{"id":"https://openalex.org/W2586130762","doi":"https://doi.org/10.1145/3022227.3022260","title":"C&amp;C session detection using random forest","display_name":"C&amp;C session detection using random forest","publication_year":2017,"publication_date":"2017-01-05","ids":{"openalex":"https://openalex.org/W2586130762","doi":"https://doi.org/10.1145/3022227.3022260","mag":"2586130762"},"language":"en","primary_location":{"id":"doi:10.1145/3022227.3022260","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3022227.3022260","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 11th International Conference on Ubiquitous Information Management and Communication","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101990691","display_name":"Lu Liang","orcid":"https://orcid.org/0000-0001-5373-8445"},"institutions":[{"id":"https://openalex.org/I135598925","display_name":"Kyushu University","ror":"https://ror.org/00p4k0j84","country_code":"JP","type":"education","lineage":["https://openalex.org/I135598925"]}],"countries":["JP"],"is_corresponding":true,"raw_author_name":"Liang Lu","raw_affiliation_strings":["Kyushu University, Fukuoka, JAPAN"],"affiliations":[{"raw_affiliation_string":"Kyushu University, Fukuoka, JAPAN","institution_ids":["https://openalex.org/I135598925"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079342045","display_name":"Yaokai Feng","orcid":"https://orcid.org/0000-0001-6074-2514"},"institutions":[{"id":"https://openalex.org/I135598925","display_name":"Kyushu University","ror":"https://ror.org/00p4k0j84","country_code":"JP","type":"education","lineage":["https://openalex.org/I135598925"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Yaokai Feng","raw_affiliation_strings":["Kyushu University, Fukuoka, JAPAN"],"affiliations":[{"raw_affiliation_string":"Kyushu University, Fukuoka, JAPAN","institution_ids":["https://openalex.org/I135598925"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001126368","display_name":"Kouichi Sakurai","orcid":"https://orcid.org/0000-0003-4621-1674"},"institutions":[{"id":"https://openalex.org/I135598925","display_name":"Kyushu University","ror":"https://ror.org/00p4k0j84","country_code":"JP","type":"education","lineage":["https://openalex.org/I135598925"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Kouichi Sakurai","raw_affiliation_strings":["Kyushu University, Fukuoka, JAPAN"],"affiliations":[{"raw_affiliation_string":"Kyushu University, Fukuoka, JAPAN","institution_ids":["https://openalex.org/I135598925"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5101990691"],"corresponding_institution_ids":["https://openalex.org/I135598925"],"apc_list":null,"apc_paid":null,"fwci":1.8648,"has_fulltext":false,"cited_by_count":15,"citation_normalized_percentile":{"value":0.87156465,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.8964189291000366},{"id":"https://openalex.org/keywords/denial-of-service-attack","display_name":"Denial-of-service attack","score":0.850376307964325},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.797134280204773},{"id":"https://openalex.org/keywords/random-forest","display_name":"Random forest","score":0.6454414129257202},{"id":"https://openalex.org/keywords/payload","display_name":"Payload (computing)","score":0.5864869952201843},{"id":"https://openalex.org/keywords/command-and-control","display_name":"Command and control","score":0.5753951072692871},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5247309803962708},{"id":"https://openalex.org/keywords/session","display_name":"Session (web analytics)","score":0.5175989866256714},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.49809765815734863},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.4927385151386261},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.42534157633781433},{"id":"https://openalex.org/keywords/application-layer-ddos-attack","display_name":"Application layer DDoS attack","score":0.42461097240448},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.23138415813446045},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.20452821254730225},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.19938409328460693},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.16839972138404846},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.10607859492301941}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.8964189291000366},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.850376307964325},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.797134280204773},{"id":"https://openalex.org/C169258074","wikidata":"https://www.wikidata.org/wiki/Q245748","display_name":"Random