{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:51:09Z","timestamp":1771699869565,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2009,3,10]],"date-time":"2009-03-10T00:00:00Z","timestamp":1236643200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2009,3,10]]},"DOI":"10.1145\/1533057.1533062","type":"proceedings-article","created":{"date-parts":[[2009,4,28]],"date-time":"2009-04-28T14:57:19Z","timestamp":1240930639000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":38,"title":["Automatic discovery of botnet communities on large-scale communication networks"],"prefix":"10.1145","author":[{"given":"Wei","family":"Lu","sequence":"first","affiliation":[{"name":"University of New Brunswick, Fredericton, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mahbod","family":"Tavallaee","sequence":"additional","affiliation":[{"name":"University of New Brunswick, Fredericton, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali A.","family":"Ghorbani","sequence":"additional","affiliation":[{"name":"University of New Brunswick, Fredericton, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,3,10]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"http:\/\/www.symantec.com\/business\/theme.jsp?themeid=threa treport Symantec Internet Security Threat Report Volume XIII: April 2008  http:\/\/www.symantec.com\/business\/theme.jsp?themeid=threa treport Symantec Internet Security Threat Report Volume XIII: April 2008"},{"key":"e_1_3_2_1_2_1","volume-title":"Advances in Information Security","author":"Barford P.","year":"2006","unstructured":"P. Barford and V. Yegneswaran , \" An inside look at Botnets,\" Special Workshop on Malware Detection , Advances in Information Security , Springer Verlag , ISBN : 0-387-32720-7, 2006 . P. Barford and V. Yegneswaran, \"An inside look at Botnets,\" Special Workshop on Malware Detection, Advances in Information Security, Springer Verlag, ISBN: 0-387-32720-7, 2006."},{"key":"e_1_3_2_1_3_1","volume-title":"available on and assessed","year":"2008","unstructured":"Sinit , available on and assessed in December 2008 http:\/\/www.secureworks.com\/research\/threats\/sinit\/ Sinit, available on and assessed in December 2008 http:\/\/www.secureworks.com\/research\/threats\/sinit\/"},{"key":"e_1_3_2_1_4_1","volume-title":"available on and assessed","year":"2008","unstructured":"Phatbot , available on and assessed in December 2008 http:\/\/www.secureworks.com\/research\/threats\/phatbot\/ Phatbot, available on and assessed in December 2008 http:\/\/www.secureworks.com\/research\/threats\/phatbot\/"},{"key":"e_1_3_2_1_5_1","volume-title":"available on and assessed","year":"2008","unstructured":"Nugache , available on and assessed in December 2008 http:\/\/www.securityfocus.com\/news\/11390\/ Nugache, available on and assessed in December 2008 http:\/\/www.securityfocus.com\/news\/11390\/"},{"key":"e_1_3_2_1_6_1","unstructured":"http:\/\/www.secureworks.com\/research\/blog\/index.php\/2007\/09\/12\/analysis-of-storm-worm-ddos-traffic\/  http:\/\/www.secureworks.com\/research\/blog\/index.php\/2007\/09\/12\/analysis-of-storm-worm-ddos-traffic\/"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85886-7_10"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177086"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_9"},{"key":"e_1_3_2_1_10_1","volume-title":"Using honeynets for internet situational awareness,\" In Proceedings of the 4th Workshop on Hot Topics in Networks","author":"Yegneswaran V.","year":"2005","unstructured":"V. Yegneswaran , P. Barford , and V. Paxson , \" Using honeynets for internet situational awareness,\" In Proceedings of the 4th Workshop on Hot Topics in Networks , College Park, MD , 2005 . V. Yegneswaran, P. Barford, and V. Paxson, \"Using honeynets for internet situational awareness,\" In Proceedings of the 4th Workshop on Hot Topics in Networks, College Park, MD, 2005."