{"id":"https://openalex.org/W1978972543","doi":"https://doi.org/10.1109/comsnets.2013.6465572","title":"Privacy-preserving domain-flux botnet detection in a large scale network","display_name":"Privacy-preserving domain-flux botnet detection in a large scale network","publication_year":2013,"publication_date":"2013-01-01","ids":{"openalex":"https://openalex.org/W1978972543","doi":"https://doi.org/10.1109/comsnets.2013.6465572","mag":"1978972543"},"language":"en","primary_location":{"id":"doi:10.1109/comsnets.2013.6465572","is_oa":false,"landing_page_url":"https://doi.org/10.1109/comsnets.2013.6465572","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2013 Fifth International Conference on Communication Systems and Networks (COMSNETS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055672093","display_name":"Hachem Guerid","orcid":null},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]},{"id":"https://openalex.org/I19370010","display_name":"Orange (France)","ror":"https://ror.org/035j0tq82","country_code":"FR","type":"company","lineage":["https://openalex.org/I19370010"]}],"countries":["FR"],"is_corresponding":true,"raw_author_name":"Hachem Guerid","raw_affiliation_strings":["Orange Laboratories, Caen, France","Telecom ParisTech, Paris, France"],"affiliations":[{"raw_affiliation_string":"Orange Laboratories, Caen, France","institution_ids":["https://openalex.org/I19370010"]},{"raw_affiliation_string":"Telecom ParisTech, Paris, France","institution_ids":["https://openalex.org/I12356871"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091134453","display_name":"Karel Mittig","orcid":null},"institutions":[{"id":"https://openalex.org/I19370010","display_name":"Orange (France)","ror":"https://ror.org/035j0tq82","country_code":"FR","type":"company","lineage":["https://openalex.org/I19370010"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Karel Mittig","raw_affiliation_strings":["Orange Laboratories, Caen, France"],"affiliations":[{"raw_affiliation_string":"Orange Laboratories, Caen, France","institution_ids":["https://openalex.org/I19370010"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5063048763","display_name":"Ahmed Serhrouchni","orcid":null},"institutions":[{"id":"https://openalex.org/I12356871","display_name":"T\u00e9l\u00e9com Paris","ror":"https://ror.org/01naq7912","country_code":"FR","type":"education","lineage":["https://openalex.org/I12356871","https://openalex.org/I205703379","https://openalex.org/I4210145102"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Ahmed Serhrouchni","raw_affiliation_strings":["Telecom ParisTech, Paris, France"],"affiliations":[{"raw_affiliation_string":"Telecom ParisTech, Paris, France","institution_ids":["https://openalex.org/I12356871"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5055672093"],"corresponding_institution_ids":["https://openalex.org/I12356871","https://openalex.org/I19370010"],"apc_list":null,"apc_paid":null,"fwci":2.8854,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.91119157,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":"11","issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11478","display_name":"Caching and Content Delivery","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.978232204914093},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8224738836288452},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7861448526382446},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.7456986904144287},{"id":"https://openalex.org/keywords/false-positive-paradox","display_name":"False positive paradox","score":0.6202218532562256},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5760811567306519},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.4898662269115448},{"id":"https://openalex.org/keywords/bloom-filter","display_name":"Bloom filter","score":0.48119741678237915},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4487643241882324},{"id":"https://openalex.org/keywords/scale","display_name":"Scale (ratio)","score":0.4321900010108948},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.37961241602897644},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.3111373782157898},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.13439032435417175},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.08460217714309692}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.978232204914093},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8224738836288452},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7861448526382446},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.7456986904144287},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.6202218532562256},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5760811567306519},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.4898662269115448},{"id":"https://openalex.org/C147224247","wikidata":"https://www.wikidata.org/wiki/Q885373","display_name":"Bloom