{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:51:08Z","timestamp":1771699868656,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":28,"publisher":"ACM","license":[{"start":{"date-parts":[[2009,3,10]],"date-time":"2009-03-10T00:00:00Z","timestamp":1236643200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0716025DUE-0723808DUE-0830624"],"award-info":[{"award-number":["CNS-0716025DUE-0723808DUE-0830624"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000172","name":"Division of Undergraduate Education","doi-asserted-by":"publisher","award":["CNS-0716025DUE-0723808DUE-0830624"],"award-info":[{"award-number":["CNS-0716025DUE-0723808DUE-0830624"]}],"id":[{"id":"10.13039\/100000172","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2009,3,10]]},"DOI":"10.1145\/1533057.1533064","type":"proceedings-article","created":{"date-parts":[[2009,4,28]],"date-time":"2009-04-28T14:57:19Z","timestamp":1240930639000},"page":"23-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["Towards complete node enumeration in a peer-to-peer botnet"],"prefix":"10.1145","author":[{"given":"Brent ByungHoon","family":"Kang","sequence":"first","affiliation":[{"name":"University of North Carolina at Charlotte"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Chan-Tin","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher P.","family":"Lee","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Tyra","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hun Jeong","family":"Kang","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chris","family":"Nunnery","sequence":"additional","affiliation":[{"name":"University of North Carolina at Charlotte"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zachariah","family":"Wadler","sequence":"additional","affiliation":[{"name":"University of North Carolina at Charlotte"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Greg","family":"Sinclair","sequence":"additional","affiliation":[{"name":"University of North Carolina at Charlotte"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"Hopper","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Dagon","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongdae","family":"Kim","sequence":"additional","affiliation":[{"name":"University of Minnesota"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,3,10]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Atrivo\/intercage's disconnection briefly disrupts spam levels. http:\/\/blogs.zdnet.com\/security\/?p=2006.  Atrivo\/intercage's disconnection briefly disrupts spam levels. http:\/\/blogs.zdnet.com\/security\/?p=2006."},{"key":"e_1_3_2_1_2_1","unstructured":"aMule network. http:\/\/www.amule.org.  aMule network. http:\/\/www.amule.org."},{"key":"e_1_3_2_1_3_1","first-page":"39","volume-title":"Usenix Workshop on Steps to Reducing Unwanted Traffic on the Internet","author":"Cooke E.","year":"2006","unstructured":"E. Cooke , F. Jahanian , and D. McPherson . The zombie roundup: Understanding, detecting, and disrupting botnets . In Usenix Workshop on Steps to Reducing Unwanted Traffic on the Internet , pages 39 -- 44 , July 2006 . E. Cooke, F. Jahanian, and D. McPherson. The zombie roundup: Understanding, detecting, and disrupting botnets. In Usenix Workshop on Steps to Reducing Unwanted Traffic on the Internet, pages 39--44, July 2006."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.44"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/646334.687813"},{"key":"e_1_3_2_1_6_1","volume-title":"ToorCon","author":"Enright B.","year":"2007","unstructured":"B. Enright . Exposing storm . In ToorCon , 2007 . B. Enright. Exposing storm. In ToorCon, 2007."},{"key":"e_1_3_2_1_7_1","volume-title":"Usenix, 33(4)","author":"Enright B.","year":"2008","unstructured":"B. Enright , G. Voelker , S. Savage , C. Kanich , and K. Levchenko . Storm: When researchers collide. ;Login , Usenix, 33(4) , August 2008 . B. Enright, G. Voelker, S. Savage, C. Kanich, and K. Levchenko. Storm: When researchers collide. ;Login, Usenix, 33(4), August 2008."},{"key":"e_1_3_2_1_8_1","unstructured":"Attacks on virtual machine emulators http:\/\/www.symantec.com\/avcenter\/reference\/Virtual_Machine_Threats.pdf.  Attacks on virtual machine emulators http:\/\/www.symantec.com\/avcenter\/reference\/Virtual_Machine_Threats.pdf."},{"key":"e_1_3_2_1_9_1","volume-title":"Symantec Security Response: Ireland","author":"Florino E.","year":"2007","unstructured":"E. Florino and M. Cibotariu . Peerbot: Catch me if you can . In Symantec Security Response: Ireland , Virus Bulletin , March 2007 . E. Florino and M. Cibotariu. Peerbot: Catch me if you can. In Symantec Security Response: Ireland, Virus Bulletin, March 2007."},{"key":"e_1_3_2_1_10_1","volume-title":"Usenix First Workshop on Hot Topics in Understanding Botnets","author":"Grizzard J.","year":"2007","unstructured":"J. Grizzard , V. Sharma , C. Nunnery , B. Kang , and D. Dagon . Peer-to-peer botnets: Overview and case study . In Usenix First Workshop on Hot Topics in Understanding Botnets , April 2007 . J. Grizzard, V. Sharma, C. Nunnery, B. Kang, and D. Dagon. Peer-to-peer botnets: Overview and case study. In Usenix First Workshop on Hot Topics in Understanding Botnets, April 2007."},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 17th annual USENIX Security Symposium. USENIX Association","author":"Gu G.","year":"2008","unstructured":"G. Gu , R. Perdisci , J. Zhang , and W. Lee . Botminer: Clustering analysis of network traffic from protocol and command and control channels in network traffic . In Proceedings of the 17th annual USENIX Security Symposium. USENIX Association , July 2008 . G. Gu, R. Perdisci, J. Zhang, and W. Lee. Botminer: Clustering analysis of network traffic from protocol and command and control channels in network traffic. In Proceedings of the 17th annual USENIX Security Symposium. USENIX Association, July 2008."