{"id":"https://openalex.org/W2592087824","doi":"https://doi.org/10.1109/ic3ina.2016.7863040","title":"Analysis of educational institution DNS network traffic for insider threats","display_name":"Analysis of educational institution DNS network traffic for insider threats","publication_year":2016,"publication_date":"2016-10-01","ids":{"openalex":"https://openalex.org/W2592087824","doi":"https://doi.org/10.1109/ic3ina.2016.7863040","mag":"2592087824"},"language":"en","primary_location":{"id":"doi:10.1109/ic3ina.2016.7863040","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ic3ina.2016.7863040","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2016 International Conference on Computer, Control, Informatics and its Applications (IC3INA)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5062434170","display_name":"Kris Ivan Santosa","orcid":null},"institutions":[{"id":"https://openalex.org/I100406981","display_name":"Swiss German University","ror":"https://ror.org/047rtk203","country_code":"ID","type":"education","lineage":["https://openalex.org/I100406981"]}],"countries":["ID"],"is_corresponding":true,"raw_author_name":"Kris Ivan Santosa","raw_affiliation_strings":["Faculty of Engineering and Information Technology, Swiss German University, Tangerang"],"affiliations":[{"raw_affiliation_string":"Faculty of Engineering and Information Technology, Swiss German University, Tangerang","institution_ids":["https://openalex.org/I100406981"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101588651","display_name":"Charles Lim","orcid":null},"institutions":[{"id":"https://openalex.org/I100406981","display_name":"Swiss German University","ror":"https://ror.org/047rtk203","country_code":"ID","type":"education","lineage":["https://openalex.org/I100406981"]}],"countries":["ID"],"is_corresponding":false,"raw_author_name":"Charles Lim","raw_affiliation_strings":["Faculty of Engineering and Information Technology, Swiss German University, Tangerang"],"affiliations":[{"raw_affiliation_string":"Faculty of Engineering and Information Technology, Swiss German University, Tangerang","institution_ids":["https://openalex.org/I100406981"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5033413852","display_name":"Alva Erwin","orcid":"https://orcid.org/0000-0002-1454-2674"},"institutions":[{"id":"https://openalex.org/I100406981","display_name":"Swiss German University","ror":"https://ror.org/047rtk203","country_code":"ID","type":"education","lineage":["https://openalex.org/I100406981"]}],"countries":["ID"],"is_corresponding":false,"raw_author_name":"Alva Erwin","raw_affiliation_strings":["Faculty of Engineering and Information Technology, Swiss German University, Tangerang"],"affiliations":[{"raw_affiliation_string":"Faculty of Engineering and Information Technology, Swiss German University, Tangerang","institution_ids":["https://openalex.org/I100406981"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5062434170"],"corresponding_institution_ids":["https://openalex.org/I100406981"],"apc_list":null,"apc_paid":null,"fwci":1.1581,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.82720019,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"147","last_page":"152"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/insider-threat","display_name":"Insider threat","score":0.8868704438209534},{"id":"https://openalex.org/keywords/insider","display_name":"Insider","score":0.8582440614700317},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7453509569168091},{"id":"https://openalex.org/keywords/domain-name-system","display_name":"Domain Name System","score":0.7261799573898315},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.7077945470809937},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6633105278015137},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.6631444692611694},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4730207920074463},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.45265406370162964},{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.4275040924549103},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.23961198329925537}],"concepts":[{"id":"https://openalex.org/C2776633304","wikidata":"https://www.wikidata.org/wiki/Q6038026","display_name":"Insider