{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T02:07:56Z","timestamp":1769911676494,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":66,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T00:00:00Z","timestamp":1670198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["2127200"],"award-info":[{"award-number":["2127200"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,12,5]]},"DOI":"10.1145\/3564625.3564649","type":"proceedings-article","created":{"date-parts":[[2022,12,3]],"date-time":"2022-12-03T01:01:29Z","timestamp":1670029289000},"page":"251-266","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["A Recent Year On the Internet: Measuring and Understanding the Threats to Everyday Internet Devices"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1449-3590","authenticated-orcid":false,"given":"Afsah","family":"Anwar","sequence":"first","affiliation":[{"name":"Khoury College of Computer Sciences, Northeastern University, USA and Computer and Information Sciences, Florida A&amp;M University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1588-9108","authenticated-orcid":false,"given":"Yi Hui","family":"Chen","sequence":"additional","affiliation":[{"name":"Khoury College of Computer Sciences, Northeastern University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9879-2370","authenticated-orcid":false,"given":"Roy","family":"Hodgman","sequence":"additional","affiliation":[{"name":"Rapid 7, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3178-2725","authenticated-orcid":false,"given":"Tom","family":"Sellers","sequence":"additional","affiliation":[{"name":"runZero, Bosnia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9988-6873","authenticated-orcid":false,"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Khoury College of Computer Sciences, Northeastern University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4979-5292","authenticated-orcid":false,"given":"Alina","family":"Oprea","sequence":"additional","affiliation":[{"name":"Khoury College of Computer Sciences, Northeastern University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,12,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Developers @\u00a0Rapid 7. 2022. An Introduction to Project Heisenberg. Available at [Online]: https:\/\/www.rapid7.com\/research\/project-heisenberg\/. (2022).  Developers @\u00a0Rapid 7. 2022. An Introduction to Project Heisenberg. Available at [Online]: https:\/\/www.rapid7.com\/research\/project-heisenberg\/. (2022)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ATNAC.2009.5464785"},{"key":"e_1_3_2_1_3_1","unstructured":"ISO 3166\u00a0Maintenance Agency. 2022. ISO 3166 Country Codes. Available at [Online]: https:\/\/www.iso.org\/iso-3166-country-codes.html. (2022).  ISO 3166\u00a0Maintenance Agency. 2022. ISO 3166 Country Codes. Available at [Online]: https:\/\/www.iso.org\/iso-3166-country-codes.html. (2022)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/EDCC.2006.17"},{"key":"e_1_3_2_1_5_1","unstructured":"Mark Allman Ethan Blanton Vern Paxson and Scott Shenker. 2006. Fighting coordinated attackers with cross-organizational information sharing. IRVINE IS BURNING 121(2006).  Mark Allman Ethan Blanton Vern Paxson and Scott Shenker. 2006. Fighting coordinated attackers with cross-organizational information sharing. IRVINE IS BURNING 121(2006)."},{"key":"e_1_3_2_1_6_1","volume-title":"The Circle Of Life: A Large-Scale Study of The IoT Malware Lifecycle. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Alrawi Omar","year":"2021","unstructured":"Omar Alrawi , Charles Lever , Kevin Valakuzhy , Ryan Court , Kevin Snow , Fabian Monrose , and Manos Antonakakis . 2021 . The Circle Of Life: A Large-Scale Study of The IoT Malware Lifecycle. In 30th USENIX Security Symposium (USENIX Security 21) . Omar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court, Kevin Snow, Fabian Monrose, and Manos Antonakakis. 2021. The Circle Of Life: A Large-Scale Study of The IoT Malware Lifecycle. In 30th USENIX Security Symposium (USENIX Security 21)."