{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T18:01:41Z","timestamp":1725559301750},"publisher-location":"Berlin, Heidelberg","reference-count":15,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540266136"},{"type":"electronic","value":"9783540316459"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2005]]},"DOI":"10.1007\/11506881_6","type":"book-chapter","created":{"date-parts":[[2010,7,14]],"date-time":"2010-07-14T20:30:33Z","timestamp":1279139433000},"page":"85-102","source":"Crossref","is-referenced-by-count":6,"title":["METAL \u2013 A Tool for Extracting Attack Manifestations"],"prefix":"10.1007","author":[{"given":"Ulf","family":"Larson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emilie","family":"Lundin-Barse","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erland","family":"Jonsson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","unstructured":"Paxon, V.: Bro: A system for detecting network intruders in real-time. In: Proceedings of the Seventh USENIX Security Symposium, San Antonio, Texas, USA, pp. 31\u201351. USENIX (1998)"},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"Lindqvist, U., Porras, P.A.: eXpert-BSM: A host-based intrusion detection solution for Sun Solaris. In: Proceedings of the 17th Annual Computer Security Applications Conference, New Orleans, Louisiana, USA (2001)","DOI":"10.1109\/ACSAC.2001.991540"},{"key":"6_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1007\/3-540-45474-8_2","volume-title":"Recent Advances in Intrusion Detection","author":"M. Almgren","year":"2001","unstructured":"Almgren, M., Lindqvist, U.: Application-integrated data collection for security monitoring. In: Lee, W., M\u00e9, L., Wespi, A. (eds.) RAID 2001. LNCS, vol.\u00a02212, pp. 22\u201336. Springer, Heidelberg (2001)"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Ilgun, K., Kemmerer, R., Porras, P.: State transition analysis: A rule-based intrusion detection approach. IEEE Transaction on Software Engineering\u00a021 (1995)","DOI":"10.1109\/32.372146"},{"key":"6_CR5","volume-title":"Proceeding of the 1999 Symposium of Security and Privacy","author":"U. Lindqvist","year":"1999","unstructured":"Lindqvist, U., Porras, P.: Detecting computer and network misuse through the Production-Based Expert System Toolset (P-BEST). In: Proceeding of the 1999 Symposium of Security and Privacy, Oakland, CA, USA. IEEE Computer Society Press, Los Alamitos (1999)"},{"key":"6_CR6","doi-asserted-by":"crossref","unstructured":"Debar, H., Becker, M., Siboni, D.: A neural network component for an intrusion detection system. In: Proceedings of the IEEE Symposium on Research in Computer Security and Privacy, Oakland, CA, USA, pp. 240\u2013250 (1992)","DOI":"10.1109\/RISP.1992.213257"},{"key":"6_CR7","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1109\/SECPRI.1996.502675","volume-title":"Proceedings of the 1996 IEEE Symposium on Research in Security and Privacy","author":"S. Forrest","year":"1996","unstructured":"Forrest, S., Hofmeyr, S.A., Somayaji, A., Longstaff, T.A.: A sense of self for Unix processes. In: Proceedings of the 1996 IEEE Symposium on Research in Security and Privacy, pp. 120\u2013128. IEEE Computer Society Press, Los Alamitos (1996)"},{"key":"6_CR8","volume-title":"Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC 2004)","author":"E.L. Barse","year":"2004","unstructured":"Barse, E.L., Jonsson, E.: Extracting attack manifestations to determine log data requirements for intrusion detection. In: Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC 2004), Tucson, Arizona, USA. IEEE Computer Society, Los Alamitos (2004)"},{"issue":"1","key":"6_CR9","doi-asserted-by":"crossref","first-page":"3","DOI":"10.3233\/JCS-1999-7102","volume":"7","author":"T. Daniels","year":"1999","unstructured":"Daniels, T., Spafford, E.: Identification of host audit data to detect attacks on low-level IP vulnerabilities. Journal of Computer Security\u00a07, 3\u201335 (1999)","journal-title":"Journal of Computer Security"},{"key":"6_CR10","unstructured":"Zamboni, D.: Using Internal Sensors for Computer Intrusion Detection. PhD thesis, Purdue University, West Lafayette, IN, USA (2001) CERIAS TR 2001-42"},{"key":"6_CR11","doi-asserted-by":"crossref","unstructured":"Killourhy, K.S., Maxion, R.A., Tan, K.M.C.: A defence-centric taxonomy based on attack manifestations. In: Proceedings of the International Conference on Dependable Systems and Networks (DSN 2004), Florence, Italy (2004)","DOI":"10.1109\/DSN.2004.1311881"},{"key":"6_CR12","unstructured":"Axelsson, S., Lindqvist, U., Gustafson, U., Jonsson, E.: An approach to UNIX security logging. In: Proceedings of the 21st National Information Systems Security Conference, Arlington, Virginia, USA, National Institute of Standards and Technology\/National Computer Security Center, pp. 62\u201375 (1998)"},{"key":"6_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1007\/978-3-540-39650-5_19","volume-title":"Computer Security \u2013 ESORICS 2003","author":"C. Kruegel","year":"2003","unstructured":"Kruegel, C., Mutz, D., Valeur, F., Vigna, G.: On the Detection of Anomalous System Call Arguments. In: Snekkenes, E., Gollmann, D. (eds.) ESORICS 2003. LNCS, vol.\u00a02808, pp. 326\u2013343. Springer, Heidelberg (2003)"},{"key":"6_CR14","unstructured":"Lee, W., Stolfo, S., Chan, P.: Learning patterns from Unix process execution traces for intrusion detection. In: AAAI Workshop: AI Approaches to Fraud Detection and Risk Management (1997)"},{"key":"6_CR15","doi-asserted-by":"crossref","unstructured":"Kreibich, C., Crowcroft, J.: Honeycomb - creating intrusion detection signatures using honeypots. In: 2nd Workshop on Hot Topics in Networks (HotNets-II), Boston, USA (2003)","DOI":"10.1145\/972374.972384"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11506881_6.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,17]],"date-time":"2020-11-17T20:03:37Z","timestamp":1605643417000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11506881_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005]]},"ISBN":["9783540266136","9783540316459"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/11506881_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2005]]}}}