{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,3]],"date-time":"2025-06-03T04:10:01Z","timestamp":1748923801873,"version":"3.41.0"},"publisher-location":"Cham","reference-count":53,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319390277"},{"type":"electronic","value":"9783319390284"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-39028-4_3","type":"book-chapter","created":{"date-parts":[[2016,4,30]],"date-time":"2016-04-30T11:42:05Z","timestamp":1462016525000},"page":"29-42","source":"Crossref","is-referenced-by-count":1,"title":["Early Warning Systems for Cyber Defence"],"prefix":"10.1007","author":[{"given":"Harsha","family":"Kalutarage","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Siraj","family":"Shaikh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bu-Sung","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chonho","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yeo Chai","family":"Kiat","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,5,1]]},"reference":[{"key":"3_CR1","unstructured":"Biskup, J., H\u00e4mmerli, B., Meier, M., Schmerl, S., T\u00f6lle, J., Vogel, M.: 2. 08102 working group-early warning systems. In: Proceedings biskup_et_al: DSP, 1493 (2008)"},{"key":"3_CR2","doi-asserted-by":"crossref","unstructured":"Lee, C., Yi, L., Tan, L.H., Goh, W., Lee, B.S., Yeo, C.K.: A wavelet entropy-based change point detection on network traffic: a case study of heartbleed vulnerability. In: 2014 IEEE 6th International Conference on Cloud Computing Technology and Science (CloudCom), pp. 995\u20131000, December 2014","DOI":"10.1109\/CloudCom.2014.78"},{"key":"3_CR3","doi-asserted-by":"crossref","unstructured":"Durumeric, Z., Kasten, J., Adrian, D., Halderman, J.A., Bailey, M., Li, F., Weaver, N., Amann, J., Beekman, J., Payer, M., et al.: The matter of heartbleed. In: Proceedings of the 2014 Conference on Internet Measurement Conference, pp. 475\u2013488. ACM (2014)","DOI":"10.1145\/2663716.2663755"},{"key":"3_CR4","unstructured":"Cho, K., Mitsuya, K., Kato, A.: Traffic data repository at the wide project. In: Proceedings of the Annual Conference on USENIX Annual Technical Conference, ATEC 2000, p. 51. USENIX Association, Berkeley (2000)"},{"key":"3_CR5","doi-asserted-by":"crossref","unstructured":"Kalutarage, H., Shaikh, S., Lee, C., Sung, F.: Towards an early warning system for network attacks using bayesian inference. In: 2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing (CSCloud), pp. 399\u2013404, November 2015","DOI":"10.1109\/CSCloud.2015.35"},{"key":"3_CR6","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1016\/j.cose.2014.11.007","volume":"49","author":"M Robinson","year":"2015","unstructured":"Robinson, M., Jones, K., Janicke, H.: Cyber warfare: issues and challenges. Comput. Secur. 49, 70\u201394 (2015)","journal-title":"Comput. Secur."},{"key":"3_CR7","doi-asserted-by":"crossref","unstructured":"Sharma, A., Gandhi, R., Mahoney, W., Sousan, W., Zhu, Q., et al.: Building a social dimensional threat model from current and historic events of cyber attacks. In: 2010 IEEE Second International Conference on Social Computing (SocialCom), pp. 981\u2013986. IEEE (2010)","DOI":"10.1109\/SocialCom.2010.145"},{"key":"3_CR8","doi-asserted-by":"publisher","first-page":"327","DOI":"10.1016\/j.compeleceng.2015.07.007","volume":"47","author":"HK Kalutarage","year":"2015","unstructured":"Kalutarage, H.K., Shaikh, S.A., Wickramasinghe, I.P., Zhou, Q., James, A.E.: Detecting stealthy attacks: efficient monitoring of suspicious activities on computer networks. Comput. Electr. Eng. 47, 327\u2013344 (2015)","journal-title":"Comput. Electr. Eng."},{"key":"3_CR9","unstructured":"Kalutarage, H.: Effective monitoring of slow suspicious activites on computer networks. Ph.D. thesis, Coventry University (2013)"},{"key":"3_CR10","doi-asserted-by":"crossref","unstructured":"Dempsey, K.: Information security continuous monitoring (ISCM) for federal information systems and organizations. US Department of Commerce, National Institute of Standards and Technology (2011)","DOI":"10.6028\/NIST.SP.800-137"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Zou, C.C., Gao, L., Gong, W., Towsley, D.: Monitoring and early warning for internet worms. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, pp. 190\u2013199. ACM (2003)","DOI":"10.1145\/948109.948136"},{"key":"3_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/978-3-642-14379-3_13","volume-title":"Critical Information Infrastructures Security","author":"M Apel","year":"2010","unstructured":"Apel, M., Biskup, J., Flegel, U., Meier, M.: Towards early warning systems \u2013 challenges, technologies and architecture. In: Rome, E., Bloomfield, R. (eds.) CRITIS 2009. LNCS, vol. 6027, pp. 151\u2013164. Springer, Heidelberg (2010)"},{"key":"3_CR13","unstructured":"Engelberth, M., Freiling, F.C., G\u00f6bel, J., Gorecki, C., Holz, T., Hund, R., Trinius, P., Willems, C.: The inmas approach (2010)"},{"issue":"1","key":"3_CR14","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1002\/sec.534","volume":"6","author":"E Magkos","year":"2013","unstructured":"Magkos, E., Avlonitis, M., Kotzanikolaou, P., Stefanidakis, M.: Toward early warning against internet worms based on critical-sized networks. Secur. Commun. Netw. 6(1), 78\u201388 (2013)","journal-title":"Secur. Commun. Netw."},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Kollias, S., Vlachos, V., Papanikolaou, A., Chatzimisios, P., Ilioudis, C., Metaxiotis, K.: Measuring the internet\u2019s threat level: a global-local approach. In: 2014 IEEE Symposium on Computers and Communication (ISCC), pp. 1\u20136. IEEE (2014)","DOI":"10.1109\/ISCC.2014.6912624"},{"key":"3_CR16","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2014.06.008","volume":"46","author":"U Franke","year":"2014","unstructured":"Franke, U., Brynielsson, J.: Cyber situational awareness-a systematic review of the literature. Comput. Secur. 46, 18\u201331 (2014)","journal-title":"Comput. Secur."},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Harmer, P., Thomas, R., Christel, B., Martin, R., Watson, C.: Wireless security situation awareness with attack identification decision support. In: 2011 IEEE Symposium on Computational Intelligence in Cyber Security (CICS), pp. 144\u2013151, April 2011","DOI":"10.1109\/CICYBS.2011.5949399"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"King, D., Orlando, G., Kohler, J.: A case for trusted sensors: encryptors with deep packet inspection capabilities. In: Military Communication Conference, MILCOM 2012, pp. 1\u20136. IEEE (2012)","DOI":"10.1109\/MILCOM.2012.6415703"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"He, H., Xiaojing, W., Xin, Y.: A decision-support model for information systems based on situational awareness. In: International Conference on Multimedia Information Networking and Security, MINES 2009, vol. 2, pp. 405\u2013408, November 2009","DOI":"10.1109\/MINES.2009.130"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Sagduyu, Y., Deng, J., Li, J., Liu, P.: Integrated situational awareness for cyber attack detection, analysis, and mitigation. In: SPIE Defense, Security, and Sensing, International Society for Optics and Photonics, p. 83850N (2012)","DOI":"10.1117\/12.919261"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Preden, J., Motus, L., Meriste, M., Riid, A.: Situation awareness for networked systems. In: 2011 IEEE First International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA), pp. 123\u2013130, February 2011","DOI":"10.1109\/COGSIMA.2011.5753430"},{"issue":"1","key":"3_CR22","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1016\/j.cose.2009.06.008","volume":"29","author":"CV Zhou","year":"2010","unstructured":"Zhou, C.V., Leckie, C., Karunasekera, S.: A survey of coordinated attacks and collaborative intrusion detection. Comput. Secur. 29(1), 124\u2013140 (2010)","journal-title":"Comput. Secur."},{"key":"3_CR23","unstructured":"CSIRT_Network: The european computer security incident response team network, June 2015. http:\/\/www.ecsirt.net\/"},{"key":"3_CR24","unstructured":"Bailey, M., Cooke, E., Jahanian, F., Nazario, J., Watson, D., et al.: The internet motion sensor-a distributed blackhole monitoring system. In: NDSS (2005)"},{"key":"3_CR25","unstructured":"Symantec: Cyber security: Deepsight intelligence, June 2015. http:\/\/www.symantec.com\/deepsight-products\/"},{"key":"3_CR26","unstructured":"Grobauer, B., Mehlau, J.I., Sander, J.: Carmentis: a co-operative approach towards situation awareness and early warning for the internet. In: IMF, pp. 55\u201366 (2006)"},{"key":"3_CR27","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/978-3-540-74565-5_5","volume-title":"KI 2007: Advances in Artificial Intelligence","author":"Y Elovici","year":"2007","unstructured":"Elovici, Y., Shabtai, A., Moskovitch, R., Tahan, G., Glezer, C.: Applying machine learning techniques for detection of malicious code in network traffic. In: Hertzberg, J., Beetz, M., Englert, R. (eds.) KI 2007. LNCS (LNAI), vol. 4667, pp. 44\u201350. Springer, Heidelberg (2007)"},{"key":"3_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1007\/11962977_9","volume-title":"Critical Information Infrastructures Security","author":"K Bsufka","year":"2006","unstructured":"Bsufka, K., Kroll-Peters, O., Albayrak, \u015e.: Intelligent network-based early warning systems. In: L\u00f3pez, J. (ed.) CRITIS 2006. LNCS, vol. 4347, pp. 103\u2013111. Springer, Heidelberg (2006)"},{"key":"3_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1007\/978-3-642-21694-7_7","volume-title":"Critical Information Infrastructures Security","author":"M Brunner","year":"2011","unstructured":"Brunner, M., Hofinger, H., Roblee, C., Schoo, P., Todt, S.: Anonymity and privacy in distributed early warning systems. In: Xenakis, C., Wolthusen, S. (eds.) CRITIS 2010. LNCS, vol. 6712, pp. 81\u201392. Springer, Heidelberg (2011)"},{"key":"3_CR30","unstructured":"Koch, R., Golling, M., Rodosek, G.D.: Evaluation of state of the art ids message exchange protocols. In: International Conference on Communication and Network Security (ICCNS) (2013)"},{"key":"3_CR31","unstructured":"Theilmann, A.: Beyond centralism: the herold approach to sensor networks and early warning systems. In: Proceedings of First European Workshop of Internet Early Warning and Network Intelligence (EWNI 2010) (2010)"},{"issue":"1","key":"3_CR32","doi-asserted-by":"publisher","first-page":"327","DOI":"10.1109\/TSP.2006.882104","volume":"55","author":"S Aldosari","year":"2007","unstructured":"Aldosari, S., Moura, J.M., et al.: Detection in sensor networks: the saddlepoint approximation. IEEE Trans. Sig. Process. 55(1), 327\u2013340 (2007)","journal-title":"IEEE Trans. Sig. Process."},{"key":"3_CR33","unstructured":"G\u00f6bel, J., Trinius, P.: Towards optimal sensor placement strategies for early warning systems. In: Sicherheit, pp. 191\u2013204 (2010)"},{"key":"3_CR34","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-1904-0","volume-title":"Distributed Detection and Data Fusion","author":"PK Varshney","year":"1997","unstructured":"Varshney, P.K.: Distributed Detection and Data Fusion. Springer Science & Business Media, New York (1997)"},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Morris, T., Mayron, L., Smith, W., Knepper, M., Ita, R., Fox, K.: A perceptually-relevant model-based cyber threat prediction method for enterprise mission assurance. In: 2011 IEEE First International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA), pp. 60\u201365, February 2011","DOI":"10.1109\/COGSIMA.2011.5753755"},{"issue":"1","key":"3_CR36","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/s10796-010-9268-7","volume":"15","author":"H Chivers","year":"2013","unstructured":"Chivers, H., Clark, J.A., Nobles, P., Shaikh, S.A., Chen, H.: Knowing who to watch: identifying attackers whose actions are hidden within false alarms and background noise. Inf. Syst. Front. 15(1), 17\u201334 (2013)","journal-title":"Inf. Syst. Front."},{"key":"3_CR37","doi-asserted-by":"crossref","unstructured":"Sudit, M., Stotz, A., Holender, M.: Situational awareness of a coordinated cyber attack. In: Defense and Security, International Society for Optics and Photonics, pp. 114\u2013129 (2005)","DOI":"10.1117\/12.606980"},{"key":"3_CR38","doi-asserted-by":"crossref","unstructured":"Schreiber-Ehle, S., Koch, W.: The jdl model of data fusion applied x2014; a review paper. In: 2012 Workshop on Sensor Data Fusion: Trends, Solutions, Applications (SDF), pp. 116\u2013119, September 2012","DOI":"10.1109\/SDF.2012.6327919"},{"issue":"1","key":"3_CR39","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/JSTSP.2012.2237381","volume":"7","author":"R Paffenroth","year":"2013","unstructured":"Paffenroth, R., Du Toit, P., Nong, R., Scharf, L., Jayasumana, A.P., Bandara, V.: Space-time signal processing for distributed pattern detection in sensor networks. IEEE J. Sel. Top. Sig. Proces. 7(1), 38\u201349 (2013)","journal-title":"IEEE J. Sel. Top. Sig. Proces."