{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,17]],"date-time":"2025-09-17T15:57:47Z","timestamp":1758124667560,"version":"3.40.3"},"publisher-location":"Cham","reference-count":14,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319192420"},{"type":"electronic","value":"9783319192437"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-19243-7_44","type":"book-chapter","created":{"date-parts":[[2015,5,26]],"date-time":"2015-05-26T13:05:09Z","timestamp":1432645509000},"page":"482-494","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Knowledge-Based Model to Represent Security Information and Reason About Multi-stage Attacks"],"prefix":"10.1007","author":[{"given":"Faeiz M.","family":"Alserhani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,5,27]]},"reference":[{"key":"44_CR1","doi-asserted-by":"crossref","unstructured":"Alserhani, F., Akhlaq, M., et al.: MARS: multi-stage attack recognition system. In: Proceedings of the International Conference on Advanced Information Networking and Applications (AINA), pp. 753-759, Perth (2010)","DOI":"10.1109\/AINA.2010.57"},{"key":"44_CR2","doi-asserted-by":"crossref","unstructured":"Alserhnai, F., Akhlaq, M., et al.: Event-based correlation systems to detect SQLI activities. In: Proceedings Of the International Conference on Advanced Information Networking and Applications (AINA), Bioplis, Singapore (2011)","DOI":"10.1109\/AINA.2011.102"},{"key":"44_CR3","doi-asserted-by":"crossref","unstructured":"Templeton, S.J., Levitt, K.: A requires\/provides model for computer attacks. In: Proceedings of the 2000 workshop on New security paradigms ACM (2000)","DOI":"10.1145\/366173.366187"},{"issue":"1","key":"44_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1210263.1210267","volume":"10","author":"J Zhou","year":"2007","unstructured":"Zhou, J., Heckman, M., Reynolds, B., Carlson, A., Bishop, M.: Modeling network intrusion detection alerts for correlation. ACM Trans. Inf. Syst. Secur. (TISSEC) 10(1), 1\u201331 (2007)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"issue":"2","key":"44_CR5","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1145\/996943.996947","volume":"7","author":"P Ning","year":"2004","unstructured":"Ning, P., Cui, Y., Reeves, D.S., Xu, D.: Techniques and tools for analyzing intrusion alerts. ACM Trans. Inf. Syst. Secur. (TISSEC) 7(2), 274\u2013318 (2004)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"44_CR6","unstructured":"Cuppens, F., Miege, A.: Alert correlation in a cooperative intrusion detection framework. In: Proceedings of the 2002 IEEE Symposium on Security and Privacy, 2002. pp. 202-215 (2002)"},{"key":"44_CR7","unstructured":"Snort; \n                    http:\/\/www.snort.org\/"},{"key":"44_CR8","unstructured":"Haines, J.W., Lippmann, R.P., Fried, D.J., Tran, E., Boswell, S., Zissman, M.A.: DARPA intrusion detection system evaluation: Design and procedures, Technical report, Lincoln Laboratory, Massachusetts Institute of Technology (2000)"},{"key":"44_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/11506881_8","volume-title":"Intrusion and Malware Detection and Vulnerability Assessment","author":"F Valeur","year":"2005","unstructured":"Valeur, F., Mutz, D., Vigna, G.: A learning-based approach to the detection of SQL attacks. In: Julisch, K., Kruegel, C. (eds.) DIMVA 2005. LNCS, vol. 3548, pp. 123\u2013140. Springer, Heidelberg (2005)"},{"key":"44_CR10","unstructured":"Qin, X.: A probabilistic-based framework for infosec alert correlation,\u201d Ph.D., Georgia Institute of Technology (2005)"},{"key":"44_CR11","unstructured":"Common Vulnerabilities and Exposures (CVE). \n                    http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2010-0188"},{"key":"44_CR12","unstructured":"Security Focus - BugTraq. \n                    http:\/\/www.securityfocus.com"},{"key":"44_CR13","unstructured":"Nessus: Security Scanner. \n                    http:\/\/www.nessus.org"},{"key":"44_CR14","unstructured":"MIT Lincoln Laboratory; \n                    http:\/\/www.ll.mit.edu\/"}],"container-title":["Lecture Notes in Business Information Processing","Advanced Information Systems Engineering Workshops"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-19243-7_44","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,6,8]],"date-time":"2020-06-08T00:12:27Z","timestamp":1591575147000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-19243-7_44"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319192420","9783319192437"],"references-count":14,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-19243-7_44","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"27 May 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}