{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T18:24:00Z","timestamp":1725560640803},"publisher-location":"Berlin, Heidelberg","reference-count":21,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642144776"},{"type":"electronic","value":"9783642144783"}],"license":[{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-14478-3_20","type":"book-chapter","created":{"date-parts":[[2010,7,23]],"date-time":"2010-07-23T12:56:16Z","timestamp":1279889776000},"page":"191-200","source":"Crossref","is-referenced-by-count":0,"title":["A Flow Based Slow and Fast Scan Detection System"],"prefix":"10.1007","author":[{"given":"N.","family":"Muraleedharan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arun","family":"Parmar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"20_CR1","unstructured":"Firewall\/IDS Evasion and Spoofing, Nmap Reference Guide, \n                    \n                      http:\/\/nmap.org\/book\/man-bypass-firewalls-ids.html"},{"key":"20_CR2","unstructured":"RFC 5101, Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information"},{"key":"20_CR3","volume-title":"IMC 2007 Proceedings of the 7th ACM SIGCOMM Conference on Internet Measurement","author":"M. Allman","year":"2007","unstructured":"Allman, M., Paxson, V., Terrel, J.: A Brief History of Scanning. In: IMC 2007 Proceedings of the 7th ACM SIGCOMM Conference on Internet Measurement. ACM, New York (2007)"},{"key":"20_CR4","unstructured":"Jung, J., Paxson, V., Berger, A.W., Balakrishnan, H.: Fast Port scan detection using sequential hypothesis testing. In: Proceedings of the IEEE Symposium on Seurity Privacy (May 2004)"},{"key":"20_CR5","doi-asserted-by":"crossref","unstructured":"Staniford, S., Hoagland, J.A., McAlerney, J.M.: Practical automated detection of stealthy portscans. Journel of Computer Security\u00a010 (2002)","DOI":"10.3233\/JCS-2002-101-205"},{"key":"20_CR6","unstructured":"Quyen, L.T., Zhanikeev, M., Tanaka, Y.: Anomaly identification based on flow analysis. In: 2006 IEEE Region 10 Conference on TENCON 2006 (November 2006)"},{"key":"20_CR7","unstructured":"Kim, M.-S., Kong, H.-J., Hong, S.-C., Chung, S.-H., Hong, J.W.: A flow-based method for abnormal network traffic detection. In: Network Operations and Management Symposium, NOMS 2004 (2004)"},{"key":"20_CR8","unstructured":"Hu, Y., Chiu, D.-M., Lui, J.C.S.: Entropy Based Adaptive Flow Aggregation. In: IEEE\/ACM (December 2007)"},{"key":"20_CR9","doi-asserted-by":"crossref","unstructured":"Nguyen, H.A., Van Nguyen, T., Kim, D.I., Choi, D.: Network traffic anomalies detection and identification with flow monitoring. In: WCON 2008 (May 2008)","DOI":"10.1109\/WOCN.2008.4542524"},{"key":"20_CR10","unstructured":"Kim, M.-S., Kang, H.-J., Hong, S.-C., Chung, S.-H., Hong, J.W.: A Flow-based Method for Abnormal Network Traffic Detection. In: IEEE\/IFIP Network Operations and Management Symposium (2004)"},{"key":"20_CR11","doi-asserted-by":"crossref","unstructured":"Gu, Y., McCallum, A., Towsley, D.: Detecting anomalies in network traffic using maximum entropy estimation. In: Proc. IM 2005 (2005)","DOI":"10.1145\/1330107.1330148"},{"key":"20_CR12","doi-asserted-by":"crossref","unstructured":"Nychis, G., Sekar, V., Andersen, D.G., Kim, H., Zhang, H.: An empirical evaluation of entropy-based traffic anomaly detection. In: 8th ACM SIGCOMM Conference on Internet (2008)","DOI":"10.1145\/1452520.1452539"},{"key":"20_CR13","unstructured":"Wagner, A., Plattner, B.: Entropy based worm and anomaly detection in fast IP networks. In: 14th IEEE International Workshops on Enabling Technologies 2005 (2005)"},{"key":"20_CR14","unstructured":"Leckie, C., Kotiagiri, R.: A probabilistic approach to detecting network scans. In: 2002 IEEE\/IFIP Network Operations and Management Symposium (2002)"},{"key":"20_CR15","unstructured":"Introduction to cisco IOS netflow - a technical overview, \n                    \n                      http:\/\/www.cisco.com\/en\/US\/prod\/collateral\/iosswrel\/ps6537\/ps6555\/ps6601\/prod_white_paper0900aecd80406232.html"},{"key":"20_CR16","unstructured":"RFC793 - Transmission Control Protocol (September 1981)"},{"key":"20_CR17","doi-asserted-by":"crossref","unstructured":"de Vivo, M., Carrasco, E., Isern, G., de Vivo, G.O.: A review of port scanning techniques. ACM SIGCOMM Computer Communication Review (April 1999)","DOI":"10.1145\/505733.505737"},{"key":"20_CR18","unstructured":"RFC1122 - Requirements for Internet Hosts \u2013 Communication Layers (October 1989)"},{"key":"20_CR19","doi-asserted-by":"crossref","unstructured":"Muraleedharan, N.: Analysis of TCP Flow data for Traffic Anomaly and Scan Detection. In: 16th IEEE International Conference on Networks (2008)","DOI":"10.1109\/ICON.2008.4772645"},{"key":"20_CR20","unstructured":"Snort Manual, \n                    \n                      http:\/\/www.snort.org"},{"key":"20_CR21","unstructured":"nmap Reference guide, \n                    \n                      http:\/\/nmap.org\/book\/man.html"}],"container-title":["Communications in Computer and Information Science","Recent Trends in Network Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-14478-3_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,20]],"date-time":"2019-05-20T21:28:46Z","timestamp":1558387726000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-14478-3_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642144776","9783642144783"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-14478-3_20","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2010]]}}}