{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:25:57Z","timestamp":1750307157606,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":53,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,11,2]],"date-time":"2011-11-02T00:00:00Z","timestamp":1320192000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,11,2]]},"DOI":"10.1145\/2068816.2068820","type":"proceedings-article","created":{"date-parts":[[2011,11,16]],"date-time":"2011-11-16T10:40:21Z","timestamp":1321440021000},"page":"29-44","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Detecting, validating and characterizing computer infections in the wild"],"prefix":"10.1145","author":[{"given":"Elias","family":"Raftopoulos","sequence":"first","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xenofontas","family":"Dimitropoulos","sequence":"additional","affiliation":[{"name":"ETH Zurich, Zurich, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,11,2]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382923"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/T-UFFC.1987.26997"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/1736481.1736491"},{"key":"e_1_3_2_1_4_1","volume-title":"Automatically identifying trigger-based behavior in malware","author":"Brumley David","year":"2008","unstructured":"David Brumley , Cody Hartwig , Zhenkai Liang , James Newsome , Dawn Song , and Heng Yin . Automatically identifying trigger-based behavior in malware , 2008 . David Brumley, Cody Hartwig, Zhenkai Liang, James Newsome, Dawn Song, and Heng Yin. Automatically identifying trigger-based behavior in malware, 2008."},{"key":"e_1_3_2_1_5_1","volume-title":"Modeling multistep cyber attacks for scenario recognition","author":"Cheung Steven","year":"2003","unstructured":"Steven Cheung , Ulf Lindqvist , and Martin W. Fong . Modeling multistep cyber attacks for scenario recognition , 2003 . Steven Cheung, Ulf Lindqvist, and Martin W. Fong. Modeling multistep cyber attacks for scenario recognition, 2003."},{"key":"e_1_3_2_1_6_1","first-page":"202","volume-title":"Proceedings of the 2002 IEEE Symposium on Security and Privacy","author":"Cuppens Fr\u00e9d\u00e9ric","unstructured":"Fr\u00e9d\u00e9ric Cuppens and Alexandre Mi\u00e8ge . Alert correlation in a cooperative intrusion detection framework . In Proceedings of the 2002 IEEE Symposium on Security and Privacy , pages 202 --, Washington, DC, USA, 2002. IEEE Computer Society. Fr\u00e9d\u00e9ric Cuppens and Alexandre Mi\u00e8ge. Alert correlation in a cooperative intrusion detection framework. In Proceedings of the 2002 IEEE Symposium on Security and Privacy, pages 202--, Washington, DC, USA, 2002. IEEE Computer Society."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/645838.670728"},{"key":"e_1_3_2_1_8_1","volume-title":"Intrusion detection message exchange format: Extensible markup language document type definition","author":"Curry D.","year":"2003","unstructured":"D. Curry and H. Debar . Intrusion detection message exchange format: Extensible markup language document type definition , 2003 . D. Curry and H. Debar. Intrusion detection message exchange format: Extensible markup language document type definition, 2003."},{"key":"e_1_3_2_1_9_1","first-page":"1","volume-title":"In Proceedings of the 2001 ACM workshop on Data Mining for Security Applications","author":"Dain Oliver","year":"2001","unstructured":"Oliver Dain and Robert K. Cunningham . Fusing a heterogeneous alert stream into scenarios . In In Proceedings of the 2001 ACM workshop on Data Mining for Security Applications , pages 1 -- 13 , 2001 . Oliver Dain and Robert K. Cunningham. Fusing a heterogeneous alert stream into scenarios. In In Proceedings of the 2001 ACM workshop on Data Mining for Security Applications, pages 1--13, 2001."},{"key":"e_1_3_2_1_10_1","volume-title":"Building scenarios from a heterogeneous alert stream","author":"Dain Oliver M.","year":"2002","unstructured":"Oliver M. Dain and Robert K. Cunningham . Building scenarios from a heterogeneous alert stream , 2002 . Oliver M. Dain and Robert K. Cunningham. Building scenarios from a heterogeneous alert stream, 2002."