{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,29]],"date-time":"2026-01-29T21:58:37Z","timestamp":1769723917200,"version":"3.49.0"},"reference-count":21,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2015,1,30]],"date-time":"2015-01-30T00:00:00Z","timestamp":1422576000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Elektrotech. Inftech."],"published-print":{"date-parts":[[2015,3]]},"DOI":"10.1007\/s00502-015-0287-4","type":"journal-article","created":{"date-parts":[[2015,1,29]],"date-time":"2015-01-29T08:36:15Z","timestamp":1422520575000},"page":"101-105","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Cyber situational awareness through network anomaly detection: state of the art and new approaches","Cyber-Lagebildverst\u00e4ndnis mittels Netzwerk-Anomalieerkennung: Stand der Technik und neuartige Ans\u00e4tze"],"prefix":"10.1007","volume":"132","author":[{"given":"Ivo","family":"Friedberg","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian","family":"Skopik","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roman","family":"Fiedler","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,1,30]]},"reference":[{"key":"287_CR1","doi-asserted-by":"crossref","first-page":"118","DOI":"10.1007\/978-3-642-30633-4_15","volume-title":"Dependable networks and services","author":"V. Barto\u0161","year":"2012","unstructured":"Barto\u0161, V., \u017d\u00e1dn\u00edk, M. (2012): Network anomaly detection: comparison and real-time issues. In Dependable networks and services (pp. 118\u2013121). Berlin: Springer."},{"key":"287_CR2","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1109\/PST.2010.5593240","volume-title":"2010 Eighth annual international conference on privacy security and trust (PST)","author":"H. Binsalleeh","year":"2010","unstructured":"Binsalleeh, H., Ormerod, T., Boukhtouta, A., Sinha, P., Youssef, A., Debbabi, M., Wang, L. (2010): On the analysis of the zeus botnet crimeware toolkit. In 2010 Eighth annual international conference on privacy security and trust (PST) (pp. 31\u201338). New York: IEEE Press."},{"issue":"3","key":"287_CR3","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V. Chandola","year":"2009","unstructured":"Chandola, V., Banerjee, A., Kumar, V. (2009): Anomaly detection: a survey. ACM Comput. Surv. (CSUR), 41(3), 15.","journal-title":"ACM Comput. Surv. (CSUR)"},{"issue":"1","key":"287_CR4","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1518\/001872095779049543","volume":"37","author":"M. R. Endsley","year":"1995","unstructured":"Endsley, M. R. (1995): Toward a theory of situation awareness in dynamic systems. Hum. Factors, 37(1), 32\u201364.","journal-title":"Hum. Factors"},{"key":"287_CR5","unstructured":"European Commission (2013): Commission proposal for a directive concerning measures to ensure a high common level of network and information security across the union. http:\/\/ec.europa.eu\/digital-agenda\/en\/news\/commission-proposal-directive-concerning-measures-ensure-high-common-level-network-and ."},{"key":"287_CR6","unstructured":"Fracker, M. L. (1991): Measures of situation awareness: review and future directions. Technical Report AL-TR-1991-0128, Wright-Patterson Air Force Base."},{"key":"287_CR7","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1016\/j.cose.2014.09.006","volume":"48","author":"I. Friedberg","year":"2015","unstructured":"Friedberg, I., Skopik, F., Settanni, G., Fiedler, R. (2015): Combating advanced persistent threats: from network event correlation to incident detection. Comput. Secur., 48, 35\u201357.","journal-title":"Comput. Secur."},{"key":"287_CR8","first-page":"1","volume-title":"Cyber conflict","author":"J. L. Hernandez-Ardieta","year":"2013","unstructured":"Hernandez-Ardieta, J. L., Tapiador, J. E., Suarez-Tangil, G. (2013): Information sharing models for cooperative cyber defence. In Cyber conflict (pp. 1\u201328)."},{"key":"287_CR9","unstructured":"ISO (2012-03-20): Iso\/iec27010: Info. tech.: security techniques\u2014information security management for inter-sector and inter-organizational communications."},{"key":"287_CR10","unstructured":"ITU-T (2012): Recommendation itu-t x. 1500 cybersecurity info. exchange tech."},{"key":"287_CR11","volume-title":"Cyber situational awareness: issues and research","author":"S. Jajodia","year":"2009","unstructured":"Jajodia, S., Liu, P., Swarup, V., Wang, C. (2009): Cyber situational awareness: issues and research. Berlin: Springer."