{"id":"https://openalex.org/W4389279009","doi":"https://doi.org/10.1145/3627106.3627126","title":"Global Analysis with Aggregation-based Beaconing Detection across Large Campus Networks","display_name":"Global Analysis with Aggregation-based Beaconing Detection across Large Campus Networks","publication_year":2023,"publication_date":"2023-12-02","ids":{"openalex":"https://openalex.org/W4389279009","doi":"https://doi.org/10.1145/3627106.3627126"},"language":"en","primary_location":{"id":"doi:10.1145/3627106.3627126","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3627106.3627126","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3627106.3627126","source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3627106.3627126","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5027344932","display_name":"Yizhe Zhang","orcid":"https://orcid.org/0009-0008-3938-8838"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yizhe Zhang","raw_affiliation_strings":["University of Virginia, USA"],"raw_orcid":"https://orcid.org/0009-0008-3938-8838","affiliations":[{"raw_affiliation_string":"University of Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015534390","display_name":"Hongying Dong","orcid":"https://orcid.org/0000-0002-7846-2649"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hongying Dong","raw_affiliation_strings":["University of Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0002-7846-2649","affiliations":[{"raw_affiliation_string":"University of Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060286120","display_name":"Alastair Nottingham","orcid":"https://orcid.org/0000-0001-8427-0670"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alastair Nottingham","raw_affiliation_strings":["University of Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0001-8427-0670","affiliations":[{"raw_affiliation_string":"University of Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103226843","display_name":"Molly Buchanan","orcid":"https://orcid.org/0009-0009-8288-0999"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Molly Buchanan","raw_affiliation_strings":["University of Virginia, USA"],"raw_orcid":"https://orcid.org/0009-0009-8288-0999","affiliations":[{"raw_affiliation_string":"University of Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086462231","display_name":"Donald E. Brown","orcid":"https://orcid.org/0000-0002-9140-2632"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Donald E. Brown","raw_affiliation_strings":["University of Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0002-9140-2632","affiliations":[{"raw_affiliation_string":"University of Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5026356718","display_name":"Yixin Sun","orcid":"https://orcid.org/0000-0001-6650-4373"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yixin Sun","raw_affiliation_strings":["University of Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0001-6650-4373","affiliations":[{"raw_affiliation_string":"University of Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.4592,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.64285714,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"565","last_page":"579"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9965999722480774,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7792911529541016},{"id":"https://openalex.org/keywords/ranking","display_name":"Ranking (information retrieval)","score":0.6338851451873779},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.6072477102279663},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5249657034873962},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.43600940704345703},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.4335663914680481},{"id":"https://openalex.org/keywords/profiling","display_name":"Profiling (computer programming)","score":0.42444974184036255},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.4172557294368744},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3818366229534149},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3567560911178589},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.19171100854873657}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7792911529541016},{"id":"https://openalex.org/C189430467","wikidata":"https://www.wikidata.org/wiki/Q7293293","display_name":"Ranking (information retrieval)","level":2,"score":0.6338851451873779},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.6072477102279663},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5249657034873962},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.43600940704345703},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.4335663914680481},{"id":"https://openalex.org/C187191949","wikidata":"https://www.wikidata.org/wiki/Q1138496","display_name":"Profiling (computer