},{"key":"e_1_3_2_1_11_1","volume-title":"In USENIX Hotbots'07","author":"Daswani Neil","year":"2007","unstructured":"Neil Daswani , The Google Click Quality , Security Teams , and Google Inc. The anatomy of clickbot.a . In In USENIX Hotbots'07 , 2007 . Neil Daswani, The Google Click Quality, Security Teams, and Google Inc. The anatomy of clickbot.a. In In USENIX Hotbots'07, 2007."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/645839.670735"},{"key":"e_1_3_2_1_13_1","volume-title":"Statl: An attack language for state-based intrusion detection","author":"Eckmann Steven","year":"2002","unstructured":"Steven Eckmann , Giovanni Vigna , and Richard A. Kemmerer . Statl: An attack language for state-based intrusion detection , 2002 . Steven Eckmann, Giovanni Vigna, and Richard A. Kemmerer. Statl: An attack language for state-based intrusion detection, 2002."},{"key":"e_1_3_2_1_14_1","unstructured":"Advanced automated threat analysis system. www.threatexpert.com.  Advanced automated threat analysis system. www.threatexpert.com."},{"key":"e_1_3_2_1_15_1","unstructured":"Anonymous postmasters early warning system. www.apews.org.  Anonymous postmasters early warning system. www.apews.org."},{"key":"e_1_3_2_1_16_1","unstructured":"Common Vulnerabilities and Exposures dictionary of known information security vulnerabilities. cve.mitre.org.  Common Vulnerabilities and Exposures dictionary of known information security vulnerabilities. cve.mitre.org."},{"key":"e_1_3_2_1_17_1","unstructured":"Cooperative Network Security Community - Internet Security. www.dshield.org.  Cooperative Network Security Community - Internet Security. www.dshield.org."},{"key":"e_1_3_2_1_18_1","unstructured":"Damballa - Botnet and Advanced Malware Detection and Protection. www.damballa.com.  Damballa - Botnet and Advanced Malware Detection and Protection. www.damballa.com."},{"key":"e_1_3_2_1_19_1","unstructured":"Emerging Threats web page. http:\/\/www.emergingthreats.net.  Emerging Threats web page. http:\/\/www.emergingthreats.net."},{"key":"e_1_3_2_1_20_1","unstructured":"Network Security Archive. http:\/\/www.networksecurityarchive.org.  Network Security Archive. http:\/\/www.networksecurityarchive.org."},{"key":"e_1_3_2_1_21_1","unstructured":"Packet Storm Full Disclosure Information Security. packetstormsecurity.org.  Packet Storm Full Disclosure Information Security. packetstormsecurity.org."},{"key":"e_1_3_2_1_22_1","unstructured":"Projecthoneypot web page. www.projecthoneypot.org.  Projecthoneypot web page. www.projecthoneypot.org."},{"key":"e_1_3_2_1_23_1","unstructured":"Shadowserver Foundation web page. www.shadowserver.org.  Shadowserver Foundation web page. www.shadowserver.org."},{"key":"e_1_3_2_1_24_1","unstructured":"Symantec SecurityFocus technical community. www.securityfocus.com.  Symantec SecurityFocus technical community. www.securityfocus.com."},{"key":"e_1_3_2_1_25_1","unstructured":"The Nessus vulnerability scanner. www.tenable.com\/products\/nessus.  The Nessus vulnerability scanner. www.tenable.com\/products\/nessus."},{"key":"e_1_3_2_1_26_1","unstructured":"The Open Vulnerability Assessment System. www.openvas.org.  The Open Vulnerability Assessment System. www.openvas.org."},{"key":"e_1_3_2_1_27_1","unstructured":"The Spamhaus Project. www.spamhaus.org.  The Spamhaus Project. www.spamhaus.org."},{"key":"e_1_3_2_1_28_1","unstructured":"The Urlblacklist web page. www.urlblacklist.org.  The Urlblacklist web page. www.urlblacklist.org."},{"key":"e_1_3_2_1_29_1","unstructured":"TrustedSource Internet Reputation System. www.trustedsource.org.  TrustedSource Internet Reputation System. www.trustedsource.org."},{"key":"e_1_3_2_1_30_1","volume-title":"EPFL","author":"Etienne Loic","year":"2009","unstructured":"Loic Etienne and Jean-Yves Le Boudec . Malicious traffic detection in local networks with snort. Technical report , EPFL , 2009 . Loic Etienne and Jean-Yves Le Boudec. Malicious traffic detection in local networks with snort. Technical report, EPFL, 2009."