{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:28:26Z","timestamp":1750220906104,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":18,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,1,10]],"date-time":"2020-01-10T00:00:00Z","timestamp":1578614400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,1,10]]},"DOI":"10.1145\/3377644.3377652","type":"proceedings-article","created":{"date-parts":[[2020,2,26]],"date-time":"2020-02-26T08:16:17Z","timestamp":1582704977000},"page":"74-78","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["A Novel Ensemble Anomaly based Approach for Command and Control Channel Detection"],"prefix":"10.1145","author":[{"given":"Tao","family":"Chen","sequence":"first","affiliation":[{"name":"Information Center of No.2, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guangming","family":"Zhou","sequence":"additional","affiliation":[{"name":"China National Salt Industry Group Co., Ltd., Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhangpu","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tao","family":"Jing","sequence":"additional","affiliation":[{"name":"Office of General Affairs, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,2,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"ACM","author":"Abu Rajab Moheeb","year":"2006","unstructured":"Abu Rajab , Moheeb , et al. \" A multifaceted approach to understanding the botnet phenomenon.\" Proceedings of the 6th ACM SIGCOMM conference on Internet measurement . ACM , 2006 . Abu Rajab, Moheeb, et al. \"A multifaceted approach to understanding the botnet phenomenon.\" Proceedings of the 6th ACM SIGCOMM conference on Internet measurement. ACM, 2006."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/997150.997156"},{"key":"e_1_3_2_1_3_1","volume-title":"Detecting botnet command and control channels in network traffic","author":"Gu Guofei","year":"2008","unstructured":"Gu , Guofei , Junjie Zhang , and Wenke Lee . \" BotSniffer : Detecting botnet command and control channels in network traffic .\" ( 2008 ). Gu, Guofei, Junjie Zhang, and Wenke Lee. \"BotSniffer: Detecting botnet command and control channels in network traffic.\" (2008)."},{"key":"e_1_3_2_1_4_1","volume-title":"ACM","author":"Tegeler Florian","year":"2012","unstructured":"Tegeler , Florian , et al. \" Botfinder : Finding bots in network traffic without deep packet inspection.\" Proceedings of the 8th international conference on Emerging networking experiments and technologies . ACM , 2012 . Tegeler, Florian, et al. \"Botfinder: Finding bots in network traffic without deep packet inspection.\" Proceedings of the 8th international conference on Emerging networking experiments and technologies. ACM, 2012."},{"key":"e_1_3_2_1_5_1","volume-title":"ACM","author":"Bilge Leyla","year":"2012","unstructured":"Bilge , Leyla , et al. \" Disclosure : detecting botnet command and control servers through large-scale netflow analysis.\" Proceedings of the 28th Annual Computer Security Applications Conference . ACM , 2012 . Bilge, Leyla, et al. \"Disclosure: detecting botnet command and control servers through large-scale netflow analysis.\" Proceedings of the 28th Annual Computer Security Applications Conference. ACM, 2012."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.04.007"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2012.06.019"},{"key":"e_1_3_2_1_8_1","volume-title":"Mining for new c&c domains in live networks with adaptive control protocol templates.\" Presented as part of the 22nd USENIX Security Symposium (USENIX Security 13)","author":"Nelms Terry","year":"2013","unstructured":"Nelms , Terry , Roberto Perdisci , and Mustaque Ahamad . \" Execscent : Mining for new c&c domains in live networks with adaptive control protocol templates.\" Presented as part of the 22nd USENIX Security Symposium (USENIX Security 13) . 2013 . Nelms, Terry, Roberto Perdisci, and Mustaque Ahamad. \"Execscent: Mining for new c&c domains in live networks with adaptive control protocol templates.\" Presented as part of the 22nd USENIX Security Symposium (USENIX Security 13). 2013."},{"volume-title":"Snort: Lightweight intrusion detection for networks[C]\/\/Lisa","year":"1999","key":"e_1_3_2_1_9_1","unstructured":"Roesch M. Snort: Lightweight intrusion detection for networks[C]\/\/Lisa . 1999 , 99(1): 229--238. Roesch M. Snort: Lightweight intrusion detection for networks[C]\/\/Lisa. 1999, 99(1): 229--238."