{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T14:54:22Z","timestamp":1763477662836,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":16,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,4,10]],"date-time":"2011-04-10T00:00:00Z","timestamp":1302393600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,4,10]]},"DOI":"10.1145\/1978672.1978682","type":"proceedings-article","created":{"date-parts":[[2011,5,9]],"date-time":"2011-05-09T12:48:29Z","timestamp":1304945309000},"page":"78-88","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":61,"title":["Sandnet"],"prefix":"10.1145","author":[{"given":"Christian","family":"Rossow","sequence":"first","affiliation":[{"name":"University of Applied Sciences Gelsenkirchen, Germany and VU University Amsterdam, The Netherlands"}]},{"given":"Christian J.","family":"Dietrich","sequence":"additional","affiliation":[{"name":"University of Applied Sciences Gelsenkirchen, Germany and University of Erlangen, Germany"}]},{"given":"Herbert","family":"Bos","sequence":"additional","affiliation":[{"name":"VU University Amsterdam, The Netherlands"}]},{"given":"Lorenzo","family":"Cavallaro","sequence":"additional","affiliation":[{"name":"VU University Amsterdam, The Netherlands"}]},{"given":"Maarten","family":"van Steen","sequence":"additional","affiliation":[{"name":"VU University Amsterdam, The Netherlands"}]},{"given":"Felix C.","family":"Freiling","sequence":"additional","affiliation":[{"name":"University of Erlangen, Germany"}]},{"given":"Norbert","family":"Pohlmann","sequence":"additional","affiliation":[{"name":"University of Applied Sciences Gelsenkirchen, Germany"}]}],"member":"320","published-online":{"date-parts":[[2011,4,10]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Hispasec Sistemas - VirusTotal. http:\/\/www.virustotal.com\/.  Hispasec Sistemas - VirusTotal. http:\/\/www.virustotal.com\/."},{"key":"e_1_3_2_1_2_1","unstructured":"Norman Sandbox. http:\/\/www.norman.com\/security_center\/security_tools\/.  Norman Sandbox. http:\/\/www.norman.com\/security_center\/security_tools\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Sandnet. http:\/\/www.if-is.net\/sandnet\/.  Sandnet. http:\/\/www.if-is.net\/sandnet\/."},{"key":"e_1_3_2_1_4_1","unstructured":"The Shadowserver Foundation - bin-test. http:\/\/bin-test.shadowserver.org\/.  The Shadowserver Foundation - bin-test. http:\/\/bin-test.shadowserver.org\/."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_9"},{"key":"e_1_3_2_1_6_1","volume-title":"Behavior-Based Malware Clustering. In NDSS","author":"Bayer U.","year":"2009","unstructured":"U. Bayer , P. M. Comparetti , C. Hlauschek , C. Kruegel , E. Kirda , and S. Barbara . Scalable , Behavior-Based Malware Clustering. In NDSS 2009 . U. Bayer, P. M. Comparetti, C. Hlauschek, C. Kruegel, E. Kirda, and S. Barbara. Scalable, Behavior-Based Malware Clustering. In NDSS 2009."},{"key":"e_1_3_2_1_7_1","volume-title":"USENIX LEET","author":"Bayer U.","year":"2009","unstructured":"U. Bayer , I. Habibi , D. Balzarotti , E. Kirda , and C. Kruegel . A View on Current Malware Behaviors . In USENIX LEET 2009 . U. Bayer, I. Habibi, D. Balzarotti, E. Kirda, and C. Kruegel. A View on Current Malware Behaviors. In USENIX LEET 2009."},{"key":"e_1_3_2_1_8_1","volume-title":"TTAnalyze: A Tool for Analyzing Malware. In EICAR","author":"Bayer U.","year":"2006","unstructured":"U. Bayer , C. Kruegel , and E. Kirda . TTAnalyze: A Tool for Analyzing Malware. In EICAR 2006 . U. Bayer, C. Kruegel, and E. Kirda. TTAnalyze: A Tool for Analyzing Malware. In EICAR 2006."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/11957454_2"},{"volume-title":"USENIX HotBots '07","author":"Goebel J.","key":"e_1_3_2_1_11_1","unstructured":"J. Goebel and T. Holz . Rishi: Identify Bot Contaminated Hosts by IRC Nickname Evaluation . In USENIX HotBots '07 . J. Goebel and T. Holz. Rishi: Identify Bot Contaminated Hosts by IRC Nickname Evaluation. In USENIX HotBots '07."},{"key":"e_1_3_2_1_12_1","volume-title":"NDSS","author":"Holz T.","year":"2008","unstructured":"T. Holz , C. Gorecki , K. Rieck , and F. C. Freiling . Measuring and detecting fast-flux service networks . In NDSS , 2008 . T. Holz, C. Gorecki, K. Rieck, and F. C. Freiling. Measuring and detecting fast-flux service networks. In NDSS, 2008."},{"key":"e_1_3_2_1_13_1","volume-title":"Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces. In NSDI","author":"Perdisci R.","year":"2010","unstructured":"R. Perdisci , W. Lee , and N. Feamster . Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces. In NSDI 2010 . R. Perdisci, W. Lee, and N. Feamster. Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces. In NSDI 2010."},{"key":"e_1_3_2_1_14_1","author":"Rieck K.","year":"2011","unstructured":"K. Rieck , P. Trinius , C. Willems , and T. Holz . Automatic Analysis of Malware Behavior using Machine Learning. In Journal of Computer Security 2011 . K. Rieck, P. Trinius, C. Willems, and T. Holz. Automatic Analysis of Malware Behavior using Machine Learning. In Journal of Computer Security 2011.","journal-title":"Automatic Analysis of Malware Behavior using Machine Learning. In Journal of Computer Security"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"e_1_3_2_1_16_1","volume-title":"A Taste of HTTP Botnets","author":"van den Berg M.","year":"2008","unstructured":"M. van den Berg . A Taste of HTTP Botnets , 2008 . M. van den Berg. A Taste of HTTP Botnets, 2008."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"}],"event":{"name":"EuroSys '11: Sixth EuroSys Conference 2011","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"],"location":"Salzburg Austria","acronym":"EuroSys '11"},"container-title":["Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1978672.1978682","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1978672.1978682","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:37Z","timestamp":1750244377000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1978672.1978682"}},"subtitle":["network traffic analysis of malicious software"],"short-title":[],"issued":{"date-parts":[[2011,4,10]]},"references-count":16,"alternative-id":["10.1145\/1978672.1978682","10.1145\/1978672"],"URL":"https:\/\/doi.org\/10.1145\/1978672.1978682","relation":{},"subject":[],"published":{"date-parts":[[2011,4,10]]},"assertion":[{"value":"2011-04-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}