{"id":"https://openalex.org/W2773105226","doi":"https://doi.org/10.1155/2017/5960307","title":"Detecting Web-Based Botnets Using Bot Communication Traffic Features","display_name":"Detecting Web-Based Botnets Using Bot Communication Traffic Features","publication_year":2017,"publication_date":"2017-01-01","ids":{"openalex":"https://openalex.org/W2773105226","doi":"https://doi.org/10.1155/2017/5960307","mag":"2773105226"},"language":"en","primary_location":{"id":"doi:10.1155/2017/5960307","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2017/5960307","pdf_url":"http://downloads.hindawi.com/journals/scn/2017/5960307.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"http://downloads.hindawi.com/journals/scn/2017/5960307.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5024320548","display_name":"Fu\u2010Hau Hsu","orcid":"https://orcid.org/0000-0002-2586-5874"},"institutions":[{"id":"https://openalex.org/I22265921","display_name":"National Central University","ror":"https://ror.org/00944ve71","country_code":"TW","type":"education","lineage":["https://openalex.org/I22265921"]}],"countries":["TW"],"is_corresponding":false,"raw_author_name":"Fu-Hau Hsu","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Central University, Taoyuan, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Central University, Taoyuan, Taiwan","institution_ids":["https://openalex.org/I22265921"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022945580","display_name":"Chih\u2010Wen Ou","orcid":"https://orcid.org/0000-0002-8310-5283"},"institutions":[{"id":"https://openalex.org/I22265921","display_name":"National Central University","ror":"https://ror.org/00944ve71","country_code":"TW","type":"education","lineage":["https://openalex.org/I22265921"]}],"countries":["TW"],"is_corresponding":true,"raw_author_name":"Chih-Wen Ou","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Central University, Taoyuan, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Central University, Taoyuan, Taiwan","institution_ids":["https://openalex.org/I22265921"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111696283","display_name":"Yan-Ling Hwang","orcid":null},"institutions":[{"id":"https://openalex.org/I91279580","display_name":"Chung Shan Medical University","ror":"https://ror.org/059ryjv25","country_code":"TW","type":"education","lineage":["https://openalex.org/I91279580"]}],"countries":["TW"],"is_corresponding":false,"raw_author_name":"Yan-Ling Hwang","raw_affiliation_strings":["School of Applied Foreign Languages, Chung Shan Medical University, Taichung, Taiwan"],"affiliations":[{"raw_affiliation_string":"School of Applied Foreign Languages, Chung Shan Medical University, Taichung, Taiwan","institution_ids":["https://openalex.org/I91279580"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023681988","display_name":"Ya\u2010Ching Chang","orcid":"https://orcid.org/0000-0003-4937-7557"},"institutions":[{"id":"https://openalex.org/I22265921","display_name":"National Central University","ror":"https://ror.org/00944ve71","country_code":"TW","type":"education","lineage":["https://openalex.org/I22265921"]}],"countries":["TW"],"is_corresponding":false,"raw_author_name":"Ya-Ching Chang","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Central University, Taoyuan, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Central University, Taoyuan, Taiwan","institution_ids":["https://openalex.org/I22265921"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5109385099","display_name":"Po-Ching Lin","orcid":null},"institutions":[{"id":"https://openalex.org/I148099254","display_name":"National Chung Cheng University","ror":"https://ror.org/0028v3876","country_code":"TW","type":"education","lineage":["https://openalex.org/I148099254"]}],"countries":["TW"],"is_corresponding":false,"raw_author_name":"Po-Ching Lin","raw_affiliation_strings":["Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan","institution_ids":["https://openalex.org/I148099254"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5022945580"],"corresponding_institution_ids":["https://openalex.org/I22265921"],"apc_list":{"value":2100,"currency":"USD","value_usd":2100},"apc_paid":{"value":2100,"currency":"USD","value_usd":2100},"fwci":1.3123,"has_fulltext":true,"cited_by_count":11,"citation_normalized_percentile":{"value":0.84069683,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"2017","issue":null,"first_page":"1","last_page":"11"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.9725086688995361},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8108334541320801},{"id":"https://openalex.org/keywords/web-server","display_name":"Web server","score":0.6195203065872192},{"id":"https://openalex.org/keywords/command-and-control","display_name":"Command and control","score":0.6024647951126099},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.559817910194397},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.5535475015640259},{"id":"https://openalex.org/keywords/web-traffic","display_name":"Web traffic","score":0.5345486998558044},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.46117082238197327},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.4537501633167267},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.42860472202301025},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.3223170340061188},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.2252652943134308},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.06759804487228394}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.9725086688995361},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8108334541320801},{"id":"https://openalex.org/C11392498","wikidata":"https://www.wikidata.org/wiki/Q11288","display_name":"Web