{"id":"https://openalex.org/W1645393624","doi":"https://doi.org/10.1109/icccn.2015.7288435","title":"Network Connectivity Graph for Malicious Traffic Dissection","display_name":"Network Connectivity Graph for Malicious Traffic Dissection","publication_year":2015,"publication_date":"2015-08-01","ids":{"openalex":"https://openalex.org/W1645393624","doi":"https://doi.org/10.1109/icccn.2015.7288435","mag":"1645393624"},"language":"en","primary_location":{"id":"doi:10.1109/icccn.2015.7288435","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icccn.2015.7288435","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 24th International Conference on Computer Communication and Networks (ICCCN)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://porto.polito.it/2625360/2/connectivity_graph.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5028032411","display_name":"Enrico Bocchi","orcid":null},"institutions":[{"id":"https://openalex.org/I4210165912","display_name":"Laboratoire Traitement et Communication de l\u2019Information","ror":"https://ror.org/057er4c39","country_code":"FR","type":"facility","lineage":["https://openalex.org/I12356871","https://openalex.org/I4210145102","https://openalex.org/I4210145102","https://openalex.org/I4210165912"]},{"id":"https://openalex.org/I177477856","display_name":"Polytechnic University of Turin","ror":"https://ror.org/00bgk9508","country_code":"IT","type":"education","lineage":["https://openalex.org/I177477856"]}],"countries":["FR","IT"],"is_corresponding":true,"raw_author_name":"Enrico Bocchi","raw_affiliation_strings":["Politecnico di Torino","Laboratory of Information, Network and Communication Sciences","Politecnico di Torino = Polytechnic of Turin","Laboratoire Traitement et Communication de l'Information"],"affiliations":[{"raw_affiliation_string":"Politecnico di Torino","institution_ids":["https://openalex.org/I177477856"]},{"raw_affiliation_string":"Laboratory of Information, Network and Communication Sciences","institution_ids":[]},{"raw_affiliation_string":"Politecnico di Torino = Polytechnic of Turin","institution_ids":["https://openalex.org/I177477856"]},{"raw_affiliation_string":"Laboratoire Traitement et Communication de l'Information","institution_ids":["https://openalex.org/I4210165912"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052118192","display_name":"Luigi Grimaudo","orcid":null},"institutions":[{"id":"https://openalex.org/I177477856","display_name":"Polytechnic University of Turin","ror":"https://ror.org/00bgk9508","country_code":"IT","type":"education","lineage":["https://openalex.org/I177477856"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Luigi Grimaudo","raw_affiliation_strings":["Politecnico di Torino","Politecnico di Torino = Polytechnic of Turin"],"affiliations":[{"raw_affiliation_string":"Politecnico di Torino","institution_ids":["https://openalex.org/I177477856"]},{"raw_affiliation_string":"Politecnico di Torino = Polytechnic of Turin","institution_ids":["https://openalex.org/I177477856"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060087704","display_name":"Marco Mellia","orcid":"https://orcid.org/0000-0003-1859-6693"},"institutions":[{"id":"https://openalex.org/I177477856","display_name":"Polytechnic University of Turin","ror":"https://ror.org/00bgk9508","country_code":"IT","type":"education","lineage":["https://openalex.org/I177477856"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Marco Mellia","raw_affiliation_strings":["Politecnico di Torino","Politecnico di Torino = Polytechnic of Turin"],"affiliations":[{"raw_affiliation_string":"Politecnico di Torino","institution_ids":["https://openalex.org/I177477856"]},{"raw_affiliation_string":"Politecnico di Torino = Polytechnic of Turin","institution_ids":["https://openalex.org/I177477856"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001695309","display_name":"Elena Baralis","orcid":"https://orcid.org/0000-0001-9231-467X"},"institutions":[{"id":"https://openalex.org/I177477856","display_name":"Polytechnic University of Turin","ror":"https://ror.org/00bgk9508","country_code":"IT","type":"education","lineage":["https://openalex.org/I177477856"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Elena Baralis","raw_affiliation_strings":["Politecnico di Torino","Politecnico di Torino = Polytechnic of Turin"],"affiliations":[{"raw_affiliation_string":"Politecnico di Torino","institution_ids":["https://openalex.org/I177477856"]},{"raw_affiliation_string":"Politecnico di Torino = Polytechnic of Turin","institution_ids":["https://openalex.org/I177477856"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065769574","display_name":"Sabyasachi Saha","orcid":"https://orcid.org/0009-0008-1050-5981"},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sabyasachi