{"id":"https://openalex.org/W2772124517","doi":"https://doi.org/10.1145/3134600.3134605","title":"DECANTeR","display_name":"DECANTeR","publication_year":2017,"publication_date":"2017-12-04","ids":{"openalex":"https://openalex.org/W2772124517","doi":"https://doi.org/10.1145/3134600.3134605","mag":"2772124517"},"language":"en","primary_location":{"id":"doi:10.1145/3134600.3134605","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3134600.3134605","pdf_url":"http://dl.acm.org/ft_gateway.cfm?id=3134605&type=pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"http://dl.acm.org/ft_gateway.cfm?id=3134605&type=pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5047353024","display_name":"Riccardo Bortolameotti","orcid":null},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":true,"raw_author_name":"Riccardo Bortolameotti","raw_affiliation_strings":["University of Twente"],"affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026980331","display_name":"Thijs van Ede","orcid":"https://orcid.org/0000-0003-3865-6390"},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Thijs van Ede","raw_affiliation_strings":["University of Twente"],"affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103253596","display_name":"Marco Caselli","orcid":"https://orcid.org/0000-0003-4883-797X"},"institutions":[{"id":"https://openalex.org/I1325886976","display_name":"Siemens (Germany)","ror":"https://ror.org/059mq0909","country_code":"DE","type":"company","lineage":["https://openalex.org/I1325886976"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Marco Caselli","raw_affiliation_strings":["Siemens AG"],"affiliations":[{"raw_affiliation_string":"Siemens AG","institution_ids":["https://openalex.org/I1325886976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084056996","display_name":"Maarten H. Everts","orcid":"https://orcid.org/0000-0002-5302-8985"},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Maarten H. Everts","raw_affiliation_strings":["University of Twente and TNO"],"affiliations":[{"raw_affiliation_string":"University of Twente and TNO","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5016345474","display_name":"Pieter Hartel","orcid":"https://orcid.org/0000-0002-0411-0421"},"institutions":[{"id":"https://openalex.org/I98358874","display_name":"Delft University of Technology","ror":"https://ror.org/02e2c7k09","country_code":"NL","type":"education","lineage":["https://openalex.org/I98358874"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Pieter Hartel","raw_affiliation_strings":["Delft University of Technology"],"affiliations":[{"raw_affiliation_string":"Delft University of Technology","institution_ids":["https://openalex.org/I98358874"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087439261","display_name":"Rick Hofstede","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rick Hofstede","raw_affiliation_strings":["RedSocks Security B.V"],"affiliations":[{"raw_affiliation_string":"RedSocks Security B.V","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111432433","display_name":"Willem Jonker","orcid":"https://orcid.org/0009-0009-7028-2967"},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Willem Jonker","raw_affiliation_strings":["University of Twente"],"affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5056553463","display_name":"Peter Andreas","orcid":"https://orcid.org/0000-0003-2929-5001"},"institutions":[{"id":"https://openalex.org/I94624287","display_name":"University of Twente","ror":"https://ror.org/006hf6230","country_code":"NL","type":"education","lineage":["https://openalex.org/I94624287"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Andreas Peter","raw_affiliation_strings":["University of Twente"],"affiliations":[{"raw_affiliation_string":"University of Twente","institution_ids":["https://openalex.org/I94624287"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5047353024"],"corresponding_institution_ids":["https://openalex.org/I94624287"],"apc_list":null,"apc_paid":null,"fwci":2.1878,"has_fulltext":true,"cited_by_count":31,"citation_normalized_percentile":{"value":0.8972849,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"373","last_page":"386"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.8561475276947021},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7802435159683228},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.73234623670578},{"id":"https://openalex.org/keywords/evasion","display_name":"Evasion (ethics)","score":0.7231454849243164},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.6197333335876465},{"id":"https://openalex.org/keywords/covert","display_name":"Covert","score":0.6158223152160645},{"id":"https://openalex.org/keywords/false-positive-rate","display_name":"False positive rate","score":0.48545271158218384},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.38162773847579956},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3546275198459625},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3358922600746155},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.277925580739975}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.8561475276947021},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7802435159683228},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.73234623670578},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.7231454849243164},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.6197333335876465},{"id":"https://openalex.org/C2779338814","wikidata":"https://www.wikidata.org/wiki/Q5179285","display_name":"Covert","level":2,"score":0.6158223152160645},{"id":"https://openalex.org/C95922358","wikidata":"https://www.wikidata.org/wiki/Q5432725","display_name":"False positive rate","level":2,"score":0.48545271158218384},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.38162773847579956},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3546275198459625},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3358922600746155},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.277925580739975},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C203014093","wikidata":"https://www.wikidata.org/wiki/Q101929","display_name":"Immunology","level":1,"score":0.0},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C8891405","wikidata":"https://www.wikidata.org/wiki/Q1059","display_name":"Immune system","level":2,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/3134600.3134605","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3134600.3134605","pdf_url":"http://dl.acm.org/ft_gateway.cfm?id=3134605&type=pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd Annual Computer Security Applications Conference","raw_type":"proceedings-article"},{"id":"pmh:oai:ris.utwente.nl:openaire/41ceea25-6280-48d9-b1d3-3d86ca0df6db","is_oa":true,"landing_page_url":"https://research.utwente.nl/en/publications/41ceea25-6280-48d9-b1d3-3d86ca0df6db","pdf_url":"https://ris.utwente.nl/ws/files/28122244/p373_bortolameotti.pdf","source":{"id":"https://openalex.org/S4406922991","display_name":"University of Twente Research Information","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Bortolameotti, R, van Ede, T, Caselli, M, Everts, M H, Hartel, P, Hofstede, R, Jonker, W & Peter, A 2017, DECANTeR: DEteCtion of Anomalous outbouNd HTTP TRaffic by Passive Application Fingerprinting. in ACSAC 2017 : Proceedings of the 33rd Annual Computer Security Applications Conference. Association for Computing Machinery, New York, NY, pp. 373-386, 33nd Annual Computer Security Applications Conference 2017 , Orlando, Florida, United States, 4/12/17. https://doi.org/10.1145/3134600.3134605","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:tud:oai:tudelft.nl:uuid:cf0a47eb-a6a1-4d18-974e-4b099fca592b","is_oa":true,"landing_page_url":"http://resolver.tudelft.nl/uuid:cf0a47eb-a6a1-4d18-974e-4b099fca592b","pdf_url":"http://resolver.tudelft.nl/uuid:cf0a47eb-a6a1-4d18-974e-4b099fca592b","source":{"id":"https://openalex.org/S4306401843","display_name":"Data Archiving and Networked Services (DANS)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1322597698","host_organization_name":"Royal Netherlands Academy of Arts and Sciences","host_organization_lineage":["https://openalex.org/I1322597698"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Proceedings - 33rd Annual Computer Security Applications Conference, ACSAC 2017, Part F132521","raw_type":"info:eu-repo/semantics/conferencepaper"},{"id":"pmh:oai:ris.utwente.nl:publications/41ceea25-6280-48d9-b1d3-3d86ca0df6db","is_oa":false,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922991","display_name":"University