programming)","level":2,"score":0.42444974184036255},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.4172557294368744},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3818366229534149},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3567560911178589},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.19171100854873657},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3627106.3627126","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3627106.3627126","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3627106.3627126","source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3627106.3627126","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3627106.3627126","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3627106.3627126","source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.5600000023841858}],"awards":[{"id":"https://openalex.org/G5103986228","display_name":"Collaborative Research: IMR: MM-1B: Automating Privacy-Preserving Data Sharing of Campus Network Traffic Logs","funder_award_id":"2319421","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7813542729","display_name":null,"funder_award_id":"W911NF18C0019","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"},{"id":"https://openalex.org/G7923272048","display_name":null,"funder_award_id":"CNS-2154962,CNS-2319421","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320323817","display_name":"Universitas Brawijaya","ror":"https://ror.org/01wk3d929"},{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"},{"id":"https://openalex.org/F4320332815","display_name":"Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4389279009.pdf","grobid_xml":"https://content.openalex.org/works/W4389279009.grobid-xml"},"referenced_works_count":40,"referenced_works":["https://openalex.org/W27994497","https://openalex.org/W1504269120","https://openalex.org/W1969082358","https://openalex.org/W2007221293","https://openalex.org/W2044023374","https://openalex.org/W2056073337","https://openalex.org/W2065323196","https://openalex.org/W2071897576","https://openalex.org/W2086908486","https://openalex.org/W2101823270","https://openalex.org/W2102262986","https://openalex.org/W2110861376","https://openalex.org/W2114996745","https://openalex.org/W2117149360","https://openalex.org/W2120256168","https://openalex.org/W2139733965","https://openalex.org/W2148500771","https://openalex.org/W2149701633","https://openalex.org/W2157949690","https://openalex.org/W2159418097","https://openalex.org/W2170689836","https://openalex.org/W2295822884","https://openalex.org/W2326059556","https://openalex.org/W2529444969","https://openalex.org/W2555608580","https://openalex.org/W2603136197","https://openalex.org/W2775389171","https://openalex.org/W2808758749","https://openalex.org/W2885618505","https://openalex.org/W2900204506","https://openalex.org/W2964159205","https://openalex.org/W2973744207","https://openalex.org/W2980720901","https://openalex.org/W3007098654","https://openalex.org/W3013589944","https://openalex.org/W3035160371","https://openalex.org/W3046195400","https://openalex.org/W3167251133","https://openalex.org/W3206325220","https://openalex.org/W4299301436"],"related_works":["https://openalex.org/W2161444195","https://openalex.org/W2589019771","https://openalex.org/W2188500270","https://openalex.org/W2303858293","https://openalex.org/W2985540061","https://openalex.org/W2185012154","https://openalex.org/W3037187668","https://openalex.org/W4252521128","https://openalex.org/W2915512527","https://openalex.org/W51364034"],"abstract_inverted_index":{"We":[0,60],"present":[1],"a":[2,37,50,83],"new":[3],"approach":[4],"to":[5,99,119],"effectively":[6],"detect":[7,87],"and":[8,29,49,57],"prioritize":[9],"malicious":[10,110],"beaconing":[11],"activities":[12,21],"in":[13,46],"large":[14,74],"campus":[15,75],"networks":[16,97],"by":[17,92],"profiling":[18],"the":[19,120,128],"server":[20],"through":[22],"aggregated":[23,47],"signals":[24,94],"across":[25,95],"multiple":[26,96],"traffic":[27,70],"protocols":[28],"networks.":[30],"Key":[31],"components":[32],"of":[33,68,113,130],"our":[34,62,103,131],"system":[35,64],"include":[36],"novel":[38],"time-series":[39],"analysis":[40],"algorithm":[41],"that":[42,54],"uncovers":[43],"hidden":[44],"periodicity":[45],"signals,":[48],"ranking-based":[51],"detection":[52,63],"pipeline":[53,105],"utilizes":[55],"self-training":[56],"active-learning":[58],"techniques.":[59],"evaluate":[61],"on":[65],"10":[66],"months":[67],"real-world":[69],"collected":[71],"at":[72,127],"two":[73],"networks,":[76],"comprising":[77],"over":[78],"75":[79],"billion":[80],"connections.":[81],"On":[82],"daily":[84],"average,":[85],"we":[86],"43%":[88],"more":[89],"periodic":[90],"domains":[91],"aggregating":[93],"compared":[98],"single-network":[100],"analysis.":[101],"Furthermore,":[102],"ranking":[104],"successfully":[106],"identifies":[107],"1,387":[108],"unique":[109],"domains,":[111],"out":[112],"which":[114],"781":[115],"(56%)":[116],"were":[117],"unknown":[118],"major":[121],"online":[122],"threat":[123],"intelligence":[124],"platform,":[125],"VirusTotal,":[126],"time":[129],"detection.":[132]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