},{"key":"e_1_3_2_1_7_1","volume-title":"Understanding the Mirai Botnet. In USENIX Security Symposium. 1093\u20131110","author":"Antonakakis Manos","year":"2017","unstructured":"Manos Antonakakis , Tim April , Michael Bailey , Matt Bernhard , Elie Bursztein , Jaime Cochran , Zakir Durumeric , J.\u00a0 Alex Halderman , Luca Invernizzi , Michalis Kallitsis , Deepak Kumar , Chaz Lever , Zane Ma , Joshua Mason , Damian Menscher , Chad Seaman , Nick Sullivan , Kurt Thomas , and Yi Zhou . 2017 . Understanding the Mirai Botnet. In USENIX Security Symposium. 1093\u20131110 . Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J.\u00a0Alex Halderman, Luca Invernizzi, Michalis Kallitsis, Deepak Kumar, Chaz Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas, and Yi Zhou. 2017. Understanding the Mirai Botnet. In USENIX Security Symposium. 1093\u20131110."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61078-4_25"},{"key":"e_1_3_2_1_9_1","unstructured":"Afsah Anwar Jinchun Choi Abdulrahman Alabduljabbar Hisham Alasmary Jeffrey Spaulding An Wang Songqing Chen DaeHun Nyang Amro Awad and David Mohaisen. 2021. Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts. arXiv preprint arXiv:2103.14217(2021).  Afsah Anwar Jinchun Choi Abdulrahman Alabduljabbar Hisham Alasmary Jeffrey Spaulding An Wang Songqing Chen DaeHun Nyang Amro Awad and David Mohaisen. 2021. Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts. arXiv preprint arXiv:2103.14217(2021)."},{"key":"e_1_3_2_1_10_1","unstructured":"Avast. 2022. EternalBlue Exploit | MS17-010 Explained | Avast. Available at [Online]: https:\/\/www.avast.com\/c-eternalblue. (2022).  Avast. 2022. EternalBlue Exploit | MS17-010 Explained | Avast. Available at [Online]: https:\/\/www.avast.com\/c-eternalblue. (2022)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2006.286376"},{"key":"e_1_3_2_1_12_1","unstructured":"Michael Bailey Evan Cooke Farnam Jahanian Jose Nazario David Watson and others. 2005. The internet motion sensor-a distributed blackhole monitoring system.. In NDSS. Citeseer.  Michael Bailey Evan Cooke Farnam Jahanian Jose Nazario David Watson and others. 2005. The internet motion sensor-a distributed blackhole monitoring system.. In NDSS. Citeseer."},{"key":"e_1_3_2_1_13_1","unstructured":"World Bank. 2021. The World Bank: Indicators. (2021). https:\/\/data.worldbank.org\/indicator\/IT.NET.USER.ZS.  World Bank. 2021. The World Bank: Indicators. (2021). https:\/\/data.worldbank.org\/indicator\/IT.NET.USER.ZS."},{"key":"e_1_3_2_1_14_1","unstructured":"Ivan Belcic. 2022. The Zeus Trojan \u2014 What It Is and How to Remove and Prevent it. Available at [Online]: https:\/\/www.avast.com\/c-zeus. (2022).  Ivan Belcic. 2022. The Zeus Trojan \u2014 What It Is and How to Remove and Prevent it. Available at [Online]: https:\/\/www.avast.com\/c-zeus. (2022)."},{"key":"e_1_3_2_1_15_1","unstructured":"Greg Belding. 2020. Purple Fox malware: What it is how it works and how to prevent it. Available at [Online] : https:\/\/resources.infosecinstitute.com\/topic\/purple-fox-malware-what-it-is-how-it-works-how-to-prevent-it\/. (2020).  Greg Belding. 2020. Purple Fox malware: What it is how it works and how to prevent it. Available at [Online] : https:\/\/resources.infosecinstitute.com\/topic\/purple-fox-malware-what-it-is-how-it-works-how-to-prevent-it\/. (2020)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354230"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2008.62"},{"key":"e_1_3_2_1_18_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Buyukkayhan Ahmet\u00a0Salih","year":"2020","unstructured":"Ahmet\u00a0Salih Buyukkayhan , Can Gemicioglu , Tobias Lauinger , Alina Oprea , William Robertson , and Engin Kirda . 2020 . What\u2019s in an Exploit? An Empirical Analysis of Reflected Server {XSS} Exploitation Techniques . In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 107\u2013120. Ahmet\u00a0Salih Buyukkayhan, Can Gemicioglu, Tobias Lauinger, Alina Oprea, William Robertson, and Engin Kirda. 