{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:07:13Z","timestamp":1750306033664,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,12,8]],"date-time":"2017-12-08T00:00:00Z","timestamp":1512691200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Open Project of Beijing Key Laboratory of Internet Culture and Digital Communication","award":["ICDD201507"],"award-info":[{"award-number":["ICDD201507"]}]},{"name":"National Natural Science Foundation of China","award":["61502039"],"award-info":[{"award-number":["61502039"]}]},{"name":"Standard Project of Science Plan of Beijing Municipal Education Committee","award":["KM201611232014"],"award-info":[{"award-number":["KM201611232014"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,12,8]]},"DOI":"10.1145\/3171592.3171595","type":"proceedings-article","created":{"date-parts":[[2018,3,16]],"date-time":"2018-03-16T12:53:36Z","timestamp":1521204816000},"page":"86-91","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["An Adaptive Malicious Domain Detection Mechanism with DNS Traffic"],"prefix":"10.1145","author":[{"given":"Shuo","family":"Xu","sequence":"first","affiliation":[{"name":"Joint Lab of Sensing and Computational Intelligence, Beijing Information Science&amp;Technology University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"ShuQin","family":"Li","sequence":"additional","affiliation":[{"name":"Joint Lab of Sensing and Computational Intelligence, Beijing Information Science&amp;Technology University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kun","family":"Meng","sequence":"additional","affiliation":[{"name":"Joint Lab of Sensing and Computational Intelligence, Beijing Information Science&amp;Technology University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"LiJun","family":"Wu","sequence":"additional","affiliation":[{"name":"Joint Lab of Sensing and Computational Intelligence, Beijing Information Science&amp;Technology University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meng","family":"Ding","sequence":"additional","affiliation":[{"name":"Joint Lab of Sensing and Computational Intelligence, Beijing Information Science&amp;Technology University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,12,8]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2012.07.021"},{"key":"e_1_3_2_1_2_1","unstructured":"DDoS attacks. http:\/\/www.cismag.net\/Article\/Info\/1400  DDoS attacks. http:\/\/www.cismag.net\/Article\/Info\/1400"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(07)70045-4"},{"key":"e_1_3_2_1_4_1","volume-title":"Master's Project","author":"Schonewille D. J.","year":"2006","unstructured":"A. Schonewille , D. J. van Helmond . The Domain Name Service as an IDS , Master's Project , University of Amsterdam , Netherlands, Feb 2006 . A. Schonewille, D. J. van Helmond. The Domain Name Service as an IDS, Master's Project, University of Amsterdam, Netherlands, Feb 2006."},{"issue":"1391","key":"e_1_3_2_1_5_1","first-page":"408","article-title":"Detecting Machine Generated Domain Names Based on Morpheme Features {J}","volume":"52","author":"Zhang W W","year":"2013","unstructured":"Zhang W W , Gong J , Liu Q , Detecting Machine Generated Domain Names Based on Morpheme Features {J} . Proceedings of International Workshop on Cloud Computing & Information Security , 2013 , 52 ( 1391 ): 408 -- 411 . Zhang W W, Gong J, Liu Q, et al. Detecting Machine Generated Domain Names Based on Morpheme Features {J}. Proceedings of International Workshop on Cloud Computing & Information Security, 2013, 52(1391):408--411.","journal-title":"Proceedings of International Workshop on Cloud Computing & Information Security"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22365-5_1"},{"key":"e_1_3_2_1_7_1","first-page":"7","article-title":"Classification of malicious domain names using support vector machine and bi-gram method {J}","author":"Davuth N","year":"2013","unstructured":"Davuth N , Kim S R . Classification of malicious domain names using support vector