{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T18:15:47Z","timestamp":1743012947942,"version":"3.40.3"},"publisher-location":"Cham","reference-count":79,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319058849"},{"type":"electronic","value":"9783319058856"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-05885-6_12","type":"book-chapter","created":{"date-parts":[[2014,4,1]],"date-time":"2014-04-01T15:08:12Z","timestamp":1396364892000},"page":"253-283","source":"Crossref","is-referenced-by-count":0,"title":["Learning Remote Computer Fingerprinting"],"prefix":"10.1007","author":[{"given":"Jo\u00e3o P. Souza","family":"Medeiros","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jo\u00e3o B. Borges","family":"Neto","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Agostinho M. Brito","family":"J\u00fanior","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paulo S. Motta","family":"Pires","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"12_CR1","doi-asserted-by":"crossref","unstructured":"Arackaparambil, C., Bratus, S., Shubina, A., Kotz, D.: On the reliability of wireless fingerprinting using clock skews. In: Proceedings of the Third ACM Conference on Wireless Network Security (WiSec), pp. 169\u2013174 (2010), doi:10.1145\/1741866.1741894","DOI":"10.1145\/1741866.1741894"},{"key":"12_CR2","unstructured":"Arkin, O., Yarochkin, F.: ICMP based remote OS TCP\/IP stack fingerprinting techniques. Phrack Magazine\u00a011(57) (2001)"},{"key":"12_CR3","doi-asserted-by":"crossref","unstructured":"Bellovin, S.: RFC 1948 (Informational), Defending Against Sequence Number Attacks. Internet Engineering Task Force (IETF) (1996)","DOI":"10.17487\/rfc1948"},{"key":"12_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/978-3-540-24668-8_16","volume-title":"Passive and Active Network Measurement","author":"R. Beverly","year":"2004","unstructured":"Beverly, R.: A robust classifier for passive TCP\/IP fingerprinting. In: Barakat, C., Pratt, I. (eds.) PAM 2004. LNCS, vol.\u00a03015, pp. 158\u2013167. Springer, Heidelberg (2004)"},{"key":"12_CR5","doi-asserted-by":"crossref","unstructured":"Braden, R.: RFC 1122 (Standard), Requirements for Internet Hosts \u2013 Communication Layers. Internet Engineering Task Force (IETF) (1989)","DOI":"10.17487\/rfc1122"},{"key":"12_CR6","doi-asserted-by":"crossref","unstructured":"Bratus, S., Cornelius, C., Kotz, D., Peebles, D.: Active behavioral fingerprinting of wireless devices. In: Proceedings of the First ACM Conference on Wireless Network Security (WiSec), pp. 56\u201361 (2008), doi:10.1145\/1352533.1352543","DOI":"10.1145\/1352533.1352543"},{"key":"12_CR7","unstructured":"Burroni, J., Sarraute, C.: Using neural networks for remote OS identification. In: Proceedings of the 3rd Pacific Security Conference (PacSec) (2005)"},{"issue":"4","key":"12_CR8","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1007\/BF00994110","volume":"9","author":"G.F. Cooper","year":"1992","unstructured":"Cooper, G.F., Herskovits, E.: A bayesian method for the induction of probabilistic networks from data. Machine Learning\u00a09(4), 309\u2013347 (1992), doi:10.1007\/BF00994110","journal-title":"Machine Learning"},{"key":"12_CR9","doi-asserted-by":"crossref","unstructured":"Corbett, C.L., Beyah, R.A., Copeland, J.A.: A passive approach to wireless NIC identification. In: Proceedings of IEEE International Conference on Communications (ICC), pp. 2329\u20132334 (2006), doi:10.1109\/ICC.2006.255117","DOI":"10.1109\/ICC.2006.255117"},{"issue":"5","key":"12_CR10","doi-asserted-by":"publisher","first-page":"335","DOI":"10.1007\/s10207-007-0053-7","volume":"7","author":"C.L. Corbett","year":"2008","unstructured":"Corbett, C.L., Beyah, R.A., Copeland, J.A.: Passive classification of wireless NICs during active scanning. International Journal of Information Security\u00a07(5), 335\u2013348 (2008), doi:10.1007\/s10207-007-0053-7","journal-title":"International Journal of Information Security"},{"issue":"3","key":"12_CR11","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/BF00994018","volume":"20","author":"C. Cortes","year":"1995","unstructured":"Cortes, C., Vapnik, V.: Support-vector networks. Machine Learning\u00a020(3), 273\u2013297 (1995), doi:10.1007\/BF00994018","journal-title":"Machine Learning"},{"key":"12_CR12","doi-asserted-by":"crossref","unstructured":"Danev, B., Luecken, H., Capkun, S., Defrawy, K.E.: Attacks on physical-layer identification. In: Proceedings of the Third ACM Conference on Wireless Network Security (WiSec), pp. 89\u201398 (2010), doi:10.1145\/1741866.1741882","DOI":"10.1145\/1741866.1741882"},{"key":"12_CR13","doi-asserted-by":"crossref","unstructured":"Danev, B., Zanetti, D., Capkun, S.: On physical-layer identification of wireless devices. ACM Computing Surveys\u00a045(1) (2012), doi:10.1145\/2379776.2379782","DOI":"10.1145\/2379776.2379782"},{"key":"12_CR14","doi-asserted-by":"crossref","unstructured":"Deering, S., Hinden, R.: RFC 2460 (Draft Standard), Internet Protocol, Version 6 (IPv6) Specification. Internet Engineering Task Force (IETF) (1998)","DOI":"10.17487\/rfc2460"},{"issue":"4","key":"12_CR15","first-page":"2","volume":"9","author":"W.M. Eddy","year":"2006","unstructured":"Eddy, W.M.: Defenses against TCP SYN flooding attacks. The Internet Protocol Journal\u00a09(4), 2\u201316 (2006)","journal-title":"The Internet Protocol Journal"},{"key":"12_CR16","doi-asserted-by":"crossref","unstructured":"Eddy, W.M.: RFC 4987 (Informational), TCP SYN Flooding Attacks and Common Mitigations. Internet Engineering Task Force (IETF) (2007)","DOI":"10.17487\/rfc4987"},{"key":"12_CR17","doi-asserted-by":"crossref","unstructured":"Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter, L., Leach, P., Berners-Lee, T.: RFC 2068 (Proposed Standard), Hypertext Transfer Protocol \u2013 HTTP\/1.1. Internet Engineering Task Force (IETF) (1999)","DOI":"10.17487\/rfc2616"},{"key":"12_CR18","unstructured":"Fritzke, B.: A growing neural gas network learns topologies. In: Tesauro, G., Touretzky, D., Leen, T. (eds.) Advances in Neural Information Processing Systems, vol.\u00a07, pp. 625\u2013632. MIT Press (1995)"},{"key":"12_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1007\/978-3-642-04238-6_61","volume-title":"Logic Programming and Nonmonotonic Reasoning","author":"F. Gagnon","year":"2009","unstructured":"Gagnon, F., Esfandiari, B.: Using answer set programming to enhance operating system discovery. In: Erdem, E., Lin, F., Schaub, T. (eds.) LPNMR 2009. LNCS, vol.\u00a05753, pp. 579\u2013584. Springer, Heidelberg (2009)"},{"key":"12_CR20","doi-asserted-by":"crossref","unstructured":"Gagnon, F., Esfandiari, B., Bertossi, L.: A hybrid approach to operating system discovery using answer set programming. In: Proceedings of the 10th IFIP\/IEEE International Symposium on Integrated Network Management (IM), pp. 391\u2013400 (2007), doi:10.1109\/INM.2007.374804","DOI":"10.1109\/INM.2007.374804"},{"key":"12_CR21","doi-asserted-by":"crossref","unstructured":"Gao, K., Corbett, C., Beyah, R.: A passive approach to wireless device fingerprinting. In: Proceedings of the IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 383\u2013392 (2010), doi:10.1109\/DSN.2010.5544294","DOI":"10.1109\/DSN.2010.5544294"},{"key":"12_CR22","doi-asserted-by":"crossref","first-page":"S64","DOI":"10.1016\/j.diin.2010.05.009","volume":"7","author":"S.L. Garfinkel","year":"2010","unstructured":"Garfinkel, S.L.: Digital forensics