{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T11:23:08Z","timestamp":1780053788536,"version":"3.54.0"},"publisher-location":"Berlin, Heidelberg","reference-count":35,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540222170","type":"print"},{"value":"9783540248521","type":"electronic"}],"license":[{"start":{"date-parts":[[2004,1,1]],"date-time":"2004-01-01T00:00:00Z","timestamp":1072915200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2004]]},"DOI":"10.1007\/978-3-540-24852-1_33","type":"book-chapter","created":{"date-parts":[[2010,9,10]],"date-time":"2010-09-10T18:37:21Z","timestamp":1284143841000},"page":"452-466","source":"Crossref","is-referenced-by-count":24,"title":["A Novel Framework for Alert Correlation and Understanding"],"prefix":"10.1007","author":[{"given":"Dong","family":"Yu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Deborah","family":"Frincke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"33_CR1","unstructured":"Armstrong, D., Carter, S., Frazier, G., Frazier, T.: A Controller-Based Autonomic Defense System. In: Proc. of DARPA Information Survivability Conference and Exposition (DISCEX) (2003)"},{"key":"33_CR2","doi-asserted-by":"crossref","unstructured":"Allen, J., Christie, A., Fithen, W., McHugh, J., Pickel, J., Stoner, E.: State of the Practice of Intrusion Detection Technologies. Technical Report CMU\/SEI-99-TR- 028 (1999)","DOI":"10.21236\/ADA375846"},{"key":"33_CR3","unstructured":"J.: P Anderson: Computer Security Threat Monitoring and Surveillance. Technical report, James P Anderson Co., Fort Washington, Pennsylvania (April 1980)"},{"key":"33_CR4","doi-asserted-by":"crossref","unstructured":"Axelsson, S.: The base-rate fallacy and its implications for the difficulty of intrusion detection. In: 6th ACM Conference on computer and communications security, November 1999, pp. 1\u20137 (1999)","DOI":"10.1145\/319709.319710"},{"key":"33_CR5","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4615-0953-0","volume-title":"Applications of Data Mining in Computer Security","author":"D. Barbara","year":"2002","unstructured":"Barbara, D., Jajodia, S.: Applications of Data Mining in Computer Security, June 2002. Kluwer Academic Pub., Dordrecht (2002)"},{"key":"33_CR6","unstructured":"de Boer, R.C.: A Generic Architecture for Fusion-Based Intrusion Detection Systems. Master Thesis, Erasmus University Rotterdam (October 2002)"},{"key":"33_CR7","unstructured":"Cuppens, F., Autrel, F., Mi\u00e8ge, A., Benferhat, S.: Correlation in an intrusion detection process. Internet Security CommunicationWorkshop (SECI 2002) (Septembre 2002)"},{"key":"33_CR8","unstructured":"Cuppens, F., Mi\u00e8ge, A.: Alert Correlation in a Cooperative Intrusion Detection Framework. In: IEEE Symposium on Security and Privacy (May 2002)"},{"key":"33_CR9","unstructured":"Cuppens, F.: Managing Alerts in a Multi-Intrusion Detection Environment. In: 17th Annual Computer Security Applications Conference, New-Orleans, USA (December 2001)"},{"key":"33_CR10","doi-asserted-by":"crossref","unstructured":"Debar, H., Wespi, A.: Aggregration and Correlation of Intrusion-Detection Alerts. In: Proceedings of the 4th International Symposium on Recent Advances in Intrusion detection (RAID) (2001)","DOI":"10.1007\/3-540-45474-8_6"},{"key":"33_CR11","unstructured":"Frincke, D., Tobin, D., Ho, Y.: Planning, Petri Nets, and Intrusion Detection. In: Proceedings of the 21st National Information Systems Security Conference (NISSC 1998)s (1998)"},{"key":"33_CR12","unstructured":"Geib, C., Goldman, R.: Plan Recognition in Intrusion Detection Systems. In: DARPA Information Survivability Conference and Exposition (DISCEX) (June 2001)"},{"key":"33_CR13","unstructured":"Goldman, R.P., Heimerdinger, W., Harp, S., Geib, C.W., Thomas, V., Carter, R.: Information Modeling for Intrusion Report Aggregation. In: Proceedings of the DARPA Information Survivability Conference and Exposition (DISCEX) (June 2001)"},{"issue":"1","key":"33_CR14","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1109\/MSECP.2003.1176995","volume":"1","author":"J. Haines","year":"2003","unstructured":"Haines, J., Ryder, D.K., Tinnel, L., Taylor, S.: Validation of Sensor Alert Correlators. IEEE Security and Privacy\u00a01(1), 46\u201356 (2003)","journal-title":"IEEE Security and Privacy"},{"key":"33_CR15","unstructured":"Huang, M.-Y., Wicks, T.M.: A Large-scale Distributed Intrusion Detection Framework Based on Attack Strategy Analysis. In: Web proceedings of the First International Workshop on Recent Advances in Intrusion Detection (RAID 1998) (1998)"},{"key":"33_CR16","doi-asserted-by":"crossref","unstructured":"Ilgun, K., Kemmerer, R., Porras, P.: State Transition Analysis: A Rule-Based Intrusion Detection System. IEEE Transactions on Software Engineering\u00a021(3) (March 1995)","DOI":"10.1109\/32.372146"},{"key":"33_CR17","doi-asserted-by":"crossref","unstructured":"Julisch, K., Dacier, M.: Mining intrusion detection alarms for actionable knowledge. In: Proceedings of the 8th ACM International Conference on Knowledge Discovery and Data Mining, July 2002, pp. 366\u2013375 (2002)","DOI":"10.1145\/775047.775101"},{"key":"33_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1007\/3-540-58043-3_21","volume-title":"A Decade of Concurrency","author":"K. Jensen","year":"1994","unstructured":"Jensen, K.: An Introduction to the Theoretical Aspects of Coloured Petri Nets. In: de Bakker, J.W., de Roever, W.