{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T00:31:56Z","timestamp":1725755516095},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319035833"},{"type":"electronic","value":"9783319035840"}],"license":[{"start":{"date-parts":[[2013,1,1]],"date-time":"2013-01-01T00:00:00Z","timestamp":1356998400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-319-03584-0_23","type":"book-chapter","created":{"date-parts":[[2013,11,7]],"date-time":"2013-11-07T15:17:57Z","timestamp":1383837477000},"page":"308-322","source":"Crossref","is-referenced-by-count":0,"title":["Detecting Stepping Stones by Abnormal Causality Probability"],"prefix":"10.1007","author":[{"given":"Sheng","family":"Wen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ping","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Di","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Xiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wanlei","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"23_CR1","unstructured":"Staniford-Chen, S., Heberlein, L.: Holding intruders accountable on the internet. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 39\u201349 (1995)"},{"key":"23_CR2","doi-asserted-by":"crossref","unstructured":"Coskun, B., Memon, N.: Online sketching of network flows for real-time stepping-stone detection. In: Annual Computer Security Applications Conference, ACSAC 2009, pp. 473\u2013483 (2009)","DOI":"10.1109\/ACSAC.2009.51"},{"key":"23_CR3","unstructured":"Zhang, L., Persaud, A., Johnson, A., Guan, Y.: Stepping-stone attack attribution in non-cooperative ip networks. In: The 25th IEEE International Performance Computing and Conference (2006)"},{"key":"23_CR4","unstructured":"Zhang, Y., Paxson, V.: Detecting stepping stones. In: Proceedings of the 9th Conference on USENIX Security Symposium, Berkeley, CA, USA, vol.\u00a09, p. 13 (2000)"},{"key":"23_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1007\/10722599_12","volume-title":"Computer Security - ESORICS 2000","author":"K. Yoda","year":"2000","unstructured":"Yoda, K., Etoh, H.: Finding a connection chain for tracing intruders. In: Cuppens, F., Deswarte, Y., Gollmann, D., Waidner, M. (eds.) ESORICS 2000. LNCS, vol.\u00a01895, pp. 191\u2013205. Springer, Heidelberg (2000)"},{"key":"23_CR6","doi-asserted-by":"publisher","first-page":"244","DOI":"10.1007\/3-540-45853-0_15","volume-title":"Computer Security \u2014 ESORICS 2002","author":"Xinyuan Wang","year":"2002","unstructured":"Wang, X., Reeves, D.S., Wu, S.F.: Inter-packet delay based correlation for tracing encrypted connections through stepping stones. In: Gollmann, D., Karjoth, G., Waidner, M. (eds.) ESORICS 2002. LNCS, vol.\u00a02502, pp. 244\u2013263. Springer, Heidelberg (2002)"},{"key":"23_CR7","first-page":"17","volume-title":"Lecture Notes in Computer Science","author":"David L. Donoho","year":"2002","unstructured":"Donoho, D.L., Flesia, A.G., Shankar, U., Paxson, V., Coit, J., Staniford, S.: Multiscale stepping-stone detection: Detecting pairs of jittered interactive streams by exploiting maximum tolerable delay. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 17\u201335. Springer, Heidelberg (2002)"},{"key":"23_CR8","first-page":"258","volume-title":"Lecture Notes in Computer Science","author":"Avrim Blum","year":"2004","unstructured":"Blum, A., Song, D., Venkataraman, S.: Detection of interactive stepping stones: Algorithms and confidence bounds. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 258\u2013277. Springer, Heidelberg (2004)"},{"key":"23_CR9","doi-asserted-by":"crossref","unstructured":"He, T., Tong, L.: A signal processing perspective to stepping-stone detection. In: 40th Annual Conference on Information Sciences and Systems 2006, pp. 687\u2013692 (2006)","DOI":"10.1109\/CISS.2006.286555"},{"issue":"5","key":"23_CR10","doi-asserted-by":"publisher","first-page":"1612","DOI":"10.1109\/TSP.2006.890881","volume":"55","author":"Ting He","year":"2007","unstructured":"He, T., Member, S., Tong, L.: Detecting encrypted stepping-stone connections. IEEE Trans. on Signal Processing\u00a055, 1612\u20131623 (2007)","journal-title":"IEEE Transactions on Signal Processing"},{"key":"23_CR11","doi-asserted-by":"crossref","unstructured":"Wang, X., Reeves, D.S.: Robust correlation of encrypted attack traffic through stepping stones by manipulation of interpacket delays. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, CCS 2003, New York, USA, pp. 20\u201329 (2003)","DOI":"10.1145\/948112.948115"},{"key":"23_CR12","unstructured":"Padhye, J.D., Wright, M.: Stepping-stone network attack kit (sneak) for evading timing-based detection methods under the cloak of constant rate multimedia streams. Master\u2019s thesis, Faculty of the Graduate School, The University of Texas at Arlington (2008)"},{"key":"23_CR13","doi-asserted-by":"crossref","unstructured":"Li, P., Zhou, W., Wang, Y.: Getting the real-time precise round-trip time for stepping stone detection. In: 2010 4th International Conference on Network and System Security (NSS), pp. 377\u2013382 (2010)","DOI":"10.1109\/NSS.2010.36"},{"key":"23_CR14","unstructured":"Wikipedia: Queueing theory. Technical report, Wikipedia (2013)"},{"key":"23_CR15","unstructured":"Wikipedia: Jackson network. Technical report, Wikipedia (2013)"},{"key":"23_CR16","unstructured":"Li, P.: Detect Stepping Stones in Internet Environments. PhD thesis, School of Information Technology, Deakin University (2011)"},{"key":"23_CR17","unstructured":"WAND Network Research Group, Wits: Auckland ix trace file. Technical report, WAND (2008)"},{"key":"23_CR18","unstructured":"Tae, H., Kim, H.L., Seo, Y.M., Choe, G., Min, S.L., Kim, C.S.: Caller identification system in the internet environment. In: Proceedings of 4th USENIX Security Symposium, pp. 69\u201378 (1993)"},{"key":"23_CR19","unstructured":"Snapp, S.R., Brentano, J., Dias, G.V., Goan, T.L., Heberlein, L.T., Lin Ho, C., Levitt, K.N., Mukherjee, B., Smaha, S.E., Grance, T., Teal, D.M., Mansur, D.: Dids (distributed intrusion detection system) - motivation, architecture, and an early prototype. In: Proceedings of the 14th National Computer Security Conference, pp. 167\u2013176 (1991)"},{"key":"23_CR20","unstructured":"Peng, P., Ning, P., Reeves, D.: On the secrecy of timing-based active watermarking trace-back techniques. In: 2006 IEEE Symposium on Security and Privacy, pp. 334\u2013349 (2006)"},{"key":"23_CR21","unstructured":"Peng, P., Ning, P., Reeves, D.S., Wang, X.: Active timing-based correlation of perturbed traffic flows with chaff packets. In: Proceedings of the Second International Workshop on Security in Distributed Computing Systems (SDCS) (ICDCSW 2005), Washington, DC, USA, vol.\u00a02, pp. 107\u2013113 (2005)"},{"key":"23_CR22","doi-asserted-by":"crossref","unstructured":"Wang, X., Wang, X., Reeves, D.S., Reeves, D.S., Wu, S.F., Wu, S.F., Yuill, J., Yuill, J.: Sleepy watermark tracing: An active network-based intrusion response framework. In: Proc. of the 16th International Information Security Conference, pp. 369\u2013384 (2001)","DOI":"10.1007\/0-306-46998-7_26"}],"container-title":["Lecture Notes in Computer Science","Cyberspace Safety and Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-03584-0_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,12,12]],"date-time":"2019-12-12T15:38:42Z","timestamp":1576165122000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-03584-0_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783319035833","9783319035840"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-03584-0_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}