{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T06:58:25Z","timestamp":1761807505156,"version":"3.40.3"},"publisher-location":"Boston, MA","reference-count":38,"publisher":"Springer US","isbn-type":[{"type":"print","value":"9781441901392"},{"type":"electronic","value":"9781441901408"}],"license":[{"start":{"date-parts":[[2009,9,30]],"date-time":"2009-09-30T00:00:00Z","timestamp":1254268800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2009,9,30]],"date-time":"2009-09-30T00:00:00Z","timestamp":1254268800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-1-4419-0140-8_5","type":"book-chapter","created":{"date-parts":[[2009,10,3]],"date-time":"2009-10-03T11:41:32Z","timestamp":1254570092000},"page":"71-102","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["Employing Honeynets For Network Situational Awareness"],"prefix":"10.1007","author":[{"given":"Paul","family":"Barford","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anup","family":"Goyal","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhichun","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vern","family":"Paxson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,9,30]]},"reference":[{"key":"5_CR1","unstructured":"HoneyBow Sensor. http:\/\/honeybow.mwcollect.org."},{"key":"5_CR2","unstructured":"Honeysnap. http:\/\/www.honeynet.org\/tools\/honeysnap\/index.html."},{"key":"5_CR3","unstructured":"Net-Worm.Win32.Allaple.a. http:\/\/www.viruslist.com\/en\/viruses\/encyclopedia?virusid=145521."},{"key":"5_CR4","unstructured":"OS Platform Statistics by W3school. http:\/\/www.w3schools.com\/browsers\/browsers_stats.asp."},{"key":"5_CR5","unstructured":"M. Bailey, E. Cooke, F. Jahanian, J. Nazario, and D. Watson. The Internet Motion Sensor: A Distributed Blackhole Monitoring System. In Network and Distributed Security Symposium, San Diego, CA, January 2005."},{"key":"5_CR6","unstructured":"J. Bethencourt et al. Mapping internet sensors with probe response attacks. In Proc. of the USENIX Security, 2005."},{"key":"5_CR7","unstructured":"J. Cai et al. Honeynets and honeygames: A game theoretic approach to defending network monitors. Technical Report TR1577, University of Wiscconsin, 2006."},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"E. Cooke, M. Bailey, M. Mao, D. Watson, F. Jahanian, and D. McPherson. Toward understanding distributed blackhole placement. In Proceedings of CCS Workshop on Rapid Malcode (WORM \u201904), October 2004.","DOI":"10.1145\/1029618.1029627"},{"key":"5_CR9","doi-asserted-by":"crossref","unstructured":"J. R. Crandall, Z. Su, and S. F. Wu. On deriving unknown vulnerabilities from zeroday polymorphic and metamorphic worm exploits. In Proc. of ACM CCS, 2005.","DOI":"10.1145\/1102120.1102152"},{"key":"5_CR10","unstructured":"Dshield. http:\/\/www.dshield.org."},{"key":"5_CR11","unstructured":"German Honeynet Project. Tracking Botnets. http:\/\/www.honeynet.org\/papers\/bots, 2005."},{"key":"5_CR12","unstructured":"G. Gu et al. Bothunter: Detecting malware infection through ids-driven dialog correlation. In Proc. of USENIX Security, 2007."},{"key":"5_CR13","unstructured":"G. Gu et al. Botsniffer: Detecting botnet command and control channels in network traffic. In Proc. of NDSS, 2008."},{"key":"5_CR14","unstructured":"The Honeynet Project. http:\/\/project.honeynet.org, 2003."},{"key":"5_CR15","unstructured":"M. G. Kendall. Rank Correlation Methods. Griffin., 1976."},{"key":"5_CR16","unstructured":"H. Kim and B. Karp. Autograph: Toward automated, distributed worm signature detection. In 13\n                                    \n                    th\n                   USENIX Security Symposium, San Diego, California, August 2004."},{"key":"5_CR17","unstructured":"C. Kreibich and J. Crowcroft. Honeycomb\u2013creating intrusion detection signatures using honeypots. In 2\n                                    \n                    nd\n                   Workshop on Hot Topics in Networks (Hotnets-II), Cambridge, Massachusetts, November 2003."},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"A. Kumar et al. Exploiting underlying structure for detailed reconstruction of an internet scale event. In Proc. of ACM IMC, 2005.","DOI":"10.1145\/1330107.1330150"},{"key":"5_CR19","unstructured":"Z. Li, A. Goyal, Y. Chen, and V. Paxson. Towards situational awareness of large-scale botnet events using honeynets. Technical Report NWU-EECS-08-08, Northwestern University, 2008."