-P., Rozenberg, G. (eds.) REX 1993. LNCS, vol.\u00a0803, pp. 230\u2013272. Springer, Heidelberg (1994)"},{"key":"33_CR19","volume-title":"Colored Petri-Nets\u2013Basic Concepts, Analysis Methods, and Practical Use","author":"K. Jensen","year":"1996","unstructured":"Jensen, K.: Colored Petri-Nets\u2013Basic Concepts, Analysis Methods, and Practical Use, 2nd edn., vol.\u00a01. Springer, Heidelberg (1996)","edition":"2"},{"key":"33_CR20","unstructured":"Julisch, K.: Mining Alarm Clusters to Improve Alarm Handling Efficiency. In: Proceedings of the 17th ACSAC, New Orleans (December 2001)"},{"key":"33_CR21","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/s100090050021","volume":"2","author":"L.M. Kristensen","year":"1998","unstructured":"Kristensen, L.M., Christensen, S., Jensen, K.: The practitioner\u2019s guide to coloured Petri nets. Int. Journal on Software Tools for Technology Transfer\u00a02, 98\u2013132 (1998)","journal-title":"Int. Journal on Software Tools for Technology Transfer"},{"key":"33_CR22","unstructured":"Kumar, S., Spafford, E.H.: A Pattern-Matching Model for Intrusion Detection. In: Proceedings of the National Computer Security Conference (1994)"},{"key":"33_CR23","unstructured":"Kumar, S., Spafford, E.: A Pattern Matching Model for Misuse Intrusion Detection. In: 17th National Computer Security Conference (1994)"},{"key":"33_CR24","unstructured":"Lincoln Lab, MIT. DARPA 2000 intrusion detection evaluation datasets (2000), \n                    \n                      http:\/\/ideval.ll.mit.edu\/2000index.html"},{"key":"33_CR25","doi-asserted-by":"crossref","unstructured":"Moon, T.: The Expectation-Maximization algorithm. IEEE Signal Processing Magazine, 47\u201360 (November 1996)","DOI":"10.1109\/79.543975"},{"key":"33_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1007\/3-540-36084-0_5","volume-title":"Recent Advances in Intrusion Detection","author":"P. Ning","year":"2002","unstructured":"Ning, P., Cui, Y., Reeves, D.S.: Analyzing Intensive Intrusion Alerts Via Correlation. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 74\u201394. Springer, Heidelberg (2002)"},{"key":"33_CR27","doi-asserted-by":"crossref","unstructured":"Ning, P., Cui, Y., Reeves, D.S.: Constructing Attack Scenarios through Correlation of Intrusion Alerts. In: Proceedings of the 9th ACM Conference on Computer & Communications Security, pp. 245\u2013254 (November 2002)","DOI":"10.1145\/586143.586144"},{"key":"33_CR28","unstructured":"Ning, P., Reeves, D.S., Cui, Y.: Correlating Alerts Using Prerequisites of Intrusions. Technical Report, TR-2001-13, North Carolina State University, Department of Computer Science (December 2001)"},{"key":"33_CR29","doi-asserted-by":"crossref","unstructured":"Porras, P.A., Fong, M.W., Valdes, A.: A Mission-Impact-Based Approach to INFOSEC Alarm Correlation. In: Proceedings Recent Advances in Intrusion Detection, October 2002, pp. 95\u2013114 (2002)","DOI":"10.1007\/3-540-36084-0_6"},{"key":"33_CR30","unstructured":"Porras, P.A., Neumann, P.G.: EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances. In: National Information Systems Security Conference (October 1997)"},{"key":"33_CR31","volume-title":"Smoothing Methods in Statistics","author":"J.S. Simonoff","year":"1998","unstructured":"Simonoff, J.S.: Smoothing Methods in Statistics. Springer, Heidelberg (1998)"},{"key":"33_CR32","doi-asserted-by":"crossref","unstructured":"Templeton, S.J., Levitt, K.: A requires\/provides model for computer attacks. In: Proceedings of the 2000 workshop on New security paradigms, pp. 31\u201338 (2001)","DOI":"10.1145\/366173.366187"},{"key":"33_CR33","doi-asserted-by":"crossref","unstructured":"Valdes, A., Skinner, K.: Probabilistic Alert Correlation. In: Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID) (2001)","DOI":"10.1007\/3-540-45474-8_4"},{"issue":"4","key":"33_CR34","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1109\/3468.935043","volume":"31","author":"N. Ye","year":"2001","unstructured":"Ye, N., Li, X., Chen, Q., Emran, S.M., Xu, M.: Probabilistic techniques for intrusion detection based on computer audit data. IEEE Transactions on Systems, Man, and Cybernetics\u00a031(4), 266\u2013274 (2001)","journal-title":"IEEE Transactions on Systems, Man, and Cybernetics"},{"key":"33_CR35","unstructured":"Ye, N., Giordano, J., Feldman, J., Zhong, Q.: Information Fusion Techniques for Network Intrusion Detection. In: IEEE InformationTechnology Conference, Information Environment for the Future (1998)"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-24852-1_33","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T18:03:00Z","timestamp":1558288980000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-24852-1_33"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2004]]},"ISBN":["9783540222170","9783540248521"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-24852-1_33","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2004]]}}}