{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T10:10:02Z","timestamp":1749636602184,"version":"3.41.0"},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319480206"},{"type":"electronic","value":"9783319480213"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-48021-3_2","type":"book-chapter","created":{"date-parts":[[2016,10,13]],"date-time":"2016-10-13T01:49:10Z","timestamp":1476323350000},"page":"12-25","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Statistical Network Anomaly Detection: An Experimental Study"],"prefix":"10.1007","author":[{"given":"Christian","family":"Callegari","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Giordano","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michele","family":"Pagano","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,10,14]]},"reference":[{"key":"2_CR1","series-title":"Computer Communications and Networks","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-1-84882-765-3_11","volume-title":"Algorithms for Next Generation Networks","author":"M Thottan","year":"2010","unstructured":"Thottan, M., Liu, G., Ji, C.: Anomaly detection approaches for communication networks. In: Cormode, G., Thottan, M., Sammes, A.J. (eds.) Algorithms for Next Generation Networks. Computer Communications and Networks, pp. 239\u2013261. Springer, London (2010)"},{"issue":"C","key":"2_CR2","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.jnca.2015.11.016","volume":"60","author":"M Ahmed","year":"2016","unstructured":"Ahmed, M., Naser Mahmood, A., Hu, J.: A survey of network anomaly detection techniques. J. Netw. Comput. Appl. 60(C), 19\u201331 (2016)","journal-title":"J. Netw. Comput. Appl."},{"key":"2_CR3","series-title":"Lecturer Notes in Computer Science","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1007\/978-3-642-36784-7_7","volume-title":"Data Traffic Monitoring and Analysis","author":"C Callegari","year":"2013","unstructured":"Callegari, C., Coluccia, A., D\u2019Alconzo, A., Ellens, W., Giordano, S., Mandjes, M., Pagano, M., Pepe, T., Ricciato, F., Zuraniewski, P.: A methodological overview on anomaly detection. In: Matijasevic, M., Callegari, C., Biersack, E. (eds.) Data Traffic Monitoring and Analysis. LNCS, vol. 7754, pp. 148\u2013183. Springer, Berlin (2013)"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"Subhabrata, B.K., Krishnamurthy, E., Sen, S., Zhang, Y., Chen, Y.: Sketch-based change detection: methods, evaluation, and applications. In. Internet Measurement Conference, pp. 234\u2013247(2003)","DOI":"10.1145\/948234.948236"},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Borgnat, P., Dewaele, G., Fukuda, K., Abry, P., Cho, K.: Seven years and one day: sketching the evolution of internet traffic. In: INFOCOM, April 2009","DOI":"10.1109\/INFCOM.2009.5061979"},{"issue":"1","key":"2_CR6","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1016\/j.jalgor.2003.12.001","volume":"55","author":"G Cormode","year":"2005","unstructured":"Cormode, G., Muthukrishnan, S.: An improved data stream summary: the count-min sketch and its applications. J. Algorithms 55(1), 58\u201375 (2005)","journal-title":"J. Algorithms"},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Lakhina, A., Crovella, M., Diot, C.: Mining anomalies using traffic feature. In: ACM SIGCOMM (2005)","DOI":"10.1145\/1080091.1080118"},{"key":"2_CR8","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1002\/nem.748","volume":"20","author":"O Salem","year":"2010","unstructured":"Salem, O., Vaton, S., Gravey, A.: A scalable, efficient and informative approach for anomaly-based intrusion detection systems: theory and practice. Int. J. Netw. Manag. 20, 271\u2013293 (2010)","journal-title":"Int. J. Netw. Manag."