{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:17:27Z","timestamp":1750306647745,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":33,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,7,12]],"date-time":"2014-07-12T00:00:00Z","timestamp":1405123200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,7,12]]},"DOI":"10.1145\/2598394.2605435","type":"proceedings-article","created":{"date-parts":[[2014,7,11]],"date-time":"2014-07-11T12:10:42Z","timestamp":1405080642000},"page":"1253-1260","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["On botnet behaviour analysis using GP and C4.5"],"prefix":"10.1145","author":[{"given":"Fariba","family":"Haddadi","sequence":"first","affiliation":[{"name":"Dalhousie University, Halifax, NS, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dylan","family":"Runkel","sequence":"additional","affiliation":[{"name":"Dalhousie University, Halifax, NS, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"A. Nur","family":"Zincir-Heywood","sequence":"additional","affiliation":[{"name":"Dalhousie University, Halifax, NS, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Malcolm I.","family":"Heywood","sequence":"additional","affiliation":[{"name":"Dalhousie University, Halifax, NS, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,7,12]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Alexa. http:\/\/www.alexa.com\/topsites.  Alexa. http:\/\/www.alexa.com\/topsites."},{"key":"e_1_3_2_1_2_1","unstructured":"Conficker Domain List. http:\/\/net.cs.uni-bonn.de\/uploads\/media\/c_domains_april2009.zip.  Conficker Domain List. http:\/\/net.cs.uni-bonn.de\/uploads\/media\/c_domains_april2009.zip."},{"key":"e_1_3_2_1_3_1","unstructured":"DNS-BH-Malware Domain Blocklist. http:\/\/www.malwaredomains.com\/.  DNS-BH-Malware Domain Blocklist. http:\/\/www.malwaredomains.com\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Publicly available pcap files. http:\/\/www.netresec.com\/?page=PcapFiles.  Publicly available pcap files. http:\/\/www.netresec.com\/?page=PcapFiles."},{"key":"e_1_3_2_1_5_1","unstructured":"Softflowd. http:\/\/www.mindrot.org\/projects\/softflowd\/.  Softflowd. http:\/\/www.mindrot.org\/projects\/softflowd\/."},{"key":"e_1_3_2_1_6_1","unstructured":"Zeus tracker. https:\/\/zeustracker.abuse.ch\/.  Zeus tracker. https:\/\/zeustracker.abuse.ch\/."},{"key":"e_1_3_2_1_7_1","unstructured":"Zeus trojan analysis. https:\/\/labs.snort.org\/papers\/zeus.html.  Zeus trojan analysis. https:\/\/labs.snort.org\/papers\/zeus.html."},{"key":"e_1_3_2_1_8_1","volume-title":"Introduction to Machine Learning","author":"Alpaydin E.","year":"2004","unstructured":"E. Alpaydin . Introduction to Machine Learning . MIT Press , 2004 . E. Alpaydin. Introduction to Machine Learning. MIT Press, 2004."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1570256.1570358"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/4235.910462"},{"key":"e_1_3_2_1_11_1","volume-title":"USNIX Cyber Security Experimentation and Test (CSET) workshop","author":"Celik Z. B.","year":"2011","unstructured":"Z. B. Celik , J. Raghuram , G. Kesidis , and D. J. Miller . Salting public traces with attack traffic to test flow classifiers . In USNIX Cyber Security Experimentation and Test (CSET) workshop , 2011 . Z. B. Celik, J. Raghuram, G. Kesidis, and D. J. Miller. Salting public traces with attack traffic to test flow classifiers. In USNIX Cyber Security Experimentation and Test (CSET) workshop, 2011."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1162\/evco.2007.15.1.61"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10710-011-9151-4"},{"key":"e_1_3_2_1_14_1","first-page":"1","article-title":"Bottrack: tracking botnets using netflow and pagerank","volume":"6640","author":"Francois J.","year":"2011","unstructured":"J. Francois , S. Wang , R. State , and T. Engel . Bottrack: tracking botnets using netflow and pagerank . Networking , 6640 : 1 -- 14 , 2011 . J. Francois, S. Wang, R. State, and T. Engel. Bottrack: tracking botnets using netflow and pagerank. Networking, 6640:1--14, 2011.","journal-title":"Networking"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508701"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/WAINA.2014.19"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CEC.2013.6557886"},{"key":"e_1_3_2_1_18_1","volume-title":"February","author":"Haddadi F.","year":"2014","unstructured":"F. Haddadi and A. N. Zincir-Heywood . Data confirmation for botnet traffic analysis. https:\/\/www.cs.dal.ca\/research\/techreports\/cs-2014-01 , February 2014 . F. Haddadi and A. N. Zincir-Heywood. Data confirmation for botnet traffic analysis. https:\/\/www.cs.dal.ca\/research\/techreports\/cs-2014-01, February 2014."