machine and bi-gram method {J} . International Journal of Security & Its Applications , 2013 , 7 . Davuth N, Kim S R. Classification of malicious domain names using support vector machine and bi-gram method {J}. International Journal of Security & Its Applications, 2013, 7.","journal-title":"International Journal of Security & Its Applications"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879148"},{"key":"e_1_3_2_1_9_1","volume-title":"The 8th International Workshop on Traffic Monitoring and Analysis (TMA16)","author":"Han Zhang","year":"2016","unstructured":"Han Zhang , Manaf Gharaibeh, Spiros Thanasoulas . BotDigger : Detecting DGA Bots in a Single Network . The 8th International Workshop on Traffic Monitoring and Analysis (TMA16) , Louvain La Neuve, Belgium , 2016 Han Zhang, Manaf Gharaibeh, Spiros Thanasoulas. BotDigger: Detecting DGA Bots in a Single Network. The 8th International Workshop on Traffic Monitoring and Analysis (TMA16), Louvain La Neuve, Belgium, 2016"},{"issue":"9","key":"e_1_3_2_1_10_1","first-page":"2348","article-title":"Detecting Machine Generated Domain Names Based on Morpheme Features {J}","volume":"27","author":"Zhang W W","year":"2016","unstructured":"Zhang W W , Gong J , Liu Q , Detecting Machine Generated Domain Names Based on Morpheme Features {J} , Journal of Software , 2016 , 27 ( 9 ): 2348 -- 2364 . Zhang W W, Gong J, Liu Q, et al. Detecting Machine Generated Domain Names Based on Morpheme Features {J}, Journal of Software, 2016, 27(9):2348--2364.","journal-title":"Journal of Software"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CC.2013.6674213"},{"key":"e_1_3_2_1_12_1","volume-title":"NPL","author":"Spring J M","year":"2011","unstructured":"Spring J M , Metcalf L B , Stoner E. Correlating Domain Registrations and DNS First Activity in General and for Malware{C}. In Securing and Trusting Internet Names , NPL , Teddington, UK , April 4-5, 2011 . Spring J M, Metcalf L B, Stoner E. Correlating Domain Registrations and DNS First Activity in General and for Malware{C}. In Securing and Trusting Internet Names, NPL, Teddington, UK, April 4-5, 2011."},{"key":"e_1_3_2_1_13_1","volume-title":"Characterizing and Tracking Domain Generation Algorithms from Passive DNS Monitoring {J}. Computer Science","author":"Schiavoni","year":"2013","unstructured":"Schiavoni , Stefano. Finding , Characterizing and Tracking Domain Generation Algorithms from Passive DNS Monitoring {J}. Computer Science , 2013 . Schiavoni, Stefano. Finding, Characterizing and Tracking Domain Generation Algorithms from Passive DNS Monitoring {J}. Computer Science, 2013."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.10.001"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2011.07.018"},{"key":"e_1_3_2_1_16_1","volume-title":"21st USENIX Security Symposium","author":"Antonakakis M","year":"2012","unstructured":"Antonakakis M , Perdisci R , Nadji Y , From Throw-Away Traffic to Bots Detecting the Rise of DGA-Based Malware{C} . In 21st USENIX Security Symposium , Bellevue, WA, USA , August 8-10, 2012 : 24--24. Antonakakis M, Perdisci R, Nadji Y, et al. From Throw-Away Traffic to Bots Detecting the Rise of DGA-Based Malware{C}. In 21st USENIX Security Symposium, Bellevue, WA, USA, August 8-10, 2012: 24--24."},{"key":"e_1_3_2_1_17_1","first-page":"15","volume-title":"Detecting and tracking the rise of DGA-based malware {J}.login:the magazine of USENIX & SAGE","author":"Antonakakis M","year":"2012","unstructured":"Antonakakis M , Perdisci R , Vasiloglou N , Detecting and tracking the rise of DGA-based malware {J}.login:the magazine of USENIX & SAGE , 2012 , 37:p\u00e1gs. 15 - 24 . Antonakakis M, Perdisci R, Vasiloglou N, et al. Detecting and tracking the rise of DGA-based malware {J}.login:the magazine of USENIX & SAGE, 2012, 37:p\u00e1gs. 15-24."