{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T03:47:34Z","timestamp":1772164054335,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2013,8,27]],"date-time":"2013-08-27T00:00:00Z","timestamp":1377561600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2013,8,27]]},"DOI":"10.1145\/2486001.2486018","type":"proceedings-article","created":{"date-parts":[[2013,8,13]],"date-time":"2013-08-13T08:31:21Z","timestamp":1376382681000},"page":"267-278","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":44,"title":["An empirical reexamination of global DNS behavior"],"prefix":"10.1145","author":[{"given":"Hongyu","family":"Gao","sequence":"first","affiliation":[{"name":"Northwestern University, Evanston, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Chen","sequence":"additional","affiliation":[{"name":"Northwestern University, Evanston, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Phillip","family":"Porras","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shalini","family":"Ghosh","sequence":"additional","affiliation":[{"name":"SRI International, Menlo Park, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Jiang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haixin","family":"Duan","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,8,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Malware Domain Block List. http:\/\/www.malwaredomains.com\/.  Malware Domain Block List. http:\/\/www.malwaredomains.com\/."},{"key":"e_1_3_2_1_2_1","unstructured":"McAfee SiteAdvisor. http:\/\/www.siteadvisor.com\/.  McAfee SiteAdvisor. http:\/\/www.siteadvisor.com\/."},{"key":"e_1_3_2_1_3_1","unstructured":"PhishTank. http:\/\/www.phishtank.com\/.  PhishTank. http:\/\/www.phishtank.com\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Safe Browsing Tool | WOT (Web of Trust). http:\/\/www.mywot.com\/.  Safe Browsing Tool | WOT (Web of Trust). http:\/\/www.mywot.com\/."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12365-8_1"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879144"},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the 19th USENIX Security Symposium","author":"Antonakakis M.","year":"2010","unstructured":"M. Antonakakis , R. Perdisci , D. Dagon , W. Lee , and N. Feamster . Building a dynamic reputation system for DNS . In Proceedings of the 19th USENIX Security Symposium , 2010 . M. Antonakakis, R. Perdisci, D. Dagon, W. Lee, and N. Feamster. Building a dynamic reputation system for DNS. In Proceedings of the 19th USENIX Security Symposium, 2010."},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Antonakakis M.","year":"2011","unstructured":"M. Antonakakis , R. Perdisci , W. Lee , N. Vasiloglou , and D. Dagon . Detecting malware domains at the upper DNS hierarchy . In Proceedings of the USENIX Security Symposium , 2011 . M. Antonakakis, R. Perdisci, W. Lee, N. Vasiloglou, and D. Dagon. Detecting malware domains at the upper DNS hierarchy. In Proceedings of the USENIX Security Symposium, 2011."},{"key":"e_1_3_2_1_9_1","volume-title":"USENIX Security Symposium","author":"Antonakakis M.","year":"2012","unstructured":"M. Antonakakis , R. Perdisci , Y. Nadji , N. Vasiloglou , S. Abu-Nimeh , W. Lee , and D. Dagon . From throw-away traffic to bots: Detecting the rise of dga-based malware . In USENIX Security Symposium , 2012 . M. Antonakakis, R. Perdisci, Y. Nadji, N. Vasiloglou, S. Abu-Nimeh, W. Lee, and D. Dagon. From throw-away traffic to bots: Detecting the rise of dga-based malware. In USENIX Security Symposium, 2012."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOMW.2011.5928919"},{"key":"e_1_3_2_1_11_1","volume-title":"18th Annual Network and Distributed System Security Symposium","author":"Bilge L.","year":"2011","unstructured":"L. Bilge , E. Kirda , C. Kruegel , and M. Balduzzi . EXPOSURE : Finding malicious domains using passive DNS analysis . In 18th Annual Network and Distributed System Security Symposium , San Diego, 02 2011 . L. Bilge, E. Kirda, C. Kruegel, and M. Balduzzi. EXPOSURE : Finding malicious domains using passive DNS analysis. In 18th Annual Network and Distributed System Security Symposium, San Diego, 02 2011."