},{"key":"2_CR9","doi-asserted-by":"crossref","unstructured":"Callegari, C., Gazzarrini, L., Giordano, S., Pagano, M., Pepe, T.: When randomness improves the anomaly detection performance. In: Proceedings of 3rd International Symposium on Applied Sciences in Biomedical and Communication Technologies (ISABEL) (2010)","DOI":"10.1109\/ISABEL.2010.5702782"},{"key":"2_CR10","doi-asserted-by":"crossref","unstructured":"Schweller, R., Gupta, A., Parsons, E., Chen, Y.: Reversible sketches for efficient and accurate change detection over network data streams. In: Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement. IMC 2004, pp. 207\u2013212. ACM, New York (2004)","DOI":"10.1145\/1028788.1028814"},{"issue":"2","key":"2_CR11","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1109\/TNSM.2009.090604","volume":"6","author":"A Kind","year":"2009","unstructured":"Kind, A., Stoecklin, M.P., Dimitropoulos, X.: Histogram-based traffic anomaly detection. IEEE Trans. Netw. Serv. Manag. 6(2), 110\u2013121 (2009)","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"issue":"6","key":"2_CR12","doi-asserted-by":"publisher","first-page":"1788","DOI":"10.1109\/TNET.2012.2187306","volume":"20","author":"D Brauckhoff","year":"2012","unstructured":"Brauckhoff, D., Dimitropoulos, X., Wagner, A., Salamatian, K.: Anomaly extraction in backbone networks using association rules. IEEE\/ACM Trans. Netw. 20(6), 1788\u20131799 (2012)","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Wagner, A., Plattner, B.: Entropy based worm and anomaly detection in fast IP networks. In: 14th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprise (WETICE 2005), pp. 172\u2013177, June 2005","DOI":"10.1109\/WETICE.2005.35"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Callegari, C., Giordano, S., Pagano, M.: On the use of compression algorithms for network anomaly detection. In: 2009 IEEE International Conference on Communications, pp. 1\u20135, June 2009","DOI":"10.1109\/ICC.2009.5199270"},{"issue":"4","key":"2_CR15","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1145\/1030194.1015492","volume":"34","author":"Anukool Lakhina","year":"2004","unstructured":"Lakhina, A.: Diagnosing network-wide traffic anomalies. In. ACM SIGCOMM, pp. 219\u2013230 (2004)","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"2_CR16","volume-title":"The Mathematical Theory of Communication","author":"CE Shannon","year":"1949","unstructured":"Shannon, C.E., Weaver, W.: The Mathematical Theory of Communication. University of Illinois Press, Champaign (1949)"},{"key":"2_CR17","unstructured":"Kolmogorov, A., Fomin, S.: Elements of the Theory of Functions and Functional Analysis. Number v. 1 in Dover Books on Mathematics. Dover (1999)"},{"key":"2_CR18","unstructured":"Flow-Tools Home Page. http:\/\/www.ietf.org\/rfc\/rfc3954.txt"},{"key":"2_CR19","unstructured":"MAWI Working Group Traffic Archive. http:\/\/mawi.wide.ad.jp\/mawi\/. Accessed Nov 2011"},{"key":"2_CR20","unstructured":"MAWILab. http:\/\/www.fukuda-lab.org\/mawilab\/ Accessed Nov 2011"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Fontugne, R., Borgnat, P., Abry, P., Fukuda, K.: MAWILab: combining diverse anomaly detectors for automated anomaly labeling and performance benchmarking. In: ACM CoNEXT (2010)","DOI":"10.1145\/1921168.1921179"},{"key":"2_CR22","doi-asserted-by":"crossref","unstructured":"Callegari, C., Casella, A., Giordano, S., Pagano, M., Pepe, T.: Sketch-based multidimensional IDS: a new approach for network anomaly detection. In: IEEE Conference on Communications and Network Security, CNS 2013, National Harbor, MD, USA, 14\u201316 October 2013, pp. 350\u2013358 (2013)","DOI":"10.1109\/CNS.2013.6682725"}],"container-title":["Communications in Computer and Information Science","Future Network Systems and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-48021-3_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T09:34:58Z","timestamp":1749634498000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-48021-3_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319480206","9783319480213"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-48021-3_2","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"14 October 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FNSS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Future Network Systems and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Paris","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 November 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 November 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"fnss2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}