{"id":"https://openalex.org/W2768896713","doi":"https://doi.org/10.1109/csnet.2017.8241990","title":"BotGM: Unsupervised graph mining to detect botnets in traffic flows","display_name":"BotGM: Unsupervised graph mining to detect botnets in traffic flows","publication_year":2017,"publication_date":"2017-10-01","ids":{"openalex":"https://openalex.org/W2768896713","doi":"https://doi.org/10.1109/csnet.2017.8241990","mag":"2768896713"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/csnet.2017.8241990","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://inria.hal.science/hal-01636480/document","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5082230185","display_name":"Sofiane Lagraa","orcid":"https://orcid.org/0000-0003-3185-9152"},"institutions":[{"id":"https://openalex.org/I4210127166","display_name":"Centre Inria de l'Universit\u00e9 de Lorraine","ror":"https://ror.org/03fcjvn64","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1326498283","https://openalex.org/I4210127166"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Sofiane Lagraa","raw_affiliation_strings":["Inria Nancy Grand Est, France"],"affiliations":[{"raw_affiliation_string":"Inria Nancy Grand Est, France","institution_ids":["https://openalex.org/I4210127166"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035034365","display_name":"J\u00e9r\u00f4me Fran\u00e7ois","orcid":"https://orcid.org/0000-0002-7457-458X"},"institutions":[{"id":"https://openalex.org/I186903577","display_name":"University of Luxembourg","ror":"https://ror.org/036x5ad56","country_code":"LU","type":"education","lineage":["https://openalex.org/I186903577"]},{"id":"https://openalex.org/I4210127166","display_name":"Centre Inria de l'Universit\u00e9 de Lorraine","ror":"https://ror.org/03fcjvn64","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1326498283","https://openalex.org/I4210127166"]}],"countries":["FR","LU"],"is_corresponding":false,"raw_author_name":"Jerome Francois","raw_affiliation_strings":["Inria Nancy Grand Est, France","SnT, University of Luxembourg, Luxembourg"],"affiliations":[{"raw_affiliation_string":"SnT, University of Luxembourg, Luxembourg","institution_ids":["https://openalex.org/I186903577"]},{"raw_affiliation_string":"Inria Nancy Grand Est, France","institution_ids":["https://openalex.org/I4210127166"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111932337","display_name":"Abdelkader Lahmadi","orcid":null},"institutions":[{"id":"https://openalex.org/I90183372","display_name":"Universit\u00e9 de Lorraine","ror":"https://ror.org/04vfs2w97","country_code":"FR","type":"education","lineage":["https://openalex.org/I90183372"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Abdelkader Lahmadi","raw_affiliation_strings":["Universit\u00e9 de Lorraine, France"],"affiliations":[{"raw_affiliation_string":"Universit\u00e9 de Lorraine, France","institution_ids":["https://openalex.org/I90183372"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045341514","display_name":"Marine Miner","orcid":null},"institutions":[{"id":"https://openalex.org/I90183372","display_name":"Universit\u00e9 de Lorraine","ror":"https://ror.org/04vfs2w97","country_code":"FR","type":"education","lineage":["https://openalex.org/I90183372"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Marine Miner","raw_affiliation_strings":["Universit\u00e9 de Lorraine, France"],"affiliations":[{"raw_affiliation_string":"Universit\u00e9 de Lorraine, France","institution_ids":["https://openalex.org/I90183372"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004384801","display_name":"Christian Hammerschmidt","orcid":"https://orcid.org/0000-0003-2460-1997"},"institutions":[{"id":"https://openalex.org/I186903577","display_name":"University of Luxembourg","ror":"https://ror.org/036x5ad56","country_code":"LU","type":"education","lineage":["https://openalex.org/I186903577"]}],"countries":["LU"],"is_corresponding":false,"raw_author_name":"Christian Hammerschmidt","raw_affiliation_strings":["SnT, University of Luxembourg, Luxembourg"],"affiliations":[{"raw_affiliation_string":"SnT, University of Luxembourg, Luxembourg","institution_ids":["https://openalex.org/I186903577"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069228908","display_name":"Radu State","orcid":"https://orcid.org/0000-0002-4751-9577"},"institutions":[{"id":"https://openalex.org/I186903577","display_name":"University of Luxembourg","ror":"https://ror.org/036x5ad56","country_code":"LU","type":"education","lineage":["https://openalex.org/I186903577"]}],"countries":["LU"],"is_corresponding":false,"raw_author_name":"Radu State","raw_affiliation_strings":["SnT, University of Luxembourg, Luxembourg"],"affiliations":[{"raw_affiliation_string":"SnT, University of Luxembourg, Luxembourg","institution_ids":["https://openalex.org/I186903577"]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":30,"citation_normalized_percentile":{"value":0.962435,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":93,"max":94},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9986,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.9948028},{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.4227364}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.9948028},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7684901},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.7468978},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7126882},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.6117743},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.5221113},{"id":"https://openalex.org/C114809511","wikidata":"https://www.wikidata.org/wiki/Q1412924","display_name":"Flow