ford","year":"0","journal-title":"Proc IEEE Int Conf Internet Surveill Prot (ICISP)"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-73614-1_9"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1145\/2504730.2504732"},{"key":"ref122","first-page":"417","article-title":"Classifying Internet one-way traffic","author":"glatz","year":"0","journal-title":"Proc ACM SIGMETRICS Int Conf Meas Model Comput Syst"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1109\/EIDWT.2013.70"}],"container-title":["IEEE Communications Surveys &amp; Tutorials"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9739\/7475979\/07317717.pdf?arnumber=7317717","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:45:22Z","timestamp":1642005922000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7317717\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"references-count":231,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/comst.2015.2497690","relation":{},"ISSN":["1553-877X"],"issn-type":[{"value":"1553-877X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}