{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T19:01:12Z","timestamp":1768417272797,"version":"3.49.0"},"reference-count":78,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2021,7,16]],"date-time":"2021-07-16T00:00:00Z","timestamp":1626393600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2021,11,30]]},"abstract":"<jats:p>Modern network infrastructures host converged applications that demand rapid elasticity of services, increased security, and ultra-fast reaction times. The Tactile Internet promises to facilitate the delivery of these services while enabling new economies of scale for high fidelity of machine-to-machine and human-to-machine interactions. Unavoidably, critical mission systems served by the Tactile Internet manifest high demands not only for high speed and reliable communications but equally, the ability to rapidly identify and mitigate threats and vulnerabilities. This article proposes a novel Multi-Agent Data Exfiltration Detector Architecture (MADEX), inspired by the mechanisms and features present in the human immune system. MADEX seeks to identify data exfiltration activities performed by evasive and stealthy malware that hides malicious traffic from an infected host in low-latency networks. Our approach uses cross-network traffic information collected by agents to effectively identify unknown illicit connections by an operating system subverted. MADEX does not require prior knowledge of the characteristics or behavior of the malicious code or a dedicated access to a knowledge repository. We tested the performance of MADEX in terms of its capacity to handle real-time data and the sensitivity of our algorithm\u2019s classification when exposed to malicious traffic. Experimental evaluation results show that MADEX achieved 99.97% sensitivity, 98.78% accuracy, and an error rate of 1.21% when compared to its best rivals. We created a second version of MADEX, called MADEX level 2, that further improves its overall performance with a slight increase in computational complexity. We argue for the suitability of MADEX level 1 in non-critical environments, while MADEX level 2 can be used to avoid data exfiltration in critical mission systems. To the best of our knowledge, this is the first article in the literature that addresses the detection of rootkits real-time in an agnostic way using an artificial immune system approach while it satisfies strict latency requirements.<\/jats:p>","DOI":"10.1145\/3419103","type":"journal-article","created":{"date-parts":[[2021,7,16]],"date-time":"2021-07-16T15:01:57Z","timestamp":1626447717000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["A Flow-based Multi-agent Data Exfiltration Detection Architecture for Ultra-low Latency Networks"],"prefix":"10.1145","volume":"21","author":[{"given":"Rafael Salema","family":"Marques","sequence":"first","affiliation":[{"name":"University of Wolverhampton, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gregory","family":"Epiphaniou","sequence":"additional","affiliation":[{"name":"Warwick Manufacturing Group (WMG), University of Warwick, Coventry, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haider","family":"Al-Khateeb","sequence":"additional","affiliation":[{"name":"University of Wolverhampton, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carsten","family":"Maple","sequence":"additional","affiliation":[{"name":"Warwick Manufacturing Group (WMG), University of Warwick, Coventry, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Hammoudeh","sequence":"additional","affiliation":[{"name":"Manchester Metropolitan University, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paulo Andr\u00e9 Lima","family":"De Castro","sequence":"additional","affiliation":[{"name":"Aeronautics Institute of Technology (ITA), Brazil"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[{"name":"University of Guelph, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kim Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[{"name":"University of Texas at San Antonio, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,7,16]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"A. K. Abbas A. H. H. Lichtman and S. Pillai. 