{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T16:19:08Z","timestamp":1774023548260,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,7,19]],"date-time":"2017-07-19T00:00:00Z","timestamp":1500422400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,7,19]]},"DOI":"10.1145\/3102304.3102331","type":"proceedings-article","created":{"date-parts":[[2017,9,25]],"date-time":"2017-09-25T13:14:14Z","timestamp":1506345254000},"update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["Malicious SSL Certificate Detection"],"prefix":"10.1145","author":[{"given":"Ibrahim","family":"Ghafir","sequence":"first","affiliation":[{"name":"Faculty of Informatics, Masaryk University, Brno, Czech Republic"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vaclav","family":"Prenosil","sequence":"additional","affiliation":[{"name":"Faculty of Informatics, Masaryk University, Brno, Czech Republic"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Hammoudeh","sequence":"additional","affiliation":[{"name":"Faculty of Science &amp; Engineering, Manchester Metropolitan University, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liangxiu","family":"Han","sequence":"additional","affiliation":[{"name":"Faculty of Science &amp; Engineering, Manchester Metropolitan University, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Umar","family":"Raza","sequence":"additional","affiliation":[{"name":"Faculty of Science &amp; Engineering, Manchester Metropolitan University, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,7,19]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2017.02.001"},{"key":"e_1_3_2_1_2_1","volume-title":"Internet of Things, Smart Spaces, and Next Generation Networking","author":"Abuarqoub Abdelrahman"},{"key":"e_1_3_2_1_3_1","unstructured":"Abuse.ch. 2017. SSL Blacklist a new weapon to fight malware and botnet. http:\/\/securityaffairs.co\/wordpress\/26672\/cyber-crime\/ssl-blacklist-new-weapon-fight-malware-botnet.html. (2017).  Abuse.ch. 2017. SSL Blacklist a new weapon to fight malware and botnet. http:\/\/securityaffairs.co\/wordpress\/26672\/cyber-crime\/ssl-blacklist-new-weapon-fight-malware-botnet.html. (2017)."},{"key":"e_1_3_2_1_4_1","unstructured":"Kostas G Anagnostakis Stelios Sidiroglou Periklis Akritidis Konstantinos Xinidis Evangelos P Markatos and Angelos D Keromytis. 2005. Detecting Targeted Attacks Using Shadow Honeypots.. In Usenix Security.   Kostas G Anagnostakis Stelios Sidiroglou Periklis Akritidis Konstantinos Xinidis Evangelos P Markatos and Angelos D Keromytis. 2005. Detecting Targeted Attacks Using Shadow Honeypots.. In Usenix Security."},{"key":"e_1_3_2_1_5_1","unstructured":"Paul Bacher Thorsten Holz Markus Kotter and Georg Wicherski. 2005. Know your enemy: Tracking botnets. (2005).  Paul Bacher Thorsten Holz Markus Kotter and Georg Wicherski. 2005. Know your enemy: Tracking botnets. (2005)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Marco Balduzzi Vincenzo Ciangaglini and Robert McArdle. 2013. Targeted Attacks Detection With SPuNge. (2013).  Marco Balduzzi Vincenzo Ciangaglini and Robert McArdle. 2013. Targeted Attacks Detection With SPuNge. (2013).","DOI":"10.1109\/PST.2013.6596053"},{"key":"e_1_3_2_1_7_1","volume-title":"ACM European Workshop on System Security (EuroSec)","volume":"2012","author":"Bencsath Boldizsar","year":"2012"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAT.2013.24"},{"key":"e_1_3_2_1_9_1","volume-title":"RT: Request Tracker. https:\/\/www.bestpractical. com\/rt\/.","year":"2017"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1247480.1247620"},{"key":"e_1_3_2_1_11_1","unstructured":"Bro-Project. 2017. Intellegence Framework. https:\/\/www.bro.org\/sphinx\/frameworks\/intel.html. (2017). Accessed: 15-02-2017  Bro-Project. 