{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T06:42:29Z","timestamp":1725518549695},"publisher-location":"Berlin, Heidelberg","reference-count":50,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540859314"},{"type":"electronic","value":"9783540859338"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-85933-8_18","type":"book-chapter","created":{"date-parts":[[2008,9,14]],"date-time":"2008-09-14T05:44:51Z","timestamp":1221371091000},"page":"181-196","source":"Crossref","is-referenced-by-count":5,"title":["Network Traffic Exploration Application: A Tool to Assess, Visualize, and Analyze Network Security Events"],"prefix":"10.1007","author":[{"given":"Grant","family":"Vandenberghe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"3","key":"18_CR1","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1109\/TDSC.2004.21","volume":"1","author":"F. Valeur","year":"2004","unstructured":"Valeur, F., et al.: A Comprehensive Approach to intrusion Detection Alert Correlation. IEEE Transactions on Dependable and Secure Computing\u00a01(3), 146\u2013149 (2004)","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"18_CR2","unstructured":"Farshchi, J.: Statistical based approach to Intrusion Detection, SANS Institute(2003) (Access date 1 April 2008), http:\/\/www.sans.org\/resources\/idfaq\/statistic_ids.php"},{"key":"18_CR3","unstructured":"Roesch, M.P: SNORT (Access date 1 April 2008), http:\/\/www.snort.org\/"},{"key":"18_CR4","unstructured":"Ertoz, L., Eilerston, E. Lazarevic, A., Tan P. Srivastava, J. and Kumar, V.: Detection and Summarization of Novel Network Attacks Using Data Mining, Techincal Report (2003), http:\/\/www-users.cs.umn.edu\/~aleks\/MINDS\/papers\/raid03.pdf"},{"key":"18_CR5","unstructured":"Chakchai, S.: A Survey of Network Traffic Monitoring and Analysis Tools, (2006) (Access date 1 April 2008), http:\/\/www.cse.wustl.edu\/~cs5\/567\/traffic\/index.html"},{"key":"18_CR6","doi-asserted-by":"crossref","unstructured":"Ranum, M.: Packet Peekers, Information Security Magazine, p. 28 (2003)","DOI":"10.1016\/S1353-4858(03)01107-3"},{"key":"18_CR7","unstructured":"Keshav, T.: A Survey of Network Performance Monitoring Tools (2006)(Access date 1 April 2008), http:\/\/www.cs.wustl.edu\/~jain\/cse567-06\/ftp\/net_perf_monitors1.pdf"},{"key":"18_CR8","unstructured":"Fortunato, T.: The Technology Firm, web page (2007), http:\/\/www.thetechfirm.com\/reviews\/"},{"key":"18_CR9","unstructured":"Lyon, G.: Top 100 Security Tools, Insecure.org (2006), http:\/\/www.insecure.org\/tools.html"},{"key":"18_CR10","first-page":"105","volume-title":"The Tao of Network Security Monitoring: Beyond Intrusion Detection","author":"R. Bejtlich","year":"2005","unstructured":"Bejtlich, R.: The Tao of Network Security Monitoring: Beyond Intrusion Detection, pp. 105\u2013344. Addison-Wesley, Boston (2005)"},{"key":"18_CR11","unstructured":"Vissher, R.: SGUIL (2007) (Access date 2 April 2008) , http:\/\/sguil.sourceforge.net\/"},{"key":"18_CR12","unstructured":"Combs, G., et al.: wireshark (2008) (Access date 2 April 2008), http:\/\/www.wireshark.org\/"},{"key":"18_CR13","unstructured":"Zalewski, M.: P0f (2006) (Access date 2 April 2008), http:\/\/lcamtuf.coredump.cx\/p0f.shtml"},{"key":"18_CR14","unstructured":"Elson, J.: tcpflow (2003) (Access date 2 April 2008), http:\/\/www.circlemud.org\/~jelson\/software\/tcpflow"},{"key":"18_CR15","unstructured":"Jacobson, V., et