{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:53:01Z","timestamp":1750308781919,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","license":[{"start":{"date-parts":[[2010,12,6]],"date-time":"2010-12-06T00:00:00Z","timestamp":1291593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2010,12,6]]},"DOI":"10.1145\/1920261.1920284","type":"proceedings-article","created":{"date-parts":[[2010,12,20]],"date-time":"2010-12-20T16:13:47Z","timestamp":1292861627000},"page":"141-150","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["The case for in-the-lab botnet experimentation"],"prefix":"10.1145","author":[{"given":"Joan","family":"Calvet","sequence":"first","affiliation":[{"name":"\u00c9cole Polytechnique de, Montr\u00e9al, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carlton R.","family":"Davis","sequence":"additional","affiliation":[{"name":"\u00c9cole Polytechnique de, Montr\u00e9al, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jos\u00e9 M.","family":"Fernandez","sequence":"additional","affiliation":[{"name":"\u00c9cole Polytechnique de, Montr\u00e9al, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jean-Yves","family":"Marion","sequence":"additional","affiliation":[{"name":"LORIA, Nancy, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pier-Luc","family":"St-Onge","sequence":"additional","affiliation":[{"name":"Ecole Polytech. de Montr\u00e9al"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wadie","family":"Guizani","sequence":"additional","affiliation":[{"name":"LORIA, Nancy, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pierre-Marc","family":"Bureau","sequence":"additional","affiliation":[{"name":"ESET, Montr\u00e9al, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anil","family":"Somayaji","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/1323128.1323134"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TRIDNT.2006.1649172"},{"key":"e_1_3_2_1_3_1","volume-title":"Proc. Int. Swarm Intelligence and Other Forms of Malware Work. (MALWARE)","author":"P.-M. Bureau and J. Fernandez","year":"2007","unstructured":"P.-M. Bureau and J. Fernandez . Optimising networks against malware . In Proc. Int. Swarm Intelligence and Other Forms of Malware Work. (MALWARE) , Apr. 2007 . P.-M. Bureau and J. Fernandez. Optimising networks against malware. In Proc. Int. Swarm Intelligence and Other Forms of Malware Work. (MALWARE), Apr. 2007."},{"key":"e_1_3_2_1_4_1","volume-title":"Int. Conf. on Malicious and Unwanted Software (MALWARE)","author":"Calvet J.","year":"2009","unstructured":"J. Calvet , C. Davis , and P.-M. Bureau . Malware authors don't learn, and that's good! In Proc . Int. Conf. on Malicious and Unwanted Software (MALWARE) , Oct. 2009 . J. Calvet, C. Davis, and P.-M. Bureau. Malware authors don't learn, and that's good! In Proc. Int. Conf. on Malicious and Unwanted Software (MALWARE), Oct. 2009."},{"key":"e_1_3_2_1_5_1","volume-title":"Proc. 3rd USENIX Work, on Cyber Sec. Experimentation and Test (CSET)","author":"Calvet J.","year":"2010","unstructured":"J. Calvet , C. Davis , J. Fernandez , W. Guizani , M. Kaczmarek , J.-Y. Marion , and P.-L. St-Onge . Isolated virtualised clusters: testbeds for high-security experimentation and training . In Proc. 3rd USENIX Work, on Cyber Sec. Experimentation and Test (CSET) , Aug. 2010 . J. Calvet, C. Davis, J. Fernandez, W. Guizani, M. Kaczmarek, J.-Y. Marion, and P.-L. St-Onge. Isolated virtualised clusters: testbeds for high-security experimentation and training. In Proc. 3rd USENIX Work, on Cyber Sec. Experimentation and Test (CSET), Aug. 2010."},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. Work. on Steps to Reducing Unwanted Traffic on the Internet (SRUTI)","author":"Cooke E.","year":"2005","unstructured":"E. Cooke , F. Jahanian , and D. McPherson . The zombie roundup: Understanding, detecting, and disrupting botnets . In Proc. Work. on Steps to Reducing Unwanted Traffic on the Internet (SRUTI) , July 2005 . E. Cooke, F. Jahanian, and D. McPherson. The zombie roundup: Understanding, detecting, and disrupting botnets. In Proc. Work. on Steps to Reducing Unwanted Traffic on the Internet (SRUTI), July 2005."