{"id":"https://openalex.org/W2181614855","doi":"https://doi.org/10.1109/cns.2015.7346852","title":"Leveraging client-side DNS failure patterns to identify malicious behaviors","display_name":"Leveraging client-side DNS failure patterns to identify malicious behaviors","publication_year":2015,"publication_date":"2015-09-01","ids":{"openalex":"https://openalex.org/W2181614855","doi":"https://doi.org/10.1109/cns.2015.7346852","mag":"2181614855"},"language":"en","primary_location":{"id":"doi:10.1109/cns.2015.7346852","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cns.2015.7346852","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 IEEE Conference on Communications and Network Security (CNS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://porto.polito.it/2625367/2/DNSCNS15.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5020136190","display_name":"Pengkui Luo","orcid":null},"institutions":[{"id":"https://openalex.org/I2800403580","display_name":"University of Minnesota System","ror":"https://ror.org/03grvy078","country_code":"US","type":"education","lineage":["https://openalex.org/I2800403580"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Pengkui Luo","raw_affiliation_strings":["University of Minnesota"],"affiliations":[{"raw_affiliation_string":"University of Minnesota","institution_ids":["https://openalex.org/I2800403580"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113675192","display_name":"Ruben Torres","orcid":null},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ruben Torres","raw_affiliation_strings":["Symantec Corp"],"affiliations":[{"raw_affiliation_string":"Symantec Corp","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100622097","display_name":"Zhi-Li Zhang","orcid":"https://orcid.org/0000-0001-8584-2319"},"institutions":[{"id":"https://openalex.org/I2800403580","display_name":"University of Minnesota System","ror":"https://ror.org/03grvy078","country_code":"US","type":"education","lineage":["https://openalex.org/I2800403580"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zhi-Li Zhang","raw_affiliation_strings":["University of Minnesota"],"affiliations":[{"raw_affiliation_string":"University of Minnesota","institution_ids":["https://openalex.org/I2800403580"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065769574","display_name":"Sabyasachi Saha","orcid":"https://orcid.org/0009-0008-1050-5981"},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sabyasachi Saha","raw_affiliation_strings":["Symantec Corp"],"affiliations":[{"raw_affiliation_string":"Symantec Corp","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101948265","display_name":"Sung-Ju Lee","orcid":"https://orcid.org/0000-0002-5518-2126"},"institutions":[{"id":"https://openalex.org/I4210099236","display_name":"Kootenay Association for Science & Technology","ror":"https://ror.org/011pv9p44","country_code":"CA","type":"nonprofit","lineage":["https://openalex.org/I4210099236"]},{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["CA","KR"],"is_corresponding":false,"raw_author_name":"Sung-Ju Lee","raw_affiliation_strings":["KAIST"],"affiliations":[{"raw_affiliation_string":"KAIST","institution_ids":["https://openalex.org/I4210099236","https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113580213","display_name":"Antonio Nucci","orcid":null},"institutions":[{"id":"https://openalex.org/I135428043","display_name":"Cisco Systems (United States)","ror":"https://ror.org/03yt1ez60","country_code":"US","type":"company","lineage":["https://openalex.org/I135428043"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Antonio Nucci","raw_affiliation_strings":["Cisco Systems"],"affiliations":[{"raw_affiliation_string":"Cisco Systems","institution_ids":["https://openalex.org/I135428043"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060087704","display_name":"Marco Mellia","orcid":"https://orcid.org/0000-0003-1859-6693"},"institutions":[{"id":"https://openalex.org/I177477856","display_name":"Polytechnic University of Turin","ror":"https://ror.org/00bgk9508","country_code":"IT","type":"education","lineage":["https://openalex.org/I177477856"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Marco Mellia","raw_affiliation_strings":["Politecnico di Torino"],"affiliations":[{"raw_affiliation_string":"Politecnico di Torino","institution_ids":["https://openalex.org/I177477856"]}]}],"institutions":[],"countries_distinct_count":4,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5020136190"],"corresponding_institution_ids":["https://openalex.org/I2800403580"],"apc_list":null,"apc_paid":null,"fwci":1.9969,"has_fulltext":false,"cited_by_count":11,"citation_normalized_percentile":{"value":0.88286716,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"406","last_page":"414"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9969000220298767,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8192222118377686},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7842585444450378},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.7760017514228821},{"id":"https://openalex.org/keywords/domain-name-system","display_name":"Domain Name System","score":0.7212039232254028},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.5984194278717041},{"id":"https://openalex.org/keywords/name-server","display_name":"Name server","score":0.559032142162323},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5457108616828918},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.5118181109428406},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.3853740096092224},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.370330810546875},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.1887967586517334},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.1387147605419159}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8192222118377686},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7842585444450378},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.7760017514228821},{"id":"https://openalex.org/C35026560","wikidata":"https://www.wikidata.org/wiki/Q8767","display_name":"Domain Name