2017. Cellular and Molecular Immunology E-Book. Elsevier Health Sciences. Retrieved from https:\/\/books.google.co.uk\/books?id=L4FUDgAAQBAJ.  A. K. Abbas A. H. H. Lichtman and S. Pillai. 2017. Cellular and Molecular Immunology E-Book. Elsevier Health Sciences. Retrieved from https:\/\/books.google.co.uk\/books?id=L4FUDgAAQBAJ."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3015135.3015138"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.07.001"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2018.2878265"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2016.11.018"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2866962"},{"key":"e_1_2_1_7_1","volume-title":"DeepDCA: Novel network-based detection of IoT attacks using artificial immune system. Appl. Sci. 10 (03","author":"Aldhaheri Sahar","year":"2020","unstructured":"Sahar Aldhaheri , Daniyal Alghazzawi , Li Cheng , Bander Alzahrani , and Abdullah Al-Barakati . 2020. DeepDCA: Novel network-based detection of IoT attacks using artificial immune system. Appl. Sci. 10 (03 2020 ), 1909. DOI:DOI:https:\/\/doi.org\/10.3390\/app10061909 10.3390\/app10061909 Sahar Aldhaheri, Daniyal Alghazzawi, Li Cheng, Bander Alzahrani, and Abdullah Al-Barakati. 2020. DeepDCA: Novel network-based detection of IoT attacks using artificial immune system. Appl. Sci. 10 (03 2020), 1909. DOI:DOI:https:\/\/doi.org\/10.3390\/app10061909"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3102304.3102326"},{"key":"#cr-split#-e_1_2_1_9_1.1","doi-asserted-by":"crossref","unstructured":"Shahram Behzad. 2018. An artificial immune based approach for detection and isolation misbehavior attacks in wireless networks. J. Comput. (2018) 705-720. DOI:DOI:https:\/\/doi.org\/10.17706\/jcp.13.6.705-720 10.17706\/jcp.13.6.705-720","DOI":"10.17706\/jcp.13.6.705-720"},{"key":"#cr-split#-e_1_2_1_9_1.2","doi-asserted-by":"crossref","unstructured":"Shahram Behzad. 2018. An artificial immune based approach for detection and isolation misbehavior attacks in wireless networks. J. Comput. (2018) 705-720. DOI:DOI:https:\/\/doi.org\/10.17706\/jcp.13.6.705-720","DOI":"10.17706\/jcp.13.6.705-720"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the IEEE Military Communications Conference. 330\u2013335","author":"Celik Z. Berkay","year":"2015","unstructured":"Z. Berkay Celik , R. J. Walls , P. McDaniel , and A. Swami . 2015. Malware traffic detection using tamper resistant features . In Proceedings of the IEEE Military Communications Conference. 330\u2013335 . DOI:DOI:https:\/\/doi.org\/10.1109\/MILCOM. 2015 .7357464 10.1109\/MILCOM.2015.7357464 Z. Berkay Celik, R. J. Walls, P. McDaniel, and A. Swami. 2015. Malware traffic detection using tamper resistant features. In Proceedings of the IEEE Military Communications Conference. 330\u2013335. DOI:DOI:https:\/\/doi.org\/10.1109\/MILCOM.2015.7357464"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23829-6_13"},{"key":"e_1_2_1_12_1","article-title":"Intrusion detection and countermeasure of virtual cloud systems-state of the art and current challenges","volume":"6","author":"Carlin Andrew","year":"2015","unstructured":"Andrew Carlin , Mohammad Hammoudeh , and Omar Aldabbas . 2015 . Intrusion detection and countermeasure of virtual cloud systems-state of the art and current challenges . Int. J. Adv. Comput. Sci. Applic. 6 , 6 (2015). Andrew Carlin, Mohammad Hammoudeh, and Omar Aldabbas. 2015. Intrusion detection and countermeasure of virtual cloud systems-state of the art and current challenges. Int. J. Adv. Comput. Sci. Applic. 6, 6 (2015).","journal-title":"Int. J. Adv. Comput. Sci. Applic."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2013.05.002"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-012-0366-8"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/3375069.3375093"},{"key":"e_1_2_1_16_1","volume-title":"Advances in Communication Networking","author":"\u010cerm\u00e1k Milan","unstructured":"Milan \u010cerm\u00e1k , Pavel \u010celeda , and Jan Vykopal . 