{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T06:49:48Z","timestamp":1760597388697},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2009,7,23]],"date-time":"2009-07-23T00:00:00Z","timestamp":1248307200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J Comput Virol"],"published-print":{"date-parts":[[2010,8]]},"DOI":"10.1007\/s11416-009-0125-5","type":"journal-article","created":{"date-parts":[[2009,7,22]],"date-time":"2009-07-22T06:13:38Z","timestamp":1248243218000},"page":"239-259","source":"Crossref","is-referenced-by-count":11,"title":["Using the KBTA method for inferring computer and network security alerts from time-stamped, raw system metrics"],"prefix":"10.1007","volume":"6","author":[{"given":"Asaf","family":"Shabtai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Fledel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Shahar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,7,23]]},"reference":[{"key":"125_CR1","doi-asserted-by":"crossref","unstructured":"Kienzle, D.M., Elder, M.C.: Internet WORMS: past, present, and future: recent worms: a survey and trends. In: Proceedings of the ACM Workshop on Rapid Malcode (2003)","DOI":"10.1145\/948187.948189"},{"key":"125_CR2","unstructured":"Heidari, M.: Malicious codes in depth. Security docs. http:\/\/www.securitydocs.com\/pdf\/2742.PDF (2004)"},{"key":"125_CR3","unstructured":"Dikinson, J.: The new anti-virus formula. 2005. http:\/\/www.ironport.com\/pdf\/ironport_new_anti-virus_formula.pdf"},{"key":"125_CR4","doi-asserted-by":"crossref","unstructured":"Seleznyov, A., Mazhelis, O.: Learning temporal patterns for anomaly intrusion detection. In: Proceedings of the 17th ACM Symposium on Applied Computing (2002)","DOI":"10.1145\/508791.508836"},{"key":"125_CR5","unstructured":"Ye, N.: A Markov chain of temporal behavior for anomaly detection. In: Workshop on Information Assurance and Security (2000)"},{"issue":"1\u20132","key":"125_CR6","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1016\/S0004-3702(96)00025-2","volume":"90","author":"Y. Shahar","year":"1997","unstructured":"Shahar Y.: A framework for knowledge-based temporal abstraction. Artif. Intell. 90(1\u20132), 79\u2013133 (1997)","journal-title":"Artif. Intell."},{"issue":"3","key":"125_CR7","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1016\/0933-3657(95)00036-4","volume":"8","author":"Y. Shahar","year":"1996","unstructured":"Shahar Y., Musen M.A.: Knowledge-based temporal abstraction in clinical domains. Artif. Intell. Med. 8(3), 267\u2013298 (1996)","journal-title":"Artif. Intell. Med."},{"key":"125_CR8","unstructured":"Jones A.K., Sielken R.S.: Computer System Intrusion Detection: A Survey. Technical Report, Computer Science Department, University of Virginia, USA (2000)"},{"key":"125_CR9","unstructured":"Axelsson, S.: Intrusion Detection Systems: A Survey and Taxonomy. Technical Report, Department of Computer Engineering, Chalmers University, Sweden (2000)"},{"issue":"4","key":"125_CR10","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1145\/1013886.1007518","volume":"29","author":"M. Christodorescu","year":"2004","unstructured":"Christodorescu M., Jha S.: Testing malware detectors. ACM SIGSOFT Softw. Eng. Notes 29(4), 34\u201344 (2004)","journal-title":"ACM SIGSOFT Softw. Eng. Notes"},{"key":"125_CR11","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1007\/s11416-008-0086-0","volume":"4","author":"G. Jacob","year":"2008","unstructured":"Jacob G., Debar H., Filiol E.: Behavioral detection of malware: from a survey towards an established taxonomy. J. Comput. Virol. 4, 251\u2013266 (2008)","journal-title":"J. Comput. Virol."},{"key":"125_CR12","unstructured":"Idika, N., Mathur, A.P.: A Survey of Malware Detection Techniques. Technical Report, Department of Computer Science, Purdue University, USA (2007)"},{"issue":"16","key":"125_CR13","doi-asserted-by":"crossref","first-page":"1569","DOI":"10.1016\/j.comcom.2004.07.002","volume":"27","author":"J.M. Estevez-Tapiador","year":"2004","unstructured":"Estevez-Tapiador J.M. et\u00a0al.: Anomaly detection methods in wired networks: a survey and taxonomy. Comput. Commun. 