{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T21:25:44Z","timestamp":1785533144550,"version":"3.56.0"},"publisher-location":"Berlin, Heidelberg","reference-count":56,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642155116","type":"print"},{"value":"9783642155123","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-15512-3_12","type":"book-chapter","created":{"date-parts":[[2010,8,31]],"date-time":"2010-08-31T08:27:39Z","timestamp":1283243259000},"page":"218-237","source":"Crossref","is-referenced-by-count":17,"title":["Generating Client Workloads and High-Fidelity Network Traffic for Controllable, Repeatable Experiments in Computer Security"],"prefix":"10.1007","author":[{"given":"Charles V.","family":"Wright","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Connelly","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Timothy","family":"Braje","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jesse C.","family":"Rabek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lee M.","family":"Rossey","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Robert K.","family":"Cunningham","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"issue":"3","key":"12_CR1","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1145\/956993.956997","volume":"33","author":"P. Barford","year":"2003","unstructured":"Barford, P., Landweber, L.: Bench-style network research in an Internet Instance Laboratory. ACM SIGCOMM Computer Communication Review\u00a033(3), 21\u201326 (2003)","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"12_CR2","doi-asserted-by":"crossref","unstructured":"Peisert, S., Bishop, M.: How to Design Computer Security Experiments. In: Proceedings of the 5th World Conference on Information Security Education (WISE), pp. 141\u2013148 (2007)","DOI":"10.1007\/978-0-387-73269-5_19"},{"key":"12_CR3","unstructured":"US Department of Homeland Security: A Roadmap for Cybersecurity Research. Technical report (November 2009), \n                    \n                      www.cyber.st.dhs.gov\/docs\/DHS-Cybersecurity-Roadmap.pdf"},{"key":"12_CR4","doi-asserted-by":"crossref","unstructured":"White, B., Lepreau, J., Stoller, L., Ricci, R., Guruprasad, S., Newbold, M., Hibler, M., Barb, C., Joglekar, A.: An integrated experimental environment for distributed systems and networks. In: Proceedings of the 5th Symposium on Operating Systems Design and Implementation (December 2002)","DOI":"10.1145\/1060289.1060313"},{"key":"12_CR5","unstructured":"Ricci, R., Duerig, J., Sanaga, P., Gebhardt, D., Hibler, M., Atkinson, K., Zhang, J., Kasera, S., Lepreau, J.: The Flexlab approach to realistic evaluation of networked systems. In: Proceedings of the 4th USENIX Symposium on Networked Systems Design & Implementation, pp. 201\u2013214 (April 2007)"},{"key":"12_CR6","doi-asserted-by":"crossref","unstructured":"Vahdat, A., Yocum, K., Walsh, K., Mahadevan, P., Kostic, D., Chase, J., Becker, D.: Scalability and Accuracy in a Large-Scale Network Emulator. In: Proceedings of the 5th Symposium on Operating Systems Design and Implementation (December 2002)","DOI":"10.1145\/1060289.1060315"},{"key":"12_CR7","doi-asserted-by":"crossref","unstructured":"Bavier, A., Feamster, N., Huang, M., Peterson, L., Rexford, J.: VINI veritas: Realistic and controlled network experimentation. In: Proceedings of ACM SIGCOMM (September 2006)","DOI":"10.1145\/1159913.1159916"},{"key":"12_CR8","doi-asserted-by":"crossref","unstructured":"Rossey, L.M., Cunningham, R.K., Fried, D.J., Rabek, J.C., Lippmann, R.P., Haines, J.W., Zissman, M.A.: LARIAT: Lincoln Adaptable Real-time Information Assurance Testbed. In: Proceedings of the IEEE Aerospace Conference (2002)","DOI":"10.1109\/AERO.2002.1036158"},{"key":"12_CR9","unstructured":"Provos, N., McNamee, D., Mavrommatis, P., Wang, K., Modadugu, N.: The Ghost in the Browser: Analysis of Web-based Malware. In: Proceedings of the First Workshop on Hot Topics in Understanding Botnets (HotBots 2007) (April 2007)"},{"key":"12_CR10","unstructured":"Fossi, M.: Symantec