{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T07:27:25Z","timestamp":1780471645511,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,12,3]],"date-time":"2012-12-03T00:00:00Z","timestamp":1354492800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["257007"],"award-info":[{"award-number":["257007"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-1116777"],"award-info":[{"award-number":["CNS-1116777"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,12,3]]},"DOI":"10.1145\/2420950.2420969","type":"proceedings-article","created":{"date-parts":[[2012,12,19]],"date-time":"2012-12-19T14:12:22Z","timestamp":1355926342000},"page":"129-138","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":191,"title":["Disclosure"],"prefix":"10.1145","author":[{"given":"Leyla","family":"Bilge","sequence":"first","affiliation":[{"name":"Symantec Research Labs"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"Eurecom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"UC Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,12,3]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"http:\/\/www.alexa.com\/topsites\/","author":"Information Company Alexa Web","year":"2009","unstructured":"Alexa Web Information Company . http:\/\/www.alexa.com\/topsites\/ , 2009 . Alexa Web Information Company. http:\/\/www.alexa.com\/topsites\/, 2009."},{"key":"e_1_3_2_1_2_1","unstructured":"EXPOSURE\n  : Exposing Malicious Domains. http:\/\/exposure.iseclab.org\/ 2011.  EXPOSURE: Exposing Malicious Domains. http:\/\/exposure.iseclab.org\/ 2011."},{"key":"e_1_3_2_1_3_1","unstructured":"FIRE\n  : FInding RoguE Networks. http:\/\/www.maliciousnetworks.org\/ 2011.  FIRE: FInding RoguE Networks. http:\/\/www.maliciousnetworks.org\/ 2011."},{"key":"e_1_3_2_1_4_1","volume-title":"http:\/\/www.google.com\/safebrowsing\/diagnostic?site=AS:as_number","author":"Browsing Google Safe","year":"2011","unstructured":"Google Safe Browsing . http:\/\/www.google.com\/safebrowsing\/diagnostic?site=AS:as_number , 2011 . Google Safe Browsing. http:\/\/www.google.com\/safebrowsing\/diagnostic?site=AS:as_number, 2011."},{"key":"e_1_3_2_1_5_1","volume-title":"18th Annual Network and Distributed System Security Symposium (NDSS'11)","author":"Bilge L.","year":"2011","unstructured":"L. Bilge , E. Kirda , C. Kruegel , and M. Balduzzi . Exposure: Finding malicious domains using passive dns analysis . In 18th Annual Network and Distributed System Security Symposium (NDSS'11) , 2011 . L. Bilge, E. Kirda, C. Kruegel, and M. Balduzzi. Exposure: Finding malicious domains using passive dns analysis. In 18th Annual Network and Distributed System Security Symposium (NDSS'11), 2011."},{"key":"e_1_3_2_1_6_1","volume-title":"Usenix Steps to Reduce Unwanted Traffic on the Internet (SRUTI)","author":"Binkley J.","year":"2006","unstructured":"J. Binkley and S. Singh . An Algorithm for Anomaly-based Botnet Detection . In Usenix Steps to Reduce Unwanted Traffic on the Internet (SRUTI) , 2006 . J. Binkley and S. Singh. An Algorithm for Anomaly-based Botnet Detection. In Usenix Steps to Reduce Unwanted Traffic on the Internet (SRUTI), 2006."},{"key":"e_1_3_2_1_7_1","unstructured":"G. E. P.\n      Box G. M.\n      Jenkins and \n      G.\n      Reinsel\n  . \n  Time Series Analysis: Forecasting and Control\n  . In 3rd eddition \n  Upper Saddle River NJ\n  : \n  Prentice-Hall 1994\n  .   G. E. P. Box G. M. Jenkins and G. Reinsel. Time Series Analysis: Forecasting and Control. In 3rd eddition Upper Saddle River NJ: Prentice-Hall 1994."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644897"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177101"},{"key":"e_1_3_2_1_10_1","volume-title":"Cisco systems netflow services export version 9","author":"Claise B.","year":"2004","unstructured":"B. Claise . Cisco systems netflow services export version 9 , 2004 . B. Claise. Cisco systems netflow services export version 9, 2004."