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of The 16th USENIX Security Symposium. USENIX Association","author":"Gu G.","year":"2007","unstructured":"G. Gu , P. Porras , V. Yegneswaran , M. Fong , and W. Lee . Bothunter: Detecting malware infection through ids-driven dialog correlation . In Proceedings of The 16th USENIX Security Symposium. USENIX Association , August 2007 . G. Gu, P. Porras, V. Yegneswaran, M. Fong, and W. Lee. Bothunter: Detecting malware infection through ids-driven dialog correlation. In Proceedings of The 16th USENIX Security Symposium. USENIX Association, August 2007."},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 15th Annual Network and Distributed System Security Symposium. ISOC","author":"Gu G.","year":"2008","unstructured":"G. Gu , J. Zhang , and W. Lee . Botsniffer: Detecting botnet command and control channels in network traffic . In Proceedings of the 15th Annual Network and Distributed System Security Symposium. ISOC , February 2008 . G. Gu, J. Zhang, and W. Lee. Botsniffer: Detecting botnet command and control channels in network traffic. In Proceedings of the 15th Annual Network and Distributed System Security Symposium. ISOC, February 2008."},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats. USENIX Association","author":"Holz T.","year":"2008","unstructured":"T. Holz , M. Steiner , F. Dahl , E. Biersack , and F. Freiling . Measurements and mitigation of peer-to-peer-based botnets: A case study on storm worm . In Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats. USENIX Association , April 2008 . T. Holz, M. Steiner, F. Dahl, E. Biersack, and F. Freiling. Measurements and mitigation of peer-to-peer-based botnets: A case study on storm worm. In Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats. USENIX Association, April 2008."},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats. USENIX Association","author":"Kanich C.","year":"2008","unstructured":"C. Kanich , K. Levchenko , B. Enright , G. Voelker , and S. Savage . The Heisenbot uncertainty problem: Challenges in separating bots from chaff . In Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats. USENIX Association , April 2008 . C. Kanich, K. Levchenko, B. Enright, G. Voelker, and S. Savage. The Heisenbot uncertainty problem: Challenges in separating bots from chaff. In Proceedings of the First USENIX Workshop on Large Scale Exploits and Emergent Threats. USENIX Association, April 2008."},{"key":"e_1_3_2_1_16_1","unstructured":"Mainline. http:\/\/www.bittorrent.com.  Mainline. http:\/\/www.bittorrent.com."},{"key":"e_1_3_2_1_17_1","unstructured":"matlab. http:\/\/www.mathworks.com\/.  matlab. http:\/\/www.mathworks.com\/."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/646334.687801"},{"key":"e_1_3_2_1_19_1","unstructured":"The Overnet Protocol https:\/\/opensvn.csie.org\/mlnet\/trunk\/docs\/overnet.txt.  The Overnet Protocol https:\/\/opensvn.csie.org\/mlnet\/trunk\/docs\/overnet.txt."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177086"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2006.231"},{"key":"e_1_3_2_1_22_1","unstructured":"SORBS. http:\/\/www.us.sorbs.net\/faq\/dul.shtml.  SORBS. http:\/\/www.us.sorbs.net\/faq\/dul.shtml."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298323"},{"key":"e_1_3_2_1_24_1","unstructured":"J. Stewart. Protocols and encryption of the storm botnet. http:\/\/www.blackhat.com\/presentations\/bh-usa-08\/Stewart\/BH_US_08_Stewart_Protocols_of_the_Storm.pdf.  J. Stewart. Protocols and encryption of the storm botnet. http:\/\/www.blackhat.com\/presentations\/bh-usa-08\/Stewart\/BH_US_08_Stewart_Protocols_of_the_Storm.pdf."},{"key":"e_1_3_2_1_25_1","unstructured":"J. Stewart. Storm worm ddos attack. http:\/\/www.secureworks.com\/research\/threats\/view.html?threat=storm-worm February 2007.  J. Stewart. Storm worm ddos attack. http:\/\/www.secureworks.com\/research\/threats\/view.html?threat=storm-worm February 2007."},{"key":"e_1_3_2_1_26_1","volume-title":"Usenix, 32(6)","author":"Stover S.","year":"2007","unstructured":"S. Stover , D. Dittrich , J. Hernandez , and S. Deitrich . Analysis of the storm and nugache trojans - P2P is here. ;Login , Usenix, 32(6) , December 2007 . S. Stover, D. Dittrich, J. Hernandez, and S. Deitrich. Analysis of the storm and nugache trojans - P2P is here. ;Login, Usenix, 32(6), December 2007."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2006.329"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1282380.1282415"}],"event":{"name":"Asia CCS 09: Asia CCS 2009 ACM Symposium on Information, Computer and Communications Security","location":"Sydney Australia","acronym":"Asia CCS 09","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 4th International Symposium on Information, Computer, and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1533057.1533064","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1533057.1533064","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:44Z","timestamp":1750253384000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1533057.1533064"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,3,10]]},"references-count":28,"alternative-id":["10.1145\/1533057.1533064","10.1145\/1533057"],"URL":"https:\/\/doi.org\/10.1145\/1533057.1533064","relation":{},"subject":[],"published":{"date-parts":[[2009,3,10]]},"assertion":[{"value":"2009-03-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}