server","level":3,"score":0.6195203065872192},{"id":"https://openalex.org/C506615639","wikidata":"https://www.wikidata.org/wiki/Q21662260","display_name":"Command and control","level":2,"score":0.6024647951126099},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.559817910194397},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.5535475015640259},{"id":"https://openalex.org/C2777672014","wikidata":"https://www.wikidata.org/wiki/Q1172573","display_name":"Web traffic","level":3,"score":0.5345486998558044},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.46117082238197327},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.4537501633167267},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.42860472202301025},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.3223170340061188},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.2252652943134308},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.06759804487228394},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1155/2017/5960307","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2017/5960307","pdf_url":"http://downloads.hindawi.com/journals/scn/2017/5960307.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:5405dd528db14c77b74bc5c0945f5176","is_oa":true,"landing_page_url":"https://doaj.org/article/5405dd528db14c77b74bc5c0945f5176","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Security and Communication Networks, Vol 2017 (2017)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1155/2017/5960307","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2017/5960307","pdf_url":"http://downloads.hindawi.com/journals/scn/2017/5960307.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1823200592","display_name":null,"funder_award_id":"106-3114-E-002-005","funder_id":"https://openalex.org/F4320322795","funder_display_name":"Ministry of Science and Technology, Taiwan"},{"id":"https://openalex.org/G5810762849","display_name":null,"funder_award_id":"105-2221-E-008-074-MY3","funder_id":"https://openalex.org/F4320322795","funder_display_name":"Ministry of Science and Technology, Taiwan"},{"id":"https://openalex.org/G7160539585","display_name":null,"funder_award_id":"Technology","funder_id":"https://openalex.org/F4320322795","funder_display_name":"Ministry of Science and Technology, Taiwan"}],"funders":[{"id":"https://openalex.org/F4320322795","display_name":"Ministry of Science and Technology, Taiwan","ror":"https://ror.org/02kv4zf79"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2773105226.pdf","grobid_xml":"https://content.openalex.org/works/W2773105226.grobid-xml"},"referenced_works_count":12,"referenced_works":["https://openalex.org/W8726526","https://openalex.org/W1837843568","https://openalex.org/W1979562156","https://openalex.org/W1997984797","https://openalex.org/W2026621111","https://openalex.org/W2058314598","https://openalex.org/W2065323196","https://openalex.org/W2130216882","https://openalex.org/W2159909072","https://openalex.org/W2399968856","https://openalex.org/W2586432806","https://openalex.org/W3125182500"],"related_works":["https://openalex.org/W2401158552","https://openalex.org/W86804927","https://openalex.org/W2898126008","https://openalex.org/W1583098994","https://openalex.org/W2386447999","https://openalex.org/W2130216882","https://openalex.org/W2091214382","https://openalex.org/W2376288852","https://openalex.org/W2100671106","https://openalex.org/W1533158771"],"abstract_inverted_index":{"Web-based":[0,6,93],"botnets":[1,108],"are":[2,115,135],"popular":[3],"nowadays.":[4],"A":[5],"botnet":[7,10,33,113],"is":[8,98,151],"a":[9,71,88],"whose":[11],"C&amp;C":[12,103],"server":[13,73],"and":[14,22,54,74],"bots":[15],"use":[16],"HTTP":[17,45,77,107],"protocol,":[18,25],"the":[19,32,42,67,83,112,145],"most":[20],"universal":[21],"supported":[23],"network":[24,49,128],"to":[26,80,100,137],"communicate":[27],"with":[28],"each":[29],"other.":[30],"Because":[31],"communication":[34],"can":[35],"be":[36],"hidden":[37,118],"easily":[38],"by":[39],"attackers":[40],"behind":[41],"relatively":[43],"massive":[44],"traffic,":[46],"administrators":[47],"of":[48,63,70,76,106,110,149],"equipment,":[50],"such":[51,58],"as":[52],"routers":[53,134],"switches,":[55],"cannot":[56],"block":[57],"suspicious":[59,102],"traffic":[60,89],"directly":[61],"regardless":[62,109],"costs.":[64],"Based":[65],"on":[66],"clients":[68,81],"constituent":[69],"Web":[72,121],"characteristics":[75],"responses":[78],"sent":[79],"from":[82,131],"server,":[84],"this":[85],"paper":[86],"proposes":[87],"inspection":[90],"solution,":[91],"called":[92],"Botnet":[94],"Detector":[95],"(WBD).":[96],"WBD":[97,150],"able":[99],"detect":[101],"(Command-and-Control)":[104],"servers":[105],"whether":[111],"commands":[114],"encrypted":[116],"or":[117],"in":[119],"normal":[120],"pages.":[122],"More":[123],"than":[124],"500":[125],"GB":[126],"real":[127],"traces":[129],"collected":[130],"11":[132],"backbone":[133],"used":[136],"evaluate":[138],"our":[139],"method.":[140],"Experimental":[141],"results":[142],"show":[143],"that":[144],"false":[146],"positive":[147],"rate":[148],"0.42%.":[152]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":4}],"updated_date":"2026-03-12T08:34:05.389933","created_date":"2025-10-10T00:00:00"}