},{"key":"e_1_3_2_1_11_1","first-page":"39","volume-title":"1st Workshop on Steps to Reducing Unwanted Traffic on the Internet","author":"Cooke E.","year":"2005","unstructured":"E. Cooke , F. Jahanian , and D. McPherson . The Zombie Roundup: Understanding, Detecting, and Disrupting Botnets . In 1st Workshop on Steps to Reducing Unwanted Traffic on the Internet , pages 39 -- 44 , 2005 . E. Cooke, F. Jahanian, and D. McPherson. The Zombie Roundup: Understanding, Detecting, and Disrupting Botnets. In 1st Workshop on Steps to Reducing Unwanted Traffic on the Internet, pages 39--44, 2005."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/345662"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352664.1352675"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/2008780.2008782"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/11555827_19"},{"key":"e_1_3_2_1_16_1","volume-title":"Workshop on Hot Topics in Understanding Botnets","author":"Goebel J.","year":"2007","unstructured":"J. Goebel and T. Holz . Rishi: Identify bot contaminated hosts by IRC nickname evaluation . In Workshop on Hot Topics in Understanding Botnets , 2007 . J. Goebel and T. Holz. Rishi: Identify bot contaminated hosts by IRC nickname evaluation. In Workshop on Hot Topics in Understanding Botnets, 2007."},{"key":"e_1_3_2_1_17_1","volume-title":"BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnet Detection. In Usenix Security Symposium","author":"Gu G.","year":"2008","unstructured":"G. Gu , R. Perdisci , J. Zhang , and W. Lee . BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnet Detection. In Usenix Security Symposium , 2008 . G. Gu, R. Perdisci, J. Zhang, and W. Lee. BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnet Detection. In Usenix Security Symposium, 2008."},{"key":"e_1_3_2_1_18_1","volume-title":"BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation. In 16th Usenix Security Symposium","author":"Gu G.","year":"2007","unstructured":"G. Gu , P. Porras , V. Yegneswaran , M. Fong , and W. Lee . BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation. In 16th Usenix Security Symposium , 2007 . G. Gu, P. Porras, V. Yegneswaran, M. Fong, and W. Lee. BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation. In 16th Usenix Security Symposium, 2007."},{"key":"e_1_3_2_1_19_1","volume-title":"BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In 15th Annual Network and Distributed System Security Symposium (NDSS)","author":"Gu G.","year":"2008","unstructured":"G. Gu , J. Zhang , and W. Lee . BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In 15th Annual Network and Distributed System Security Symposium (NDSS) , 2008 . G. Gu, J. Zhang, and W. Lee. BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In 15th Annual Network and Distributed System Security Symposium (NDSS), 2008."},{"key":"e_1_3_2_1_20_1","volume-title":"Studying Spamming Botnets Using Botlab. In 6th Usenix Symposium on Networked Systems Design and Implementation (NSDI)","author":"John J.","year":"2009","unstructured":"J. John , A. Moshchuk , S. Gribble , and A. Krishnamurthy . Studying Spamming Botnets Using Botlab. In 6th Usenix Symposium on Networked Systems Design and Implementation (NSDI) , 2009 . J. John, A. Moshchuk, S. Gribble, and A. Krishnamurthy. Studying Spamming Botnets Using Botlab. In 6th Usenix Symposium on Networked Systems Design and Implementation (NSDI), 2009."},{"key":"e_1_3_2_1_21_1","volume-title":"Wide-scale Botnet Detection and Characterization. In Usenix Workshop on Hot Topics in Understanding Botnets","author":"Karasaridis A.","year":"2007","unstructured":"A. Karasaridis , B. Rexroad , and D. Hoeflin . Wide-scale Botnet Detection and Characterization. In Usenix Workshop on Hot Topics in Understanding Botnets , 2007 . A. Karasaridis, B. Rexroad, and D. Hoeflin. Wide-scale Botnet Detection and Characterization. In Usenix Workshop on Hot Topics in Understanding Botnets, 2007."},{"key":"e_1_3_2_1_22_1","volume-title":"The Art of Computer Programming","author":"Knuth D. E.","year":"1969","unstructured":"D. E. Knuth . Seminumerical algorithms . In The Art of Computer Programming , Volume 2 , Addison Wesley , 1969 . D. E. Knuth. Seminumerical algorithms. In The Art of Computer Programming, Volume 2, Addison Wesley, 1969."