{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,21]],"date-time":"2026-06-21T12:57:58Z","timestamp":1782046678193,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":28,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,3,24]],"date-time":"2014-03-24T00:00:00Z","timestamp":1395619200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N000140911042"],"award-info":[{"award-number":["N000140911042"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Secure Business Austria"},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF0910553"],"award-info":[{"award-number":["W911NF0910553"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0845559, CNS-0905537"],"award-info":[{"award-number":["CNS-0845559, CNS-0905537"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,3,24]]},"DOI":"10.1145\/2554850.2554896","type":"proceedings-article","created":{"date-parts":[[2014,7,22]],"date-time":"2014-07-22T15:08:30Z","timestamp":1406041710000},"page":"1657-1662","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["Extracting probable command and control signatures for detecting botnets"],"prefix":"10.1145","author":[{"given":"Ali","family":"Zand","sequence":"first","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xifeng","family":"Yan","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2014,3,24]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/CATCH.2009.40"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420969"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2007.1000"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1370905.1370911"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/3091622.3091637"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920283"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4757-3982-4","volume-title":"Entropy and information theory","author":"Gray R. M.","year":"1990","unstructured":"R. M. Gray . Entropy and information theory . Springer-Verlag New York, Inc. , New York, NY, USA , 1990 . R. M. Gray. Entropy and information theory. Springer-Verlag New York, Inc., New York, NY, USA, 1990."},{"key":"e_1_3_2_1_8_1","first-page":"139","volume-title":"SS'08: Proceedings of the 17th Conference on Security symposium","author":"Gu G.","year":"2008","unstructured":"G. Gu , R. Perdisci , J. Zhang , and W. Lee . BotMiner: clustering analysis of network traffic for protocol- and structure-independent botnet detection . In SS'08: Proceedings of the 17th Conference on Security symposium , pages 139 -- 154 , Berkeley, CA, USA , 2008 . USENIX Association. G. Gu, R. Perdisci, J. Zhang, and W. Lee. BotMiner: clustering analysis of network traffic for protocol- and structure-independent botnet detection. In SS'08: Proceedings of the 17th Conference on Security symposium, pages 139--154, Berkeley, CA, USA, 2008. USENIX Association."},{"key":"e_1_3_2_1_9_1","first-page":"1","volume-title":"SS'07: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium","author":"Gu G.","year":"2007","unstructured":"G. Gu , P. Porras , V. Yegneswaran , M. Fong , and W. Lee . BotHunter: detecting malware infection through IDS-driven dialog correlation . In SS'07: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium , pages 1 -- 16 , Berkeley, CA, USA , 2007 . G. Gu, P. Porras, V. Yegneswaran, M. Fong, and W. Lee. BotHunter: detecting malware infection through IDS-driven dialog correlation. In SS'07: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, pages 1--16, Berkeley, CA, USA, 2007."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.30"},{"key":"e_1_3_2_1_11_1","volume-title":"BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In In Proceedings of 15th Annual Network and Distributed System Security Symposium (NDSS 2008)","author":"Gu G.","year":"2008","unstructured":"G. Gu , J. Zhang , and W. Lee . BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In In Proceedings of 15th Annual Network and Distributed System Security Symposium (NDSS 2008) , 2008 . G. Gu, J. Zhang, and W. Lee. BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic. In In Proceedings of 15th Annual Network and Distributed System Security Symposium (NDSS 2008), 2008."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-006-0038-2"},{"key":"e_1_3_2_1_13_1","first-page":"19","volume-title":"SSYM'04: Proceedings of the 13th conference on USENIX Security Symposium","author":"Kim H.-A.","year":"2004","unstructured":"H.