{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T08:53:02Z","timestamp":1768726382917,"version":"3.49.0"},"reference-count":26,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"10","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2020,10,1]]},"DOI":"10.1587\/transinf.2020edp7076","type":"journal-article","created":{"date-parts":[[2020,9,30]],"date-time":"2020-09-30T22:33:27Z","timestamp":1601505207000},"page":"2113-2124","source":"Crossref","is-referenced-by-count":17,"title":["Real-Time Detection of Global Cyberthreat Based on Darknet by Estimating Anomalous Synchronization Using Graphical Lasso"],"prefix":"10.1587","volume":"E103.D","author":[{"given":"Chansu","family":"HAN","sequence":"first","affiliation":[{"name":"National Institute of Information and Communications Technology"},{"name":"Kyushu University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jumpei","family":"SHIMAMURA","sequence":"additional","affiliation":[{"name":"clwit Inc."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takeshi","family":"TAKAHASHI","sequence":"additional","affiliation":[{"name":"National Institute of Information and Communications Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daisuke","family":"INOUE","sequence":"additional","affiliation":[{"name":"National Institute of Information and Communications Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun'ichi","family":"TAKEUCHI","sequence":"additional","affiliation":[{"name":"Kyushu University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Koji","family":"NAKAO","sequence":"additional","affiliation":[{"name":"National Institute of Information and Communications Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"crossref","unstructured":"[1] C. Han, J. Shimamura, T. Takahashi, D. Inoue, M. Kawakita, J. Takeuchi, and K. Nakao, \u201cReal-time detection of malware activities by analyzing darknet traffic using graphical lasso,\u201d 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom), pp.144-151, IEEE, 2019. 10.1109\/trustcom\/bigdatase.2019.00028","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00028"},{"key":"2","unstructured":"[2] M. Bailey, E. Cooke, F. Jahanian, and J. Nazario, \u201cThe internet motion sensor-A distributed blackhole monitoring system,\u201d Proc. Network and Distributed System Security Symposium (NDSS), The Internet Society, pp.167-179, 2005."},{"key":"3","doi-asserted-by":"crossref","unstructured":"[3] M. Bailey, E. Cooke, F. Jahanian, A. Myrick, and S. Sinha, \u201cPractical darknet measurement,\u201d 40th Annual Conference on Information Sciences and Systems, pp.1496-1501, IEEE, 2006. 10.1109\/ciss.2006.286376","DOI":"10.1109\/CISS.2006.286376"},{"key":"4","doi-asserted-by":"publisher","unstructured":"[4] V. Yegneswaran, P. Barford, and D. Plonka, \u201cOn the design and use of internet sinks for network abuse monitoring,\u201d Recent Advances in Intrusion Detection: 7th International Symposium (RAID), pp.146-165, Springer, 2004. 10.1007\/978-3-540-30143-1_8","DOI":"10.1007\/978-3-540-30143-1_8"},{"key":"5","unstructured":"[5] D. Moore, \u201cNetwork telescopes: Tracking denial-of-service attacks and internet worms around the globe,\u201d Proc. 17th Conference on Systems Administration (LISA), USENIX, 2003."},{"key":"6","doi-asserted-by":"crossref","unstructured":"[6] M. Akiyama, T. Kawamoto, M. Shimamura, T. Yokoyama, Y. Kadobayashi, and S. Yamaguchi, \u201cA proposal of metrics for botnet detection based on its cooperative behavior,\u201d 2007 International Symposium on Applications and the Internet-Workshops (SAINT), p.82, IEEE, 2007. 10.1109\/saint-w.2007.14","DOI":"10.1109\/SAINT-W.2007.14"},{"key":"7","unstructured":"[7] J. Friedman, T. Hastie, and R. Tibshirani, \u201cGraphical lasso: Estimation of gaussian graphical models,\u201d 2018. https:\/\/cran.r-project.org\/web\/packages\/glasso\/glasso.pdf."},{"key":"8","doi-asserted-by":"publisher","unstructured":"[8] J. Friedman, T. Hastie, and R. Tibshirani, \u201cSparse inverse covariance estimation with the graphical lasso,\u201d Biostatistics, vol.9, no.3, pp.432-441, 2007. 10.1093\/biostatistics\/kxm045","DOI":"10.1093\/biostatistics\/kxm045"},{"key":"9","unstructured":"[9] G. Gu, J. Zhang, and W. Lee, \u201cBotsniffer: Detecting botnet command and control channels in network traffic,\u201d Proc. Network and Distributed System Security Symposium (NDSS), The Internet Society, 2008."},{"key":"10","unstructured":"[10] G. Gu, R. Perdisci, J. Zhang, and W. Lee, \u201cBotminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection,\u201d Proc. 17th USENIX Security Symposium, pp.139-154, 2008."},{"key":"11","doi-asserted-by":"publisher","unstructured":"[11] C. Fachkha and M. Debbabi, \u201cDarknet as a source of cyber intelligence: Survey, taxonomy, and characterization,\u201d IEEE Commun. Surveys Tuts., vol.18, no.2, pp.1197-1227, 2016. 