{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T13:40:02Z","timestamp":1746279602564,"version":"3.40.4"},"publisher-location":"Berlin, Heidelberg","reference-count":41,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783662436158"},{"type":"electronic","value":"9783662436165"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-662-43616-5_1","type":"book-chapter","created":{"date-parts":[[2014,6,26]],"date-time":"2014-06-26T08:04:57Z","timestamp":1403769897000},"page":"3-38","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A Bio-inspired Comprehensive Distributed Correlation Approach for Intrusion Detection Alerts and Events"],"prefix":"10.1007","author":[{"given":"Ayman M.","family":"Bahaa-Eldin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,6,27]]},"reference":[{"key":"1_CR1","unstructured":"Taha, A.E.: Intrusion detection correlation in computer network using multi-agent system. Ph.D. Thesis, University of Ain Shams, Cairo, Egypt, 2011"},{"key":"1_CR2","doi-asserted-by":"crossref","unstructured":"Tran, Q.A., Jiang, F., Ha, Q.M.: Evolving block-based neural network and field programmable gate arrays for host-based intrusion detection system. In: 2012 Fourth International Conference on Knowledge and Systems Engineering (KSE), IEEE, 2012","DOI":"10.1109\/KSE.2012.31"},{"key":"1_CR3","unstructured":"Elshoush, H.T., Osman, I.M.: An improved framework for intrusion alert correlation. Proceedings of the World Congress on Engineering, Vol I, pp. 1\u20136, 4\u20136 July. London, U.K (2012)"},{"key":"1_CR4","doi-asserted-by":"crossref","unstructured":"Tran, Q.A., Jiang, F., Hu, J.: A real-time netflow-based intrusion detection system with improved BBNN and high-frequency field programmable gate arrays. In: 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 2012","DOI":"10.1109\/TrustCom.2012.51"},{"issue":"2","key":"1_CR5","first-page":"64","volume":"2","author":"Georgios Spathoulas","year":"2013","unstructured":"Spathoulas, Georgios, Katsikas, Sokratis: Methods for post-processing of alerts in intrusion detection: a survey. Int. J. Inf.Secur. Sci. 2(2), 64\u201380 (2013)","journal-title":"Int. J. Inf.Secur. Sci."},{"key":"1_CR6","doi-asserted-by":"crossref","unstructured":"Jiang, F., Michael F., Hu, J.:A bio-inspired host-based multi-engine detection system with sequential pattern recognition. In: IEEE Ninth International Conference on Dependable, Autonomic and Secure Computing (DASC), 2011","DOI":"10.1109\/DASC.2011.46"},{"key":"1_CR7","doi-asserted-by":"crossref","unstructured":"Shittu, R. et al.: Visual analytic agent-based framework for intrusion alert analysis. In: IEEE International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), 2012","DOI":"10.1109\/CyberC.2012.41"},{"key":"1_CR8","doi-asserted-by":"crossref","unstructured":"Elshoush, H.T., Osman, I.M.: Intrusion alert correlation framework: an innovative approach. In: IAENG Transactions on Engineering Technologies, pp. 405\u2013420. Springer, The Netherlands (2013).","DOI":"10.1007\/978-94-007-6190-2_31"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Jiang, F., Ling, S.S.H., Agbinya, J.I.: A nature inspired anomaly detection system using multiple detection engines. In: IEEE 2011 6th International Conference on Broadband and Biomedical Communications (IB2Com), 2011","DOI":"10.1109\/IB2Com.2011.6217920"},{"key":"1_CR10","doi-asserted-by":"crossref","unstructured":"Bahaa-Eldin, A.M.: Time series analysis based models for network abnormal traffic detection. In: 2011 International Conference on Computer Engineering & Systems (ICCES), pp. 64\u201370, 29 Nov\u20131 Dec 2011. doi:10.1109\/ICCES.2011.6141013","DOI":"10.1109\/ICCES.2011.6141013"},{"key":"1_CR11","unstructured":"Tucker, C.J.: Performance Metrics for Network Intrusion Systems (2013)"},{"key":"1_CR12","unstructured":"Gabra, H.N., Bahaa-Eldin, A.M., Korashy H.:Classification of ids alerts with data mining techniques . In: 2012 International Conference