{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,28]],"date-time":"2025-02-28T05:31:05Z","timestamp":1740720665615,"version":"3.38.0"},"reference-count":25,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2010,10,28]],"date-time":"2010-10-28T00:00:00Z","timestamp":1288224000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Front. Comput. Sci. China"],"published-print":{"date-parts":[[2011,3]]},"DOI":"10.1007\/s11704-010-0321-y","type":"journal-article","created":{"date-parts":[[2010,11,4]],"date-time":"2010-11-04T11:02:59Z","timestamp":1288868579000},"page":"109-118","source":"Crossref","is-referenced-by-count":3,"title":["Boosting performance in attack intention recognition by integrating multiple techniques"],"prefix":"10.1007","volume":"5","author":[{"given":"Hao","family":"Bai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kunsheng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Changzhen","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaochuan","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2010,10,28]]},"reference":[{"key":"321_CR1","doi-asserted-by":"crossref","unstructured":"Yi P, Xing H, Wu Y, Cai J. Alert correlation through results tracing back to reasons. In: Proceedings of the 2009 International Conference on Communications and Mobile Computing. Kunming, 2009, 465\u2013469","DOI":"10.1109\/CMC.2009.327"},{"key":"321_CR2","unstructured":"Ning P, Xu D, Healey C, Amant R. Building attack scenarios through integration of complementary alert correlation methods. In: Proceedings of the 11th Annual Network and Distributed System Security Symposium. 2004, 97\u2013111"},{"key":"321_CR3","doi-asserted-by":"crossref","unstructured":"Soleimani M, Ghorbani A. Critical episode mining in intrusion detection alerts. In: Proceedings of the 6th Communication Networks and Services Research Conference, Halifax, 2008, 157\u2013164","DOI":"10.1109\/CNSR.2008.62"},{"key":"321_CR4","unstructured":"Wang L, Li Z, Li D, Lei J. Attack scenario construction with a new sequential mining technique. In: 8th ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel\/Distributed Computing. 2007, 53\u201387"},{"key":"321_CR5","unstructured":"Agrawal R, Srikant R. Fast Algorithms for Mining Association Rules. IBM Alamnden Research Center. 1994"},{"issue":"1","key":"321_CR6","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1023\/B:DAMI.0000005258.31418.83","volume":"8","author":"J. Han","year":"2004","unstructured":"Han J, Pei J, Yin Y, Mao R. Mining frequent patterns without candidate generation: A frequent-pattern tree approach. Data Mining and Knowledge Discovery, 2004, 8(1): 53\u201387","journal-title":"Data Mining and Knowledge Discovery"},{"issue":"2","key":"321_CR7","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1007\/s10844-006-0006-z","volume":"28","author":"J. Pei","year":"2007","unstructured":"Pei J, Han J, Wang W. Constraint-based sequential pattern mining: the pattern-growth methods. Journal of Intelligent Information Systems, 2007, 28(2): 133\u2013160","journal-title":"Journal of Intelligent Information Systems"},{"key":"321_CR8","doi-asserted-by":"crossref","unstructured":"Cuppens F, Miege A. Alert correlation in a cooperative intrusion detection framework. In: Proceedings of the 2002 IEEE Symposium on Security and Privacy. 2002, 202\u2013215","DOI":"10.1109\/SECPRI.2002.1004372"},{"key":"321_CR9","doi-asserted-by":"crossref","unstructured":"Xiao S, Zhang Y, Liu X, Gao J. Alert fusion based on cluster and correlation analysis. In: Proceedings of International Conference on Convergence and Hybrid Information Technology 2008. Gyeongbuk S. Korea, 2008, 163\u2013168","DOI":"10.1109\/ICHIT.2008.197"},{"issue":"9","key":"321_CR10","first-page":"132","volume":"8","author":"R. Yusof","year":"2008","unstructured":"Yusof R, Selamat S R, Sahib S. Intrusion alert correlation technique analysis for heterogeneous log. IJCSNS International Journal of Computer Science and Network Security, 2008, 8(9), 132\u2013138","journal-title":"IJCSNS International Journal of Computer Science and Network Security"},{"key":"321_CR11","doi-asserted-by":"crossref","unstructured":"Long W, Xin Y, Yang Y. Vulnerabilities analyzing model for alert correlation in distributed environment. In: Proceedings of the 2009 IITA International Conference on Services Science, Management and Engineering. Zhangjiajie, 2009, 408\u2013411","DOI":"10.1109\/SSME.2009.132"},{"key":"321_CR12","doi-asserted-by":"crossref","unstructured":"Liu