2014. Detection of DNS traffic anomalies in large networks . In Advances in Communication Networking , Yvon Kermarrec (Ed.). Springer International Publishing , Cham , 215\u2013226. Milan \u010cerm\u00e1k, Pavel \u010celeda, and Jan Vykopal. 2014. Detection of DNS traffic anomalies in large networks. In Advances in Communication Networking, Yvon Kermarrec (Ed.). Springer International Publishing, Cham, 215\u2013226."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2019.01.002"},{"key":"#cr-split#-e_1_2_1_18_1.1","doi-asserted-by":"crossref","unstructured":"Jiageng Chen Chunhua Su Kuo-Hui Yeh and Moti Yung. 2018. Special Issue on Advanced Persistent Threat. https:\/\/doi.org\/10.1016\/j.future.2017.11.005 10.1016\/j.future.2017.11.005","DOI":"10.1016\/j.future.2017.11.005"},{"key":"#cr-split#-e_1_2_1_18_1.2","doi-asserted-by":"crossref","unstructured":"Jiageng Chen Chunhua Su Kuo-Hui Yeh and Moti Yung. 2018. Special Issue on Advanced Persistent Threat. https:\/\/doi.org\/10.1016\/j.future.2017.11.005","DOI":"10.1016\/j.future.2017.11.005"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"B. Claise B. Trammell and P. Aitken. 2013. Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information. RFC 7011 (Internet Standard). Retrieved from https:\/\/www.ietf.org\/rfc\/rfc7011.txt.  B. Claise B. Trammell and P. Aitken. 2013. Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information. RFC 7011 (Internet Standard). Retrieved from https:\/\/www.ietf.org\/rfc\/rfc7011.txt.","DOI":"10.17487\/rfc7015"},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the 2nd International Conference on Multi-agent Systems (ICMAS\u201996)","author":"Collinot Anne","year":"1996","unstructured":"Anne Collinot , Alexis Drogoul , and Philippe Benhamou . 1996 . Agent oriented design of a soccer robot team . In Proceedings of the 2nd International Conference on Multi-agent Systems (ICMAS\u201996) . 41\u201347. Anne Collinot, Alexis Drogoul, and Philippe Benhamou. 1996. Agent oriented design of a soccer robot team. In Proceedings of the 2nd International Conference on Multi-agent Systems (ICMAS\u201996). 41\u201347."},{"key":"e_1_2_1_21_1","volume-title":"Suteresu: An LKM rootkit targeting Linux 2.6\/3.x on x86(64), and ARM.","author":"Coppola Michael","year":"2020","unstructured":"Michael Coppola . 2013. Accessed 14 Apr . 2020 . Suteresu: An LKM rootkit targeting Linux 2.6\/3.x on x86(64), and ARM. Retrieved from https:\/\/github.com\/mncoppola. Michael Coppola. 2013. Accessed 14 Apr. 2020. Suteresu: An LKM rootkit targeting Linux 2.6\/3.x on x86(64), and ARM. Retrieved from https:\/\/github.com\/mncoppola."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.8"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/579419"},{"key":"e_1_2_1_24_1","volume-title":"Law 1: Attackers will Always Find Their Way","author":"Diehl Eric","unstructured":"Eric Diehl . 2016. Law 1: Attackers will Always Find Their Way . Springer International Publishing , Cham , 1\u201343. DOI:DOI:https:\/\/doi.org\/10.1007\/978-3-319-42641-9_1 10.1007\/978-3-319-42641-9_1 Eric Diehl. 2016. Law 1: Attackers will Always Find Their Way. Springer International Publishing, Cham, 1\u201343. DOI:DOI:https:\/\/doi.org\/10.1007\/978-3-319-42641-9_1"},{"key":"e_1_2_1_25_1","doi-asserted-by":"crossref","unstructured":"El-Sayed M. El-Alfy. 2019. Nature-inspired Cyber Security and Resiliency: Fundamentals Techniques and Applications.Institution of Engineering and Technology. https:\/\/books.google.co.uk\/books\/about\/Nature_Inspired_Cyber_Security_and_Resil.html?id=vzqUDwAAQBAJ&source=kp_book_description&redir_esc=y.   El-Sayed M. El-Alfy. 2019. Nature-inspired Cyber Security and Resiliency: Fundamentals Techniques and Applications.Institution of Engineering and Technology. https:\/\/books.google.co.uk\/books\/about\/Nature_Inspired_Cyber_Security_and_Resil.html?id=vzqUDwAAQBAJ&source=kp_book_description&redir_esc=y.","DOI":"10.1049\/PBSE010E"},{"key":"#cr-split#-e_1_2_1_26_1.1","doi-asserted-by":"crossref","unstructured":"G. Epiphaniou P. Pillai M. Bottarelli H. Al-Khateeb M. Hammoudeh and C. Maple. 