2020. What\u2019s in an Exploit? An Empirical Analysis of Reflected Server {XSS} Exploitation Techniques. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 107\u2013120."},{"key":"e_1_3_2_1_19_1","unstructured":"Catalin Cimpanu. 2019. New XBash malware combines ransomware coinminer botnet and worm features in deadly combo. Available at [Online]: https:\/\/tinyurl.com\/3d9wczsr. (2019).  Catalin Cimpanu. 2019. New XBash malware combines ransomware coinminer botnet and worm features in deadly combo. Available at [Online]: https:\/\/tinyurl.com\/3d9wczsr. (2019)."},{"key":"e_1_3_2_1_20_1","volume-title":"Understanding Linux Malware. In IEEE Symposium on Security & Privacy.","author":"Cozzi Emanuele","year":"2018","unstructured":"Emanuele Cozzi , Mariano Graziano , Yanick Fratantonio , and Davide Balzarotti . 2018 . Understanding Linux Malware. In IEEE Symposium on Security & Privacy. Emanuele Cozzi, Mariano Graziano, Yanick Fratantonio, and Davide Balzarotti. 2018. Understanding Linux Malware. In IEEE Symposium on Security & Privacy."},{"key":"e_1_3_2_1_21_1","volume-title":"Malware: Repositorio de Indicadores de Compromiso.","year":"2022","unstructured":"CronUp. 2022 . Malware: Repositorio de Indicadores de Compromiso. (2022). https:\/\/github.com\/CronUP\/Malware-IOCs. CronUp. 2022. Malware: Repositorio de Indicadores de Compromiso. (2022). https:\/\/github.com\/CronUP\/Malware-IOCs."},{"key":"e_1_3_2_1_22_1","volume-title":"https:\/\/github.com\/CyberMonitor\/APT_CyberCriminal_Campagin_Collections","author":"Cybercriminals Campaign Collection APT","year":"2022","unstructured":"CyberMonitor. 2022. APT & Cybercriminals Campaign Collection . ( 2022 ). https:\/\/github.com\/CyberMonitor\/APT_CyberCriminal_Campagin_Collections . CyberMonitor. 2022. APT & Cybercriminals Campaign Collection. (2022). https:\/\/github.com\/CyberMonitor\/APT_CyberCriminal_Campagin_Collections."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10772-6_3"},{"key":"e_1_3_2_1_24_1","unstructured":"Danielle\u00a0Desfosses David\u00a0Pany Steve\u00a0Miller. 2019. Bypassing Network Restrictions Through RDP Tunneling. Available at [Online]: https:\/\/www.mandiant.com\/resources\/bypassing-network-restrictions-through-rdp-tunneling. (2019).  Danielle\u00a0Desfosses David\u00a0Pany Steve\u00a0Miller. 2019. Bypassing Network Restrictions Through RDP Tunneling. Available at [Online]: https:\/\/www.mandiant.com\/resources\/bypassing-network-restrictions-through-rdp-tunneling. (2019)."},{"key":"e_1_3_2_1_25_1","unstructured":"Microsoft Documentation. 2021. IPC$ share and null session behavior in Windows. Available at [Online]: https:\/\/docs.microsoft.com\/en-us\/troubleshoot\/windows-server\/networking\/inter-process-communication-share-null-session. (2021).  Microsoft Documentation. 2021. IPC$ share and null session behavior in Windows. Available at [Online]: https:\/\/docs.microsoft.com\/en-us\/troubleshoot\/windows-server\/networking\/inter-process-communication-share-null-session. (2021)."},{"key":"e_1_3_2_1_26_1","unstructured":"Executemalware. 2022. IOCs from malware investigations. (2022). https:\/\/github.com\/executemalware\/Malware-IOCs.  Executemalware. 2022. IOCs from malware investigations. (2022). https:\/\/github.com\/executemalware\/Malware-IOCs."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Claude Fachkha Elias Bou-Harb Anastasis Keliris Nasir\u00a0D Memon and Mustaque Ahamad. 2017. Internet-scale Probing of CPS: Inference Characterization and Orchestration Analysis.. In NDSS.  Claude Fachkha Elias Bou-Harb Anastasis Keliris Nasir\u00a0D Memon and Mustaque Ahamad. 2017. Internet-scale Probing of CPS: Inference Characterization and Orchestration Analysis.. In NDSS.","DOI":"10.14722\/ndss.2017.23149"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243840"},{"key":"e_1_3_2_1_29_1","unstructured":"Amnesty International. 