{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T01:23:05Z","timestamp":1744161785321},"publisher-location":"Berlin, Heidelberg","reference-count":28,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642452598"},{"type":"electronic","value":"9783642452604"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-45260-4_8","type":"book-chapter","created":{"date-parts":[[2013,11,18]],"date-time":"2013-11-18T09:56:14Z","timestamp":1384768574000},"page":"103-116","source":"Crossref","is-referenced-by-count":14,"title":["Anomaly Detection in the Cloud: Detecting Security Incidents via Machine Learning"],"prefix":"10.1007","author":[{"given":"Matthias","family":"Gander","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Felderer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adrian","family":"Tolbaru","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruth","family":"Breu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessandro","family":"Moschitti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"8_CR1","unstructured":"Amazon, EC: Amazon elastic compute cloud (amazon ec2). Amazon Elastic Compute Cloud, Amazon EC2 (2010)"},{"issue":"4","key":"8_CR2","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1145\/1721654.1721672","volume":"53","author":"M. Armbrust","year":"2010","unstructured":"Armbrust, M., Fox, A., Griffith, R., Joseph, A., Katz, R., Konwinski, A., Lee, G., Patterson, D., Rabkin, A., Stoica, I., et al.: A view of cloud computing. Communications of the ACM\u00a053(4), 50\u201358 (2010)","journal-title":"Communications of the ACM"},{"key":"8_CR3","doi-asserted-by":"crossref","unstructured":"Ristenpart, T., Tromer, E., Shacham, H., Savage, S.: Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, pp. 199\u2013212. ACM (2009)","DOI":"10.1145\/1653662.1653687"},{"key":"8_CR4","unstructured":"Walker-Morgan, D.: Vsftpd backdoor discovered in source code. Website (2011), http:\/\/h-online.com\/-1272310 (visited: July 4, 2011)"},{"key":"8_CR5","unstructured":"Hoglund, G., Butler, J.: Rootkits: subverting the Windows kernel. Addison-Wesley Professional (2006)"},{"key":"8_CR6","volume-title":"Intrusion Detection with Snort","author":"J. Koziol","year":"2003","unstructured":"Koziol, J.: Intrusion Detection with Snort, 1st edn. Sams, Indianapolis (2003)","edition":"1"},{"key":"8_CR7","unstructured":"Trend Micro, Inc.: Ossec documentation, http:\/\/www.ossec.net\/ (accessed: December 14, 2010)"},{"issue":"1-2","key":"8_CR8","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P. Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro, P., Diaz-Verdejo, J., Macia-Fernandez, G., Vazquez, E.: Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges. Computers & Security\u00a028(1-2), 18\u201328 (2009)","journal-title":"Computers & Security"},{"key":"8_CR9","unstructured":"Portnoy, L., Eskin, E., Stolfo, S.: Intrusion detection with unlabeled data using clustering. In: Proceedings of ACM CSS Workshop on Data Mining Applied to Security (2001)"},{"key":"8_CR10","unstructured":"Leung, K., Leckie, C.: Unsupervised anomaly detection in network intrusion detection using clusters. In: Proceedings of the Twenty-eighth Australasian Conference on Computer Science, vol.\u00a038, pp. 333\u2013342 (2005)"},{"issue":"3","key":"8_CR11","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V. Chandola","year":"2009","unstructured":"Chandola, V., Banerjee, A., Kumar, V.: Anomaly detection: A survey. ACM Computing Surveys (CSUR)\u00a041(3), 15 (2009)","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"8_CR12","unstructured":"Gu, G., Perdisci, R., Zhang, J., Lee, W.: Botminer: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: Proceedings of the 17th Conference on Security Symposium, pp. 139\u2013154 (2008)"},{"key":"8_CR13","doi-asserted-by":"crossref","unstructured":"Eckert, M., Bry, F.: Complex Event Processing, CEP (2009)","DOI":"10.1007\/s00287-009-0329-6"},{"key":"8_CR14","doi-asserted-by":"crossref","unstructured":"Breu, R., Innerhofer-Oberperfler, F., Yautsiukhin, A.: Quantitative assessment of enterprise security system. In: The Third International Conference on Availability, Reliability and Security, pp. 921\u2013928. IEEE (2008)","DOI":"10.1109\/ARES.2008.164"},{"key":"8_CR15","doi-asserted-by":"crossref","unstructured":"Innerhofer-Oberperfler, F., Breu, R., Hafner, M.: Living security collaborative security management in a changing world. In: Parallel and Distributed Computing and Networks\/720: Software Engineering. ACTA Press (2011)","DOI":"10.2316\/P.2011.720-006"},{"key":"8_CR16","doi-asserted-by":"crossref","unstructured":"Mulo, E., Zdun, U., Dustdar, S.: Monitoring web service event trails for business compliance. In: 2009 IEEE International Conference on Service-Oriented Computing and Applications (SOCA), pp. 1\u20138. IEEE (2009)","DOI":"10.1109\/SOCA.2009.5410273"},{"key":"8_CR17","unstructured":"Grohe, S., Schlameu, C., Sommer, R.: Performancevergleich von cep-engines. Technical report, Hochschulschriftenserver der Universitt Stuttgart, Germany (2010), http:\/\/elib.uni-stuttgart.de\/opus\/oai2\/oai2.php"},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"Denning, D.: An intrusion-detection model. IEEE Transactions on Software Engineering (2), 222\u2013232 (1987)","DOI":"10.1109\/TSE.1987.232894"},{"key":"8_CR19","unstructured":"Durgin, N.A., Zhang, P.: Profile-based adaptive anomaly detection for network security (2005)"},{"key":"8_CR20","unstructured":"Nicolett, M., Kelly, K.: 2012 Gartner Critical Capabilities and Magic Quadrant for SIEM (2012)"},{"key":"8_CR21","unstructured":"Tan, P., Steinbach, M., Kumar, V.: Cluster Analysis: basic concepts and algorithms. In: Introduction to Data Mining. Addison-Wensley (2006)"},{"issue":"1","key":"8_CR22","doi-asserted-by":"crossref","first-page":"85","DOI":"10.6339\/JDS.2005.03(1).192","volume":"3","author":"H. Finch","year":"2005","unstructured":"Finch, H.: Comparison of distance measures in cluster analysis with dichotomous data. Journal of Data Science\u00a03(1), 85\u2013100 (2005)","journal-title":"Journal of Data Science"},{"key":"8_CR23","unstructured":"Ester, M., Kriegel, H., Sander, J., Xu, X.: A density-based algorithm for discovering clusters in large spatial databases with noise. In: Proceedings of the 2nd International Conference on Knowledge Discovery and Data Mining, vol.\u00a01996, pp. 226\u2013231. AAAI Press (1996)"},{"key":"8_CR24","series-title":"Lecture Notes in Artificial Intelligence","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1007\/978-3-540-24775-3_33","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"J. Oldmeadow","year":"2004","unstructured":"Oldmeadow, J., Ravinutala, S., Leckie, C.: Adaptive clustering for network intrusion detection. In: Dai, H., Srikant, R., Zhang, C. (eds.) PAKDD 2004. LNCS (LNAI), vol.\u00a03056, pp. 255\u2013259. Springer, Heidelberg (2004)"},{"issue":"4","key":"8_CR25","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/MITP.2009.89","volume":"12","author":"K. Vieira","year":"2010","unstructured":"Vieira, K., Schulter, A., Westphall, C., Westphall, C.: Intrusion detection for grid and cloud computing. IT Professional\u00a012(4), 38\u201343 (2010)","journal-title":"IT Professional"},{"key":"8_CR26","unstructured":"Hernandez-Campos, F., Nobel, A., Smith, F., Jeffay, K.: Understanding patterns of tcp connection usage with statistical clustering. In: 13th IEEE International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems, pp. 35\u201344. IEEE (2005)"},{"key":"8_CR27","unstructured":"Berre, A.: Service oriented architecture modeling language (soaml)-specification for the uml profile and metamodel for services, upms (2008)"},{"issue":"10","key":"8_CR28","doi-asserted-by":"publisher","first-page":"639","DOI":"10.1016\/S0950-5849(99)00016-6","volume":"41","author":"W. Aalst van der","year":"1999","unstructured":"van der Aalst, W.: Formalization and verification of event-driven process chains. Information and Software Technology\u00a041(10), 639\u2013650 (1999)","journal-title":"Information and Software Technology"}],"container-title":["Communications in Computer and Information Science","Trustworthy Eternal Systems via Evolving Software, Data and Knowledge"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-45260-4_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,12]],"date-time":"2022-03-12T18:08:10Z","timestamp":1647108490000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-45260-4_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642452598","9783642452604"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-45260-4_8","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2013]]}}}