al.: Libpcap (2007) (Access date 2 April 2008), http:\/\/www.tcpdump.org\/"},{"key":"18_CR16","unstructured":"Jacobson, V., Leres, C., and McCanne, S.: tcpdump (2007) (Access date 2 April 2008), http:\/\/www.tcpdump.org\/"},{"key":"18_CR17","unstructured":"OPNET ACE Application Characterization Environment (2007) (Access date 2 April 2008), http:\/\/www.opnet.com\/solutions\/brochures\/Ace.pdf"},{"key":"18_CR18","unstructured":"Paxon, V.: BRO (2007) (Access date 2 April 2008), http:\/\/bro-ids.org\/"},{"key":"18_CR19","unstructured":"Computer Associates, eHealth (2008) (Access date 2 April 2008), http:\/\/www.ca.com\/us\/products\/product.aspx?ID=5637"},{"key":"18_CR20","unstructured":"Kohler, E.: ipsumdump (2006) (Access date 2 April 2008), http:\/\/www.cs.ucla.edu\/~kohler\/ipsumdump\/"},{"key":"18_CR21","unstructured":"Ritter, J.: ngrep (2006) (Access date 2 April 2008), http:\/\/ngrep.sourceforge.net\/"},{"key":"18_CR22","unstructured":"Combs, G., et al.: editcap\/ mergecap (2008) (Access date 2 April 2008), http:\/\/www.wireshark.org\/"},{"key":"18_CR23","unstructured":"Astashonok, S.: Fprobe (2005) (Access date 2 April 2008), http:\/\/sourceforge.net\/projects\/fprobe"},{"key":"18_CR24","unstructured":"Ostermann, S.: tcptrace (2003) (Access date 2 April 2008), http:\/\/www.tcptrace.org\/"},{"key":"18_CR25","unstructured":"Deri, L.: ntop (2008) (Access date 2 April 2008), http:\/\/www.ntop.org\/"},{"key":"18_CR26","doi-asserted-by":"crossref","unstructured":"Postel, J.: RFC 792 - Internet Control Message Protocol, (1981) (Access date 2 April 2008), http:\/\/www.faqs.org\/rfcs\/rfc792.html","DOI":"10.17487\/rfc0792"},{"key":"18_CR27","unstructured":"Kreibich, C.: netdude (2007) (Access date 2 April 2008), http:\/\/netdude.sourceforge.net\/"},{"key":"18_CR28","unstructured":"Fullmer, M.: flow-tools (2005) (Access date 2 April 2008), http:\/\/www.splintered.net\/sw\/flow-tools\/docs\/flow-tools.html"},{"key":"18_CR29","unstructured":"Walkin, L.: ipcad (2007) (Access date 2 April 2008), http:\/\/sourceforge.net\/projects\/ipcad\/"},{"key":"18_CR30","unstructured":"Curry, J.: SANCP (2003) (Access date 2 April 2008), http:\/\/www.metre.net\/sancp.html"},{"key":"18_CR31","unstructured":"Kernen, T.: Traceroute (2008) (Access date 2 April 2008), http:\/\/www.traceroute.org\/"},{"key":"18_CR32","unstructured":"Fenner, B.: tcpslice (2002) (Access date 2 April 2008), http:\/\/sourceforge.net\/projects\/tcpslice\/"},{"key":"18_CR33","unstructured":"Buyllard, C.: Argus, (2008) (Access date 2 April 2008), http:\/\/www.qosient.com\/argus"},{"key":"18_CR34","unstructured":"Cho, K., Dittrich, D.: tcpdstat (2000), http:\/\/staff.washington.edu\/dittrich\/talks\/core02\/tools\/tools.html"},{"key":"18_CR35","unstructured":"Naval Research Laboratory, \u201cHandbook for the Computer Security Certification of Trusted Systems\u201d, Technical Memorandum 5540, 062A (1996)"},{"key":"18_CR36","unstructured":"Temmingh, R.: Setiri: Advances in Trojan Technology (2002) (Access date 2 April 2008), http:\/\/www.blackhat.com\/presentations\/bh-asia-02\/Sensepost\/bh-asia-02-sensepost.pdf"},{"key":"18_CR37","unstructured":"Smith, J.: Covert Shells (2000) (Access date 2 April 2008), http:\/\/www.s0ftpj.org\/docs\/covert_shells.htm"},{"key":"18_CR38","unstructured":"Kieltyka, P.: ICMP Shell (2002) (Access date 3 April 2008), http:\/\/sourceforge.net\/projects\/icmpshell"},{"key":"18_CR39","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1145\/1030083.1030100","volume-title":"Proceedings of the 11th ACM conference on Computer and communications security","author":"K. Borders","year":"2004","unstructured":"Borders, K.: Web Tap: Detecting Covert Web Traffic. In: Proceedings of the 11th ACM conference on Computer and communications security, pp. 110\u2013120. ACM, Washington (2004)"},{"key":"18_CR40","unstructured":"Northcutt, S., Novak, J.: Network Intrusion Detection, An Analyst\u2019s Handbook, New Riders, Indianapolis, Indiana, pp. 63\u201365 (2000)"},{"key":"18_CR41","unstructured":"Northcutt, S., Cooper, M., Fearnow, M., Fredrick, K.: Intrusion Signatures and Analysis, New Riders, Indianapolis, Indiana, p. 137 (2001)"},{"key":"18_CR42","unstructured":"Knight, G., et al.: Detecting covert tunnels within the hypertext transfer protocol (2003), http:\/\/www.rmc.ca\/academic\/gradrech\/abstracts\/2003\/ece2003-2_e.html"},{"key":"18_CR43","unstructured":"Castro, S.: Covert Channel and Tunneling over the HTTP protocol Detection: GW implementation theoretical design (2003), http:\/\/www.infosecwriters.com\/hhworld\/cctde.html"},{"key":"18_CR44","unstructured":"Dyatlov, A.: Exploitation of data streams authorized by a network access control system for arbitrary data transfers: tunneling and covert channels over HTTP protocol (2003) (Access date 2 April 2008), http:\/\/www.net-security.org\/dl\/articles\/covertpaper.txt"},{"key":"18_CR45","unstructured":"Feamster, N., Balazinska, M., Harfst, G., Balakrishnan, H., Karger, D.: Infranet: Circumventing Web Censorship and Surveillance. In: 11th USENIX Security Symposium, San Francisco, CA (2002)"},{"key":"18_CR46","doi-asserted-by":"crossref","unstructured":"Crotti, M., Dusi, M., Gringoli, F., Salgarelli, L.: Detecting HTTP Tunnels with Statistical Mechanisms. In: ICC 2007. IEEE International Conference on Communications, pp. 6162\u20136168 (2007)","DOI":"10.1109\/ICC.2007.1020"},{"key":"18_CR47","unstructured":"Castro, S.: Cctde - Covert Channel and Tunneling Over the HTTP Protocol Detection (2003) (Access date 2 April 2008), http:\/\/gray-world.net\/projects\/papers\/html\/cctde.html"},{"key":"18_CR48","unstructured":"Vecna. PacketStorm - 007Shell.tgz (1999) (Access date 2 April 2008), http:\/\/packetstormsecurity.org\/groups\/s0ftpj\/"},{"key":"18_CR49","doi-asserted-by":"crossref","unstructured":"Rowland, C.: Covert Channels in the TCP\/IP Protocol Suite (1996) (Access date 2 April 2008), http:\/\/www.firstmonday.dk\/issues\/issue2_5\/rowland\/","DOI":"10.5210\/fm.v2i5.528"},{"key":"18_CR50","unstructured":"Hauser, V.: Reverse-WWW-Tunnel-Backdoor v1.6 (1998) (Access date 2 April 2008), http:\/\/packetstormsecurity.org\/groups\/thc\/rwwwshell-1.6.perl"}],"container-title":["Lecture Notes in Computer Science","Visualization for Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-85933-8_18.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,24]],"date-time":"2020-11-24T02:36:27Z","timestamp":1606185387000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-85933-8_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540859314","9783540859338"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-85933-8_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[]}}