forest","level":2,"score":0.6454414129257202},{"id":"https://openalex.org/C134066672","wikidata":"https://www.wikidata.org/wiki/Q1424639","display_name":"Payload (computing)","level":3,"score":0.5864869952201843},{"id":"https://openalex.org/C506615639","wikidata":"https://www.wikidata.org/wiki/Q21662260","display_name":"Command and control","level":2,"score":0.5753951072692871},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5247309803962708},{"id":"https://openalex.org/C2779182362","wikidata":"https://www.wikidata.org/wiki/Q17126187","display_name":"Session (web analytics)","level":2,"score":0.5175989866256714},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.49809765815734863},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.4927385151386261},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.42534157633781433},{"id":"https://openalex.org/C120865594","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Application layer DDoS attack","level":4,"score":0.42461097240448},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.23138415813446045},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.20452821254730225},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.19938409328460693},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.16839972138404846},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.10607859492301941},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3022227.3022260","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3022227.3022260","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 11th International Conference on Ubiquitous Information Management and Communication","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6899999976158142,"display_name":"Life in Land","id":"https://metadata.un.org/sdg/15"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":6,"referenced_works":["https://openalex.org/W1546505347","https://openalex.org/W1680392829","https://openalex.org/W2026621111","https://openalex.org/W2128509737","https://openalex.org/W2285840518","https://openalex.org/W2924374262"],"related_works":["https://openalex.org/W2783792841","https://openalex.org/W3166165364","https://openalex.org/W2598265749","https://openalex.org/W2560748881","https://openalex.org/W2181380068","https://openalex.org/W4285609096","https://openalex.org/W2389528884","https://openalex.org/W4284680554","https://openalex.org/W2779270152","https://openalex.org/W2419539551"],"abstract_inverted_index":{"DDoS":[0,94,102],"(Distributed":[1],"Denial":[2],"of":[3,8,14,29,69,80,87,93,152,168,182],"Service)":[4,15],"attack":[5,21,33,44,63],"is":[6,18,71,83,107,117,149],"one":[7],"the":[9,43,52,122,145,166,175,180],"most":[10],"used":[11],"DoS":[12],"(Denial":[13],"attack.":[16,103],"It":[17],"a":[19,27,34,56,84,101,130,139],"distributed":[20],"in":[22],"which":[23],"an":[24,108,150],"attacker":[25,53],"uses":[26,55],"multitude":[28],"compromised":[30,38],"computers":[31,39],"to":[32,59,65,111,119,143],"single":[35],"target.":[36],"Those":[37],"that":[40,154,170,188],"actually":[41],"execute":[42],"are":[45],"called":[46,72],"botnet.":[47],"To":[48],"hide":[49],"their":[50],"identity,":[51],"usually":[54],"third-party":[57],"server":[58,70],"control":[60],"and":[61,90,137],"send":[62],"command":[64,126],"bots,":[66],"this":[67],"kind":[68],"C&C":[73,81,97,113,183,195],"(command":[74],"&":[75],"control)":[76],"server.":[77],"The":[78],"detection":[79,89,92,181],"sessions":[82,114],"strong":[85],"proof":[86],"botnet":[88],"early":[91],"attacks":[95],"as":[96,115],"connections":[98],"occur":[99],"before":[100],"Network":[104],"traffic":[105],"analysis":[106],"effective":[109],"method":[110],"detect":[112],"it":[116,162],"hard":[118],"avoid":[120],"encrypting":[121],"payload":[123],"or":[124],"change":[125],"code.":[127],"We":[128],"consider":[129],"new":[131],"feature":[132],"vector":[133],"with":[134,157],"55":[135],"features,":[136],"use":[138],"random":[140],"forest":[141,148],"algorithm":[142],"build":[144],"classifier.":[146],"Random":[147],"ensemble":[151],"classifiers":[153],"can":[155,163],"deal":[156],"high-dimension":[158],"problems.":[159],"In":[160],"fact,":[161],"also":[164],"calculate":[165],"importance":[167],"features":[169,177],"will":[171],"help":[172],"us":[173],"find":[174],"key":[176],"responsible":[178],"for":[179],"sessions.":[184],"Experimental":[185],"results":[186],"show":[187],"our":[189],"approach":[190],"has":[191],"better":[192],"performance":[193],"on":[194],"session":[196],"detection.":[197]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":4},{"year":2019,"cited_by_count":2},{"year":2018,"cited_by_count":2},{"year":2017,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