Internet Security Threat Report: Trends for 2008 (April 2009)"},{"key":"12_CR11","unstructured":"Deibert, R., Rohozinski, R.: Tracking GhostNet: Investigating a Cyber Espionage Network. Technical Report JR02-2009, Information Warfare Monitor (March 2009)"},{"key":"12_CR12","unstructured":"Nagaraja, S., Anderson, R.: The Snooping Dragon: Social-Malware Surveillance of the Tibetan Movement. Technical Report UCAM-CL-TR-746, University of Cambridge Computer Laboratory (March 2009)"},{"key":"12_CR13","unstructured":"Provos, N., Mavrommatis, P., Rajab, M., Monrose, F.: All Your iFrames Point to Us. In: Proceedings of the 17th USENIX Security Symposium (July 2008)"},{"key":"12_CR14","unstructured":"Pinheiro, E., Weber, W.D., Barroso, L.A.: Failure Trends in a Large Disk Drive Population. In: Proceedings of the 5th USENIX Conference on File and Storage Technologies (February 2007)"},{"key":"12_CR15","unstructured":"Lippmann, R.P., Fried, D.J., Graf, I., Haines, J.W., Kendall, K.R., McClung, D., Weber, D., Webster, S.E., Wyschogrod, D., Cunningham, R.K., Zissman, M.A.: Evaluating Intrusion Detection Systems: The 1998 DARPA Off-Line Intrusion Detection Evaluation. In: Proceedings of the 2000 DARPA Information Survivability Conference and Exposition (2000)"},{"issue":"4","key":"12_CR16","first-page":"279","volume":"34","author":"R. Lippmann","year":"2000","unstructured":"Lippmann, R., Haines, J.W., Fried, D.J., Korba, J., Das, K.: The 1999 DARPA Off-line Intrusion Detection Evaluation. Computer Networks\u00a034(4), 279\u2013595 (2000)","journal-title":"Computer Networks"},{"key":"12_CR17","unstructured":"Yu, T., Fuller, B., Bannick, J., Rossey, L., Cunningham, R.: Integrated Environment Management for Information Operations Testbeds. In: Proceedings of the 2007 Workshop on Visualization for Computer Security (October 2007)"},{"key":"12_CR18","doi-asserted-by":"crossref","unstructured":"Benzel, T., Braden, R., Kim, D., Neuman, C., Joseph, A., Sklower, K., Ostrenga, R., Schwab, S.: Experience with DETER: A Testbed for Security Research. In: Proceedings of the 2nd International Conference on Testbeds and Research Infrastructures for the Development of Networks and Communities (TRIDENTCOM) (March 2006)","DOI":"10.1109\/TRIDNT.2006.1649172"},{"key":"12_CR19","unstructured":"Boothe-Rabek, J.C.: WinNTGen: Creation of a Windows NT 5.0+ network traffic generator. Master\u2019s thesis, Massachusetts Institute of Technology (2003)"},{"key":"12_CR20","first-page":"196","volume-title":"ANSS 2006: Proceedings of the 39th Annual Symposium on Simulation, Washington, DC, USA","author":"A. Garg","year":"2006","unstructured":"Garg, A., Vidyaraman, S., Upadhyaya, S., Kwiat, K.: USim: A User Behavior Simulation Framework for Training and Testing IDSes in GUI Based Systems. In: ANSS 2006: Proceedings of the 39th Annual Symposium on Simulation, Washington, DC, USA, pp. 196\u2013203. IEEE Computer Society, Los Alamitos (2006)"},{"key":"12_CR21","unstructured":"Cui, W., Paxson, V., Weaver, N.C.: GQ: Realizing a System to Catch Worms in a Quarter Million Places. Technical Report TR-06-004, International Computer Science Institute (September 2006)"},{"key":"12_CR22","unstructured":"Cui, W., Paxson, V., Weaver, N.C., Katz, R.H.: Protocol-Independent Adaptive Replay of Application Dialog. In: Proceedings of the 13th Annual Symposium on Network and Distributed System Security (NDSS 2006) (February 2006)"},{"key":"12_CR23","unstructured":"Small, S., Mason, J., Monrose, F., Provos, N., Stubblefield, A.: To catch a predator: A natural language approach for eliciting malicious payloads. In: Proceedings of the 17th USENIX Security Symposium (August 2008)"},{"key":"12_CR24","unstructured":"Wang, K.: Using HoneyClients to Detect New Attacks. In: RECON Conference (June 2005)"},{"key":"12_CR25","unstructured":"Wang, Y.M., Beck, D., Jiang, X., Roussev, R., Verbowski, C., Chen, S., King, S.: Automated Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit Browser Vulnerabilities. In: Proceedings of the 13th Annual Symposium on