{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T13:40:02Z","timestamp":1746279602660,"version":"3.40.4"},"publisher-location":"Berlin, Heidelberg","reference-count":22,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783662438619"},{"type":"electronic","value":"9783662438626"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-662-43862-6_19","type":"book-chapter","created":{"date-parts":[[2014,6,25]],"date-time":"2014-06-25T03:51:34Z","timestamp":1403668294000},"page":"160-172","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing Network Intrusion Detection by Correlation of Modularly Hashed Sketches"],"prefix":"10.1007","author":[{"given":"Martin","family":"Dra\u0161ar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tom\u00e1\u0161","family":"Jirs\u00edk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Vizv\u00e1ry","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"3","key":"19_CR1","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1145\/357830.357849","volume":"3","author":"S. Axelsson","year":"2000","unstructured":"Axelsson, S.: The Base-rate Fallacy and the Difficulty of Intrusion Detection. ACM Trans. Inf. Syst. Secur.\u00a03(3), 186\u2013205 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"issue":"7","key":"19_CR2","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1016\/j.comcom.2012.01.016","volume":"35","author":"P. Casas","year":"2012","unstructured":"Casas, P., Mazel, J., Owezarski, P.: Unsupervised Network Intrusion Detection Systems: Detecting the Unknown without Knowledge. Computer Communications\u00a035(7), 772\u2013783 (2012)","journal-title":"Computer Communications"},{"key":"19_CR3","doi-asserted-by":"crossref","unstructured":"Cormode, G., Muthukrishnan, S.: What\u2019s new: finding significant differences in network data streams. In: Proceedings of the IEEE INFOCOM, vol.\u00a03, pp. 1534\u20131545 (2004)","DOI":"10.1109\/INFCOM.2004.1354567"},{"key":"19_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1007\/978-3-642-40552-5_30","volume-title":"Advances in Communication Networking","author":"M. Dra\u0161ar","year":"2013","unstructured":"Dra\u0161ar, M.: Protocol-Independent Detection of Dictionary Attacks. In: Bauschert, T. (ed.) EUNICE 2013. LNCS, vol.\u00a08115, pp. 304\u2013309. Springer, Heidelberg (2013)"},{"key":"19_CR5","doi-asserted-by":"crossref","unstructured":"Fontugne, R., Borgnat, P., Abry, P., Fukuda, K.: MAWILab: Combining Diverse Anomaly Detectors for Automated Anomaly Labeling and Performance Benchmarking. In: Proceedings of the 6th International Conference, Co-NEXT 2010, pp. 8:1\u20138:12. ACM, New York (2010)","DOI":"10.1145\/1921168.1921179"},{"key":"19_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-20757-0_1","volume-title":"NETWORKING 2011","author":"J. Fran\u00e7ois","year":"2011","unstructured":"Fran\u00e7ois, J., Wang, S., State, R., Engel, T.: BotTrack: Tracking Botnets Using NetFlow and PageRank. In: Domingo-Pascual, J., Manzoni, P., Palazzo, S., Pont, A., Scoglio, C. (eds.) NETWORKING 2011, Part I. LNCS, vol.\u00a06640, pp. 1\u201314. Springer, Heidelberg (2011)"},{"key":"19_CR7","unstructured":"Goldfarb, J.: Identifying Anomalous Network Traffic Through the Use of Client Port Distribution. In: CERT FloCon Workshop, Vancouver, Washington, USA (2006), http:\/\/www.cert.org\/flocon\/2006\/presentations\/clientport_dist1205.pdf (January 11, 2014)"},{"key":"19_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1007\/978-3-642-30633-4_11","volume-title":"Dependable Networks and Services","author":"L. Hellemons","year":"2012","unstructured":"Hellemons, L., Hendriks, L., Hofstede, R., Sperotto, A., Sadre, R., Pras, A.: SSHCure: A Flow-Based SSH Intrusion Detection System. In: Sadre, R., Novotn\u00fd, J., \u010celeda, P., Waldburger, M., Stiller, B. (eds.) AIMS 2012. LNCS, vol.