Z, Wang C, Chen S. Correlating multi-step attack and constructing attack scenarios based on attack pattern modeling. In: Proceedings of the International Conference on Information Security and Assurance. Busan, 2008, 214\u2013219","DOI":"10.1109\/ISA.2008.11"},{"key":"321_CR13","doi-asserted-by":"crossref","unstructured":"Xu M, Wu T, Tang J. An IDS alert fusion approach based on happened before relation. In: Proceedings of 4th International Conference on Wireless Communications, Networking and Mobile Computing. Dalian, 2008, 1\u20134","DOI":"10.1109\/WiCom.2008.2937"},{"key":"321_CR14","unstructured":"Yi P, Xing H, Wu Y, Li L. Alert correlation by a retrospective method. In: Proceedings of the 23rd international conference on Information Networking. Chiang Mai, 2009, 380\u2013382"},{"key":"321_CR15","doi-asserted-by":"crossref","unstructured":"Li Z, Lei J, Wang L, Li D. A Data mining approach to generating network attack graph for intrusion prediction. In: Proceedings of 4th International Conference on Fuzzy Systems and Knowledge Discovery. Haikou, 2007, 307\u2013311","DOI":"10.1109\/FSKD.2007.15"},{"key":"321_CR16","doi-asserted-by":"crossref","unstructured":"Li Z, Zhang A, Lei J, Wang L. Real-time correlation of network security alerts. In: Proceedings of IEEE International Conference on e-Business Engineering. 2007, 73\u201380","DOI":"10.1109\/ICEBE.2007.69"},{"key":"321_CR17","doi-asserted-by":"crossref","unstructured":"Li W, Tian S. Preprocessor of intrusion alerts correlation based on ontology. In: Proceedings of 2009 International Conference on Communications and Mobile Computing. Kunming, 2009, 460\u2013464","DOI":"10.1109\/CMC.2009.63"},{"key":"321_CR18","unstructured":"Qin X, Lee W. Attack plan recognition and prediction using causal networks. In: Proceedings of the 20th Annual Computer Security Applications Conference. 2004, 370\u2013379"},{"key":"321_CR19","doi-asserted-by":"crossref","unstructured":"Qin X, Lee W. Statistical causality analysis of INFOSEC alert data. In: Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection. 2003, 73\u201393","DOI":"10.1007\/978-3-540-45248-5_5"},{"key":"321_CR20","unstructured":"Ou X, Govindavajhala S, Appel A. MulVAL: A logic-based network security analyzer. In: 14th USENIX Security Symposium. Society for Industrial and Applied Mathematics. 2005, 8\u20138"},{"key":"321_CR21","unstructured":"Ou X. Logic-programming approach to network security analysis. PhD thesis. Department of Computer Science. Princeton University. 2005"},{"key":"321_CR22","doi-asserted-by":"crossref","unstructured":"Mei H, Gong J. Intrusion alert correlation based on D-S evidence theory. In: Proceedings of 2nd International Conference on IEEE Communications and Networking in China. Shanghai, 2007, 377\u2013381","DOI":"10.1109\/CHINACOM.2007.4469406"},{"key":"321_CR23","doi-asserted-by":"crossref","unstructured":"Hofmann A, Dedinski I, Sick B, deMeer H. A novelty-driven approach to intrusion alert correlation based on distributed hash tables. In: Proceedings of 12th IEEE Symposium on Computer and Communications. Averio Portugal, 2007, 71\u201378","DOI":"10.1109\/ISCC.2007.4381564"},{"key":"321_CR24","unstructured":"Pei J, Han J, Lu H, Nishio S, Tang S, Yang D. H-mine: hyperstructure mining of frequent patterns in large database. In: Proceedings of 1st IEEE International Conference on Data Mining. 2001, 441\u2013448"},{"key":"321_CR25","unstructured":"Zhai Y, Ning P, Iyer P, Reeves D. Reasoning about complementary intrusion evidence. In: Proceedings of the 20th annual Computer Security Applications Conference. 2004, 39\u201348"}],"container-title":["Frontiers of Computer Science in China"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-010-0321-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11704-010-0321-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-010-0321-y","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,27]],"date-time":"2025-02-27T15:59:07Z","timestamp":1740671947000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11704-010-0321-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,10,28]]},"references-count":25,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,3]]}},"alternative-id":["321"],"URL":"https:\/\/doi.org\/10.1007\/s11704-010-0321-y","relation":{},"ISSN":["1673-7350","1673-7466"],"issn-type":[{"type":"print","value":"1673-7350"},{"type":"electronic","value":"1673-7466"}],"subject":[],"published":{"date-parts":[[2010,10,28]]}}}