{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T17:15:53Z","timestamp":1778001353767,"version":"3.51.4"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319474120","type":"print"},{"value":"9783319474137","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-47413-7_24","type":"book-chapter","created":{"date-parts":[[2016,10,4]],"date-time":"2016-10-04T20:20:15Z","timestamp":1475612415000},"page":"415-434","source":"Crossref","is-referenced-by-count":25,"title":["Optimal Thresholds for Anomaly-Based Intrusion Detection in Dynamical Environments"],"prefix":"10.1007","author":[{"given":"Amin","family":"Ghafouri","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Waseem","family":"Abbas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aron","family":"Laszka","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yevgeniy","family":"Vorobeychik","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xenofon","family":"Koutsoukos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,10,5]]},"reference":[{"key":"24_CR1","unstructured":"Abrams, M., Weiss, J.: Malicious control system cyber security attack case study - Maroochy Water Services, Australia, July 2008. http:\/\/csrc.nist.gov\/groups\/SMA\/fisma\/ics\/documents\/Maroochy-Water-Services-Case-Study_report.pdf"},{"key":"24_CR2","doi-asserted-by":"crossref","unstructured":"Alippi, C., Roveri, M.: An adaptive CUSUM-based test for signal change detection. In: Proceedings of the 2006 IEEE International Symposium on Circuits and Systems (ISCAS), pp. 5752\u20135755. IEEE (2006)","DOI":"10.1109\/ISCAS.2006.1693942"},{"key":"24_CR3","doi-asserted-by":"crossref","unstructured":"Alpcan, T., Basar, T.: A game theoretic approach to decision and analysis in network intrusion detection. In: Proceedings of the 42nd IEEE Conference on Decision and Control (CDC), vol. 3, pp. 2595\u20132600. IEEE (2003)","DOI":"10.1109\/CDC.2003.1273013"},{"key":"24_CR4","doi-asserted-by":"crossref","unstructured":"Alpcan, T., Ba\u015far, T.: A game theoretic analysis of intrusion detection in access control systems. In: Proceedings of the 43rd IEEE Conference on Decision and Control (CDC), vol. 2, pp. 1568\u20131573. IEEE (2004)","DOI":"10.1109\/CDC.2004.1430267"},{"issue":"1","key":"24_CR5","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/MNET.2013.6423187","volume":"27","author":"S Amin","year":"2013","unstructured":"Amin, S., Schwartz, G.A., Hussain, A.: In quest of benchmarking security risks to cyber-physical systems. IEEE Netw. 27(1), 19\u201324 (2013)","journal-title":"IEEE Netw."},{"key":"24_CR6","volume-title":"Detection of Abrupt Changes: Theory and Application","author":"M Basseville","year":"1993","unstructured":"Basseville, M., Nikiforov, I.V., et al.: Detection of Abrupt Changes: Theory and Application, vol. 104. Prentice Hall, Englewood Cliffs (1993)"},{"key":"24_CR7","doi-asserted-by":"crossref","unstructured":"C\u00e1rdenas, A.A., Amin, S., Lin, Z.-S., Huang, Y.-L., Huang, C.-Y., Sastry, S.: Attacks against process control systems: risk assessment, detection, and response. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security (ASIACCS), pp. 355\u2013366. ACM (2011)","DOI":"10.1145\/1966913.1966959"},{"key":"24_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-3-319-04483-5_4","volume-title":"Distributed Computing and Internet Technology","author":"W Casey","year":"2014","unstructured":"Casey, W., Morales, J.A., Nguyen, T., Spring, J., Weaver, R., Wright, E., Metcalf, L., Mishra, B.: Cyber security via signaling games: toward a science of cyber security. In: Natarajan, R. (ed.) ICDCIT 2014. LNCS, vol. 8337, pp. 34\u201342. Springer, Heidelberg (2014). doi: 10.1007\/978-3-319-04483-5_4"},{"issue":"6","key":"24_CR9","doi-asserted-by":"crossref","first-page":"1546","DOI":"10.3390\/w6061546","volume":"6","author":"B Durin","year":"2014","unstructured":"Durin, B., Margeta, J.: Analysis of the possible use of solar photovoltaic energy in urban water supply systems. Water 6(6), 1546\u20131561 (2014)","journal-title":"Water"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"Estiri, M., Khademzadeh, A.: A theoretical signaling game model for intrusion detection in wireless sensor networks. In: Proceedings of the 14th International Telecommunications Network Strategy and Planning Symposium (NETWORKS), pp. 1\u20136. IEEE (2010)","DOI":"10.1109\/NETWKS.2010.5624961"},{"issue":"6","key":"24_CR11","doi-asserted-by":"crossref","first-page":"2230","DOI":"10.1109\/18.720538","volume":"44","author":"T Kailath","year":"1998","unstructured":"Kailath, T., Poor, H.V.: Detection of stochastic processes. IEEE Trans. Inf. Theor. 44(6), 2230\u20132231 (1998)","journal-title":"IEEE Trans. Inf. Theor."},{"key":"24_CR12","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1613\/jair.3269","volume":"41","author":"D Korzhyk","year":"2011","unstructured":"Korzhyk, D., Yin, Z., Kiekintveld, C., Conitzer, V., Tambe, M.: Stackelberg vs. Nash in security games: an extended investigation of interchangeability, equivalence, and uniqueness. J. Artif. Intell. Res. 41, 297\u2013327 (2011)","journal-title":"J. Artif. Intell. Res."