},{"key":"e_1_3_2_1_7_1","volume-title":"Proc. of CAIDA DNS-OARC Work","author":"Dagon D.","year":"2005","unstructured":"D. Dagon , G. Gu , C. Zou , J. Grizzard , S. Dwivedi , W. Lee , and R. Lipton . A taxonomy of botnets . In Proc. of CAIDA DNS-OARC Work , July 2005 . D. Dagon, G. Gu, C. Zou, J. Grizzard, S. Dwivedi, W. Lee, and R. Lipton. A taxonomy of botnets. In Proc. of CAIDA DNS-OARC Work, July 2005."},{"key":"e_1_3_2_1_8_1","volume-title":"Proc. 13th Network and Distributed System Security Symp. (NDSS)","author":"Dagon D.","year":"2006","unstructured":"D. Dagon , C. Zou , and W. Lee . Modeling botnet propagation using time zones . In Proc. 13th Network and Distributed System Security Symp. (NDSS) , Feb. 2006 . D. Dagon, C. Zou, and W. Lee. Modeling botnet propagation using time zones. In Proc. 13th Network and Distributed System Security Symp. (NDSS), Feb. 2006."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2009.5403016"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2008.4690855"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_30"},{"key":"e_1_3_2_1_12_1","unstructured":"S. Gaudin. Storm botnet puts up defenses and starts attacking back http:\/\/informationweek.com Aug. 2007.  S. Gaudin. Storm botnet puts up defenses and starts attacking back http:\/\/informationweek.com Aug. 2007."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CATCH.2009.26"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/1558977.1558997"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455774"},{"key":"e_1_3_2_1_16_1","volume-title":"Proc. 1st USENLX Work. Large-Scale Exploits &amp; Emergent Threats (LEET)","author":"Kanich C.","year":"2008","unstructured":"C. Kanich , K. Levchenko , B. Enright , G. Voelker , and S. Savage . The Heisenbot uncertainty problem: Challenges in separating bots from chaff . In Proc. 1st USENLX Work. Large-Scale Exploits &amp; Emergent Threats (LEET) , Apr. 2008 . C. Kanich, K. Levchenko, B. Enright, G. Voelker, and S. Savage. The Heisenbot uncertainty problem: Challenges in separating bots from chaff. In Proc. 1st USENLX Work. Large-Scale Exploits &amp; Emergent Threats (LEET), Apr. 2008."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1113361.1113367"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177086"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/QEST.2008.43"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2009.5403015"},{"key":"e_1_3_2_1_21_1","volume-title":"Feb.","author":"Stewart J.","year":"2007","unstructured":"J. Stewart . Storm worm DDoS attack. http:\/\/www.secureworks.com\/research\/threats\/storm-worm , Feb. 2007 . J. Stewart. Storm worm DDoS attack. http:\/\/www.secureworks.com\/research\/threats\/storm-worm, Feb. 2007."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/EC2ND.2009.10"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/1323128.1323130"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060289.1060313"},{"key":"e_1_3_2_1_25_1","volume-title":"Proc. 6th USENIX Symp. on Networked Systems Designs and Implementation (NSDI)","author":"Zhao Y.","year":"2009","unstructured":"Y. Zhao , Y. Xie , F. Yu , Q. Ke , Y. Yu , Y. Chen , and E. Gillum . Botgraph: Large scale spamming botnet detection . In Proc. 6th USENIX Symp. on Networked Systems Designs and Implementation (NSDI) , 2009 . Y. Zhao, Y. Xie, F. Yu, Q. Ke, Y. Yu, Y. Chen, and E. Gillum. Botgraph: Large scale spamming botnet detection. In Proc. 6th USENIX Symp. on Networked Systems Designs and Implementation (NSDI), 2009."}],"event":{"name":"ACSAC '10: 2010 Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Austin Texas USA","acronym":"ACSAC '10"},"container-title":["Proceedings of the 26th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920284","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1920261.1920284","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:22:43Z","timestamp":1750278163000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920284"}},"subtitle":["creating and taking down a 3000-node botnet"],"short-title":[],"issued":{"date-parts":[[2010,12,6]]},"references-count":25,"alternative-id":["10.1145\/1920261.1920284","10.1145\/1920261"],"URL":"https:\/\/doi.org\/10.1145\/1920261.1920284","relation":{},"subject":[],"published":{"date-parts":[[2010,12,6]]},"assertion":[{"value":"2010-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}