{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T14:59:35Z","timestamp":1764687575200},"reference-count":28,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2011,3,1]],"date-time":"2011-03-01T00:00:00Z","timestamp":1298937600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2011,3]]},"DOI":"10.1109\/tifs.2010.2086445","type":"journal-article","created":{"date-parts":[[2010,10,12]],"date-time":"2010-10-12T14:59:31Z","timestamp":1286895571000},"page":"175-188","source":"Crossref","is-referenced-by-count":40,"title":["Towards Situational Awareness of Large-Scale Botnet Probing Events"],"prefix":"10.1109","volume":"6","author":[{"given":"Zhichun","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anup","family":"Goyal","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vern","family":"Paxson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2010.5461939"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.857113"},{"key":"ref12","author":"barford","year":"2006","journal-title":"An inside look at Botnets"},{"key":"ref13","article-title":"how to own the internet in your spare time","author":"staniford","year":"2002","journal-title":"Proc Usenix Security"},{"key":"ref14","author":"kendall","year":"1976","journal-title":"Rank Correlation Methods"},{"key":"ref15","author":"rice","year":"1994","journal-title":"Mathematical Statistics and Data Analysis"},{"key":"ref16","author":"weisstein","year":"0","journal-title":"Stirling number of the second kind"},{"key":"ref17","article-title":"mapping internet sensors with probe response attacks","author":"bethencourt","year":"2005","journal-title":"Proc Usenix Security"},{"key":"ref18","author":"cai","year":"2006","journal-title":"Honeynets and Honeygames A Game Theoretic Approach to Defending Network Monitors"},{"key":"ref19","year":"0","journal-title":"OS Platform Statistics by W3school"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330150"},{"key":"ref4","article-title":"a multifaceted approach to understanding the botnet phenomenon","author":"rajab","year":"2006","journal-title":"Proc ACM IMC"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"ref3","article-title":"a case study of the rustock rootkit and spam bot","author":"chiang","year":"2007","journal-title":"Proceedings of USENIX HotBots"},{"key":"ref6","article-title":"a virtual honeypot framework","author":"provos","year":"2004","journal-title":"Proc Usenix Security"},{"key":"ref5","year":"0","journal-title":"Dshield org Distributed Intrusion Detection System"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177096"},{"key":"ref7","author":"bacher","year":"0","journal-title":"Know your enemy Tracking botnets"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"ref1","year":"0","journal-title":"Adrian Lamo Charged With Computer Crimes"},{"key":"ref9","article-title":"using honeynets for internet situational awareness","author":"yegneswaran","year":"2005","journal-title":"Proc ACM HotNets-I"},{"key":"ref20","year":"0","journal-title":"AP Market Sharing"},{"key":"ref22","year":"0","journal-title":"Net-Worm Win32 Allaple a"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637243"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330151"},{"key":"ref23","article-title":"automating analysis of large-scale botnet probing events","author":"li","year":"2009","journal-title":"Proc ACM ASIACCS"},{"key":"ref26","year":"0","journal-title":"Honeysnap"},{"key":"ref25","year":"0","journal-title":"HoneyBow Sensor"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/10206\/5712892\/05599296.pdf?arnumber=5599296","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,10]],"date-time":"2021-10-10T23:47:23Z","timestamp":1633909643000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/5599296\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,3]]},"references-count":28,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2010.2086445","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,3]]}}}