{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T11:53:36Z","timestamp":1746186816344},"publisher-location":"Berlin, Heidelberg","reference-count":36,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642319082"},{"type":"electronic","value":"9783642319099"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-31909-9_2","type":"book-chapter","created":{"date-parts":[[2012,9,22]],"date-time":"2012-09-22T07:23:23Z","timestamp":1348298603000},"page":"19-38","source":"Crossref","is-referenced-by-count":6,"title":["An On-Line Learning Statistical Model to Detect Malicious Web Requests"],"prefix":"10.1007","author":[{"given":"Harald","family":"Lampesberger","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Philipp","family":"Winter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Markus","family":"Zeilinger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eckehard","family":"Hermann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"6","key":"2_CR1","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1145\/360825.360855","volume":"18","author":"A.V. Aho","year":"1975","unstructured":"Aho, A.V., Corasick, M.J.: Efficient string matching: an aid to bibliographic search. Commun. ACM\u00a018(6), 333\u2013340 (1975)","journal-title":"Commun. ACM"},{"key":"2_CR2","unstructured":"Apache 2.0 Documentation: Apache Module mod_rewrite (2011), http:\/\/httpd.apache.org\/docs\/2.0\/mod\/mod_rewrite.html (Online; accessed April 28, 2011)"},{"key":"2_CR3","first-page":"1","volume-title":"CCS 1999: Proceedings of the 6th ACM Conference on Computer and Communications Security","author":"S. Axelsson","year":"1999","unstructured":"Axelsson, S.: The base-rate fallacy and its implications for the difficulty of intrusion detection. In: CCS 1999: Proceedings of the 6th ACM Conference on Computer and Communications Security, pp. 1\u20137. ACM, New York (1999)"},{"issue":"1","key":"2_CR4","first-page":"385","volume":"22","author":"R. Begleiter","year":"2004","unstructured":"Begleiter, R., El-Yaniv, R., Yona, G.: On prediction using variable order markov models. J. Artif. Int. Res.\u00a022(1), 385\u2013421 (2004)","journal-title":"J. Artif. Int. Res."},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Berners-Lee, T., Fielding, R., Masinter, L.: Uniform Resource Identifier (URI): Generic Syntax. RFC 3986 (Standard) (January 2005), http:\/\/www.ietf.org\/rfc\/rfc3986.txt","DOI":"10.17487\/rfc3986"},{"key":"2_CR6","series-title":"LNICST","doi-asserted-by":"publisher","first-page":"448","DOI":"10.1007\/978-3-642-05284-2_26","volume-title":"Security and Privacy in Communication Networks","author":"E. Chan-Tin","year":"2009","unstructured":"Chan-Tin, E., Feldman, D., Hopper, N., Kim, Y.: The Frog-Boiling Attack: Limitations of Anomaly Detection for Secure Network Coordinate Systems. In: Chen, Y., Dimitriou, T.D., Zhou, J. (eds.) SecureComm 2009. LNICST, vol.\u00a019, pp. 448\u2013458. Springer, Heidelberg (2009)"},{"key":"2_CR7","doi-asserted-by":"publisher","first-page":"396","DOI":"10.1109\/TCOM.1984.1096090","volume":"32","author":"J.G. Cleary","year":"1984","unstructured":"Cleary, J.G., Witten, I.H.: Data compression using adaptive coding and partial string matching. IEEE Transactions on Communications\u00a032, 396\u2013402 (1984)","journal-title":"IEEE Transactions on Communications"},{"key":"2_CR8","first-page":"233","volume-title":"Proceedings of the 23rd International Conference on Machine Learning, ICML 2006","author":"J. Davis","year":"2006","unstructured":"Davis, J., Goadrich, M.: The relationship between precision-recall and roc curves. In: ICML 2006, pp. 233\u2013240. ACM, New York (2006)"},{"key":"2_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1007\/978-3-540-89862-7_17","volume-title":"Information Systems Security","author":"P. D\u00fcssel","year":"2008","unstructured":"D\u00fcssel, P., Gehl, C., Laskov, P., Rieck, K.: Incorporation of Application Layer Protocol Syntax into Anomaly Detection. In: Sekar, R., Pujari, A.K. (eds.) ICISS 2008. LNCS, vol.