{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T10:30:43Z","timestamp":1758709843417},"reference-count":46,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2015,2,14]],"date-time":"2015-02-14T00:00:00Z","timestamp":1423872000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2015,11]]},"DOI":"10.1007\/s10207-015-0276-y","type":"journal-article","created":{"date-parts":[[2015,2,13]],"date-time":"2015-02-13T05:37:53Z","timestamp":1423805873000},"page":"561-581","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["URL query string anomaly sensor designed with the bidimensional Haar wavelet transform"],"prefix":"10.1007","volume":"14","author":[{"given":"Alice","family":"Kozakevicius","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cristian","family":"Cappo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bruno A.","family":"Mozzaquatro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Raul Ceretta","family":"Nunes","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian E.","family":"Schaerer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,2,14]]},"reference":[{"issue":"1","key":"276_CR1","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/TDSC.2004.2","volume":"1","author":"A Avizienis","year":"2004","unstructured":"Avizienis, A., Laprie, J.C., Randell, B., Landwehr, C.: Basic concepts and taxonomy of dependable and secure computing. IEEE Trans. Dependable Secure Comput. 1(1), 11\u201333 (2004)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"276_CR2","unstructured":"Cavnar, W., Trenkle, J.: n-gram-based text categorization. In: SDAIR, pp. 161\u2013175 (1994)"},{"issue":"3","key":"276_CR3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V Chandola","year":"2009","unstructured":"Chandola, V., Banerjee, A., Kumar, V.: Anomaly detection: a survey. ACM Comput. Surv. 41(3), 1\u201358 (2009)","journal-title":"ACM Comput. Surv."},{"key":"276_CR4","unstructured":"CVE-2001-0500, C.: (2011). http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2001-0500 . Accessed Dec 2011"},{"key":"276_CR5","doi-asserted-by":"crossref","first-page":"843","DOI":"10.1126\/science.267.5199.843","volume":"5199","author":"M Damashek","year":"1995","unstructured":"Damashek, M.: Gauging similarity with n-grams: language-independent categorization of text. Science 5199, 843\u2013848 (1995)","journal-title":"Science"},{"key":"276_CR6","doi-asserted-by":"crossref","DOI":"10.1137\/1.9781611970104","volume-title":"Ten Lectures on Wavelets","author":"I Daubechies","year":"1992","unstructured":"Daubechies, I.: Ten Lectures on Wavelets. Society for Industrial and Applied Mathematics, Philadelphia, PA (1992)"},{"key":"276_CR7","doi-asserted-by":"crossref","first-page":"425","DOI":"10.1093\/biomet\/81.3.425","volume":"81","author":"D Donoho","year":"1994","unstructured":"Donoho, D., Johnstone, I.: Ideal spatial adaptation via wavelet shrinkage. Biometrika 81, 425\u2013455 (1994). doi: 10.1093\/biomet\/81.3.425","journal-title":"Biometrika"},{"key":"276_CR8","doi-asserted-by":"crossref","first-page":"1200","DOI":"10.1080\/01621459.1995.10476626","volume":"90","author":"D Donoho","year":"1995","unstructured":"Donoho, D., Johnstone, I.: Adapting to unknown smoothness via wavelet shrinkage. J. Am. Stat. Assoc. 90, 1200\u20131224 (1995)","journal-title":"J. Am. Stat. Assoc."},{"key":"276_CR9","doi-asserted-by":"crossref","unstructured":"Ficco, M., Coppolino, L., Romano, L.: A weight-based symptom correlation approach to sql injection attacks. In: Fourth Latin-American Symposium on Dependable Computing, 2009. LADC \u201909, pp. 9\u201316 (2009). doi: 10.1109\/LADC.2009.14","DOI":"10.1109\/LADC.2009.14"},{"key":"276_CR10","doi-asserted-by":"crossref","unstructured":"Fonseca, J., Vieira, M., Madeira, H.: The web attacker perspective\u2014a field study. In: 2010 IEEE 21st International Symposium on Software Reliability Engineering (ISSRE), pp. 299\u2013308 (2010). doi: 