2017. Intellegence Framework. https:\/\/www.bro.org\/sphinx\/frameworks\/intel.html. (2017). Accessed: 15-02-2017"},{"key":"e_1_3_2_1_12_1","volume-title":"IFIP International Conference on. IEEE, 1-5.","author":"Brogi Guillaume","year":"2016"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCPCT.2016.7530239"},{"key":"e_1_3_2_1_14_1","volume-title":"Communications and Informatics (ICACCI), 2015 International Conference on. IEEE","author":"Chandran Saranya","year":"2015"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1621890.1621893"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.08.004"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1810891.1810904"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Ibrahim Ghafir Mohammad Hammoudeh and Vaclav Prenosil. 2017. Disguised executable files in spear-phishing emails: Detecting the point of entry in advanced persistent threat. (2017).  Ibrahim Ghafir Mohammad Hammoudeh and Vaclav Prenosil. 2017. Disguised executable files in spear-phishing emails: Detecting the point of entry in advanced persistent threat. (2017).","DOI":"10.7287\/peerj.preprints.2998v1"},{"key":"e_1_3_2_1_19_1","first-page":"10","volume-title":"Proceedings of student conference Zvule, IEEE\/UREL","author":"Ghafir Ibrahim","year":"2014"},{"key":"e_1_3_2_1_20_1","article-title":"Advanced Persistent Threat Attack Detection","volume":"4","author":"Ghafir Ibrahim","year":"2014","journal-title":"An Overview. International Journal of Advances in Computer Networks and Its Security (IJCNS)"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2014.1410"},{"key":"e_1_3_2_1_22_1","first-page":"34","volume-title":"Proceedings of International Conference on Distance Learning, Simulation and Communication","author":"Ghafir Ibrahim","year":"2015"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/GCCT.2015.7342657"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPIN.2015.7095337"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-81-322-2517-1_63"},{"key":"e_1_3_2_1_26_1","volume-title":"Advanced Computer and Communication Engineering Technology","author":"Ghafir Ibrahim"},{"key":"e_1_3_2_1_27_1","volume-title":"Social Engineering Attack Strategies and Defence Approaches. In IEEE 4th International Conference on Future Internet of Things and Cloud (FiCloud). IEEE Xplore Digital Library, 145-149","author":"Ghafir Ibrahim","year":"2016"},{"key":"e_1_3_2_1_28_1","article-title":"Botnet Command and Control Traffic Detection Challenges","volume":"7","author":"Ghafir Ibrahim","year":"2015","journal-title":"A Correlation-based Solution. International Journal of Advances in Computer Networks and Its Security (IJCNS)"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/W-FiCloud.2016.30"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2014.1411"},{"key":"e_1_3_2_1_31_1","volume-title":"International Journal of Advances in Computer Networks and its security (ICJNS)","author":"Ghafir Ibrahim","year":"2015"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecurity.2012.16"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Mohammad Hammoudeh Fayez Al-Fayez Huw Lloyd Robert Newman Bamidele Adebisi Ahcene Bounceur and Abdelrahman Abuarqoub. 2017. A Wireless Sensor Network Border Monitoring System: Deployment Issues and Routing Protocols. IEEE Sensors Journal (2017).  Mohammad Hammoudeh Fayez Al-Fayez Huw Lloyd Robert Newman Bamidele Adebisi Ahcene Bounceur and Abdelrahman Abuarqoub. 2017. A Wireless Sensor Network Border Monitoring System: Deployment Issues and Routing Protocols. IEEE Sensors Journal (2017).","DOI":"10.1109\/JSEN.2017.2672501"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SSD.2010.5585512"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.3390\/s150922970"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISA.2008.11"},{"key":"e_1_3_2_1_37_1","unstructured":"Mandiant. 2017. Mandiant APT1 Report Appendix F Update: SSL Certificate Hashes. https:\/\/www.mandiant.com\/blog\/md5-sha1\/. (2017). Accessed: 10-02-2017.  Mandiant. 2017. Mandiant APT1 Report Appendix F Update: SSL Certificate Hashes. https:\/\/www.mandiant.com\/blog\/md5-sha1\/. (2017). Accessed: 10-02-2017."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1132026.1132027"},{"key":"e_1_3_2_1_39_1","unstructured":"Catherine Moxey Mike Edwards Opher Etzion Mamdouh Ibrahim Sreekanth Iyer Hubert Lalanne Mweene Monze Marc Peters Yuri Rabinovich Guy Sharon and others. 