{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:25:58Z","timestamp":1750307158000,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":29,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,11,2]],"date-time":"2011-11-02T00:00:00Z","timestamp":1320192000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,11,2]]},"DOI":"10.1145\/2068816.2068854","type":"proceedings-article","created":{"date-parts":[[2011,11,16]],"date-time":"2011-11-16T10:40:21Z","timestamp":1321440021000},"page":"397-412","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":28,"title":["GQ"],"prefix":"10.1145","author":[{"given":"Christian","family":"Kreibich","sequence":"first","affiliation":[{"name":"ICSI &amp; UCB, Berkeley, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"Weaver","sequence":"additional","affiliation":[{"name":"ICSI &amp; UCB, Berkeley, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chris","family":"Kanich","sequence":"additional","affiliation":[{"name":"UC San Diego, San Diego, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weidong","family":"Cui","sequence":"additional","affiliation":[{"name":"Microsoft Research, Redmond, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vern","family":"Paxson","sequence":"additional","affiliation":[{"name":"ICSI &amp; UCB, Berkeley, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,11,2]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/1323128.1323134"},{"key":"e_1_3_2_1_2_1","volume-title":"15th Annual Conference of the European Institute for Computer Antivirus Research (EICAR)","author":"Bayer U.","year":"2006","unstructured":"U. Bayer , C. Kruegel , and E. Kirda . TTAnalyze: A tool for analyzing malware . In 15th Annual Conference of the European Institute for Computer Antivirus Research (EICAR) , 2006 . U. Bayer, C. Kruegel, and E. Kirda. TTAnalyze: A tool for analyzing malware. In 15th Annual Conference of the European Institute for Computer Antivirus Research (EICAR), 2006."},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the 20th USENIX Security Symposium","author":"Caballero J.","year":"2011","unstructured":"J. Caballero , C. Grier , C. Kreibich , and V. Paxson . Measuring Pay-per-Install: The Commoditization of Malware Distribution . In Proceedings of the 20th USENIX Security Symposium , San Francisco, CA, USA , August 2011 . J. Caballero, C. Grier, C. Kreibich, and V. Paxson. Measuring Pay-per-Install: The Commoditization of Malware Distribution. In Proceedings of the 20th USENIX Security Symposium, San Francisco, CA, USA, August 2011."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653737"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920284"},{"key":"e_1_3_2_1_6_1","volume-title":"http:\/\/cbl.abuseat.org","author":"Composite Blocking List CBL.","year":"2003","unstructured":"CBL. Composite Blocking List . http:\/\/cbl.abuseat.org , 2003 . CBL. Composite Blocking List. http:\/\/cbl.abuseat.org, 2003."},{"key":"e_1_3_2_1_8_1","first-page":"177","volume-title":"Proceedings of the 38th Conference on Dependable Systems and Networks (DSN)","author":"Chen X.","year":"2008","unstructured":"X. Chen , J. Andersen , Z. Mao , M. Bailey , and J. Nazario . Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware . In Proceedings of the 38th Conference on Dependable Systems and Networks (DSN) , pages 177 -- 186 . IEEE, 2008 . X. Chen, J. Andersen, Z. Mao, M. Bailey, and J. Nazario. Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware. In Proceedings of the 38th Conference on Dependable Systems and Networks (DSN), pages 177--186. IEEE, 2008."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/CATCH.2009.26"},{"key":"e_1_3_2_1_11_1","first-page":"2","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Jiang X.","unstructured":"X. Jiang and D. Xu . Collapsar: A VM-based architecture for network attack detention center . In Proceedings of the 13th USENIX Security Symposium , page 2 . USENIX Association, 2004. X. Jiang and D. Xu. Collapsar: A VM-based architecture for network attack detention center. In Proceedings of the 13th USENIX Security Symposium, page 2. USENIX Association, 2004."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/1558977.1558997"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455774"},{"key":"e_1_3_2_1_14_1","unstructured":"T. Kerremans and B. Verstricht. Trinity Rescue Kit. http:\/\/trinityhome.org.  T. Kerremans and B. Verstricht. Trinity Rescue Kit. http:\/\/trinityhome.org."},{"key":"e_1_3_2_1_15_1","volume-title":"SOCKS. In Proceedings of the 3rd USENIX Security Symposium. USENIX Association","author":"Koblas D.","year":"1992","unstructured":"D. Koblas . SOCKS. In Proceedings of the 3rd USENIX Security Symposium. USENIX Association , September 1992 . D. Koblas. SOCKS. In Proceedings of the 3rd USENIX Security Symposium. USENIX Association, September 1992."