{"id":"https://openalex.org/W3026820624","doi":"https://doi.org/10.1109/tnsm.2020.2996502","title":"Botnet Fingerprinting: A Frequency Distributions Scheme for Lightweight Bot Detection","display_name":"Botnet Fingerprinting: A Frequency Distributions Scheme for Lightweight Bot Detection","publication_year":2020,"publication_date":"2020-05-21","ids":{"openalex":"https://openalex.org/W3026820624","doi":"https://doi.org/10.1109/tnsm.2020.2996502","mag":"3026820624"},"language":"en","primary_location":{"id":"doi:10.1109/tnsm.2020.2996502","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2020.2996502","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://hal.science/hal-02568587","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5031952821","display_name":"Agathe Blaise","orcid":"https://orcid.org/0000-0002-9598-8482"},"institutions":[{"id":"https://openalex.org/I1294671590","display_name":"Centre National de la Recherche Scientifique","ror":"https://ror.org/02feahw73","country_code":"FR","type":"government","lineage":["https://openalex.org/I1294671590"]},{"id":"https://openalex.org/I39804081","display_name":"Sorbonne Universit\u00e9","ror":"https://ror.org/02en5vm52","country_code":"FR","type":"education","lineage":["https://openalex.org/I39804081"]},{"id":"https://openalex.org/I4210140930","display_name":"Thales (France)","ror":"https://ror.org/04emwm605","country_code":"FR","type":"company","lineage":["https://openalex.org/I4210140930"]},{"id":"https://openalex.org/I51101395","display_name":"Universit\u00e9 Paris 1 Panth\u00e9on-Sorbonne","ror":"https://ror.org/002t25c44","country_code":"FR","type":"education","lineage":["https://openalex.org/I51101395"]}],"countries":["FR"],"is_corresponding":true,"raw_author_name":"Agathe Blaise","raw_affiliation_strings":["CNRS LIP6, Sorbonne Universit\u00e9, Paris, France","Thales SIX GTS France, Gennevilliers, France","Phare (France)","THALES [France] (France)"],"raw_orcid":"https://orcid.org/0000-0002-9598-8482","affiliations":[{"raw_affiliation_string":"CNRS LIP6, Sorbonne Universit\u00e9, Paris, France","institution_ids":["https://openalex.org/I39804081","https://openalex.org/I51101395","https://openalex.org/I1294671590"]},{"raw_affiliation_string":"Thales SIX GTS France, Gennevilliers, France","institution_ids":["https://openalex.org/I4210140930"]},{"raw_affiliation_string":"Phare (France)","institution_ids":[]},{"raw_affiliation_string":"THALES [France] (France)","institution_ids":["https://openalex.org/I4210140930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076067036","display_name":"Mathieu Bouet","orcid":"https://orcid.org/0000-0003-0516-8729"},"institutions":[{"id":"https://openalex.org/I4210140930","display_name":"Thales (France)","ror":"https://ror.org/04emwm605","country_code":"FR","type":"company","lineage":["https://openalex.org/I4210140930"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Mathieu Bouet","raw_affiliation_strings":["Thales SIX GTS France, Gennevilliers, France","THALES [France] (France)"],"raw_orcid":"https://orcid.org/0000-0003-0516-8729","affiliations":[{"raw_affiliation_string":"Thales SIX GTS France, Gennevilliers, France","institution_ids":["https://openalex.org/I4210140930"]},{"raw_affiliation_string":"THALES [France] (France)","institution_ids":["https://openalex.org/I4210140930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5105838501","display_name":"Vania Conan","orcid":null},"institutions":[{"id":"https://openalex.org/I4210140930","display_name":"Thales (France)","ror":"https://ror.org/04emwm605","country_code":"FR","type":"company","lineage":["https://openalex.org/I4210140930"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Vania Conan","raw_affiliation_strings":["Thales SIX GTS France, Gennevilliers, France","THALES [France] (France)"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Thales SIX GTS France, Gennevilliers, France","institution_ids":["https://openalex.org/I4210140930"]},{"raw_affiliation_string":"THALES [France] (France)","institution_ids":["https://openalex.org/I4210140930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5025676566","display_name":"Stefano Secci","orcid":"https://orcid.org/0000-0002-6129-0676"},"institutions":[{"id":"https://openalex.org/I124158823","display_name":"Conservatoire National des Arts et M\u00e9tiers","ror":"https://ror.org/0175hh227","country_code":"FR","type":"education","lineage":["https://openalex.org/I124158823","https://openalex.org/I4210134562"]},{"id":"https://openalex.org/I4210145724","display_name":"Centre