},{"key":"e_1_3_2_1_18_1","volume-title":"IEEE","author":"Gavrilut D T","year":"2017","unstructured":"Gavrilut D T , Popoiu G , Benchea R. Identifying DGA-Based Botnets Using Network Anomaly Detection{C}\/\/ International Symposium on Symbolic and Numeric Algorithms for Scientific Computing . IEEE , 2017 . Gavrilut D T, Popoiu G, Benchea R. Identifying DGA-Based Botnets Using Network Anomaly Detection{C}\/\/ International Symposium on Symbolic and Numeric Algorithms for Scientific Computing. IEEE, 2017."},{"key":"e_1_3_2_1_19_1","unstructured":"Markov Chain. https:\/\/en.wikipedia.org\/wiki\/Markov_chain  Markov Chain. https:\/\/en.wikipedia.org\/wiki\/Markov_chain"},{"key":"e_1_3_2_1_20_1","unstructured":"Alexa Internet. Actionable analytics for the web {EB\/OL}. {2017-01-10}. http:\/\/www. alexa.com\/  Alexa Internet. Actionable analytics for the web {EB\/OL}. {2017-01-10}. http:\/\/www. alexa.com\/"},{"key":"e_1_3_2_1_21_1","unstructured":"johannesbader.ch {DB\/OL}. {2017-01-10}. http:\/\/johannesbadr.ch\/  johannesbader.ch {DB\/OL}. {2017-01-10}. http:\/\/johannesbadr.ch\/"},{"key":"e_1_3_2_1_22_1","unstructured":"abuse.ch. Zeus Tracker {EB\/OL}. {2017-01-10}. https:\/\/zeustracker.abuse.ch\/  abuse.ch. Zeus Tracker {EB\/OL}. {2017-01-10}. https:\/\/zeustracker.abuse.ch\/"},{"key":"e_1_3_2_1_23_1","unstructured":"abuse.ch. Spy Eye Tracker {EB\/OL}. {2017-01-10}.https:\/\/spyeyetracker.abuse.ch\/  abuse.ch. Spy Eye Tracker {EB\/OL}. {2017-01-10}.https:\/\/spyeyetracker.abuse.ch\/"},{"key":"e_1_3_2_1_24_1","unstructured":"abuse.ch. Palevo Tracker {EB\/OL}. {2017-01-10}. https:\/\/palevotracker.abuse.ch\/  abuse.ch. Palevo Tracker {EB\/OL}. {2017-01-10}. https:\/\/palevotracker.abuse.ch\/"},{"key":"e_1_3_2_1_25_1","unstructured":"Malware Domain List {DB\/OL}. {2017-01-10}. http:\/\/www. malwaredomainlist.com\/  Malware Domain List {DB\/OL}. {2017-01-10}. http:\/\/www. malwaredomainlist.com\/"},{"key":"e_1_3_2_1_26_1","unstructured":"DNS-BH Malware Domain Blocklist {DB\/OL}. {2017-01-10}. http:\/\/www.malwaredomains.com\/  DNS-BH Malware Domain Blocklist {DB\/OL}. {2017-01-10}. http:\/\/www.malwaredomains.com\/"},{"key":"e_1_3_2_1_27_1","unstructured":"CyberCrime {DB\/OL}. {2017-01-10}. http:\/\/cybercrime-tracker.net\/  CyberCrime {DB\/OL}. {2017-01-10}. http:\/\/cybercrime-tracker.net\/"},{"key":"e_1_3_2_1_28_1","unstructured":"PhishTank {DB\/OL}. {2017-01-10}.http:\/\/phishtank.com  PhishTank {DB\/OL}. {2017-01-10}.http:\/\/phishtank.com"},{"key":"e_1_3_2_1_29_1","unstructured":"VirusTotal {CP\/OL}. {2017-02-01}. https:\/\/www.virustotal.com\/  VirusTotal {CP\/OL}. {2017-02-01}. https:\/\/www.virustotal.com\/"},{"key":"e_1_3_2_1_30_1","unstructured":"ThreatExpert Ltd. ThreatExpert {CP\/OL}. {2017-02-01}  ThreatExpert Ltd. ThreatExpert {CP\/OL}. {2017-02-01}"},{"issue":"8","key":"e_1_3_2_1_31_1","first-page":"1","volume":"2013","author":"YanQin Zhu","unstructured":"YanQin Zhu , LingYun Ying, DengGuo Feng et al . Behavioral Analysis of Fast Flux Service Network. Computer Systems & Applications , 2013 ( 8 ): 1 -- 8 YanQin Zhu, LingYun Ying, DengGuo Feng et al. Behavioral Analysis of Fast Flux Service Network. Computer Systems & Applications, 2013 (8): 1--8","journal-title":"Behavioral Analysis of Fast Flux Service Network. Computer Systems & Applications"}],"event":{"name":"ICNCC 2017: 2017 VI International Conference on Network, Communication and Computing","acronym":"ICNCC 2017","location":"Kunming China"},"container-title":["Proceedings of the 2017 VI International Conference on Network, Communication and Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3171592.3171595","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3171592.3171595","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:02:53Z","timestamp":1750215773000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3171592.3171595"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,12,8]]},"references-count":31,"alternative-id":["10.1145\/3171592.3171595","10.1145\/3171592"],"URL":"https:\/\/doi.org\/10.1145\/3171592.3171595","relation":{},"subject":[],"published":{"date-parts":[[2017,12,8]]},"assertion":[{"value":"2017-12-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}