{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T12:12:04Z","timestamp":1763467924179,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":27,"publisher":"ACM","license":[{"start":{"date-parts":[[2009,8,21]],"date-time":"2009-08-21T00:00:00Z","timestamp":1250812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2009,8,21]]},"DOI":"10.1145\/1592681.1592686","type":"proceedings-article","created":{"date-parts":[[2009,8,24]],"date-time":"2009-08-24T14:08:35Z","timestamp":1251122915000},"page":"27-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Impact of IT monoculture on behavioral end host intrusion detection"],"prefix":"10.1145","author":[{"given":"Dhiman","family":"Barman","sequence":"first","affiliation":[{"name":"Juniper, Sunnyvale, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jaideep","family":"Chandrashekar","sequence":"additional","affiliation":[{"name":"Intel Labs, Berkeley, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nina","family":"Taft","sequence":"additional","affiliation":[{"name":"Intel Labs, Berkeley, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Faloutsos","sequence":"additional","affiliation":[{"name":"University of California, Riverside, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ling","family":"Huang","sequence":"additional","affiliation":[{"name":"Intel Labs, Berkeley, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frederic","family":"Giroire","sequence":"additional","affiliation":[{"name":"INRIA, Sophia-Antipolis, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,8,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Damballa. http:\/\/www.damballa.com\/solutions.  Damballa. http:\/\/www.damballa.com\/solutions."},{"key":"e_1_3_2_1_2_1","unstructured":"Intel Active Management Technology. http:\/\/www.intel.com\/technology\/platform-technology\/intel-amt\/ http:\/\/www3.intel.com\/cd\/business\/enterprise\/emea\/ENG\/310547.htm.  Intel Active Management Technology. http:\/\/www.intel.com\/technology\/platform-technology\/intel-amt\/ http:\/\/www3.intel.com\/cd\/business\/enterprise\/emea\/ENG\/310547.htm."},{"key":"e_1_3_2_1_3_1","unstructured":"Mcafee. http:\/\/www.mcafee.com\/products\/systems_security\/clients.  Mcafee. http:\/\/www.mcafee.com\/products\/systems_security\/clients."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2008.2007431"},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. of FLOCON","author":"Binkley J.","year":"2009","unstructured":"J. Binkley and D. Parekh . Traffic Analysis of UDP-based flows in Ourmon . In Proc. of FLOCON , 2009 . J. Binkley and D. Parekh. Traffic Analysis of UDP-based flows in Ourmon. In Proc. of FLOCON, 2009."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.24"},{"key":"e_1_3_2_1_8_1","volume-title":"Proc. of NDSS Symposium","author":"Caballero J.","year":"2008","unstructured":"J. Caballero , T. Kampouris , D. Song , and J. Wang . Would diversity really increase the robustness of the routing infrastructure against software defects ? In Proc. of NDSS Symposium , San Diego , 2008 . J. Caballero, T. Kampouris, D. Song, and J. Wang. Would diversity really increase the robustness of the routing infrastructure against software defects? In Proc. of NDSS Symposium, San Diego, 2008."},{"key":"e_1_3_2_1_10_1","unstructured":"Cisco. Always Vigilant Endpoint. http:\/\/www.cisco.com\/en\/US\/products\/sw\/secursw\/ps5057\/index.html.  Cisco. Always Vigilant Endpoint. http:\/\/www.cisco.com\/en\/US\/products\/sw\/secursw\/ps5057\/index.html."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_3_2_1_12_1","volume-title":"Phalanx: Withstanding Multimillion-Node Botnets. In Proc. of USENIX NSDI","author":"Colin","year":"2008","unstructured":"Colin Dixon et al . Phalanx: Withstanding Multimillion-Node Botnets. In Proc. of USENIX NSDI , 2008 . Colin Dixon et al. Phalanx: Withstanding Multimillion-Node Botnets. In Proc. of USENIX NSDI, 2008."},{"key":"e_1_3_2_1_13_1","volume-title":"Proc. of USENIX Security Symposium","author":"David","year":"2007","unstructured":"David Brumley et al. Towards Automatic Discovery of Deviations in Binary Implementations with Applications to Error Detection and Fingerprint Generation . In Proc. of USENIX Security Symposium , 2007 . David Brumley et al. Towards Automatic Discovery of Deviations in Binary Implementations with Applications to Error Detection and Fingerprint Generation. In Proc. of USENIX Security Symposium, 2007."