{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T15:56:25Z","timestamp":1783526185401,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":18,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540770473","type":"print"},{"value":"9783540770480","type":"electronic"}],"license":[{"start":{"date-parts":[[2007,1,1]],"date-time":"2007-01-01T00:00:00Z","timestamp":1167609600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2007]]},"DOI":"10.1007\/978-3-540-77048-0_34","type":"book-chapter","created":{"date-parts":[[2007,11,16]],"date-time":"2007-11-16T15:10:22Z","timestamp":1195225822000},"page":"438-451","source":"Crossref","is-referenced-by-count":22,"title":["Collecting Autonomous Spreading Malware Using High-Interaction Honeypots"],"prefix":"10.1007","author":[{"given":"Jianwei","family":"Zhuge","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thorsten","family":"Holz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinhui","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chengyu","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Zou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"34_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/11856214_9","volume-title":"Recent Advances in Intrusion Detection","author":"P. Baecher","year":"2006","unstructured":"Baecher, P., Koetter, M., Holz, T., Dornseif, M., Freiling, F.C.: The nepenthes platform: An efficient approach to collect malware. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 165\u2013184. Springer, Heidelberg (2006)"},{"key":"34_CR2","volume-title":"Proceeedings of the 6th IEEE Information Assurance Workshop","author":"E. Balas","year":"2005","unstructured":"Balas, E., Viecco, C.: Towards a Third Generation Data Capture Architecture for Honeynets. In: Proceeedings of the 6th IEEE Information Assurance Workshop, IEEE Computer Society Press, Los Alamitos (2005)"},{"key":"34_CR3","doi-asserted-by":"crossref","unstructured":"Goebel, J., Holz, T., Willems, C.: Measurement and Analysis of Autonomous Spreading Malware in a University Environment. In: Proceeding of 4th Conference on Detection of Intrusions & Malware, and Vulnerability Assessment (DIMVA 2007) (2007)","DOI":"10.1007\/978-3-540-73614-1_7"},{"key":"34_CR4","unstructured":"Intel Corporation and SystemSoft. The preboot execution environment specification v2.1 (September 1999), https:\/\/2.zoppoz.workers.dev:443\/http\/www.pix.net\/software\/pxeboot\/archive\/pxespec.pdf"},{"key":"34_CR5","doi-asserted-by":"crossref","unstructured":"Levine, J., Grizzard, J., Owen, H.: Application of a methodology to characterize rootkits retrieved from honeynets. In: Proceedings of the 5th Information Assurance Workshop, pp. 15\u201321 (2004)","DOI":"10.1109\/IAW.2004.1437792"},{"issue":"4","key":"34_CR6","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1109\/MSECP.2003.1219056","volume":"1","author":"D. Moore","year":"2003","unstructured":"Moore, D., Paxson, V., Savage, S., Shannon, C., Staniford, S., Weaver, N.: Inside the slammer worm. IEEE Security and Privacy\u00a01(4), 33\u201339 (2003)","journal-title":"IEEE Security and Privacy"},{"issue":"4","key":"34_CR7","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1218063.1217938","volume":"40","author":"G. Portokalidis","year":"2006","unstructured":"Portokalidis, G., Slowinska, A., Bos, H.: Argos: an emulator for fingerprinting zero-day attacks for advertised honeypots with automatic signature generation. SIGOPS Oper. Syst. Rev.\u00a040(4), 15\u201327 (2006)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"34_CR8","unstructured":"Provos, N.: A virtual honeypot framework. In: Proceedings of the 13th USENIX Security Symposium (August 2004)"},{"key":"34_CR9","volume-title":"Virtual Honeypots: From Botnet Tracking to Intrusion Detection","author":"N. Provos","year":"2007","unstructured":"Provos, N., Holz, T.: Virtual Honeypots: From Botnet Tracking to Intrusion Detection. Addison-Wesley Professional, Reading (2007)"},{"key":"34_CR10","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1145\/1177080.1177086","volume-title":"Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement","author":"M.A. Rajab","year":"2006","unstructured":"Rajab, M.A., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, pp. 41\u201352. ACM Press, New York (2006)"},{"key":"34_CR11","unstructured":"Stewart, J.: Mocbot\/MS06-040 IRC bot analysis, (August 2006), https:\/\/2.zoppoz.workers.dev:443\/http\/www.secureworks.com\/research\/threats\/mocbot-ms06040\/"},{"key":"34_CR12","unstructured":"Symantec Inc. Symantec Internet security threat report: Trends for January - June 2007, (2007), https:\/\/2.zoppoz.workers.dev:443\/http\/www.symantec.com\/business\/theme.jsp?themeid=threatreport"},{"key":"34_CR13","unstructured":"The Honeynet Project. Know Your Enemy, https:\/\/2.zoppoz.workers.dev:443\/http\/honeynet.org\/"},{"key":"34_CR14","unstructured":"The Honeynet Project. Know Your Enemy: Tracking Botnets (March 2005), https:\/\/2.zoppoz.workers.dev:443\/http\/www.honeynet.org\/papers\/bots\/"},{"key":"34_CR15","unstructured":"The Honeynet Project. Honeywall CDROM, (March 2007), https:\/\/2.zoppoz.workers.dev:443\/http\/honeynet.org\/tools\/cdrom\/"},{"issue":"5","key":"34_CR16","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1145\/1095809.1095825","volume":"39","author":"M. Vrable","year":"2005","unstructured":"Vrable, M., Ma, J., Chen, J., Moore, D., Vandekieft, E., Snoeren, A.C., Voelker, G.M., Savage, S.: Scalability, fidelity, and containment in the potemkin virtual honeyfarm. SIGOPS Oper. Syst. Rev.\u00a039(5), 148\u2013162 (2005)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"34_CR17","unstructured":"Wang, Y.-M., Beck, D., Jiang, X., Roussev, R., Verbowski, C., Chen, S., King, S.T.: Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities. In: NDSS (2006)"},{"key":"34_CR18","unstructured":"Werner, T.: honeytrap: Ein Meta-Honeypot zur Identifikation und Analyse neuer Angriffstechniken. In: Proceedings of the 14th DFN-CERT Workshop Sicherheit in vernetzten Systemen (2007), https:\/\/2.zoppoz.workers.dev:443\/http\/honeytrap.mwcollect.org"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-77048-0_34","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,22]],"date-time":"2025-01-22T13:14:28Z","timestamp":1737551668000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/link.springer.com\/10.1007\/978-3-540-77048-0_34"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007]]},"ISBN":["9783540770473","9783540770480"],"references-count":18,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/978-3-540-77048-0_34","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2007]]}}}