{"id":"https://openalex.org/W2978691144","doi":"https://doi.org/10.1109/hpcc/smartcity/dss.2019.00090","title":"A New Hybrid Approach for C&amp;C Channel Detection","display_name":"A New Hybrid Approach for C&amp;C Channel Detection","publication_year":2019,"publication_date":"2019-08-01","ids":{"openalex":"https://openalex.org/W2978691144","doi":"https://doi.org/10.1109/hpcc/smartcity/dss.2019.00090","mag":"2978691144"},"language":"en","primary_location":{"id":"doi:10.1109/hpcc/smartcity/dss.2019.00090","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hpcc/smartcity/dss.2019.00090","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 IEEE 21st International Conference on High Performance Computing and Communications; IEEE 17th International Conference on Smart City; IEEE 5th International Conference on Data Science and Systems (HPCC/SmartCity/DSS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102722080","display_name":"Jianguo Jiang","orcid":"https://orcid.org/0000-0002-0947-9500"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Jianguo Jiang","raw_affiliation_strings":["School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001953231","display_name":"Qilei Yin","orcid":"https://orcid.org/0000-0002-0148-2772"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qilei Yin","raw_affiliation_strings":["School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108660469","display_name":"Zhixin Shi","orcid":null},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhixin Shi","raw_affiliation_strings":["School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101801918","display_name":"Qiwen Wang","orcid":"https://orcid.org/0000-0001-9471-1409"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qiwen Wang","raw_affiliation_strings":["School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5026526428","display_name":"Wei Zhou","orcid":"https://orcid.org/0000-0003-3622-3970"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wei Zhou","raw_affiliation_strings":["Unit 32256, China"],"affiliations":[{"raw_affiliation_string":"Unit 32256, China","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5102722080"],"corresponding_institution_ids":["https://openalex.org/I4210165038"],"apc_list":null,"apc_paid":null,"fwci":0.7074,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.7383493,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":"45","issue":null,"first_page":"583","last_page":"590"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/heuristic","display_name":"Heuristic","score":0.7596186399459839},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7357109785079956},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7313805818557739},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.6417186260223389},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5470082759857178},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.5293845534324646},{"id":"https://openalex.org/keywords/channel","display_name":"Channel (broadcasting)","score":0.5168648362159729},{"id":"https://openalex.org/keywords/filter","display_name":"Filter (signal processing)","score":0.5155191421508789},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4724700152873993},{"id":"https://openalex.org/keywords/measure","display_name":"Measure (data warehouse)","score":0.46099212765693665},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3816923499107361},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.12376540899276733}],"concepts":[{"id":"https://openalex.org/C173801870","wikidata":"https://www.wikidata.org/wiki/Q201413","display_name":"Heuristic","level":2,"score":0.7596186399459839},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7357109785079956},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7313805818557739},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.6417186260223389},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5470082759857178},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.5293845534324646},{"id":"https://openalex.org/C127162648","wikidata":"https://www.wikidata.org/wiki/Q16858953","display_name":"Channel (broadcasting)","level":2,"score":0.5168648362159729},{"id":"https://openalex.org/C106131492","wikidata":"https://www.wikidata.org/wiki/Q3072260","display_name":"Filter (signal