10.1109\/ISSRE.2010.21","DOI":"10.1109\/ISSRE.2010.21"},{"key":"276_CR11","doi-asserted-by":"crossref","unstructured":"Forrest, S., Hofmeyr, S., Somayaji, A., Longstaff, T.: A sense of self for unix processes. In: IEEE Symposium on Security and Privacy, pp. 120\u2013128 (1996)","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"276_CR12","unstructured":"Ghosh, A., Schwartzbard, A., Schatz, M.: Learning program behavior profiles for intrusion detection. In: USENIX Workshop on Intrusion Detection and Network Monitoring, pp. 51\u201362 (1999)"},{"issue":"11","key":"276_CR13","doi-asserted-by":"crossref","first-page":"2580","DOI":"10.1016\/j.csda.2009.12.010","volume":"54","author":"A Gran\u00e9","year":"2010","unstructured":"Gran\u00e9, A., Veiga, H.: Wavelet-based detection of outliers in financial time series. Comput. Stat. Data Anal. 54(11), 2580\u20132593 (2010). doi: 10.1016\/j.csda.2009.12.010","journal-title":"Comput. Stat. Data Anal."},{"issue":"3","key":"276_CR14","first-page":"309","volume":"6","author":"CT Huang","year":"2008","unstructured":"Huang, C.T., Thareja, S., Shin, Y.J.: Wavelet-based real time detection of network traffic anomalies. I. J. Netw. Secur. 6(3), 309\u2013320 (2008)","journal-title":"I. J. Netw. Secur."},{"key":"276_CR15","unstructured":"Ingham, K.L.: Anomaly detection for http intrusion detection: algorithm comparisons and the effect of generalization on accuracy. Ph.D. thesis, University of New Mexico (2007)"},{"key":"276_CR16","doi-asserted-by":"crossref","unstructured":"Ingham, K.L., Inoue, H.: Comparing anomaly detection techniques for http. In: Proceedings of the 10th International Conference on Recent Advances in Intrusion Detection. RAID\u201907, pp. 42\u201362. Springer, Berlin (2007)","DOI":"10.1007\/978-3-540-74320-0_3"},{"key":"276_CR17","doi-asserted-by":"crossref","first-page":"1239","DOI":"10.1016\/j.comnet.2006.09.016","volume":"51","author":"KL Ingham","year":"2007","unstructured":"Ingham, K.L., Somayaji, A., Burge, J., Forrest, S.: Learning dfa representations of http for protecting web applications. Comput. Netw. 51, 1239\u20131255 (2007)","journal-title":"Comput. Netw."},{"key":"276_CR18","doi-asserted-by":"crossref","unstructured":"Jamdagni, A., Tan, Z., Nanda, P., He, X., Liu, R.P.: Intrusion detection using gsad model for http traffic on web services. In: Proceedings of the 6th International Wireless Communications and Mobile Computing Conference, IWCMC \u201910, pp. 1193\u20131197. ACM, New York, NY (2010). doi: 10.1145\/1815396.1815669","DOI":"10.1145\/1815396.1815669"},{"key":"276_CR19","doi-asserted-by":"crossref","unstructured":"Kiani, M., Clark, A., Mohay, G.: Evaluation of anomaly based character distribution models in the detection of sql injection attacks. In: Third International Conference on Availability, Reliability and Security, 2008. ARES 08, pp. 47\u201355 (2008). doi: 10.1109\/ARES.2008.123","DOI":"10.1109\/ARES.2008.123"},{"key":"276_CR20","volume-title":"Intrusion Detection and Correlation: Challenges and Solutions","author":"C Kruegel","year":"2004","unstructured":"Kruegel, C., Valeur, F., Vigna, G.: Intrusion Detection and Correlation: Challenges and Solutions. Springer-Verlag TELOS, Santa Clara, CA (2004)"},{"key":"276_CR21","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Vigna, G.: Anomaly detection of web-based attacks. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, CCS \u201903, pp. 251\u2013261. ACM, New York, NY (2003). doi: 10.1145\/948109.948144","DOI":"10.1145\/948109.948144"},{"key":"276_CR22","doi-asserted-by":"crossref","first-page":"717","DOI":"10.1016\/j.comnet.2005.01.009","volume":"48","author":"C Kruegel","year":"2005","unstructured":"Kruegel, C., Vigna, G., Robertson, W.: A multi-model approach to the detection of web-based attacks. Comput. Netw. 48, 717\u2013738 (2005). doi: 10.1016\/j.comnet.2005.01.009","journal-title":"Comput. Netw."