{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T18:00:28Z","timestamp":1742925628210,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":30,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642358869"},{"type":"electronic","value":"9783642358876"}],"license":[{"start":{"date-parts":[[2013,1,1]],"date-time":"2013-01-01T00:00:00Z","timestamp":1356998400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-35887-6_8","type":"book-chapter","created":{"date-parts":[[2013,1,4]],"date-time":"2013-01-04T06:10:13Z","timestamp":1357279813000},"page":"150-168","source":"Crossref","is-referenced-by-count":1,"title":["Towards a Model- and Learning-Based Framework for Security Anomaly Detection"],"prefix":"10.1007","author":[{"given":"Matthias","family":"Gander","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Felderer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruth","family":"Breu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"unstructured":"Portnoy, L., Eskin, E., Stolfo, S.: Intrusion detection with unlabeled data using clustering. In: Proceedings of ACM CSS Workshop on Data Mining Applied to Security, Philadelphia, PA (2001)","key":"8_CR1"},{"unstructured":"Leung, K., Leckie, C.: Unsupervised anomaly detection in network intrusion detection using clusters. In: Proceedings of the Twenty-Eighth Australasian Conference on Computer Science, vol.\u00a038, pp. 333\u2013342. Australian Computer Society, Inc. (2005)","key":"8_CR2"},{"unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: Botminer: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: Proceedings of the 17th Conference on Security Symposium, pp. 139\u2013154. USENIX Association (2008)","key":"8_CR3"},{"doi-asserted-by":"crossref","unstructured":"Wang, W., Battiti, R.: Identifying intrusions in computer networks with principal component analysis. In: The First International Conference on Availability, Reliability and Security, ARES 2006, p. 8. IEEE (2006)","key":"8_CR4","DOI":"10.1109\/ARES.2006.73"},{"issue":"1-2","key":"8_CR5","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P. Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro, P., Diaz-Verdejo, J., Macia-Fernandez, G., Vazquez, E.: Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges. Computers & Security\u00a028(1-2), 18\u201328 (2009)","journal-title":"Computers & Security"},{"unstructured":"OMG: Omg uml specification, v2.0 (2005)","key":"8_CR6"},{"doi-asserted-by":"crossref","unstructured":"Breu, R., Innerhofer-Oberperfler, F., Yautsiukhin, A.: Quantitative assessment of enterprise security system. In: The Third International Conference on Availability, Reliability and Security, pp. 921\u2013928. IEEE (2008)","key":"8_CR7","DOI":"10.1109\/ARES.2008.164"},{"doi-asserted-by":"crossref","unstructured":"Innerhofer-Oberperfler, F., Breu, R., Hafner, M.: Living security \u2013 collaborative security management in a changing world. In: Parallel and Distributed Computing and Networks\/720: Software Engineering. ACTA Press (2011)","key":"8_CR8","DOI":"10.2316\/P.2011.720-006"},{"doi-asserted-by":"crossref","unstructured":"Breu, R.: Ten principles for living models-a manifesto of change-driven software engineering. In: 2010 International Conference on Complex, Intelligent and Software Intensive Systems, pp. 1\u20138. IEEE (2010)","key":"8_CR9","DOI":"10.1109\/CISIS.2010.73"},{"unstructured":"Berre, A.: Service oriented architecture modeling language (soaml)-specification for the uml profile and metamodel for services (upms) (2008)","key":"8_CR10"},{"unstructured":"Popescu, V., Smith, V., Pandit, B.: Service modeling language, version 1.1. W3C recommendation, W3C (May 2009), \n                    \n                      http:\/\/www.w3.org\/TR\/2009\/REC-sml-20090512\/","key":"8_CR11"},{"issue":"10","key":"8_CR12","doi-asserted-by":"publisher","first-page":"639","DOI":"10.1016\/S0950-5849(99)00016-6","volume":"41","author":"W. Aalst van der","year":"1999","unstructured":"van der Aalst, W.: Formalization and verification of event-driven process chains. Information and Software Technology\u00a041(10), 639\u2013650 (1999)","journal-title":"Information and Software Technology"},{"doi-asserted-by":"crossref","unstructured":"Mulo, E., Zdun, U., Dustdar, S.: Monitoring web service event trails for business compliance. In: 2009 IEEE International Conference on Service-Oriented Computing and Applications, SOCA, pp. 1\u20138. IEEE (2009)","key":"8_CR13","DOI":"10.1109\/SOCA.2009.5410273"},{"key":"8_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1007\/11607380_7","volume-title":"Technologies for E-Services","author":"L. Baresi","year":"2006","unstructured":"Baresi, L., Guinea, S., Plebani, P.: WS-Policy for Service Monitoring. In: Bussler, C.J., Shan, M.