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-30955-7_5"},{"key":"e_1_3_2_1_20_1","volume-title":"Cert Flocon","author":"Krmicek V.","year":"2011","unstructured":"V. Krmicek and T. Plesnik . Detecting botnets with netflow . In Cert Flocon , 2011 . V. Krmicek and T. Plesnik. Detecting botnets with netflow. In Cert Flocon, 2011."},{"key":"e_1_3_2_1_21_1","volume-title":"White paper","author":"Leder F.","year":"2009","unstructured":"F. Leder and T. Werner . Know your enemy: Containing conficker. The HoneyNet Project , White paper , 2009 . F. Leder and T. Werner. Know your enemy: Containing conficker. The HoneyNet Project, White paper, 2009."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10710-008-9067-9"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.3233\/IDA-2011-0496"},{"key":"e_1_3_2_1_24_1","volume-title":"The role of DNS in botnet command and control","author":"Open DNS Inc.","year":"2012","unstructured":"Open DNS Inc. The role of DNS in botnet command and control , 2012 . Open DNS Inc. The role of DNS in botnet command and control, 2012."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECURWARE.2010.39"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920285"},{"key":"e_1_3_2_1_27_1","first-page":"1","article-title":"Botnet detection based on network behavior","volume":"36","author":"Strayer W.","year":"2008","unstructured":"W. Strayer , D. Lapsely , R. Walsh , and C. Livadas . Botnet detection based on network behavior . Advances in Information Security , 36 : 1 -- 24 , 2008 . W. Strayer, D. Lapsely, R. Walsh, and C. Livadas. Botnet detection based on network behavior. Advances in Information Security, 36:1--24, 2008.","journal-title":"Advances in Information Security"},{"volume-title":"http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/zeuszbot-malware-shapes-up-in-2013\/","year":"2013","key":"e_1_3_2_1_28_1","unstructured":"Trend Labs - Security Intelligence Blog. Zeus\/zbot malware shapes up in 2013. http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/zeuszbot-malware-shapes-up-in-2013\/ , 2013 . Trend Labs - Security Intelligence Blog. Zeus\/zbot malware shapes up in 2013. http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/zeuszbot-malware-shapes-up-in-2013\/, 2013."},{"key":"e_1_3_2_1_29_1","unstructured":"Twitter API. http:\/\/blog.unmaskparasites.com\/2009\/12\/09\/twitter-api-still-attracts-hackers\/.  Twitter API. http:\/\/blog.unmaskparasites.com\/2009\/12\/09\/twitter-api-still-attracts-hackers\/."},{"key":"e_1_3_2_1_30_1","unstructured":"weka. http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/.  weka. http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/1813084.1813104"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2012.2184552"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNIT.2010.5508552"}],"event":{"name":"GECCO '14: Genetic and Evolutionary Computation Conference","sponsor":["SIGEVO ACM Special Interest Group on Genetic and Evolutionary Computation"],"location":"Vancouver BC Canada","acronym":"GECCO '14"},"container-title":["Proceedings of the Companion Publication of the 2014 Annual Conference on Genetic and Evolutionary Computation"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2598394.2605435","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2598394.2605435","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:56:06Z","timestamp":1750229766000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2598394.2605435"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,7,12]]},"references-count":33,"alternative-id":["10.1145\/2598394.2605435","10.1145\/2598394"],"URL":"https:\/\/doi.org\/10.1145\/2598394.2605435","relation":{},"subject":[],"published":{"date-parts":[[2014,7,12]]},"assertion":[{"value":"2014-07-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}