},{"key":"276_CR23","doi-asserted-by":"crossref","unstructured":"Krueger, T., Gehl, C., Rieck, K., Laskov, P.: Tokdoc: a self-healing web application firewall. In: Proceedings of the 2010 ACM Symposium on Applied Computing, SAC \u201910, pp. 1846\u20131853. ACM, New York, NY (2010). doi: 10.1145\/1774088.1774480","DOI":"10.1145\/1774088.1774480"},{"key":"276_CR24","doi-asserted-by":"crossref","unstructured":"Kr\u00fcgel, C., Toth, T., Kirda, E.: Service specific anomaly detection for network intrusion detection. In: Proceedings of the 2002 ACM Symposium on Applied Computing, SAC \u201902, pp. 201\u2013208. ACM, New York, NY (2002). doi: 10.1145\/508791.508835","DOI":"10.1145\/508791.508835"},{"key":"276_CR25","first-page":"1","volume":"4","author":"W Lu","year":"2009","unstructured":"Lu, W., Ghorbani, A.A.: Network anomaly detection based on wavelet analysis. EURASIP J. Adv. Signal Process 4, 1\u201316 (2009). doi: 10.1155\/2009\/837601","journal-title":"EURASIP J. Adv. Signal Process"},{"key":"276_CR26","first-page":"49","volume":"12","author":"P Mahalanobis","year":"1936","unstructured":"Mahalanobis, P.: On the generalized distance in statistics. Proc. Natl. Inst. Sci. Calcutta 12, 49\u201355 (1936)","journal-title":"Proc. Natl. Inst. Sci. Calcutta"},{"key":"276_CR27","unstructured":"Mallat, S.: A Wavelet Tour of Signal Processing, 3rd edn. Elsevier\/Academic Press, Amsterdam (2009). The sparse way, With contributions from Gabriel Peyr\u00e9"},{"issue":"2","key":"276_CR28","first-page":"112","volume":"2","author":"B Mozzaquatro","year":"2011","unstructured":"Mozzaquatro, B., Azevedo, R.P., Nunes, R., Kozakevicius, A., Cappo, C., Schaerer, C.: Anomaly-based techniques for web attacks detection. J. Appl. Comput. Res. 2(2), 112\u2013120 (2011)","journal-title":"J. Appl. Comput. Res."},{"key":"276_CR29","unstructured":"OWASP, T.O.W.A.S.P.: Top 10 web application security risks (2010). http:\/\/www.owasp.org\/index.php\/Top10"},{"key":"276_CR30","doi-asserted-by":"crossref","unstructured":"Patcha, A., Park, J.M.: An overview of anomaly detection techniques: existing solutions and latest technological trends. Comput. Netw. 51(12), 3448\u20133470 (2007). doi: 10.1016\/j.comnet.2007.02.001","DOI":"10.1016\/j.comnet.2007.02.001"},{"key":"276_CR31","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1080\/14786440009463897","volume":"50","author":"K Pearson","year":"1900","unstructured":"Pearson, K.: On a criterion that a given system of deviations from the probable in the case of correlated system of variables is duch that it can be reasonably supposed to have arisen from random sampling. Philos. Mag. 50, 157\u2013175 (1900)","journal-title":"Philos. Mag."},{"key":"276_CR32","doi-asserted-by":"crossref","unstructured":"Rieck, K., Laskov, P.: Detecting Unknown Network Attacks Using Language Models, Lecture Notes in Computer Science, vol. 4064, pp. 74\u201390. Springer, Berlin (2006). doi: 10.1007\/11790754_5","DOI":"10.1007\/11790754_5"},{"key":"276_CR33","unstructured":"Robertson, W., Vigna, G., Kruegel, C., Kemmerer, R.: Using generalization and characterization techniques in the anomaly-based detection of web attacks. In: Proceeding of the Network and Distributed System Security Symposium (NDSS). San Diego, CA (2006)"},{"key":"276_CR34","unstructured":"Robertson, W.K.: Detecting and preventing attacks against web applications. Ph.D. thesis, University of California, Santa Barbara (2009)"},{"key":"276_CR35","volume-title":"Hacking Exposed Web Applications","author":"J Scambray","year":"2011","unstructured":"Scambray, J., Liu, V., Sima, C.: Hacking Exposed Web Applications. Mc Graw Hill, New York (2011)"},{"key":"276_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"891","DOI":"10.1007\/978-3-642-01307-2_93","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"G Singh","year":"2009","unstructured":"Singh, G., Masseglia, F., Fiot, C., Marascu, A., Poncelet, P.: Data mining for intrusion detection: from outliers to true