{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:47:38Z","timestamp":1783788458678,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":31,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642043413","type":"print"},{"value":"9783642043420","type":"electronic"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-04342-0_2","type":"book-chapter","created":{"date-parts":[[2009,9,28]],"date-time":"2009-09-28T19:00:22Z","timestamp":1254164422000},"page":"21-40","source":"Crossref","is-referenced-by-count":33,"title":["Protecting a Moving Target: Addressing Web Application Concept Drift"],"prefix":"10.1007","author":[{"given":"Federico","family":"Maggi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"2_CR1","unstructured":"Turner, D., Fossi, M., Johnson, E., Mark, T., Blackbird, J., Entwise, S., Low, M.K., McKinney, D., Wueest, C.: Symantec Global Internet Security Threat Report \u2013 Trends for July-December 2007. Technical Report XII, Symantec Corporation (April 2008)"},{"key":"2_CR2","unstructured":"Shezaf, O., Grossman, J., Auger, R.: Web Hacking Incidents Database (March 2009), http:\/\/whid.xiom.org"},{"key":"2_CR3","unstructured":"Open Security Foundation: DLDOS: Data Loss Database \u2013 Open Source (March 2009), http:\/\/datalossdb.org\/"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"Cho, S., Cha, S.: SAD: web session anomaly detection based on parameter estimation. In: Computers & Security, vol.\u00a023, pp. 312\u2013319 (2004)","DOI":"10.1016\/j.cose.2004.01.006"},{"issue":"5","key":"2_CR5","doi-asserted-by":"publisher","first-page":"717","DOI":"10.1016\/j.comnet.2005.01.009","volume":"48","author":"C. Kruegel","year":"2005","unstructured":"Kruegel, C., Robertson, W., Vigna, G.: A Multi-model Approach to the Detection of Web-based Attacks. Journal of Computer Networks\u00a048(5), 717\u2013738 (2005)","journal-title":"Journal of Computer Networks"},{"key":"2_CR6","unstructured":"Robertson, W., Vigna, G., Kruegel, C., Kemmerer, R.A.: Using Generalization and Characterization Techniques in the Anomaly-based Detection of Web Attacks. In: Proceedings of the Network and Distributed System Security Symposium (NDSS 2006), San Diego, CA, USA (February 2006)"},{"key":"2_CR7","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1109\/ICCIT.2008.151","volume-title":"Proceedings of the 3rd International Conference on Convergence and Hybrid Information Technology (ICCIT 2008)","author":"L. Guangmin","year":"2008","unstructured":"Guangmin, L.: Modeling Unknown Web Attacks in Network Anomaly Detection. In: Proceedings of the 3rd International Conference on Convergence and Hybrid Information Technology (ICCIT 2008), Washington, DC, USA, pp. 112\u2013116. IEEE Computer Society, Los Alamitos (2008)"},{"key":"2_CR8","unstructured":"Zanero, S., Criscione, C.: Masibty: A Web Application Firewall based on Anomaly Detection. In: DeepSec - In-depth security conference (November 2008)"},{"key":"2_CR9","unstructured":"Citrix Systems, Inc.: Citrix Application Firewall (January 2009), http:\/\/www.citrix.com\/English\/PS2\/products\/product.asp?contentID=25636"},{"key":"2_CR10","unstructured":"F5 Networks, Inc.: BIG-IP Application Security Manager (January 2009), http:\/\/www.f5.com\/products\/big-ip\/product-modules\/application-security-manager.html"},{"key":"2_CR11","unstructured":"Breach Security, Inc.: Breach WebDefend (January 2009), http:\/\/www.breach.com\/products\/webdefend.html"},{"key":"2_CR12","first-page":"1","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS 1999)","author":"S. Axelsson","year":"1999","unstructured":"Axelsson, S.: The Base-Rate Fallacy and its Implications for the Difficulty of Intrusion Detection. In: Proceedings of the ACM Conference on Computer and Communications Security (CCS 1999), pp. 1\u20137. ACM, New York (1999)"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Frias-Martinez, V., Stolfo, S.J., Keromytis, A.D.: Behavior-Profile Clustering for False Alert Reduction in Anomaly Detection Sensors. In: Proceedings of the Annual Computer Security Applications Conference (ACSAC 2008), Anaheim, CA, USA (December 2008)","DOI":"10.1109\/ACSAC.2008.30"},{"key":"2_CR14","unstructured":"Escalante, H.J., Fuentes, O.: Kernel Methods for Anomaly Detection and Noise Elimination. In: Proceedings of the International Conference on Computing (CORE 2006), Mexico City, Mexico, pp. 69\u201380 (2006)"},{"key":"2_CR15","doi-asserted-by":"publisher","first-page":"517","DOI":"10.1109\/PCCC.2008.4745080","volume-title":"Proceedings of the Performance, Computing and Communications Conference (IPCCC 2008)","author":"S.i. Kim","year":"2008","unstructured":"Kim, S.i., Nwanze, N.: Noise-Resistant Payload Anomaly Detection for Network Intrusion Detection Systems. In: Proceedings of the Performance, Computing and Communications Conference (IPCCC 2008), Austin, TX, USA, pp. 517\u2013523. IEEE Computer Society, Los Alamitos (2008)"},{"key":"2_CR16","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/SP.2008.11","volume-title":"Proceedings of the 2008 IEEE Symposium on Security and Privacy (S&P 2008)","author":"G.F. Cretu","year":"2008","unstructured":"Cretu, G.F., Stavrou, A., Locasto, M.E., Stolfo, S.J., Keromytis, A.D.: Casting out Demons: Sanitizing Training Data for Anomaly Sensors. In: Proceedings of the 2008 IEEE Symposium on Security and Privacy (S&P 2008), Oakland, CA, USA, pp. 81\u201395. IEEE Computer Society, Los Alamitos (2008)"},{"key":"2_CR17","unstructured":"Song, Y., Stolfo, S., Keromytis, A.: Spectrogram: A Mixture-of-Markov-Chains Model for Anomaly Detection in Web Traffic. In: Proc. of the 16th Annual Network and Distributed System Security Symposium, NDSS (2009)"},{"key":"2_CR18","doi-asserted-by":"crossref","unstructured":"Schlimmer, J., Granger, R.: Beyond incremental processing: Tracking concept drift. In: Proceedings of the Fifth National Conference on Artificial Intelligence, vol.