Saha","raw_affiliation_strings":["Symantec, Corp","Symantec"],"affiliations":[{"raw_affiliation_string":"Symantec, Corp","institution_ids":["https://openalex.org/I1308906816"]},{"raw_affiliation_string":"Symantec","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048401451","display_name":"Stanislav Miskovic","orcid":null},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stanislav Miskovic","raw_affiliation_strings":["Symantec, Corp","Symantec"],"affiliations":[{"raw_affiliation_string":"Symantec, Corp","institution_ids":["https://openalex.org/I1308906816"]},{"raw_affiliation_string":"Symantec","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012600119","display_name":"Gaspar Modelo-Howard","orcid":null},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gaspar Modelo-Howard","raw_affiliation_strings":["Symantec, Corp","Symantec"],"affiliations":[{"raw_affiliation_string":"Symantec, Corp","institution_ids":["https://openalex.org/I1308906816"]},{"raw_affiliation_string":"Symantec","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101948265","display_name":"Sung-Ju Lee","orcid":"https://orcid.org/0000-0002-5518-2126"},"institutions":[{"id":"https://openalex.org/I4210099236","display_name":"Kootenay Association for Science & Technology","ror":"https://ror.org/011pv9p44","country_code":"CA","type":"nonprofit","lineage":["https://openalex.org/I4210099236"]},{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["CA","KR"],"is_corresponding":false,"raw_author_name":"Sung-Ju Lee","raw_affiliation_strings":["KAIST","Korea Advanced Institute of Science and Technology"],"affiliations":[{"raw_affiliation_string":"KAIST","institution_ids":["https://openalex.org/I4210099236","https://openalex.org/I157485424"]},{"raw_affiliation_string":"Korea Advanced Institute of Science and Technology","institution_ids":["https://openalex.org/I157485424"]}]}],"institutions":[],"countries_distinct_count":5,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5028032411"],"corresponding_institution_ids":["https://openalex.org/I177477856","https://openalex.org/I4210165912"],"apc_list":null,"apc_paid":null,"fwci":0.6997,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.74307509,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7781503796577454},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7622780799865723},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.5406891703605652},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.5088949203491211},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.46455734968185425},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4632924795150757},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.43608444929122925},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.4258512258529663},{"id":"https://openalex.org/keywords/malware-analysis","display_name":"Malware analysis","score":0.42326247692108154},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.38671889901161194},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.18080490827560425},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.16195541620254517}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7781503796577454},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7622780799865723},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.5406891703605652},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.5088949203491211},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.46455734968185425},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4632924795150757},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.43608444929122925},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.4258512258529663},{"id":"https://openalex.org/C2779395397","wikidata":"https://www.wikidata.org/wiki/Q15731404","display_name":"Malware analysis","level":3,"score":0.42326247692108154},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.38671889901161194},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.18080490827560425},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.16195541620254517},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/icccn.2015.7288435","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icccn.2015.7288435","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 24th International Conference on Computer Communication and Networks (ICCCN)","raw_type":"proceedings-article"},{"id":"pmh:oai:HAL:hal-01254716v1","is_oa":false,"landing_page_url":"https://hal.science/hal-01254716","pdf_url":null,"source":{"id":"https://openalex.org/S4406922461","display_name":"SPIRE - Sciences Po Institutional REpository","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"2015 24th International Conference on Computer Communication and Networks (ICCCN), Aug 2015, Las Vegas, United States. pp.1 -- 9 &#x27E8;10.1109/ICCCN.2015.7288435&#x27E9;","raw_type":"Conference papers"},{"id":"pmh:oai:porto.polito.it:2625360","is_oa":true,"landing_page_url":"http://porto.polito.it/2625360/2/connectivity_graph.