{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2023,2,1]],"date-time":"2023-02-01T18:32:56Z","timestamp":1675276376943},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2012,11,8]],"date-time":"2012-11-08T00:00:00Z","timestamp":1352332800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2013,4]]},"DOI":"10.1007\/s10207-012-0178-1","type":"journal-article","created":{"date-parts":[[2012,11,7]],"date-time":"2012-11-07T01:32:53Z","timestamp":1352251973000},"page":"97-110","source":"Crossref","is-referenced-by-count":4,"title":["Evaluation in the absence of absolute ground truth: toward reliable evaluation methodology for scan detectors"],"prefix":"10.1007","volume":"12","author":[{"given":"Mansour","family":"Alsaleh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"P. C.","family":"van Oorschot","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2012,11,8]]},"reference":[{"key":"178_CR1","doi-asserted-by":"crossref","unstructured":"Allman, M., Paxson, V., Terrell, J.: A brief history of scanning. In: Proceedings the 7th ACM SIGCOMM Conference on Internet Measurement (2007)","DOI":"10.1145\/1298306.1298316"},{"issue":"3","key":"178_CR2","doi-asserted-by":"crossref","first-page":"186","DOI":"10.1145\/357830.357849","volume":"3","author":"S Axelsson","year":"2000","unstructured":"Axelsson, S.: The base-rate fallacy and the difficulty of intrusion detection. ACM Trans. Inf. Syst. Secur. (TISSEC). 3(3), 186\u2013205 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)."},{"key":"178_CR3","unstructured":"Bro intrusion detection system. http:\/\/bro-ids.org\/ . Accessed May 2010"},{"key":"178_CR4","unstructured":"Casado, M., Freedman, M.J.: Peering through the shroud: the effect of edge opacity on IP-based client identification. In: 4th USENIX Symposium on Networked Systems Design and Implementation (NDSS\u201907) (2007)"},{"key":"178_CR5","unstructured":"Coull, S.E., Wright, C.V., Monrose, F., Collins, M.P., Reiter, M.K.: Playing devil\u2019s advocate: inferring sensitive information from anonymized network traces. In: NDSS (2007)"},{"key":"178_CR6","doi-asserted-by":"crossref","first-page":"392","DOI":"10.1109\/90.944338","volume":"9","author":"S Floyd","year":"2001","unstructured":"Floyd, S., Paxson, V.: Difficulties in simulating the internet. IEEE\/ACM Trans. Netw. 9, 392\u2013403 (2001)","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"178_CR7","unstructured":"Gates, C.: Co-ordinated port scans: a model, a detector and an evaluation methodology. PhD thesis, Dalhousie University (2006)"},{"key":"178_CR8","doi-asserted-by":"crossref","unstructured":"Gates, C., McNutt, J.J., Kadane, J.B., Kellner, M.: Scan detection on very large networks using logistic regression modeling. In: Proceedings of the 11th IEEE Symposium on Computers and Communications (ISCC\u201906) (2006)","DOI":"10.1109\/ISCC.2006.142"},{"key":"178_CR9","doi-asserted-by":"crossref","unstructured":"Heberlein, L.T., Dias, G.V., Levitt, K.N., Mukherjee, B., Wood, J., Wolber, D.: A network security monitor. In: IEEE Symposium on Security and Privacy, p. 296 (1990)","DOI":"10.2172\/6223037"},{"key":"178_CR10","unstructured":"Jin, R., Ghahramani, Z.: Learning with multiple labels. Adv. Neural Inf. Process. Syst. 15, 897\u2013904 (2002)"},{"key":"178_CR11","unstructured":"Jung, J.: Real-time detection of malicious network activity using stochastic models. PhD thesis, Massachusetts Institute of Technology (2006)"},{"key":"178_CR12","doi-asserted-by":"crossref","unstructured":"Jung, J., Paxson, V., Berger, A.W., Balakrishnan, H.: Fast portscan detection using sequential hypothesis testing. In: IEEE Symposium on Security and Privacy (2004)","DOI":"10.1109\/SECPRI.2004.1301325"},{"key":"178_CR13","doi-asserted-by":"crossref","unstructured":"Kang, M.G., Caballero, J., Song, D.: Distributed evasive scan techniques and countermeasures. In: Proceedings of the Conference on Detection of Intrusions and Malware and Vulnerability Assessment (2007)","DOI":"10.1007\/978-3-540-73614-1_10"},{"issue":"11","key":"178_CR14","first-page":"1817","volume":"E82\u2013B","author":"N Kato","year":"1999","unstructured":"Kato, N., Nitou, H., Ohta, K., Mansfield, G., Nemoto, Y.: A real-time intrusion detection system (IDS) for large scale networks and its evaluations. IEICE Trans. Commun. E82\u2013B(11), 1817\u20131825 (1999)","journal-title":"IEICE Trans. Commun."