2020. Electronic regulation of data sharing and processing using smart ledger technologies for supply-chain security. IEEE Trans. Eng. Manag. (2020) 1-15. https:\/\/doi.org\/10.1109\/TEM.2020.2987113 10.1109\/TEM.2020.2987113","DOI":"10.1109\/TEM.2020.2987113"},{"key":"#cr-split#-e_1_2_1_26_1.2","doi-asserted-by":"crossref","unstructured":"G. Epiphaniou P. Pillai M. Bottarelli H. Al-Khateeb M. Hammoudeh and C. Maple. 2020. Electronic regulation of data sharing and processing using smart ledger technologies for supply-chain security. IEEE Trans. Eng. Manag. (2020) 1-15. https:\/\/doi.org\/10.1109\/TEM.2020.2987113","DOI":"10.1109\/TEM.2020.2987113"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-2789(81)90072-5"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2017.06.007"},{"key":"e_1_2_1_29_1","unstructured":"Martin Fischer. 2017. Accessed 14 Apr. 2020. r77 Rootkit: Ring 3 Rootkit DLL. Retrieved from https:\/\/github.com\/bytecode77\/r77-rootkit.  Martin Fischer. 2017. Accessed 14 Apr. 2020. r77 Rootkit: Ring 3 Rootkit DLL. Retrieved from https:\/\/github.com\/bytecode77\/r77-rootkit."},{"key":"e_1_2_1_30_1","volume-title":"Nonvolatile kernel rootkit detection using cross-view clean boot in cloud computing. Concurr. Computat.: Pract. Exper. 33, 3","author":"Geetha Ramani R.","year":"2019","unstructured":"R. Geetha Ramani and S. Suresh Kumar . 2019. Nonvolatile kernel rootkit detection using cross-view clean boot in cloud computing. Concurr. Computat.: Pract. Exper. 33, 3 ( 2019 ). https:\/\/browzine.com\/libraries\/1684\/journals\/12613\/issues\/379973128?showArticleInContext=doi%3A10.1002%2Fcpe.5239. R. Geetha Ramani and S. Suresh Kumar. 2019. Nonvolatile kernel rootkit detection using cross-view clean boot in cloud computing. Concurr. Computat.: Pract. Exper. 33, 3 (2019). https:\/\/browzine.com\/libraries\/1684\/journals\/12613\/issues\/379973128?showArticleInContext=doi%3A10.1002%2Fcpe.5239."},{"key":"e_1_2_1_31_1","unstructured":"Giovanni Giacobbi. 1995. Accessed 14 Apr. 2020. The GNU netCat Project. Retrieved from https:\/\/seclists.org\/bugtraq\/1995\/Oct\/28.  Giovanni Giacobbi. 1995. Accessed 14 Apr. 2020. The GNU netCat Project. Retrieved from https:\/\/seclists.org\/bugtraq\/1995\/Oct\/28."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85072-4_26"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/11536444_12"},{"key":"e_1_2_1_35_1","volume-title":"Robust Intelligent Systems","author":"Greensmith Julie","unstructured":"Julie Greensmith , Uwe Aickelin , and Steve Cayzer . 2008. Detecting danger: The dendritic cell algorithm . In Robust Intelligent Systems . Springer Publishing Company , London , 89\u2013112. Retrieved from http:\/\/eprints.nottingham.ac.uk\/987\/. Julie Greensmith, Uwe Aickelin, and Steve Cayzer. 2008. Detecting danger: The dendritic cell algorithm. In Robust Intelligent Systems. Springer Publishing Company, London, 89\u2013112. Retrieved from http:\/\/eprints.nottingham.ac.uk\/987\/."},{"key":"e_1_2_1_36_1","unstructured":"Julie Greensmith Uwe Aickelin and Gianni Tedesco. 2007. Information fusion for anomaly detection with the dendritic cell algorithm. Inf. Fus. Retrieved from http:\/\/eprints.nottingham.ac.uk\/570\/.  Julie Greensmith Uwe Aickelin and Gianni Tedesco. 2007. Information fusion for anomaly detection with the dendritic cell algorithm. Inf. Fus. Retrieved from http:\/\/eprints.nottingham.ac.uk\/570\/."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1002\/wcm.1139"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.3390\/s150922970"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/JCN.2016.000110"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.3390\/app9071402"},{"key":"e_1_2_1_41_1","volume-title":"DIGITAL 2019: GLOBAL DIGITAL OVERVIEW.","author":"Kemp Simon","year":"2019","unstructured":"Simon Kemp . 