},{"key":"5_CR20","unstructured":"D. Moore. Network telescopes: Observing small or distant security events. Invited Presentation at the 11th USENIX Security Symposium, 2002."},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"D. Moore et al. Inside the slammer worm. IEEE Security and Privacy, 2003.","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"D. Moore, C. Shannon, and J. Brown. Code red: A case study on the spread and victims of an internet worm. In Proceedings of ACM SIGCOMM Internet Measurement Workshop, November 2002.","DOI":"10.1145\/637241.637244"},{"key":"5_CR23","doi-asserted-by":"crossref","unstructured":"D. Moore, G. Voelker, and S. Savage. Inferring internet denial of service activity. In Proceedings of the 2001 USENIX Security Symposium, Washington D.C., August 2001.","DOI":"10.21236\/ADA400003"},{"key":"5_CR24","unstructured":"Navy Aviation Schools Command. Situational Awareness. https:\/\/www.cnet.navy.mil.crm\/crm\/stand_mat\/seven_skills\/SA.asp, 2005."},{"key":"5_CR25","unstructured":"Network Centric Operations Industry Consortium. Situational Awareness. http:\/\/www.ncoic.org\/download\/NCOIC_Lexicon_v8.pdf, 2005."},{"key":"5_CR26","doi-asserted-by":"crossref","unstructured":"R. Pang et al. Characteristics of Internet background radiation. In Proc. of ACM IMC, 2004.","DOI":"10.1145\/1028788.1028794"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"R. Pang, V. Yegneswaran, P. Barford, V. Paxson, and L. Peterson. Characteristics of Internet Background Radiation. In Proceedings of the ACM SIGCOMM Internet Measurement Conference, 2004.","DOI":"10.1145\/1028788.1028794"},{"key":"5_CR28","unstructured":"V. Paxson. BRO: A system for detecting network intruders in real time. In 7\n                                    \n                    th\n                   USENIX Security Symposium, San Antonio, Texas, January 1998."},{"key":"5_CR29","unstructured":"N. Provos. A virtual honeypot framework. In Proceedings of USENIX Security Symposium, San Diego, CA, August 2004."},{"key":"5_CR30","unstructured":"N. Provos. A virtual honeypot framework. In Proc. of USENIX Security, 2004."},{"key":"5_CR31","unstructured":"M. Rajab, J. Zarfoss, F. Monrose, and A. Terzis. A multifaceted approach to understanding the botnet phenomenon. In Proc. of ACM IMC, 2006."},{"key":"5_CR32","unstructured":"J. A. Rice. Mathematical Statistics and Data Analysis. Duxbury Press, 1994."},{"key":"5_CR33","unstructured":"S. Singh, C. Estan, G. Varghese, and S. Savage. The Earlybird system for real-time detection of unknown worms. In Operating System Design and Implementation, 2004."},{"key":"5_CR34","unstructured":"S. Staniford et al. How to 0wn the Internet in your spare time. In Proc. of USENIX Security, 2002."},{"key":"5_CR35","unstructured":"W. E. Weisstein. Stirling Number of the Second Kind. http:\/\/mathworld.wolfram.com\/StirlingNumberoftheSecondKind.html."},{"key":"5_CR36","doi-asserted-by":"crossref","unstructured":"V. Yegneswaran, P. Barford, and D. Plonka. On the design and use of internet sinks for network abuse monitoring. In Proceedings of Recent Advances in Intrusion Detection, 2004.","DOI":"10.1007\/978-3-540-30143-1_8"},{"key":"5_CR37","doi-asserted-by":"crossref","unstructured":"V. Yegneswaran, P. Barford, and J. Ullrich. Internet intrusions: Global characteristics and prevalence. In Proceedings of ACM SIGMETRICS, June 2003.","DOI":"10.1145\/781027.781045"},{"key":"5_CR38","doi-asserted-by":"crossref","unstructured":"V. Yegneswaran, J. T. Giffin, P. Barford, and S. Jha. An Architecture for Semantic-Aware Signature Generation. In Proceedings of USENIX Security Symposium, 2005.","DOI":"10.21236\/ADA449063"}],"container-title":["Advances in Information Security","Cyber Situational Awareness"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4419-0140-8_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,20]],"date-time":"2024-03-20T09:38:28Z","timestamp":1710927508000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-1-4419-0140-8_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,9,30]]},"ISBN":["9781441901392","9781441901408"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-1-4419-0140-8_5","relation":{},"ISSN":["1568-2633"],"issn-type":[{"type":"print","value":"1568-2633"}],"subject":[],"published":{"date-parts":[[2009,9,30]]},"assertion":[{"value":"30 September 2009","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}