27(16), 1569\u20131584 (2004)","journal-title":"Comput. Commun."},{"issue":"9","key":"125_CR14","doi-asserted-by":"crossref","first-page":"4544","DOI":"10.1016\/j.csda.2008.01.028","volume":"52","author":"R. Moskovitch","year":"2008","unstructured":"Moskovitch R., Elovici Y., Rokach L.: Detection of unknown computer worms based on behavioral classification of the host. Comput. Stat. Data. Anal. 52(9), 4544\u20134566 (2008)","journal-title":"Comput. Stat. Data. Anal."},{"issue":"3","key":"125_CR15","doi-asserted-by":"crossref","first-page":"295","DOI":"10.1145\/322510.322526","volume":"2","author":"T. Lane","year":"1999","unstructured":"Lane T., Brodley C.E.: Temporal sequence learning and data reduction for anomaly detection. ACM Trans. Inf. Syst. Secur. 2(3), 295\u2013331 (1999)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"125_CR16","unstructured":"Ghosh, A.K., Schwartzbard, A., Schatz, M.: Using program behavior profiles for intrusion detection. In: Proceedings of the 1st USENIX Workshop on Intrusion Detection and Network Monitoring (1999)"},{"key":"125_CR17","doi-asserted-by":"crossref","unstructured":"Naldurg, P. et\u00a0al.: A temporal logic based framework for intrusion detection. In: Proceedings of the 24th Formal Techniques for Networked and Distributed Systems International Conference (2004)","DOI":"10.1007\/978-3-540-30232-2_23"},{"issue":"4","key":"125_CR18","doi-asserted-by":"crossref","first-page":"407","DOI":"10.1145\/503339.503342","volume":"4","author":"P. Ning","year":"2001","unstructured":"Ning P., Jajodia S., Wang X.S.: Abstraction-based intrusion detection in distributed environments. ACM Trans. Inf. Syst. Secur. 4(4), 407\u2013452 (2001)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"125_CR19","doi-asserted-by":"crossref","unstructured":"Kohout, L.J., Yasinsac, A., McDuffie, E.: Activity profiles for intrusion detection. In: North American Fuzzy Information Processing Society-Fuzzy Logic and the Internet (2002)","DOI":"10.1109\/NAFIPS.2002.1018104"},{"issue":"11","key":"125_CR20","doi-asserted-by":"crossref","first-page":"832","DOI":"10.1145\/182.358434","volume":"26","author":"J.F. Allen","year":"1983","unstructured":"Allen J.F.: Maintaining knowledge about temporal intervals. Commun. ACM 26(11), 832\u2013843 (1983)","journal-title":"Commun. ACM"},{"issue":"1\u20132","key":"125_CR21","doi-asserted-by":"crossref","first-page":"137","DOI":"10.3233\/JCS-2002-101-206","volume":"10","author":"Y. Li","year":"2002","unstructured":"Li Y. et\u00a0al.: Enhancing profiles for anomaly detection using time granularities. J Comput. Secur. 10(1\u20132), 137\u2013157 (2002)","journal-title":"J Comput. Secur."},{"key":"125_CR22","doi-asserted-by":"crossref","unstructured":"Talbi, M., Mejry, M., Bouhoula, A.: Specification and evaluation of polymorphic shellcode properties using a new temporal logic. J. Comput. Virol. (2008)","DOI":"10.1007\/s11416-008-0089-x"},{"key":"125_CR23","doi-asserted-by":"crossref","unstructured":"Morin, B., Debar, H.: Correlation of intrusion symptoms: an application of chronicles. In: Proceedings Recent Advances in Intrusion Detection (RAID) Symposium (2003)","DOI":"10.1007\/978-3-540-45248-5_6"},{"key":"125_CR24","doi-asserted-by":"crossref","unstructured":"Cuppens, F., Miege, A.: Alert correlation in a cooperative intrusion detection framework. In: Proceedings of the 2002 IEEE Symposium on Security and Privacy (2002)","DOI":"10.1109\/SECPRI.2002.1004372"},{"issue":"1","key":"125_CR25","doi-asserted-by":"crossref","first-page":"71","DOI":"10.3233\/JCS-2002-101-204","volume":"10","author":"S.T. Eckmann","year":"2002","unstructured":"Eckmann S.T., Vigna G., Kemmerer R.A.: STATL: an attack language for state-based intrusion detection. J. Comput. Secur. 10(1), 71\u2013104 (2002)","journal-title":"J. Comput. Secur."