{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T09:05:51Z","timestamp":1725613551948},"publisher-location":"Berlin, Heidelberg","reference-count":19,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642247118"},{"type":"electronic","value":"9783642247125"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-24712-5_18","type":"book-chapter","created":{"date-parts":[[2011,9,24]],"date-time":"2011-09-24T01:54:28Z","timestamp":1316829268000},"page":"194-205","source":"Crossref","is-referenced-by-count":17,"title":["On Detecting Abrupt Changes in Network Entropy Time Series"],"prefix":"10.1007","author":[{"given":"Philipp","family":"Winter","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Harald","family":"Lampesberger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Markus","family":"Zeilinger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eckehard","family":"Hermann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"18_CR1","first-page":"71","volume-title":"Proc. of the 2nd ACM SIGCOMM Workshop on Internet Measurement, IMW 2002","author":"P. Barford","year":"2002","unstructured":"Barford, P., Kline, J., Plonka, D., Ron, A.: A Signal Analysis of Network Traffic Anomalies. In: Proc. of the 2nd ACM SIGCOMM Workshop on Internet Measurement, IMW 2002, pp. 71\u201382. ACM, New York (2002)"},{"key":"18_CR2","first-page":"1","volume-title":"Proc. of the Conference on Cyber Security Experimentation and Test","author":"D. Brauckhoff","year":"2008","unstructured":"Brauckhoff, D., Wagner, A., May, M.: FLAME: A Flow-Level Anomaly Modeling Engine. In: Proc. of the Conference on Cyber Security Experimentation and Test, pp. 1\u20136. USENIX Association, Berkeley (2008)"},{"key":"18_CR3","first-page":"139","volume-title":"Proc. of the 14th USENIX Conference on System Administration","author":"J.D. Brutlag","year":"2000","unstructured":"Brutlag, J.D.: Aberrant Behavior Detection in Time Series for Network Monitoring. In: Proc. of the 14th USENIX Conference on System Administration, pp. 139\u2013146. USENIX Association, Berkeley (2000)"},{"unstructured":"Cisco Systems, http:\/\/www.cisco.com\/web\/go\/netflow","key":"18_CR4"},{"doi-asserted-by":"crossref","unstructured":"Claise, B.: Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information. RFC 5101 (Proposed Standard) (January 2008), http:\/\/www.ietf.org\/rfc\/rfc5101.txt","key":"18_CR5","DOI":"10.17487\/rfc5101"},{"issue":"2","key":"18_CR6","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1016\/j.comnet.2004.03.033","volume":"46","author":"J. Fan","year":"2004","unstructured":"Fan, J., Xu, J., Ammar, M.H., Moon, S.B.: Prefix-Preserving IP Address Anonymization: Measurement-based Security Evaluation and a New Cryptography-based Scheme. Computer Networks\u00a046(2), 253\u2013272 (2004)","journal-title":"Computer Networks"},{"doi-asserted-by":"crossref","unstructured":"Feinstein, L., Schnackenberg, D., Balupari, R., Kindred, D.: Statistical Approaches to DDoS Attack Detection and Response. In: DARPA Information Survivability Conference and Exposition, vol.\u00a01, pp. 303\u2013314 (2003)","key":"18_CR7","DOI":"10.1109\/DISCEX.2003.1194894"},{"unstructured":"Fitzgibbon, N., Wood, M.: Conficker.C \u2013 A Technical Analysis. Tech. rep., Sophos Inc. (2009)","key":"18_CR8"},{"unstructured":"Haag, P.: NFDUMP, http:\/\/nfdump.sourceforge.net","key":"18_CR9"},{"unstructured":"Haag, P.: NfSen, http:\/\/nfsen.sourceforge.net","key":"18_CR10"},{"key":"18_CR11","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1145\/1080091.1080118","volume-title":"Proc. of the 2005 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications, SIGCOMM 2005","author":"A. Lakhina","year":"2005","unstructured":"Lakhina, A., Crovella, M., Diot, C.: Mining Anomalies Using Traffic Feature Distributions. In: Proc. of