{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T14:10:06Z","timestamp":1744207806204,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":18,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642333378"},{"type":"electronic","value":"9783642333385"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-33338-5_15","type":"book-chapter","created":{"date-parts":[[2012,9,26]],"date-time":"2012-09-26T01:17:07Z","timestamp":1348622227000},"page":"294-313","source":"Crossref","is-referenced-by-count":10,"title":["ALERT-ID: Analyze Logs of the Network Element in Real Time for Intrusion Detection"],"prefix":"10.1007","author":[{"given":"Jie","family":"Chu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zihui","family":"Ge","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Richard","family":"Huber","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ping","family":"Ji","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jennifer","family":"Yates","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yung-Chao","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"15_CR1","unstructured":"Anderson, J.P.: Computer security threat monitoring and surveillance. Technical Report James P Anderson Co Fort Washington Pa, p.\u00a056 (1980)"},{"key":"15_CR2","unstructured":"Carrel, D., Grant, L.: The TACACS+ protocol (January 1997)"},{"key":"15_CR3","volume-title":"Proceedings of the 15th conference on USENIX Security Symposium","author":"H. Dreger","year":"2006","unstructured":"Dreger, H., Feldmann, A., Mai, M., Paxson, V., Sommer, R.: Dynamic application-layer protocol analysis for network intrusion detection. In: Proceedings of the 15th conference on USENIX Security Symposium, vol.\u00a015. USENIX Association, Berkeley (2006)"},{"key":"15_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1007\/978-3-642-02247-0_11","volume-title":"User Modeling, Adaptation, and Personalization","author":"J.A. Iglesias","year":"2009","unstructured":"Iglesias, J.A., Ledezma, A., Sanchis, A.: Creating User Profiles from a Command-Line Interface: A Statistical Approach. In: Houben, G.-J., McCalla, G., Pianesi, F., Zancanaro, M. (eds.) UMAP 2009. LNCS, vol.\u00a05535, pp. 90\u2013101. Springer, Heidelberg (2009)"},{"key":"15_CR5","doi-asserted-by":"publisher","first-page":"234","DOI":"10.1145\/948205.948236","volume-title":"Proceedings of the 3rd ACM SIGCOMM Conference on Internet Measurement, IMC 2003","author":"B. Krishnamurthy","year":"2003","unstructured":"Krishnamurthy, B., Sen, S., Zhang, Y., Chen, Y.: Sketch-based change detection: methods, evaluation, and applications. In: Proceedings of the 3rd ACM SIGCOMM Conference on Internet Measurement, IMC 2003, pp. 234\u2013247. ACM, New York (2003)"},{"key":"15_CR6","first-page":"279","volume-title":"Proceedings of the ACM SIGCOMM 2010 Conference on SIGCOMM, SIGCOMM 2010","author":"Z. Li","year":"2010","unstructured":"Li, Z., Xia, G., Gao, H., Tang, Y., Chen, Y., Liu, B., Jiang, J., Lv, Y.: Netshield: massive semantics-based vulnerability signature matching for high-speed networks. In: Proceedings of the ACM SIGCOMM 2010 Conference on SIGCOMM, SIGCOMM 2010, pp. 279\u2013290. ACM, New York (2010)"},{"key":"15_CR7","unstructured":"Lunt, T.F., Jagannathan, R., Lee, R., Listgarten, S., Edwards, D.L., Neumann, P.G., Javitz, H.S., Valdes, A., Lunt, T.F., Jagannathan, R., Lee, R., Listgarten, S., Edwards, D.L., Neumann, P.G., Javitz, H.S., Valdes, A.: Ides: The enhanced prototype - a real-time intrusion-detection expert system. Tech. rep., SRI International, 333 Ravenswood Avenue, Menlo Park (1988)"},{"key":"15_CR8","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1109\/TDSC.2008.69","volume":"7","author":"F. Maggi","year":"2010","unstructured":"Maggi, F., Matteucci, M., Zanero, S.: Detecting intrusions through system call sequence and argument analysis. IEEE Transactions on Dependable and Secure Computing\u00a07, 381\u2013395 (2010)","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Maronna, R., Martin, R., Yohai, V.: Robust statistics: theory and methods. Wiley series in probability and statistics. J. Wiley (2006)","DOI":"10.1002\/0470010940"},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Maxion, R.: Masquerade detection using enriched command lines. In: Proc. of 2003 International Conference on Dependable Systems and Networks, pp. 5\u201314 (June 2003)","DOI":"10.1109\/DSN.2003.1209911"},{"key":"15_CR11","doi-asserted-by":"publisher","first-page":"2435","DOI":"10.1016\/S1389-1286(99)00112-7","volume":"31","author":"V. Paxson","year":"1999","unstructured":"Paxson, V.: Bro: a system for detecting network intruders in real-time. Comput. Netw.\u00a031, 2435\u20132463 (1999)","journal-title":"Comput. Netw."},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Rigney, C., Willens, S., Rubens, A., Simpson, W.: Remote authentication dial in user service, radius (2000)","DOI":"10.17487\/rfc2865"},{"key":"15_CR13","unstructured":"Robertson, W., Maggi, F., Kruegel, C., Vigna, G.: Effective Anomaly Detection with Scarce Training Data. In: Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA (February 2010)"},{"key":"15_CR14","first-page":"229","volume-title":"Proceedings of the 13th USENIX Conference on System Administration, LISA 1999","author":"M. Roesch","year":"1999","unstructured":"Roesch, M.: Snort - lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration, LISA 1999, pp. 229\u2013238. USENIX Association, Berkeley (1999)"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Salem, M.B., Stolfo, S.J.: A comparison of one-class bag-of-words user behavior modeling techniques for masquerade detection. Security and Communication Networks (2011)","DOI":"10.1002\/sec.311"},{"key":"15_CR16","unstructured":"Song, Y., Keromytis, A.D., Stolfo, S.J.: Spectrogram: A mixture-of-markov-chains model for anomaly detection in web traffic. In: NDSS. The Internet Society (2009)"},{"key":"15_CR17","unstructured":"Stefan, A.: Intrusion detection systems: A survey and taxonomy. Technical Report 99(Technical report 99-15), 1\u201315 (2000)"},{"key":"15_CR18","first-page":"463","volume-title":"Proceedings of the 21st Annual Computer Security Applications Conference","author":"X. Suo","year":"2005","unstructured":"Suo, X., Zhu, Y., Owen, G.S.: Graphical passwords: A survey. In: Proceedings of the 21st Annual Computer Security Applications Conference, pp. 463\u2013472. IEEE Computer Society, Washington, DC (2005)"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-33338-5_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T13:30:38Z","timestamp":1744205438000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-642-33338-5_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642333378","9783642333385"],"references-count":18,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-33338-5_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2012]]}}}