{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T00:03:44Z","timestamp":1772064224629,"version":"3.50.1"},"reference-count":21,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2012,10,25]],"date-time":"2012-10-25T00:00:00Z","timestamp":1351123200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Peer-to-Peer Netw. Appl."],"published-print":{"date-parts":[[2014,12]]},"DOI":"10.1007\/s12083-012-0173-3","type":"journal-article","created":{"date-parts":[[2012,10,24]],"date-time":"2012-10-24T01:39:28Z","timestamp":1351042768000},"page":"346-358","source":"Crossref","is-referenced-by-count":31,"title":["Distributed Denial of Service (DDoS) detection by traffic pattern analysis"],"prefix":"10.1007","volume":"7","author":[{"given":"Theerasak","family":"Thapngam","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shui","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wanlei","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S. Kami","family":"Makki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2012,10,25]]},"reference":[{"key":"173_CR1","unstructured":"MIT Lincoln Laboratory, \u201cLincoln Laboratory Scenario (DDoS) 1.0,\u201d Massachusetts Institute of Technology (MIT), 1999. Available: http:\/\/www.ll.mit.edu\/mission\/communications\/ist\/corpora\/ideval\/data\/2000\/LLS_DDOS_1.0.html"},{"key":"173_CR2","unstructured":"US CERT 04, \u201cW32\/MyDoom.B Virus,\u201d United States Computer Emergency Readiness Team, Available: http:\/\/www.us-cert.gov\/cas\/techalerts\/TA04-028A.html , 2 Febuary 2004"},{"key":"173_CR3","doi-asserted-by":"crossref","unstructured":"Rajab MA, Zarfoss J, Monrose F and Terzis A (2006) \u201cA multifaceted approach to understanding the Botnet Phenomenon.\u201d In: Proceedings of the 6th ACM SIGCOMM conference on Internet measurement, pp. 41\u201352, October 2006","DOI":"10.1145\/1177080.1177086"},{"key":"173_CR4","doi-asserted-by":"crossref","unstructured":"Oikonomou G and Mirkovic J (2009) \u201cModeling human behavior for defense against flash-crowd attacks.\u201d In: Proceedings of IEEE International Conference on Communications 2009 (ICC\u201909), pp. 1\u20136, 11 August 2009","DOI":"10.1109\/ICC.2009.5199191"},{"issue":"1","key":"173_CR5","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1109\/TNET.2008.923716","volume":"17","author":"Y Xie","year":"2009","unstructured":"Xie Y, Yu SZ (2009) A large-scale hidden Semi-Markov model for anomaly detection on user browsing behaviors networking. IEEE\/ACM Trans Networking 17(1):54\u201365","journal-title":"IEEE\/ACM Trans Networking"},{"issue":"1","key":"173_CR6","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1109\/TNET.2008.925628","volume":"17","author":"Y Xie","year":"2009","unstructured":"Xie Y, Yu SZ (2009) Monitoring the application-layer DDoS attacks for popular websites. IEEE\/ACM Trans Networking 17(1):15\u201325","journal-title":"IEEE\/ACM Trans Networking"},{"issue":"1","key":"173_CR7","first-page":"9","volume":"1","author":"F Yi","year":"2008","unstructured":"Yi F, Yu S, Zhou W, Hai J, Bonti A (2008) Source-based filtering scheme against DDOS attacks. Int J Database Theory Appl 1(1):9\u201322","journal-title":"Int J Database Theory Appl"},{"key":"173_CR8","doi-asserted-by":"crossref","unstructured":"Feinstein L, Schnackenberg D, Balupari R and Kindred D (2003) \u201cStatistical approaches to DDoS attack detection and response.\u201d In: Proceedings of the DARPA Information Survivability Conference and Exposition, vol. 1, IEEE CS Press, 22\u201324 April 2003, pp. 303\u2013314","DOI":"10.1109\/DISCEX.2003.1194894"},{"key":"173_CR9","doi-asserted-by":"crossref","unstructured":"Khan L, Awad M and Thuraisingham B (2007) \u201cA new intrusion detection system using support vector machines and hierarchical clustering.\u201d The International Journal on Very Large Data Bases (The VLDB Journal), vol. 16, no. 4, pp. 507\u2013521, Springer-Verlag, New York, October 2007","DOI":"10.1007\/s00778-006-0002-5"},{"key":"173_CR10","doi-asserted-by":"crossref","unstructured":"Yu S, Thapngam T, Liu J, Wei S and Zhou W (2009) \u201cDiscriminating DDoS flows from flash crowds using information distance.