{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T02:04:29Z","timestamp":1775700269068,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2006,9,11]]},"DOI":"10.1145\/1162666.1162667","type":"proceedings-article","created":{"date-parts":[[2006,10,18]],"date-time":"2006-10-18T22:04:00Z","timestamp":1161209040000},"page":"99-106","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["Privacy-preserving payload-based correlation for accurate malicious traffic detection"],"prefix":"10.1145","author":[{"given":"Janak J.","family":"Parekh","sequence":"first","affiliation":[{"name":"Columbia University, New York, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ke","family":"Wang","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Salvatore J.","family":"Stolfo","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2006,9,11]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335438"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICON.2003.1266224"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/1315451.1315530"},{"key":"e_1_3_2_1_4_1","volume-title":"Privacy-Enhanced Searches Using Encrypted Bloom Filters","author":"Bellovin S. M.","year":"2004","unstructured":"S. M. Bellovin and W. R. Cheswick . Privacy-Enhanced Searches Using Encrypted Bloom Filters , 2004 . S. M. Bellovin and W. R. Cheswick. Privacy-Enhanced Searches Using Encrypted Bloom Filters, 2004."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/362686.362692"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2004.1354643"},{"key":"e_1_3_2_1_7_1","volume-title":"Detecting and Disrupting Botnets. In USENIX SRUTI Workshop","author":"Cooke E.","year":"2005","unstructured":"E. Cooke , F. Jahanian , and D. McPherson . The Zombie Roundup: Understanding , Detecting and Disrupting Botnets. In USENIX SRUTI Workshop , Cambridge, MA , 2005 . E. Cooke, F. Jahanian, and D. McPherson. The Zombie Roundup: Understanding, Detecting and Disrupting Botnets. In USENIX SRUTI Workshop, Cambridge, MA, 2005."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095824"},{"key":"e_1_3_2_1_9_1","volume-title":"Intrusion and Anomaly Detection Model Exchange for Mobile Ad-Hoc Networks. In IEEE Consumer Communications and Networking Conference","author":"Cretu G.","year":"2006","unstructured":"G. Cretu , J. J. Parekh , K. Wang , and S. J. Stolfo . Intrusion and Anomaly Detection Model Exchange for Mobile Ad-Hoc Networks. In IEEE Consumer Communications and Networking Conference , Las Vegas, NV , 2006 . G. Cretu, J. J. Parekh, K. Wang, and S. J. Stolfo. Intrusion and Anomaly Detection Model Exchange for Mobile Ad-Hoc Networks. In IEEE Consumer Communications and Networking Conference, Las Vegas, NV, 2006."},{"key":"e_1_3_2_1_10_1","volume-title":"Modeling Botnet Propagation Using Time Zones. In Network and Distributed System Security Symposium (NDSS)","author":"Dagon D.","year":"2006","unstructured":"D. Dagon , C. Zou , and W. Lee . Modeling Botnet Propagation Using Time Zones. In Network and Distributed System Security Symposium (NDSS) , San Diego, CA , 2006 . D. Dagon, C. Zou, and W. Lee. Modeling Botnet Propagation Using Time Zones. In Network and Distributed System Security Symposium (NDSS), San Diego, CA, 2006."},{"key":"e_1_3_2_1_11_1","volume-title":"Polymorphic Shellcode Engine Using Spectrum Analysis","author":"Detristan T.","year":"2003","unstructured":"T. Detristan , T. Ulenspiegel , Y. Malcom , and M. von Underduk . Polymorphic Shellcode Engine Using Spectrum Analysis , 2003 . T. Detristan, T. Ulenspiegel, Y. Malcom, and M. von Underduk. Polymorphic Shellcode Engine Using Spectrum Analysis, 2003."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CONECT.2003.1231477"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/508171.508174"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/285237.285287"},{"key":"e_1_3_2_1_15_1","volume-title":"Columbia University, 2006. Submitted to conference.","author":"Frias-Martinez V.","unstructured":"V. Frias-Martinez and S. J. Stolfo . BARTER: Profile Model Exchange for Behavior-based Access Control. Technical report , Columbia University, 2006. Submitted to conference. V. Frias-Martinez and S. J. Stolfo. BARTER: Profile Model Exchange for Behavior-based Access Control. Technical report, Columbia University, 2006. Submitted to conference."