research: The next 10 years. Digital Investigation\u00a07, S64\u2013S73 (2010), doi:10.1016\/j.diin.2010.05.009","journal-title":"Digital Investigation"},{"key":"12_CR23","doi-asserted-by":"crossref","unstructured":"Gont, F., Bellovin, S.: RFC 6528 (Standards Track), Defending Against Sequence Number Attacks. Internet Engineering Task Force (IETF) (2012)","DOI":"10.17487\/rfc6528"},{"key":"12_CR24","unstructured":"Greenwald, L.G., Thomas, T.J.: Toward undetected operating system fingerprinting. In: Proceedings of the First USENIX Workshop on Offensive Technologies (WOOT) (2007)"},{"issue":"3","key":"12_CR25","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1002\/bltj.20257","volume":"12","author":"L.G. Greenwald","year":"2007","unstructured":"Greenwald, L.G., Thomas, T.J.: Understanding and preventing network device fingerprinting. Bell Labs Technical Journal\u00a012(3), 149\u2013166 (2007), doi:10.1002\/bltj.20257","journal-title":"Bell Labs Technical Journal"},{"key":"12_CR26","unstructured":"Hartmeier, D.: Design and performance of the OpenBSD stateful packet filter (pf). In: Proceedings of the FREENIX Track: USENIX Annual Technical Conference, pp. 171\u2013180 (2002)"},{"key":"12_CR27","doi-asserted-by":"crossref","unstructured":"Huang, D.J., Yang, K.T., Ni, C.C., Teng, W.C., Hsiang, T.R., Lee, Y.J.: Clock skew based client device identification in cloud environments. In: Proceedings of the IEEE 26th International Conference on Advanced Information Networking and Applications (AINA), pp. 526\u2013533 (2012), doi:10.1109\/AINA.2012.51","DOI":"10.1109\/AINA.2012.51"},{"key":"12_CR28","doi-asserted-by":"crossref","unstructured":"Jacobson, V., Braden, R., Borman, D.: RFC 1323 (Proposed Standard), TCP Extensions for High Performance. Internet Engineering Task Force (IETF) (1992)","DOI":"10.17487\/rfc1323"},{"key":"12_CR29","unstructured":"Jacobson, V., Leres, C., McCanne, S.: TCPDUMP\/LIBPCAP public repository, version 4.3.0 (2012), \n                    http:\/\/www.tcpdump.org\/\n                   (released on June 2012)"},{"issue":"3","key":"12_CR30","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1109\/TMC.2009.145","volume":"9","author":"S. Jana","year":"2010","unstructured":"Jana, S., Kasera, S.K.: On fast and accurate detection of unauthorized wireless access points using clock skews. IEEE Transactions on Mobile Computing\u00a09(3), 449\u2013462 (2010), doi:10.1109\/TMC.2009.145","journal-title":"IEEE Transactions on Mobile Computing"},{"issue":"2","key":"12_CR31","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1109\/TDSC.2005.26","volume":"2","author":"T. Kohno","year":"2005","unstructured":"Kohno, T., Broido, A., Claffy, K.: Remote physical device fingerprinting. IEEE Transactions on Dependable and Secure Computing\u00a02(2), 93\u2013108 (2005), doi:10.1109\/TDSC.2005.26","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"issue":"1","key":"12_CR32","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/BF00337288","volume":"43","author":"T. Kohonen","year":"1982","unstructured":"Kohonen, T.: Self-organized formation of topologically correct feature maps. Biological Cybernetics\u00a043(1), 59\u201369 (1982)","journal-title":"Biological Cybernetics"},{"key":"12_CR33","doi-asserted-by":"crossref","unstructured":"Kohonen, T.: Self-Organizing Maps, 3rd edn. Springer (2001)","DOI":"10.1007\/978-3-642-56927-2"},{"key":"12_CR34","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1090\/qam\/10666","volume":"2","author":"K. Levenberg","year":"1944","unstructured":"Levenberg, K.: A method for the solution of certain non-linear problems in least squares. Quarterly of Applied Mathematics\u00a02, 164\u2013168 (1944)","journal-title":"Quarterly of Applied Mathematics"},{"key":"12_CR35","doi-asserted-by":"crossref","unstructured":"Li, W., Zhang, D.