2010. A conceptual model for event processing systems. IBM Redguide publication (2010).  Catherine Moxey Mike Edwards Opher Etzion Mamdouh Ibrahim Sreekanth Iyer Hubert Lalanne Mweene Monze Marc Peters Yuri Rabinovich Guy Sharon and others. 2010. A conceptual model for event processing systems. IBM Redguide publication (2010)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.10.014"},{"key":"e_1_3_2_1_41_1","unstructured":"Oracle. 2017. Network tracing. https:\/\/www.virtualbox.org\/wiki\/Network tips. (2017). Accessed: 07-02-2017.  Oracle. 2017. Network tracing. https:\/\/www.virtualbox.org\/wiki\/Network tips. (2017). Accessed: 07-02-2017."},{"key":"e_1_3_2_1_42_1","volume-title":"Mobility and Security (NTMS), 2016 8th IFIP International Conference on. IEEE, 1-5.","author":"Gomez Ortega Jose Luis","year":"2016"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_44_1","unstructured":"Bro Project. 2017. Input Framework. https:\/\/www.bro.org\/sphinx\/frameworks\/input.html. (2017). Accessed: 01-06-2017.  Bro Project. 2017. Input Framework. https:\/\/www.bro.org\/sphinx\/frameworks\/input.html. (2017). Accessed: 01-06-2017."},{"key":"e_1_3_2_1_45_1","unstructured":"Bro Project. 2017. x509 certificate event. https:\/\/www.bro.org\/sphinx\/scripts\/base\/bif\/plugins\/Bro_X509.events.bif.bro.html#id-x509_certificate. (2017). Accessed: 01-06-2017.  Bro Project. 2017. x509 certificate event. https:\/\/www.bro.org\/sphinx\/scripts\/base\/bif\/plugins\/Bro_X509.events.bif.bro.html#id-x509_certificate. (2017). Accessed: 01-06-2017."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.omega.2011.03.008"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSNDSP.2014.6923831"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1002\/sam.11296"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/EISIC.2013.37"},{"key":"e_1_3_2_1_50_1","first-page":"1280","article-title":"DIVINE: Building a Wearable Device for Intelligent Control of Environment Using Google Glass. In Computer and Information Technology; Ubiquitous Computing and Communications; Dependable, Autonomic and Secure Computing; Pervasive Intelligence and Computing (CIT\/IUCC\/DASC\/PICOM), 2015 IEEE International Conference on","author":"Sobeih Tamir","year":"2015","journal-title":"IEEE"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.5555\/597917.597922"},{"key":"e_1_3_2_1_52_1","article-title":"Network monitoring approaches: An overview","volume":"5","author":"Svoboda Jakub","year":"2015","journal-title":"International Journal of Advances in Computer Networks and Its Security (IJCNS)"},{"key":"e_1_3_2_1_53_1","volume-title":"IEEE International Conference on Communications.","author":"Wang Xu"},{"key":"e_1_3_2_1_54_1","unstructured":"Paul Wood Mathew Nisbet Gerry Egan and others. 2012. Symantec internet security threat report trends for 2011. Volume XVII (2012).  Paul Wood Mathew Nisbet Gerry Egan and others. 2012. Symantec internet security threat report trends for 2011. Volume XVII (2012)."}],"event":{"name":"ICFNDS '17: International Conference on Future Networks and Distributed Systems","location":"Cambridge United Kingdom","acronym":"ICFNDS '17","sponsor":["LABSTICC Labsticc"]},"container-title":["Proceedings of the International Conference on Future Networks and Distributed Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3102304.3102331","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3102304.3102331","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:37:05Z","timestamp":1750217825000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3102304.3102331"}},"subtitle":["A Step Towards Advanced Persistent Threat Defence"],"short-title":[],"issued":{"date-parts":[[2017,7,19]]},"references-count":54,"alternative-id":["10.1145\/3102304.3102331","10.1145\/3102304"],"URL":"https:\/\/doi.org\/10.1145\/3102304.3102331","relation":{},"subject":[],"published":{"date-parts":[[2017,7,19]]},"assertion":[{"value":"2017-07-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}