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1176995"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/950191.950192"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/775047.775101"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251086.1251120"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/1776434.1776447"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.877857"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45248-5_6"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586144"},{"key":"e_1_3_2_1_40_1","first-page":"229","volume-title":"Knowledge Discovery in Databases","author":"Piatetsky-Shapiro G.","year":"1991","unstructured":"G. Piatetsky-Shapiro . Discovery, analysis and presentation of strong rules . In G. Piatetsky-Shapiro and W. J. Frawley, editors, Knowledge Discovery in Databases , pages 229 -- 248 . AAAI Press , 1991 . G. Piatetsky-Shapiro. Discovery, analysis and presentation of strong rules. In G. Piatetsky-Shapiro and W. J. Frawley, editors, Knowledge Discovery in Databases, pages 229--248. AAAI Press, 1991."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45248-5_5"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/1884848.1884861"},{"key":"e_1_3_2_1_44_1","unstructured":"Vyas Sekar Yinglian Xie Michael K. Reiter and Hui Zhang. Is host-based anomaly detection  Vyas Sekar Yinglian Xie Michael K. Reiter and Hui Zhang. Is host-based anomaly detection"},{"key":"e_1_3_2_1_45_1","unstructured":"temporal correlation = worm causality? 2007.  temporal correlation = worm causality? 2007."},{"key":"e_1_3_2_1_46_1","first-page":"57","volume-title":"Proceedings of the 3rd International Conference on Malicious and Unwanted Software (MALWARE'08)","author":"Sinha Sushant","year":"2008","unstructured":"Sushant Sinha , Michael Bailey , and Farnam Jahanian . Shades of grey: On the effectiveness of reputation-based blacklists . In Proceedings of the 3rd International Conference on Malicious and Unwanted Software (MALWARE'08) , pages 57 -- 64 , Fairfax, Virginia, USA , October 2008 . Sushant Sinha, Michael Bailey, and Farnam Jahanian. Shades of grey: On the effectiveness of reputation-based blacklists. In Proceedings of the 3rd International Conference on Malicious and Unwanted Software (MALWARE'08), pages 57--64, Fairfax, Virginia, USA, October 2008."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/69.149926"},{"key":"e_1_3_2_1_48_1","unstructured":"A free lightweight network intrusion detection system for UNIX and Windows. http:\/\/www.snort.org.  A free lightweight network intrusion detection system for UNIX and Windows. http:\/\/www.snort.org."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028799"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720288"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1402958.1402991"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45474-8_4"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/781027.781045"},{"key":"e_1_3_2_1_54_1","volume-title":"Abstract alert correlation for extracting attack strategies","author":"Zhu Bin","year":"2005","unstructured":"Bin Zhu and Ali A. Ghorbani . Abstract alert correlation for extracting attack strategies , 2005 . Bin Zhu and Ali A. Ghorbani. Abstract alert correlation for extracting attack strategies, 2005."}],"event":{"name":"IMC '11: Internet Measurement Conference","sponsor":["SIGMETRICS ACM Special Interest Group on Measurement and Evaluation","SIGCOMM ACM Special Interest Group on Data Communication","USENIX Assoc USENIX Assoc"],"location":"Berlin Germany","acronym":"IMC '11"},"container-title":["Proceedings of the 2011 ACM SIGCOMM conference on Internet measurement conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2068816.2068820","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2068816.2068820","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:54:24Z","timestamp":1750240464000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2068816.2068820"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,11,2]]},"references-count":53,"alternative-id":["10.1145\/2068816.2068820","10.1145\/2068816"],"URL":"https:\/\/doi.org\/10.1145\/2068816.2068820","relation":{},"subject":[],"published":{"date-parts":[[2011,11,2]]},"assertion":[{"value":"2011-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}