{"id":"W2937420105","doi":"","title":"Exploring a Service-Based Normal Behaviour Profiling System for Botnet Detection","year":2017,"lang":"en","type":"book-chapter","venue":"Author eBooks","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Dalhousie University","funders":"","keywords":"Botnet; Profiling (computer programming); Anomaly detection; Computer science; Deep packet inspection; Payload (computing); Constant false alarm rate; Data mining; Outlier; Encryption; Network packet; Intrusion detection system; False alarm; Computer security; Artificial intelligence; The Internet; Operating system","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0007716269,0.0005904166,0.0005134431,0.001289426,0.0002973764,0.001133133,0.0009021419,0.0005703048,0.001636939],"category_scores_gemma":[0.001656372,0.0002818986,0.0003290583,0.001398848,0.0004394299,0.001864369,0.0008185601,0.000958695,0.001864671],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006470004,"about_ca_system_score_gemma":0.0005368436,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001910529,"about_ca_topic_score_gemma":0.002046183,"domain_scores_codex":[0.9995159,0.00006460046,0.00002542738,0.0001243269,0.0002342684,0.00003558428],"domain_scores_gemma":[0.9991525,0.0002520656,0.00005668846,0.0001239233,0.0003642624,0.00005048241],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0001748685,0.0001487296,0.009982733,0.0001695092,0.00004703493,0.0001914969,0.0004096941,0.02268422,0.04702354,0.01321518,0.01377572,0.8921773],"study_design_scores_gemma":[0.00000856119,0.0001331361,0.005210104,0.00004708412,0.00003070406,0.0005599306,0.0001005565,0.9106377,0.03945228,0.0149701,0.02878686,0.00006303941],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.03905033,0.0008881788,0.9388137,0.0003480884,0.0001204785,0.00008980341,0.0002900438,0.01404369,0.006355639],"genre_scores_gemma":[0.3587593,0.001475824,0.6192784,0.0003341777,0.0001634083,0.0001119622,0.001518155,0.0008006108,0.01755813],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.001910529,"threshold_uncertainty_score":0.005476177,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.1104901281275905,"score_gpt":0.2614465003788951,"score_spread":0.1509563722513046,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}