},{"key":"e_1_3_2_1_11_1","volume-title":"Series: Advances in Information Security","author":"Li Z. H.","year":"2008","unstructured":"Z. H. Li , A. Goyal , and Y. Chen , \" Honeynet-based botnet scan traffic analysis,\" Botnet Detection: Countering the Largest Security Threat , in Series: Advances in Information Security , Vol. 36 , W. K. Lee, C. Wang, D. Dagon, (Eds.), Springer , ISBN: 978-0-387-68766-7, 2008 . Z. H. Li, A. Goyal, and Y. Chen, \"Honeynet-based botnet scan traffic analysis,\" Botnet Detection: Countering the Largest Security Threat, in Series: Advances in Information Security, Vol. 36, W. K. Lee, C. Wang, D. Dagon, (Eds.), Springer, ISBN: 978-0-387-68766-7, 2008."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/11555827_19"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats","author":"Holz T.","year":"2008","unstructured":"T. Holz , M. Steiner , F. Dahl , E. Biersack and F. Freiling , \" Measurements and mitigation of peer-to-peer-based botnets: a case study on storm worm \", In Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats , San Francisco, California , 2008 . T. Holz, M. Steiner, F. Dahl, E. Biersack and F. Freiling, \"Measurements and mitigation of peer-to-peer-based botnets: a case study on storm worm\", In Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats, San Francisco, California, 2008."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"T. Strayer R. Walsh C. Livadas D. Lapsley \"Detecting botnets with tight command and control \" Proceedings 2006 31st IEEE Conference on Local Computer Networks pp. 195--202 2006.  T. Strayer R. Walsh C. Livadas D. Lapsley \"Detecting botnets with tight command and control \" Proceedings 2006 31 st IEEE Conference on Local Computer Networks pp. 195--202 2006.","DOI":"10.1109\/LCN.2006.322100"},{"key":"e_1_3_2_1_15_1","volume-title":"Series: Advances in Information Security","author":"Strayer T.","year":"2008","unstructured":"T. Strayer , D. Lapsley , R. Walsh , and C. Livadas , \" Botnet detection based on network behavior,\" Botnet Detection: Countering the Largest Security Threat , in Series: Advances in Information Security , Vol. 36 , W. K. Lee, C. Wang, D. Dagon, (Eds.), Springer , 2008 . T. Strayer, D. Lapsley, R. Walsh, and C. Livadas, \"Botnet detection based on network behavior,\" Botnet Detection: Countering the Largest Security Threat, in Series: Advances in Information Security, Vol. 36, W. K. Lee, C. Wang, D. Dagon, (Eds.), Springer, 2008."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"C. Livadas R. Walsh D. Lapsley T. Strayer \"Using machine learning techniques to identify botnet traffic \" In Proceedings 2006 31st IEEE Conference on Local Computer Networks pp. 967--974 Nov. 2006.  C. Livadas R. Walsh D. Lapsley T. Strayer \"Using machine learning techniques to identify botnet traffic \" In Proceedings 2006 31 st IEEE Conference on Local Computer Networks pp. 967--974 Nov. 2006.","DOI":"10.1109\/LCN.2006.322210"},{"key":"e_1_3_2_1_17_1","volume-title":"Rishi: Identify bot contaminated hosts by irc nickname evaluation,\" In Proceedings of USENIX HotBots'07","author":"Goebel J.","year":"2007","unstructured":"J. Goebel and T. Holz , \" Rishi: Identify bot contaminated hosts by irc nickname evaluation,\" In Proceedings of USENIX HotBots'07 , 2007 . J. Goebel and T. Holz, \"Rishi: Identify bot contaminated hosts by irc nickname evaluation,\" In Proceedings of USENIX HotBots'07, 2007."},{"key":"e_1_3_2_1_18_1","volume-title":"Wide-scale botnet detection and characterization,\" In Proceedings of the 1st Conference on 1st Workshop on Hot Topics in Understanding Botnets","author":"Karasaridis A.","year":"2007","unstructured":"A. Karasaridis , B. Rexroad , and D. Hoeflin , \" Wide-scale botnet detection and characterization,\" In Proceedings of the 1st Conference on 1st Workshop on Hot Topics in Understanding Botnets , Cambridge, MA , 2007 . A. Karasaridis, B. Rexroad, and D. Hoeflin, \"Wide-scale botnet detection and characterization,\" In Proceedings of the 1st Conference on 1st Workshop on Hot Topics in Understanding Botnets, Cambridge, MA, 2007."},{"key":"e_1_3_2_1_19_1","volume-title":"An algorithm for anomaly-based botnet detection,\" USENIX SRUTI: 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet","author":"Binkley J. R.","year":"2006","unstructured":"J. R. Binkley and S. Singh , \" An algorithm for anomaly-based botnet detection,\" USENIX SRUTI: 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet , 2006 . J. R. Binkley and S. Singh, \"An algorithm for anomaly-based botnet detection,\" USENIX SRUTI: 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet, 2006."