{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,26]],"date-time":"2025-10-26T20:51:55Z","timestamp":1761511915327,"version":"3.28.0"},"reference-count":27,"publisher":"IEEE Comput. Soc","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1109\/discex.2003.1194881","type":"proceedings-article","created":{"date-parts":[[2004,3,1]],"date-time":"2004-03-01T21:26:50Z","timestamp":1078176410000},"page":"152-163","source":"Crossref","is-referenced-by-count":9,"title":["Finding the vocabulary of program behavior data for anomaly detection"],"prefix":"10.1109","author":[{"given":"C.C.","family":"Michael","sequence":"first","affiliation":[]}],"member":"263","reference":[{"article-title":"Linear time algorithms for finding and representing all the tandem repeats in a string","year":"1998","author":"gusfield","key":"ref10"},{"article-title":"The strmat software-package","year":"1998","author":"knight","key":"ref11"},{"key":"ref12","first-page":"366","article-title":"An application of machine learning to anomaly detection","author":"lane","year":"1997","journal-title":"Proceedings of the 20th National Information Systems Security Conf erence"},{"key":"ref13","article-title":"Learning patterns from Unix process execution traces for intrusion det ection","author":"lee","year":"1997","journal-title":"Proceedings of AAAI97 Workshop on AI Methods in Fraud and Risk Man agement"},{"key":"ref14","article-title":"Information-theoretic measures for anomaly detection","author":"lee","year":"2001","journal-title":"Proceedings of the 2001 IEEE Symposium on Security and Privacy"},{"key":"ref15","article-title":"Ides: an intelligent system for detecting intruders","author":"lunt","year":"1990","journal-title":"Proceedings of the Symposium Computer Security Threat and Coun-termeasures"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(93)90029-5"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1988.8098"},{"key":"ref18","article-title":"A realtime intrusion-detection expert system (ides)","author":"lunt","year":"1992","journal-title":"Computer Science Laboratory SRI Internationnal"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/366173.366197"},{"key":"ref4","first-page":"443","article-title":"Artificial neural networks for misuse detection","author":"cannady","year":"1998","journal-title":"Proceedings of the 1998 National Information Systems Security Conf erence (NISSC'98)"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/SWAT.1973.13"},{"key":"ref3","article-title":"Computer security threat monitoring and surveillance","author":"anderson","year":"1980","journal-title":"Technical report James P Anderson Co"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.1998.738647"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502674"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.1998.738646"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"journal-title":"Principles of Compiler Design","year":"1977","author":"aho","key":"ref2"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511574931"},{"journal-title":"DARPA Intrusion Detection Evaluation","year":"1999","key":"ref1"},{"key":"ref20","first-page":"262","article-title":"A space-economic suffix tree construction algorithm","volume":"23","author":"mccreight","year":"1976","journal-title":"Jrnl A C M"},{"key":"ref22","first-page":"353","article-title":"Event monitoring enabling responses to anomalous live disturbances","author":"porras","year":"1997","journal-title":"Proceedings of the 20th National Information Systems Security Conference"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/32.988709"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0030787"},{"key":"ref23","first-page":"144","article-title":"A fast automaton-based method for detecting anomalous program behaviors","author":"sekar","year":"2000","journal-title":"Proc 2000 IEEE Symp Security Privacy"},{"key":"ref26","first-page":"484","article-title":"Constructing suffix trees on-line in linear time","author":"ukkonen","year":"1992","journal-title":"Proceedings of the IFIP 12th World Computer Congress Volume 1 Algorithms Software Architecture"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2002.1004371"}],"event":{"name":"DARPA Information Survivability Conference and Exposition","acronym":"DISCEX-03","location":"Washington, DC, USA"},"container-title":["Proceedings DARPA Information Survivability Conference and Exposition"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/8503\/26875\/01194881.pdf?arnumber=1194881","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,3,13]],"date-time":"2017-03-13T17:48:46Z","timestamp":1489427326000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/1194881\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/discex.2003.1194881","relation":{},"subject":[]}}