\u00a01, pp. 502\u2013507 (1986)","DOI":"10.1007\/BF00116895"},{"key":"2_CR19","first-page":"2755","volume":"8","author":"J. Kolter","year":"2007","unstructured":"Kolter, J., Maloof, M.: Dynamic weighted majority: An ensemble method for drifting concepts. The Journal of Machine Learning Research\u00a08, 2755\u20132790 (2007)","journal-title":"The Journal of Machine Learning Research"},{"key":"2_CR20","unstructured":"Hansen, R.: (RSnake): XSS (Cross Site Scripting) Cheat Sheet (June 2009), http:\/\/ha.ckers.org\/xss.html"},{"key":"2_CR21","unstructured":"Mavituna, F.: SQL Injection Cheat Sheet (June 2009), http:\/\/ferruh.mavituna.com\/sql-injection-cheatsheet-oku\/"},{"issue":"2","key":"2_CR22","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1109\/TSE.1987.232894","volume":"13","author":"D.E. Denning","year":"1987","unstructured":"Denning, D.E.: An Intrusion-Detection Model. IEEE Transactions on Software Engineering\u00a013(2), 222\u2013232 (1987)","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"4","key":"2_CR23","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1145\/382912.382914","volume":"3","author":"W. Lee","year":"2000","unstructured":"Lee, W., Stolfo, S.J.: A Framework for Constructing Features and Models for Intrusion Detection Systems. ACM Transactions on Information and System Security\u00a03(4), 227\u2013261 (2000)","journal-title":"ACM Transactions on Information and System Security"},{"issue":"1","key":"2_CR24","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1145\/1127345.1127348","volume":"9","author":"D. Mutz","year":"2006","unstructured":"Mutz, D., Valeur, F., Vigna, G., Kruegel, C.: Anomaly system call detection. ACM Transactions on Information and System Security\u00a09(1), 61\u201393 (2006)","journal-title":"ACM Transactions on Information and System Security"},{"key":"2_CR25","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1109\/SECPRI.1996.502675","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P 1996)","author":"S. Forrest","year":"1996","unstructured":"Forrest, S., Hofmeyr, S.A., Somayaji, A., Longstaff, T.A.: A Sense of Self for Unix Processes. In: Proceedings of the IEEE Symposium on Security and Privacy (S&P 1996), Oakland, CA, USA, pp. 120\u2013128. IEEE Computer Society, Los Alamitos (1996)"},{"key":"2_CR26","first-page":"156","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P 2001)","author":"D. Wagner","year":"2001","unstructured":"Wagner, D., Dean, D.: Intrusion Detection via Static Analysis. In: Proceedings of the IEEE Symposium on Security and Privacy (S&P 2001), Oakland, CA, USA, pp. 156\u2013168. IEEE Computer Society, Los Alamitos (2001)"},{"key":"2_CR27","unstructured":"Maggi, F., Matteucci, M., Zanero, S.: Detecting intrusions through system call sequence and argument analysis. IEEE Transactions on Dependable and Secure Computing\u00a099(1) (5555)"},{"key":"2_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2004","unstructured":"Wang, K., Stolfo, S.J.: Anomalous Payload-based Network Intrusion Detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 203\u2013222. Springer, Heidelberg (2004)"},{"key":"2_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1007\/11856214_12","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2006","unstructured":"Wang, K., Parekh, J.J., Stolfo, S.J.: Anagram: A Content Anomaly Detector Resistant to Mimicry Attack. In: Zamboni, D., Kr\u00fcgel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 226\u2013248. Springer, Heidelberg (2006)"},{"key":"2_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1007\/11553595_10","volume-title":"Image Analysis and Processing \u2013 ICIAP 2005","author":"S. Zanero","year":"2005","unstructured":"Zanero, S.: Analyzing TCP traffic patterns using self organizing maps. In: Roli, F., Vitulano, S. (eds.) ICIAP 2005. LNCS, vol.\u00a03617, pp. 83\u201390. Springer, Heidelberg (2005)"},{"key":"2_CR31","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Mutz, D., Robertson, W., Valeur, F.: Bayesian Event Classification for Intrusion Detection. In: Proceedings of the Annual Computer Security Applications Conference (ACSAC 2003), Las Vegas, NV, USA. IEEE Computer Society, Los Alamitos (2003)","DOI":"10.1109\/CSAC.2003.1254306"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-04342-0_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,22]],"date-time":"2019-05-22T18:11:59Z","timestamp":1558548719000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-04342-0_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642043413","9783642043420"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-04342-0_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009]]}}}