{"id":"https://openalex.org/W2762032850","doi":"https://doi.org/10.1109/infocom.2017.8057064","title":"Botnet protocol inference in the presence of encrypted traffic","display_name":"Botnet protocol inference in the presence of encrypted traffic","publication_year":2017,"publication_date":"2017-05-01","ids":{"openalex":"https://openalex.org/W2762032850","doi":"https://doi.org/10.1109/infocom.2017.8057064","mag":"2762032850"},"language":"en","primary_location":{"id":"doi:10.1109/infocom.2017.8057064","is_oa":false,"landing_page_url":"https://doi.org/10.1109/infocom.2017.8057064","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE INFOCOM 2017 - IEEE Conference on Computer Communications","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056233859","display_name":"Lorenzo De Carli","orcid":"https://orcid.org/0000-0003-0432-3686"},"institutions":[{"id":"https://openalex.org/I92446798","display_name":"Colorado State University","ror":"https://ror.org/03k1gpj17","country_code":"US","type":"education","lineage":["https://openalex.org/I92446798"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lorenzo De Carli","raw_affiliation_strings":["Colorado State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Colorado State University","institution_ids":["https://openalex.org/I92446798"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113675192","display_name":"Ruben Torres","orcid":null},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ruben Torres","raw_affiliation_strings":["Symantec"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Symantec","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012600119","display_name":"Gaspar Modelo-Howard","orcid":null},"institutions":[{"id":"https://openalex.org/I1308906816","display_name":"NortonLifeLock (United States)","ror":"https://ror.org/0449t3a80","country_code":"US","type":"company","lineage":["https://openalex.org/I1308906816"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gaspar Modelo-Howard","raw_affiliation_strings":["Symantec"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Symantec","institution_ids":["https://openalex.org/I1308906816"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022716924","display_name":"Alok Tongaonkar","orcid":null},"institutions":[{"id":"https://openalex.org/I1328219102","display_name":"Red Hat (United States)","ror":"https://ror.org/03ncs3316","country_code":"US","type":"company","lineage":["https://openalex.org/I1328219102"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alok Tongaonkar","raw_affiliation_strings":["RedLock Inc"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"RedLock Inc","institution_ids":["https://openalex.org/I1328219102"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5088826068","display_name":"Somesh Jha","orcid":"https://orcid.org/0000-0001-5877-0436"},"institutions":[{"id":"https://openalex.org/I135310074","display_name":"University of Wisconsin\u2013Madison","ror":"https://ror.org/01y2jtd41","country_code":"US","type":"education","lineage":["https://openalex.org/I135310074"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Somesh Jha","raw_affiliation_strings":["University of Wisconsin, Madison"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Wisconsin, Madison","institution_ids":["https://openalex.org/I135310074"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.8675,"has_fulltext":false,"cited_by_count":25,"citation_normalized_percentile":{"value":0.87279924,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.8400915861129761},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8241777420043945},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.7585189342498779},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.6088788509368896},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.5161267518997192},{"id":"https://openalex.org/keywords/reverse-engineering","display_name":"Reverse engineering","score":0.4943816661834717},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4638071060180664},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.4472275972366333},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.4274653494358063},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.41507017612457275},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3804716467857361},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.16465219855308533},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.1088683009147644},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.10476970672607422},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.08334541320800781}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.8400915861129761},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8241777420043945},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.7585189342498779},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.6088788509368896},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.5161267518997192},{"id":"https://openalex.org/C207850805","wikidata":"https://www.wikidata.org/wiki/Q269608","display_name":"Reverse