\u00a05352, pp. 188\u2013202. Springer, Heidelberg (2008)"},{"key":"2_CR10","unstructured":"Evans, M., Hastings, N., Peacock, B.: Statistical Distributions, 3rd edn. Wiley-Interscience (2000)"},{"key":"2_CR11","unstructured":"Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter, L., Leach, P., Berners-Lee, T.: Hypertext Transfer Protocol \u2013 HTTP\/1.1. RFC 2616 (Draft Standard) (June 1999), http:\/\/www.ietf.org\/rfc\/rfc2616.txt , updated by RFCs 2817, 5785"},{"key":"2_CR12","first-page":"47","volume-title":"Proceedings of the 2nd ACM Workshop on Security and Artificial Intelligence, AISec 2009","author":"N. G\u00f6rnitz","year":"2009","unstructured":"G\u00f6rnitz, N., Kloft, M., Rieck, K., Brefeld, U.: Active learning for network intrusion detection. In: Proceedings of the 2nd ACM Workshop on Security and Artificial Intelligence, AISec 2009, pp. 47\u201354. ACM, New York (2009)"},{"key":"2_CR13","volume-title":"Data Mining: Concepts and Techniques","author":"J. Han","year":"2006","unstructured":"Han, J., Kamber, M.: Data Mining: Concepts and Techniques, 2nd edn. Morgan Kaufmann Publishers Inc., San Francisco (2006)","edition":"2"},{"key":"2_CR14","doi-asserted-by":"publisher","first-page":"1239","DOI":"10.1016\/j.comnet.2006.09.016","volume":"51","author":"K.L. Ingham","year":"2007","unstructured":"Ingham, K.L., Somayaji, A., Burge, J., Forrest, S.: Learning dfa representations of http for protecting web applications. Comput. Netw.\u00a051, 1239\u20131255 (2007)","journal-title":"Comput. Netw."},{"key":"2_CR15","unstructured":"Knuth, D.E.: The Art of Computer Programming. Seminumerical Algorithms, 2nd edn., vol.\u00a0II. Addison-Wesley (1981)"},{"key":"2_CR16","first-page":"251","volume-title":"CCS 2003: Proceedings of the 10th ACM Conference on Computer and Communications Security","author":"C. Kruegel","year":"2003","unstructured":"Kruegel, C., Vigna, G.: Anomaly detection of web-based attacks. In: CCS 2003: Proceedings of the 10th ACM Conference on Computer and Communications Security, pp. 251\u2013261. ACM, New York (2003)"},{"key":"2_CR17","doi-asserted-by":"crossref","first-page":"1846","DOI":"10.1145\/1774088.1774480","volume-title":"SAC 2010: Proceedings of the 2010 ACM Symposium on Applied Computing","author":"T. Krueger","year":"2010","unstructured":"Krueger, T., Gehl, C., Rieck, K., Laskov, P.: Tokdoc: a self-healing web application firewall. In: SAC 2010: Proceedings of the 2010 ACM Symposium on Applied Computing, pp. 1846\u20131853. ACM, New York (2010)"},{"key":"2_CR18","unstructured":"Ma, J., Liu, X., Wang, Q., Dai, G.: Compression-based web anomaly detection model. In: 2010 IEEE 29th International Performance Computing and Communications Conference (IPCCC) (December 2010)"},{"key":"2_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1007\/978-3-642-04342-0_2","volume-title":"RAID 2009","author":"F. Maggi","year":"2009","unstructured":"Maggi, F., Robertson, W., Kruegel, C., Vigna, G.: Protecting a Moving Target: Addressing Web Application Concept Drift. In: Kirda, E., Jha, S., Balzarotti, D. (eds.) RAID 2009. LNCS, vol.\u00a05758, pp. 21\u201340. Springer, Heidelberg (2009)"},{"key":"2_CR20","unstructured":"Metasploit: The Metasploit Project (2011), http:\/\/www.metasploit.com\/ (Online; accessed April 30, 2011)"},{"key":"2_CR21","unstructured":"MITRE Corporation: Common Vulnerabilites and Exposures (2011), http:\/\/cve.mitre.org\/ (Online; accessed May 12, 2011)"},{"key":"2_CR22","unstructured":"MITRE Corporation: Common Weakness Enumeration (2011), http:\/\/cwe.mitre.org\/ (Online; accessed April 28, 2011)"},{"issue":"11","key":"2_CR23","doi-asserted-by":"publisher","first-page":"1917","DOI":"10.1109\/26.61469","volume":"38","author":"A. Moffat","year":"1990","unstructured":"Moffat, A.: Implementing the ppm data compression scheme. IEEE Transactions on Communications\u00a038(11), 1917\u20131921 (1990)","journal-title":"IEEE Transactions on Communications"},{"issue":"6","key":"2_CR24","doi-asserted-by":"publisher","first-page":"864","DOI":"10.1016\/j.comnet.2008.11.011","volume":"53","author":"R. Perdisci","year":"2009","unstructured":"Perdisci, R., Ariu, D., Fogla, P., Giacinto, G., Lee, W.: Mcpad: A multiple classifier system for accurate payload-based anomaly detection. Computer Networks\u00a053(6), 864\u2013881 (2009); traffic Classification and Its Applications to Modern Networks","journal-title":"Computer Networks"},{"key":"2_CR25","volume-title":"Proceedings of the First Conference on First Workshop on Hot Topics in Understanding Botnets","author":"N. Provos","year":"2007","unstructured":"Provos, N., McNamee, D., Mavrommatis, P., Wang, K., Modadugu, N.: The ghost in the browser analysis of web-based malware. In: Proceedings of the First Conference on First Workshop on Hot Topics in Understanding Botnets. USENIX Association, Berkeley (2007)"},{"key":"2_CR26","unstructured":"Robertson, W., Vigna, G., Kruegel, C., Kemmerer, R.: Using generalization and characterization techniques in the anomaly-based detection of web attacks. In: Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA (February 2006)"},{"key":"2_CR27","unstructured":"Robertson, W., Maggi, F., Kruegel, C., Vigna, G.: Effective anomaly detection with scarce training data. In: Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA (February 2010)"},{"key":"2_CR28","volume-title":"Data Compression: The Complete Reference","author":"D. Salomon","year":"2007","unstructured":"Salomon, D.: Data Compression: The Complete Reference. Springer, Heidelberg (2007)"},{"key":"2_CR29","doi-asserted-by":"crossref","unstructured":"Sommer, R., Paxson, V.: Outside the closed world: On using machine learning for network intrusion detection. In: IEEE Symposium on Security and Privacy, pp. 305\u2013316 (2010)","DOI":"10.1109\/SP.2010.25"},{"key":"2_CR30","unstructured":"Song, Y., Keromytis, A.D., Stolfo, S.J.: Spectrogram: A mixture-of-markov-chains model for anomaly detection in web traffic. In: Proc. of Network and Distributed System Security Symposium, NDSS (2009)"},{"key":"2_CR31","volume-title":"Algorithmic Learning in a Random World","author":"V. Vovk","year":"2005","unstructured":"Vovk, V., Gammerman, A., Shafer, G.: Algorithmic Learning in a Random World. Springer-Verlag New York, Inc., Secaucus (2005)"},{"key":"2_CR32","first-page":"255","volume-title":"Proceedings of the 9th ACM Conference on Computer and Communications Security, CCS 2002","author":"D. Wagner","year":"2002","unstructured":"Wagner, D., Soto, P.: Mimicry attacks on host-based intrusion detection systems. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, CCS 2002, pp. 255\u2013264. ACM, New York (2002)"},{"key":"2_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1007\/11856214_12","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2006","unstructured":"Wang, K., Parekh, J.J., Stolfo, S.J.: Anagram: A Content Anomaly Detector Resistant to Mimicry Attack. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol.\u00a04219, pp. 226\u2013248. Springer, Heidelberg (2006)"},{"key":"2_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection","author":"K. Wang","year":"2004","unstructured":"Wang, K., Stolfo, S.J.: Anomalous Payload-Based Network Intrusion Detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.\u00a03224, pp. 203\u2013222. Springer, Heidelberg (2004)"},{"issue":"3","key":"2_CR35","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1080\/00401706.1962.10490022","volume":"4","author":"B.P. Welford","year":"1962","unstructured":"Welford, B.P.: Note on a method for calculating corrected sums of squares and products. Technometrics\u00a04(3), 419\u2013420 (1962)","journal-title":"Technometrics"},{"key":"2_CR36","unstructured":"Wojtczuk, R.: Libnids (2011), http:\/\/libnids.sourceforge.net\/ (Online; accessed May 9, 2011)"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-31909-9_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,29]],"date-time":"2022-01-29T13:47:26Z","timestamp":1643464046000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-31909-9_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642319082","9783642319099"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-31909-9_2","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2012]]}}}