on Internet Study (NETs2012), Bangkok, Thailand, 2012"},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Gabra, H.N., Bahaa-Eldin, A.M., Korashy HM.: Data mining based technique for IDS alerts classification. Int. J. Electron. Commer. Stud. 5(1), 1\u20136 (2014) (Academy of Taiwan Information Systems Research)","DOI":"10.7903\/ijecs.1392"},{"key":"1_CR14","doi-asserted-by":"crossref","unstructured":"Porras, P., Fong, M., Valdes, A.: A mission-impact-based approach to INFOSEC alarm correlation. In: Proceedings of the. International Symposium. The Recent Advances in Intrusion Detection, pp. 95\u2013114. Zurich, Switzerland, Oct 2002","DOI":"10.1007\/3-540-36084-0_6"},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"Long, W., Xin, Y., Yang, Y.: \u2018Vulnerabilities analyzing model for alert correlation in distributed environment. In: 2009 IITA International Conference on Services Science, Management and Engineering, pp. 408\u2013411. Nov 2009","DOI":"10.1109\/SSME.2009.132"},{"key":"1_CR16","doi-asserted-by":"crossref","unstructured":"Jiang,G., Member., Cybenko, G.: Temporal and spatial distributed event correlation for network security. In: Proceedings of the American Control Conference, 30 June\u20132 July 2004","DOI":"10.23919\/ACC.2004.1386701"},{"key":"1_CR17","unstructured":"Eid, M., Artail, H., Kayssi, A., Chehab, A.: A lightweight adaptive mobile agent-based intrusion detection system LAMAIDS. Int. J. Netw. Secur. 6(2), 145\u2013157 (2008)"},{"key":"1_CR18","unstructured":"Dastjerdi, A.V., Bakar, K.A.: A novel hybrid mobile agent based distributed intrusion detection system. In: Proceedings of World Academy of Science, Engineering and Technology, vol. 35. ISSN 2070\u20133740, Nov 2008"},{"key":"1_CR19","doi-asserted-by":"crossref","unstructured":"Liu, J., Li, L.: A distributed intrusion detection system based on agents. In: 2008 IEEE Pacific-Asia Workshop on Computational Intelligence and Industrial Application, pp. 553\u2013557, Dec 2008","DOI":"10.1109\/PACIIA.2008.143"},{"key":"1_CR20","unstructured":"Crosbie, M., Spafford, G.: Active defense of computer system using autonomous agent. Technical report no 95\u2013008, COAST group, computer science department, Purdue University, February, 1995"},{"key":"1_CR21","unstructured":"Balasubramaniyan, J.S., Spafford, E., Zamboniy, D.: An architecture for intrusion detection using autonomous agents. COAST technical report 98\/05, COAST Laboratory, Purdue University, 11 June 1998"},{"key":"1_CR22","doi-asserted-by":"crossref","unstructured":"Ktata, F.B., El-Kadhi, N., Ghedira, K.: Distributed agent architecture for intrusion detection based on new metrics. In: Proceeding 2009 Third International Conference on Network and System, Security, pp. 321\u2013327, Oct 2009","DOI":"10.1109\/NSS.2009.50"},{"key":"1_CR23","doi-asserted-by":"crossref","unstructured":"Mohamed, A.A., Basir, O.: Fusion based approach for distributed alarm correlation in computer networks. In: 2010 Second International Conference on Communication Software and Networks, pp. 318\u2013324, Feb 2010","DOI":"10.1109\/ICCSN.2010.65"},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Mohamed, A.A., Basir, O.: An adaptive multi-agent approach for distributed alarm correlation and fault identification. In: Proceedings of the Ninth IASTED International Conference on Parallel and Distributed Computing and Networks, Feb 2010","DOI":"10.2316\/P.2010.676-072"},{"key":"1_CR25","doi-asserted-by":"crossref","unstructured":"Valeur, F., Vigna, G., Kruegel, C., Kemmerer, R.A.: Comprehensive approach to intrusion detection alert correlation. IEEE Trans. Dependable Secure Comput. 1, 146\u201369 (2004)","DOI":"10.1109\/TDSC.2004.21"},{"key":"1_CR26","unstructured":"Valeur, F.: Real-time intrusion detection alert correlation, Ph.D. Thesis, University of California Santa Barbara, Santa Barbara, California, USA, (2006)"},{"key":"1_CR27","unstructured":"Kruegel, C., Valeur, F., Vigna, G.: Intrusion Detection and Correlation Challenges and Solutions. Springer, New York (2005). ISBN: 0-387-23398-9"},{"key":"1_CR28","unstructured":"David W Chadwick, \u201cNetwork Firewall Technologies\u201d, Technical Report, IS Institute, University of Salford, Salford, M5 4WT, England."