{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T06:32:55Z","timestamp":1759991575531,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":38,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,3,30]],"date-time":"2020-03-30T00:00:00Z","timestamp":1585526400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,3,30]]},"DOI":"10.1145\/3341105.3373862","type":"proceedings-article","created":{"date-parts":[[2020,3,29]],"date-time":"2020-03-29T12:13:52Z","timestamp":1585484032000},"page":"1696-1705","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["HeadPrint"],"prefix":"10.1145","author":[{"given":"Riccardo","family":"Bortolameotti","sequence":"first","affiliation":[{"name":"University of Twente"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thijs","family":"van Ede","sequence":"additional","affiliation":[{"name":"University of Twente"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Continella","sequence":"additional","affiliation":[{"name":"UC Santa Barbara"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Hupperich","sequence":"additional","affiliation":[{"name":"University of Muenster"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maarten H.","family":"Everts","sequence":"additional","affiliation":[{"name":"University of Twente"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Reza","family":"Rafati","sequence":"additional","affiliation":[{"name":"Bitdefender"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Willem","family":"Jonker","sequence":"additional","affiliation":[{"name":"University of Twente"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pieter","family":"Hartel","sequence":"additional","affiliation":[{"name":"Delft University of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andreas","family":"Peter","sequence":"additional","affiliation":[{"name":"University of Twente"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,3,30]]},"reference":[{"volume-title":"An LCS-based string metric","author":"Bakkelund Daniel","key":"e_1_3_2_1_1_1","unstructured":"Daniel Bakkelund . 2009. An LCS-based string metric . Olso, Norway : University of Oslo (2009) . Daniel Bakkelund. 2009. An LCS-based string metric. Olso, Norway: University of Oslo (2009)."},{"key":"e_1_3_2_1_2_1","volume-title":"Nordic Conference on Secure IT Systems. Springer, 31--46","author":"Boda K\u00e1roly","year":"2011","unstructured":"K\u00e1roly Boda , \u00c1d\u00e1m M\u00e1t\u00e9 F\u00f6ldes , G\u00e1bor Gy\u00f6rgy Guly\u00e1s , and S\u00e1ndor Imre . 2011 . User tracking on the web via cross-browser fingerprinting . In Nordic Conference on Secure IT Systems. Springer, 31--46 . K\u00e1roly Boda, \u00c1d\u00e1m M\u00e1t\u00e9 F\u00f6ldes, G\u00e1bor Gy\u00f6rgy Guly\u00e1s, and S\u00e1ndor Imre. 2011. User tracking on the web via cross-browser fingerprinting. In Nordic Conference on Secure IT Systems. Springer, 31--46."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030100"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972788.22"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134605"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37228-6_22"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23152"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23465"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1198255.1198257"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2013.6566868"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23456"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/1881151.1881152"},{"key":"e_1_3_2_1_13_1","unstructured":"Electronic Frontier Foundation. [n. d.]. Kaspersky User-Agent Strings - NSA. ([n. d.]). https:\/\/www.eff.org\/it\/node\/86529  Electronic Frontier Foundation. [n. d.]. Kaspersky User-Agent Strings - NSA. ([n. d.]). https:\/\/www.eff.org\/it\/node\/86529"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978313"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-47854-7_7"},{"key":"e_1_3_2_1_16_1","unstructured":"Martin Roesch. [n. d.]. Cisco Announces OpenAppID the Next Open Source Game Changer in Cybersecurity. ([n. d.]). https:\/\/blogs.cisco.com\/security\/cisco-announces-openappid-the-next-open-source-game-changer-in-cybersecurity  Martin Roesch. [n. d.]. Cisco Announces OpenAppID the Next Open Source Game Changer in Cybersecurity. ([n. d.]). https:\/\/blogs.cisco.com\/security\/cisco-announces-openappid-the-next-open-source-game-changer-in-cybersecurity"},{"key":"e_1_3_2_1_17_1","unstructured":"Martin Roesch. [n. d.]. Firepower Management Center Configuration Guide. ([n. d.]). https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/firepower\/610\/configuration\/guide\/fpmc-config-guide-v61\/application_detection.html?bookSearch=true  Martin Roesch. [n. d.]. Firepower Management Center Configuration Guide. ([n. d.]). https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/firepower\/610\/configuration\/guide\/fpmc-config-guide-v61\/application_detection.html?bookSearch=true"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-15509-8_5"},{"key":"e_1_3_2_1_19_1","unstructured":"MITRE. [n. d.]. Commonly Used Ports MITRE. ([n. d.]). https:\/\/attack.mitre.org\/techniques\/T1043\/  MITRE. [n. d.]. Commonly Used Ports MITRE. ([n. d.]). https:\/\/attack.mitre.org\/techniques\/T1043\/"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2008.4690854"},{"key":"e_1_3_2_1_21_1","volume-title":"Proc. of the USENIX Security Symposium.","author":"Nelms Terry","year":"2013","unstructured":"Terry Nelms , Roberto Perdisci , and Mustaque Ahamad . 2013 . ExecScent: Mining for New C&C Domains in Live Networks with Adaptive Control Protocol Templates . In Proc. of the USENIX Security Symposium. Terry Nelms, Roberto Perdisci, and Mustaque Ahamad. 