2019 . Accessed 13 Jun. 2019 . DIGITAL 2019: GLOBAL DIGITAL OVERVIEW. Retrieved from https:\/\/datareportal.com\/reports\/digital-2019-global-digital-overview. Simon Kemp. 2019. Accessed 13 Jun. 2019. DIGITAL 2019: GLOBAL DIGITAL OVERVIEW. Retrieved from https:\/\/datareportal.com\/reports\/digital-2019-global-digital-overview."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-13-1165-9_1"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.3991\/ijoe.v14i09.8625"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2019.407"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.iy.12.040194.005015"},{"key":"e_1_2_1_46_1","volume-title":"Machine learning aided Android malware classification. Comput. Electric. Eng. (7","author":"Milosevic Nikola","year":"2017","unstructured":"Nikola Milosevic , Ali Dehghantanha , and Kim-Kwang Raymond Choo . 2017. Machine learning aided Android malware classification. Comput. Electric. Eng. (7 2017 ). DOI:DOI:https:\/\/doi.org\/10.1016\/j.compeleceng.2017.02.013 10.1016\/j.compeleceng.2017.02.013 Nikola Milosevic, Ali Dehghantanha, and Kim-Kwang Raymond Choo. 2017. Machine learning aided Android malware classification. Comput. Electric. Eng. (7 2017). DOI:DOI:https:\/\/doi.org\/10.1016\/j.compeleceng.2017.02.013"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2014.08.030"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2337256"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2014.25"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12065-008-0011-y"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.23919\/INM.2017.7987293"},{"key":"e_1_2_1_52_1","unstructured":"Ilias Raftopoulos. 2014. Extrusion Detection: Monitoring Detecting and Characterizing Internal Infections. Ph.D. Dissertation. ETH Zurich.  Ilias Raftopoulos. 2014. Extrusion Detection: Monitoring Detecting and Characterizing Internal Infections. Ph.D. Dissertation. ETH Zurich."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSEngT.2016.7849626"},{"key":"#cr-split#-e_1_2_1_54_1.1","doi-asserted-by":"crossref","unstructured":"P. Keerthi Reddy G. Soniya and K. Ramya Sree. 2019. A novel approach for intrusion detection and prevention system. (2019). https:\/\/doi.org\/10.32628\/CSEIT1952320 10.32628\/CSEIT1952320","DOI":"10.32628\/CSEIT1952320"},{"key":"#cr-split#-e_1_2_1_54_1.2","doi-asserted-by":"crossref","unstructured":"P. Keerthi Reddy G. Soniya and K. Ramya Sree. 2019. A novel approach for intrusion detection and prevention system. (2019). https:\/\/doi.org\/10.32628\/CSEIT1952320","DOI":"10.32628\/CSEIT1952320"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2016.2636078"},{"key":"e_1_2_1_56_1","unstructured":"Packet Storm Security. Accessed 14 Apr. 2020. cb-r00tkit Rootkit. Retrieved from https:\/\/packetstormsecurity.com\/files\/29877\/cb-r00tkit.tgz.html.  Packet Storm Security. Accessed 14 Apr. 2020. cb-r00tkit Rootkit. Retrieved from https:\/\/packetstormsecurity.com\/files\/29877\/cb-r00tkit.tgz.html."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2014.06.022"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2014.03.012"},{"key":"e_1_2_1_59_1","first-page":"745","article-title":"Systems and methods for cyber intrusion detection and prevention","volume":"16","author":"Smith Benjamin","year":"2019","unstructured":"Benjamin Smith , Mohan Rao , Sylvian Crozon , and Niranjan Mayya . 2019 . Systems and methods for cyber intrusion detection and prevention . US Patent App. 16\/120 , 745 . Benjamin Smith, Mohan Rao, Sylvian Crozon, and Niranjan Mayya. 2019. Systems and methods for cyber intrusion detection and prevention. US Patent App. 16\/120,745.","journal-title":"US Patent App."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.5815\/ijeme.2018.02.03"},{"key":"e_1_2_1_61_1","volume-title":"Computer Networks","author":"Tanenbaum Andrew S.","unstructured":"Andrew S. Tanenbaum . 2014. Computer Networks ( 5 th ed.), Andrew S. Tanenbaum, David J. Wetherall, Eds.). Pearson, Harlow, Essex . Andrew S. Tanenbaum. 