-A. Kim and B. Karp . Autograph: toward automated, distributed worm signature detection . In SSYM'04: Proceedings of the 13th conference on USENIX Security Symposium , pages 19 -- 19 , Berkeley, CA, USA , 2004 . USENIX Association. H.-A. Kim and B. Karp. Autograph: toward automated, distributed worm signature detection. In SSYM'04: Proceedings of the 13th conference on USENIX Security Symposium, pages 19--19, Berkeley, CA, USA, 2004. USENIX Association."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/1778902.1778912"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/972374.972384"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference, 4","author":"Kruegel C.","year":"2006","unstructured":"C. Kruegel , E. Kirda , and U. Bayer . Ttanalyze: A tool for analyzing malware . In Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference, 4 2006 . Best Paper Award. C. Kruegel, E. Kirda, and U. Bayer. Ttanalyze: A tool for analyzing malware. In Proceedings of the 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference, 4 2006. Best Paper Award."},{"key":"e_1_3_2_1_17_1","first-page":"967","volume-title":"In 2nd IEEE LCN Workshop on Network Security (WoNS '2006)","author":"Livadas C.","year":"2006","unstructured":"C. Livadas , R. Walsh , D. Lapsley , and W. T. Strayer . Using Machine Learning Techniques to Identify Botnet Traffic . In In 2nd IEEE LCN Workshop on Network Security (WoNS '2006) , pages 967 -- 974 , 2006 . C. Livadas, R. Walsh, D. Lapsley, and W. T. Strayer. Using Machine Learning Techniques to Identify Botnet Traffic. In In 2nd IEEE LCN Workshop on Network Security (WoNS '2006), pages 967--974, 2006."},{"key":"e_1_3_2_1_18_1","volume-title":"Machine Learning","author":"Mitchell T. M.","year":"1997","unstructured":"T. M. Mitchell . Machine Learning . McGraw-Hill, Inc. , New York, NY, USA , 1997 . T. M. Mitchell. Machine Learning. McGraw-Hill, Inc., New York, NY, USA, 1997."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.15"},{"key":"e_1_3_2_1_20_1","volume-title":"Behavioral clustering of http-based malware and signature generation using malicious network traces. of the 7th USENIX conference on","author":"Perdisci R.","year":"2010","unstructured":"R. Perdisci and W. Lee . Behavioral clustering of http-based malware and signature generation using malicious network traces. of the 7th USENIX conference on , 2010 . R. Perdisci and W. Lee. Behavioral clustering of http-based malware and signature generation using malicious network traces. of the 7th USENIX conference on, 2010."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251254.1251258"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2006.322100"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01206331"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.5555\/1813084.1813104"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/290941.290956"},{"key":"e_1_3_2_1_27_1","first-page":"321","volume-title":"NSDI'09: Proceedings of the 6th USENIX symposium on Networked systems design and implementation","author":"Zhao Y.","year":"2009","unstructured":"Y. Zhao , Y. Xie , F. Yu , Q. Ke , Y. Yu , Y. Chen , and E. Gillum . BotGraph: large scale spamming botnet detection . In NSDI'09: Proceedings of the 6th USENIX symposium on Networked systems design and implementation , pages 321 -- 334 , Berkeley, CA, USA , 2009 . USENIX Association. Y. Zhao, Y. Xie, F. Yu, Q. Ke, Y. Yu, Y. Chen, and E. Gillum. BotGraph: large scale spamming botnet detection. In NSDI'09: Proceedings of the 6th USENIX symposium on Networked systems design and implementation, pages 321--334, Berkeley, CA, USA, 2009. USENIX Association."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456377.1456394"}],"event":{"name":"SAC 2014: Symposium on Applied Computing","location":"Gyeongju Republic of Korea","acronym":"SAC 2014","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"]},"container-title":["Proceedings of the 29th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2554850.2554896","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2554850.2554896","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:18:16Z","timestamp":1750234696000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2554850.2554896"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,3,24]]},"references-count":28,"alternative-id":["10.1145\/2554850.2554896","10.1145\/2554850"],"URL":"https:\/\/doi.org\/10.1145\/2554850.2554896","relation":{},"subject":[],"published":{"date-parts":[[2014,3,24]]},"assertion":[{"value":"2014-03-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}