{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:51:10Z","timestamp":1771699870750,"version":"3.50.1"},"reference-count":23,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,6]]},"DOI":"10.1109\/dsn.2011.5958212","type":"proceedings-article","created":{"date-parts":[[2011,7,21]],"date-time":"2011-07-21T15:17:24Z","timestamp":1311261444000},"page":"121-132","source":"Crossref","is-referenced-by-count":58,"title":["Detecting stealthy P2P botnets using statistical traffic fingerprints"],"prefix":"10.1109","author":[{"given":"Junjie","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roberto","family":"Perdisci","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenke","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Unum","family":"Sarfraz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiapu","family":"Luo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","author":"lemos","year":"2006","journal-title":"Bot Software Looks to Improve Peerage"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2010.5461939"},{"key":"ref12","article-title":"Finding peer-to-peer file sharing using coarse network behaviors","author":"collins","year":"2006","journal-title":"Proc ESORICS"},{"key":"ref13","article-title":"A multi-perspective analysis of the storm (peacomm) worm","author":"porras","year":"2007","journal-title":"Technical Report"},{"key":"ref14","author":"porras","year":"2009","journal-title":"Conficker C Analysis"},{"key":"ref15","article-title":"Botgrep: Finding p2p bots with structured graph analysis","author":"nagaraja","year":"2010","journal-title":"Proc Usenix Security"},{"key":"ref16","doi-asserted-by":"crossref","DOI":"10.1145\/988672.988742","article-title":"Accurate, scalable in-network identication of p2p traffic using application signatures","author":"sen","year":"2004","journal-title":"WWW"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2009.5403015"},{"key":"ref18","article-title":"Analysis of the storm and nugache trojans: P2p is here","volume":"32","author":"stover","year":"2007","journal-title":"USENIX login"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2010.76"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177105"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1071690.1064220"},{"key":"ref6","article-title":"Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection","author":"gu","year":"2008","journal-title":"Proc Usenix Security"},{"key":"ref5","article-title":"Bothunter: Detecting malware infection through IDS-driven dialog correlation","author":"gu","year":"2007","journal-title":"Proc Usenix Security"},{"key":"ref8","article-title":"Measurements and mitigation of peer-to-peer-based botnets: A case study on storm worm","author":"holz","year":"2008","journal-title":"Proc USENIX LEET"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1023\/A:1012801612483"},{"key":"ref2","year":"0","journal-title":"Autoit Script"},{"key":"ref1","year":"0","journal-title":"Auditing Network Activity"},{"key":"ref9","article-title":"Towards complete node enumeration in a peer-to-peer botnet","author":"kang","year":"2009","journal-title":"Proc ACM ASIACCS"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028804"},{"key":"ref22","article-title":"Botgraph: Large scale spamming botnet detection","author":"zhao","year":"2009","journal-title":"Proc USENIX NSDI"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/1080091.1080119"},{"key":"ref23","doi-asserted-by":"crossref","DOI":"10.1145\/235968.233324","article-title":"Birch: An efficient data clustering method for very large databases","author":"zhang","year":"1996","journal-title":"Proc ACM SIGMOD"}],"event":{"name":"Networks (DSN)","location":"Hong Kong, China","start":{"date-parts":[[2011,6,27]]},"end":{"date-parts":[[2011,6,30]]}},"container-title":["2011 IEEE\/IFIP 41st International Conference on Dependable Systems &amp; Networks (DSN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/5949577\/5958196\/05958212.pdf?arnumber=5958212","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,7]],"date-time":"2025-03-07T07:23:40Z","timestamp":1741332220000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/5958212\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,6]]},"references-count":23,"URL":"https:\/\/doi.org\/10.1109\/dsn.2011.5958212","relation":{},"subject":[],"published":{"date-parts":[[2011,6]]}}}