2014. Computer Networks (5th ed.), Andrew S. Tanenbaum, David J. Wetherall, Eds.). Pearson, Harlow, Essex.","edition":"5"},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of the IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS\u201917)","author":"Tayal A.","year":"2017","unstructured":"A. Tayal , N. Hubballi , and N. Tripathi . 2017. Communication recurrence and similarity detection in network flows . In Proceedings of the IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS\u201917) . 1\u20136. DOI:DOI:https:\/\/doi.org\/10.1109\/ANTS. 2017 .8384174 10.1109\/ANTS.2017.8384174 A. Tayal, N. Hubballi, and N. Tripathi. 2017. Communication recurrence and similarity detection in network flows. In Proceedings of the IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS\u201917). 1\u20136. DOI:DOI:https:\/\/doi.org\/10.1109\/ANTS.2017.8384174"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2928060"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.05.009"},{"key":"e_1_2_1_65_1","volume-title":"\u201cBlue pill","author":"Vaas Lisa","year":"2007","unstructured":"Lisa Vaas . 2007. Researchers: \u201cBlue pill \u201d rootkit detectable (security researcher working on hypervisor rootkit detection). eWeek ( 2007 ). https:\/\/www.eweek.com\/security\/researchers-blue-pill-rootkit-detectable\/. Lisa Vaas. 2007. Researchers: \u201cBlue pill\u201d rootkit detectable (security researcher working on hypervisor rootkit detection). eWeek (2007). https:\/\/www.eweek.com\/security\/researchers-blue-pill-rootkit-detectable\/."},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOMMST.2014.6992342"},{"key":"e_1_2_1_67_1","volume-title":"Threats on the horizon: Understanding security threats in the era of cyber-physical systems. J. Supercomput. (24","author":"Walker-Roberts Steven","year":"2019","unstructured":"Steven Walker-Roberts , Mohammad Hammoudeh , Omar Aldabbas , Mehmet Aydin , and Ali Dehghantanha . 2019. Threats on the horizon: Understanding security threats in the era of cyber-physical systems. J. Supercomput. (24 Oct. 2019 ). DOI:DOI:https:\/\/doi.org\/10.1007\/s11227-019-03028-9 10.1007\/s11227-019-03028-9 Steven Walker-Roberts, Mohammad Hammoudeh, Omar Aldabbas, Mehmet Aydin, and Ali Dehghantanha. 2019. Threats on the horizon: Understanding security threats in the era of cyber-physical systems. J. Supercomput. (24 Oct. 2019). DOI:DOI:https:\/\/doi.org\/10.1007\/s11227-019-03028-9"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIME.2010.5478178"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.pmcj.2019.02.004"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.5555\/25201.25227"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.5555\/1695886"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1017\/S0269888900008122"},{"key":"#cr-split#-e_1_2_1_73_1.1","doi-asserted-by":"crossref","unstructured":"Meriem Zekri and Labiba Souici-Meslati. 2014. Immunological approach for intrusion detection. https:\/\/doi.org\/10.46298\/arima.1974 10.46298\/arima.1974","DOI":"10.46298\/arima.1974"},{"key":"#cr-split#-e_1_2_1_73_1.2","doi-asserted-by":"crossref","unstructured":"Meriem Zekri and Labiba Souici-Meslati. 2014. Immunological approach for intrusion detection. https:\/\/doi.org\/10.46298\/arima.1974","DOI":"10.46298\/arima.1974"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939918.2939923"}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3419103","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3419103","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:32:05Z","timestamp":1750195925000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3419103"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,16]]},"references-count":78,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,11,30]]}},"alternative-id":["10.1145\/3419103"],"URL":"https:\/\/doi.org\/10.1145\/3419103","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"value":"1533-5399","type":"print"},{"value":"1557-6051","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,16]]},"assertion":[{"value":"2020-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-07-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}