{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,24]],"date-time":"2025-02-24T05:19:14Z","timestamp":1740374354311,"version":"3.37.3"},"publisher-location":"Berlin, Heidelberg","reference-count":38,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540281382"},{"type":"electronic","value":"9783540319375"}],"license":[{"start":{"date-parts":[[2005,1,1]],"date-time":"2005-01-01T00:00:00Z","timestamp":1104537600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2005]]},"DOI":"10.1007\/11535706_1","type":"book-chapter","created":{"date-parts":[[2010,7,25]],"date-time":"2010-07-25T18:03:17Z","timestamp":1280080997000},"page":"1-15","source":"Crossref","is-referenced-by-count":4,"title":["Streams, Security and Scalability"],"prefix":"10.1007","author":[{"given":"Theodore","family":"Johnson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S.","family":"Muthukrishnan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Oliver","family":"Spatscheck","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Divesh","family":"Srivastava","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"1_CR1","unstructured":"Abadi, D.J., Ahmad, Y., Balazinska, M., \u00c7etintemel, U., Cherniack, M., Hwang, J.-H., Lindner, W., Maskey, A., Rasin, A., Ryvkina, E., Tatbul, N., Xing, Y., Zdonik, S.B.: The design of the Borealis stream processing engine. In: CIDR, pp. 277\u2013289 (2005), http:\/\/www-db.cs.wisc.edu\/cidr\/papers\/P23.pdf"},{"issue":"2","key":"1_CR2","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/s00778-003-0095-z","volume":"12","author":"D.J. Abadi","year":"2003","unstructured":"Abadi, D.J., Carney, D., \u00c7etintemel, U., Cherniack, M., Convey, C., Lee, S., Stonebraker, M., Tatbul, N., Zdonik, S.B.: Aurora: A new model and architecture for data stream management. VLDB J.\u00a012(2), 120\u2013139 (2003), http:\/\/dx.doi.org\/10.1007\/s00778-003-0095-z","journal-title":"VLDB J."},{"key":"1_CR3","doi-asserted-by":"crossref","unstructured":"Alon, N., Duffield, N.G., Lund, C., Thorup, M.: Estimating arbitrary subset sums with few probes. In: PODS 2005 (2005)","DOI":"10.1145\/1065167.1065209"},{"issue":"1","key":"1_CR4","first-page":"19","volume":"26","author":"A. Arasu","year":"2003","unstructured":"Arasu, A., Babcock, B., Babu, S., Datar, M., Ito, K., Motwani, R., Nishizawa, I., Srivastava, U., Thomas, D., Varma, R., Widom, J.: Stream: The Stanford stream data manager. IEEE Data Eng. Bull.\u00a026(1), 19\u201326 (2003)","journal-title":"IEEE Data Eng. Bull."},{"volume-title":"Proceedings of the 11th ACM Conference on Computer and Communications Security, CCS 2004","year":"2004","key":"1_CR5","unstructured":"Atluri, V., Pfitzmann, B., McDaniel, P. (eds.): Proceedings of the 11th ACM Conference on Computer and Communications Security, CCS 2004, Washington, DC, USA, 2004, October 25-29, 2004. ACM, New York (2004)"},{"key":"1_CR6","doi-asserted-by":"crossref","unstructured":"CERT. Cert advisory ca-1996-21 TCP SYN flooding and IP spoofing attacks (2000), http:\/\/www.cert.org\/advisories\/CA-1996-21.html","DOI":"10.1016\/S1353-4858(96)90059-8"},{"key":"1_CR7","unstructured":"CERT. Cert coordination center: Denial of service attacks (2001), http:\/\/www.cert.org\/tech_tips\/denial_of_service.html"},{"key":"1_CR8","unstructured":"CERT. Cert coordination center: Email bombing and spamming (2002), http:\/\/www.cert.org\/tech_tips\/email_bombing_spamming.html"},{"key":"1_CR9","unstructured":"CERT. Overview of attack trends (2002), http:\/\/www.cert.org\/archive\/pdf\/attack_trends.pdf"},{"key":"1_CR10","unstructured":"CERT. Cert\/cc advisories (2004), http:\/\/www.cert.org\/advisories\/"},{"key":"1_CR11","doi-asserted-by":"crossref","unstructured":"Chandrasekaran, S., Cooper, O., Deshpande, A., Franklin, M.J., Hellerstein, J.M., Hong, W., Krishnamurthy, S., Madden, S., Raman, V., Reiss, F., Shah, M.A.: TelegraphCQ: Continuous dataflow processing for an uncertain world. In: CIDR 2003 (2003), http:\/\/www-db.cs.wisc.edu\/cidr2003\/program\/p24.pdf","DOI":"10.1145\/872853.872857"},{"key":"1_CR12","first-page":"35","volume-title":"SIGMOD