intrusions. In: Theeramunkong, T., Kijsirikul, B., Cercone, N., Ho, T.B. (eds.) Advances in Knowledge Discovery and Data Mining. Lecture Notes in Computer Science, vol. 5476, pp. 891\u2013898. Springer, Berlin (2009)"},{"key":"276_CR37","unstructured":"Song, Y., Keromytis, A., Stolfo, S.: Spectrogram: a mixture-of-markov-chains model for anomaly detection in web traffic. In: Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS) San Diego, pp. 121\u2013135. Internet Society (2009)"},{"key":"276_CR38","doi-asserted-by":"crossref","unstructured":"Sriraghavan, R., Lucchese, L.: Data processing and anomaly detection in web-based applications. In: IEEE Workshop on Machine Learning for Signal Processing, 2008. MLSP 2008, pp. 187\u2013192 (2008). doi: 10.1109\/MLSP.2008.4685477","DOI":"10.1109\/MLSP.2008.4685477"},{"issue":"3","key":"276_CR39","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/38.376616","volume":"15","author":"E Stollnitz","year":"1995","unstructured":"Stollnitz, E., DeRose, A., Salesin, D.: Wavelets for computer graphics: a primer 1. IEEE Comput. Graph. Appl. 15(3), 76\u201384 (1995). doi: 10.1109\/38.376616","journal-title":"IEEE Comput. Graph. Appl."},{"key":"276_CR40","doi-asserted-by":"crossref","first-page":"372","DOI":"10.1145\/1111320.1111070","volume":"41","author":"Z Su","year":"2006","unstructured":"Su, Z., Wassermann, G.: The essence of command injection attacks in web applications. SIGPLAN Not. 41, 372\u2013382 (2006). doi: 10.1145\/1111320.1111070","journal-title":"SIGPLAN Not."},{"key":"276_CR41","unstructured":"Vulnerabilities, C.C., Exposures: common vulnerabilities and exposures (2011). http:\/\/www.cve.mitre.org . Accessed Dec 2011"},{"key":"276_CR42","unstructured":"Wagner, R., Fontoura, L.M., Nunes, R.C.: Tailoring rational unified process to contemplate the SSE-CMM. In: Latin American Conference on Informatics, CLEI 2011. Quito, Equador (2011)"},{"key":"276_CR43","doi-asserted-by":"crossref","unstructured":"Wang, K., Parekh, J., Stolfo, S.: Anagram: A content anomaly detector resistant to mimicry attack. In: Recent Adances in Intrusion Detection (RAID), pp. 226\u2013248 (2006)","DOI":"10.1007\/11856214_12"},{"key":"276_CR44","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection, Lecture Notes in Computer Science","author":"K Wang","year":"2004","unstructured":"Wang, K., Stolfo, S.: Anomalous payload-based network intrusion detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) Recent Advances in Intrusion Detection, Lecture Notes in Computer Science, vol. 3224, pp. 203\u2013222. Springer, Berlin (2004)"},{"issue":"2","key":"276_CR45","doi-asserted-by":"crossref","first-page":"217","DOI":"10.2307\/2983604","volume":"1","author":"F Yates","year":"1934","unstructured":"Yates, F.: Contingency table involving small numbers and the $$\\chi ^2$$ \u03c7 2 test. Suppl J R Stat Soc 1(2), 217\u2013235 (1934)","journal-title":"Suppl J R Stat Soc"},{"key":"276_CR46","doi-asserted-by":"crossref","unstructured":"Zhou, Z., Zhongwen, C., Tiecheng, Z., Xiaohui, G.: The study on network intrusion detection system of snort. In: 2010 2nd International Conference on Networking and Digital Society (ICNDS), vol. 2, pp. 194\u2013196 (2010). doi: 10.1109\/ICNDS.2010.5479341","DOI":"10.1109\/ICNDS.2010.5479341"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-015-0276-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-015-0276-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-015-0276-y","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,29]],"date-time":"2019-05-29T07:05:05Z","timestamp":1559113505000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-015-0276-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,2,14]]},"references-count":46,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2015,11]]}},"alternative-id":["276"],"URL":"https:\/\/doi.org\/10.1007\/s10207-015-0276-y","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,2,14]]}}}