filter","level":2,"score":0.48119741678237915},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4487643241882324},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.4321900010108948},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.37961241602897644},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.3111373782157898},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.13439032435417175},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.08460217714309692},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/comsnets.2013.6465572","is_oa":false,"landing_page_url":"https://doi.org/10.1109/comsnets.2013.6465572","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2013 Fifth International Conference on Communication Systems and Networks (COMSNETS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320320300","display_name":"European Commission","ror":"https://ror.org/00k4n6c32"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":23,"referenced_works":["https://openalex.org/W155384935","https://openalex.org/W196740607","https://openalex.org/W1561983441","https://openalex.org/W1828150029","https://openalex.org/W1954903228","https://openalex.org/W1993284846","https://openalex.org/W2100307718","https://openalex.org/W2102283838","https://openalex.org/W2123845384","https://openalex.org/W2136495567","https://openalex.org/W2149701633","https://openalex.org/W2168248885","https://openalex.org/W2296151511","https://openalex.org/W2315772904","https://openalex.org/W2401054255","https://openalex.org/W2410666586","https://openalex.org/W4300958237","https://openalex.org/W6606342502","https://openalex.org/W6633578641","https://openalex.org/W6640663528","https://openalex.org/W6697154064","https://openalex.org/W6699186867","https://openalex.org/W6713023146"],"related_works":["https://openalex.org/W2929621094","https://openalex.org/W1996006176","https://openalex.org/W4285325964","https://openalex.org/W1975357770","https://openalex.org/W2127784084","https://openalex.org/W2950578529","https://openalex.org/W2086416962","https://openalex.org/W4383553080","https://openalex.org/W2155669648","https://openalex.org/W4293879742"],"abstract_inverted_index":{"In":[0,35],"a":[1,18,40,81,126,181,188,192],"large":[2,127],"scale":[3,128],"network,":[4],"the":[5,8,11,73,94,110,118,164,168],"privacy":[6,121,194],"of":[7,69,103,120,125,150],"users":[9],"and":[10,32,54,76,123,134],"performance":[12,124],"are":[13],"critical":[14],"issues":[15],"when":[16],"conceiving":[17],"detection":[19,24,179,185,197],"system,":[20],"precisely":[21],"for":[22,177],"botnet":[23,196],"where":[25],"we":[26,38],"need":[27],"to":[28,50,106,115,162],"differentiate":[29],"between":[30],"benign":[31],"malicious":[33,55,87,151],"traffic.":[34],"this":[36],"paper,":[37],"propose":[39],"new":[41],"approach":[42,100],"which":[43,112],"conciliates":[44],"these":[45,90],"two":[46,62],"requirements":[47],"in":[48,80,180],"order":[49],"detect":[51],"domain-flux":[52],"botnets":[53],"servers":[56,88],"controlling":[57,89],"them.":[58],"It":[59,146],"relies":[60],"on":[61],"successive":[63],"steps:":[64],"(1)":[65],"it":[66,85,136,173],"identifies":[67,86],"communities":[68],"bots,":[70],"infected":[71],"by":[72,92],"same":[74],"malware":[75],"showing":[77],"similar":[78],"behaviour":[79],"defined":[82],"interval;":[83],"(2)":[84],"bots":[91],"correlating":[93],"traffic":[95,140],"within":[96],"each":[97],"community.":[98],"Our":[99,158,184],"takes":[101],"advantage":[102],"Bloom":[104],"filters":[105],"represent":[107],"information":[108],"during":[109],"analysis,":[111],"allows":[113],"us":[114],"comply":[116],"with":[117,137,154],"constraints":[119],"preservation":[122],"implementation.":[129],"We":[130],"implemented":[131],"our":[132],"system":[133,159,186],"fed":[135],"anonymised":[138],"DNS":[139],"coming":[141],"from":[142],"an":[143],"operator":[144],"network.":[145],"detected":[147],"several":[148],"hundreds":[149],"domain":[152],"names":[153],"few":[155],"false":[156],"positives.":[157],"was":[160],"able":[161],"process":[163],"capture":[165],"faster":[166],"than":[167],"injection":[169],"rate,":[170],"indicating":[171],"that":[172],"can":[174],"be":[175],"scaled":[176],"real-time":[178],"production":[182],"environment.":[183],"is":[187],"first":[189],"step":[190],"into":[191],"fully":[193],"conservative":[195],"system.":[198]},"counts_by_year":[{"year":2023,"cited_by_count":2},{"year":2020,"cited_by_count":3},{"year":2018,"cited_by_count":3},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":1},{"year":2014,"cited_by_count":2},{"year":2013,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
