{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T16:53:41Z","timestamp":1743094421307,"version":"3.40.3"},"publisher-location":"Cham","reference-count":15,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319240176"},{"type":"electronic","value":"9783319240183"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-24018-3_15","type":"book-chapter","created":{"date-parts":[[2015,8,21]],"date-time":"2015-08-21T07:32:50Z","timestamp":1440142370000},"page":"237-248","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Normalizing Security Events with a Hierarchical Knowledge Base"],"prefix":"10.1007","author":[{"given":"David","family":"Jaeger","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Azodi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Feng","family":"Cheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christoph","family":"Meinel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,10,24]]},"reference":[{"key":"15_CR1","unstructured":"United States Computer Emergency Readiness Team (US-CERT). USCERT Year in Review CY 2012. Tech. rep. US Department of Homeland Security (2012)"},{"key":"15_CR2","unstructured":"US Office of Management and Budget. Fiscal Year 2012 Report to Congress on the Implementation of The Federal Information Security Management Act of 2002 (March 2013)"},{"key":"15_CR3","unstructured":"Kent, K., Souppaya, M.: Guide to Computer Security Log Management. In: NIST special publication (September 2006). \n                      http:\/\/212.200.39.245:81\/CrnaRupa\/2009-2010\/FIM\/ZIS\/Literatura\/GuidetoComputerSecurityLogManagementSP800-92.pdf"},{"key":"15_CR4","unstructured":"Gerhards, R.: The Syslog Protocol. RFC 5424 (Proposed Standard). Internet Engineering Task Force (March 2009). \n                      http:\/\/www.ietf.org\/rfc\/rfc5424.txt"},{"key":"15_CR5","unstructured":"Chuvakin, A., Marty, R., et al.: Common Event Expression. White Paper, MITRE (June (2008)"},{"key":"15_CR6","unstructured":"Hewlett-Packard. Implementing ArcSight CEF. 20. Hewlett-Packard (June 2013)"},{"key":"15_CR7","unstructured":"Barnum, S., Martin, R., et al.: The CybOX Language Specification. Draft 1. The MITRE Corporation (April 2012)"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Sapegin, A., Jaeger, D., et al.: Hierarchical Object Log Format for Normalisation of Security Events. In: Proceedings of the 9th International Conference on Information Assurance and Security (IAS 2013), Yassmine Hammamet, Tunisia, pp. 25\u201330 (December 2013)","DOI":"10.1109\/ISIAS.2013.6947748"},{"key":"15_CR9","unstructured":"Friedl, J.E.F.: Mastering Regular Expressions. In: Oram, A. (ed.) 3rd edn. O\u2019Reilly Media (August 2006)"},{"key":"15_CR10","unstructured":"Sparvieri, L.: SAP HANA Text Analysis. SAP (January 2014). \n                      http:\/\/scn.sap.com\/community\/developer-center\/hana\/blog\/2013\/01\/03\/sap-hana-text-analysis"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Kobayashi, S., Fukuda, K., Esaki, H.: Towards an NLPbased log template generation algorithm for system log analysis. In: Proceedings of The Ninth International Conference on Future Internet Technologies, p. 11 (2014)","DOI":"10.1145\/2619287.2619290"},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Azodi, A., Jaeger, D., et al.: Pushing the limits in event normalisation to improve attack detection in IDS\/SIEM systems. In: Proceedings of the First Internation Conference on Advanced Cloud and Big Data (CBD 2013), Nanjing, China (December 2013)","DOI":"10.1109\/CBD.2013.27"},{"key":"15_CR13","doi-asserted-by":"crossref","unstructured":"Azodi, A., Jaeger, D., et al.: A new approach to building a multi- tier direct access knowledge base for IDS\/SIEM systems. In: Proceedings of the 11th IEEE International Conference on Dependable, Autonomic and Secure Computing (DASC 2013), Chengdu, China (December 2013)","DOI":"10.1109\/DASC.2013.48"},{"key":"15_CR14","unstructured":"Real-time Event Analysis and Monitoring System (REAMS). \n                      http:\/\/hpi.de\/en\/meinel\/security-tech\/network-security\/securityanalytics\/reams.html\n                      \n                     (visited on November 5, 2015)"},{"key":"15_CR15","unstructured":"The Honeynet Project. Honeynet Challenges: Scan of the Month 34. Web Site (2005). \n                      http:\/\/old.honeynet.org\/scans\/scan34\/\n                      \n                     (visited on May 4, 2013)"}],"container-title":["Lecture Notes in Computer Science","Information Security Theory and Practice"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-24018-3_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,22]],"date-time":"2019-08-22T07:04:20Z","timestamp":1566457460000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-24018-3_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319240176","9783319240183"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-24018-3_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"24 October 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}