{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T19:35:31Z","timestamp":1782761731312,"version":"3.54.5"},"publisher-location":"Cham","reference-count":16,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319672076","type":"print"},{"value":"9783319672083","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-67208-3_5","type":"book-chapter","created":{"date-parts":[[2017,8,30]],"date-time":"2017-08-30T12:21:00Z","timestamp":1504095660000},"page":"81-94","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["Detecting Anomalous Programmable Logic Controller Events Using Machine Learning"],"prefix":"10.1007","author":[{"given":"Ken","family":"Yau","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kam-Pui","family":"Chow","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,8,31]]},"reference":[{"key":"5_CR1","unstructured":"Beresford, D.: Exploiting Siemens Simatic S7 PLCs. Presented at Black Hat USA (2011)"},{"key":"5_CR2","doi-asserted-by":"crossref","unstructured":"Bolton, W.: Programmable Logic Controllers, Newnes, Burlington, Massachusetts (2009)","DOI":"10.1016\/B978-1-85617-751-1.00001-X"},{"key":"5_CR3","unstructured":"Falliere, N., O\u2019Murchu, L., Chien, E.: W32.Stuxnet Dossier, Symantec, Mountain View, California (2011)"},{"key":"5_CR4","volume-title":"Forensic Analysis of Industrial Control Systems, InfoSec Reading Room","author":"L Folkerth","year":"2015","unstructured":"Folkerth, L.: Forensic Analysis of Industrial Control Systems, InfoSec Reading Room. SANS Institute, Bethesda (2015)"},{"key":"5_CR5","unstructured":"Hergenhahn, T.: libnodave (2014). sourceforge.net\/projects\/libnodave"},{"issue":"4","key":"5_CR6","doi-asserted-by":"publisher","first-page":"460","DOI":"10.3390\/fi5040460","volume":"5","author":"M Mantere","year":"2013","unstructured":"Mantere, M., Sailio, M., Noponen, S.: Network traffic features for anomaly detection in a specific industrial control system network. Future Internet 5(4), 460\u2013473 (2013)","journal-title":"Future Internet"},{"key":"5_CR7","unstructured":"MathWorks, Supervised Learning Workflow and Algorithms, Natick, Massachusetts (2017). www.mathworks.com\/help\/stats\/supervised-learning-machine-learning-workflow-and-algorithms.html?requestedDomain=www.mathworks.com"},{"key":"5_CR8","unstructured":"Mitchell, T.: Machine Learning. WCB\/McGraw-Hill, Boston, Massachusetts (1997)"},{"key":"5_CR9","unstructured":"Morris, T., Thornton, Z., Turnipseed, I.: Industrial control system simulation and data logging for intrusion detection system research. In: Proceedings of the Seventh Annual Southeastern Cyber Security Summit (2015)"},{"key":"5_CR10","unstructured":"Nardella, D.: Step 7 Open Source Ethernet Communication Suite, Bari, Italy (2016). snap.7.sourceforge.net"},{"key":"5_CR11","unstructured":"Patzlaff, H.: D 7.1 Preliminary Report on Forensic Analysis for Industrial Systems, CRISALIS Consortium, Symantec, Sophia Antipolis, France (2013)"},{"key":"5_CR12","unstructured":"Institute, S.A.S., Learning, M.: What it is and Why it Matters, Milan, Italy (2016). www.sas.com\/it_it\/insights\/analytics\/machine-learning.html"},{"key":"5_CR13","unstructured":"Sayad, S.: An Introduction to Data Mining, University of Toronto, Toronto, Canada (2011)"},{"key":"5_CR14","unstructured":"scikit-learn Project, An Introduction to Machine Learning with scikit-learn (2016). scikit-learn.org\/stable\/tutorial\/basic\/tutorial.html"},{"key":"5_CR15","unstructured":"scikit-learn Project, Supervised Learning (2016). scikit-learn.org\/stable\/supervised_learning.html"},{"key":"5_CR16","unstructured":"Siemens, SIMATIC S7\u2013300 Programmable Controller Quick Start, Primer, Preface, C79000\u2013G7076-C500-01, Nuremberg, Germany (1996)"}],"container-title":["IFIP Advances in Information and Communication Technology","Advances in Digital Forensics XIII"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-67208-3_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,31]],"date-time":"2021-08-31T00:06:02Z","timestamp":1630368362000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-67208-3_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319672076","9783319672083"],"references-count":16,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-67208-3_5","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"value":"1868-4238","type":"print"},{"value":"1868-422X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"31 August 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DigitalForensics","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Digital Forensics","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Orlando","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 January 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 February 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"digitalforensics2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ifip119.org\/Conferences\/ConferenceProgram2017.pdf","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}