},{"key":"e_1_3_2_1_16_1","volume-title":"NDSS","author":"Huang Q.","year":"2005","unstructured":"Q. Huang , H. J. Wang , and N. Borisov . Privacy-Preserving Friends Troubleshooting Network . In NDSS , San Diego, CA , 2005 . Q. Huang, H. J. Wang, and N. Borisov. Privacy-Preserving Friends Troubleshooting Network. In NDSS, San Diego, CA, 2005."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/938984.939801"},{"key":"e_1_3_2_1_18_1","volume-title":"Distributed Worm Signature Detection. In USENIX Security Symposium","author":"Kim H.-A.","year":"2004","unstructured":"H.-A. Kim and B. Karp . Autograph: Toward Automated , Distributed Worm Signature Detection. In USENIX Security Symposium , San Diego, CA , 2004 . H.-A. Kim and B. Karp. Autograph: Toward Automated, Distributed Worm Signature Detection. In USENIX Security Symposium, San Diego, CA, 2004."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/11535218_15"},{"key":"e_1_3_2_1_20_1","volume-title":"Advanced Polymorphic Worms: Evading IDS by Blending in with Normal Traffic","author":"Kolesnikov O.","year":"2006","unstructured":"O. Kolesnikov , D. Dagon , and W. Lee . Advanced Polymorphic Worms: Evading IDS by Blending in with Normal Traffic , 2006 . O. Kolesnikov, D. Dagon, and W. Lee. Advanced Polymorphic Worms: Evading IDS by Blending in with Normal Traffic, 2006."},{"key":"e_1_3_2_1_21_1","volume-title":"Honeycomb - Creating Intrusion Detection Signatures Using Honeypots. In ACM Workshop on Hot Topics in Networks","author":"Kreibich C.","year":"2003","unstructured":"C. Kreibich and J. Crowcroft . Honeycomb - Creating Intrusion Detection Signatures Using Honeypots. In ACM Workshop on Hot Topics in Networks , Boston, MA , 2003 . C. Kreibich and J. Crowcroft. Honeycomb - Creating Intrusion Detection Signatures Using Honeypots. In ACM Workshop on Hot Topics in Networks, Boston, MA, 2003."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_11"},{"key":"e_1_3_2_1_23_1","volume-title":"Decentralized Event Correlation for Intrusion Detection. In International Conference on Information Security and Cryptology","author":"Kruegel C.","year":"2002","unstructured":"C. Kruegel , T. Toth , and C. Kerer . Decentralized Event Correlation for Intrusion Detection. In International Conference on Information Security and Cryptology , 2002 . C. Kruegel, T. Toth, and C. Kerer. Decentralized Event Correlation for Intrusion Detection. In International Conference on Information Security and Cryptology, 2002."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102150"},{"key":"e_1_3_2_1_25_1","volume-title":"USENIX Security","author":"Lincoln P.","year":"2004","unstructured":"P. Lincoln , P. Porras , and V. Shmatikov . Privacy-Preserving Sharing and Correlation of Security Alerts . In USENIX Security , 2004 . P. Lincoln, P. Porras, and V. Shmatikov. Privacy-Preserving Sharing and Correlation of Security Alerts. In USENIX Security, 2004."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/IAW.2005.1495971"},{"key":"e_1_3_2_1_27_1","first-page":"95","volume-title":"Software Self-Healing Using Collaborative Application Communities. In Internet Society (ISOC) Symposium on Network and Distributed Systems Security","author":"Locasto M. E.","year":"2006","unstructured":"M. E. Locasto , S. Sidiroglou , and A. D. Keromytis . Software Self-Healing Using Collaborative Application Communities. In Internet Society (ISOC) Symposium on Network and Distributed Systems Security , pages 95 -- 106 , San Diego, CA , 2006 . M. E. Locasto, S. Sidiroglou, and A. D. Keromytis. Software Self-Healing Using Collaborative Application Communities. In Internet Society (ISOC) Symposium on Network and Distributed Systems Security, pages 95--106, San Diego, CA, 2006."