2021. Forensic Methodology Report: How to catch NSO Group\u2019s Pegasus. (2021). https:\/\/www.amnesty.org\/en\/latest\/research\/2021\/07\/forensic-methodology-report-how-to-catch-nso-groups-pegasus\/.  Amnesty International. 2021. Forensic Methodology Report: How to catch NSO Group\u2019s Pegasus. (2021). https:\/\/www.amnesty.org\/en\/latest\/research\/2021\/07\/forensic-methodology-report-how-to-catch-nso-groups-pegasus\/."},{"key":"e_1_3_2_1_30_1","unstructured":"James Kehr. 2020. SMB and Null Sessions: Why Your Pen Test is Probably Wrong. (2020). https:\/\/techcommunity.microsoft.com\/t5\/storage-at-microsoft\/smb-and-null-sessions-why-your-pen-test-is-probably-wrong\/ba-p\/1185365.  James Kehr. 2020. SMB and Null Sessions: Why Your Pen Test is Probably Wrong. (2020). https:\/\/techcommunity.microsoft.com\/t5\/storage-at-microsoft\/smb-and-null-sessions-why-your-pen-test-is-probably-wrong\/ba-p\/1185365."},{"key":"e_1_3_2_1_31_1","volume-title":"Conti Ransomware Group Diaries","author":"Krebs Brian","year":"2022","unstructured":"Brian Krebs . 2022. Conti Ransomware Group Diaries , Part II: The Office . ( 2022 ). https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-ii-the-office\/. Brian Krebs. 2022. Conti Ransomware Group Diaries, Part II: The Office. (2022). https:\/\/krebsonsecurity.com\/2022\/03\/conti-ransomware-group-diaries-part-ii-the-office\/."},{"key":"e_1_3_2_1_32_1","unstructured":"KrebsOnSecurity. 2016. Hacked Cameras DVRs Powered Today\u2019s Massive Internet Outage. Available at: https:\/\/krebsonsecurity.com\/2016\/10\/hacked-cameras-dvrs-powered-todays-massive-internet-outage\/. (2016).  KrebsOnSecurity. 2016. Hacked Cameras DVRs Powered Today\u2019s Massive Internet Outage. Available at: https:\/\/krebsonsecurity.com\/2016\/10\/hacked-cameras-dvrs-powered-todays-massive-internet-outage\/. (2016)."},{"key":"e_1_3_2_1_33_1","unstructured":"Gjoko\u00a0\u2019LiquidWorm\u2019 Krstic. 2020. Microhard Systems 3G\/4G Cellular Ethernet and Serial Gateway Configuration Download. Available at [Online]: https:\/\/www.exploit-db.com\/exploits\/45036. (2020).  Gjoko\u00a0\u2019LiquidWorm\u2019 Krstic. 2020. Microhard Systems 3G\/4G Cellular Ethernet and Serial Gateway Configuration Download. Available at [Online]: https:\/\/www.exploit-db.com\/exploits\/45036. (2020)."},{"key":"e_1_3_2_1_34_1","unstructured":"Don\u00a0Ovid Ladores Ian Kenefick and Earle\u00a0Maui Earnshaw. 2022. New Nokoyawa Ransomware Possibly Related to Hive. (2022). https:\/\/www.trendmicro.com\/en_us\/research\/22\/c\/nokoyawa-ransomware-possibly-related-to-hive-.html  Don\u00a0Ovid Ladores Ian Kenefick and Earle\u00a0Maui Earnshaw. 2022. New Nokoyawa Ransomware Possibly Related to Hive. (2022). https:\/\/www.trendmicro.com\/en_us\/research\/22\/c\/nokoyawa-ransomware-possibly-related-to-hive-.html"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/WISTDCS.2008.8"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2006.172"},{"key":"e_1_3_2_1_37_1","unstructured":"Metasploit. 2015. Realtek SDK - Miniigd UPnP SOAP Command Execution. (2015). https:\/\/www.exploit-db.com\/exploits\/37169.  Metasploit. 2015. Realtek SDK - Miniigd UPnP SOAP Command Execution. (2015). https:\/\/www.exploit-db.com\/exploits\/37169."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3229598.3229604"},{"key":"e_1_3_2_1_39_1","volume-title":"https:\/\/attack.mitre.org\/","author":"Enterprise MITRE.","year":"2022","unstructured":"MITRE. 2022. ATT&CK Matrix for Enterprise . ( 2022 ). https:\/\/attack.mitre.org\/ . MITRE. 2022. ATT&CK Matrix for Enterprise. (2022). https:\/\/attack.mitre.org\/."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2487788.2488056"},{"key":"e_1_3_2_1_41_1","unstructured":"Elizabeth Montalbano. 2021. Purple Fox Malware Targets Windows Machines With New Worm Capabilities. Available at [Online] : https:\/\/threatpost.com\/purple-fox-malware-windows-worm\/164993\/. (2021).  Elizabeth Montalbano. 2021. Purple Fox Malware Targets Windows Machines With New Worm Capabilities. Available at [Online] : https:\/\/threatpost.com\/purple-fox-malware-windows-worm\/164993\/. (2021)."