scispace - formally typeset
N

Norbert Pohlmann

Publications -  67
Citations -  983

Norbert Pohlmann is an academic researcher. The author has contributed to research in topics: Malware & The Internet. The author has an hindex of 12, co-authored 59 publications receiving 787 citations.

Papers
More filters
Proceedings ArticleDOI

Prudent Practices for Designing Malware Experiments: Status Quo and Outlook

TL;DR: Study of methodological rigor and prudence in 36 academic publications from 2006-2011 that rely on malware execution finds frequent shortcomings, including problematic assumptions regarding the use of execution-driven datasets, absence of description of security precautions taken during experiments, and oftentimes insufficient description of the experimental setup.
Proceedings Article

On Botnets That Use DNS for Command and Control.

TL;DR: This work discovered and reverse engineered Feederbot, a botnet that uses DNS as carrier for its command and control and correctly detected DNS C&C in mixed office workstation network traffic.
Journal ArticleDOI

CoCoSpot: Clustering and recognizing botnet command and control channels using traffic analysis

TL;DR: It is shown that for more than 20 recent botnets and over 87,000 C&C flows, CoCoSpot can recognize more than 88% of the C &C flows at a false positive rate below 0.1%.
Proceedings ArticleDOI

Sandnet: network traffic analysis of malicious software

TL;DR: This work provides a comprehensive overview of typical malware network behavior by discussing the results that were obtained during the analysis of more than 100,000 malware samples and develops a new analysis environment called Sandnet that complements existing systems by focusing on network traffic analysis.
Proceedings ArticleDOI

Beyond the Front Page:Measuring Third Party Dynamics in the Field

TL;DR: A large-scale measurement study to analyze the magnitude of new challenges faced by service providers in the modern Web and reflects the connectedness of third parties in a model the authors call third party trees, which reflects an approximation of the loading dependencies of all third parties embedded into a given website.