{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T08:07:28Z","timestamp":1759133248238,"version":"3.41.0"},"reference-count":22,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2010,11,9]],"date-time":"2010-11-09T00:00:00Z","timestamp":1289260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGKDD Explor. Newsl."],"published-print":{"date-parts":[[2010,11,9]]},"abstract":"<jats:p>We present a multicriteria clustering approach that has been developed to address a problem known as attack attribution in the realm of investigative data mining. Our method can be applied to a broad range of security data sets in order to get a better understanding of the root causes of the underlying phenomena that may have produced the observed data. A key feature of this approach is the combination of cluster analysis with a component for multi-criteria decision analysis. As a result, multiple criteria of interest (or attack features) can be aggregated using different techniques, allowing one to unveil complex relationships resulting from phenomena with eventually dynamic behaviors. To illustrate the method, we provide some empirical results obtained from a data set made of attack traces collected in the Internet by a set of honeypots during two years. Thanks to the application of our attribution method, we are able to identify several large-scale phenomena composed of IP sources that are linked to the same root cause, which constitute a type of phenomenon that we have called Misbehaving cloud (MC). An in-depth analysis of two instances of such clouds demonstrates the utility and meaningfulness of the approach, as well as the kind of insights we can get into the behaviors of malicious sources involved in these clouds.<\/jats:p>","DOI":"10.1145\/1882471.1882474","type":"journal-article","created":{"date-parts":[[2010,11,12]],"date-time":"2010-11-12T13:36:08Z","timestamp":1289568968000},"page":"11-20","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["On a multicriteria clustering approach for attack attribution"],"prefix":"10.1145","volume":"12","author":[{"given":"Olivier","family":"Thonnard","sequence":"first","affiliation":[{"name":"Royal Military Academy, Polytechnic Faculty, Brussels, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wim","family":"Mees","sequence":"additional","affiliation":[{"name":"Royal Military Academy, Polytechnic Faculty, Brussels, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marc","family":"Dacier","sequence":"additional","affiliation":[{"name":"Symantec Research, Sophia Antipolis, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,11,9]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"G. Beliakov A. Pradera and T. Calvo. Aggregation Functions: A Guide for Practitioners. Springer Berlin New York 2007.   G. Beliakov A. Pradera and T. Calvo. Aggregation Functions: A Guide for Practitioners. Springer Berlin New York 2007."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2008.299"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298319"},{"key":"e_1_2_1_4_1","unstructured":"Symantec Corporation. Symantec Report on Rogue Security Software http:\/\/www.symantec.com\/business\/theme.jsp?themeid=threatreport {oct 2009}.  Symantec Corporation. Symantec Report on Rogue Security Software http:\/\/www.symantec.com\/business\/theme.jsp?themeid=threatreport {oct 2009}."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10772-6_3"},{"volume-title":"Society for Industrial and Applied Mathematics","year":"2006","author":"Davis Timothy A.","key":"e_1_2_1_6_1"},{"key":"e_1_2_1_7_1","unstructured":"A.K. Jain and R.C. Dubes. Algorithms for Clustering Data. Prentice-Hall advanced reference series 1988.   A.K. Jain and R.C. Dubes. Algorithms for Clustering Data. Prentice-Hall advanced reference series 1988."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177729694"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/WISTDCS.2008.8"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/EDCC-7.2008.15"},{"key":"e_1_2_1_11_1","unstructured":"Leurre.com Eurecom Honeypot Project. http:\/\/www.leurrecom.org\/ {{s}ep 2009}.  Leurre.com Eurecom Honeypot Project. http:\/\/www.leurrecom.org\/ {{s}ep 2009}."},{"issue":"1","key":"e_1_2_1_12_1","first-page":"145","article-title":"Divergence measures based on the shannon entropy. Information Theory","volume":"37","author":"Lin J.","year":"1991","journal-title":"IEEE Transactions on"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/1965841.1965859"},{"volume-title":"TELECOM ParisTech","year":"2009","author":"Pham Van-Hau","key":"e_1_2_1_15_1"},{"volume-title":"Brisbane","year":"2004","author":"Pouget F.","key":"e_1_2_1_16_1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1126\/science.210.4468.390"},{"key":"e_1_2_1_18_1","first-page":"2579","article-title":"Visualizing data using t-sne","volume":"9","author":"van der Maaten Laurens","year":"2008","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"C. Westphal. Data Mining for Intelligence Fraud & Criminal Detection: Advanced Analytics & Information Sharing Technologies. CRC Press 1st edition (December 22 2008) 2008.   C. Westphal. Data Mining for Intelligence Fraud & Criminal Detection: Advanced Analytics & Information Sharing Technologies. CRC Press 1st edition (December 22 2008) 2008.","DOI":"10.1201\/9781420067248"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.21236\/ADA468859"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/21.87068"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/781027.781045"}],"container-title":["ACM SIGKDD Explorations Newsletter"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1882471.1882474","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1882471.1882474","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:34Z","timestamp":1750244374000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1882471.1882474"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,11,9]]},"references-count":22,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2010,11,9]]}},"alternative-id":["10.1145\/1882471.1882474"],"URL":"https:\/\/doi.org\/10.1145\/1882471.1882474","relation":{},"ISSN":["1931-0145","1931-0153"],"issn-type":[{"type":"print","value":"1931-0145"},{"type":"electronic","value":"1931-0153"}],"subject":[],"published":{"date-parts":[[2010,11,9]]},"assertion":[{"value":"2010-11-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}