{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T11:07:15Z","timestamp":1743073635377,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":15,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540309345"},{"type":"electronic","value":"9783540320999"}],"license":[{"start":{"date-parts":[[2005,1,1]],"date-time":"2005-01-01T00:00:00Z","timestamp":1104537600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2005]]},"DOI":"10.1007\/11602897_21","type":"book-chapter","created":{"date-parts":[[2005,11,17]],"date-time":"2005-11-17T10:31:17Z","timestamp":1132223477000},"page":"243-255","source":"Crossref","is-referenced-by-count":0,"title":["Port Scan Behavior Diagnosis by Clustering"],"prefix":"10.1007","author":[{"given":"Lanjia","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haixin","family":"Duan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xing","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"21_CR1","doi-asserted-by":"crossref","unstructured":"Berk, V.H., Gray, R.S., Bakos, G.: Using sensor networks and data fusion for early detection of active worms. In: Proceedings of the SPIE AeroSense (2003)","DOI":"10.1117\/12.500849"},{"key":"21_CR2","unstructured":"Brutlag, J.: Aberrant Behavior Detection in Timeseries for Network Monitoring. In: Proceedings of USENIX Fourteenth Systems Administration Conference (LISA), New Orleans, LA (December 2000)"},{"key":"21_CR3","unstructured":"Jung, J., Paxson, V., Berger, A.W., Balakrishnan, H.: Fast Portscan Detection Using Sequential Hypothesis Testing. In: Proceedings of 2004 IEEE Symposium on Security and Privacy, Berkeley, CA, USA, May 2004, pp. 211\u2013225 (2004)"},{"key":"21_CR4","doi-asserted-by":"crossref","unstructured":"Kompella, R.R., Singh, S., Varghese, G.: On Scalable Attack Detection in the Network. In: Proceedings of the 4th ACM SIGCOMM conference on Internet measurement, Taormina, Sicily, Italy, October 2004, pp. 187\u2013200 (2004)","DOI":"10.1145\/1028788.1028812"},{"key":"21_CR5","doi-asserted-by":"crossref","unstructured":"Krishnamurthy, B., Sen, S., Zhang, Y., Chen, Y.: Sketch-based Change Detection: Methods, Evaluation, and Applications. In: Proceedings of the 3rd ACM SIGCOMM conference on Internet measurement, Pages, Miami Beach, FL, USA, October 2003, pp. 234\u2013247 (2003)","DOI":"10.1145\/948205.948236"},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Leckie, C., Kotagiri, R.: A probabilistic approach to detecting network scans. In: Proceedings of the Eighth IEEE Network Operations and Management Symposium (NOMS 2002), Florence, Italy, April 2002, pp. 359\u2013372 (2002)","DOI":"10.1109\/NOMS.2002.1015594"},{"key":"21_CR7","unstructured":"Moore, D., Shannon, C., Voelker, G.M., Savage, S.: Internet Quarantine: Requirements for Containing Self-Propagating Code. In: Proceedings of IEEE INFOCOM (April 2003)"},{"key":"21_CR8","unstructured":"Paxson, V.: Bro: A System for Detecting Network Intruders in Real Time. In: Proceedings of the 7th USENIX Security Symposium (1998)"},{"key":"21_CR9","doi-asserted-by":"crossref","unstructured":"Robertson, S., Siegel, E.V., Miller, M., Stolfo, S.J.: Surveillance detection in high bandwidth environments. In: Proceedings of the 2003 DARPA DISCEX III Conference, Washington, DC, April 2003, pp. 130\u2013139 (2003)","DOI":"10.1109\/DISCEX.2003.1194879"},{"key":"21_CR10","unstructured":"Roesch, M.: Snort: Lightweight intrusion detection for networks. In: Proceedings of the 13th Conference on Systems Administration (LISA 1999), Berkeley, CA, November 1999, pp. 229\u2013238. USENIX Association (1999)"},{"key":"21_CR11","doi-asserted-by":"crossref","unstructured":"Schechter, S.E., Jung, J., Berger, A.W.: Fast Detection of Scan Worm Infections. In: Proceedings of the Seventh International Symposium on Recent Advances in Intrusion Detection, Sophia Antipolis, France (September 2004)","DOI":"10.1007\/978-3-540-30143-1_4"},{"key":"21_CR12","unstructured":"Staniford, S., Hoagland, J.A., McAlerney, J.M.: Practical automated detection of stealthy portscans. In: Proceedings of the 7th ACM Conference on Computer and Communications Security, Athens, Greece (2000)"},{"key":"21_CR13","first-page":"138","volume-title":"Proceedings of the 2003 ACM SIGMETRICS, volume 31, 1 of Performance Evaluation Review","author":"V. Yegneswaran","year":"2003","unstructured":"Yegneswaran, V., Barford, P., Ullrich, J.: Internet intrusions: global characteristics and prevalence. In: Proceedings of the 2003 ACM SIGMETRICS, volume 31, 1 of Performance Evaluation Review, June 2003, pp. 138\u2013147. ACM Press, New York (2003)"},{"issue":"2","key":"21_CR14","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1145\/505733.505737","volume":"29","author":"M. Vivo de","year":"1999","unstructured":"de Vivo, M., Carrasco, E., Isern, G., de Vivo, G.: A Review of Port Scan Techniques. Computer Communications Review\u00a029(2), 41\u201348 (1999)","journal-title":"Computer Communications Review"},{"key":"21_CR15","doi-asserted-by":"crossref","unstructured":"Zou, C.C., Gao, L., Gong, W., Towsley, D.: Monitoring and Early Warning for Internet Worms. In: Proceedings of the 10th ACM conference on Computer and communications security, Washington, DC, USA (October 2003)","DOI":"10.1145\/948134.948136"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11602897_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,5]],"date-time":"2025-01-05T18:03:31Z","timestamp":1736100211000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11602897_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005]]},"ISBN":["9783540309345","9783540320999"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/11602897_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2005]]}}}