10.1109\/comst.2015.2497690","DOI":"10.1109\/COMST.2015.2497690"},{"key":"12","doi-asserted-by":"crossref","unstructured":"[12] A. Dainotti, K. Benson, A. King, k. claffy, M. Kallitsis, E. Glatz, and X. Dimitropoulos, \u201cEstimating internet address space usage through passive measurements,\u201d SIGCOMM Comput. Commun. Rev., vol.44, no.1, pp.42-49, 2014.","DOI":"10.1145\/2567561.2567568"},{"key":"13","unstructured":"[13] Z. Durumeric, M. Bailey, and J.A. Halderman, \u201cAn internet-wide view of internet-wide scanning,\u201d Proc. 23rd USENIX Security Symposium, pp.65-78, 2014."},{"key":"14","doi-asserted-by":"crossref","unstructured":"[14] C. Fachkha, E. Bou-Harb, A. Keliris, N.D. Memon, and M. Ahamad, \u201cInternet-scale probing of CPS: inference, characterization and orchestration analysis,\u201d 24th Annual Network and Distributed System Security Symposium (NDSS), The Internet Society, 2017. 10.14722\/ndss.2017.23149","DOI":"10.14722\/ndss.2017.23149"},{"key":"15","doi-asserted-by":"publisher","unstructured":"[15] D. Inoue, K. Yoshioka, M. Eto, M. Yamagata, E. Nishino, J. Takeuchi, K. Ohkouchi, and K. Nakao, \u201cAn incident analysis system NICTER and its analysis engines based on data mining techniques,\u201d Advances in Neuro-Information Processing, 15th International Conference (ICONIP), pp.579-586, Springer, 2008. 10.1007\/978-3-642-02490-0_71","DOI":"10.1007\/978-3-642-02490-0_71"},{"key":"16","doi-asserted-by":"crossref","unstructured":"[16] T. Ban, L. Zhu, J. Shimamura, S. Pang, D. Inoue, and K. Nakao, \u201cDetection of botnet activities through the lens of a large-scale darknet,\u201d Neural Information Processing-24th International Conference (ICONIP), pp.442-451, Springer, 2017. 10.1007\/978-3-319-70139-4_45","DOI":"10.1007\/978-3-319-70139-4_45"},{"key":"17","doi-asserted-by":"crossref","unstructured":"[17] E. Ahmed, A.J. Clark, and G.M. Mohay, \u201cA novel sliding window based change detection algorithm for asymmetric traffic,\u201d IFIP International Conference on Network and Parallel Computing (NPC), pp.168-175, IEEE Computer Society, 2008. 10.1109\/npc.2008.81","DOI":"10.1109\/NPC.2008.81"},{"key":"18","doi-asserted-by":"publisher","unstructured":"[18] J. Takeuchi and K. Yamanishi, \u201cA unifying framework for detecting outliers and change points from time series,\u201d IEEE Trans. Knowl. Data Eng., vol.18, no.4, pp.482-492, 2006. 10.1109\/tkde.2006.1599387","DOI":"10.1109\/TKDE.2006.1599387"},{"key":"19","unstructured":"[19] FOX-IT, \u201cRecent vulnerability in eir d1000 router used to spread updated version of mirai ddos bot,\u201d 2016. https:\/\/blog.fox-it.com\/2016\/11\/28\/recent-vulnerability-in-eir-d1000-router-used-to-spread-updated-version-of-mirai-ddos-bot\/."},{"key":"20","doi-asserted-by":"crossref","unstructured":"[20] S. Herwig, K. Harvey, G. Hughey, R. Roberts, and D. Levin, \u201cMeasurement and analysis of hajime, a peer-to-peer iot botnet,\u201d 26th Annual Network and Distributed System Security Symposium (NDSS), The Internet Society, 2019. 10.14722\/ndss.2019.23488","DOI":"10.14722\/ndss.2019.23488"},{"key":"21","unstructured":"[21] Netlab360, \u201cHns botnet recent activities,\u201d 2018. https:\/\/blog.netlab.360.com\/hns-botnet-recent-activities-en\/."},{"key":"22","unstructured":"[22] Netlab360, \u201c7,500+ mikrotik routers are forwarding owners&apos; traffic to the attackers, how is yours?,\u201d 2018. https:\/\/blog.netlab.360.com\/7500-mikrotik-routers-are-forwarding-owners-traffic-to-the-attackers-how-is-yours-en\/."},{"key":"23","unstructured":"[23] Huawei, \u201cSecurity notice-statement on remote code execution vulnerability in huawei hg532 product,\u201d 2017. https:\/\/www.huawei.com\/en\/psirt\/security-notices\/huawei-sn-20171130-01-hg532-en."},{"key":"24","unstructured":"[24] Tenable-Research, \u201cTenable research advisory: Peekaboo critical vulnerability in nuuo network video recorder,\u201d 2018. https:\/\/www.tenable.com\/blog\/tenable-research-advisory-peekaboo-critical-vulnerability-in-nuuo-network-video-recorder."},{"key":"25","unstructured":"[25] Netlab360, \u201cBcmpupnp_hunter: A 100k botnet turns home routers to email spammers,\u201d 2018. https:\/\/blog.netlab.360.com\/bcmpupnp_hunter-a-100k-botnet-turns-home-routers-to-email-spammers-en\/."},{"key":"26","doi-asserted-by":"crossref","unstructured":"[26] T. Id\u00e9, A.C. Lozano, N. Abe, and Y. Liu, \u201cProximity-based anomaly detection using sparse structure learning,\u201d Proc. SIAM International Conference on Data Mining, SDM, pp.97-108, Society for Industrial and Applied Mathematics, 2009. 10.1137\/1.9781611972795.9","DOI":"10.1137\/1.9781611972795.9"}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E103.D\/10\/E103.D_2020EDP7076\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,3]],"date-time":"2020-10-03T03:31:27Z","timestamp":1601695887000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E103.D\/10\/E103.D_2020EDP7076\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,1]]},"references-count":26,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2020]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2020edp7076","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"value":"0916-8532","type":"print"},{"value":"1745-1361","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,10,1]]}}}