{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:AWUQZTYWMFPATKPQUWI7P7PWKP","short_pith_number":"pith:AWUQZTYW","schema_version":"1.0","canonical_sha256":"05a90ccf16615e09a9f0a591f7fdf653d8af4e770588a8067947021628943c51","source":{"kind":"arxiv","id":"1811.00925","version":1},"attestation_state":"computed","paper":{"title":"An Anomaly-based Botnet Detection Approach for Identifying Stealthy Botnets","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hooman Sanatkar, Maghsoud Abbaspour, Mehdi Kharrazi, Sajjad Arshad","submitted_at":"2018-11-02T15:12:45Z","abstract_excerpt":"Botnets (networks of compromised computers) are often used for malicious activities such as spam, click fraud, identity theft, phishing, and distributed denial of service (DDoS) attacks. Most of previous researches have introduced fully or partially signature-based botnet detection approaches. In this paper, we propose a fully anomaly-based approach that requires no a priori knowledge of bot signatures, botnet C&C protocols, and C&C server addresses. We start from inherent characteristics of botnets. Bots connect to the C&C channel and execute the received commands. Bots belonging to the same "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1811.00925","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-11-02T15:12:45Z","cross_cats_sorted":[],"title_canon_sha256":"efd82333aebd375146cf45a9352c8c530f5ba89af027f778ad3eb0ae1900ec87","abstract_canon_sha256":"9b0a4152fd7811c4307c8609914c1c8b58736be42a9d7a87325d7b508babbc0a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:01:41.729934Z","signature_b64":"0Np27tmMp6DPJuS9wx3PbdLRVR/CAhNsb3OQwP6J8xSdnB314rCGIdor97Va15G1pFUnsuNt4DcesVxcJrAbAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"05a90ccf16615e09a9f0a591f7fdf653d8af4e770588a8067947021628943c51","last_reissued_at":"2026-05-18T00:01:41.729438Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:01:41.729438Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"An Anomaly-based Botnet Detection Approach for Identifying Stealthy Botnets","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hooman Sanatkar, Maghsoud Abbaspour, Mehdi Kharrazi, Sajjad Arshad","submitted_at":"2018-11-02T15:12:45Z","abstract_excerpt":"Botnets (networks of compromised computers) are often used for malicious activities such as spam, click fraud, identity theft, phishing, and distributed denial of service (DDoS) attacks. Most of previous researches have introduced fully or partially signature-based botnet detection approaches. In this paper, we propose a fully anomaly-based approach that requires no a priori knowledge of bot signatures, botnet C&C protocols, and C&C server addresses. We start from inherent characteristics of botnets. Bots connect to the C&C channel and execute the received commands. Bots belonging to the same "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.00925","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1811.00925","created_at":"2026-05-18T00:01:41.729518+00:00"},{"alias_kind":"arxiv_version","alias_value":"1811.00925v1","created_at":"2026-05-18T00:01:41.729518+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.00925","created_at":"2026-05-18T00:01:41.729518+00:00"},{"alias_kind":"pith_short_12","alias_value":"AWUQZTYWMFPA","created_at":"2026-05-18T12:32:13.499390+00:00"},{"alias_kind":"pith_short_16","alias_value":"AWUQZTYWMFPATKPQ","created_at":"2026-05-18T12:32:13.499390+00:00"},{"alias_kind":"pith_short_8","alias_value":"AWUQZTYW","created_at":"2026-05-18T12:32:13.499390+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2605.23004","citing_title":"Botnet Detection on CTU-13 Using Lightweight Machine Learning Models","ref_index":4,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP","json":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP.json","graph_json":"https://pith.science/api/pith-number/AWUQZTYWMFPATKPQUWI7P7PWKP/graph.json","events_json":"https://pith.science/api/pith-number/AWUQZTYWMFPATKPQUWI7P7PWKP/events.json","paper":"https://pith.science/paper/AWUQZTYW"},"agent_actions":{"view_html":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP","download_json":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP.json","view_paper":"https://pith.science/paper/AWUQZTYW","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1811.00925&json=true","fetch_graph":"https://pith.science/api/pith-number/AWUQZTYWMFPATKPQUWI7P7PWKP/graph.json","fetch_events":"https://pith.science/api/pith-number/AWUQZTYWMFPATKPQUWI7P7PWKP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP/action/storage_attestation","attest_author":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP/action/author_attestation","sign_citation":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP/action/citation_signature","submit_replication":"https://pith.science/pith/AWUQZTYWMFPATKPQUWI7P7PWKP/action/replication_record"}},"created_at":"2026-05-18T00:01:41.729518+00:00","updated_at":"2026-05-18T00:01:41.729518+00:00"}