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306402038","display_name":"PORTO Publications Open Repository TOrino (Politecnico di Torino)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I177477856","host_organization_name":"Politecnico di Torino","host_organization_lineage":["https://openalex.org/I177477856"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":{"id":"pmh:oai:porto.polito.it:2625360","is_oa":true,"landing_page_url":"http://porto.polito.it/2625360/2/connectivity_graph.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306402038","display_name":"PORTO Publications Open Repository TOrino (Politecnico di Torino)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I177477856","host_organization_name":"Politecnico di Torino","host_organization_lineage":["https://openalex.org/I177477856"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W191098608","https://openalex.org/W1561983441","https://openalex.org/W1779735989","https://openalex.org/W1828150029","https://openalex.org/W1970867218","https://openalex.org/W1983776999","https://openalex.org/W2021753915","https://openalex.org/W2023973750","https://openalex.org/W2040424958","https://openalex.org/W2093016338","https://openalex.org/W2101737524","https://openalex.org/W2102283838","https://openalex.org/W2110675786","https://openalex.org/W2118676997","https://openalex.org/W2118843309","https://openalex.org/W2143182259","https://openalex.org/W2288791011","https://openalex.org/W3159049404","https://openalex.org/W4253872296","https://openalex.org/W4300958237","https://openalex.org/W6607784307","https://openalex.org/W6633578641","https://openalex.org/W6637957265","https://openalex.org/W6638584947"],"related_works":["https://openalex.org/W2469507153","https://openalex.org/W2008790809","https://openalex.org/W2768892939","https://openalex.org/W3164408430","https://openalex.org/W4285507391","https://openalex.org/W2397240470","https://openalex.org/W2602767565","https://openalex.org/W170652726","https://openalex.org/W2883822334","https://openalex.org/W2134874482"],"abstract_inverted_index":{"Malware":[0],"is":[1,64,111,126],"a":[2,44,55,60,67,112,127,152,157,210],"major":[3],"threat":[4],"to":[5,33,54,77,180,187,194],"security":[6,31],"and":[7,25,30,101,129,144],"privacy":[8],"of":[9,15,37,50,73,87,122,132,204,215],"network":[10,51,71,103,142,182],"users.":[11],"A":[12,174],"huge":[13],"variety":[14],"malware":[16],"typically":[17],"spreads":[18],"over":[19,80],"the":[20,27,35,78,90,118,123,133,162,202,205],"Internet,":[21],"evolving":[22],"every":[23],"day,":[24],"challenging":[26],"research":[28],"community":[29],"practitioners":[32],"improve":[34],"effectiveness":[36],"countermeasures.":[38],"In":[39],"this":[40],"paper,":[41],"we":[42],"present":[43],"system":[45,63],"that":[46,69,116,201],"automatically":[47],"extracts":[48],"patterns":[49,97],"activity":[52],"related":[53,186],"specific":[56],"malicious":[57,134,188,216],"event,":[58],"i.e.,":[59],"seed.":[61,124],"Our":[62],"based":[65],"on":[66,151],"methodology":[68],"correlates":[70],"events":[72],"hosts":[74,137],"normally":[75],"connected":[76],"Internet":[79],"(i)":[81],"time":[82],"(i.e.,":[83,95],"analyzing":[84],"different":[85,99],"samples":[86],"traffic":[88,164],"from":[89,140],"same":[91],"host),":[92],"(ii)":[93],"space":[94],"correlating":[96],"across":[98],"hosts),":[100],"(iii)":[102],"layers":[104],"(e.g.,":[105],"HTTP,":[106],"DNS,":[107],"etc.).":[108],"The":[109],"result":[110],"Network":[113,206],"Connectivity":[114,207],"Graph":[115,208],"captures":[117],"overall":[119],"\"network":[120],"behavior\"":[121],"That":[125],"focused":[128],"enriched":[130],"representation":[131],"pattern":[135],"infected":[136],"exhibit,":[138],"purified":[139],"ordinary":[141],"activities":[143],"background":[145],"traffic.":[146],"We":[147,190],"applied":[148],"our":[149,196,220],"approach":[150],"large":[153],"dataset":[154],"collected":[155],"in":[156],"real":[158],"commercial":[159,175],"ISP":[160],"where":[161],"aggregated":[163],"produced":[165],"by":[166],"more":[167,212],"than":[168],"20,000":[169],"households":[170],"has":[171,177],"been":[172,178],"monitored.":[173],"IDS":[176],"used":[179],"complement":[181],"data":[183],"with":[184],"alerts":[185,193],"activities.":[189],"use":[191],"such":[192],"trigger":[195],"processing":[197],"system.":[198],"Results":[199],"shows":[200],"richness":[203],"provides":[209],"much":[211],"detailed":[213],"picture":[214],"activities,":[217],"considerably":[218],"enhancing":[219],"understanding.":[221]},"counts_by_year":[{"year":2019,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":1}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