\u00a07279, pp. 86\u201397. Springer, Heidelberg (2012)"},{"key":"19_CR9","doi-asserted-by":"crossref","unstructured":"Id\u00e9, T., Papadimitriou, S., Vlachos, M.: Computing Correlation Anomaly Scores Using Stochastic Nearest Neighbors. In: Proceedings of the IEEE International Conference on Data Mining, pp. 523\u2013528 (2007)","DOI":"10.1109\/ICDM.2007.12"},{"key":"19_CR10","unstructured":"Ishibashi, K., Kondoh, T., Harada, S., Mori, T., Kawahara, R., Asano, S.: Detecting Anomalies in Interhosts Communication Graph. In: CERT FloCon Workshop, Scottsdale, Arizona, USA (2009), http:\/\/www.cert.org\/flocon\/2009\/presentations\/Ishibashi_GraphAnomalies.pdf (accessed January 11, 2014)"},{"key":"19_CR11","first-page":"234","volume-title":"Proceedings of the 3rd ACM SIGCOMM, IMC 2003","author":"B. Krishnamurthy","year":"2003","unstructured":"Krishnamurthy, B., Sen, S., Zhang, Y., Chen, Y.: Sketch-based Change Detection: Methods, Evaluation, and Applications. In: Proceedings of the 3rd ACM SIGCOMM, IMC 2003, pp. 234\u2013247. ACM, New York (2003)"},{"key":"19_CR12","unstructured":"Network\u00a0Systems Lab. Opensketch (2013), https:\/\/github.com\/USC-NSL\/opensketch"},{"issue":"3","key":"19_CR13","first-page":"759","volume":"6","author":"A. Li","year":"2012","unstructured":"Li, A., Han, Y., Zhou, B., Han, W., Jia, Y.: Detecting Hidden Anomalies Using Sketch for High-speed Network Data Stream Monitoring. Applied Mathematics and Information Sciences\u00a06(3), 759\u2013765 (2012)","journal-title":"Applied Mathematics and Information Sciences"},{"key":"19_CR14","unstructured":"Mahimkar, A., Lall, A., Wang, J., Xu, J., Yates, J., Zhao, Q.: SYNERGY: Detecting and Diagnosing Correlated Network Anomalies, http:\/\/www.research.att.com\/export\/sites\/att_labs\/techdocs\/TD-7KEJWS.pdf (accessed January 11, 2014)"},{"key":"19_CR15","unstructured":"IEEE 802.3 Ethernet Working\u00a0Group. IEEE 802.3TM Industry Connections Ethernet Bandwidth Assessment (July 2012), http:\/\/www.ieee802.org\/3\/ad_hoc\/bwa\/BWA_Report.pdf"},{"key":"19_CR16","unstructured":"Synmatec Corporation. Internet Security Threat Report 2013 (April 2013), http:\/\/www.symantec.com\/security_response\/publications\/threatreport.jsp"},{"key":"19_CR17","unstructured":"Schweller, R., Chen, Y., Parsons, E., Gupta, A., Memik, G., Zhang, Y.: Reverse Hashing for Sketch-based Change Detection on High-speed Networks. Technical report, Proceedings of the INFOCOM (2004)"},{"key":"19_CR18","doi-asserted-by":"crossref","unstructured":"Schweller, R., Gupta, A., Parsons, E., Chen, Y.: Reversible Sketches for Efficient and Accurate Change Detection over Network Data Streams. In: Proceedings of the 4th ACM SIGCOMM, IMC 2004, pp. 207\u2013212. ACM, New York (2004)","DOI":"10.1145\/1028788.1028814"},{"key":"19_CR19","series-title":"CCIS","doi-asserted-by":"publisher","first-page":"666","DOI":"10.1007\/978-3-642-22714-1_69","volume-title":"Advances in Computing and Communications","author":"J. Vykopal","year":"2011","unstructured":"Vykopal, J.: A Flow-Level Taxonomy and Prevalence of Brute Force Attacks. In: Abraham, A., Lloret Mauri, J., Buford, J.F., Suzuki, J., Thampi, S.M. (eds.) ACC 2011, Part II. CCIS, vol.\u00a0191, pp. 666\u2013675. Springer, Heidelberg (2011)"},{"key":"19_CR20","unstructured":"Vykopal, J., Dra\u0161ar, M., Winter, P.: Flow-based Brute-force Attack Detection, pp. 41\u201351. Fraunhofer Research Institution AISEC, Garching near Muenchen (2013)"},{"key":"19_CR21","doi-asserted-by":"crossref","unstructured":"Yan, R., Shao, C.: Hierarchical Method for Anomaly Detection and Attack Identification in High-speed Network. Information Technology Journal\u00a011(9), 1243\u20131250 (2012)","DOI":"10.3923\/itj.2012.1243.1250"},{"key":"19_CR22","first-page":"101","volume-title":"Proceedings of the 4th ACM SIGCOMM, IMC 2004","author":"Y. Zhang","year":"2004","unstructured":"Zhang, Y., Singh, S., Sen, S., Duffield, N., Lund, C.: Online Identification of Hierarchical Heavy Hitters: Algorithms, Evaluation, and Applications. In: Proceedings of the 4th ACM SIGCOMM, IMC 2004, pp. 101\u2013114. ACM, New York (2004)"}],"container-title":["Lecture Notes in Computer Science","Monitoring and Securing Virtualized Networks and Services"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-43862-6_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,3]],"date-time":"2025-05-03T13:06:21Z","timestamp":1746277581000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-662-43862-6_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783662438619","9783662438626"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-43862-6_19","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}