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2001.965864"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1452335.1452341"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/144179.144301"},{"key":"e_1_3_2_1_15_1","unstructured":"C. J. Dietrich. Feederbot - a bot using DNS as carrier for its C&C. http:\/\/blog.cj2s.de\/archives\/28-Feederbot-a-bot-using-DNS-as-carrier-fo%r-its-CC.html 2011.  C. J. Dietrich. Feederbot - a bot using DNS as carrier for its C&C. http:\/\/blog.cj2s.de\/archives\/28-Feederbot-a-bot-using-DNS-as-carrier-fo%r-its-CC.html 2011."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068842"},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of Network and Distributed Security Symposium","author":"Holz T.","year":"2008","unstructured":"T. Holz , C. Gorecki , K. Rieck , and F. C. Freiling . Measuring and detecting fast-flux service networks . In Proceedings of Network and Distributed Security Symposium , 2008 . T. Holz, C. Gorecki, K. Rieck, and F. C. Freiling. Measuring and detecting fast-flux service networks. In Proceedings of Network and Distributed Security Symposium, 2008."},{"key":"e_1_3_2_1_18_1","unstructured":"Internet Systems Consortium. Welcome to Security Information Exchange (SIE) Portal. https:\/\/sie.isc.org.  Internet Systems Consortium. Welcome to Security Information Exchange (SIE) Portal. https:\/\/sie.isc.org."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028838"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2002.803905"},{"key":"e_1_3_2_1_21_1","volume-title":"BlackHat USA","author":"Kaminsky D.","year":"2008","unstructured":"D. Kaminsky . It is the end of the cache as we know it . BlackHat USA , 2008 . D. Kaminsky. It is the end of the cache as we know it. BlackHat USA, 2008."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00975-4_22"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382267"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36516-4_15"},{"key":"e_1_3_2_1_25_1","unstructured":"Malware Domain List. Malware Domain List. www.malwaredomainlist.com.  Malware Domain List. Malware Domain List. www.malwaredomainlist.com."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5555\/1394399"},{"key":"e_1_3_2_1_27_1","unstructured":"MaxMind Inc. http:\/\/www.maxmind.com\/.  MaxMind Inc. http:\/\/www.maxmind.com\/."},{"key":"e_1_3_2_1_28_1","unstructured":"P. Mockapetris. Domain Names--Concepts and Facilities RFC 1034. http:\/\/www.ietf.org\/rfc\/rfc1034.txt.   P. Mockapetris. Domain Names--Concepts and Facilities RFC 1034. http:\/\/www.ietf.org\/rfc\/rfc1034.txt."},{"key":"e_1_3_2_1_29_1","unstructured":"P. Mockapetris. Domain Names--Concepts and Facilities RFC 882. http:\/\/www.ietf.org\/rfc\/rfc882.txt.   P. Mockapetris. Domain Names--Concepts and Facilities RFC 882. http:\/\/www.ietf.org\/rfc\/rfc882.txt."},{"key":"e_1_3_2_1_30_1","unstructured":"P. Mockapetris. Domain Names--Implementation and Specification RFC 1035. http:\/\/www.ietf.org\/rfc\/rfc1035.txt.   P. Mockapetris. Domain Names--Implementation and Specification RFC 1035. http:\/\/www.ietf.org\/rfc\/rfc1035.txt."},{"key":"e_1_3_2_1_31_1","unstructured":"P. Mockapetris. Domain Names--Implementation and Specification RFC 883. http:\/\/www.ietf.org\/rfc\/rfc883.txt.   P. Mockapetris. Domain Names--Implementation and Specification RFC 883. http:\/\/www.ietf.org\/rfc\/rfc883.txt."},{"key":"e_1_3_2_1_32_1","unstructured":"C. Mullaney. Morto worm sets a (DNS) record. http:\/\/www.symantec.com\/connect\/blogs\/morto-worm-sets-dns-record 2011.  C. Mullaney. Morto worm sets a (DNS) record. http:\/\/www.symantec.com\/connect\/blogs\/morto-worm-sets-dns-record 2011."