-F., Yang, J.: Remote OS fingerprinting using BP neural network. In: Wang, J., Liao, X.-F., Yi, Z. (eds.) ISNN 2005. LNCS, vol.\u00a03498, pp. 367\u2013372. Springer, Heidelberg (2005)","DOI":"10.1007\/11427469_59"},{"key":"12_CR36","doi-asserted-by":"crossref","unstructured":"Liu, M.W., Doherty, J.F.: Wireless device identification in MIMO channels. In: Proceedings of the 43rd Annual Conference on Information Sciences and Systems (CISS), pp. 563\u2013567 (2009), doi:10.1109\/CISS.2009.5054783","DOI":"10.1109\/CISS.2009.5054783"},{"key":"12_CR37","doi-asserted-by":"crossref","unstructured":"Loh, D.C.C., Cho, C.Y., Tan, C.P., Lee, R.S.: Identifying unique devices through wireless fingerprinting. In: Proceedings of the First ACM Conference on Wireless Network Security (WiSec), pp. 46\u201355 (2008), doi:10.1145\/1352533.1352542","DOI":"10.1145\/1352533.1352542"},{"key":"12_CR38","unstructured":"Lyon, G.F.: The art of port scanning. Phrack Magazine\u00a07(51) (1997)"},{"key":"12_CR39","unstructured":"Lyon, G.F.: Remote OS detection via TCP\/IP fingerprinting. Phrack Magazine\u00a08(54) (1998)"},{"key":"12_CR40","unstructured":"Lyon, G.F.: Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. Insecure.Com LLC (2009)"},{"key":"12_CR41","unstructured":"MacQueen, J.B.: Some methods for classification and analysis of multivariate observations. In: Proceedings of 5th Berkeley Symposium on Mathematical Statistics and Probability, vol.\u00a01, pp. 281\u2013297 (1967)"},{"key":"12_CR42","doi-asserted-by":"crossref","unstructured":"Marek, V.W., Truszczy\u0144ski, M.: Stable models and an alternative logic programming paradigm. In: Apt, K.R., Marek, V.W., Truszczy\u0144ski, M., Warren, D.S. (eds.) The Logic Programming Paradigm: A 25-Year Perspective, pp. 375\u2013398. Springer (1999), doi:10.1007\/978-3-642-60085-2_17","DOI":"10.1007\/978-3-642-60085-2_17"},{"issue":"2","key":"12_CR43","doi-asserted-by":"publisher","first-page":"431","DOI":"10.1137\/0111030","volume":"11","author":"D.W. Marquardt","year":"1963","unstructured":"Marquardt, D.W.: An algorithm for least-squares estimation of nonlinear parameters. Journal of the Society for Industrial and Applied Mathematics\u00a011(2), 431\u2013441 (1963), doi:10.1137\/0111030","journal-title":"Journal of the Society for Industrial and Applied Mathematics"},{"key":"12_CR44","unstructured":"McCanne, S., Jacobson, V.: The BSD packet filter: A new architecture for user-level packet capture. In: Proceedings of the USENIX Winter 1993 Conference, pp. 259\u2013269 (1993)"},{"key":"12_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/978-3-540-89173-4_20","volume-title":"Critical Information Infrastructures Security","author":"J.P.S. Medeiros","year":"2008","unstructured":"Medeiros, J.P.S., Cunha, A.C., Brito Jr., A.M., Motta Pires, P.S.: Application of kohonen maps to improve security tests on automation devices. In: Lopez, J., H\u00e4mmerli, B.M. (eds.) CRITIS 2007. LNCS, vol.\u00a05141, pp. 235\u2013245. Springer, Heidelberg (2008)"},{"key":"12_CR46","doi-asserted-by":"crossref","unstructured":"Medeiros, J.P.S., Cunha, A.C., Brito, A.M., Pires, P.S.M.: Automating security tests for industrial automation devices using neural networks. In: Proceedings of the 12th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), pp. 772\u2013775 (2007), doi:10.1109\/EFTA.2007.4416854","DOI":"10.1109\/EFTA.2007.4416854"},{"key":"12_CR47","doi-asserted-by":"crossref","unstructured":"Medeiros, J.P.S., Brito Jr., A.M., Pires, P.S.M.: A data mining based analysis of Nmap operating system fingerprint database. In: Herrero, \u00c1., Gastaldo, P., Zunino, R., Corchado, E. (eds.) CISIS 09. AISC, vol.