network","level":2,"score":0.4255073},{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.4227364},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.35508472},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.20454043},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.16653317},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0}],"mesh":[],"locations_count":5,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/csnet.2017.8241990","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.inria.fr/hal-01636480","pdf_url":"https://inria.hal.science/hal-01636480/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://inria.hal.science/hal-01636480/file/botgm-csnet.pdf","pdf_url":"https://inria.hal.science/hal-01636480/file/botgm-csnet.pdf","source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.inria.fr/hal-01636480/document","pdf_url":"https://hal.inria.fr/hal-01636480/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.inria.fr/hal-01636480/file/botgm-csnet.pdf","pdf_url":"https://hal.inria.fr/hal-01636480/file/botgm-csnet.pdf","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://hal.inria.fr/hal-01636480","pdf_url":"https://inria.hal.science/hal-01636480/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, justice, and strong institutions","score":0.48}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":34,"referenced_works":["https://openalex.org/W1529004212","https://openalex.org/W1594972289","https://openalex.org/W1676351273","https://openalex.org/W1909494783","https://openalex.org/W191098608","https://openalex.org/W1916198581","https://openalex.org/W1975844474","https://openalex.org/W1988667381","https://openalex.org/W2010541316","https://openalex.org/W2012917383","https://openalex.org/W2026621111","https://openalex.org/W2046720672","https://openalex.org/W2053550965","https://openalex.org/W2065323196","https://openalex.org/W2077488147","https://openalex.org/W2079625175","https://openalex.org/W2082550445","https://openalex.org/W2085313531","https://openalex.org/W2093331366","https://openalex.org/W2109877485","https://openalex.org/W2110675786","https://openalex.org/W2120665430","https://openalex.org/W2122646361","https://openalex.org/W2126401948","https://openalex.org/W2133259017","https://openalex.org/W2164348526","https://openalex.org/W2239778906","https://openalex.org/W2520335248","https://openalex.org/W2522714599","https://openalex.org/W2560810941","https://openalex.org/W2736633391","https://openalex.org/W2738334271","https://openalex.org/W2738616664","https://openalex.org/W4240946707"],"related_works":["https://openalex.org/W4285325964","https://openalex.org/W4230824443","https://openalex.org/W2929621094","https://openalex.org/W2559738661","https://openalex.org/W2378449000","https://openalex.org/W2294483539","https://openalex.org/W2097156747","https://openalex.org/W2038807247","https://openalex.org/W1996006176","https://openalex.org/W1599449514"],"abstract_inverted_index":{"Botnets":[0],"are":[1,13,49],"one":[2],"of":[3,17,34,70,89,127,145],"the":[4,59,108,114],"most":[5],"dangerous":[6],"and":[7,106],"serious":[8],"cybersecurity":[9],"threats":[10],"since":[11],"they":[12],"a":[14,78,122,138],"major":[15],"vector":[16],"large-scale":[18],"attack":[19],"campaigns":[20],"such":[21,57],"as":[22,58],"phishing,":[23],"distributed":[24],"denial-of-service":[25],"(DDoS)":[26],"attacks,":[27],"trojans,":[28],"spams,":[29],"etc.":[30],"A":[31],"large":[32,125],"body":[33],"research":[35],"has":[36],"been":[37],"accomplished":[38],"on":[39,86,121],"botnet":[40,83,135],"detection,":[41],"but":[42],"recent":[43],"security":[44],"incidents":[45],"show":[46],"that":[47],"there":[48],"still":[50],"several":[51],"challenges":[52],"remaining":[53],"to":[54,61,81,102,112],"be":[55],"addressed,":[56],"ability":[60],"develop":[62],"detectors":[63],"which":[64],"can":[65],"cope":[66],"with":[67,137],"new":[68,79],"types":[69],"botnets.":[71],"In":[72],"this":[73],"paper,":[74],"we":[75],"propose":[76],"BotGM,":[77],"approach":[80],"detect":[82,103],"activities":[84],"based":[85],"behavioral":[87],"analysis":[88],"network":[90,95,129],"traffic":[91,96],"flow.":[92],"BotGM":[93,120],"identifies":[94],"behavior":[97],"using":[98],"graph-based":[99],"mining":[100],"techniques":[101],"botnets":[104],"behaviors":[105,136],"model":[107],"dependencies":[109],"among":[110],"flows":[111],"trace-back":[113],"root":[115],"causes":[116],"then.":[117],"We":[118],"applied":[119],"publicly":[123],"available":[124],"dataset":[126],"Botnet":[128],"flows,":[130],"where":[131],"it":[132],"detects":[133],"various":[134],"high":[139],"accuracy":[140],"without":[141],"any":[142],"prior":[143],"knowledge":[144],"them.":[146]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2768896713","counts_by_year":[{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":13},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":2}],"updated_date":"2025-01-22T23:44:54.610618","created_date":"2017-12-04"}