processing)","level":2,"score":0.5155191421508789},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4724700152873993},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.46099212765693665},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3816923499107361},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.12376540899276733},{"id":"https://openalex.org/C120665830","wikidata":"https://www.wikidata.org/wiki/Q14620","display_name":"Optics","level":1,"score":0.0},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.0},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/hpcc/smartcity/dss.2019.00090","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hpcc/smartcity/dss.2019.00090","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2019 IEEE 21st International Conference on High Performance Computing and Communications; IEEE 17th International Conference on Smart City; IEEE 5th International Conference on Data Science and Systems (HPCC/SmartCity/DSS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure","score":0.4099999964237213}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W47988595","https://openalex.org/W70584117","https://openalex.org/W1504269120","https://openalex.org/W1583098994","https://openalex.org/W1775772884","https://openalex.org/W1820098372","https://openalex.org/W1916198581","https://openalex.org/W2021753915","https://openalex.org/W2026621111","https://openalex.org/W2064675550","https://openalex.org/W2077488147","https://openalex.org/W2105497548","https://openalex.org/W2114250523","https://openalex.org/W2114996745","https://openalex.org/W2120256168","https://openalex.org/W2157331557","https://openalex.org/W2157949690","https://openalex.org/W2162969618","https://openalex.org/W2184678913","https://openalex.org/W2296719434","https://openalex.org/W2331488455","https://openalex.org/W2606697812","https://openalex.org/W2736937187","https://openalex.org/W2748868501","https://openalex.org/W2963197901","https://openalex.org/W6601890406","https://openalex.org/W6602816918","https://openalex.org/W6634779276","https://openalex.org/W6638021444","https://openalex.org/W6638648299","https://openalex.org/W6675613107","https://openalex.org/W6697265569","https://openalex.org/W6743493502"],"related_works":["https://openalex.org/W2294483539","https://openalex.org/W2378449000","https://openalex.org/W2901835651","https://openalex.org/W2883616266","https://openalex.org/W186576250","https://openalex.org/W2002178493","https://openalex.org/W2372254325","https://openalex.org/W3005861778","https://openalex.org/W2185627654","https://openalex.org/W13127727"],"abstract_inverted_index":{"A":[0],"great":[1],"many":[2],"of":[3,23,128],"botnet":[4],"detection":[5,31,106,186],"researches":[6],"focus":[7],"on":[8],"recognizing":[9],"and":[10,100,181],"blocking":[11],"its":[12],"significant":[13,145],"C&C":[14,24,37,66,76,94,98,105,126],"channel.":[15],"And":[16],"they":[17],"typically":[18],"require":[19],"a":[20,29,59,108,184],"certain":[21],"number":[22],"training":[25,38,77],"instances":[26,39],"to":[27,73,90],"build":[28],"behavior":[30,109,160,171],"model.":[32],"However,":[33],"when":[34],"lacking":[35],"the":[36,75,92,103,124,136,149,174],"for":[40,63,119,131],"new":[41,60],"or":[42,51],"even":[43,52],"unknown":[44],"botnets,":[45],"these":[46],"methods":[47],"may":[48],"become":[49],"inefficient":[50],"invalid.":[53],"To":[54],"overcome":[55],"it,":[56],"we":[57],"propose":[58],"hybrid":[61],"approach":[62,122,143],"network":[64,164],"based":[65,110,153],"channel":[67],"detection.":[68],"It":[69,85],"neither":[70],"needs":[71],"us":[72],"prepare":[74],"instances,":[78],"nor":[79],"requires":[80,116],"deploying":[81],"malicious":[82],"activities":[83],"monitors.":[84],"utilizes":[86],"two":[87],"heuristic":[88,151],"rules":[89],"filter":[91],"non":[93],"traffic":[95,118,165],"disobeying":[96],"common":[97],"characteristics,":[99],"then":[101,182],"makes":[102],"final":[104],"through":[107],"anomaly":[111,175],"detecting":[112],"model,":[113],"which":[114],"only":[115,140],"normal":[117],"training.":[120],"Our":[121],"achieved":[123],"average":[125],"F-measure":[127],"above":[129],"0.9":[130],"most":[132],"evaluation":[133],"datasets.":[134],"Moreover,":[135],"comparison":[137],"result":[138],"not":[139],"demonstrates":[141],"our":[142,159],"has":[144],"performance":[146],"advantages":[147],"than":[148,173],"pure":[150],"rule":[152],"methods,":[154],"but":[155],"also":[156],"shows":[157],"that":[158],"model":[161],"can":[162],"profile":[163],"in":[166],"detail,":[167],"mine":[168],"more":[169],"useful":[170],"differences":[172],"models":[176],"using":[177],"traditional":[178],"statistical":[179],"features,":[180],"achieve":[183],"better":[185],"result.":[187]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
