{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T18:26:13Z","timestamp":1787163973742,"version":"build-2736575974"},"reference-count":74,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"10","license":[{"start":{"date-parts":[[2023,5,15]],"date-time":"2023-05-15T00:00:00Z","timestamp":1684108800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,5,15]],"date-time":"2023-05-15T00:00:00Z","timestamp":1684108800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,5,15]],"date-time":"2023-05-15T00:00:00Z","timestamp":1684108800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100009532","name":"Ministry of Interior of the Czech Republic through Flow-Based Encrypted Traffic Analysis","doi-asserted-by":"publisher","award":["VJ02010024"],"award-info":[{"award-number":["VJ02010024"]}],"id":[{"id":"10.13039\/100009532","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Agency of the CTU in Prague"},{"DOI":"10.13039\/100007655","name":"MEYS of the Czech Republic","doi-asserted-by":"publisher","award":["SGS20\/210\/OHK3\/3T\/18"],"award-info":[{"award-number":["SGS20\/210\/OHK3\/3T\/18"]}],"id":[{"id":"10.13039\/100007655","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2023,5,15]]},"DOI":"10.1109\/jiot.2022.3228816","type":"journal-article","created":{"date-parts":[[2022,12,13]],"date-time":"2022-12-13T14:42:02Z","timestamp":1670942522000},"page":"8416-8431","source":"Crossref","is-referenced-by-count":19,"title":["BOTA: Explainable IoT Malware Detection in Large Networks"],"prefix":"10.1109","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7339-4803","authenticated-orcid":false,"given":"Daniel","family":"Uh\u0159\u00ed\u010dek","sequence":"first","affiliation":[{"name":"Network Security Lab, Avast Software s.r.o., Prague, Czech Republic"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8281-618X","authenticated-orcid":false,"given":"Karel","family":"Hynek","sequence":"additional","affiliation":[{"name":"Security and Administration Department, CESNET z.s.p.o., Prague, Czech Republic"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7794-9511","authenticated-orcid":false,"given":"Tom\u00e1\u0161","family":"\u010cejka","sequence":"additional","affiliation":[{"name":"Security and Administration Department, CESNET z.s.p.o., Prague, Czech Republic"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2094-6560","authenticated-orcid":false,"given":"Du\u0161an","family":"Kol\u00e1\u0159","sequence":"additional","affiliation":[{"name":"Department of Information Systems, FIT, Brno University of Technology, Brno, Czech Republic"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Consumer IoT market\u2014Growth, trends, COVID-19 impact, and forecasts (2021\u20132026)","year":"2020"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427256"},{"key":"ref3","volume-title":"Botnet: An overview","volume":"240","author":"Saha","year":"2005"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241275"},{"key":"ref5","volume-title":"A new botnet attack just mozied into town","author":"McMillen","year":"2020"},{"key":"ref6","volume-title":"Azure DDoS protection\u20142021 Q3 and Q4 DDoS attack trends","author":"Toh","year":"2022"},{"issue":"1","key":"ref7","first-page":"1","article-title":"Botnets: Detection, measurement, disinfection & defence","volume":"1","author":"Plohmann","year":"2011","journal-title":"Eur. Netw. Inf. Security Agency"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.3390\/app11125713"},{"key":"ref9","volume-title":"What is a botnet attack? A guide for security professionals","author":"Greenlee","year":"2021"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2014.2321898"},{"key":"ref11","first-page":"2783","article-title":"99% false positives: A qualitative study of SoC analysts\u2019 perspectives on security alarms","volume-title":"Proc. 31st USENIX Security Symp. (USENIX Security)","author":"Alahmadi"},{"key":"ref12","volume-title":"Missed alarms and 40 million stolen credit card numbers: How target blew it","author":"Riley","year":"2014"},{"key":"ref13","volume-title":"Dataset used for training IoT C&C classifier","author":"Uh\u0159\u00ed\u010dek","year":"2022"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.02.009"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00077-7"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.02.064"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.3390\/s22020432"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/WD.2011.6098218"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2014.6883583"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2974293"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3314148.3314352"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1823844.1823846"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00013"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3368691.3368733"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/PDGC50313.2020.9315792"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-021-09621-9"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3060878"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOMWKSHPS50562.2020.9162668"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3119055"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3131981"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3100755"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2020.08.011"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453101"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-021-09606-8"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2988359"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207199"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2870052"},{"key":"ref38","first-page":"4768","article-title":"A unified approach to interpreting model predictions","volume-title":"Proc. Int. Conf. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Lundberg"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.3390\/info11020122"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2018.8599738"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ITNAC46935.2019.9077964"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICIET.2010.5625700"},{"key":"ref43","first-page":"93","article-title":"Rule generation for signature based detection systems of Cyber attacks in IoT environments","volume":"8","author":"Soe","year":"2019","journal-title":"Bull. Netw. Comput. Syst. Softw."},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/6639714"},{"key":"ref45","article-title":"Extending signature-based intrusion detection systems with Bayesian Abductive reasoning","volume-title":"arXiv:1903.12101","author":"Ganesan","year":"2019"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1016\/j.aej.2022.02.038"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2709942"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00054"},{"key":"ref49","volume-title":"Worm war: The botnet battle for IoT territory","author":"Hilt","year":"2020"},{"key":"ref50","article-title":"Internet security threat report\u2014April 2017","year":"2017"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.2307\/j.ctt1dnnbfr.4"},{"key":"ref52","volume-title":"Gafgtyt_tor and Necro are on the move again","year":"2021"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2003.10.003"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/ICSSA.2017.12"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355576"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2005.1577769"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CNSM.2016.7818417"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/AICCSA.2007.370913"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1613\/jair.953"},{"key":"ref60","volume-title":"C4.5: Programs for Machine Learning","author":"Quinlan","year":"1993"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1201\/9780203753736"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/7902.7906"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICDAR.1995.598994"},{"key":"ref64","first-page":"148","article-title":"Experiments with a new boosting algorithm","volume-title":"Proc. ICML","author":"Freund"},{"issue":"1","key":"ref65","first-page":"37","article-title":"Evaluation: From precision, recall and F-measure to ROC, informedness, markedness & correlation","volume":"2","author":"Powers","year":"2011","journal-title":"J. Mach. Learn. Technol."},{"key":"ref66","article-title":"Automatic anomaly detection in the cloud via statistical learning","volume-title":"arXiv:1704.07706","author":"Hochenbaum","year":"2017"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1016\/j.simpa.2020.100049"},{"key":"ref68","volume-title":"Forecasting: Principles and practice","author":"Hyndman","year":"2018"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.2478\/v10198-012-0034-2"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1016\/0169-2070(90)90103-I"},{"key":"ref71","volume-title":"Art of Computer Programming, Volume 2: Seminumerical Algorithms","author":"Knuth","year":"2014"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-39814-3_19"},{"key":"ref73","volume-title":"IoT-23: A labeled dataset with malicious and benign IoT network traffic","author":"Garcia","year":"2020"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2018.2866249"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/10119650\/09983820.pdf?arnumber=9983820","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,31]],"date-time":"2024-01-31T23:27:57Z","timestamp":1706743677000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9983820\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,15]]},"references-count":74,"journal-issue":{"issue":"10"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2022.3228816","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,15]]}}}