{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,2]],"date-time":"2026-08-02T12:28:05Z","timestamp":1785673685462,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":16,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,3,14]],"date-time":"2018-03-14T00:00:00Z","timestamp":1520985600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1700527"],"award-info":[{"award-number":["1700527"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,3,14]]},"DOI":"10.1145\/3180465.3180467","type":"proceedings-article","created":{"date-parts":[[2018,3,15]],"date-time":"2018-03-15T13:22:14Z","timestamp":1521120134000},"page":"1-6","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":101,"title":["Machine Learning-Based Detection of Ransomware Using SDN"],"prefix":"10.1145","author":[{"given":"Greg","family":"Cusack","sequence":"first","affiliation":[{"name":"University of Colorado Boulder, Boulder, CO, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Oliver","family":"Michel","sequence":"additional","affiliation":[{"name":"University of Colorado Boulder, Boulder, CO, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eric","family":"Keller","sequence":"additional","affiliation":[{"name":"University of Colorado Boulder, Boulder, CO, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2018,3,14]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1177\/1094342016672542"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2656877.2656890"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486011"},{"key":"e_1_3_2_1_4_1","volume-title":"Software- Defined Networking-based Crypto Ransomware Detection Using HTTP Traffic Characteristics. CoRR abs\/1611.08294","author":"Cabaj Krzysztof","year":"2016","unstructured":"Krzysztof Cabaj , Marcin Gregorczyk , and Wojciech Mazurczyk . 2016. Software- Defined Networking-based Crypto Ransomware Detection Using HTTP Traffic Characteristics. CoRR abs\/1611.08294 ( 2016 ). arXiv:1611.08294 http:\/\/arxiv.org\/abs\/1611.08294 Krzysztof Cabaj, Marcin Gregorczyk, and Wojciech Mazurczyk. 2016. Software- Defined Networking-based Crypto Ransomware Detection Using HTTP Traffic Characteristics. CoRR abs\/1611.08294 (2016). arXiv:1611.08294 http:\/\/arxiv.org\/abs\/1611.08294"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2016.1600110NM"},{"key":"e_1_3_2_1_6_1","unstructured":"Europol. 2017. Internet Organised Crime Assessment 2016 IOCTA. (2017). https:\/\/www.europol.europa.eu\/activities-services\/main-reports\/internet-organised-crime-threat-assessment-iocta-2017  Europol. 2017. Internet Organised Crime Assessment 2016 IOCTA. (2017). https:\/\/www.europol.europa.eu\/activities-services\/main-reports\/internet-organised-crime-threat-assessment-iocta-2017"},{"key":"e_1_3_2_1_7_1","unstructured":"Guofei Gu Roberto Perdisci Junjie Zhang Wenke Lee etal 2008. BotMiner: Clustering Analysis of Network Traffic for Protocol-and Structure-Independent Botnet Detection.. In USENIX security symposium Vol. 5. 139--154.   Guofei Gu Roberto Perdisci Junjie Zhang Wenke Lee et al. 2008. BotMiner: Clustering Analysis of Network Traffic for Protocol-and Structure-Independent Botnet Detection.. In USENIX security symposium Vol. 5. 139--154."},{"key":"e_1_3_2_1_8_1","volume-title":"FlowRadar: A Better NetFlow for Data Centers. In 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16)","author":"Li Yuliang","year":"2016","unstructured":"Yuliang Li , Rui Miao , Changhoon Kim , and Minlan Yu . 