\u00a063, pp. 1\u20138. Springer, Heidelberg (2009)","DOI":"10.1007\/978-3-642-04091-7_1"},{"key":"12_CR48","doi-asserted-by":"crossref","unstructured":"Medeiros, J.P.S., Brito, A.M., Pires, P.S.M.: A new method for recognizing operating systems of automation devices. In: Proceedings of the 14th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), pp. 1\u20134 (2009), doi:10.1109\/ETFA.2009.5347095","DOI":"10.1109\/ETFA.2009.5347095"},{"issue":"4","key":"12_CR49","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1504\/IJSSE.2009.031347","volume":"1","author":"J.P.S. Medeiros","year":"2009","unstructured":"Medeiros, J.P.S., Santos, S.R., Brito, A.M., Pires, P.S.M.: Advances in network topology security visualisation. International Journal of System of Systems Engineering\u00a01(4), 387\u2013400 (2009), doi:10.1504\/IJSSE.2009.031347","journal-title":"International Journal of System of Systems Engineering"},{"key":"12_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1007\/978-3-642-11207-2_16","volume-title":"Data Privacy Management and Autonomous Spontaneous Security","author":"J.P.S. Medeiros","year":"2010","unstructured":"Medeiros, J.P.S., Brito Jr., A.M., Motta Pires, P.S.: An effective TCP\/IP fingerprinting technique based on strange attractors classification. In: Garcia-Alfaro, J., Navarro-Arribas, G., Cuppens-Boulahia, N., Roudier, Y. (eds.) DPM 2009. LNCS, vol.\u00a05939, pp. 208\u2013221. Springer, Heidelberg (2010)"},{"issue":"4","key":"12_CR51","first-page":"554","volume":"5","author":"J.P.S. Medeiros","year":"2010","unstructured":"Medeiros, J.P.S., Brito, A.M., Pires, P.S.M.: Using intelligent techniques to extend the applicability of operating system fingerprint databases. Journal of Information Assurance and Security\u00a05(4), 554\u2013560 (2010)","journal-title":"Journal of Information Assurance and Security"},{"key":"12_CR52","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/978-3-642-21323-6_9","volume-title":"Computational Intelligence in Security for Information Systems","author":"J.P.S. Medeiros","year":"2011","unstructured":"Medeiros, J.P.S., de Medeiros Brito J\u00fanior, A., Motta Pires, P.S.: A qualitative survey of active TCP\/IP fingerprinting tools and techniques for operating systems identification. In: Herrero, \u00c1., Corchado, E. (eds.) CISIS 2011. LNCS, vol.\u00a06694, pp. 68\u201375. Springer, Heidelberg (2011)"},{"key":"12_CR53","unstructured":"Meehan, A., Manes, G., Davis, L., Hale, J., Shenoi, S.: Packet sniffing for automated chat room monitoring and evidence preservation. In: Proceedings of the 2001 IEEE Workshop on Information Assurance and Security, pp. 285\u2013288 (2001)"},{"key":"12_CR54","doi-asserted-by":"crossref","unstructured":"Mockapetris, P.: RFC 1035 (Internet Standard), Domain Names \u2013 Implementation and Specification. Internet Engineering Task Force (IETF) (1987)","DOI":"10.17487\/rfc1035"},{"key":"12_CR55","series-title":"IFIP","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/1-4020-8070-0_1","volume-title":"Data and Applications Security XVII","author":"J. Novotny","year":"2004","unstructured":"Novotny, J., Schulte, D., Manes, G., Shenoi, S.: Remote computer fingerprinting for cyber crime investigations. In: di Vimercati, S.D.C., Ray, I., Ray, I. (eds.) Data and Applications Security XVII. IFIP, vol.\u00a0142, pp. 3\u201315. Springer, Boston (2004)"},{"key":"12_CR56","doi-asserted-by":"crossref","unstructured":"Novotny, J.M., Meehan, A., Schulte, D., Manes, G.W., Shenoi, S.: Evidence acquisition tools for cyber sex crimes investigations. In: Proceedings of the SPIE, Sensors, and Command, Control, Communications, and Intelligence (C3I) Technologies for Homeland Defense and Law Enforcement, vol.