{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,10]],"date-time":"2025-04-10T23:40:02Z","timestamp":1744328402653,"version":"3.40.4"},"publisher-location":"Berlin, Heidelberg","reference-count":32,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642347801"},{"type":"electronic","value":"9783642347818"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-34781-8_14","type":"book-chapter","created":{"date-parts":[[2012,10,11]],"date-time":"2012-10-11T15:20:37Z","timestamp":1349968837000},"page":"162-180","source":"Crossref","is-referenced-by-count":2,"title":["Monitoring Anomalies in IT-Landscapes Using Clustering Techniques and Complex Event Processing"],"prefix":"10.1007","author":[{"given":"Matthias","family":"Gander","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Felderer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruth","family":"Breu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"1-2","key":"14_CR1","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P. Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro, P., Diaz-Verdejo, J., Macia-Fernandez, G., Vazquez, E.: Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges. Computers & Security\u00a028(1-2), 18\u201328 (2009)","journal-title":"Computers & Security"},{"key":"14_CR2","unstructured":"Portnoy, L., Eskin, E., Stolfo, S.: Intrusion detection with unlabeled data using clustering. In: Proceedings of ACM CSS Workshop on Data Mining Applied to Security (2001)"},{"issue":"3","key":"14_CR3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V. Chandola","year":"2009","unstructured":"Chandola, V., Banerjee, A., Kumar, V.: Anomaly detection: A survey. ACM Comput. Surv.\u00a041(3), 15:1\u201315:58 (2009)","journal-title":"ACM Comput. Surv."},{"key":"14_CR4","doi-asserted-by":"crossref","unstructured":"Eckert, M., Bry, F.: Complex Event Processing, CEP (2009)","DOI":"10.1007\/s00287-009-0329-6"},{"key":"14_CR5","unstructured":"OMG: Omg uml specification, v2.0 (2005)"},{"key":"14_CR6","unstructured":"Moses, T.: eXtensible Access Control Markup Language TC v2.0 (XACML) (2005)"},{"issue":"1","key":"14_CR7","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1145\/300830.300837","volume":"2","author":"E. Bertino","year":"1999","unstructured":"Bertino, E., Ferrari, E., Atluri, V.: The specification and enforcement of authorization constraints in workflow management systems. ACM Transactions on Information and System Security (TISSEC)\u00a02(1), 65\u2013104 (1999)","journal-title":"ACM Transactions on Information and System Security (TISSEC)"},{"key":"14_CR8","unstructured":"Walker-Morgan, D.: Vsftpd backdoor discovered in source code. Website (2011), http:\/\/h-online.com\/-1272310 (accessed: July 20, 2012)"},{"key":"14_CR9","unstructured":"Hoglund, G., Butler, J.: Rootkits: subverting the Windows kernel. Addison-Wesley Professional (2006)"},{"key":"14_CR10","doi-asserted-by":"crossref","unstructured":"Peikari, C., Chuvakin, A.: Security Warrior. O\u2019Reilly (2004)","DOI":"10.1016\/S1353-4858(04)00117-5"},{"key":"14_CR11","unstructured":"Wells, J.: Computer fraud casebook: the bytes that bite. John Wiley & Sons Inc. (2008)"},{"issue":"7","key":"14_CR12","doi-asserted-by":"publisher","first-page":"810","DOI":"10.1109\/TC.2002.1017701","volume":"51","author":"N. Ye","year":"2002","unstructured":"Ye, N., Emran, S.M., Chen, Q., Vilbert, S.: Multivariate Statistical Analysis of Audit Trails for Host-based Intrusion Detection. IEEE Transactions on Computers\u00a051(7), 810\u2013820 (2002)","journal-title":"IEEE Transactions on Computers"},{"key":"14_CR13","unstructured":"Roesch, M.: Snort: Lightweight intrusion detection for networks. In: LISA, pp. 229\u2013238. USENIX (1999)"},{"key":"14_CR14","doi-asserted-by":"crossref","unstructured":"Breu, R., Innerhofer-Oberperfler, F., Yautsiukhin, A.: Quantitative assessment of enterprise security system. In: The Third International Conference on Availability, Reliability and Security, pp. 921\u2013928. IEEE (2008)","DOI":"10.1109\/ARES.2008.164"},{"key":"14_CR15","doi-asserted-by":"crossref","unstructured":"Innerhofer-Oberperfler, F., Breu, R., Hafner, M.: Living security collaborative security management in a changing world. In: Parallel and Distributed Computing and Networks\/720: Software Engineering. ACTA Press (2011)","DOI":"10.2316\/P.2011.720-006"},{"key":"14_CR16","unstructured":"Xtext, http:\/\/www.eclipse.org\/Xtext\/ (accessed: July 20, 2012)"},{"key":"14_CR17","doi-asserted-by":"crossref","unstructured":"Mulo, E., Zdun, U., Dustdar, S.: Monitoring web service event trails for business compliance. In: 2009 IEEE International Conference