},{"key":"178_CR15","unstructured":"KDD cup data. http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html . Accessed Jan 2010"},{"key":"178_CR16","doi-asserted-by":"crossref","unstructured":"Kim, H., Kim, S., Kouritzin, M.A., Sun, W.: Detecting network portscans through anomaly detection. In: Proceedings of SPIE: Signal Processing, Sensor Fusion, and Target Recognition XIII, vol. 5429, p. 254 (2004)","DOI":"10.1117\/12.546127"},{"issue":"5","key":"178_CR17","doi-asserted-by":"crossref","first-page":"553","DOI":"10.1109\/3468.618255","volume":"27","author":"L Lam","year":"1997","unstructured":"Lam, L., Suen, S.: Application of majority voting to pattern recognition: an analysis of its behavior and performance. IEEE Trans. Syst. Man Cybern. A Syst. Hum. 27(5), 553\u2013568 (1997)","journal-title":"IEEE Trans. Syst. Man Cybern. A Syst. Hum."},{"key":"178_CR18","unstructured":"Leckie, C., Kotagiri, R.: A probabilistic approach to detecting network scans. In: Proceedings of the Eighth IEEE Network Operations and Management, Symposium (NOMS\u201902) (2002)"},{"key":"178_CR19","doi-asserted-by":"crossref","unstructured":"Li, Z., Goyal, A., Chen, Y.: Honeynet-based botnet scan traffic analysis. In: Botnet detection: countering the largest security threat. Advances in information security, vol. 36, pp. 25\u201344 (2008)","DOI":"10.1007\/978-0-387-68768-1_2"},{"key":"178_CR20","doi-asserted-by":"crossref","unstructured":"Li, Z., Goyal, A., Chen, Y., Paxson, V.: Automating analysis of large-scale botnet probing events. In: ASIACCS (2009)","DOI":"10.1145\/1533057.1533063"},{"issue":"4","key":"178_CR21","doi-asserted-by":"crossref","first-page":"579","DOI":"10.1016\/S1389-1286(00)00139-0","volume":"34","author":"R Lippmann","year":"2000","unstructured":"Lippmann, R., Haines, J., Fried, D., Korba, J., Das, K.: The 1999 DARPA off-line intrusion detection evaluation. Comput. Netw. 34(4), 579\u2013595 (2000)","journal-title":"Comput. Netw."},{"key":"178_CR22","unstructured":"Lippmann, R.P., Cunningham, R.K., Fried, D.J., Graf, I., Kendall, K.R., Webster, S.E., Zissman, M.A.: Results of the DARPA 1998 offline intrusion detection evaluation. In: Proceedings of the Symposium on Recent Advances in Intrusion Detection (RAID\u201999) (1999)"},{"key":"178_CR23","doi-asserted-by":"crossref","unstructured":"Mahoney, M.V., Chan, P.K.: An analysis of the 1999 DARPA \/Lincoln Laboratory evaluation data for network anomaly detection. In: Proceedings of the Sixth International Symposium on Recent Advances in Intrusion Detection (RAID\u201903) (2003)","DOI":"10.1007\/978-3-540-45248-5_13"},{"key":"178_CR24","doi-asserted-by":"crossref","unstructured":"Mason, J., Small, S., Monrose, F., MacManus, G.: English shellcode. In: Proceedings of the 16th ACM Conference on Computer and Communications Security (2009)","DOI":"10.1145\/1653662.1653725"},{"key":"178_CR25","doi-asserted-by":"crossref","first-page":"262","DOI":"10.1145\/382912.382923","volume":"3","author":"J McHugh","year":"2000","unstructured":"McHugh, J.: Testing intrusion detection systems: a critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by Lincoln laboratory. ACM Trans. Inf. Syst. Secur. (TISSEC) 3, 262\u2013294 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"178_CR26","unstructured":"Ptacek, T., Newsham, T., Simpson, H.J.: Insertion, evasion, and denial of service: eluding network intrusion detection. Technical report, Secure Networks, Inc., January (1998)"},{"key":"178_CR27","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1145\/1341431.1341443","volume":"38","author":"H Ringberg","year":"2008","unstructured":"Ringberg, H., Roughan, M., Rexford, J.: The need for simulation in evaluating anomaly detectors. SIGCOMM Comput. Commun. Rev. 38, 55\u201359 (2008)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"178_CR28","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1145\/1341431.1341437","volume":"38","author":"H Ringberg","year":"2008","unstructured":"Ringberg, H., Soule, A., Rexford, J.: WebClass: adding rigor to manual labeling of traffic anomalies. SIGCOMM Comput. Commun. Rev. 38, 35\u201338 (2008)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"178_CR29","unstructured":"Roelker, D., Norton, M., Hewlett, J.: sfPortscan. http:\/\/projects.cs.luc.edu\/comp412\/dredd\/docs\/software\/readmes\/sfsportscan . Accessed Jan 2010"},{"key":"178_CR30","unstructured":"Roesch, M.: Snort: lightweight intrusion detection for networks. In: Proceedings of the 13th Systems Administration Conference (LISA\u201999) (1999)"},{"key":"178_CR31","doi-asserted-by":"crossref","unstructured":"Sheng, V., Provost, F., Ipeirotis, P.: Get another label? Improving data quality and data mining using multiple, noisy labelers. In: Proceedings of the Conference on Knowledge Discovery and Data Mining (2008)","DOI":"10.1145\/1401890.1401965"},{"key":"178_CR32","doi-asserted-by":"crossref","unstructured":"Simon, G., Xiong, H., Eilertson, E., Kumar, V.: Scan detection: a data mining approach. In: Proceedings of the International Conference on Data Mining (SIAM\u201906) (2006)","DOI":"10.1137\/1.9781611972764.11"},{"key":"178_CR33","unstructured":"Designer, Solar., Magazine, Phrack.: Designing and attacking port scan detection tools. 8(53), July 8, 1998, article 13. http:\/\/www.phrack.org\/issues.html?issue=53&id=13#article"},{"key":"178_CR34","doi-asserted-by":"crossref","unstructured":"Sommer, R., Paxson, V.: Outside the closed world: on using machine learning for network intrusion detection. In: IEEE Symposium on Security and Privacy, May (2010)","DOI":"10.1109\/SP.2010.25"},{"key":"178_CR35","doi-asserted-by":"crossref","unstructured":"Staniford, S., Hoagland, J.A., McAlerney, J.M.: Practical automated detection of stealthy portscans. J. Comput. Secur. 10(1\/2), 105\u2013136 (2002)","DOI":"10.3233\/JCS-2002-101-205"},{"key":"178_CR36","unstructured":"Tcpdpriv. http:\/\/ita.ee.lbl.gov\/html\/contrib\/tcpdpriv.html . Accessed July 2010"},{"key":"178_CR37","unstructured":"Thabtah, F., Cowling, P., Peng, Y.: Multiple labels associative classification. Knowl. Inf. Syst. 9(1), 109\u2013129 (2006)"},{"key":"178_CR38","doi-asserted-by":"crossref","unstructured":"Vigna, G.: Network intrusion detection: dead or alive? In: Proceedings of the 26th Annual Computer Security Applications Conference (ACSAC\u201910) (2010)","DOI":"10.1145\/1920261.1920279"},{"key":"178_CR39","doi-asserted-by":"crossref","unstructured":"Weaver, N., Staniford, S., Paxson, V.: Very fast containment of scanning worms, revisited. In: Christodorescu, M., Jha, S., Maughan, D., Song, D., Wang, C. (eds.) Malware Detection. Advances in information security vol. 27, chap. 6. Springer, pp. 113\u2013145 (2007)","DOI":"10.1007\/978-0-387-44599-1_6"},{"key":"178_CR40","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Fang, B.: A novel approach to scan detection on the backbone. In: Sixth International Conference on Information Technology: New, Generations (ITNG\u201909), April (2009)","DOI":"10.1109\/ITNG.2009.16"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-012-0178-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-012-0178-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-012-0178-1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,5]],"date-time":"2019-07-05T05:42:42Z","timestamp":1562305362000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-012-0178-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,11,8]]},"references-count":40,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2013,4]]}},"alternative-id":["178"],"URL":"https:\/\/doi.org\/10.1007\/s10207-012-0178-1","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,11,8]]}}}