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/354871.354874"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.10"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/1387709.1387710"},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of the Second USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET)","author":"Kreibich C.","year":"2009","unstructured":"C. Kreibich , C. Kanich , K. Levchenko , B. Enright , G. M. Voelker , V. Paxson , and S. Savage . Spamcraft: An inside look at spam campaign orchestration . In Proceedings of the Second USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET) , Boston, USA , April 2009 . C. Kreibich, C. Kanich, K. Levchenko, B. Enright, G. M. Voelker, V. Paxson, and S. Savage. Spamcraft: An inside look at spam campaign orchestration. In Proceedings of the Second USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET), Boston, USA, April 2009."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1355734.1355746"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/2026647.2026661"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2010.5655108"},{"key":"e_1_3_2_1_23_1","unstructured":"Norman ASA. Norman SandBox. http:\/\/www.norman.com\/security_center\/security_tools\/.  Norman ASA. Norman SandBox. http:\/\/www.norman.com\/security_center\/security_tools\/."},{"key":"e_1_3_2_1_24_1","first-page":"31","volume-title":"Bro: A System for Detecting Network Intruders in Real-Time. Proceedings of the 7th USENIX Security Symposium","author":"Paxson V.","year":"1998","unstructured":"V. Paxson . Bro: A System for Detecting Network Intruders in Real-Time. Proceedings of the 7th USENIX Security Symposium , pages 31 -- 51 , 1998 . V. Paxson. Bro: A System for Detecting Network Intruders in Real-Time. Proceedings of the 7th USENIX Security Symposium, pages 31--51, 1998."},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the 17th Annual Network and Distributed System Security Symposium(NDSS)","author":"Pitsillidis A.","year":"2010","unstructured":"A. Pitsillidis , K. Levchenko , C. Kreibich , C. Kanich , G. Voelker , V. Paxson , N. Weaver , and S. Savage . Botnet Judo: Fighting Spam with Itself . In Proceedings of the 17th Annual Network and Distributed System Security Symposium(NDSS) , San Diego, CA, USA , March 2010 . A. Pitsillidis, K. Levchenko, C. Kreibich, C. Kanich, G. Voelker, V. Paxson, N. Weaver, and S. Savage. Botnet Judo: Fighting Spam with Itself . In Proceedings of the 17th Annual Network and Distributed System Security Symposium(NDSS), San Diego, CA, USA, March 2010."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"J. Postel. Simple Mail Transfer Protocol. RFC 1982 821 10.17487\/RFC0821","DOI":"10.17487\/rfc0821"},{"key":"e_1_3_2_1_27_1","volume-title":"http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_respons%e\/whitepapers\/W32_Waledac.pdf","author":"Tenebro G.","year":"2009","unstructured":"G. Tenebro . W32. Waledac Threat Analysis . http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_respons%e\/whitepapers\/W32_Waledac.pdf , 2009 . G. Tenebro. W32.Waledac Threat Analysis. http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_respons%e\/whitepapers\/W32_Waledac.pdf, 2009."},{"key":"e_1_3_2_1_28_1","unstructured":"N. Villeneuve. Koobface: Inside a Crimeware Network. http:\/\/www.infowar-monitor.net\/reports\/iwm-koobface.pdf November 2010.  N. Villeneuve. Koobface: Inside a Crimeware Network. http:\/\/www.infowar-monitor.net\/reports\/iwm-koobface.pdf November 2010."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095809.1095825"},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS)","author":"Wang Y.","year":"2006","unstructured":"Y. Wang , D. Beck , X. Jiang , and R. Roussev . Automated Web Patrol with Strider Honeymonkeys: Finding Web Sites that Exploit Browser Vulnerabilities . In Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS) , San Diego, CA, USA , March 2006 . Y. Wang, D. Beck, X. Jiang, and R. Roussev. Automated Web Patrol with Strider Honeymonkeys: Finding Web Sites that Exploit Browser Vulnerabilities. In Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, March 2006."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.45"}],"event":{"name":"IMC '11: Internet Measurement Conference","sponsor":["SIGMETRICS ACM Special Interest Group on Measurement and Evaluation","SIGCOMM ACM Special Interest Group on Data Communication","USENIX Assoc USENIX Assoc"],"location":"Berlin Germany","acronym":"IMC '11"},"container-title":["Proceedings of the 2011 ACM SIGCOMM conference on Internet measurement conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2068816.2068854","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2068816.2068854","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:54:24Z","timestamp":1750240464000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2068816.2068854"}},"subtitle":["practical containment for measuring modern malware systems"],"short-title":[],"issued":{"date-parts":[[2011,11,2]]},"references-count":29,"alternative-id":["10.1145\/2068816.2068854","10.1145\/2068816"],"URL":"https:\/\/doi.org\/10.1145\/2068816.2068854","relation":{},"subject":[],"published":{"date-parts":[[2011,11,2]]},"assertion":[{"value":"2011-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}