System","level":3,"score":0.7212039232254028},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.5984194278717041},{"id":"https://openalex.org/C105320234","wikidata":"https://www.wikidata.org/wiki/Q41494","display_name":"Name server","level":3,"score":0.559032142162323},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5457108616828918},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.5118181109428406},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.3853740096092224},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.370330810546875},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.1887967586517334},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.1387147605419159},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/cns.2015.7346852","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cns.2015.7346852","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 IEEE Conference on Communications and Network Security (CNS)","raw_type":"proceedings-article"},{"id":"pmh:oai:porto.polito.it:2625367","is_oa":true,"landing_page_url":"http://porto.polito.it/2625367/2/DNSCNS15.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306402038","display_name":"PORTO Publications Open Repository TOrino (Politecnico di Torino)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I177477856","host_organization_name":"Politecnico di Torino","host_organization_lineage":["https://openalex.org/I177477856"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":{"id":"pmh:oai:porto.polito.it:2625367","is_oa":true,"landing_page_url":"http://porto.polito.it/2625367/2/DNSCNS15.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306402038","display_name":"PORTO Publications Open Repository TOrino (Politecnico di Torino)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I177477856","host_organization_name":"Politecnico di Torino","host_organization_lineage":["https://openalex.org/I177477856"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7300000190734863,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320306078","display_name":"U.S. Department of Defense","ror":"https://ror.org/0447fe631"},{"id":"https://openalex.org/F4320332186","display_name":"Defense Threat Reduction Agency","ror":"https://ror.org/04tz64554"},{"id":"https://openalex.org/F4320333591","display_name":"Multidisciplinary University Research Initiative","ror":null},{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W155384935","https://openalex.org/W1561983441","https://openalex.org/W1647671624","https://openalex.org/W1816173724","https://openalex.org/W1954903228","https://openalex.org/W1990497396","https://openalex.org/W2030382024","https://openalex.org/W2100307718","https://openalex.org/W2101737524","https://openalex.org/W2102283838","https://openalex.org/W2136495567","https://openalex.org/W2156279557","https://openalex.org/W2158204917","https://openalex.org/W2296396094","https://openalex.org/W2396434032","https://openalex.org/W2401054255","https://openalex.org/W3023762229","https://openalex.org/W6606342502","https://openalex.org/W6633578641","https://openalex.org/W6636915900","https://openalex.org/W6638878298","https://openalex.org/W6640663528","https://openalex.org/W6648823466","https://openalex.org/W6697323961","https://openalex.org/W6713023146"],"related_works":["https://openalex.org/W2929621094","https://openalex.org/W1996006176","https://openalex.org/W2065991182","https://openalex.org/W2948569047","https://openalex.org/W596534943","https://openalex.org/W3214913819","https://openalex.org/W1642214788","https://openalex.org/W2733931179","https://openalex.org/W2054545906","https://openalex.org/W2965181964"],"abstract_inverted_index":{"DNS":[0,13,16,55,66,73,110,154,194],"has":[1,11],"been":[2],"increasingly":[3],"abused":[4],"by":[5,76,112,169],"adversaries":[6],"for":[7,43,67],"cyber-attacks.":[8],"Recent":[9],"research":[10],"leveraged":[12],"failures":[14,74,155],"(i.e.":[15],"queries":[17],"that":[18,34,87,100,108,182],"result":[19],"in":[20,152],"a":[21,40,51,98,176],"Non-Existent-Domain":[22],"response":[23],"from":[24],"the":[25,59,128,146,163,170,190],"server)":[26],"to":[27,72,133],"identify":[28],"malware":[29],"activities,":[30],"especially":[31],"domain-flux":[32,77],"botnets":[33],"generate":[35],"many":[36,81],"random":[37],"domains":[38],"as":[39,118,120],"rendezvous":[41],"technique":[42],"command-&-control.":[44],"Using":[45],"ISP":[46,178],"network":[47,179],"traces,":[48],"we":[49,79,96],"conduct":[50],"systematic":[52],"analysis":[53],"of":[54,61,104,116,145,148,165,189],"failure":[56,85],"characteristics,":[57],"with":[58,192,196],"goal":[60],"uncovering":[62],"how":[63],"attackers":[64],"exploit":[65],"malicious":[68],"activities.":[69],"In":[70],"addition":[71],"generated":[75],"bots,":[78],"discover":[80],"diverse":[82,102],"and":[83,159],"stealthy":[84],"patterns":[86],"have":[88],"received":[89],"little":[90],"attention.":[91],"Based":[92],"on":[93,156,162,175],"these":[94],"findings,":[95],"present":[97],"framework":[99,126,150,184],"detects":[101,185],"clusters":[103,129],"suspicious":[105,193],"domain":[106],"names":[107],"cause":[109],"failures,":[111],"considering":[113],"multiple":[114,166],"types":[115],"syntactic":[117],"well":[119],"temporal":[121],"patterns.":[122],"Our":[123,173],"evolutionary":[124],"learning":[125],"evaluates":[127],"produced":[130],"over":[131,197],"time":[132],"eliminate":[134],"spurious":[135],"cases":[136],"while":[137],"retaining":[138],"sustaining":[139],"(i.e.,":[140],"highly":[141],"suspicious)":[142],"clusters.":[143],"One":[144],"advantages":[147],"our":[149,183],"is":[151],"analyzing":[153],"per-client":[157],"basis":[158],"not":[160],"hinging":[161],"existence":[164],"clients":[167,191],"infected":[168],"same":[171],"malware.":[172],"evaluation":[174],"large":[177],"trace":[180],"shows":[181],"at":[186],"least":[187],"97%":[188],"behaviors,":[195],"81%":[198],"precision.":[199]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":2},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":4}],"updated_date":"2026-02-26T08:16:20.718346","created_date":"2025-10-10T00:00:00"}