2016 . FlowRadar: A Better NetFlow for Data Centers. In 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16) . USENIX Association, Santa Clara, CA, 311--324. https:\/\/www.usenix.org\/conference\/nsdi16\/technical-sessions\/presentation\/li-yuliang Yuliang Li, Rui Miao, Changhoon Kim, and Minlan Yu. 2016. FlowRadar: A Better NetFlow for Data Centers. In 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI 16). USENIX Association, Santa Clara, CA, 311--324. https:\/\/www.usenix.org\/conference\/nsdi16\/technical-sessions\/presentation\/li-yuliang"},{"key":"e_1_3_2_1_9_1","unstructured":"Arna Magn\u00fasard\u00f3ttir. 2017. Malware is Moving Heavily to HTTPS. (2017). https:\/\/www.cyren.com\/blog\/articles\/over-one-third-of-malware-uses-https  Arna Magn\u00fasard\u00f3ttir. 2017. Malware is Moving Heavily to HTTPS. (2017). https:\/\/www.cyren.com\/blog\/articles\/over-one-third-of-malware-uses-https"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098822.3098829"},{"key":"e_1_3_2_1_11_1","volume-title":"Ensemble machine learning","author":"Yanjun Qi.","unstructured":"Yanjun Qi. 2012. Random forest for bioinformatics . In Ensemble machine learning . Springer , 307--323. Yanjun Qi. 2012. Random forest for bioinformatics. In Ensemble machine learning. Springer, 307--323."},{"key":"e_1_3_2_1_12_1","volume-title":"Cerber Ransomware: Everything You Need to Know.","author":"Research Barkly","year":"2017","unstructured":"Barkly Research . 2017 . Cerber Ransomware: Everything You Need to Know. (2017). https:\/\/blog.barkly.com\/cerber-ransomware-statistics-2017 Barkly Research. 2017. Cerber Ransomware: Everything You Need to Know. (2017). https:\/\/blog.barkly.com\/cerber-ransomware-statistics-2017"},{"key":"e_1_3_2_1_13_1","volume-title":"Lupu","author":"Sgandurra Daniele","year":"2016","unstructured":"Daniele Sgandurra , Luis Mu\u00f1oz-Gonz\u00e1lez , Rabih Mohsen , and Emil C . Lupu . 2016 . Automated Dynamic Analysis of Ransomware: Benefits, Limitations and use for Detection. CoRR abs\/1609.03020 (2016). arXiv:1609.03020 http:\/\/arxiv.org\/abs\/1609.03020 Daniele Sgandurra, Luis Mu\u00f1oz-Gonz\u00e1lez, Rabih Mohsen, and Emil C. Lupu. 2016. Automated Dynamic Analysis of Ransomware: Benefits, Limitations and use for Detection. CoRR abs\/1609.03020 (2016). arXiv:1609.03020 http:\/\/arxiv.org\/abs\/1609.03020"},{"key":"e_1_3_2_1_14_1","volume-title":"Smith","author":"Sonchack John","year":"2017","unstructured":"John Sonchack , Adam J. Aviv , Eric Keller , and Jonathon M . Smith . 2017 . TurboFlow: Accelerating Flow Collection on Commodity Switches . (2017). John Sonchack, Adam J. Aviv, Eric Keller, and Jonathon M. Smith. 2017. TurboFlow: Accelerating Flow Collection on Commodity Switches. (2017)."},{"key":"e_1_3_2_1_15_1","first-page":"4","article-title":"Ransomware attacks pose growing threat","volume":"63","author":"Tuttle Hilary","year":"2016","unstructured":"Hilary Tuttle . 2016 . Ransomware attacks pose growing threat . Risk Management 63 , 4 (2016), 4 . Hilary Tuttle. 2016. Ransomware attacks pose growing threat. Risk Management 63, 4 (2016), 4.","journal-title":"Risk Management"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_11"}],"event":{"name":"CODASPY '18: Eighth ACM Conference on Data and Application Security and Privacy","location":"Tempe AZ USA","acronym":"CODASPY '18","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks &amp; Network Function Virtualization"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3180465.3180467","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3180465.3180467","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3180465.3180467","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:26:21Z","timestamp":1750213581000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3180465.3180467"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,3,14]]},"references-count":16,"alternative-id":["10.1145\/3180465.3180467","10.1145\/3180465"],"URL":"https:\/\/doi.org\/10.1145\/3180465.3180467","relation":{},"subject":[],"published":{"date-parts":[[2018,3,14]]},"assertion":[{"value":"2018-03-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}