{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T17:55:51Z","timestamp":1780595751738,"version":"3.54.1"},"publisher-location":"Berlin, Heidelberg","reference-count":33,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642236433","type":"print"},{"value":"9783642236440","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-23644-0_9","type":"book-chapter","created":{"date-parts":[[2012,2,11]],"date-time":"2012-02-11T00:06:20Z","timestamp":1328918780000},"page":"161-180","source":"Crossref","is-referenced-by-count":220,"title":["Revisiting Traffic Anomaly Detection Using Software Defined Networking"],"prefix":"10.1007","author":[{"given":"Syed Akbar","family":"Mehdi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junaid","family":"Khalid","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Syed Ali","family":"Khayam","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"9_CR1","unstructured":"Acm sigcomm workshop on home networks (homenets), \n                    \n                      http:\/\/conferences.sigcomm.org\/sigcomm\/2010\/HomeNets.php"},{"key":"9_CR2","unstructured":"Arbor networks peakflow-x homepage, \n                    \n                      http:\/\/www.arbornetworks.com\/en\/peakflow-x.html"},{"key":"9_CR3","unstructured":"Cisco anomaly guard module homepage, \n                    \n                      www.cisco.com\/en\/US\/products\/ps6235\/"},{"key":"9_CR4","unstructured":"Endace ninjabox homepage, \n                    \n                      http:\/\/www.endace.com\/ninjabox.html"},{"key":"9_CR5","unstructured":"Nox box, \n                    \n                      http:\/\/noxrepo.org\/manual\/noxbox.html"},{"key":"9_CR6","unstructured":"Open vswitch, \n                    \n                      http:\/\/openvswitch.org\/"},{"key":"9_CR7","unstructured":"Openflow specification version 1.0.0, \n                    \n                      http:\/\/www.openflow.org\/documents\/openflow-spec-v1.0.0.pdf"},{"key":"9_CR8","unstructured":"Openflow specification version 1.1.0, \n                    \n                      http:\/\/www.openflow.org\/documents\/openflow-spec-v1.1.0.pdf"},{"key":"9_CR9","unstructured":"Pc engines alix 2c3 system board, \n                    \n                      http:\/\/www.pcengines.ch\/alix2c3.htm"},{"key":"9_CR10","unstructured":"Voyage linux, \n                    \n                      http:\/\/linux.voyage.hk\/"},{"key":"9_CR11","unstructured":"Anti-phishingworking group. phishing activity trends report, 4th quarter \/ 2009 (2010), \n                    \n                      http:\/\/www.antiphishing.org\/reports\/apwg_report_Q4_2009.pdf"},{"key":"9_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"351","DOI":"10.1007\/978-3-540-87403-4_19","volume-title":"Recent Advances in Intrusion Detection","author":"A.B. Ashfaq","year":"2008","unstructured":"Ashfaq, A.B., Robert, M.J., Mumtaz, A., Ali, M.Q., Sajjad, A., Khayam, S.A.: A comparative evaluation of anomaly detectors under portscan attacks. In: Lippmann, R., Kirda, E., Trachtenberg, A. (eds.) RAID 2008. LNCS, vol.\u00a05230, pp. 351\u2013371. Springer, Heidelberg (2008)"},{"key":"9_CR13","first-page":"159","volume-title":"Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, IMC 2006","author":"D. Brauckhoff","year":"2006","unstructured":"Brauckhoff, D., Tellenbach, B., Wagner, A., May, M., Lakhina, A.: Impact of packet sampling on anomaly detection metrics. In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, IMC 2006, pp. 159\u2013164. ACM, New York (2006)"},{"key":"9_CR14","first-page":"15","volume-title":"Proceedings of the 2nd Conference on Symposium on Networked Systems Design & Implementation, NSDI 2005","author":"M. Caesar","year":"2005","unstructured":"Caesar, M., Caldwell, D., Feamster, N., Rexford, J., Shaikh, A., van der Merwe, J.: Design and implementation of a routing control platform. In: Proceedings of the 2nd Conference on Symposium on Networked Systems Design & Implementation, NSDI 2005, vol.\u00a02, pp. 15\u201328. USENIX Association, Berkeley (2005)"},{"key":"9_CR15","unstructured":"Calvert, K.L., Keith, W., Rebecca, E., Grinter, E.: Moving toward the middle: The case against the end-to-end argument. In: Home Networking. Sixth Workshop on Hot Topics in Networks (2007)"},{"key":"9_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1282427.1282382","volume":"37","author":"M. Casado","year":"2007","unstructured":"Casado, M., Freedman, M.J., Pettit, J., Luo, J., McKeown, N., Shenker, S.: Ethane: taking control of the enterprise. SIGCOMM Comput. Commun. Rev.\u00a037, 1\u201312 (2007)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"9_CR17","volume-title":"Proceedings of the 15th Conference on USENIX Security Symposium","author":"M. Casado","year":"2006","unstructured":"Casado, M., Garfinkel, T., Akella, A., Freedman, M.J., Boneh, D., McKeown, N., Shenker, S.: Sane: a protection architecture for enterprise networks. In: Proceedings of the 15th Conference on USENIX Security Symposium, vol.