},{"key":"3_CR40","doi-asserted-by":"crossref","unstructured":"Mathews, M.L., Halvorsen, P., Joshi, A., Finin, T.: A collaborative approach to situational awareness for cybersecurity. In: 2012 8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), pp. 216\u2013222. IEEE (2012)","DOI":"10.4108\/icst.collaboratecom.2012.250794"},{"key":"3_CR41","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1007\/978-1-4419-7133-3_5","volume-title":"Insider Threats in Cyber Security","author":"FL Greitzer","year":"2010","unstructured":"Greitzer, F.L., Frincke, D.A.: Combining traditional cyber security audit data with psychosocial data: towards predictive modeling for insider threat mitigation. In: Probst, C.W., et al. (eds.) Insider Threats in Cyber Security, pp. 85\u2013113. Springer, New York (2010)"},{"key":"3_CR42","unstructured":"Grothoff, K., Brunner, M., Hofinger, H., Roblee, C., Eckert, C.: Problems in web-based open source information processing for it early warning (2011)"},{"key":"3_CR43","doi-asserted-by":"crossref","unstructured":"Jonker, D., Langevin, S., Schretlen, P., Canfield, C.: Agile visual analytics for banking cyber x201c;big data x201d;. In: 2012 IEEE Conference on Visual Analytics Science and Technology (VAST), pp. 299\u2013300, October 2012","DOI":"10.1109\/VAST.2012.6400507"},{"key":"3_CR44","doi-asserted-by":"crossref","unstructured":"Harrison, L., Laska, J., Spahn, R., Iannacone, M., Downing, E., Ferragut, E.M., Goodall, J.R.: situ: Situational understanding and discovery for cyber attacks. In: 2012 IEEE Conference on Visual Analytics Science and Technology (VAST), pp. 307\u2013308, October 2012","DOI":"10.1109\/VAST.2012.6400503"},{"key":"3_CR45","doi-asserted-by":"crossref","unstructured":"Streilein, W.W., Truelove, J., Meiners, C.R., Eakman, G.: Cyber situational awareness through operational streaming analysis. In: Military Communications Conference, MILCOM 2011, pp. 1152\u20131157. IEEE (2011)","DOI":"10.1109\/MILCOM.2011.6127455"},{"key":"3_CR46","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Noel, S., Kalapa, P., Albanese, M., Williams, J.: Cauldron mission-centric cyber situational awareness with defense in depth. In: Military Communications Conference, MILCOM 2011, pp. 1339\u20131344. IEEE (2011)","DOI":"10.1109\/MILCOM.2011.6127490"},{"key":"3_CR47","unstructured":"Weber, D.: Transforming traditional security strategies into an early warning system for advanced threats, September 2012. http:\/\/www.emc.com\/collateral\/software\/solution-overview\/h11031-transforming-traditional-security-strategies-so.pdf"},{"key":"3_CR48","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/978-1-4419-0140-8_4","volume-title":"Cyber Situational Awareness","author":"J Li","year":"2010","unstructured":"Li, J., Ou, X., Rajagopalan, R.: Uncertainty and risk management in cyber situational awareness. In: Jajodia, S., et al. (eds.) Cyber Situational Awareness, pp. 51\u201368. Springer, New York (2010)"},{"key":"3_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/978-3-642-45204-8_12","volume-title":"Information Systems Security","author":"HK Kalutarage","year":"2013","unstructured":"Kalutarage, H.K., Shaikh, S.A., Zhou, Q., James, A.E.: Monitoring for slow suspicious activities using a target centric approach. In: Bagchi, A., Ray, I. (eds.) ICISS 2013. LNCS, vol. 8303, pp. 163\u2013168. Springer, Heidelberg (2013)"},{"key":"3_CR50","volume-title":"Low Rank Approximation: Algorithms, Implementation, Applications","author":"I Markovsky","year":"2011","unstructured":"Markovsky, I.: Low Rank Approximation: Algorithms, Implementation, Applications. Springer Science & Business Media, New York (2011)"},{"key":"3_CR51","unstructured":"Viswanath, B., Bashir, M.A., Crovella, M., Guha, S., Gummadi, K.P., Krishnamurthy, B., Mislove, A.: Towards detecting anomalous user behavior in online social networks. In: Proceedings of the 23rd USENIX Security Symposium (USENIX Security) (2014)"},{"key":"3_CR52","unstructured":"Kalutarage, H.K., Shaikh, S.A., Zhou, Q., James, A.E.: Sensing for suspicion at scale: a bayesian approach for cyber conflict attribution and reasoning. In: 2012 4th International Conference on Cyber Conflict (CYCON), pp. 1\u201319. IEEE (2012)"},{"key":"3_CR53","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/s11235-015-0071-0","volume":"62","author":"SA Shaikh","year":"2015","unstructured":"Shaikh, S.A., Kalutarage, H.K.: Effective network security monitoring: from attribution to target-centric monitoring. Telecommun. Syst. 62, 167\u2013178 (2015)","journal-title":"Telecommun. Syst."}],"container-title":["Lecture Notes in Computer Science","Open Problems in Network Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-39028-4_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,2]],"date-time":"2025-06-02T23:18:37Z","timestamp":1748906317000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-39028-4_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319390277","9783319390284"],"references-count":53,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-39028-4_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}