},{"issue":"3","key":"24_CR13","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1109\/MSPEC.2013.6471059","volume":"50","author":"D Kushner","year":"2013","unstructured":"Kushner, D.: The real story of stuxnet. IEEE Spectr. 50(3), 48\u201353 (2013)","journal-title":"IEEE Spectr."},{"key":"24_CR14","doi-asserted-by":"crossref","unstructured":"Laszka, A., Abbas, W., Sastry, S.S., Vorobeychik, Y., Koutsoukos, X.: Optimal thresholds for intrusion detection systems. In: Proceedings of the 3rd Annual Symposium and Bootcamp on the Science of Security (HotSoS), pp. 72\u201381 (2016)","DOI":"10.1145\/2898375.2898399"},{"key":"24_CR15","doi-asserted-by":"crossref","unstructured":"Laszka, A., Horvath, G., Felegyhazi, M., Buttyan, L., FlipThem: modeling targeted attacks with FlipIt for multiple resources. In: Proceedings of the 5th Conference on Decision and Game Theory for Security (GameSec), pp. 175\u2013194, November 2014","DOI":"10.1007\/978-3-319-12601-2_10"},{"key":"24_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/978-3-642-45046-4_26","volume-title":"Web and Internet Economics","author":"A Laszka","year":"2013","unstructured":"Laszka, A., Johnson, B., Grossklags, J.: Mitigating covert compromises. In: Chen, Y., Immorlica, N. (eds.) WINE 2013. LNCS, vol. 8289, pp. 319\u2013332. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-45046-4_26"},{"key":"24_CR17","unstructured":"Lee, R.M., Assante, M.J., Conway, T.: German steel mill cyber attack. Technical report, SANS Industrial Control Systems (2014)"},{"issue":"11","key":"24_CR18","doi-asserted-by":"crossref","first-page":"2715","DOI":"10.1109\/TAC.2013.2266831","volume":"58","author":"F Pasqualetti","year":"2013","unstructured":"Pasqualetti, F., Dorfler, F., Bullo, F.: Attack detection and identification in cyber-physical systems. IEEE Trans. Autom. Control 58(11), 2715\u20132729 (2013)","journal-title":"IEEE Trans. Autom. Control"},{"key":"24_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1007\/978-3-319-25594-1_16","volume-title":"Decision and Game Theory for Security","author":"J Pawlick","year":"2015","unstructured":"Pawlick, J., Farhang, S., Zhu, Q.: Flip the cloud: cyber-physical signaling games in the presence of advanced persistent threats. In: Khouzani, M.H.R., Panaousis, E., Theodorakopoulos, G. (eds.) GameSec 2015. LNCS, vol. 9406, pp. 289\u2013308. Springer, Heidelberg (2015). doi: 10.1007\/978-3-319-25594-1_16"},{"issue":"6","key":"24_CR20","doi-asserted-by":"crossref","first-page":"2404","DOI":"10.1016\/j.camwa.2011.07.027","volume":"62","author":"S Shen","year":"2011","unstructured":"Shen, S., Li, Y., Xu, H., Cao, Q.: Signaling game based strategy of intrusion detection in wireless sensor networks. Comput. Math. Appl. 62(6), 2404\u20132416 (2011)","journal-title":"Comput. Math. Appl."},{"key":"24_CR21","first-page":"795","volume":"2","author":"A Shiryaev","year":"1961","unstructured":"Shiryaev, A.: The problem of the most rapid detection of a disturbance in a stationary process. Soviet Math. Dokl 2, 795\u2013799 (1961)","journal-title":"Soviet Math. Dokl"},{"key":"24_CR22","doi-asserted-by":"crossref","first-page":"645","DOI":"10.1214\/aos\/1176349142","volume":"21","author":"M Srivastava","year":"1993","unstructured":"Srivastava, M., Wu, Y.: Comparison of EWMA, CUSUM and Shiryayev-Roberts procedures for detecting a shift in the mean. Ann. Stat. 21, 645\u2013670 (1993)","journal-title":"Ann. Stat."},{"key":"24_CR23","unstructured":"Tantawy, A.M.: Model-based detection in cyber-physical systems. Ph.D. thesis, Vanderbilt University (2011)"},{"issue":"4","key":"24_CR24","doi-asserted-by":"crossref","first-page":"655","DOI":"10.1007\/s00145-012-9134-5","volume":"26","author":"M Dijk Van","year":"2013","unstructured":"Van Dijk, M., Juels, A., Oprea, A., Rivest, R.L.: FlipIt: the game of stealthy takeover. J. Cryptol. 26(4), 655\u2013713 (2013)","journal-title":"J. Cryptol."},{"issue":"9","key":"24_CR25","doi-asserted-by":"crossref","first-page":"4161","DOI":"10.1016\/j.csda.2008.01.026","volume":"52","author":"G Verdier","year":"2008","unstructured":"Verdier, G., Hilgert, N., Vila, J.-P.: Adaptive threshold computation for cusum-type procedures in change detection and isolation problems. Comput. Stat. Data Anal. 52(9), 4161\u20134174 (2008)","journal-title":"Comput. Stat. Data Anal."}],"container-title":["Lecture Notes in Computer Science","Decision and Game Theory for Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-47413-7_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,14]],"date-time":"2019-09-14T07:56:56Z","timestamp":1568447816000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-47413-7_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319474120","9783319474137"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-47413-7_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}