},{"issue":"2","key":"e_1_3_2_1_10_1","first-page":"64","article-title":"The Study of Bro: a System for Detecting Network Intruder in Real-time[J]","volume":"22","author":"Wei TENG","year":"2005","unstructured":"ZHAO Yu-ming,ZHANG Wei , TENG Shao-hua . The Study of Bro: a System for Detecting Network Intruder in Real-time[J] . Journal of Guangdong University of Technology , 2005 , 22 ( 2 ): 64 -- 68 . ZHAO Yu-ming,ZHANG Wei,TENG Shao-hua. The Study of Bro: a System for Detecting Network Intruder in Real-time[J]. Journal of Guangdong University of Technology, 2005, 22(2): 64--68.","journal-title":"Journal of Guangdong University of Technology"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2014.2364743"},{"key":"e_1_3_2_1_12_1","volume-title":"IEEE","author":"Wang Wei","year":"2017","unstructured":"Wang , Wei , et al. \" Malware traffic classification using convolutional neural network for representation learning.\" 2017 International Conference on Information Networking (ICOIN) . IEEE , 2017 . Wang, Wei, et al. \"Malware traffic classification using convolutional neural network for representation learning.\" 2017 International Conference on Information Networking (ICOIN). IEEE, 2017."},{"key":"e_1_3_2_1_13_1","article-title":"Botcatcher: botnet detection system based on deep learning","author":"Di F. Binxing","year":"2018","unstructured":"W. U. Di , F. Binxing , C. Xiang , and L. Qixu , \" Botcatcher: botnet detection system based on deep learning ,\" Journal on Communications , 2018 . W. U. Di, F. Binxing, C. Xiang, and L. Qixu, \"Botcatcher: botnet detection system based on deep learning,\" Journal on Communications, 2018.","journal-title":"Journal on Communications"},{"key":"e_1_3_2_1_14_1","volume-title":"Support vector method for novelty detection.\" Advances in neural information processing systems","author":"Sch\u00f6lkopf Bernhard","year":"2000","unstructured":"Sch\u00f6lkopf , Bernhard , et al. \" Support vector method for novelty detection.\" Advances in neural information processing systems . 2000 . Sch\u00f6lkopf, Bernhard, et al. \"Support vector method for novelty detection.\" Advances in neural information processing systems. 2000."},{"key":"e_1_3_2_1_15_1","volume-title":"IEEE","author":"Aygun R. Can","year":"2017","unstructured":"Aygun , R. Can , and A. Gokhan Yavuz . \" Network anomaly detection with stochastically improved autoencoder based models.\" 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud) . IEEE , 2017 . Aygun, R. Can, and A. Gokhan Yavuz. \"Network anomaly detection with stochastically improved autoencoder based models.\" 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud). IEEE, 2017."},{"key":"e_1_3_2_1_16_1","volume-title":"Kitsune: an ensemble of autoencoders for online network intrusion detection.\" arXiv preprint arXiv:1802.09089","author":"Mirsky Yisroel","year":"2018","unstructured":"Mirsky , Yisroel , et al. \" Kitsune: an ensemble of autoencoders for online network intrusion detection.\" arXiv preprint arXiv:1802.09089 ( 2018 ). Mirsky, Yisroel, et al. \"Kitsune: an ensemble of autoencoders for online network intrusion detection.\" arXiv preprint arXiv:1802.09089 (2018)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Garcia Sebastian et al. \"An empirical comparison of botnet detection methods.\" computers & security 45 (2014): 100--123.  Garcia Sebastian et al. \"An empirical comparison of botnet detection methods.\" computers & security 45 (2014): 100--123.","DOI":"10.1016\/j.cose.2014.05.011"},{"key":"e_1_3_2_1_18_1","volume-title":"Deep learning with Keras","author":"Gulli Antonio","year":"2017","unstructured":"Gulli , Antonio , and Sujit Pal . Deep learning with Keras . Packt Publishing Ltd , 2017 . Gulli, Antonio, and Sujit Pal. Deep learning with Keras. Packt Publishing Ltd, 2017."}],"event":{"name":"ICCSP 2020: 2020 4th International Conference on Cryptography, Security and Privacy","sponsor":["NJU Nanjing University"],"location":"Nanjing China","acronym":"ICCSP 2020"},"container-title":["Proceedings of the 2020 4th International Conference on Cryptography, Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377644.3377652","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3377644.3377652","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:53Z","timestamp":1750203893000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377644.3377652"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,1,10]]},"references-count":18,"alternative-id":["10.1145\/3377644.3377652","10.1145\/3377644"],"URL":"https:\/\/doi.org\/10.1145\/3377644.3377652","relation":{},"subject":[],"published":{"date-parts":[[2020,1,10]]},"assertion":[{"value":"2020-02-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}