},{"key":"e_1_3_2_1_20_1","volume-title":"CA","author":"Gu G. F.","year":"2008","unstructured":"G. F. Gu , J. J. Zhang , and W. K. Lee , \" BotSniffer: detecting botnet command and control channels in network traffic,\" In Proceedings of the 15th Annual Network and Distributed System Security Symposium, San Diego , CA , February 2008 . G. F. Gu, J. J. Zhang, and W. K. Lee, \"BotSniffer: detecting botnet command and control channels in network traffic,\" In Proceedings of the 15th Annual Network and Distributed System Security Symposium, San Diego, CA, February 2008."},{"key":"e_1_3_2_1_21_1","volume-title":"BotMiner: clustering analysis of network traffic for protocol- and structure-independent Botnet detection,\" In Proceedings of the 17th USENIX Security Symposium (Security'08)","author":"Gu G. F.","year":"2008","unstructured":"G. F. Gu , R. Perdisci , J. J. Zhang , and W. K. Lee . \" BotMiner: clustering analysis of network traffic for protocol- and structure-independent Botnet detection,\" In Proceedings of the 17th USENIX Security Symposium (Security'08) , San Jose, CA , 2008 . G. F. Gu, R. Perdisci, J. J. Zhang, and W. K. Lee. \"BotMiner: clustering analysis of network traffic for protocol- and structure-independent Botnet detection,\" In Proceedings of the 17th USENIX Security Symposium (Security'08), San Jose, CA, 2008."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31966-5_4"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1163593.1163596"},{"key":"e_1_3_2_1_24_1","first-page":"205","volume-title":"Flow clustering using machine learning techniques,\" Proceedings of 5th International Workshop on Passive and Active Network Measurement","author":"McGregor A.","year":"2004","unstructured":"A. McGregor , M. Hall , P. Lorier , and J. Brunskill , \" Flow clustering using machine learning techniques,\" Proceedings of 5th International Workshop on Passive and Active Network Measurement , pp. 205 -- 214 , Antibes Juan-les-Pins , France , 2004 . A. McGregor, M. Hall, P. Lorier, and J. Brunskill, \"Flow clustering using machine learning techniques,\" Proceedings of 5th International Workshop on Passive and Active Network Measurement, pp. 205--214, Antibes Juan-les-Pins, France, 2004."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2005.35"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368436.1368445"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1071690.1064220"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1198255.1198257"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028805"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1269880.1269889"},{"key":"e_1_3_2_1_31_1","volume-title":"Towards automated application signature generation for traffic identification,\" In Proceedings of the IEEE\/IFIP Network Operations and Management Symposium (NOMS","author":"Park C.","year":"2008","unstructured":"C. Park , Y. Won , M. Kim and J. Hong , \" Towards automated application signature generation for traffic identification,\" In Proceedings of the IEEE\/IFIP Network Operations and Management Symposium (NOMS 2008 ), Salvador , Brazil , 160--167, 2008. C. Park, Y. Won, M. Kim and J. Hong, \"Towards automated application signature generation for traffic identification,\" In Proceedings of the IEEE\/IFIP Network Operations and Management Symposium (NOMS 2008), Salvador, Brazil, 160--167, 2008."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080091.1080119"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1129582.1129589"},{"key":"e_1_3_2_1_34_1","volume-title":"available on and assessed","year":"2008","unstructured":"Fred-eZone WiFi ISP , available on and assessed in December 2008 http:\/\/www.fred-ezone.ca\/ Fred-eZone WiFi ISP, available on and assessed in December 2008 http:\/\/www.fred-ezone.ca\/"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014064"},{"key":"e_1_3_2_1_36_1","volume-title":"Sophia Antipolis","author":"Stolfo S.","year":"2004","unstructured":"K.Wang and S. Stolfo . \" Anomalous payload-based network intrusion detection,\" In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID) , Sophia Antipolis , France , 2004 . K.Wang and S. Stolfo. \"Anomalous payload-based network intrusion detection,\" In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID), Sophia Antipolis, France, 2004."