},{"key":"e_1_3_2_1_14_1","volume-title":"Usenix Security","author":"Guofei Gu","year":"2007","unstructured":"Guofei Gu et al. BotHunter: Detecting Malware Infection Through IDS-driven Dialog Correlation . In Usenix Security 2007 . Guofei Gu et al. BotHunter: Detecting Malware Infection Through IDS-driven Dialog Correlation. In Usenix Security 2007."},{"volume-title":"Proc. of NDSS'08","author":"Guofei","key":"e_1_3_2_1_15_1","unstructured":"Guofei Gu et al. BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic . In Proc. of NDSS'08 . Guofei Gu et al. BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In Proc. of NDSS'08."},{"key":"e_1_3_2_1_16_1","volume-title":"SRUTI Workshop","author":"James","year":"2006","unstructured":"James Binkley et al. An algorithm for anomaly-based botnet detection . SRUTI Workshop , 2006 . James Binkley et al. An algorithm for anomaly-based botnet detection. SRUTI Workshop, 2006."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/822075.822408"},{"key":"e_1_3_2_1_18_1","volume-title":"Proc. of USENIX SRUTI","author":"James","year":"2006","unstructured":"James R. Binkley et al. An algorithm for anomaly-based botnet detection . In Proc. of USENIX SRUTI , 2006 . James R. Binkley et al. An algorithm for anomaly-based botnet detection. In Proc. of USENIX SRUTI, 2006."},{"key":"e_1_3_2_1_19_1","volume-title":"Profiling the End Host. In Passive and Active Measurement Conference (PAM)","author":"Karagiannis T.","year":"2007","unstructured":"T. Karagiannis , D. Papagiannaki , N. Taft , and M. Faloutsos . Profiling the End Host. In Passive and Active Measurement Conference (PAM) , April 2007 . T. Karagiannis, D. Papagiannaki, N. Taft, and M. Faloutsos. Profiling the End Host. In Passive and Active Measurement Conference (PAM), April 2007."},{"key":"e_1_3_2_1_20_1","volume-title":"Fourth Workshop on Hot Topics in Networks (HotNets-IV)","author":"Kreibich C.","year":"2005","unstructured":"C. Kreibich , A. Warfield , J. Crowcroft , S. Hand , and I. Pratt . Using Packet Symmetry to Curtail Malicious Traffic . Fourth Workshop on Hot Topics in Networks (HotNets-IV) , 2005 . C. Kreibich, A. Warfield, J. Crowcroft, S. Hand, and I. Pratt. Using Packet Symmetry to Curtail Malicious Traffic. Fourth Workshop on Hot Topics in Networks (HotNets-IV), 2005."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1402958.1402981"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1146269.1146277"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.58"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/762476.762477"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"e_1_3_2_1_27_1","volume-title":"Proc 22nd Int'l Symp. Reliable Distributed Systems","author":"Xu J.","year":"2003","unstructured":"J. Xu , Z. Kalbarczyk , and R.K. Iyer . Transparent Runtime Randomization for Security . In Proc 22nd Int'l Symp. Reliable Distributed Systems , 2003 . J. Xu, Z. Kalbarczyk, and R.K. Iyer. Transparent Runtime Randomization for Security. In Proc 22nd Int'l Symp. Reliable Distributed Systems, 2003."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2004.1301320"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.914506"}],"event":{"name":"SIGCOMM '09: ACM SIGCOMM 2009 Conference","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication","ACM Association for Computing Machinery"],"location":"Barcelona Spain","acronym":"SIGCOMM '09"},"container-title":["Proceedings of the 1st ACM workshop on Research on enterprise networking"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1592681.1592686","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1592681.1592686","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:35Z","timestamp":1750253375000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1592681.1592686"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,8,21]]},"references-count":27,"alternative-id":["10.1145\/1592681.1592686","10.1145\/1592681"],"URL":"https:\/\/doi.org\/10.1145\/1592681.1592686","relation":{},"subject":[],"published":{"date-parts":[[2009,8,21]]},"assertion":[{"value":"2009-08-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}