-C. (eds.) TES 2005. LNCS, vol.\u00a03811, pp. 72\u201383. Springer, Heidelberg (2006)"},{"doi-asserted-by":"crossref","unstructured":"Erradi, A., Maheshwari, P., Tosic, V.: WS-Policy based monitoring of composite web services (2007)","key":"8_CR15","DOI":"10.1109\/ECOWS.2007.31"},{"key":"8_CR16","series-title":"Lecture Notes in Artificial Intelligence","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1007\/978-3-540-24775-3_33","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"J. Oldmeadow","year":"2004","unstructured":"Oldmeadow, J., Ravinutala, S., Leckie, C.: Adaptive Clustering for Network Intrusion Detection. In: Dai, H., Srikant, R., Zhang, C. (eds.) PAKDD 2004. LNCS (LNAI), vol.\u00a03056, pp. 255\u2013259. Springer, Heidelberg (2004)"},{"issue":"1","key":"8_CR17","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1145\/300830.300837","volume":"2","author":"E. Bertino","year":"1999","unstructured":"Bertino, E., Ferrari, E., Atluri, V.: The specification and enforcement of authorization constraints in workflow management systems. ACM Transactions on Information and System Security (TISSEC)\u00a02(1), 65\u2013104 (1999)","journal-title":"ACM Transactions on Information and System Security (TISSEC)"},{"unstructured":"Godik, S., Moses, T. (eds.): eXtensible Access Control Markup Language (XACML) Version 1.0 (February 2003)","key":"8_CR18"},{"unstructured":"Walker-Morgan, D.: Vsftpd backdoor discovered in source code. Website (2011), \n                    \n                      http:\/\/h-online.com\/-1272310\n                    \n                    \n                   (visited: July 4, 2011)","key":"8_CR19"},{"unstructured":"Hoglund, G., Butler, J.: Rootkits: subverting the Windows kernel. Addison-Wesley Professional (2006)","key":"8_CR20"},{"doi-asserted-by":"crossref","unstructured":"Peikari, C., Chuvakin, A.: Security Warrior. O\u2019Reilly (2004)","key":"8_CR21","DOI":"10.1016\/S1353-4858(04)00117-5"},{"unstructured":"Wells, J.: Computer fraud casebook: the bytes that bite. John Wiley & Sons Inc. (2008)","key":"8_CR22"},{"doi-asserted-by":"crossref","unstructured":"Kozen, D.: Automata and computability. Springer (1997)","key":"8_CR23","DOI":"10.1007\/978-1-4612-1844-9"},{"unstructured":"McClure, S., Scambray, J., Kurtz, G.: Hacking exposed 6. McGraw-Hill (2009)","key":"8_CR24"},{"doi-asserted-by":"crossref","unstructured":"Allman, M., Paxson, V., Stevens, W.: RFC 2581 (rfc2581) - TCP Congestion Control. Technical Report 2581 (1999)","key":"8_CR25","DOI":"10.17487\/rfc2581"},{"unstructured":"Tan, P., Steinbach, M., Kumar, V.: Cluster Analysis: basic concepts and algorithms. In: Introduction to Data Mining. Addison-Wensley (2006)","key":"8_CR26"},{"doi-asserted-by":"crossref","unstructured":"OMG: Omg xmi specification, v1.2 (2002)","key":"8_CR27","DOI":"10.1016\/S1351-4180(02)00809-7"},{"doi-asserted-by":"crossref","unstructured":"Kruegel, C., Vigna, G.: Anomaly detection of web-based attacks. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, pp. 251\u2013261. ACM (2003)","key":"8_CR28","DOI":"10.1145\/948143.948144"},{"key":"8_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1007\/978-3-642-17358-5_25","volume-title":"Service-Oriented Computing","author":"P. Leitner","year":"2010","unstructured":"Leitner, P., Wetzstein, B., Karastoyanova, D., Hummer, W., Dustdar, S., Leymann, F.: Preventing SLA Violations in Service Compositions Using Aspect-Based Fragment Substitution. In: Maglio, P.P., Weske, M., Yang, J., Fantinato, M. (eds.) ICSOC 2010. LNCS, vol.\u00a06470, pp. 365\u2013380. Springer, Heidelberg (2010)"},{"unstructured":"Nicolett, M., Litan, A., Proctor, P.E.: Pattern Discovery With Security Monitoring and Fraud Detection Techniques (2009)","key":"8_CR30"}],"container-title":["Lecture Notes in Computer Science","Formal Methods for Components and Objects"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-35887-6_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T21:38:21Z","timestamp":1558301901000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-35887-6_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642358869","9783642358876"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-35887-6_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}