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_12"},{"key":"e_1_3_2_1_38_1","volume-title":"BotHunter: detecting malware infection through IDS-Driven dialog correlation,\" Proceedings of the 16th USENIX Security Symposium","author":"Gu G. F.","year":"2007","unstructured":"G. F. Gu , P. Porras , V. Yegneswaran , M. Fong , and W. K. Lee , \" BotHunter: detecting malware infection through IDS-Driven dialog correlation,\" Proceedings of the 16th USENIX Security Symposium , Boston, MA , 2007 . G. F. Gu, P. Porras, V. Yegneswaran, M. Fong, and W. K. Lee, \"BotHunter: detecting malware infection through IDS-Driven dialog correlation,\" Proceedings of the 16th USENIX Security Symposium, Boston, MA, 2007."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SAINT-W.2007.14"},{"key":"e_1_3_2_1_40_1","first-page":"255","article-title":"Anomaly detection over noisy data using learned probability distributions","author":"Eskin E.","year":"2000","unstructured":"E. Eskin , \" Anomaly detection over noisy data using learned probability distributions ,\" In Proceedings of 17th International Conference on Machine Learning , pp. 255 -- 262 , Palo Alto, 2000 . E. Eskin, \"Anomaly detection over noisy data using learned probability distributions,\" In Proceedings of 17th International Conference on Machine Learning, pp. 255--262, Palo Alto, 2000.","journal-title":"Proceedings of 17th International Conference on Machine Learning"},{"key":"e_1_3_2_1_41_1","volume-title":"available on and assessed","year":"2008","unstructured":"Kaiten , available on and assessed in December 2008 http:\/\/packetstormsecurity.org\/distributed\/indexsize.html Kaiten, available on and assessed in December 2008 http:\/\/packetstormsecurity.org\/distributed\/indexsize.html"},{"key":"e_1_3_2_1_42_1","volume-title":"available on and assessed","year":"2008","unstructured":"BlackEnergy , available on and assessed in December 2008 http:\/\/atlas-public.ec2.arbor.net\/docs\/BlackEnergy+DDoS+Bot+Analysis.pdf BlackEnergy, available on and assessed in December 2008 http:\/\/atlas-public.ec2.arbor.net\/docs\/BlackEnergy+DDoS+Bot+Analysis.pdf"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273445.1273454"},{"key":"e_1_3_2_1_44_1","unstructured":"P. Wang S. Sparks and C. Zou \"An advanced hybrid peer-to-peer botnet \" In Proceedings of the 1st conference on 1st Workshop on Hot Topics in Understanding Botnets Cambridge MA 2007.   P. Wang S. Sparks and C. Zou \"An advanced hybrid peer-to-peer botnet \" In Proceedings of the 1 st conference on 1 st Workshop on Hot Topics in Understanding Botnets Cambridge MA 2007."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2006.38"},{"key":"e_1_3_2_1_46_1","volume-title":"assessed","year":"2008","unstructured":"German Honeynet Project , assessed in Dec 2008 http:\/\/pi1.informatik.uni-mannheim.de\/index.php? pagecontent=site\/Research.menu\/Honeynet.page German Honeynet Project, assessed in Dec 2008 http:\/\/pi1.informatik.uni-mannheim.de\/index.php? pagecontent=site\/Research.menu\/Honeynet.page"}],"event":{"name":"Asia CCS 09: Asia CCS 2009 ACM Symposium on Information, Computer and Communications Security","location":"Sydney Australia","acronym":"Asia CCS 09","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 4th International Symposium on Information, Computer, and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1533057.1533062","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1533057.1533062","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:44Z","timestamp":1750253384000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1533057.1533062"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,3,10]]},"references-count":46,"alternative-id":["10.1145\/1533057.1533062","10.1145\/1533057"],"URL":"https:\/\/doi.org\/10.1145\/1533057.1533062","relation":{},"subject":[],"published":{"date-parts":[[2009,3,10]]},"assertion":[{"value":"2009-03-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}