{"id":"https://openalex.org/W2143403916","doi":"https://doi.org/10.1145/1558607.1558662","title":"Behavioral analysis of fast flux service networks","display_name":"Behavioral analysis of fast flux service networks","publication_year":2009,"publication_date":"2009-04-13","ids":{"openalex":"https://openalex.org/W2143403916","doi":"https://doi.org/10.1145/1558607.1558662","mag":"2143403916"},"language":"en","primary_location":{"id":"doi:10.1145/1558607.1558662","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1558607.1558662","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5075202100","display_name":"Alper \u00c7a\u011flayan","orcid":"https://orcid.org/0000-0001-6884-489X"},"institutions":[{"id":"https://openalex.org/I4210148178","display_name":"Milcord (United States)","ror":"https://ror.org/04c9me270","country_code":"US","type":"company","lineage":["https://openalex.org/I4210148178"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Alper Caglayan","raw_affiliation_strings":["Milcord LLC, Waltham, MA"],"affiliations":[{"raw_affiliation_string":"Milcord LLC, Waltham, MA","institution_ids":["https://openalex.org/I4210148178"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083565118","display_name":"Mike Toothaker","orcid":null},"institutions":[{"id":"https://openalex.org/I4210148178","display_name":"Milcord (United States)","ror":"https://ror.org/04c9me270","country_code":"US","type":"company","lineage":["https://openalex.org/I4210148178"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mike Toothaker","raw_affiliation_strings":["Milcord LLC, Orono, ME"],"affiliations":[{"raw_affiliation_string":"Milcord LLC, Orono, ME","institution_ids":["https://openalex.org/I4210148178"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032835244","display_name":"Dan Drapaeau","orcid":null},"institutions":[{"id":"https://openalex.org/I4210148178","display_name":"Milcord (United States)","ror":"https://ror.org/04c9me270","country_code":"US","type":"company","lineage":["https://openalex.org/I4210148178"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dan Drapaeau","raw_affiliation_strings":["Milcord LLC, Orono, ME"],"affiliations":[{"raw_affiliation_string":"Milcord LLC, Orono, ME","institution_ids":["https://openalex.org/I4210148178"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026653910","display_name":"Dustin Burke","orcid":null},"institutions":[{"id":"https://openalex.org/I4210148178","display_name":"Milcord (United States)","ror":"https://ror.org/04c9me270","country_code":"US","type":"company","lineage":["https://openalex.org/I4210148178"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dustin Burke","raw_affiliation_strings":["Milcord LLC, Waltham, MA"],"affiliations":[{"raw_affiliation_string":"Milcord LLC, Waltham, MA","institution_ids":["https://openalex.org/I4210148178"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5041610756","display_name":"Gerry Eaton","orcid":null},"institutions":[{"id":"https://openalex.org/I4210148178","display_name":"Milcord (United States)","ror":"https://ror.org/04c9me270","country_code":"US","type":"company","lineage":["https://openalex.org/I4210148178"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gerry Eaton","raw_affiliation_strings":["Milcord LLC, Waltham, MA"],"affiliations":[{"raw_affiliation_string":"Milcord LLC, Waltham, MA","institution_ids":["https://openalex.org/I4210148178"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5075202100"],"corresponding_institution_ids":["https://openalex.org/I4210148178"],"apc_list":null,"apc_paid":null,"fwci":4.7078,"has_fulltext":false,"cited_by_count":23,"citation_normalized_percentile":{"value":0.95243548,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"4"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11478","display_name":"Caching and Content Delivery","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9969000220298767,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8270975351333618},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.7135910391807556},{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.7067631483078003},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6764827966690063},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.4894038736820221},{"id":"https://openalex.org/keywords/service","display_name":"Service (business)","score":0.487131804227829},{"id":"https://openalex.org/keywords/flux","display_name":"Flux (metallurgy)","score":0.4804393947124481},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4617021679878235},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.4217562675476074},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.41833510994911194},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3301229476928711},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.20977401733398438},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.161973774433136}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8270975351333618},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.7135910391807556},{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.7067631483078003},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6764827966690063},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.4894038736820221},{"id":"https://openalex.org/C2780378061","wikidata":"https://www.wikidata.org/wiki/Q25351891","display_name":"Service (business)","level":2,"score":0.487131804227829},{"id":"https://openalex.org/C68709404","wikidata":"https://www.wikidata.org/wiki/Q1134475","display_name":"Flux (metallurgy)","level":2,"score":0.4804393947124481},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4617021679878235},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.4217562675476074},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.41833510994911194},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3301229476928711},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.20977401733398438},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.161973774433136},{"id":"https://openalex.org/C192562407","wikidata":"https://www.wikidata.org/wiki/Q228736","display_name":"Materials science","level":0,"score":0.0},{"id":"https://openalex.org/C191897082","wikidata":"https://www.wikidata.org/wiki/Q11467","display_name":"Metallurgy","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C136264566","wikidata":"https://www.wikidata.org/wiki/Q159810","display_name":"Economy","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/1558607.1558662","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1558607.1558662","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies","raw_type":"proceedings-article"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.502.9691","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.502.9691","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.csiir.ornl.gov/csiirw/09/CSIIRW09-Proceedings/Abstracts/Caglayan-abstract.pdf","raw_type":"text"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320306110","display_name":"U.S. Department of Homeland Security","ror":"https://ror.org/00jyr0d86"},{"id":"https://openalex.org/F4320332664","display_name":"Science and Technology Directorate","ror":"https://ror.org/00jyr0d86"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":4,"referenced_works":["https://openalex.org/W80155331","https://openalex.org/W2122941797","https://openalex.org/W2159636195","https://openalex.org/W3202272593"],"related_works":["https://openalex.org/W17155033","https://openalex.org/W2149202530","https://openalex.org/W2807822918","https://openalex.org/W3207760230","https://openalex.org/W1496222301","https://openalex.org/W2921723332","https://openalex.org/W2482950156","https://openalex.org/W4396966040","https://openalex.org/W1590307681","https://openalex.org/W1966145327"],"abstract_inverted_index":{"Here":[0],"we":[1,52],"present":[2],"a":[3,19,26],"behavioral":[4],"analysis":[5],"of":[6,15,21,28,74,98],"fast":[7,55,65,75],"flux":[8,56,66,76],"service":[9],"networks":[10,77,84],"(FFSNs)":[11],"using":[12,44,62],"our":[13,54,63],"database":[14,60],"FFSNs":[16,24],"collected":[17,61],"over":[18],"period":[20],"9":[22],"months.":[23],"exploit":[25],"network":[27,67],"compromised":[29],"machines":[30],"(zombies)":[31],"for":[32],"illegal":[33],"activities":[34],"such":[35,83],"as":[36],"spam":[37],"campaigns,":[38],"phishing":[39],"scams":[40],"and":[41,58,89,96],"malware":[42],"delivery":[43],"DNS":[45],"record":[46],"manipulation":[47],"techniques.":[48],"In":[49],"this":[50],"paper,":[51],"use":[53],"domain":[57],"IP":[59],"real-time":[64],"detection":[68],"algorithm":[69],"to":[70],"analyze":[71],"the":[72],"behavior":[73],"[1].":[78],"Our":[79],"results":[80],"show":[81],"that":[82],"share":[85],"common":[86],"lifecycle":[87],"characteristics,":[88],"form":[90],"clusters":[91],"based":[92],"on":[93],"size,":[94],"growth":[95],"type":[97],"malicious":[99],"behavior.":[100]},"counts_by_year":[{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":2},{"year":2014,"cited_by_count":3},{"year":2013,"cited_by_count":3},{"year":2012,"cited_by_count":5}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
