1. Antonakakis, M., Perdisci, R., Dagon, D., Lee, W., Feamster, N.: Building a dynamic reputation system for DNS. In: Proceedings of the 19th USENIX Security Symposium (Security 2010). USENIX Association (August 2010)
2. Choi, H., Lee, H.: Identifying botnets by capturing group activities in DNS traffic. Journal of Computer Networks 56, 20–33 (2011)
3. Cuppens, F., Miège, A.: Alert correlation in a cooperative intrusion detection framework. In: Proceedings of IEEE Symposium on Security and Privacy, pp. 202–215 (May 2002)
4. IFIP ACIT, ch.13;A. Flaglien,2011
5. Goebel, J., Holz, T.: Rishi: Identifying bot-contaminated hosts by IRC nickname evaluation. In: HotBots 2007: Proceedings of the First USENIX Workshop on Hot Topics in Understanding Botnets, Cambridge, Mass. USENIX Association (June 2007)