Network and Distributed System Security (NDSS 2006) (February 2006)"},{"key":"12_CR26","unstructured":"Sanders, M.: autopy: A simple, cross-platform GUI automation toolkit for Python, \n                    \n                      http:\/\/github.com\/msanders\/autopy"},{"key":"12_CR27","doi-asserted-by":"crossref","unstructured":"Yeh, T., Chang, T.H., Miller, R.C.: Sikuli: Using GUI Screenshots for Search and Automation. In: Proceedings of the 22nd Symposium on User Interface Software and Technology (October 2009)","DOI":"10.1145\/1622176.1622213"},{"key":"12_CR28","unstructured":"Kleek, M.V., Bernstein, M., Karger, D., Schraefel, M.C.: Getting to Know You Gradually: Personal Lifetime User Modeling (PLUM). Technical report, MIT CSAIL (April 2007)"},{"key":"12_CR29","doi-asserted-by":"crossref","unstructured":"Simpson, C.R., Reddy, D., Riley, G.F.: Empirical Models of TCP and UDP EndUser Network Trafc from NETI@home Data Analysis. In: 20th International Workshop on Principles of Advanced and Distributed Simulation (May 2006)","DOI":"10.1109\/PADS.2006.17"},{"key":"12_CR30","unstructured":"Kurz, C., Hlavacs, H., Kotsis, G.: Workload Generation by Modelling User Behavior in an ISP Subnet. In: Proceedings of the International Symposium on Telecommunications (August 2001)"},{"key":"12_CR31","unstructured":"tcpreplay by Aaron Turner, \n                    \n                      http:\/\/tcpreplay.synfin.net\/"},{"key":"12_CR32","doi-asserted-by":"crossref","unstructured":"Hong, S.S., Wu, S.F.: On Interactive Internet Traffic Replay. In: Proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection (September 2006)","DOI":"10.1007\/11663812_13"},{"key":"12_CR33","doi-asserted-by":"crossref","unstructured":"Sommers, J., Barford, P.: Self-configuring network traffic generation. In: Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement, pp. 68\u201381 (2004)","DOI":"10.1145\/1028788.1028798"},{"key":"12_CR34","unstructured":"Cao, J., Cleveland, W.S., Gao, Y., Jeffay, K., Smith, F.D., Weigle, M.C.: Stochastic models for generating synthetic HTTP source traffic. In: INFOCOM (2004)"},{"issue":"3","key":"12_CR35","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1145\/1140086.1140094","volume":"36","author":"M.C. Weigle","year":"2006","unstructured":"Weigle, M.C., Adurthi, P., Hern\u00e1ndez-Campos, F., Jeffay, K., Smith, F.D.: Tmix: a tool for generating realistic TCP application workloads in ns-2. ACM SIGCOMM Computer Communication Review\u00a036(3), 65\u201376 (2006)","journal-title":"ACM SIGCOMM Computer Communication Review"},{"issue":"3","key":"12_CR36","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1145\/643114.643117","volume":"12","author":"K.C. Lan","year":"2002","unstructured":"Lan, K.C., Heidemann, J.: Rapid model parameterization from traffic measurements. ACM Transactions on Modeling and Computer Simulation (TOMACS)\u00a012(3), 201\u2013229 (2002)","journal-title":"ACM Transactions on Modeling and Computer Simulation (TOMACS)"},{"key":"12_CR37","doi-asserted-by":"crossref","unstructured":"Vishwanath, K.V., Vahdat, A.: Realistic and Responsive Network Traffic Generation. In: Proceedings of ACM SIGCOMM (September 2006)","DOI":"10.1145\/1159913.1159928"},{"key":"12_CR38","unstructured":"Sommers, J., Yegneswaran, V., Barford, P.: Toward Comprehensive Trafc Generation for Online IDS Evaluation. Technical report, University of Wisconsin (2005)"},{"key":"12_CR39","doi-asserted-by":"crossref","unstructured":"Mutz, D., Vigna, G., Kemmerer, R.: An Experience Developing an IDS Stimulator for the Black-Box Testing of Network Intrusion Detection Systems. In: Proceedings of the Annual Computer Security Applications Conference (December 2003)","DOI":"10.1109\/CSAC.2003.1254342"},{"key":"12_CR40","doi-asserted-by":"crossref","unstructured":"Kayacik, H.G., Zincir-Heywood, N.: Generating Representative Traffic for Intrusion Detection System Benchmarking. In: Proceedings of the 3rd Annual Communication Networks and Services Research Conference, pp. 112\u2013117 (May 