d'Etudes et De Recherche en Informatique et Communications","ror":"https://ror.org/044j5mm75","country_code":"FR","type":"facility","lineage":["https://openalex.org/I4210145724"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Stefano Secci","raw_affiliation_strings":["Conservatoire National des Arts et M\u00e9tiers, CEDRIC, Paris, France","CEDRIC - ROC - CEDRIC. R\u00e9seaux et Objets Connect\u00e9s (France)"],"raw_orcid":"https://orcid.org/0000-0002-6129-0676","affiliations":[{"raw_affiliation_string":"Conservatoire National des Arts et M\u00e9tiers, CEDRIC, Paris, France","institution_ids":["https://openalex.org/I124158823","https://openalex.org/I4210145724"]},{"raw_affiliation_string":"CEDRIC - ROC - CEDRIC. R\u00e9seaux et Objets Connect\u00e9s (France)","institution_ids":["https://openalex.org/I4210145724"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5031952821"],"corresponding_institution_ids":["https://openalex.org/I1294671590","https://openalex.org/I39804081","https://openalex.org/I4210140930","https://openalex.org/I51101395"],"apc_list":null,"apc_paid":null,"fwci":3.0754,"has_fulltext":false,"cited_by_count":34,"citation_normalized_percentile":{"value":0.91701801,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"17","issue":"3","first_page":"1701","last_page":"1714"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.9548313617706299},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8200997114181519},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.7991784811019897},{"id":"https://openalex.org/keywords/denial-of-service-attack","display_name":"Denial-of-service attack","score":0.7293153405189514},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6631853580474854},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.5088031888008118},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.4121599495410919},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4106219708919525},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3731878101825714},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.3650100827217102},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.34562233090400696},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.3418189287185669},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2948465049266815},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.08908692002296448},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.0842278003692627}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.9548313617706299},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8200997114181519},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.7991784811019897},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.7293153405189514},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6631853580474854},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.5088031888008118},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.4121599495410919},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4106219708919525},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3731878101825714},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.3650100827217102},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.34562233090400696},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.3418189287185669},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2948465049266815},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.08908692002296448},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.0842278003692627},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tnsm.2020.2996502","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2020.2996502","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"},{"id":"pmh:oai:HAL:hal-02568587v1","is_oa":true,"landing_page_url":"https://hal.science/hal-02568587","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Transactions on Network and Service Management, 2020, 17 (3), pp.1701-1714. &#x27E8;10.1109/TNSM.2020.2996502&#x27E9;","raw_type":"Journal articles"}],"best_oa_location":{"id":"pmh:oai:HAL:hal-02568587v1","is_oa":true,"landing_page_url":"https://hal.science/hal-02568587","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Transactions on Network and Service Management, 2020, 17 (3), pp.1701-1714. &#x27E8;10.1109/TNSM.2020.2996502&#x27E9;","raw_type":"Journal