the 2005 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications, SIGCOMM 2005, pp. 217\u2013228. ACM, New York (2005)"},{"key":"18_CR12","first-page":"130","volume-title":"Proc. of the 2001 IEEE Symposium on Security and Privacy","author":"W. Lee","year":"2001","unstructured":"Lee, W., Xiang, D.: Information-Theoretic Measures for Anomaly Detection. In: Proc. of the 2001 IEEE Symposium on Security and Privacy, pp. 130\u2013143. IEEE Computer Society, Washington, DC (2001)"},{"key":"18_CR13","first-page":"151","volume-title":"Proc. of the 8th ACM SIGCOMM Conference on Internet Measurement, IMC 2008","author":"G. Nychis","year":"2008","unstructured":"Nychis, G., Sekar, V., Andersen, D.G., Kim, H., Zhang, H.: An Empirical Evaluation of Entropy-based Traffic Anomaly Detection. In: Proc. of the 8th ACM SIGCOMM Conference on Internet Measurement, IMC 2008, pp. 151\u2013156. ACM, New York (2008)"},{"key":"18_CR14","first-page":"722","volume-title":"Proc. of the 29th Conference on Computer Communications, INFOCOM 2010","author":"F. Silveira","year":"2010","unstructured":"Silveira, F., Diot, C.: URCA: Pulling out Anomalies by their Root Causes. In: Proc. of the 29th Conference on Computer Communications, INFOCOM 2010, pp. 722\u2013730. IEEE Press, Piscataway (2010)"},{"doi-asserted-by":"crossref","unstructured":"Sommer, R., Paxson, V.: Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. In: IEEE Symposium on Security and Privacy, pp. 305\u2013316 (2010)","key":"18_CR15","DOI":"10.1109\/SP.2010.25"},{"issue":"3","key":"18_CR16","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1109\/SURV.2010.032210.00054","volume":"12","author":"A. Sperotto","year":"2010","unstructured":"Sperotto, A., Schaffrath, G., Sadre, R., Morariu, C., Pras, A., Stiller, B.: An Overview of IP Flow-Based Intrusion Detection. IEEE Communications Surveys Tutorials\u00a012(3), 343\u2013356 (2010)","journal-title":"IEEE Communications Surveys Tutorials"},{"key":"18_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-3-642-00975-4_24","volume-title":"Passive and Active Network Measurement","author":"B. Tellenbach","year":"2009","unstructured":"Tellenbach, B., Burkhart, M., Sornette, D., Maillart, T.: Beyond Shannon: Characterizing Internet Traffic with Generalized Entropy Metrics. In: Moon, S.B., Teixeira, R., Uhlig, S. (eds.) PAM 2009. LNCS, vol.\u00a05448, pp. 239\u2013248. Springer, Heidelberg (2009)"},{"key":"18_CR18","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1109\/WETICE.2005.35","volume-title":"Proc. of the 14th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprise","author":"A. Wagner","year":"2005","unstructured":"Wagner, A., Plattner, B.: Entropy Based Worm and Anomaly Detection in Fast IP Networks. In: Proc. of the 14th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprise, pp. 172\u2013177. IEEE Computer Society, Washington, DC (2005)"},{"key":"18_CR19","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1145\/948187.948190","volume-title":"Proc. of the 2003 ACM Workshop on Rapid Malcode, WORM 2003","author":"N. Weaver","year":"2003","unstructured":"Weaver, N., Paxson, V., Staniford, S., Cunningham, R.: A Taxonomy of Computer Worms. In: Proc. of the 2003 ACM Workshop on Rapid Malcode, WORM 2003, pp. 11\u201318. ACM, New York (2003)"}],"container-title":["Lecture Notes in Computer Science","Communications and Multimedia Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-24712-5_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,16]],"date-time":"2019-06-16T06:02:14Z","timestamp":1560664934000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-24712-5_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642247118","9783642247125"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-24712-5_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}