Conference","author":"G. Cormode","year":"2004","unstructured":"Cormode, G., Johnson, T., Korn, F., Muthukrishnan, S., Spatscheck, O., Srivastava, D.: Holistic UDAFs at streaming speeds. In: Weikum, G., K\u00f6nig, A.C., De\u00dfloch, S. (eds.) SIGMOD Conference, pp. 35\u201346. ACM, New York (2004), http:\/\/doi.acm.org\/10.1145\/1007568"},{"key":"1_CR13","first-page":"623","volume-title":"SIGMOD Conference","author":"C.D. Cranor","year":"2002","unstructured":"Cranor, C.D., Gao, Y., Johnson, T., Shkapenyuk, V., Spatscheck, O.: Gigascope: High performance network monitoring with an SQL interface. In: Franklin, M.J., Moon, B., Ailamaki, A. (eds.) SIGMOD Conference, p. 623. ACM, New York (2002), http:\/\/doi.acm.org\/10.1145\/564691.564777"},{"key":"1_CR14","first-page":"647","volume-title":"SIGMOD Conference","author":"C.D. Cranor","year":"2003","unstructured":"Cranor, C.D., Johnson, T., Spatscheck, O., Shkapenyuk, V.: Gigascope: A stream database for network applications. In: Halevy, A.Y., Ives, Z.G., Doan, A. (eds.) SIGMOD Conference, pp. 647\u2013651. ACM, New York (2003), http:\/\/www.acm.org\/sigmod\/sigmod03\/eproceedings\/papers\/ind03.pdf"},{"issue":"1","key":"1_CR15","first-page":"27","volume":"26","author":"C.D. Cranor","year":"2003","unstructured":"Cranor, C.D., Johnson, T., Spatscheck, O., Shkapenyuk, V.: The Gigascope stream database. IEEE Data Eng. Bull.\u00a026(1), 27\u201332 (2003)","journal-title":"IEEE Data Eng. Bull."},{"key":"1_CR16","doi-asserted-by":"crossref","unstructured":"Dreger, H., Feldmann, A., Paxson, V., Sommer, R.: Operational experiences with high-volume network intrusion detection. In: et. al, A. (ed.) [5], pp. 2\u201311, http:\/\/doi.acm.org\/10.1145\/1030086","DOI":"10.1145\/1030083.1030086"},{"issue":"3","key":"1_CR17","doi-asserted-by":"publisher","first-page":"270","DOI":"10.1145\/859716.859719","volume":"21","author":"C. Estan","year":"2003","unstructured":"Estan, C., Varghese, G.: New directions in traffic measurement and accounting: Focusing on the elephants, ignoring the mice. ACM Trans. Comput. Syst.\u00a021(3), 270\u2013313 (2003), http:\/\/doi.acm.org\/10.1145\/859716.859719","journal-title":"ACM Trans. Comput. Syst."},{"key":"1_CR18","first-page":"541","volume-title":"VLDB","author":"P.B. Gibbons","year":"2001","unstructured":"Gibbons, P.B.: Distinct sampling for highly-accurate answers to distinct values queries and event reports. In: Apers, P.M.G., Atzeni, P., Ceri, S., Paraboschi, S., Ramamohanarao, K., Snodgrass, R.T. (eds.) VLDB, pp. 541\u2013550. Morgan Kaufmann, San Francisco (2001), http:\/\/www.vldb.org\/conf\/2001\/P541.pdf"},{"key":"1_CR19","doi-asserted-by":"crossref","unstructured":"Greenwald, M., Khanna, S.: Space-efficient online computation of quantile summaries. In: SIGMOD Conference (2001), http:\/\/www.acm.org\/sigs\/sigmod\/sigmod01\/eproceedings\/papers\/Research-Greenwald-Khanna.pdf","DOI":"10.1145\/375663.375670"},{"key":"1_CR20","unstructured":"Johnson, T.: GSQL users manual (2005),Accessible from, http:\/\/www.research.att.com\/~johnsont"},{"key":"1_CR21","doi-asserted-by":"crossref","unstructured":"Johnson, T., Muthukrishnan, S., Rozenbaum, I.: Sampling algorithms in a stream operator. In: SIGMOD Conference (2005)","DOI":"10.1145\/1066157.1066159"},{"key":"1_CR22","unstructured":"Johnson, T., Muthukrishnan, S., Shkapenyuk, V., Spatscheck, O.: A heartbeat mechanism and its application in Gigascope. In: VLDB Conference (2005)"},{"key":"1_CR23","first-page":"211","volume-title":"IEEE Symposium on Security and Privacy","author":"J. Jung","year":"2004","unstructured":"Jung, J., Paxson, V., Berger, A.W., Balakrishnan, H.: Fast portscan detection using sequential hypothesis testing. In: IEEE Symposium on Security and Privacy, pp. 211\u2013225. IEEE Computer Society, Los Alamitos (2004), http:\/\/csdl.computer.org\/comp\/proceedings\/sp\/2004\/2136\/00\/21360211abs.htm"},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Karamcheti, V., Geiger, D., Kedem, Z., Muthukrishnan, S.: Detecting malicious network traffic using inverse distributions of packet contents. In: MineNet (2005)","DOI":"10.1145\/1080173.1080176"},{"key":"1_CR25","unstructured":"Kim, H.