on Service-Oriented Computing and Applications (SOCA), pp. 1\u20138. IEEE (2009)","DOI":"10.1109\/SOCA.2009.5410273"},{"key":"14_CR18","unstructured":"Grohe, S., Schlameu, C., Sommer, R.: Performancevergleich von cep-engines. Technical report, Hochschulschriftenserver der Universitt Stuttgart (Germany) (2010), http:\/\/elib.uni-stuttgart.de\/opus\/oai2\/oai2.php"},{"key":"14_CR19","unstructured":"McClure, S., Scambray, J., Kurtz, G.: Hacking exposed 6. McGraw-Hill (2009)"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Allman, M., Paxson, V., Stevens, W.: RFC 2581 (rfc2581) - TCP Congestion Control. Technical Report 2581 (1999)","DOI":"10.17487\/rfc2581"},{"key":"14_CR21","unstructured":"Tan, P., Steinbach, M., Kumar, V.: Cluster Analysis: basic concepts and algorithms. In: Introduction to Data Mining, Addison-Wensley (2006)"},{"key":"14_CR22","doi-asserted-by":"crossref","unstructured":"Hernandez-Campos, F., Nobel, A.B., Smith, F.D., Jeffay, K.: Understanding patterns of tcp connection usage with statistical clustering. In: 13th IEEE International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems, pp. 35\u201344. IEEE (2005)","DOI":"10.1109\/MASCOTS.2005.75"},{"key":"14_CR23","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: Botminer: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: Proceedings of the 17th Conference on Security Symposium, pp. 139\u2013154 (2008)"},{"key":"14_CR24","unstructured":"Malerba, D., Esposito, F., Gioviale, V., Tamma, V.: Comparing dissimilarity measures for symbolic data analysis. In: Proceedings of Exchange of Technology and Know-how and New Techniques and Technologies for Statistics, vol.\u00a01, pp. 473\u2013481 (2001)"},{"key":"14_CR25","series-title":"Lecture Notes in Artificial Intelligence","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1007\/978-3-540-24775-3_33","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"J. Oldmeadow","year":"2004","unstructured":"Oldmeadow, J., Ravinutala, S., Leckie, C.: Adaptive Clustering for Network Intrusion Detection. In: Dai, H., Srikant, R., Zhang, C. (eds.) PAKDD 2004. LNCS (LNAI), vol.\u00a03056, pp. 255\u2013259. Springer, Heidelberg (2004)"},{"key":"14_CR26","unstructured":"Berre, A.: Service oriented architecture modeling language (soaml)-specification for the uml profile and metamodel for services (upms) (2008)"},{"key":"14_CR27","unstructured":"Popescu, V., Smith, V., Pandit, B.: Service modeling language, version 1.1. W3C recommendation, W3C (May 2009), http:\/\/www.w3.org\/TR\/2009\/REC-sml-20090512\/"},{"issue":"10","key":"14_CR28","doi-asserted-by":"publisher","first-page":"639","DOI":"10.1016\/S0950-5849(99)00016-6","volume":"41","author":"W. Aalst van der","year":"1999","unstructured":"van der Aalst, W.: Formalization and verification of event-driven process chains. Information and Software Technology\u00a041(10), 639\u2013650 (1999)","journal-title":"Information and Software Technology"},{"key":"14_CR29","doi-asserted-by":"crossref","unstructured":"Baresi, L., Guinea, S., Plebani, P.: WS-Policy for service monitoring. In: Technologies for E-Services, pp. 72\u201383 (2006)","DOI":"10.1007\/11607380_7"},{"key":"14_CR30","doi-asserted-by":"crossref","unstructured":"Erradi, A., Maheshwari, P., Tosic, V.: WS-Policy based monitoring of composite web services (2007)","DOI":"10.1109\/ECOWS.2007.31"},{"key":"14_CR31","unstructured":"Leung, K., Leckie, C.: Unsupervised anomaly detection in network intrusion detection using clusters. In: Proceedings of the Twenty-eighth Australasian Conference on Computer Science, vol.\u00a038, pp. 333\u2013342 (2005)"},{"issue":"4","key":"14_CR32","doi-asserted-by":"publisher","first-page":"471","DOI":"10.1145\/950191.950192","volume":"6","author":"K. Julisch","year":"2003","unstructured":"Julisch, K.: Clustering intrusion detection alarms to support root cause analysis. ACM Transactions on Information and System Security (TISSEC)\u00a06(4), 471 (2003)","journal-title":"ACM Transactions on Information and System Security (TISSEC)"}],"container-title":["Communications in Computer and Information Science","Leveraging Applications of Formal Methods, Verification, and Validation"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-34781-8_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,10]],"date-time":"2025-04-10T23:05:13Z","timestamp":1744326313000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-34781-8_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642347801","9783642347818"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-34781-8_14","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2012]]}}}