{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T06:00:18Z","timestamp":1761976818879,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319035833"},{"type":"electronic","value":"9783319035840"}],"license":[{"start":{"date-parts":[[2013,1,1]],"date-time":"2013-01-01T00:00:00Z","timestamp":1356998400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-319-03584-0_9","type":"book-chapter","created":{"date-parts":[[2013,11,7]],"date-time":"2013-11-07T15:17:57Z","timestamp":1383837477000},"page":"104-116","source":"Crossref","is-referenced-by-count":3,"title":["Online Mining of Attack Models in IDS Alerts from Network Backbone by a Two-Stage Clustering Method"],"prefix":"10.1007","author":[{"given":"Lin-Bo","family":"Qiao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo-Feng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui-Yuan","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jin-Shu","family":"Su","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"9_CR1","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1109\/TDSC.2004.21","volume":"1","author":"F. Valeur","year":"2004","unstructured":"Valeur, F., Vigna, G., Kruegel, C., Kemmerer, R.A.: Comprehensive approach to intrusion detection alert correlation. IEEE Transactions on Dependable and Secure Computing\u00a01, 146\u2013169 (2004)","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"9_CR2","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1007\/0-306-46998-7_25","volume-title":"Trusted Information: The New Decade Challenge","author":"C. Michel","year":"2001","unstructured":"Michel, C., Me, L.: ADELE: An attack description language for knowledge-based intrusion detection. In: Trusted Information: The New Decade Challenge, pp. 353\u2013368. Kluwer Academic Publishers, Norwell (2001)"},{"key":"9_CR3","doi-asserted-by":"publisher","first-page":"71","DOI":"10.3233\/JCS-2002-101-204","volume":"10","author":"T.E. Steven","year":"2002","unstructured":"Steven, T.E., Giovanni, V., Richard, A.K.: STATL: an attack language for state-based intrusion detection. J. Comput. Secur.\u00a010, 71\u2013103 (2002)","journal-title":"J. Comput. Secur."},{"key":"9_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/3-540-39945-3_13","volume-title":"Recent Advances in Intrusion Detection","author":"F. Cuppens","year":"2000","unstructured":"Cuppens, F., Ortalo, R.: LAMBDA: A Language to Model a Database for Detection of Attacks. In: Debar, H., M\u00e9, L., Wu, S.F. (eds.) RAID 2000. LNCS, vol.\u00a01907, pp. 197\u2013216. Springer, Heidelberg (2000)"},{"key":"9_CR5","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1145\/586110.586144","volume-title":"Proceedings of the 9th ACM Conference on Computer and Communications Security","author":"P. Ning","year":"2002","unstructured":"Ning, P., Cui, Y., Reeves, D.S.: Constructing attack scenarios through correlation of intrusion alerts. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 245\u2013254. ACM, Washington (2002)"},{"key":"9_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1007\/3-540-36084-0_6","volume-title":"Recent Advances in Intrusion Detection","author":"P.A. Porras","year":"2002","unstructured":"Porras, P.A., Fong, M.W., Valdes, A.: A Mission-Impact-Based Approach to INFOSEC Alarm Correlation. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 95\u2013114. Springer, Heidelberg (2002)"},{"key":"9_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"457","DOI":"10.1007\/978-3-540-25952-7_36","volume-title":"Intelligence and Security Informatics","author":"J. Levera","year":"2004","unstructured":"Levera, J., Bar\u00e1n, B., Grossman, R.L.: Experimental studies using median polish procedure to reduce alarm rates in data cubes of intrusion data. In: Chen, H., Moore, R., Zeng, D.D., Leavitt, J. (eds.) ISI 2004. LNCS, vol.\u00a03073, pp. 457\u2013466. Springer, Heidelberg (2004)"},{"key":"9_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1007\/3-540-39945-3_11","volume-title":"Recent Advances in Intrusion Detection","author":"R. Lippmann","year":"2000","unstructured":"Lippmann, R., Haines, J.W., Fried, D.J., Korba, J., Das, K.: Analysis and results of the 1999 DARPA off-line intrusion detection evaluation. In: Debar, H., M\u00e9, L., Wu, S.F. (eds.) RAID 2000. LNCS, vol.\u00a01907, pp. 162\u2013182. Springer, Heidelberg (2000)"},{"key":"9_CR9","doi-asserted-by":"publisher","first-page":"739","DOI":"10.1109\/SNPD.2007.216","volume-title":"Eighth ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel\/Distributed Computing","author":"M. Xiao","year":"2007","unstructured":"Xiao, M., Xiao, D.: Alert verification based on attack classification in collaborative intrusion detection. In: Eighth ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel\/Distributed Computing, vol.