{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,6]],"date-time":"2025-07-06T23:10:08Z","timestamp":1751843408283,"version":"3.41.0"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030004699"},{"type":"electronic","value":"9783030004705"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-00470-5_27","type":"book-chapter","created":{"date-parts":[[2018,9,6]],"date-time":"2018-09-06T10:43:19Z","timestamp":1536230599000},"page":"577-599","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Statistical Similarity of Critical Infrastructure Network Traffic Based on Nearest Neighbor Distances"],"prefix":"10.1007","author":[{"given":"Jeong-Han","family":"Yun","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yoonho","family":"Hwang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Woomyo","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hee-Kap","family":"Ahn","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sin-Kyu","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,9,7]]},"reference":[{"key":"27_CR1","unstructured":"Shodan search engine for internet-connected devices. http:\/\/www.shodan.io"},{"key":"27_CR2","doi-asserted-by":"crossref","unstructured":"Barbosa, R.R.R., Sadre, R., Pras, A.: A first look into SCADA network traffic. In: Network Operations and Management Symposium (NOMS), pp. 518\u2013521. IEEE (2012)","DOI":"10.1109\/NOMS.2012.6211945"},{"key":"27_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"126","DOI":"10.1007\/978-3-642-28537-0_13","volume-title":"Passive and Active Measurement","author":"RRR Barbosa","year":"2012","unstructured":"Barbosa, R.R.R., Sadre, R., Pras, A.: Difficulties in modeling SCADA traffic: a comparative analysis. In: Taft, N., Ricciato, F. (eds.) PAM 2012. LNCS, vol. 7192, pp. 126\u2013135. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-28537-0_13"},{"key":"27_CR4","doi-asserted-by":"crossref","unstructured":"Berthier, R., et al.: On the practicality of detecting anomalies with encrypted traffic in AMI. In: International Conference on Smart Grid Communications (SmartGridComm), pp. 890\u2013895. IEEE (2014)","DOI":"10.1109\/SmartGridComm.2014.7007761"},{"key":"27_CR5","first-page":"1","volume":"128","author":"CM Bishop","year":"2006","unstructured":"Bishop, C.M.: Pattern recognition. Mach. Learn. 128, 1\u201358 (2006)","journal-title":"Mach. Learn."},{"issue":"3","key":"27_CR6","doi-asserted-by":"publisher","first-page":"637","DOI":"10.1086\/260062","volume":"81","author":"F Black","year":"1973","unstructured":"Black, F., Scholes, M.: The pricing of options and corporate liabilities. J. Polit. Econ. 81(3), 637\u2013654 (1973)","journal-title":"J. Polit. Econ."},{"key":"27_CR7","doi-asserted-by":"crossref","unstructured":"Caselli, M., Zambon, E., Kargl, F.: Sequence-aware intrusion detection in industrial control systems. In: Proceedings of the 1st Workshop on Cyber-Physical System Security, pp. 13\u201324. ACM (2015)","DOI":"10.1145\/2732198.2732200"},{"issue":"7","key":"27_CR8","doi-asserted-by":"publisher","first-page":"790","DOI":"10.1016\/j.comcom.2004.11.001","volume":"28","author":"AB Downey","year":"2005","unstructured":"Downey, A.B.: Lognormal and Pareto distributions in the Internet. Comput. Commun. 28(7), 790\u2013801 (2005)","journal-title":"Comput. Commun."},{"key":"27_CR9","doi-asserted-by":"crossref","unstructured":"Feng, X., Li, Q., Wang, H., Sun, L.: Characterizing industrial control system devices on the internet. In: 24th International Conference on Network Protocols (ICNP), pp. 1\u201310. IEEE (2016)","DOI":"10.1109\/ICNP.2016.7784467"},{"key":"27_CR10","doi-asserted-by":"crossref","unstructured":"Formby, D., Srinivasan, P., Leonard, A., Rogers, J., Beyah, R.: Who\u2019s in control of your control system? Device fingerprinting for cyber-physical systems. In: Network and Distributed System Security Symposium (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23142"},{"key":"27_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1007\/978-3-319-71368-7_8","volume-title":"Critical Information Infrastructures Security","author":"J Goh","year":"2017","unstructured":"Goh, J., Adepu, S., Junejo, K.N., Mathur, A.: A dataset to support research in the design of secure water treatment systems. In: Havarneanu, G., Setola, R., Nassopoulos, H., Wolthusen, S. (eds.) CRITIS 2016. LNCS, vol. 10242, pp. 88\u201399. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-71368-7_8"},{"issue":"3","key":"27_CR12","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1016\/j.comnet.2004.11.026","volume":"48","author":"WB Gong","year":"2005","unstructured":"Gong, W.B., Liu, Y., Misra, V., Towsley, D.: Self-similarity and long range dependence on the internet: a second look at the evidence, origins and implications. Comput. Netw. 48(3), 377\u2013399 (2005)","journal-title":"Comput. Netw."},{"key":"27_CR13","doi-asserted-by":"crossref","unstructured":"Krotofil, M., Larsen, J., Gollmann, D.: The process matters: ensuring data veracity in cyber-physical systems. In: Proceedings of the 10th Symposium on Information, Computer and Communications Security, pp. 133\u2013144. ACM (2015)","DOI":"10.1145\/2714576.2714599"},{"key":"27_CR14","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1007\/978-3-642-20042-7_36","volume-title":"Intelligent Information and Database Systems","author":"H Kwon","year":"2011","unstructured":"Kwon, H., Kim, T., Yu, S.J., Kim, H.K.: Self-similarity based lightweight intrusion detection method for cloud computing. In: Nguyen, N.T., Kim, C.-G., Janiak, A. (eds.) ACIIDS 2011. LNCS (LNAI), vol. 6592, pp. 353\u2013362. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-20042-7_36"},{"issue":"1","key":"27_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/90.282603","volume":"2","author":"WE Leland","year":"1994","unstructured":"Leland, W.E., Taqqu, M.S., Willinger, W., Wilson, D.V.: On the self-similar nature of ethernet traffic (extended version). IEEE\/ACM Trans. Netw. 2(1), 1\u201315 (1994)","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"27_CR16","unstructured":"Lemay, A., Fernandez, J.M.: Providing SCADA network data sets for intrusion detection research. In: Workshop on Cyber Security Experimentation and Test (CSET). USENIX Association (2016)"},{"key":"27_CR17","doi-asserted-by":"crossref","unstructured":"Lin, C.Y., Nadjm-Tehrani, S., Asplund, M.: Timing-based anomaly detection in SCADA networks. In: International Conference on Critical Infrastructures Security (CRITIS) (2017)","DOI":"10.1007\/978-3-319-99843-5_5"},{"key":"27_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1007\/978-3-540-30561-3_24","volume-title":"Intelligent Information Technology","author":"S Rawat","year":"2004","unstructured":"Rawat, S., Sastry, C.S.: Network intrusion detection using wavelet analysis. In: Das, G., Gulati, V.P. (eds.) CIT 2004. LNCS, vol. 3356, pp. 224\u2013232. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30561-3_24"},{"key":"27_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1007\/978-3-319-59870-3_30","volume-title":"Information Security and Privacy","author":"NR Rodofile","year":"2017","unstructured":"Rodofile, N.R., Schmidt, T., Sherry, S.T., Djamaludin, C., Radke, K., Foo, E.: Process control cyber-attacks and labelled datasets on S7Comm critical infrastructure. In: Pieprzyk, J., Suriadi, S. (eds.) ACISP 2017. LNCS, vol. 10343, pp. 452\u2013459. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-59870-3_30"},{"key":"27_CR20","doi-asserted-by":"crossref","unstructured":"Urbina, D.I., et al.: Limiting the impact of stealthy attacks on industrial control systems. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 1092\u20131105. ACM (2016)","DOI":"10.1145\/2976749.2978388"},{"key":"27_CR21","unstructured":"Welch, G., Bishop, G.: An introduction to the Kalman filter (1995)"},{"issue":"1","key":"27_CR22","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1109\/90.554723","volume":"5","author":"W Willinger","year":"1997","unstructured":"Willinger, W., Taqqu, M.S., Sherman, R., Wilson, D.V.: Self-similarity through high-variability: statistical analysis of ethernet LAN traffic at the source level. IEEE\/ACM Trans. Netw. (ToN) 5(1), 71\u201386 (1997)","journal-title":"IEEE\/ACM Trans. Netw. (ToN)"},{"key":"27_CR23","doi-asserted-by":"crossref","unstructured":"Yu, S.J., Koh, P., Kwon, H., Kim, D.S., Kim, H.K.: Hurst parameter based anomaly detection for intrusion detection system. In: International Conference on Computer and Information Technology (CIT), pp. 234\u2013240. IEEE (2016)","DOI":"10.1109\/CIT.2016.98"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00470-5_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,6]],"date-time":"2025-07-06T22:47:54Z","timestamp":1751842074000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-00470-5_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030004699","9783030004705"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00470-5_27","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]}}}