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28537-0_21"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2398776.2398831"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028790"},{"key":"e_1_3_2_1_36_1","first-page":"727","volume-title":"Proceedings of the 17th International Conference on Machine Learning","volume":"1","author":"Pelleg D.","year":"2000","unstructured":"D. Pelleg , A. Moore , : Extending K-means with efficient estimation of the number of clusters . In Proceedings of the 17th International Conference on Machine Learning , volume 1 , pages 727 -- 734 , 2000 . D. Pelleg, A. Moore, et al. X-means: Extending K-means with efficient estimation of the number of clusters. In Proceedings of the 17th International Conference on Machine Learning, volume 1, pages 727--734, 2000."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.36"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1852096.1852097"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of LEET","author":"Sato K.","year":"2010","unstructured":"K. Sato , keisuke Ishibashi, T. Toyono , and N. Miyake . Extending black domain name list by using co-occurrence relation between DNS queries . In Proceedings of LEET , 2010 . K. Sato, keisuke Ishibashi, T. Toyono, and N. Miyake. Extending black domain name list by using co-occurrence relation between DNS queries. In Proceedings of LEET, 2010."},{"key":"e_1_3_2_1_40_1","volume-title":"Securing and Trusting Internet Names","author":"Spring J.","year":"2011","unstructured":"J. Spring , L. Metcalf , and E. Stoner . Correlating domain registrations and DNS first activity in general and for malware . In Securing and Trusting Internet Names , 2011 . J. Spring, L. Metcalf, and E. Stoner. Correlating domain registrations and DNS first activity in general and for malware. In Securing and Trusting Internet Names, 2011."},{"key":"e_1_3_2_1_41_1","volume-title":"DNS cache poisoning--the next generation","author":"Stewart J.","year":"2003","unstructured":"J. Stewart . DNS cache poisoning--the next generation , 2003 . J. Stewart. DNS cache poisoning--the next generation, 2003."},{"key":"e_1_3_2_1_42_1","volume-title":"Passive and Active Network Measurement Workshop (PAM)","author":"Wessels D.","year":"2003","unstructured":"D. Wessels and M. Fomenkov . Wow, That's a lot of packets . In Passive and Active Network Measurement Workshop (PAM) , San Diego, CA , Apr 2003 . D. Wessels and M. Fomenkov. Wow, That's a lot of packets. In Passive and Active Network Measurement Workshop (PAM), San Diego, CA, Apr 2003."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24668-8_15"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879148"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of SecureComm","author":"Yadav S.","year":"2011","unstructured":"S. Yadav and A. N. Reddy . Winning with DNS failures: Strategies for faster botnet detection . In Proceedings of SecureComm , 2011 . S. Yadav and A. N. Reddy. Winning with DNS failures: Strategies for faster botnet detection. In Proceedings of SecureComm, 2011."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-05284-2_11"}],"event":{"name":"SIGCOMM'13: ACM SIGCOMM 2013 Conference","location":"Hong Kong China","acronym":"SIGCOMM'13","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication"]},"container-title":["Proceedings of the ACM SIGCOMM 2013 conference on SIGCOMM"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2486001.2486018","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2486001.2486018","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:48:40Z","timestamp":1750222120000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2486001.2486018"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,8,27]]},"references-count":46,"alternative-id":["10.1145\/2486001.2486018","10.1145\/2486001"],"URL":"https:\/\/doi.org\/10.1145\/2486001.2486018","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/2534169.2486018","asserted-by":"object"}]},"subject":[],"published":{"date-parts":[[2013,8,27]]},"assertion":[{"value":"2013-08-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}