{"id":"https://openalex.org/W1621952536","doi":"https://doi.org/10.1109/iwcmc.2015.7289115","title":"Semantics based analysis of botnet activity from heterogeneous data sources","display_name":"Semantics based analysis of botnet activity from heterogeneous data sources","publication_year":2015,"publication_date":"2015-08-01","ids":{"openalex":"https://openalex.org/W1621952536","doi":"https://doi.org/10.1109/iwcmc.2015.7289115","mag":"1621952536"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/iwcmc.2015.7289115","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://hal.science/hal-01162734/document","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5017900691","display_name":"Santiago Ruano Rinc\u00f3n","orcid":"https://orcid.org/0000-0003-4806-2561"},"institutions":[{"id":"https://openalex.org/I4210148559","display_name":"\u00c9cole nationale sup\u00e9rieure de techniques avanc\u00e9es Bretagne","ror":"https://ror.org/059n54003","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210148559"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Santiago Ruano Rincon","raw_affiliation_strings":["INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)"],"affiliations":[{"raw_affiliation_string":"INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)","institution_ids":["https://openalex.org/I4210148559"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043411973","display_name":"Sandrine Vaton","orcid":"https://orcid.org/0000-0001-8940-6004"},"institutions":[{"id":"https://openalex.org/I2802519937","display_name":"Institut de Recherche en Informatique et Syst\u00e8mes Al\u00e9atoires","ror":"https://ror.org/00myn0z94","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I1326498283","https://openalex.org/I2802204017","https://openalex.org/I2802519937","https://openalex.org/I28221208","https://openalex.org/I4210127572","https://openalex.org/I4210159245","https://openalex.org/I56067802"]},{"id":"https://openalex.org/I4210148559","display_name":"\u00c9cole nationale sup\u00e9rieure de techniques avanc\u00e9es Bretagne","ror":"https://ror.org/059n54003","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210148559"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Sandrine Vaton","raw_affiliation_strings":["ADOPNET - Advanced technologies for operated networks (T\u00e9l\u00e9com Bretagne - Technop\u00f4le Brest Iroise - CS 83818 - 29238 BREST Cedex 3 / IRISA - Campus de Beaulieu 35042 Rennes cedex - France)","INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)"],"affiliations":[{"raw_affiliation_string":"ADOPNET - Advanced technologies for operated networks (T\u00e9l\u00e9com Bretagne - Technop\u00f4le Brest Iroise - CS 83818 - 29238 BREST Cedex 3 / IRISA - Campus de Beaulieu 35042 Rennes cedex - France)","institution_ids":["https://openalex.org/I2802519937"]},{"raw_affiliation_string":"INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)","institution_ids":["https://openalex.org/I4210148559"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053896866","display_name":"Antoine Beugnard","orcid":"https://orcid.org/0000-0002-3096-237X"},"institutions":[{"id":"https://openalex.org/I2802519937","display_name":"Institut de Recherche en Informatique et Syst\u00e8mes Al\u00e9atoires","ror":"https://ror.org/00myn0z94","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I1326498283","https://openalex.org/I2802204017","https://openalex.org/I2802519937","https://openalex.org/I28221208","https://openalex.org/I4210127572","https://openalex.org/I4210159245","https://openalex.org/I56067802"]},{"id":"https://openalex.org/I4210148559","display_name":"\u00c9cole nationale sup\u00e9rieure de techniques avanc\u00e9es Bretagne","ror":"https://ror.org/059n54003","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210148559"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Antoine Beugnard","raw_affiliation_strings":["INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)","PASS - Process for Adaptative Software Systems (T\u00e9l\u00e9com Bretagne - Technop\u00f4le Brest Iroise - CS 83818 - 29238 BREST Cedex 3 /\r\nIRISA - Campus de Beaulieu 35042 Rennes cedex - France)"],"affiliations":[{"raw_affiliation_string":"PASS - Process for Adaptative Software Systems (T\u00e9l\u00e9com Bretagne - Technop\u00f4le Brest Iroise - CS 83818 - 29238 BREST Cedex 3 /\r\nIRISA - Campus de Beaulieu 35042 Rennes cedex - France)","institution_ids":["https://openalex.org/I2802519937"]},{"raw_affiliation_string":"INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)","institution_ids":["https://openalex.org/I4210148559"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5000339680","display_name":"Serge Garlatti","orcid":null},"institutions":[{"id":"https://openalex.org/I161929037","display_name":"Universit\u00e9 de Bretagne Occidentale","ror":"https://ror.org/01b8h3982","country_code":"FR","type":"education","lineage":["https://openalex.org/I161929037"]},{"id":"https://openalex.org/I4210148559","display_name":"\u00c9cole nationale sup\u00e9rieure de techniques avanc\u00e9es Bretagne","ror":"https://ror.org/059n54003","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210148559"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Serge Garlatti","raw_affiliation_strings":["INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)","Lab-STICC_TB_CID_IHSEV (France)"],"affiliations":[{"raw_affiliation_string":"Lab-STICC_TB_CID_IHSEV (France)","institution_ids":["https://openalex.org/I161929037"]},{"raw_affiliation_string":"INFO - D\u00e9partement informatique (T\u00e9l\u00e9com Bretagne Technopole Brest Iroise CS 83818 29238 Brest Cedex 3 - France)","institution_ids":["https://openalex.org/I4210148559"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":3,"citation_normalized_percentile":{"value":0.818287,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":76,"max":79},"biblio":{"volume":null,"issue":null,"first_page":"391","last_page":"396"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9993,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.818082}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8185509},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.818082},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.67741793},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.5075933},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.46269354},{"id":"https://openalex.org/C2780586882","wikidata":"https://www.wikidata.org/wiki/Q7520643","display_name":"Simple (philosophy)","level":2,"score":0.45133078},{"id":"https://openalex.org/C75684735","wikidata":"https://www.wikidata.org/wiki/Q858810","display_name":"Big data","level":2,"score":0.4380754},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3897543},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.21876308},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.12868726},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/iwcmc.2015.7289115","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.archives-ouvertes.fr/hal-01162734","pdf_url":"https://hal.science/hal-01162734/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.archives-ouvertes.fr/hal-01162734/file/paper-botnet-case-study-TB-publishable.pdf","pdf_url":"https://hal.archives-ouvertes.fr/hal-01162734/file/paper-botnet-case-study-TB-publishable.pdf","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://hal.archives-ouvertes.fr/hal-01162734/document","pdf_url":"https://hal.archives-ouvertes.fr/hal-01162734/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://hal.archives-ouvertes.fr/hal-01162734","pdf_url":"https://hal.science/hal-01162734/document","source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":["Centre National de la Recherche Scientifique"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":17,"referenced_works":["https://openalex.org/W1027316353","https://openalex.org/W1518438846","https://openalex.org/W1654805921","https://openalex.org/W1976955738","https://openalex.org/W2003967425","https://openalex.org/W2004259102","https://openalex.org/W2100035808","https://openalex.org/W2111427271","https://openalex.org/W2119192239","https://openalex.org/W2142096121","https://openalex.org/W2154874878","https://openalex.org/W2155273278","https://openalex.org/W2167366440","https://openalex.org/W2298478167","https://openalex.org/W2576712987","https://openalex.org/W4285719527","https://openalex.org/W96766689"],"related_works":["https://openalex.org/W3187581118","https://openalex.org/W3143747655","https://openalex.org/W3005861778","https://openalex.org/W2901835651","https://openalex.org/W2883616266","https://openalex.org/W2378449000","https://openalex.org/W2372254325","https://openalex.org/W2294483539","https://openalex.org/W2002178493","https://openalex.org/W186576250"],"abstract_inverted_index":{"The":[0],"diversity":[1],"in":[2,82],"network":[3,18,22,59,77],"devices,":[4],"protocols,":[5],"data":[6,80],"sources":[7,64],"and":[8,16,28,111],"probes":[9],"impose":[10],"different":[11,66],"challenges":[12,45],"to":[13,31,56,61,75,79,121],"uniformly":[14],"measure":[15,34],"analyse":[17],"traffic.":[19],"Analysing":[20],"a":[21,72,91,101],"means":[23],"considering":[24],"distinctive":[25],"reporting":[26],"approaches":[27],"diverse":[29],"methods":[30],"represent":[32],"data,":[33],"times":[35],"or":[36],"identify":[37],"nodes.":[38],"In":[39,68],"this":[40,87],"work,":[41],"we":[42,70,89],"tackle":[43],"these":[44],"by":[46],"relying":[47],"on":[48,86],"semantics,":[49],"taking":[50,129],"advantage":[51],"of":[52,65,104],"the":[53],"ontologies'":[54],"ability":[55],"map":[57,76],"high-level":[58],"concepts":[60,78],"concrete":[62],"information":[63],"nature.":[67],"particular,":[69],"propose":[71],"simple":[73],"architecture":[74],"stored":[81],"relational":[83],"databases.":[84],"Based":[85],"architecture,":[88],"implement":[90],"tool":[92],"that":[93],"looks":[94],"for":[95],"malicious":[96],"bot":[97],"activity,":[98],"studying,":[99],"from":[100,108,114],"unique":[102],"point":[103],"view,":[105],"DNS":[106,124],"traffic":[107],"PCAP":[109],"sources,":[110],"TCP":[112],"connections":[113],"IPFIX":[115],"reports.":[116],"This":[117],"approach":[118],"is":[119],"able":[120],"enhance":[122],"current":[123],"based":[125],"botnet":[126],"detection":[127],"methods,":[128],"into":[130],"account":[131],"additional":[132],"heterogeneous":[133],"analysis":[134],"elements.":[135]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W1621952536","counts_by_year":[{"year":2020,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2016,"cited_by_count":1}],"updated_date":"2024-12-11T22:17:16.400780","created_date":"2016-06-24"}