},{"key":"e_1_3_2_1_42_1","unstructured":"Palo\u00a0Alto Networks. 2022. PAN Unit 42 iocs: indicators related to Unit 42 Public Reports. (2022). https:\/\/github.com\/pan-unit42\/iocs.  Palo\u00a0Alto Networks. 2022. PAN Unit 42 iocs: indicators related to Unit 42 Public Reports. (2022). https:\/\/github.com\/pan-unit42\/iocs."},{"key":"e_1_3_2_1_43_1","unstructured":"Lily\u00a0Hay Newman. 2018. GitHub Survived the Biggest DDoS Attack Ever Recorded. Available at [Online] : https:\/\/www.wired.com\/story\/github-ddos-memcached\/. (2018).  Lily\u00a0Hay Newman. 2018. GitHub Survived the Biggest DDoS Attack Ever Recorded. Available at [Online] : https:\/\/www.wired.com\/story\/github-ddos-memcached\/. (2018)."},{"key":"e_1_3_2_1_44_1","unstructured":"NIST. 2022. National Vulnerability Database. (2022). https:\/\/nvd.nist.gov\/.  NIST. 2022. National Vulnerability Database. (2022). https:\/\/nvd.nist.gov\/."},{"key":"e_1_3_2_1_45_1","unstructured":"NVD. 2001. CVE-2001-0540 Detail. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2001-0540. (2001).  NVD. 2001. CVE-2001-0540 Detail. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2001-0540. (2001)."},{"key":"e_1_3_2_1_46_1","unstructured":"NVD. 2022. CVE-2017-12615. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12615. (2022).  NVD. 2022. CVE-2017-12615. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12615. (2022)."},{"key":"e_1_3_2_1_47_1","unstructured":"NVD. 2022. CVE-2017-9805. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-9805. (2022).  NVD. 2022. CVE-2017-9805. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-9805. (2022)."},{"key":"e_1_3_2_1_48_1","unstructured":"NVD. 2022. CVE-2022-21893 Detail. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-21893. (2022).  NVD. 2022. CVE-2022-21893 Detail. Available at [Online]: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-21893. (2022)."},{"key":"e_1_3_2_1_49_1","unstructured":"The\u00a0Department of Justice. 2015. Cybersecurity Information Sharing ACT Of 2015 Procedures And Guidance. (2015). https:\/\/www.cisa.gov\/publication\/cybersecurity-information-sharing-act-2015-procedures-and-guidance.  The\u00a0Department of Justice. 2015. Cybersecurity Information Sharing ACT Of 2015 Procedures And Guidance. (2015). https:\/\/www.cisa.gov\/publication\/cybersecurity-information-sharing-act-2015-procedures-and-guidance."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.2197\/ipsjjip.24.522"},{"key":"e_1_3_2_1_51_1","unstructured":"Trine\u00a0Cecilia Peinert and Ingvild\u00a0Bye Giset. 2020. Analyzing the IoT Threat Landscape Within University Network Environments Using Honeypots. Master\u2019s thesis. NTNU.  Trine\u00a0Cecilia Peinert and Ingvild\u00a0Bye Giset. 2020. Analyzing the IoT Threat Landscape Within University Network Environments Using Honeypots. Master\u2019s thesis. NTNU."},{"key":"e_1_3_2_1_52_1","volume-title":"https:\/\/malpedia.caad.fkie.fraunhofer.de\/","author":"Plohmann Daniel","year":"2022","unstructured":"Daniel Plohmann and Steffen Enders . 2022. Malpedia. ( 2022 ). https:\/\/malpedia.caad.fkie.fraunhofer.de\/ . Daniel Plohmann and Steffen Enders. 2022. Malpedia. (2022). https:\/\/malpedia.caad.fkie.fraunhofer.de\/."},{"key":"e_1_3_2_1_53_1","unstructured":"ESET Research. 2022. Malware Indicators of Compromise. (2022). https:\/\/github.com\/eset\/malware-ioc.  ESET Research. 2022. Malware Indicators of Compromise. (2022). https:\/\/github.com\/eset\/malware-ioc."},{"key":"e_1_3_2_1_54_1","volume-title":"Amplification Hell: Revisiting Network Protocols for DDoS Abuse.. In NDSS. 1\u201315.","author":"Rossow Christian","year":"2014","unstructured":"Christian Rossow . 2014 . Amplification Hell: Revisiting Network Protocols for DDoS Abuse.. In NDSS. 1\u201315. Christian Rossow. 2014. Amplification Hell: Revisiting Network Protocols for DDoS Abuse.. In NDSS. 1\u201315."