{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T15:30:11Z","timestamp":1742916611433,"version":"3.40.3"},"publisher-location":"New York, NY","reference-count":15,"publisher":"Springer New York","isbn-type":[{"type":"print","value":"9781461475965"},{"type":"electronic","value":"9781461475972"}],"license":[{"start":{"date-parts":[[2013,6,15]],"date-time":"2013-06-15T00:00:00Z","timestamp":1371254400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2013,6,15]],"date-time":"2013-06-15T00:00:00Z","timestamp":1371254400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-1-4614-7597-2_3","type":"book-chapter","created":{"date-parts":[[2013,6,14]],"date-time":"2013-06-14T13:27:30Z","timestamp":1371216450000},"page":"39-62","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["Recognizing Unexplained Behavior in Network Traffic"],"prefix":"10.1007","author":[{"given":"Massimiliano","family":"Albanese","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert F.","family":"Erbacher","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sushil","family":"Jajodia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"C.","family":"Molinaro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio","family":"Persia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Antonio","family":"Picariello","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giancarlo","family":"Sperl\u00ec","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"V. S.","family":"Subrahmanian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2013,6,15]]},"reference":[{"issue":"1\u20132","key":"3_CR1","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P. Garc\u00eda-Teodoro","year":"2009","unstructured":"P. Garc\u00eda-Teodoro, J. D\u00edaz-Verdejo, G. Maci\u00e1-Fern\u00e1ndez, E. V\u00e1zquez, Anomaly-based network intrusion detection: techniques, systems and challenges. Comput. Secur. 28(1\u20132), 18\u201328 (2009)","journal-title":"Comput. Secur."},{"key":"3_CR2","unstructured":"A. Jones, S. Li, Temporal signatures for intrusion detection, in Proceedings of the 17th Annual Computer Security Applications Conference (ACSAC 2001) (IEEE Computer Society, 2001), New Orleans, pp. 252\u2013261"},{"issue":"3","key":"3_CR3","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/65.283931","volume":"8","author":"B. Mukherjee","year":"1994","unstructured":"B. Mukherjee, L.T. Heberlein, K.N. Levitt, Network intrusion detection. IEEE Netw.\n                8(3), 26\u201341 (1994)","journal-title":"IEEE Netw."},{"issue":"4","key":"3_CR4","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/s11416-008-0103-3","volume":"5","author":"SO Al-Mamory","year":"2009","unstructured":"S.O. Al-Mamory, H. Zhang, Ids alerts correlation using grammar-based approach. J. Comput. Virol. 5(4), 271\u2013282 (2009)","journal-title":"J. Comput. Virol."},{"key":"3_CR5","doi-asserted-by":"crossref","unstructured":"H. Debar, A. Wespi, Aggregation and correlation of intrusion-detection alerts, in Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID 2001), eds. W. Lee, L. M\u00e9, A. Wespi. Lecture Notes in Computer Science, vol. 2212 (Springer, 2001), Davis, pp. 85\u2013103","DOI":"10.1007\/3-540-45474-8_6"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"P. Ning, Y. Cui, D.S. Reeves, Constructing attack scenarios through correlation of in- trusion alerts, in Proceedings of the 9th ACM Conference on Computer and Communications Security(CCS 2002) (ACM, 2002), Washington, pp. 245\u2013254","DOI":"10.1145\/586110.586144"},{"key":"3_CR7","unstructured":"S. Noel, E. Robertson, S. Jajodia, Correlating intrusion events and building attack scenarios through attack graph distances, in Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC 2004) (2004), Tucson, pp. 350\u2013359"},{"issue":"15","key":"3_CR8","doi-asserted-by":"publisher","first-page":"2917","DOI":"10.1016\/j.comcom.2006.04.001","volume":"29","author":"L Wang","year":"2006","unstructured":"L. Wang, A. Liu, S. Jajodia, Using attack graphs for correlating, hypothesizing, and predicting intrusion alerts. Comput. Commun. 29(15), 2917\u20132933 (2006)","journal-title":"Comput. Commun."},{"key":"3_CR9","unstructured":"J.P. Anderson, Computer security threat monitoring and surveillance. Technical report, James Anderson Co., Fort Washington, Apr 1980"},{"key":"3_CR10","unstructured":"O. Sheyner, J. Haines, S. Jha, R. Lippmann, J.M. Wing, Automated generation and analysis of attack graphs, in Proceedings of the 2002 IEEE Symposium on Security and Privacy (S&P 2002), Berkeley, 2002, pp. 273\u2013284"},{"key":"3_CR11","unstructured":"X. Qin, A probabilistic-based framework for INFOSEC alert correlation. Ph.D. thesis, Georgia Institute of Technology, 2005"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"X. Qin, W. Lee, Statistical causality analysis of INFOSEC alert data, in Proceedings of the 6th International Symposium on Re- cent Advances in Intrusion Detection (RAID 2003), eds. G. Vigna, C. Kruegel, E. Jonsson. Lecture Notes in Computer Science, vol. 2820 (Springer, 2003), Pittsburgh pp. 73\u201393","DOI":"10.1007\/978-3-540-45248-5_5"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"A.J. Oliner, A.V. Kulkarni, A. Aiken, Community epidemic detection using time- correlated anomalies, in Proceedings of the 13th International Symposium on Recent Advances in Intrusion Detection (RAID 2010), eds. S. Jha, R. Sommer, C. Kreibich. Lecture Notes in Computer Science, vol. 6307 (Springer, 2010), Ottawa, pp. 360\u2013381","DOI":"10.1007\/978-3-642-15512-3_19"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"M. Albanese, C. Molinaro, F. Persia, A. Picariello, V.S. Subrahmanian, Finding \u201cun- explained\u201d activities in video, in Proceedings of the 22nd International Joint Conference on Artificial Intelligence (IJCAI 2011), Barcelona, 2011, pp. 1628\u20131634","DOI":"10.21236\/ADA587505"},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"M. Albanese, S. Jajodia, A. Pugliese, V.S. Subrahmanian, Scalable analysis of attack scenarios, in Proceedings of the 16th European Symposium on Research in Computer Security (ESORICS 2011) (Springer, 2011), Leuven, pp. 416\u2013433","DOI":"10.1007\/978-3-642-23822-2_23"}],"container-title":["Advances in Information Security","Network Science and Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-7597-2_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T03:49:58Z","timestamp":1675223398000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-1-4614-7597-2_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,6,15]]},"ISBN":["9781461475965","9781461475972"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-7597-2_3","relation":{},"ISSN":["1568-2633"],"issn-type":[{"type":"print","value":"1568-2633"}],"subject":[],"published":{"date-parts":[[2013,6,15]]},"assertion":[{"value":"15 June 2013","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}