of Twente Research Information","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":""}],"best_oa_location":{"id":"doi:10.1145/3134600.3134605","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3134600.3134605","pdf_url":"http://dl.acm.org/ft_gateway.cfm?id=3134605&type=pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6600000262260437}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2772124517.pdf","grobid_xml":"https://content.openalex.org/works/W2772124517.grobid-xml"},"referenced_works_count":39,"referenced_works":["https://openalex.org/W12316596","https://openalex.org/W70584117","https://openalex.org/W1451710050","https://openalex.org/W1493883477","https://openalex.org/W1507388815","https://openalex.org/W1516506771","https://openalex.org/W1583098994","https://openalex.org/W1598169875","https://openalex.org/W1682759715","https://openalex.org/W1775772884","https://openalex.org/W1827212170","https://openalex.org/W1973980104","https://openalex.org/W1990981691","https://openalex.org/W1992110042","https://openalex.org/W1993861188","https://openalex.org/W2011184586","https://openalex.org/W2012543144","https://openalex.org/W2018916405","https://openalex.org/W2031029123","https://openalex.org/W2041836242","https://openalex.org/W2092756033","https://openalex.org/W2103378897","https://openalex.org/W2114996745","https://openalex.org/W2121008990","https://openalex.org/W2124929753","https://openalex.org/W2136433906","https://openalex.org/W2146189323","https://openalex.org/W2150115633","https://openalex.org/W2182726966","https://openalex.org/W2200463568","https://openalex.org/W2276979642","https://openalex.org/W2498359591","https://openalex.org/W2559964890","https://openalex.org/W2612544399","https://openalex.org/W2773722012","https://openalex.org/W2896042305","https://openalex.org/W2914982603","https://openalex.org/W3121817559","https://openalex.org/W4235400066"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4387298227","https://openalex.org/W2526398307","https://openalex.org/W2470029541","https://openalex.org/W4387065217","https://openalex.org/W4285357721","https://openalex.org/W4368275542","https://openalex.org/W2470502009","https://openalex.org/W3152957156","https://openalex.org/W2388600609"],"abstract_inverted_index":{"We":[0,46,63,106],"present":[1],"DECANTeR,":[2],"a":[3,20,42,48,69],"system":[4,27,67],"to":[5,29,161],"detect":[6,30,162],"anomalous":[7],"outbound":[8],"HTTP":[9,119,127],"communication,":[10],"which":[11,117,157],"passively":[12],"extracts":[13],"fingerprints":[14,39],"for":[15,75],"each":[16],"application":[17],"running":[18],"on":[19,125],"monitored":[21,77],"host.":[22],"The":[23,129],"goal":[24],"of":[25,60,73,84,138,151],"our":[26,66,108,155],"is":[28],"unknown":[31,38],"malware":[32,93],"and":[33,57,86,144],"backdoor":[34],"communication":[35,121],"indicated":[36],"by":[37,92,123],"extracted":[40],"from":[41,53],"host's":[43],"network":[44],"traffic.":[45,62,128],"evaluate":[47],"prototype":[49],"with":[50,110],"realistic":[51],"data":[52,163],"an":[54,80],"international":[55],"organization":[56],"datasets":[58],"composed":[59],"malicious":[61],"show":[64,131],"that":[65,87,132],"achieves":[68],"false":[70,141],"positive":[71,142],"rate":[72,83],"0.9%":[74],"441":[76],"host":[78],"machines,":[79],"average":[81],"detection":[82,139],"97.7%,":[85],"it":[88],"cannot":[89],"be":[90],"evaded":[91],"using":[94,100],"simple":[95],"evasion":[96],"techniques":[97],"such":[98],"as":[99],"known":[101],"browser":[102],"user":[103],"agent":[104],"values.":[105],"compare":[107],"solution":[109],"DUMONT":[111,135],"[24],":[112],"the":[113],"current":[114],"state-of-the-art":[115],"IDS":[116],"detects":[118,149],"covert":[120],"channels":[122],"focusing":[124],"benign":[126],"results":[130],"DECANTeR":[133,148],"outperforms":[134],"in":[136,154],"terms":[137],"rate,":[140,143],"even":[145],"evasion-resistance.":[146],"Finally,":[147],"96.8%":[150],"information":[152],"stealers":[153],"dataset,":[156],"shows":[158],"its":[159],"potential":[160],"exfiltration.":[164]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":2},{"year":2018,"cited_by_count":3}],"updated_date":"2026-03-17T17:19:04.345684","created_date":"2017-12-22T00:00:00"}