},{"key":"287_CR12","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1007\/978-3-642-30353-1_34","volume-title":"Advances in artificial intelligence","author":"G. Li","year":"2012","unstructured":"Li, G., Japkowicz, N., Yang, L. (2012): Anomaly detection via coupled Gaussian kernels. In Advances in artificial intelligence (pp. 343\u2013349). Berlin: Springer."},{"key":"287_CR13","unstructured":"NIST (2014-02-12): Framework for improving critical infrastructure cybersecurity."},{"key":"287_CR14","first-page":"23","volume-title":"3rd international conference on systems and networks communications","author":"F. Sabahi","year":"2008","unstructured":"Sabahi, F., Movaghar, A. (2008): Intrusion detection: a survey. In 3rd international conference on systems and networks communications, 2008, ICSNC\u201908 (pp. 23\u201326). New York: IEEE Press."},{"key":"287_CR15","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1207\/s15327108ijap0101_4","volume":"1","author":"N. D. Sarter","year":"1991","unstructured":"Sarter, N. D., Woods, D. D. (1991): Situation awareness: a critical but ill-defined phenomenon. Int. J. Aviat. Psychol., 1, 45\u201357.","journal-title":"Int. J. Aviat. Psychol."},{"issue":"8","key":"287_CR16","doi-asserted-by":"crossref","first-page":"2191","DOI":"10.1109\/TSP.2003.814797","volume":"51","author":"M. Thottan","year":"2003","unstructured":"Thottan, M., Ji, C. (2003): Anomaly detection in ip networks. IEEE Trans. Signal Process., 51(8), 2191\u20132204.","journal-title":"IEEE Trans. Signal Process."},{"key":"287_CR17","first-page":"1298","volume-title":"Proceedings of 2004 international conference on machine learning and cybernetics","author":"J. Yin","year":"2004","unstructured":"Yin, J., Zhang, G., Chen, Y.-Q., Fan, X.-L. (2004): Multi-events analysis for anomaly intrusion detection. In Proceedings of 2004 international conference on machine learning and cybernetics, 2004 (Vol.\u00a02, pp. 1298\u20131303). New York: IEEE Press."},{"issue":"1","key":"287_CR18","first-page":"9","volume":"28","author":"Y. Yu","year":"2012","unstructured":"Yu, Y. (2012): A survey of anomaly intrusion detection techniques. J. Comput. Sci. Coll., 28(1), 9\u201317.","journal-title":"J. Comput. Sci. Coll."},{"key":"287_CR19","first-page":"1","volume-title":"International symposium on computer network and multimedia technology","author":"W. Zhang","year":"2009","unstructured":"Zhang, W., Yang, Q., Geng, Y. (2009): A survey of anomaly detection methods in networks. In International symposium on computer network and multimedia technology, 2009, CNMT 2009 (pp. 1\u20133). New York: IEEE Press."},{"key":"287_CR20","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1109\/ISECS.2009.174","volume-title":"Second international symposium on electronic commerce and security","author":"Y.-l. Zhang","year":"2009","unstructured":"Zhang, Y.-l., Han, Z.-g., Ren, J.-x. (2009): A network anomaly detection method based on relative entropy theory. In Second international symposium on electronic commerce and security, 2009, ISECS\u201909 (Vol.\u00a01, pp. 231\u2013235). New York: IEEE Press."},{"key":"287_CR21","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1109\/ICCIIS.2010.48","volume-title":"2010 International conference on communications and intelligence information security (ICCIIS)","author":"Y. Zhao","year":"2010","unstructured":"Zhao, Y., Zheng, Z., Wen, H. (2010): Bayesian statistical inference in machine learning anomaly detection. In 2010 International conference on communications and intelligence information security (ICCIIS) (pp. 113\u2013116). New York: IEEE Press."}],"container-title":["e &amp; i Elektrotechnik und Informationstechnik"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00502-015-0287-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00502-015-0287-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00502-015-0287-4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,29]],"date-time":"2019-05-29T08:21:58Z","timestamp":1559118118000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00502-015-0287-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,1,30]]},"references-count":21,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,3]]}},"alternative-id":["287"],"URL":"https:\/\/doi.org\/10.1007\/s00502-015-0287-4","relation":{},"ISSN":["0932-383X","1613-7620"],"issn-type":[{"value":"0932-383X","type":"print"},{"value":"1613-7620","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,1,30]]}}}