engineering","level":2,"score":0.4943816661834717},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4638071060180664},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.4472275972366333},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.4274653494358063},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.41507017612457275},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3804716467857361},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.16465219855308533},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.1088683009147644},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.10476970672607422},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.08334541320800781},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/infocom.2017.8057064","is_oa":false,"landing_page_url":"https://doi.org/10.1109/infocom.2017.8057064","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE INFOCOM 2017 - IEEE Conference on Computer Communications","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.47999998927116394,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":31,"referenced_works":["https://openalex.org/W9614445","https://openalex.org/W82544137","https://openalex.org/W89505464","https://openalex.org/W126407768","https://openalex.org/W1507388815","https://openalex.org/W1538375546","https://openalex.org/W1547308659","https://openalex.org/W1553308705","https://openalex.org/W1827212170","https://openalex.org/W1882010690","https://openalex.org/W1912382034","https://openalex.org/W2021753915","https://openalex.org/W2049208027","https://openalex.org/W2054143615","https://openalex.org/W2065995359","https://openalex.org/W2074231493","https://openalex.org/W2115675703","https://openalex.org/W2126881776","https://openalex.org/W2132111557","https://openalex.org/W2134633067","https://openalex.org/W2145802904","https://openalex.org/W2155440239","https://openalex.org/W2156453323","https://openalex.org/W2164253698","https://openalex.org/W2172163424","https://openalex.org/W3199888168","https://openalex.org/W4210285581","https://openalex.org/W4239813889","https://openalex.org/W6632460521","https://openalex.org/W6638623425","https://openalex.org/W6685277877"],"related_works":["https://openalex.org/W2294483539","https://openalex.org/W2378449000","https://openalex.org/W3187581118","https://openalex.org/W2938399969","https://openalex.org/W2616994865","https://openalex.org/W3143747655","https://openalex.org/W2002178493","https://openalex.org/W2929621094","https://openalex.org/W1996006176","https://openalex.org/W4210907385"],"abstract_inverted_index":{"Network":[0],"protocol":[1,68,104,154],"reverse":[2],"engineering":[3],"of":[4,23,28,140],"botnet":[5],"command":[6],"and":[7,19,47,64,74,86,126,146],"control":[8],"(C&C)":[9],"is":[10],"a":[11,20,67],"challenging":[12],"task,":[13],"which":[14,34],"requires":[15],"various":[16],"manual":[17],"steps":[18],"significant":[21],"amount":[22],"domain":[24],"knowledge.":[25],"Furthermore,":[26],"most":[27],"today's":[29],"C&C":[30,72],"protocols":[31],"are":[32,130,144],"encrypted,":[33],"prevents":[35],"any":[36],"analysis":[37],"on":[38,119],"the":[39,44,61,71,83,132],"traffic":[40],"without":[41],"first":[42],"discovering":[43,60],"encryption":[45,62,84],"algorithm":[46,63,85],"key.":[48],"To":[49],"address":[50],"these":[51],"challenges,":[52],"we":[53,88,106],"present":[54],"an":[55],"end-to-end":[56],"system":[57],"for":[58,70],"automatically":[59],"keys,":[65],"generating":[66],"specification":[69],"traffic,":[73],"crafting":[75],"effective":[76],"network":[77,113],"signatures.":[78],"In":[79,100],"order":[80,101],"to":[81,92,102],"infer":[82,107],"key,":[87],"enhance":[89],"state-of-the-art":[90],"techniques":[91],"extract":[93],"this":[94],"information":[95],"using":[96],"lightweight":[97],"binary":[98],"analysis.":[99],"generate":[103],"specifications":[105,148],"field":[108],"types":[109],"purely":[110],"by":[111],"analyzing":[112],"traffic.":[114],"We":[115],"evaluate":[116],"our":[117],"approach":[118,133],"three":[120,136],"prominent":[121],"malware":[122],"families:":[123],"Sality,":[124],"ZeroAccess":[125],"Ramnit.":[127],"Our":[128],"results":[129],"encouraging:":[131],"decrypts":[134],"all":[135],"protocols,":[137],"detects":[138],"97%":[139],"fields":[141],"whose":[142],"semantics":[143],"supported,":[145],"infers":[147],"that":[149],"correctly":[150],"align":[151],"with":[152],"real":[153],"specifications.":[155]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":2},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":3},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