\u201d In: Proceedings of the 3rd IEEE International Conference on Network and System Security (NSS\u201909), 18\u201321 October 2009","DOI":"10.1109\/NSS.2009.29"},{"key":"173_CR11","doi-asserted-by":"crossref","first-page":"717","DOI":"10.1109\/LCOMM.2009.090615","volume":"13","author":"A Chonka","year":"2009","unstructured":"Chonka A, Singh J, Zhou W (2009) Chaos theory based detection against network mimicking DDoS attacks. IEEE Commun Lett 13:717\u2013719","journal-title":"IEEE Commun Lett"},{"key":"173_CR12","unstructured":"Carlinet Y, Cherkaoui O, Dressler F, Ehinger C, Fadlallah A, Muenz G, Mu\u00dfner M, Paul O, Serhrouchni A, Sloman M, and Yusuf S (2004) \u201cDistributed adaptive security by Programmable Firewall,\u201d DIADEM Firewall Consortium, retrieved 6 September 2008, Available: http:\/\/www.diadem-firewall.org\/documents\/Diadem%20Firewall%20-%20D3%20-%20Attack%20Requirements%20Specification.pdf , June 2004"},{"issue":"9","key":"173_CR13","doi-asserted-by":"crossref","first-page":"1137","DOI":"10.1016\/j.jpdc.2006.04.007","volume":"66","author":"Y Chen","year":"2006","unstructured":"Chen Y, Hwang K (2006) Collaborative detection and filtering of shrew DDoS attacks using spectral analysis. J Parallel Distr Com 66(9):1137\u20131151","journal-title":"J Parallel Distr Com"},{"key":"173_CR14","doi-asserted-by":"crossref","unstructured":"Tuncer T and Tatar Y (2008) \u201cDetection SYN Flooding Attacks Using Fuzzy Logic.\u201d In: Proceedings of International Conference on Information Security and Assurance (ISA\u201908), pp. 321\u2013325, 24\u201326 April 2008","DOI":"10.1109\/ISA.2008.50"},{"key":"173_CR15","unstructured":"Kuzmanovic A and Knightly E (2003) \u201cLow-Rate TCP \u2013Targeted Denial of Service Attacks (The Shrew vs. the Mice and Elephants).\u201d In: Proceedings of ACM SIGCOMM 2003, Kalrushe, Germany, pp. 75\u201386, August 2003"},{"key":"173_CR16","doi-asserted-by":"crossref","unstructured":"Chen Y and Hwang K (2007) \u201cSpectral analysis of TCP flows for defense against reduction-of-quality attacks.\u201d In: Proceedings of the 2007 IEEE International Conference on Communications (ICC\u201907), pp. 1203\u20131210, June 2007","DOI":"10.1109\/ICC.2007.204"},{"issue":"5","key":"173_CR17","doi-asserted-by":"crossref","first-page":"643","DOI":"10.1016\/j.comnet.2003.10.003","volume":"44","author":"C Douligeris","year":"2004","unstructured":"Douligeris C, Mitrokotsa A (2004) DDoS attacks and defense mechanisms: Classification and state of the art. Comput Netw 44(5):643\u2013666","journal-title":"Comput Netw"},{"key":"173_CR18","doi-asserted-by":"crossref","unstructured":"Peng T, Leckie C and Ramamohanarao K (2007) \u201cSurvey of network-based defense mechanisms countering the DoS and DDoS problems.\u201d In: ACM Computing Surveys, Vol. 39, No. 1, April 2007","DOI":"10.1145\/1216370.1216373"},{"issue":"2","key":"173_CR19","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1145\/997150.997156","volume":"34","author":"J Mirkovic","year":"2004","unstructured":"Mirkovic J, Reiher P (2004) A Taxonomy of DDoS attack and DDoS defense mechanisms. ACM SIGCOMM Comput Commun Rev 34(2):39\u201353","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"key":"173_CR20","volume-title":"Advanced Engineering Mathematics","author":"E Kreyszig","year":"2006","unstructured":"Kreyszig E (2006) Advanced Engineering Mathematics, 9th edn. Wiley, Singapore","edition":"9"},{"key":"173_CR21","unstructured":"M. Arlitt and T. Jin \u201c1998 World Cup Web Site Access Logs,\u201d August 1998. Available: http:\/\/www.acm.org\/sigcomm\/ITA\/"}],"container-title":["Peer-to-Peer Networking and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-012-0173-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s12083-012-0173-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-012-0173-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,4]],"date-time":"2019-07-04T19:22:03Z","timestamp":1562268123000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s12083-012-0173-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,10,25]]},"references-count":21,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2014,12]]}},"alternative-id":["173"],"URL":"https:\/\/doi.org\/10.1007\/s12083-012-0173-3","relation":{},"ISSN":["1936-6442","1936-6450"],"issn-type":[{"value":"1936-6442","type":"print"},{"value":"1936-6450","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,10,25]]}}}