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_5"},{"key":"e_1_3_2_1_29_1","volume-title":"Vulnerability-Specific Execution Filtering for Exploit Prevention on Commodity Software. In Network and Distributed Security Symposium (NDSS)","author":"Newsome J.","year":"2006","unstructured":"J. Newsome , D. Brumley , and D. Song . Vulnerability-Specific Execution Filtering for Exploit Prevention on Commodity Software. In Network and Distributed Security Symposium (NDSS) , San Diego, CA , 2006 . J. Newsome, D. Brumley, and D. Song. Vulnerability-Specific Execution Filtering for Exploit Prevention on Commodity Software. In Network and Distributed Security Symposium (NDSS), San Diego, CA, 2006."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"key":"e_1_3_2_1_31_1","volume-title":"Privacy-Preserving Payload-Based Correlation for Accurate Malicious Traffic Detection. Technical report","author":"Parekh J. J.","year":"2006","unstructured":"J. J. Parekh , K. Wang , and S. J. Stolfo . Privacy-Preserving Payload-Based Correlation for Accurate Malicious Traffic Detection. Technical report , 2006 . http:\/\/mice.cs.columbia.edu\/getTechreport.php?techreportID=409. J. J. Parekh, K. Wang, and S. J. Stolfo. Privacy-Preserving Payload-Based Correlation for Accurate Malicious Traffic Detection. Technical report, 2006. http:\/\/mice.cs.columbia.edu\/getTechreport.php?techreportID=409."},{"key":"e_1_3_2_1_32_1","volume-title":"National Information Systems Security Conference","author":"Porras P.","year":"1997","unstructured":"P. Porras and P. G. Neumann . EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances . In National Information Systems Security Conference , 1997 . P. Porras and P. G. Neumann. EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances. In National Information Systems Security Conference, 1997."},{"key":"e_1_3_2_1_33_1","first-page":"05","volume":"3","author":"Project H.","year":"2005","unstructured":"H. Project and R. Alliance . Know your Enemy: Tracking Botnets , 3\/13 \/ 05 2005 . http:\/\/www.honeynet.org\/papers\/bots\/. H. Project and R. Alliance. Know your Enemy: Tracking Botnets, 3\/13\/05 2005. http:\/\/www.honeynet.org\/papers\/bots\/.","journal-title":"Know your Enemy: Tracking Botnets"},{"key":"e_1_3_2_1_34_1","volume-title":"Automated Worm Fingerprinting. In 6th Symposium on Operating Systems Design and Implementation (OSDI '04)","author":"Singh S.","year":"2004","unstructured":"S. Singh , C. Estan , G. Varghese , and S. Savage . Automated Worm Fingerprinting. In 6th Symposium on Operating Systems Design and Implementation (OSDI '04) , San Francisco, CA , 2004 . S. Singh, C. Estan, G. Varghese, and S. Savage. Automated Worm Fingerprinting. In 6th Symposium on Operating Systems Design and Implementation (OSDI '04), San Francisco, CA, 2004."},{"key":"e_1_3_2_1_35_1","volume-title":"GrIDS - A Graph Based Intrusion Detection System for Large Networks. In National Information Computer Security Conference","author":"Staniford-Chen S.","year":"1996","unstructured":"S. Staniford-Chen , S. Cheung , R. Crawford , and M. Dilger . GrIDS - A Graph Based Intrusion Detection System for Large Networks. In National Information Computer Security Conference , Baltimore, MD , 1996 . S. Staniford-Chen, S. Cheung, R. Crawford, and M. Dilger. GrIDS - A Graph Based Intrusion Detection System for Large Networks. In National Information Computer Security Conference, Baltimore, MD, 1996."},{"key":"e_1_3_2_1_36_1","volume-title":"USENIX Security","author":"Staniford-Chen S.","year":"2002","unstructured":"S. Staniford-Chen , V. Paxson , and N. Weaver . How to Own the Internet in Your Spare Time . In USENIX Security , 2002 . S. Staniford-Chen, V. Paxson, and N. Weaver. How to Own the Internet in Your Spare Time. In USENIX Security, 2002."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.28"},{"key":"e_1_3_2_1_38_1","volume-title":"International Conference on Knowledge Discovery and Data Mining","author":"Stolfo S. J.","year":"1997","unstructured":"S. J. Stolfo , A. L. Prodromidis , S. Tselepis , W. Lee , D. W. Fan , and P. Chan . JAM: Java Agents for Meta-Learning over Distributed Databases . In International Conference on Knowledge Discovery and Data Mining , Newport Beach, CA , 1997 . S. J. Stolfo, A. L. Prodromidis, S. Tselepis, W. Lee, D. W. Fan, and P. Chan. JAM: Java Agents for Meta-Learning over Distributed Databases. In International Conference on Knowledge Discovery and Data Mining, Newport Beach, CA, 1997."