\u00a015. USENIX Association, Berkeley (2006)"},{"key":"9_CR18","doi-asserted-by":"crossref","unstructured":"Dixon, C., Mahajan, R., Agarwal, S., Brush, A.J., Lee, B., Saroiu, S., Bahl, V.: The home needs an operating system (and an app store). In: Proceedings of the Ninth ACM SIGCOMM Workshop on Hot Topics in Networks, Hotnets 2010, pp.18:1\u201318:6. ACM, New York (2010)","DOI":"10.1145\/1868447.1868465"},{"key":"9_CR19","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1145\/1851307.1851317","volume-title":"Proceedings of the 2010 ACM SIGCOMM Workshop on Home Networks, HomeNets 2010","author":"N. Feamster","year":"2010","unstructured":"Feamster, N.: Outsourcing home network security. In: Proceedings of the 2010 ACM SIGCOMM Workshop on Home Networks, HomeNets 2010, pp. 37\u201342. ACM, New York (2010)"},{"key":"9_CR20","first-page":"32","volume-title":"Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement, IMC 2005","author":"Y. Gu","year":"2005","unstructured":"Gu, Y., McCallum, A., Towsley, D.: Detecting anomalies in network traffic using maximum entropy estimation. In: Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement, IMC 2005, p. 32. USENIX Association, Berkeley (2005)"},{"key":"9_CR21","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1145\/1384609.1384625","volume":"38","author":"N. Gude","year":"2008","unstructured":"Gude, N., Koponen, T., Pettit, J., Pfaff, B., Casado, M., McKeown, N., Shenker, S.: Nox: towards an operating system for networks. SIGCOMM Comput. Commun. Rev.\u00a038, 105\u2013110 (2008)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"9_CR22","unstructured":"Jung, J., Paxson, V., Berger, A.W., Balakrishnan, H.: Fast portscan detection using sequential hypothesis testing. In: Proceedings of the IEEE Symposium on Security and Privacy (2004)"},{"key":"9_CR23","unstructured":"Kim, M.S., Kong, H.J., Hong, S.C., Chung, S.H., Hong, J.: A flow-based method for abnormal network traffic detection. In: IEEE\/IFIP Network Operations and Management Symposium, NOMS 2004, vol.\u00a01, pp. 599\u2013612 (2004)"},{"key":"9_CR24","first-page":"1","volume-title":"Proceedings of the 9th USENIX Conference on Operating Systems Design and Implementation, OSDI 2010","author":"T. Koponen","year":"2010","unstructured":"Koponen, T., Casado, M., Gude, N., Stribling, J., Poutievski, L., Zhu, M., Ramanathan, R., Iwata, Y., Inoue, H., Hama, T., Shenker, S.: Onix: a distributed control platform for large-scale production networks. In: Proceedings of the 9th USENIX Conference on Operating Systems Design and Implementation, OSDI 2010, pp. 1\u20136. USENIX Association, Berkeley (2010)"},{"key":"9_CR25","doi-asserted-by":"crossref","unstructured":"Lakhina, A., Crovella, M., Diot, C.: Mining anomalies using traffic feature distributions. In: ACM SIGCOMM. pp. 217\u2013228 (2005)","DOI":"10.1145\/1090191.1080118"},{"key":"9_CR26","series-title":"Lecture Notes in Computer Science","first-page":"346","volume-title":"Selected Areas in Cryptography","author":"M.V. Mahoney","year":"2004","unstructured":"Mahoney, M.V.: Network traffic anomaly detection based on packet bytes. In: Matsui, M., Zuccherato, R.J. (eds.) SAC 2003. LNCS, vol.\u00a03006, pp. 346\u2013350. Springer, Heidelberg (2004)"},{"key":"9_CR27","first-page":"165","volume-title":"Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, IMC 2006","author":"J. Mai","year":"2006","unstructured":"Mai, J., Chuah, C.N., Sridharan, A., Ye, T., Zang, H.: Is sampled data sufficient for anomaly detection? In: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, IMC 2006, pp. 165\u2013176. ACM, New York (2006)"},{"key":"9_CR28","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1145\/1355734.1355746","volume":"38","author":"N. McKeown","year":"2008","unstructured":"McKeown, N., Anderson, T., Balakrishnan, H., Parulkar, G., Peterson, L., Rexford, J., Shenker, S., Turner, J.: Openflow: enabling innovation in campus networks. SIGCOMM Comput. Commun. Rev.\u00a038, 69\u201374 (2008)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"9_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/978-3-540-30143-1_4","volume-title":"Recent Advances in Intrusion Detection","author":"S.E. Schechter","year":"2004","unstructured":"Schechter, S.E., Jung, J., Berger, A.W.: Fast detection of scanning worm infections. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 59\u201381. Springer, Heidelberg (2004)"},{"key":"9_CR30","first-page":"20","volume-title":"Proceedings of the 12th Conference on USENIX Security Symposium","author":"J. Twycross","year":"2003","unstructured":"Twycross, J., Williamson, M.M.: Implementing and testing a virus throttle. In: Proceedings of the 12th Conference on USENIX Security Symposium, vol.\u00a012, p. 20. USENIX Association, Berkeley (2003)"},{"key":"9_CR31","unstructured":"Williamson, M.M.: Throttling viruses: Restricting propagation to defeat malicious mobile code. In: ACSAC (2002)"},{"key":"9_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1851307.1851309","volume-title":"Proceedings of the 2010 ACM SIGCOMM Workshop on Home Networks, HomeNets 2010","author":"J. Yang","year":"2010","unstructured":"Yang, J., Edwards, W.K.: A study on network management tools of householders. In: Proceedings of the 2010 ACM SIGCOMM Workshop on Home Networks, HomeNets 2010, pp. 1\u20136. ACM, New York (2010)"},{"key":"9_CR33","unstructured":"Cai, Z., Cox, A.L., Eugene Ng, T.S.: Maestro: A system for scalable openflow control, \n                    \n                      http:\/\/www.cs.rice.edu\/~eugeneng\/papers\/TR10-11.pdf"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-23644-0_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,4,27]],"date-time":"2019-04-27T12:21:16Z","timestamp":1556367676000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-23644-0_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642236433","9783642236440"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-23644-0_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011]]}}}