\u00a04708, pp. 53\u201360 (2002), doi:10.1117\/12.479292","DOI":"10.1117\/12.479292"},{"key":"12_CR57","series-title":"IFIP","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1007\/1-4020-8070-0_28","volume-title":"Data and Applications Security XVII","author":"M. Pollitt","year":"2004","unstructured":"Pollitt, M., Caloyannides, M., Novotny, J., Shenoi, S.: Digital forensics: Operational, legal and research issues. In: di Vimercati, S.D.C., Ray, I., Ray, I. (eds.) Data and Applications Security XVII. IFIP, vol.\u00a0142, pp. 393\u2013403. Springer, Boston (2004)"},{"key":"12_CR58","doi-asserted-by":"crossref","unstructured":"Postel, J.: RFC 768 (Internet Standard), User Datagram Protocol. Internet Engineering Task Force (IETF) (1980)","DOI":"10.17487\/rfc0768"},{"key":"12_CR59","doi-asserted-by":"crossref","unstructured":"Postel, J.: RFC 791 (Internet Standard), Internet Protocol \u2013 DARPA Internet Program, Protocol Specification. Internet Engineering Task Force (IETF) (1981)","DOI":"10.17487\/rfc0791"},{"key":"12_CR60","doi-asserted-by":"crossref","unstructured":"Postel, J.: RFC 792 (Internet Standard), Internet Control Message Protocol \u2013 DARPA Internet Program, Protocol Specification. Internet Engineering Task Force (IETF) (1981)","DOI":"10.17487\/rfc0777"},{"key":"12_CR61","doi-asserted-by":"crossref","unstructured":"Postel, J.: RFC 793 (Internet Standard), Transmission Control Protocol \u2013 DARPA Internet Program, Protocol Specification. Internet Engineering Task Force (IETF) (1981)","DOI":"10.17487\/rfc0791"},{"key":"12_CR62","doi-asserted-by":"crossref","unstructured":"Postel, J., Reynolds, J.: RFC 854 (Internet Standard), Telnet Protocol Specification. Internet Engineering Task Force (IETF) (1983)","DOI":"10.17487\/rfc0854"},{"key":"12_CR63","doi-asserted-by":"crossref","unstructured":"Postel, J., Reynolds, J.: RFC 959 (Internet Standard), File Transfer Protocol (FTP). Internet Engineering Task Force (IETF) (1985)","DOI":"10.17487\/rfc0959"},{"key":"12_CR64","unstructured":"Provos, N.: A virtual honeypot framework. In: Proceedings of the 13th USENIX Security Symposium (2004)"},{"key":"12_CR65","unstructured":"Provos, N., Holz, T.: Virtual Honeypots: From Botnet Tracking to Intrusion Detection. Addison-Wesley (2008)"},{"key":"12_CR66","doi-asserted-by":"crossref","unstructured":"Ramakrishnan, K., Floyd, S., Black, D.: RFC 3168 (Proposed Standard), The Addition of Explicit Congestion Notification (ECN) to IP. Internet Engineering Task Force (IETF) (2001)","DOI":"10.17487\/rfc3168"},{"key":"12_CR67","doi-asserted-by":"crossref","unstructured":"Rasmussen, K.B., Capkun, S.: Implications of radio fingerprinting on the security of sensor networks. In: Proceedings of the Third International Conference on Security and Privacy in Communications Networks and the Workshops (SecureComm), pp. 331\u2013340 (2007), doi:10.1109\/SECCOM.2007.4550352","DOI":"10.1109\/SECCOM.2007.4550352"},{"key":"12_CR68","doi-asserted-by":"crossref","unstructured":"Remley, K., Grosvenor, C., Johnk, R., Novotny, D., Hale, P., McKinley, M.: Electromagnetic signatures of WLAN cards and network security. In: Proceedings of Fifth IEEE International Symposium on Signal Processing and Information Technology, pp. 484\u2013488 (2005), doi:10.1109\/ISSPIT.2005.1577145","DOI":"10.1109\/ISSPIT.2005.1577145"},{"key":"12_CR69","doi-asserted-by":"crossref","unstructured":"Rivest, R.: RFC 1321 (Informational), The MD5 Message-Digest Algorithm. Internet Engineering Task Force (IETF) (1992)","DOI":"10.17487\/rfc1321"},{"issue":"6088","key":"12_CR70","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1038\/323533a0","volume":"323","author":"D.E. Rumelhart","year":"1986","unstructured":"Rumelhart, D.E., Hinton, G.E., Williams, R.J.: Learning representations by back-propagating errors. Nature\u00a0323(6088), 533\u2013536 (1986), doi:10.1038\/323533a0","journal-title":"Nature"},{"issue":"1","key":"12_CR71","first-page":"35","volume":"8","author":"C. Sarraute","year":"2008","unstructured":"Sarraute, C., Burroni, J.: Using neural networks to improve classical operating system fingerprinting techniques. Electronic Journal of SADIO\u00a08(1), 35\u201347 (2008)","journal-title":"Electronic Journal of SADIO"},{"issue":"3","key":"12_CR72","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","volume":"27","author":"C.E. Shanon","year":"1948","unstructured":"Shanon, C.E.: A mathematical theory of communication. Bell System Technical Journal\u00a027(3), 379\u2013423 (1948)","journal-title":"Bell System Technical Journal"},{"key":"12_CR73","unstructured":"Smart, M., Malan, G.R., Jahanian, F.: Defeating TCP\/IP stack fingerprinting. In: Proceedings of the 9th USENIX Security Symposium (2000)"},{"issue":"1","key":"12_CR74","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/CJECE.2007.364330","volume":"32","author":"O. Ureten","year":"2007","unstructured":"Ureten, O., Serinken, N.: Wireless security through RF fingerprinting. Canadian Journal of Electrical and Computer Engineering\u00a032(1), 27\u201333 (2007), doi:10.1109\/CJECE.2007.364330","journal-title":"Canadian Journal of Electrical and Computer Engineering"},{"key":"12_CR75","unstructured":"Walls, R.J., Levine, B.N., Liberatore, M., Shields, C.: Effective digital forensics research is investigator-centric. In: Proceedings of the 6th USENIX Conference on Hot Topics in Security (HotSec) (2011)"},{"key":"12_CR76","doi-asserted-by":"crossref","unstructured":"Watson, D., Smart, M., Malan, G., Jahanian, F.: Protocol scrubbing: network security through transparent flow modification. In: Proceedings of the DARPA Information Survivability Conference and Exposition II (DISCEX), pp. 108\u2013118 (2001), doi:10.1109\/DISCEX.2001.932163","DOI":"10.1109\/DISCEX.2001.932163"},{"issue":"2","key":"12_CR77","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1109\/TNET.2003.822645","volume":"12","author":"D. Watson","year":"2004","unstructured":"Watson, D., Smart, M., Malan, G., Jahanian, F.: Protocol scrubbing: network security through transparent flow modification. IEEE\/ACM Transactions on Networking\u00a012(2), 261\u2013273 (2004), doi:10.1109\/TNET.2003.822645","journal-title":"IEEE\/ACM Transactions on Networking"},{"key":"12_CR78","unstructured":"Zalewski, M.: Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks, 1st edn. No Starch Press (2005)"},{"key":"12_CR79","doi-asserted-by":"crossref","unstructured":"Zhang, B., Zou, T., Wang, Y., Zhang, B.: Remote operation system detection base on machine learning. In: Proceedings of the International Conference on Frontier of Computer Science and Technology, pp. 539\u2013542 (2005), doi:10.1109\/FCST.2009.21","DOI":"10.1109\/FCST.2009.21"}],"container-title":["Studies in Computational Intelligence","Computational Intelligence in Digital Forensics: Forensic Investigation and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-05885-6_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,7]],"date-time":"2023-02-07T23:13:23Z","timestamp":1675811603000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-05885-6_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319058849","9783319058856"],"references-count":79,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-05885-6_12","relation":{},"ISSN":["1860-949X","1860-9503"],"issn-type":[{"type":"print","value":"1860-949X"},{"type":"electronic","value":"1860-9503"}],"subject":[],"published":{"date-parts":[[2014]]}}}