{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,9]],"date-time":"2025-09-09T20:53:39Z","timestamp":1757451219546},"reference-count":20,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,7,1]],"date-time":"2020-07-01T00:00:00Z","timestamp":1593561600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,7,1]],"date-time":"2020-07-01T00:00:00Z","timestamp":1593561600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,7,1]],"date-time":"2020-07-01T00:00:00Z","timestamp":1593561600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,7]]},"DOI":"10.1109\/iscc50000.2020.9219547","type":"proceedings-article","created":{"date-parts":[[2020,10,12]],"date-time":"2020-10-12T17:03:51Z","timestamp":1602522231000},"page":"1-7","source":"Crossref","is-referenced-by-count":13,"title":["Towards Comprehensive Detection of DNS Tunnels"],"prefix":"10.1109","author":[{"given":"Meng","family":"Luo","sequence":"first","affiliation":[]},{"given":"Qiuyun","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Yepeng","family":"Yao","sequence":"additional","affiliation":[]},{"given":"Xuren","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Peian","family":"Yang","sequence":"additional","affiliation":[]},{"given":"Zhengwei","family":"Jiang","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_14"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2016.02.009"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897877"},{"key":"ref13","first-page":"399","article-title":"Hindom: A robust malicious domain detection system based on heterogeneous information network with transductive classification","author":"sun","year":"2019","journal-title":"22nd International Symposium on Research in Attacks Intrusions and Defenses (RAID 2019)"},{"key":"ref14","article-title":"Detecting DNS tunnels using character frequency analysis","author":"born","year":"2010","journal-title":"CoRR"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2014.6883426"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38998-6_16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CAMAD.2014.7033254"},{"key":"ref18","first-page":"17","article-title":"Practical comprehensive bounds on surreptitious communication over DNS","author":"paxson","year":"2013","journal-title":"Presented as part of the 22nd USENIX Security Symposium (USENIX Security 13)"},{"key":"ref19","article-title":"Entropy-based prediction of network protocols in the forensic analysis of dns tunnels","author":"homem","year":"2017","journal-title":"arXiv preprint arXiv 1709 06363"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.256"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.09.006"},{"key":"ref6","first-page":"469","article-title":"Detecting credential spearphishing in enterprise settings","author":"ho","year":"0","journal-title":"26th USENIX Security Symposium (USENIX Security 17)"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134049"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2018.12.005"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2008.17"},{"year":"0","key":"ref2","article-title":"Advanced persistent threat groups"},{"key":"ref1","article-title":"A study of newly observed hostnames and dns tunneling in the wild","author":"tatang","year":"2019","journal-title":"arXiv preprint arXiv 1902 08454"},{"key":"ref9","first-page":"1165","article-title":"FANCI: Feature-based automated nxdomain classification and intelligence","author":"sch\u00fcppen","year":"2018","journal-title":"27th USENIX Security Symposium (USENIX Security 18)"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355580"}],"event":{"name":"2020 IEEE Symposium on Computers and Communications (ISCC)","start":{"date-parts":[[2020,7,7]]},"location":"Rennes, France","end":{"date-parts":[[2020,7,10]]}},"container-title":["2020 IEEE Symposium on Computers and Communications (ISCC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9213178\/9219543\/09219547.pdf?arnumber=9219547","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,28]],"date-time":"2022-06-28T17:52:01Z","timestamp":1656438721000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9219547\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7]]},"references-count":20,"URL":"https:\/\/doi.org\/10.1109\/iscc50000.2020.9219547","relation":{},"subject":[],"published":{"date-parts":[[2020,7]]}}}