threat","level":3,"score":0.8868704438209534},{"id":"https://openalex.org/C2778971194","wikidata":"https://www.wikidata.org/wiki/Q1664551","display_name":"Insider","level":2,"score":0.8582440614700317},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7453509569168091},{"id":"https://openalex.org/C35026560","wikidata":"https://www.wikidata.org/wiki/Q8767","display_name":"Domain Name System","level":3,"score":0.7261799573898315},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.7077945470809937},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6633105278015137},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.6631444692611694},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4730207920074463},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.45265406370162964},{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.4275040924549103},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.23961198329925537},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ic3ina.2016.7863040","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ic3ina.2016.7863040","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2016 International Conference on Computer, Control, Informatics and its Applications (IC3INA)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.7400000095367432,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W95238038","https://openalex.org/W1828150029","https://openalex.org/W1936523258","https://openalex.org/W2019862794","https://openalex.org/W2030382024","https://openalex.org/W2051131064","https://openalex.org/W2082550445","https://openalex.org/W2097571405","https://openalex.org/W2101737524","https://openalex.org/W2133671968","https://openalex.org/W2133990480","https://openalex.org/W2157392950","https://openalex.org/W2170687800","https://openalex.org/W2252815174","https://openalex.org/W2255638286","https://openalex.org/W6683104683"],"related_works":["https://openalex.org/W2766781562","https://openalex.org/W4205304595","https://openalex.org/W2733931179","https://openalex.org/W2979782961","https://openalex.org/W1642214788","https://openalex.org/W308359497","https://openalex.org/W1499596878","https://openalex.org/W3136170567","https://openalex.org/W2947769183","https://openalex.org/W4387194049"],"abstract_inverted_index":{"The":[0],"Internet":[1,57],"is":[2,53,96,191],"a":[3,97,193],"medium":[4],"for":[5,37,102],"people":[6],"to":[7,66,76,81,107,115,141],"communicate":[8],"with":[9,17],"each":[10],"other.":[11],"Individuals":[12],"and/or":[13],"organizations":[14,25,162],"are":[15,43,128,139,171],"faced":[16],"increased":[18],"security":[19,30,34,41],"threats":[20,31,35,42,118,127,159,170,187],"on":[21,27,63,131],"the":[22,73,83,132,143,161,164],"Internet.":[23],"Many":[24],"prioritize":[26],"handling":[28],"external":[29],"over":[32],"internal":[33,40],"and":[36,123,163,188],"this":[38],"reason,":[39],"often":[44],"missed":[45],"or":[46,86],"worst":[47],"ignored.":[48],"Domain":[49],"Name":[50],"System":[51],"(DNS)":[52],"one":[54],"of":[55,72,100,154,168],"major":[56],"services":[58],"that":[59,151],"resolve":[60,82],"user's":[61,92],"request":[62],"domain":[64,77,84],"name":[65,78,85],"an":[67,198],"IP":[68],"address.":[69],"Since":[70],"all":[71],"user":[74],"query":[75],"utilize":[79],"DNS":[80,95,120,133,144,155],"vice":[87],"versa,":[88],"including":[89],"malicious":[90],"intended":[91],"query.":[93],"Thus,":[94],"great":[98],"source":[99],"information":[101],"detecting":[103],"potential":[104,125],"insider":[105,110,117,126,158,169,177,186],"threat":[106,178],"detect":[108,116],"unknown":[109],"threats.":[111],"This":[112],"research":[113,149],"aims":[114],"using":[119],"based":[121,130],"features":[122],"these":[124],"clustered":[129],"traffic":[134,145,156],"features.":[135],"Machine":[136],"learning":[137],"algorithms":[138],"used":[140],"cluster":[142,190,195],"under":[146],"investigation.":[147],"Our":[148],"shows":[150],"suspected":[152],"clusters":[153,181],"contain":[157],"in":[160,176],"most":[165],"frequent":[166],"suspect":[167],"botnet,":[172],"categorized":[173],"as":[174],"misuse":[175],"classification.":[179],"Some":[180],"could":[182],"be":[183],"suspicious":[184],"indicating":[185],"other":[189],"also":[192],"benign":[194],"but":[196],"potentially":[197],"abnormal":[199],"traffic.":[200]},"counts_by_year":[{"year":2020,"cited_by_count":1},{"year":2018,"cited_by_count":4}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