},{"key":"e_1_3_2_1_39_1","volume-title":"Defending Against Internet Worms: A Signature-Based Approach","author":"Tang Y.","year":"2005","unstructured":"Y. Tang and S. Chen . Defending Against Internet Worms: A Signature-Based Approach . In IEEE Infocom , Miami, FL , 2005 . Y. Tang and S. Chen. Defending Against Internet Worms: A Signature-Based Approach. In IEEE Infocom, Miami, FL, 2005."},{"key":"e_1_3_2_1_40_1","volume-title":"DShield home page","author":"Ullrich J.","year":"2005","unstructured":"J. Ullrich . DShield home page , 2005 . http:\/\/www.dshield.org. J. Ullrich. DShield home page, 2005. http:\/\/www.dshield.org."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015489"},{"key":"e_1_3_2_1_43_1","volume-title":"OSDI","author":"Wang H. J.","year":"2004","unstructured":"H. J. Wang , J. C. Platt , Y. Chen , R. Zhang , and Y.-M. Wang . Automatic Misconfiguration Troubleshooting with PeerPressure . In OSDI , San Francisco , 2004 . H. J. Wang, J. C. Platt, Y. Chen, R. Zhang, and Y.-M. Wang. Automatic Misconfiguration Troubleshooting with PeerPressure. In OSDI, San Francisco, 2004."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_12"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_12"},{"key":"e_1_3_2_1_46_1","volume-title":"Anomalous Payload-based Network Intrusion Detection. In Symposium on Recent Advances in Intrusion Detection","author":"Wang K.","year":"2004","unstructured":"K. Wang and S. J. Stolfo . Anomalous Payload-based Network Intrusion Detection. In Symposium on Recent Advances in Intrusion Detection , Sophia Antipolis, France , 2004 . K. Wang and S. J. Stolfo. Anomalous Payload-based Network Intrusion Detection. In Symposium on Recent Advances in Intrusion Detection, Sophia Antipolis, France, 2004."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.45"},{"key":"e_1_3_2_1_48_1","volume-title":"Protocols for Secure Computations. In IEEE Symposium on Foundations of Computer Science","author":"Yao A. C.","year":"1982","unstructured":"A. C. Yao . Protocols for Secure Computations. In IEEE Symposium on Foundations of Computer Science , 1982 . A. C. Yao. Protocols for Secure Computations. In IEEE Symposium on Foundations of Computer Science, 1982."},{"key":"e_1_3_2_1_49_1","volume-title":"NDSS","author":"Yegneswaran V.","year":"2004","unstructured":"V. Yegneswaran , P. Barford , and S. Jha . Global Intrusion Detection in the DOMINO Overlay System . In NDSS , 2004 . V. Yegneswaran, P. Barford, and S. Jha. Global Intrusion Detection in the DOMINO Overlay System. In NDSS, 2004."},{"key":"e_1_3_2_1_50_1","volume-title":"An Architecture for Generating Semantics-Aware Signatures. In USENIX Security Symposium","author":"Yegneswaran V.","year":"2005","unstructured":"V. Yegneswaran , J. T. Giffin , P. Barford , and S. Jha . An Architecture for Generating Semantics-Aware Signatures. In USENIX Security Symposium , 2005 . V. Yegneswaran, J. T. Giffin, P. Barford, and S. Jha. An Architecture for Generating Semantics-Aware Signatures. In USENIX Security Symposium, 2005."}],"event":{"name":"SIGCOMM06: ACM SIGCOMM 2006 Conference","location":"Pisa Italy","acronym":"SIGCOMM06"},"container-title":["Proceedings of the 2006 SIGCOMM workshop on Large-scale attack defense"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1162666.1162667","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,12]],"date-time":"2023-01-12T11:35:26Z","timestamp":1673523326000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1162666.1162667"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,9,11]]},"references-count":50,"alternative-id":["10.1145\/1162666.1162667","10.1145\/1162666"],"URL":"https:\/\/doi.org\/10.1145\/1162666.1162667","relation":{},"subject":[],"published":{"date-parts":[[2006,9,11]]},"assertion":[{"value":"2006-09-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}