\u00a02, pp. 739\u2013744. IEEE Computer Soc., Los Alamitos (2007)"},{"key":"9_CR10","first-page":"12604","volume-title":"Fourth International Conference on Wireless Communications, Networking and Mobile Computing","author":"M. Xu","year":"2008","unstructured":"Xu, M., Wu, T., Tang, J.F.: An IDS Alert Fusion Approach Based on Happened Before Relation. In: Fourth International Conference on Wireless Communications, Networking and Mobile Computing, vol.\u00a031, pp. 12604\u201312607. IEEE, New York (2008)"},{"key":"9_CR11","first-page":"376","volume-title":"2012 2nd International Conference on Computer Science and Network Technology (ICCSNT)","author":"J. Xu","year":"2012","unstructured":"Xu, J., Li, A., Zhao, H., Yin, H.: A multi-step attack pattern discovery method based on graph mining. In: 2012 2nd International Conference on Computer Science and Network Technology (ICCSNT), pp. 376\u2013380. IEEE, Changchun (2012)"},{"key":"9_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/3-540-45474-8_4","volume-title":"Recent Advances in Intrusion Detection","author":"A. Valdes","year":"2001","unstructured":"Valdes, A., Skinner, K.: Probabilistic Alert Correlation. In: Lee, W., M\u00e9, L., Wespi, A. (eds.) RAID 2001. LNCS, vol.\u00a02212, pp. 54\u201368. Springer, Heidelberg (2001)"},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"Siraj, A., Vaughn, R.B.: Multi-level alert clustering for intrusion detection sensor data. In: 2005 Annual Meeting of the North American Fuzzy Information Processing Society, pp. 748\u2013753. IEEE, New York (2005)","DOI":"10.1109\/NAFIPS.2005.1548632"},{"key":"9_CR14","doi-asserted-by":"publisher","first-page":"471","DOI":"10.1109\/CW.2008.94","volume-title":"Proceedings of the 2008 International Conference on Cyberworlds","author":"Y.G. Zhang","year":"2008","unstructured":"Zhang, Y.G., Mao, S.S., Zhuang, X., Peng, X.: Using Cluster and Correlation to Construct Attack Scenarios. In: Proceedings of the 2008 International Conference on Cyberworlds, pp. 471\u2013476. IEEE Computer Soc., Los Alamitos (2008)"},{"key":"9_CR15","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1016\/j.cose.2009.06.008","volume":"29","author":"C.V. Zhou","year":"2009","unstructured":"Zhou, C.V., Leckie, C., Karunasekera, S.: A survey of coordinated attacks and collaborative intrusion detection. Comput. Secur.\u00a029, 124\u2013140 (2009)","journal-title":"Comput. Secur."},{"key":"9_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1007\/978-3-642-33338-5_16","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"B. Amann","year":"2012","unstructured":"Amann, B., Sommer, R., Sharma, A., Hall, S.: A lone wolf no more: supporting network intrusion detection with real-time intelligence. In: Balzarotti, D., Stolfo, S.J., Cova, M. (eds.) RAID 2012. LNCS, vol.\u00a07462, pp. 314\u2013333. Springer, Heidelberg (2012)"},{"key":"9_CR17","unstructured":"Srujana Reddy, V., Dileep Kumar, G.: Online and Offline Intrusion Alert Aggregation. International Journal of Computer Science & Communication Networks\u00a02, 1776\u20131779 (2013)"},{"key":"9_CR18","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1016\/j.cose.2008.11.010","volume":"28","author":"R. Sadoddin","year":"2009","unstructured":"Sadoddin, R., Ghorbani, A.A.: An incremental frequent structure mining framework for real-time alert correlation. Comput. Secur.\u00a028, 153\u2013173 (2009)","journal-title":"Comput. Secur."},{"key":"9_CR19","first-page":"1257","volume-title":"2012 IEEE 26th International Parallel and Distributed Processing Symposium Workshops & PhD Forum (IPDPSW)","author":"L. Qiao","year":"2012","unstructured":"Qiao, L., Zhang, B., Lai, Z., Su, J.: Mining of Attack Models in IDS Alerts from Network Backbone by a Two-stage Clustering Method. In: 2012 IEEE 26th International Parallel and Distributed Processing Symposium Workshops & PhD Forum (IPDPSW), pp. 1257\u20131263. IEEE Computer Soc., Shanghai (2012)"},{"key":"9_CR20","first-page":"556","volume-title":"2013 International Conference on Computer, Networks and Communication Engineering","author":"R. Chen","year":"2013","unstructured":"Chen, R., Qiao, L., Zhang, B., Gong, Z.: A Framework of Event-Driven Detection System for Intricate Network Threats. In: 2013 International Conference on Computer, Networks and Communication Engineering, pp. 556\u2013560. Atlantis Press, Beijing (2013)"}],"container-title":["Lecture Notes in Computer Science","Cyberspace Safety and Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-03584-0_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T19:49:55Z","timestamp":1746042595000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-03584-0_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783319035833","9783319035840"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-03584-0_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}