},{"key":"e_1_3_2_1_23_1","first-page":"18","volume":"2","author":"Liaw A.","year":"2002","unstructured":"A. Liaw and M. Wiener . Classification and regression by randomforest. In R News , volume 2\/3 , page 18 , 2002 . A. Liaw and M. Wiener. Classification and regression by randomforest. In R News, volume 2\/3, page 18, 2002.","journal-title":"Classification and regression by randomforest. In R News"},{"key":"e_1_3_2_1_24_1","volume-title":"the 2nd IEEE LCN Workshop on Network Security (WoNS'2006)","author":"Livadas C.","year":"2006","unstructured":"C. Livadas , R. Walsh , D. Lapsley , and W. T. Strayer . Using machine learning techniques to identify botnet traffic . In the 2nd IEEE LCN Workshop on Network Security (WoNS'2006) , 2006 . C. Livadas, R. Walsh, D. Lapsley, and W. T. Strayer. Using machine learning techniques to identify botnet traffic. In the 2nd IEEE LCN Workshop on Network Security (WoNS'2006), 2006."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177102"},{"key":"e_1_3_2_1_26_1","volume-title":"Programs for machine learning","author":"Quinlan J.","year":"1993","unstructured":"J. Quinlan . C4.5 : Programs for machine learning . In Morgan Kaufmann Publishers , 1993 . J. Quinlan. C4.5: Programs for machine learning. In Morgan Kaufmann Publishers, 1993."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177086"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1151659.1159947"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_11"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87357-0_2"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.29"},{"key":"e_1_3_2_1_32_1","volume-title":"Detecting Botnets with Tight Command and Control. In 31st IEEE Conference on Local Computer Networks (LCN)","author":"Strayer W.","year":"2006","unstructured":"W. Strayer , R. Walsh , C. Livadas , and D. Lapsley . Detecting Botnets with Tight Command and Control. In 31st IEEE Conference on Local Computer Networks (LCN) , 2006 . W. Strayer, R. Walsh, C. Livadas, and D. Lapsley. Detecting Botnets with Tight Command and Control. In 31st IEEE Conference on Local Computer Networks (LCN), 2006."},{"key":"e_1_3_2_1_33_1","volume-title":"Pattern Recognition","author":"Theodoridis S.","year":"2009","unstructured":"S. Theodoridis and K. Koutroumbas . Pattern Recognition . Academic Press , 2009 . S. Theodoridis and K. Koutroumbas. Pattern Recognition. Academic Press, 2009."},{"key":"e_1_3_2_1_34_1","volume-title":"SIG SIDAR Graduierten-Workshop uber Reaktive Sicherheit (SPRING'06)","author":"Wagner A.","year":"2006","unstructured":"A. Wagner and B. Plattner . Entropy based worm and anomaly detection in fast ip networks . In SIG SIDAR Graduierten-Workshop uber Reaktive Sicherheit (SPRING'06) , 2006 . A. Wagner and B. Plattner. Entropy based worm and anomaly detection in fast ip networks. In SIG SIDAR Graduierten-Workshop uber Reaktive Sicherheit (SPRING'06), 2006."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/1813084.1813104"}],"event":{"name":"ACSAC '12: Annual Computer Security Applications Conference","location":"Orlando Florida USA","acronym":"ACSAC '12","sponsor":["ACSA Applied Computing Security Assoc"]},"container-title":["Proceedings of the 28th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420969","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2420950.2420969","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:33:57Z","timestamp":1750239237000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420969"}},"subtitle":["detecting botnet command and control servers through large-scale NetFlow analysis"],"short-title":[],"issued":{"date-parts":[[2012,12,3]]},"references-count":35,"alternative-id":["10.1145\/2420950.2420969","10.1145\/2420950"],"URL":"https:\/\/doi.org\/10.1145\/2420950.2420969","relation":{},"subject":[],"published":{"date-parts":[[2012,12,3]]},"assertion":[{"value":"2012-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}