-A., Karp, B.: Autograph: Toward automated, distributed worm signature detection. In: USENIX Security Symposium, USENIX, 2004, pp. 271\u2013286 (2004), http:\/\/www.usenix.org\/publications\/library\/proceedings\/sec04\/tech\/kim.html"},{"key":"1_CR26","first-page":"187","volume-title":"Internet Measurement Conference","author":"R.R. Kompella","year":"2004","unstructured":"Kompella, R.R., Singh, S., Varghese, G.: On scalable attack detection in the network. In: Lombardo, A., Kurose, J.F. (eds.) Internet Measurement Conference, pp. 187\u2013200. ACM, New York (2004), http:\/\/doi.acm.org\/10.1145\/1028812"},{"key":"1_CR27","first-page":"1145","volume-title":"ICDE","author":"N. Koudas","year":"2005","unstructured":"Koudas, N., Srivastava, D.: Data stream query processing. In: ICDE, p. 1145. IEEE Computer Society, Los Alamitos (2005), http:\/\/csdl.computer.org\/comp\/proceedings\/icde\/2005\/2285\/00\/22851145abs.htm"},{"key":"1_CR28","doi-asserted-by":"crossref","unstructured":"Lakhina, A., Crovella, M., Diot, C.: Mining anomalies using traffic feature distributions. In: SIGCOMM 2005 (2005)","DOI":"10.1145\/1080091.1080118"},{"key":"1_CR29","doi-asserted-by":"crossref","unstructured":"Levchenko, K., Paturi, R., Varghese, G.: On the difficulty of scalably detecting network attacks. In: Atluri, et al. (eds.) [5], pp. 12\u201320, http:\/\/doi.acm.org\/10.1145\/1030087","DOI":"10.1145\/1030083.1030087"},{"key":"1_CR30","doi-asserted-by":"crossref","unstructured":"Manku, G.S., Motwani, R.: Approximate frequency counts over data streams. In: VLDB, pp. 346\u2013357 (2002), http:\/\/www.vldb.org\/conf\/2002\/S10P03.pdf","DOI":"10.1016\/B978-155860869-6\/50038-X"},{"key":"1_CR31","unstructured":"Muthukrishnan, S.: Data stream algorithms and applications (2005), http:\/\/www.cs.rutgers.edu\/~muthu\/stream-1-1.ps"},{"issue":"23-24","key":"1_CR32","doi-asserted-by":"publisher","first-page":"2435","DOI":"10.1016\/S1389-1286(99)00112-7","volume":"31","author":"V. Paxson","year":"1999","unstructured":"Paxson, V.: Bro: A system for detecting network intruders in real-time. Computer Networks\u00a031(23-24), 2435\u20132463 (1999), http:\/\/dx.doi.org\/10.1016\/S1389-12869900112-7","journal-title":"Computer Networks"},{"key":"1_CR33","unstructured":"Singh, S., Estan, C., Varghese, G., Savage, S.: Automated worm fingerprinting. In: OSDI, pp. 45\u201360 (2004), http:\/\/www.usenix.org\/events\/osdi04\/tech\/singh.html"},{"key":"1_CR34","unstructured":"Snort. The de facto standard for intrusion detection, http:\/\/www.snort.org"},{"issue":"3","key":"1_CR35","doi-asserted-by":"publisher","first-page":"555","DOI":"10.1109\/TKDE.2003.1198390","volume":"15","author":"P.A. Tucker","year":"2003","unstructured":"Tucker, P.A., Maier, D., Sheard, T., Fegaras, L.: Exploiting punctuation semantics in continuous data streams. IEEE Trans. Knowl. Data Eng.\u00a015(3), 555\u2013568 (2003), http:\/\/www.computer.org\/tkde\/tk2003\/k0555abs.htm","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"1_CR36","unstructured":"US-CERT. Technical cyber security alerts (2005), http:\/\/www.us-cert.gov\/cas\/techalerts\/index.html"},{"issue":"1","key":"1_CR37","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1145\/3147.3165","volume":"11","author":"J.S. Vitter","year":"1985","unstructured":"Vitter, J.S.: Random sampling with a reservoir. ACM Trans. Math. Softw.\u00a011(1), 37\u201357 (1985)","journal-title":"ACM Trans. Math. Softw."},{"key":"1_CR38","unstructured":"Wang, H., Zhang, D., Shin, K.G.: Detecting SYN flooding attacks. In: INFOCOM (2002), http:\/\/www.ieee-infocom.org\/2002\/papers\/800.pdf"}],"container-title":["Lecture Notes in Computer Science","Data and Applications Security XIX"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11535706_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,23]],"date-time":"2025-02-23T10:11:59Z","timestamp":1740305519000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11535706_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005]]},"ISBN":["9783540281382","9783540319375"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/11535706_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2005]]}}}