2005)","DOI":"10.1109\/CNSR.2005.35"},{"key":"12_CR41","doi-asserted-by":"crossref","unstructured":"Sommers, J., Yegneswaran, V., Barford, P.: A framework for malicious workload generation. In: Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement, pp. 82\u201387 (2004)","DOI":"10.1145\/1028788.1028799"},{"key":"12_CR42","unstructured":"Hunt, G., Brubacher, D.: Detours: Binary Interception of Win32 Functions. In: Third USENIX Windows NT Symposium (July 1999)"},{"key":"12_CR43","unstructured":"Klimt, B., Yang, Y.: Introducing the Enron Corpus. In: Proceedings of the First Conference on Email and Anti-Spam (CEAS) (July 2004)"},{"key":"12_CR44","doi-asserted-by":"crossref","unstructured":"Paxson, V., Floyd, S.: Wide Area Traffic: The Failure of Poisson Modeling. IEEE\/ACM Transactions on Networking\u00a03(3) (June 1995)","DOI":"10.1109\/90.392383"},{"issue":"1","key":"12_CR45","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/272991.272995","volume":"8","author":"M. Matsumoto","year":"1998","unstructured":"Matsumoto, M., Nishimura, T.: Mersenne Twister: a 623-dimensionally equidistributed uniform pseudo-random number generator. ACM Transactions on Modelling and Computer Simulation\u00a08(1), 3\u201330 (1998)","journal-title":"ACM Transactions on Modelling and Computer Simulation"},{"key":"12_CR46","unstructured":"GINA: MSDN Windows Developer Center, \n                    \n                      http:\/\/msdn.microsoft.com\/en-us\/library\/aa375457VS.85.aspx"},{"key":"12_CR47","unstructured":"Hibler, M., Ricci, R., Stoller, L., Duerig, J., Guruprasad, S., Stack, T., Webb, K., Lepreau, J.: Large-scale Virtualization in the Emulab Network Testbed. In: Proceedings of the 2008 USENIX Annual Technical Conference (June 2008)"},{"key":"12_CR48","unstructured":"Google, Inc.: Google search appliance, \n                    \n                      http:\/\/www.google.com\/enterprise\/search\/gsa.html"},{"key":"12_CR49","unstructured":"osCommerce: Open Source E-Commerce Solutions, \n                    \n                      http:\/\/www.oscommerce.com\/"},{"key":"12_CR50","unstructured":"DMOZ Open Directory Project, \n                    \n                      http:\/\/www.dmoz.org\/"},{"key":"12_CR51","unstructured":"Yahoo! Directory, \n                    \n                      http:\/\/dir.yahoo.com\/"},{"key":"12_CR52","unstructured":"Alexa Top Sites, \n                    \n                      http:\/\/www.alexa.com\/topsites"},{"key":"12_CR53","unstructured":"AV-Comparatives e.V.: Anti-Virus Comparative Performance Test: Impact of Anti-Virus Software on System Performance (December 2009), \n                    \n                      http:\/\/www.av-comparatives.org\/comparativesreviews\/performance-tests"},{"key":"12_CR54","unstructured":"Warner, O.: What Really Slows Windows Down (September 2006), \n                    \n                      http:\/\/www.thepcspy.com\/read\/what_really_slows_windows_down"},{"key":"12_CR55","unstructured":"Chatterton, D., Gigante, M., Goodwin, M., Kavadias, T., Keronen, S., Knispel, J., McDonell, K., Matveev, M., Milewska, A., Moore, D., Muehlebach, H., Rayner, I., Scott, N., Shimmin, T., Schultz, T., Tuthill, B.: Performance Co-Pilot for IRIX Advanced User\u2019s and Administrator\u2019s Guide. 2.3 edn. SGI Technical Publications (2002), \n                    \n                      http:\/\/oss.sgi.com\/projects\/pcp\/index.html"},{"key":"12_CR56","unstructured":"Timekeeping in VMware Virtual Machines, \n                    \n                      http:\/\/www.vmware.com\/pdf\/vmware_timekeeping.pdf"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-15512-3_12.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,30]],"date-time":"2021-04-30T08:56:04Z","timestamp":1619772964000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-15512-3_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642155116","9783642155123"],"references-count":56,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-15512-3_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}