2013. ExecScent: Mining for New C&C Domains in Live Networks with Adaptive Control Protocol Templates. In Proc. of the USENIX Security Symposium."},{"key":"e_1_3_2_1_22_1","volume-title":"Bro: a system for detecting network intruders in real-time. Computer networks 31, 23-24","author":"Paxson Vern","year":"1999","unstructured":"Vern Paxson . 1999. Bro: a system for detecting network intruders in real-time. Computer networks 31, 23-24 ( 1999 ), 2435--2463. Vern Paxson. 1999. Bro: a system for detecting network intruders in real-time. Computer networks 31, 23-24 (1999), 2435--2463."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2078195"},{"key":"e_1_3_2_1_24_1","volume-title":"Proc. of the USENIX Symposium on Networked Systems Design and Implementation, NSDI 2010","author":"Perdisci Roberto","year":"2010","unstructured":"Roberto Perdisci , Wenke Lee , and Nick Feamster . 2010 . Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces . In Proc. of the USENIX Symposium on Networked Systems Design and Implementation, NSDI 2010 , April 28 --30 , 2010, San Jose, CA, USA. 391--404. Roberto Perdisci, Wenke Lee, and Nick Feamster. 2010. Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces. In Proc. of the USENIX Symposium on Networked Systems Design and Implementation, NSDI 2010, April 28--30, 2010, San Jose, CA, USA. 391--404."},{"key":"e_1_3_2_1_25_1","unstructured":"Ponemon Institute. [n. d.]. 2018 Cost of a Data Breach Study by Ponemon. ([n. d.]). https:\/\/www.ibm.com\/security\/data-breach  Ponemon Institute. [n. d.]. 2018 Cost of a Data Breach Study by Ponemon. ([n. d.]). https:\/\/www.ibm.com\/security\/data-breach"},{"key":"e_1_3_2_1_26_1","volume-title":"International Workshop on Recent Advances in Intrusion Detection. Springer, 144--163","author":"Zubair Rafique M","year":"2013","unstructured":"M Zubair Rafique and Juan Caballero . 2013 . Firma: Malware clustering and network signature generation with mixed network behaviors . In International Workshop on Recent Advances in Intrusion Detection. Springer, 144--163 . M Zubair Rafique and Juan Caballero. 2013. Firma: Malware clustering and network signature generation with mixed network behaviors. In International Workshop on Recent Advances in Intrusion Detection. Springer, 144--163."},{"key":"e_1_3_2_1_27_1","first-page":"46","article-title":"Pattern-matching-the gestalt approach","volume":"13","author":"Ratcliff John W","year":"1988","unstructured":"John W Ratcliff and David E Metzener . 1988 . Pattern-matching-the gestalt approach . Dr Dobbs Journal 13 , 7 (1988), 46 . John W Ratcliff and David E Metzener. 1988. Pattern-matching-the gestalt approach. Dr Dobbs Journal 13, 7 (1988), 46.","journal-title":"Dr Dobbs Journal"},{"key":"e_1_3_2_1_28_1","volume-title":"Proc. of the Conference on Systems Administration (LISA-99)","author":"Roesch Martin","year":"1999","unstructured":"Martin Roesch . 1999 . Snort: Lightweight Intrusion Detection for Networks . In Proc. of the Conference on Systems Administration (LISA-99) , Seattle, WA, USA, November 7--12 , 1999. 229--238. Martin Roesch. 1999. Snort: Lightweight Intrusion Detection for Networks. In Proc. of the Conference on Systems Administration (LISA-99), Seattle, WA, USA, November 7--12, 1999. 229--238."},{"key":"e_1_3_2_1_29_1","volume-title":"2011 Seventh European Conference on. IEEE, 25--32","author":"Schwenk Guido","year":"2011","unstructured":"Guido Schwenk and Konrad Rieck . 2011 . Adaptive detection of covert communication in http requests. In Computer Network Defense (EC2ND) , 2011 Seventh European Conference on. IEEE, 25--32 . Guido Schwenk and Konrad Rieck. 2011. Adaptive detection of covert communication in http requests. In Computer Network Defense (EC2ND), 2011 Seventh European Conference on. IEEE, 25--32."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2014.2382590"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.40"},{"key":"e_1_3_2_1_33_1","volume-title":"FP-STALKER: Tracking Browser Fingerprint Evolutions","author":"Vastel Antoine","year":"2018","unstructured":"Antoine Vastel , Pierre Laperdrix , Walter Rudametkin , and Romain Rouvoy . 2018. FP-STALKER: Tracking Browser Fingerprint Evolutions . In IEEE S&P 2018 -39th IEEE Symposium on Security and Privacy. IEEE , 1--14. Antoine Vastel, Pierre Laperdrix, Walter Rudametkin, and Romain Rouvoy. 2018. FP-STALKER: Tracking Browser Fingerprint Evolutions. In IEEE S&P 2018-39th IEEE Symposium on Security and Privacy. IEEE, 1--14."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2015.7218526"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2789168.2790097"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2554850.2554896"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2007.4317620"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2014.6890946"}],"event":{"name":"SAC '20: The 35th ACM\/SIGAPP Symposium on Applied Computing","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"],"location":"Brno Czech Republic","acronym":"SAC '20"},"container-title":["Proceedings of the 35th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3341105.3373862","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3341105.3373862","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:54:11Z","timestamp":1750204451000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3341105.3373862"}},"subtitle":["detecting anomalous communications through header-based application fingerprinting"],"short-title":[],"issued":{"date-parts":[[2020,3,30]]},"references-count":38,"alternative-id":["10.1145\/3341105.3373862","10.1145\/3341105"],"URL":"https:\/\/doi.org\/10.1145\/3341105.3373862","relation":{},"subject":[],"published":{"date-parts":[[2020,3,30]]},"assertion":[{"value":"2020-03-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}