},{"key":"e_1_3_2_1_55_1","unstructured":"Florian Roth. 2022. Signature-Base: YARA signature and IOC database for our scanners LOKI and THOR Lite. (2022). https:\/\/github.com\/Neo23x0\/signature-base.  Florian Roth. 2022. Signature-Base: YARA signature and IOC database for our scanners LOKI and THOR Lite. (2022). https:\/\/github.com\/Neo23x0\/signature-base."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/2245276.2232004"},{"key":"e_1_3_2_1_57_1","unstructured":"Offensive Security. 2022. Exploit Database. Available at [Online]: https:\/\/www.exploit-db.com\/. (2022).  Offensive Security. 2022. Exploit Database. Available at [Online]: https:\/\/www.exploit-db.com\/. (2022)."},{"key":"e_1_3_2_1_58_1","unstructured":"Joshua Shilko Zach Riddle Jennifer Brooks Genevieve Stark Adam Brunner Kimberly Goody and Jeremy Kennelly. 2021. FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. (2021). https:\/\/www.mandiant.com\/resources\/fin12-ransomware-intrusion-actor-pursuing-healthcare-targets.  Joshua Shilko Zach Riddle Jennifer Brooks Genevieve Stark Adam Brunner Kimberly Goody and Jeremy Kennelly. 2021. FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. (2021). https:\/\/www.mandiant.com\/resources\/fin12-ransomware-intrusion-actor-pursuing-healthcare-targets."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.29"},{"key":"e_1_3_2_1_60_1","volume-title":"Welcome to the OWASP Top 10 -","author":"OWASP","year":"2021","unstructured":"OWASP Top\u00a010 team. 2022. Welcome to the OWASP Top 10 - 2021 . (2022). https:\/\/owasp.org\/Top10\/. OWASP Top\u00a010 team. 2022. Welcome to the OWASP Top 10 - 2021. (2022). https:\/\/owasp.org\/Top10\/."},{"key":"e_1_3_2_1_61_1","volume-title":"A framework for attack patterns","author":"Thonnard Olivier","year":"2008","unstructured":"Olivier Thonnard and Marc Dacier . 2008. A framework for attack patterns \u2019 discovery in honeynet data. digital investigation 5( 2008 ), S128\u2013S139. Olivier Thonnard and Marc Dacier. 2008. A framework for attack patterns\u2019 discovery in honeynet data. digital investigation 5(2008), S128\u2013S139."},{"key":"e_1_3_2_1_62_1","unstructured":"Lisa Vaas. 2022. Widespread Easily Exploitable Windows RDP Bug Opens Users to Data Theft. Available at [Online]: https:\/\/tinyurl.com\/2u88758p. (2022).  Lisa Vaas. 2022. Widespread Easily Exploitable Windows RDP Bug Opens Users to Data Theft. Available at [Online]: https:\/\/tinyurl.com\/2u88758p. (2022)."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_26"},{"key":"e_1_3_2_1_64_1","unstructured":"VT. 2022. VirusTotal Detection. Available at [Online]: https:\/\/www.virustotal.com\/gui\/ip-address\/5.188.87.51\/. (2022).  VT. 2022. VirusTotal Detection. Available at [Online]: https:\/\/www.virustotal.com\/gui\/ip-address\/5.188.87.51\/. (2022)."},{"key":"e_1_3_2_1_65_1","volume-title":"NVRs and IP cameras.","year":"2020","unstructured":"YourChief. 2020. Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs , NVRs and IP cameras. ( 2020 ). https:\/\/habr.com\/en\/post\/486856\/. YourChief. 2020. Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs, NVRs and IP cameras. (2020). https:\/\/habr.com\/en\/post\/486856\/."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2956173"}],"event":{"name":"ACSAC: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC"},"container-title":["Proceedings of the 38th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564649","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3564649","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3564649","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:12Z","timestamp":1750183752000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564649"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,5]]},"references-count":66,"alternative-id":["10.1145\/3564625.3564649","10.1145\/3564625"],"URL":"https:\/\/doi.org\/10.1145\/3564625.3564649","relation":{},"subject":[],"published":{"date-parts":[[2022,12,5]]},"assertion":[{"value":"2022-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}