{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,21]],"date-time":"2026-03-21T21:13:28Z","timestamp":1774127608959,"version":"3.50.1"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["ACI-1547245"],"award-info":[{"award-number":["ACI-1547245"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1544910"],"award-info":[{"award-number":["CNS-1544910"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["ACI-1642143"],"award-info":[{"award-number":["ACI-1642143"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1643020"],"award-info":[{"award-number":["CNS-1643020"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2017,6]]},"DOI":"10.1109\/tifs.2017.2668361","type":"journal-article","created":{"date-parts":[[2017,2,13]],"date-time":"2017-02-13T19:20:35Z","timestamp":1487013635000},"page":"1430-1443","source":"Crossref","is-referenced-by-count":65,"title":["Stealthy Domain Generation Algorithms"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7949-0556","authenticated-orcid":false,"given":"Yu","family":"Fu","sequence":"first","affiliation":[]},{"given":"Lu","family":"Yu","sequence":"additional","affiliation":[]},{"given":"Oluwakemi","family":"Hambolu","sequence":"additional","affiliation":[]},{"given":"Ilker","family":"Ozcelik","sequence":"additional","affiliation":[]},{"given":"Benafsh","family":"Husain","sequence":"additional","affiliation":[]},{"given":"Jingxuan","family":"Sun","sequence":"additional","affiliation":[]},{"given":"Karan","family":"Sapra","sequence":"additional","affiliation":[]},{"given":"Dan","family":"Du","sequence":"additional","affiliation":[]},{"given":"Christopher Tate","family":"Beasley","sequence":"additional","affiliation":[]},{"given":"Richard R.","family":"Brooks","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","author":"paganini","year":"2016","journal-title":"Cisco Talos Profiled the Goznym Botnet After Cracking the Trojan DGA"},{"key":"ref38","author":"newspaper","year":"2016","journal-title":"Cracking of Sphinx Trojan DGA Opens the Door for Botnet Takedown"},{"key":"ref33","author":"kasza","year":"2015","journal-title":"Using Algorithms to Brute Force Algorithms"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1147\/JRD.2016.2557639"},{"key":"ref31","first-page":"263","article-title":"A comprehensive measurement study of domain generating malware","author":"plohmann","year":"0","journal-title":"Proc 25th USENIX Secur Symp (USENIX Security) USENIX Assoc"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511809071"},{"key":"ref37","author":"edwards","year":"2016","journal-title":"The Mad Max DGA"},{"key":"ref36","author":"hagen","year":"2016","journal-title":"Why Domain Generating Algorithms (DGAS)"},{"key":"ref35","year":"2012","journal-title":"Domain Generation Algorithms (DGA) in Stealthy Malware"},{"key":"ref34","author":"pereira","year":"2015","journal-title":"A Look Inside Tinba Botnets"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2009.06.008"},{"key":"ref62","doi-asserted-by":"crossref","first-page":"498","DOI":"10.1090\/S0002-9904-1945-08391-8","article-title":"Theory of games and economic behavior","volume":"51","author":"von neumann","year":"1945","journal-title":"Bull Amer Math Soc"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/2746266.2746275"},{"key":"ref63","year":"2013","journal-title":"Welcome to Project Sonar"},{"key":"ref28","author":"jurafsky","year":"2014","journal-title":"Minimum Edit Distance&#x2014;Definition of Minimum Edit Distance"},{"key":"ref27","article-title":"Measuring dialect pronunciation differences using Levenshtein distance","author":"heeringa","year":"2004"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1002\/asi.4630240406"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2015.7413691"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICICIC.2009.127"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.10.001"},{"key":"ref22","author":"manning","year":"1999","journal-title":"Foundations of Statistical Natural Language Processing"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177729694"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1148\/radiology.143.1.7063747"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36618-0_22"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICICIC.2008.422"},{"key":"ref25","first-page":"707","article-title":"Binary codes capable of correcting deletions, insertions and reversals","volume":"10","author":"levenshtein","year":"1966","journal-title":"Sov Phys Doklady"},{"key":"ref50","article-title":"Network traffic analysis using stochastic grammars","author":"lu","year":"2012"},{"key":"ref51","first-page":"806","article-title":"A normalized statistical metric space for hidden Markov models","volume":"43","author":"lu","year":"0","journal-title":"IEEE Trans Cybern"},{"key":"ref59","first-page":"131","article-title":"Statistical properties of probabilistic context-free grammars","volume":"25","author":"chi","year":"1999","journal-title":"Comput Linguistics"},{"key":"ref58","author":"harris","year":"2002","journal-title":"The Theory of Branching Processes"},{"key":"ref57","author":"manning","year":"1999","journal-title":"Foundations of Statistical Natural Language Processing"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/T-C.1973.223746"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1956.1056813"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1023\/A:1010388907793"},{"key":"ref53","author":"beale","year":"2003","journal-title":"12dicts Introduction&#x2014;The 3ESL List"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2012.93"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1053283.1053288"},{"key":"ref11","article-title":"Tracking and characterizing botnets using automatically generated domains","author":"schiavoni","year":"2013"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2013.6703693"},{"key":"ref12","first-page":"408","article-title":"Detecting machine generated domain names based on morpheme features","author":"wei-wei","year":"2013","journal-title":"Proc Int Workshop Sec Cloud Comput"},{"key":"ref13","first-page":"1","article-title":"Automatic extraction of domain name generation algorithms from current malware","author":"barabosch","year":"2012","journal-title":"Proc NATO Symp IST-111 Inf Assurance Cyber Defense"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1002\/spe.885"},{"key":"ref15","doi-asserted-by":"crossref","DOI":"10.21236\/ADA017676","article-title":"A random word generator for pronounceable passwords","author":"gasser","year":"1975"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW.2014.20"},{"key":"ref17","first-page":"91","article-title":"Semantic based DNS forensics","author":"marchal","year":"2012","journal-title":"Proc IEEE Int Workshop Inf Forensics Secur (WIFS)"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2357251"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.77"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1455518.1455525"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2012.2184552"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.jare.2014.01.001"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2584679"},{"key":"ref8","first-page":"16","article-title":"BotDigger: Detecting DGA bots in a single network","author":"zhang","year":"2016","journal-title":"Proc IEEE Int Workshop Traffic Monitor Anal"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879148"},{"key":"ref49","article-title":"Pattern recognition for command and control data systems","author":"schwier","year":"2009"},{"key":"ref9","first-page":"491","article-title":"From throw-away traffic to bots: Detecting the rise of DGA-based malware","author":"antonakakis","year":"2012","journal-title":"Proc Usenix Secur Symp"},{"key":"ref46","author":"wolf","year":"2008","journal-title":"Technical Details of Srizbi&#x2019;s Domain Generation Algorithm"},{"key":"ref45","author":"news","year":"2008","journal-title":"Spam on Rise After Brief Reprieve"},{"key":"ref48","article-title":"Word hy-phen-a-tion by com-put-er","author":"liang","year":"1983"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"ref42","article-title":"Know your enemy: Containing conficker","author":"leder","year":"2009"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2011.2173486"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1002\/spe.885"},{"key":"ref43","author":"leder","year":"2008","journal-title":"Containing Conficker"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/ieeexplore.ieee.org\/ielaam\/10206\/7867904\/7852496-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/7867904\/07852496.pdf?arnumber=7852496","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,8]],"date-time":"2022-04-08T18:51:55Z","timestamp":1649443915000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7852496\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,6]]},"references-count":63,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2017.2668361","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,6]]}}}