articles"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":44,"referenced_works":["https://openalex.org/W191098608","https://openalex.org/W192611445","https://openalex.org/W1526821023","https://openalex.org/W1583098994","https://openalex.org/W1594972289","https://openalex.org/W1673310716","https://openalex.org/W1971350231","https://openalex.org/W1975461060","https://openalex.org/W1980792387","https://openalex.org/W2019030333","https://openalex.org/W2032338144","https://openalex.org/W2065479644","https://openalex.org/W2077488147","https://openalex.org/W2085313531","https://openalex.org/W2097998348","https://openalex.org/W2109722477","https://openalex.org/W2110983102","https://openalex.org/W2120871080","https://openalex.org/W2157578436","https://openalex.org/W2294483539","https://openalex.org/W2327762824","https://openalex.org/W2403153566","https://openalex.org/W2613920221","https://openalex.org/W2620580412","https://openalex.org/W2737801898","https://openalex.org/W2739052910","https://openalex.org/W2768896713","https://openalex.org/W2809684781","https://openalex.org/W2907376671","https://openalex.org/W2915130643","https://openalex.org/W2991374072","https://openalex.org/W3004307973","https://openalex.org/W3010612350","https://openalex.org/W3011200047","https://openalex.org/W3103656239","https://openalex.org/W3161677312","https://openalex.org/W6607784307","https://openalex.org/W6634779276","https://openalex.org/W6635614179","https://openalex.org/W6637131181","https://openalex.org/W6674385629","https://openalex.org/W6676367512","https://openalex.org/W6697341179","https://openalex.org/W6759742124"],"related_works":["https://openalex.org/W2294483539","https://openalex.org/W2378449000","https://openalex.org/W2938399969","https://openalex.org/W3187581118","https://openalex.org/W4230824443","https://openalex.org/W2292210693","https://openalex.org/W2038807247","https://openalex.org/W1979706594","https://openalex.org/W2097156747","https://openalex.org/W2193050358"],"abstract_inverted_index":{"Efficient":[0],"bot":[1,89,157],"detection":[2,19,90],"is":[3,72,185],"a":[4,88,142,161],"crucial":[5],"security":[6],"matter":[7],"and":[8,21,33,68,112,123,165,194],"widely":[9],"explored":[10],"in":[11,27],"the":[12,57,65,81,149],"past":[13],"years.":[14],"Recent":[15],"approaches":[16],"supplant":[17],"flow-based":[18],"techniques":[20],"exploit":[22],"graph-based":[23],"features,":[24],"incurring":[25],"however":[26],"scalability":[28,70],"issues,":[29],"with":[30,56,103],"high":[31],"time":[32],"space":[34],"complexity.":[35],"Bots":[36],"exhibit":[37],"specific":[38,46],"communication":[39,55,66],"patterns:":[40],"they":[41],"use":[42],"particular":[43],"protocols,":[44],"contact":[45],"domains,":[47],"hence":[48],"can":[49,188],"be":[50],"identified":[51],"by":[52,98],"analyzing":[53],"their":[54],"outside.":[58],"A":[59],"way":[60],"we":[61,181],"follow":[62],"to":[63,136,160,178],"simplify":[64],"graph":[67],"avoid":[69],"issues":[71],"looking":[73],"at":[74],"frequency":[75,105],"distributions":[76],"of":[77,83,156,192],"protocol":[78],"attributes":[79],"capturing":[80],"specificity":[82],"botnets":[84],"behaviour.":[85],"We":[86,145],"propose":[87],"technique":[91],"named":[92],"BotFP,":[93],"for":[94],"BotFingerPrinting,":[95],"which":[96,152],"acts":[97],"(i)":[99],"characterizing":[100],"hosts":[101,111,127],"behaviour":[102],"attribute":[104],"distribution":[106],"signatures,":[107],"(ii)":[108],"learning":[109],"benign":[110,132],"bots":[113,130],"behaviours":[114],"through":[115],"either":[116,128],"clustering":[117],"or":[118,131,139,173],"supervised":[119],"Machine":[120],"Learning":[121],"(ML),":[122],"(iii)":[124],"classifying":[125],"new":[126],"as":[129,170],"ones,":[133],"using":[134],"distances":[135],"labelled":[137],"clusters":[138],"relying":[140],"on":[141,148],"ML":[143],"algorithm.":[144],"validate":[146],"BotFP":[147,184],"CTU-13":[150],"dataset,":[151],"contains":[153],"13":[154],"scenarios":[155],"infections,":[158],"connecting":[159],"Command-and-Control":[162],"(C&C)":[163],"channel":[164],"launching":[166],"malicious":[167],"actions":[168],"such":[169],"port":[171],"scanning":[172],"Denial-of-Service":[174],"(DDoS)":[175],"attacks.":[176],"Compared":[177],"state-of-the-art":[179],"techniques,":[180],"show":[182],"that":[183],"more":[186],"lightweight,":[187],"handle":[189],"large":[190],"amounts":[191],"data,":[193],"shows":[195],"better":[196],"accuracy.":[197]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
