{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T17:02:42Z","timestamp":1775667762730,"version":"3.50.1"},"reference-count":23,"publisher":"IEEE","license":[{"start":{"date-parts":[[2019,10,1]],"date-time":"2019-10-01T00:00:00Z","timestamp":1569888000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,10,1]],"date-time":"2019-10-01T00:00:00Z","timestamp":1569888000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,10]]},"DOI":"10.1109\/ipccc47392.2019.8958714","type":"proceedings-article","created":{"date-parts":[[2020,1,16]],"date-time":"2020-01-16T21:04:32Z","timestamp":1579208672000},"page":"1-8","source":"Crossref","is-referenced-by-count":33,"title":["A Byte-level CNN Method to Detect DNS Tunnels"],"prefix":"10.1109","author":[{"given":"Chang","family":"Liu","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences School of Cyber Security, University of Chinese Academy of Sciences,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liang","family":"Dai","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences School of Cyber Security, University of Chinese Academy of Sciences,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenjing","family":"Cui","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences School of Cyber Security, University of Chinese Academy of Sciences,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tao","family":"Lin","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences School of Cyber Security, University of Chinese Academy of Sciences,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC.2013.6755060"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-10-4154-9_26"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/6137098"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.09.006"},{"key":"ref14","article-title":"Harnessing predictive models for assisting network forensic investigations of DNS tunnels","author":"homem","year":"2017","journal-title":"ADFSL Conference on Digital Forensics Security and Law"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICUFN.2016.7536939"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2014.6883426"},{"key":"ref17","article-title":"Entropy-based prediction of network protocols in the forensic analysis of DNS tunnels","author":"homem","year":"2016","journal-title":"World Congress on Internet Security (WorldCIS)"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2897795.2897804"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.256"},{"key":"ref4","author":"kaminsky","year":"0","journal-title":"Ozymandns"},{"key":"ref3","author":"bowes","year":"0","journal-title":"DNScat"},{"key":"ref6","author":"farnham","year":"2013","journal-title":"Detecting DNS Tunneling"},{"key":"ref5","author":"borges","year":"0","journal-title":"ReverseDNShell"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/EC2ND.2011.16"},{"key":"ref7","article-title":"DNS as a covert channel within protected networks","author":"bromberger","year":"2011","journal-title":"National Electronic Sector Cyber Security Organization (NESCO)"},{"key":"ref2","author":"dembour","year":"0","journal-title":"Dns2tcp"},{"key":"ref1","author":"andersson","year":"0","journal-title":"iodine"},{"key":"ref9","article-title":"Morto worm sets a (DNS) record","author":"mullaney","year":"2011","journal-title":"The Official Symantec Blog"},{"key":"ref20","first-page":"649","article-title":"Character-level convolutional networks for text classification","author":"zhang","year":"2015","journal-title":"Advances in Neural Information Processing Systems (NIPS)"},{"key":"ref22","article-title":"URLnet: Learning a URL representation with deep learning for malicious URL detection","author":"le","year":"2018","journal-title":"arXiv preprint arXiv 1802 03395"},{"key":"ref21","first-page":"438","article-title":"A deep learning based online malicious URL and DNS detection scheme","author":"jiang","year":"2017","journal-title":"International Conference on Security and Privacy in Communication Systems"},{"key":"ref23","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1607 02533"}],"event":{"name":"2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC)","location":"London, UK","start":{"date-parts":[[2019,10,29]]},"end":{"date-parts":[[2019,10,31]]}},"container-title":["2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8955479\/8958711\/08958714.pdf?arnumber=8958714","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T19:21:52Z","timestamp":1756754512000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8958714\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,10]]},"references-count":23,"URL":"https:\/\/doi.org\/10.1109\/ipccc47392.2019.8958714","relation":{},"subject":[],"published":{"date-parts":[[2019,10]]}}}