{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T12:37:28Z","timestamp":1779194248113,"version":"3.51.4"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030786113","type":"print"},{"value":"9783030786120","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-78612-0_19","type":"book-chapter","created":{"date-parts":[[2021,7,8]],"date-time":"2021-07-08T23:38:40Z","timestamp":1625787520000},"page":"231-241","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["IPv6-Darknet Network Traffic Detection"],"prefix":"10.1007","author":[{"given":"ChenHuan","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"QianKun","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"ShanShan","family":"Hao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"CongXiao","family":"Bao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xing","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,7,9]]},"reference":[{"key":"19_CR1","unstructured":"The Team Cymru Darknet Project. http:\/\/www.cymru.com\/Darknet\/"},{"key":"19_CR2","doi-asserted-by":"crossref","unstructured":"Pang, R., Yegneswaran, V., Barford, P., Paxson, V., Peterson, L.: Characteristics of internet background radiation. In: Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement, pp. 27\u201340 (2004)","DOI":"10.1145\/1028788.1028794"},{"key":"19_CR3","doi-asserted-by":"crossref","unstructured":"Wustrow, E., Karir, M., Bailey, M., Jahanian, F., Huston, G.: Internet background radiation revisited. In: Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement, pp. 62\u201374 (2010)","DOI":"10.1145\/1879141.1879149"},{"key":"19_CR4","unstructured":"Darknet Incoming Traffic Stats. http:\/\/www.cymru.com\/Reach\/darknet.html"},{"issue":"5","key":"19_CR5","doi-asserted-by":"publisher","first-page":"649","DOI":"10.1016\/j.comcom.2010.06.004","volume":"34","author":"G Zhang","year":"2011","unstructured":"Zhang, G., Quoitin, B., Zhou, S.: Phase changes in the evolution of the IPv4 and IPv6 AS-Level Internet topologies. Comput. Commun. 34(5), 649\u2013657 (2011)","journal-title":"Comput. Commun."},{"key":"19_CR6","unstructured":"Ronan, J., Ford, M., Stevens, J.: Initial results from an IPv6 Darknet. (2006)"},{"key":"19_CR7","unstructured":"Deccio, C.T.: Turning Down the Lights: Darknet Deployment Lessons Learned. No. SAND2012\u20133966P. Sandia National Lab. (SNL-CA), Livermore, CA (United States) (2012)"},{"key":"19_CR8","unstructured":"Huston, G.: IPv6 Background Radiation. Technical report, Slides of a talk given at DUST 2012\u2013The 1st International Workshop on Darkspace and UnSolicited Traffic Analysis, San Diego, California (2012)"},{"key":"19_CR9","doi-asserted-by":"crossref","unstructured":"Czyz, J., Lady, K., Miller, S. G., Bailey, M., Kallitsis, M., Karir, M.: Understanding IPv6 internet background radiation. In:\u00a0Proceedings of the 2013 Conference on Internet Measurement Conference, pp. 105\u2013118. (2013)","DOI":"10.1145\/2504730.2504732"},{"key":"19_CR10","unstructured":"Cooke, E., Bailey, M., Watson, D., Jahanian, F., Nazario, J.: The Internet motion sensor: a distributed global scoped Internet threat monitoring system. Technical Report CSE-TR-491\u201304 (2004)"},{"key":"19_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1007\/978-3-540-30143-1_8","volume-title":"Recent Advances in Intrusion Detection","author":"V Yegneswaran","year":"2004","unstructured":"Yegneswaran, V., Barford, P., Plonka, D.: On the design and use of Internet sinks for network abuse monitoring. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol. 3224, pp. 146\u2013165. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30143-1_8"},{"key":"19_CR12","doi-asserted-by":"crossref","unstructured":"Bailey, M., Cooke, E., Jahanian, F., Myrick, A., Sinha, S.: Practical darknet measurement. In: 2006 40th Annual Conference on Information Sciences and System, pp. 1496\u20131501. IEEE (2006)","DOI":"10.1109\/CISS.2006.286376"},{"key":"19_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/978-3-642-28537-0_18","volume-title":"Passive and Active Measurement","author":"N Brownlee","year":"2012","unstructured":"Brownlee, N.: One-way traffic monitoring with iatmon. In: Taft, N., Ricciato, F. (eds.) PAM 2012. LNCS, vol. 7192, pp. 179\u2013188. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-28537-0_18"},{"key":"19_CR14","doi-asserted-by":"crossref","unstructured":"Glatz, E., Dimitropoulos, X.: Classifying internet one-way traffic. In: Proceedings of the 2012 Internet Measurement Conference, pp. 37\u201350 (2012)","DOI":"10.1145\/2398776.2398781"},{"issue":"2","key":"19_CR15","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1109\/TNET.2013.2297678","volume":"23","author":"A Dainotti","year":"2014","unstructured":"Dainotti, A., King, A., Claffy, K., Papale, F., Pescap\u00e9, A.: Analysis of a \u201c\/0\u201d stealth scan from a botnet. IEEE\/ACM Trans. Networking 23(2), 341\u2013354 (2014)","journal-title":"IEEE\/ACM Trans. Networking"},{"key":"19_CR16","unstructured":"King, A.: Syria disappears from the Internet (2012)"},{"key":"19_CR17","unstructured":"Aben, E., King, A., Benson, K., Hyun, Y., Dainotti, A., Claffy, K.: Lessons learned by \u201cmeasuring\u201d the Internet during\/after the Sandy storm. In: Proceedings of FCC Workshop on Network Resiliency (2013)"},{"key":"19_CR18","doi-asserted-by":"crossref","unstructured":"Dainotti, A., et al.: Analysis of country-wide internet outages caused by censorship. In: Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference, pp. 1\u201318 (2011)","DOI":"10.1145\/2068816.2068818"},{"key":"19_CR19","unstructured":"Barford, P., Nowak, R., Willett, R., Yegneswaran, V.: Toward a model for source addresses of internet background radiation. In: Proceedings of the Passive and Active Measurement Conference (2006)"},{"key":"19_CR20","doi-asserted-by":"crossref","unstructured":"Bailey, M., Cooke, E., Jahanian, F., Provos, N., Rosaen, K., Watson, D.: Data reduction for the scalable automated analysis of distributed darknet traffic. In: Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement, p. 21 (2005)","DOI":"10.1145\/1330107.1330135"},{"key":"19_CR21","doi-asserted-by":"crossref","unstructured":"Cooke, E., Bailey, M., Mao, Z. M., Watson, D., Jahanian, F., McPherson, D.: Toward understanding distributed blackhole placement. In: Proceedings of the 2004 ACM Workshop on Rapid Malcode, pp. 54\u201364 (2004)","DOI":"10.1145\/1029618.1029627"},{"key":"19_CR22","unstructured":"Moore, D., Shannon, C., Voelker, G., Savage, S.: Network telescopes: technical report. In: Cooperative Association for Internet Data Analysis (CAIDA) (2004)"},{"issue":"4","key":"19_CR23","first-page":"383","volume":"2","author":"SS Pandya","year":"2015","unstructured":"Pandya, S.S.: Active defence system for network security \u2500 honeypot. Adv. Comput. Sci. Inf. Technol. (ACSIT) 2(4), 383\u2013386 (2015)","journal-title":"Adv. Comput. Sci. Inf. Technol. (ACSIT)"},{"key":"19_CR24","doi-asserted-by":"crossref","unstructured":"Kishimoto, K., Ohira, K., Yamaguchi, Y., Yamaki, H., Takakura, H.: An adaptive honeypot system to capture ipv6 address scans. In:\u00a02012 International Conference on Cyber Security, pp. 165\u2013172. IEEE (2012)","DOI":"10.1109\/CyberSecurity.2012.28"},{"key":"19_CR25","unstructured":"Schindler, S., Schnor, B., Kiertscher, S., Scheffler, T., Zack, E.: HoneydV6: A low-interaction IPv6 honeypot. In: 2013 International Conference on Security and Cryptography (SECRYPT), pp. 1\u201312. IEEE (2013)"},{"key":"19_CR26","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-662-44788-8_15","volume-title":"E-Business and Telecommunications","author":"S Schindler","year":"2014","unstructured":"Schindler, S., Schnor, B., Kiertscher, S., Scheffler, T., Zack, E.: IPv6 network attack detection with HoneydV6. In: Obaidat, M.S., Filipe, J. (eds.) ICETE 2013. CCIS, vol. 456, pp. 252\u2013269. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44788-8_15"}],"container-title":["Lecture Notes in Computer Science","Artificial Intelligence and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-78612-0_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,30]],"date-time":"2021-08-30T22:04:44Z","timestamp":1630361084000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-78612-0_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030786113","9783030786120"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-78612-0_19","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"9 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICAIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Artificial Intelligence and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dublin","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ireland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 July 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"incodldos2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.icaisconf.com\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}