},{"key":"125_CR26","doi-asserted-by":"crossref","unstructured":"Lindqvist, U., Porras, P.A.: Detecting computer and network misuse through the production-based expert system toolset (P-BEST). In: Proceedings of the 1999 IEEE Symposium on Security and Privacy (1999)","DOI":"10.1109\/SECPRI.1999.766911"},{"issue":"1\u20134","key":"125_CR27","first-page":"3","volume":"30","author":"S. Chakravarty","year":"2000","unstructured":"Chakravarty S., Shahar Y.: CAPSUL: a constraint-based specification of repeating patterns in time-oriented data. Ann. Math. AI 30(1\u20134), 3\u201322 (2000)","journal-title":"Ann. Math. AI"},{"key":"125_CR28","unstructured":"Shabtai, A., Shahar, Y., Elovici, Y.: Monitoring for malware using a temporal-abstraction knowledge base. In: Proceedings of the 8th International Symposium on System and Information Security (2006)"},{"key":"125_CR29","unstructured":"Shabtai, A., Shahar, Y., Elovici, Y.: Using the knowledge-based temporal-abstraction (KBTA) method for detection of electronic threats. In: Proceedings of the 5th European Conference on Information Warfare and Security (2006)"},{"key":"125_CR30","doi-asserted-by":"crossref","unstructured":"Spokoiny, A., Shahar, Y.: An active database architecture for knowledge-based incremental abstraction of complex concepts from continuously arriving time-oriented raw data. J. Intell. Inf. Syst. 28(3), 199\u2013231 (2007)","DOI":"10.1007\/s10844-006-0008-x"},{"key":"125_CR31","doi-asserted-by":"crossref","unstructured":"Shabtai A., Klimov D., Shahar Y., Elovici Y.: An intelligent, interactive tool for exploration and visualization of time-oriented security data. In: Proceedings of the 3rd International Workshop on Visualization for Computer Security (2006)","DOI":"10.1145\/1179576.1179580"},{"key":"125_CR32","doi-asserted-by":"crossref","unstructured":"Shabtai, A., Atlas, M., Shahar, Y., Elovici, Y.: Evaluation of a temporal-abstraction knowledge acquisition tool in the network security domain. In: Proceedings of the 4th International Conference on Knowledge Capture (2007)","DOI":"10.1145\/1298406.1298410"},{"key":"125_CR33","doi-asserted-by":"crossref","unstructured":"Stopel, D., Moskovitch, R., Boger, Z., Shahar, Y., Elovici, Y.: Using artificial neural networks to detect unknown computer worms. J. Neural Comput. Appl. (2009)","DOI":"10.1007\/s00521-009-0238-2"},{"key":"125_CR34","doi-asserted-by":"crossref","unstructured":"Moskovitch, R., et\u00a0al.: Host based intrusion detection using machine learning. IEEE Inf. Secur. Inf. (2007)","DOI":"10.1109\/ISI.2007.379542"},{"key":"125_CR35","unstructured":"Puzis, R., Tubi, M., Elovici, Y., Glezer, C.: A decision support system for placement of intrusion detection and prevention devices in large-scale networks. Submitted to ACM Transactions on Information and System Security (TISSEC)"},{"key":"125_CR36","doi-asserted-by":"crossref","unstructured":"Tubi, M., Puzis, R., Elovici, Y.: Deployment of DNIDS in social networks. ISI (2007)","DOI":"10.1109\/ISI.2007.379534"},{"key":"125_CR37","doi-asserted-by":"crossref","unstructured":"Moore, D. et\u00a0al.: Inside the slammer worm. IEEE Secur. Priv. (2003)","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"125_CR38","unstructured":"CERT 2000. Love letter worm. http:\/\/www.cert.org\/advisories\/CA-2000-04.html"},{"key":"125_CR39","doi-asserted-by":"crossref","unstructured":"Thommes, R., Coates, M.: Epidemiological modeling of peer-to-peer viruses and pollution. In: Proceedings of IEEE Infocom (2006)","DOI":"10.1109\/INFOCOM.2006.101"}],"container-title":["Journal in Computer Virology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-009-0125-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-009-0125-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-009-0125-5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T14:45:42Z","timestamp":1559400342000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-009-0125-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,7,23]]},"references-count":39,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2010,8]]}},"alternative-id":["125"],"URL":"https:\/\/doi.org\/10.1007\/s11416-009-0125-5","relation":{},"ISSN":["1772-9890","1772-9904"],"issn-type":[{"value":"1772-9890","type":"print"},{"value":"1772-9904","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,7,23]]}}}