{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T12:19:02Z","timestamp":1767183542168,"version":"3.37.3"},"reference-count":35,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T00:00:00Z","timestamp":1559347200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T00:00:00Z","timestamp":1559347200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T00:00:00Z","timestamp":1559347200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2019,6]]},"DOI":"10.1109\/tifs.2018.2881657","type":"journal-article","created":{"date-parts":[[2018,11,15]],"date-time":"2018-11-15T21:00:24Z","timestamp":1542315624000},"page":"1485-1500","source":"Crossref","is-referenced-by-count":39,"title":["Enhanced PeerHunter: Detecting Peer-to-Peer Botnets Through Network-Flow Level Community Behavior Analysis"],"prefix":"10.1109","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4569-7123","authenticated-orcid":false,"given":"Di","family":"Zhuang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J. Morris","family":"Chang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SECURWARE.2009.48"},{"journal-title":"Barracuda Reputation Block List","year":"2018","key":"ref32"},{"journal-title":"Argus - Auditing Network Activity","year":"2018","key":"ref31"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028804"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420968"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2018.1331034"},{"key":"ref10","first-page":"95","article-title":"BotGrep: Finding P2P bots with structured graph analysis","author":"nagaraja","year":"2010","journal-title":"Proc Usenix Secur Symp"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TCNS.2016.2532804"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3140549.3140552"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3098991"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1002\/nem.1977"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2010.04.007"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2771228"},{"key":"ref17","first-page":"229","article-title":"Snort&#x2014;Lightweight intrusion detection for networks","volume":"99","author":"roesch","year":"1999","journal-title":"Proc 13th Syst Admin Conf LISA"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2010.5502092"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.swevo.2017.09.008"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/2008\/10\/P10008"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2015.7218396"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/1327452.1327492"},{"key":"ref3","first-page":"1","article-title":"Entelecheia: Detecting P2P botnets in their waiting stage","author":"hang","year":"2013","journal-title":"Proc IFIP Netw Conf"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920283"},{"journal-title":"Malware Sample Sources for Researchers","year":"2018","key":"ref29"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/DESEC.2017.8073832"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2014.03.002"},{"journal-title":"MAWI working group traffic archive","year":"2018","key":"ref7"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2013.2290197"},{"key":"ref9","first-page":"1","article-title":"Bothunter: Detecting malware infection through IDS-driven dialog correlation","volume":"7","author":"gu","year":"2007","journal-title":"Proc 16th USENIX Security Symp"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.17"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2013.6567180"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2357251"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2016.0288"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2009.5199062"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.23919\/INM.2017.7987417"},{"key":"ref26","first-page":"1","article-title":"Measurements and mitigation of peer-to-peer-based botnets: A case study on storm worm","volume":"8","author":"holz","year":"2008","journal-title":"USENIX Workshop on Large-scale Exploits and Emergent Threats"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177105"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/8639028\/08536452.pdf?arnumber=8536452","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,13]],"date-time":"2022-07-13T21:15:47Z","timestamp":1657746947000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8536452\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6]]},"references-count":35,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2018.2881657","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2019,6]]}}}