},{"key":"1_CR29","unstructured":"Kak, A.: Port and Vulnerability Scanning, Packet Sniffing, Intrusion Detection, and Penetration Testing, Lecture Notes on Computer and Network Security, April 15, Purdue University (2014). https:\/\/engineering.purdue.edu\/kak\/compsec\/NewLectures\/Lecture23.pdf"},{"key":"1_CR30","unstructured":"Veysset, F., Butti, L.: Honey pot technologies. First Conference, France T\u00e9l\u00e9com R&D, June 2006"},{"key":"1_CR31","unstructured":"Wireshark, Network Protocol Analyzer. http:\/\/www.wireshark.org, June 2010"},{"key":"1_CR32","doi-asserted-by":"crossref","unstructured":"Taha, A.E., Ghaffar, I.A., Bahaa-Eldin, A.M., Mahdi, H.M.K.: Agent based correlation model for intrusion detection alerts. In: Proceeding of IEEE International Conference on Intelligence and Security Informatics (ISI 2010), pp. 89\u201394. Vancouver, Canada May 2010","DOI":"10.1109\/ISI.2010.5484771"},{"key":"1_CR33","doi-asserted-by":"crossref","unstructured":"Ghaffar, I.A.,Taha, A.E., Bahaa-Eldin, A.M., Mahdi, H.M.K.: Towards implementing agent based correlation model for real-time intrusion detection alerts. In: Proceeding of 7th International Conference on Electrical Engineering, ICEENG 2010, MTC, Cairo, Egypt, May 2010","DOI":"10.21608\/iceeng.2010.33007"},{"key":"1_CR34","doi-asserted-by":"crossref","unstructured":"Bahaa-Eldin, A.M., Mahdi, H.M.K., Taha, A.E., Ghaffar, I.A.: Dynamic Parallel correlation Model for intrusion detection alerts, posterIn. In: Annual Information Security Symposium of Center of Education and Research of Information Assurance and Security (CERIAS), Purdue University, West Lafayette. Indiana, USA, March 2010","DOI":"10.1109\/ISI.2010.5484771"},{"key":"1_CR35","unstructured":"Center of Education and Research for Information Assurance and Security (CERIAS). http:\/\/www.cerias.purdue.edu, June 2011"},{"key":"1_CR36","unstructured":"Snort\u2014the open source network intrusion prevention and detection system. http:\/\/www.snort.org (2010)"},{"key":"1_CR37","unstructured":"Basic Analysis and Security Engine (BASE). http:\/\/base.securei-deas.net\/about.php. June 2010"},{"key":"1_CR38","unstructured":"Nessus Vulnerabilty Scanner. http:\/\/www.nessus.org. June 2010"},{"key":"1_CR39","unstructured":"Nmap- Network Mapper, Security Scanner For Network Exploration & Hacking. http:\/\/nmap.org June, 2010"},{"key":"1_CR40","doi-asserted-by":"crossref","unstructured":"Templeton, S., Levitt, K.: A requires\/provides model for computer attacks. In: Proceedings of New Security Paradigms Workshop, pp. 31\u201338. ACM Press, Sept 2000","DOI":"10.1145\/366173.366187"},{"key":"1_CR41","doi-asserted-by":"crossref","unstructured":"Ning, P., Cui, Y., Reeves, D.S.: Constructing attack scenarios through correlation of intrusion alerts. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 245\u2013254. Washington, D.C., Nov 2002","DOI":"10.1145\/586110.586144"}],"container-title":["Intelligent Systems Reference Library","Bio-inspiring Cyber Security and Cloud Services: Trends and Innovations"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-43616-5_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T13:26:05Z","timestamp":1746278765000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-662-43616-5_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783662436158","9783662436165"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-43616-5_1","relation":{},"ISSN":["1868-4394","1868-4408"],"issn-type":[{"type":"print","value":"1868-4394"},{"type":"electronic","value":"1868-4408"}],"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"27 June 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}