{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T08:16:02Z","timestamp":1759133762132},"reference-count":36,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"10","license":[{"start":{"date-parts":[[2014,10,1]],"date-time":"2014-10-01T00:00:00Z","timestamp":1412121600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE J. Select. Areas Commun."],"published-print":{"date-parts":[[2014,10]]},"DOI":"10.1109\/jsac.2014.2358834","type":"journal-article","created":{"date-parts":[[2014,9,17]],"date-time":"2014-09-17T18:56:24Z","timestamp":1410980184000},"page":"1933-1946","source":"Crossref","is-referenced-by-count":7,"title":["IDS Alert Correlation in the Wild With EDGe"],"prefix":"10.1109","volume":"32","author":[{"given":"Elias","family":"Raftopoulos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xenofontas","family":"Dimitropoulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22424-9_9"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2011.5958263"},{"key":"ref31","first-page":"243","article-title":"Extracting ambiguous sessions from real traffic with intrusion prevention systems","volume":"14","author":"chen","year":"2012","journal-title":"Int J Netw Security"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330151"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"ref35","first-page":"87","article-title":"False positives and negatives from real traffic with intrusion detection\/prevention systems","volume":"1","author":"yuan ho","year":"2012","journal-title":"Journal of Future Computer and Communication"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_13"},{"key":"ref10","author":"sekar","year":"2007","journal-title":"Is host-based $\\hbox anomaly \\ \\hbox detection \\ \\hbox + \\ \\hbox emporal \\ \\hbox correlation =\\hbox worm \\ \\hbox causality $?"},{"key":"ref11","article-title":"Advanced automated threat analysis system","year":"0"},{"key":"ref12","year":"0","journal-title":"TrendMicro Threat Encyclopedia"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2013.12"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-37300-8_14"},{"key":"ref15","first-page":"162","article-title":"Bothunter: Detecting malware infection through ids-driven dialog correlation","author":"gu","year":"0","journal-title":"Proc 16th USENIX Security Symp"},{"key":"ref16","year":"2007","journal-title":"Malware Threat Center"},{"key":"ref17","first-page":"149","article-title":"How to own the Internet in your spare time","author":"staniford","year":"0","journal-title":"Proc USENIX"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/T-UFFC.1987.26997"},{"key":"ref19","first-page":"13","article-title":"Measuring Pay-per-Install: The commoditization of malware distribution","author":"caballero","year":"0","journal-title":"Proc USENIX"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/781027.781045"},{"key":"ref4","author":"etienne","year":"2009","journal-title":"Malicious traffic detection in local networks with snort"},{"key":"ref27","first-page":"139","article-title":"Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection","author":"gu","year":"0","journal-title":"Proc 17th Conf Security Symp"},{"key":"ref3","first-page":"54","article-title":"Probabilistic alert correlation","author":"valdes","year":"0","journal-title":"Proc 4th Int RAID Symp"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/69.149926"},{"key":"ref29","year":"2000","journal-title":"Cooperative Network Security Community"},{"key":"ref5","year":"2006","journal-title":"Network Security Archive"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068820"},{"key":"ref7","first-page":"229","article-title":"Discovery, analysis and presentation of strong rules","author":"piatetsky-shapiro","year":"1991","journal-title":"Knowledge Discovery in Databases"},{"key":"ref2","year":"2003","journal-title":"Emerging Threats Rules"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-68768-1_4"},{"key":"ref1","article-title":"Network intrusion detection system for UNIX and Windows","year":"1998"},{"key":"ref20","first-page":"73","article-title":"Statistical causality analysis of infosec alert data","author":"qin","year":"0","journal-title":"Proc 6th Int RAID Symp"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/950191.950192"},{"key":"ref21","first-page":"85","article-title":"Aggregation and correlation of intrusion-detection alerts","author":"debar","year":"0","journal-title":"Proc 4th Int RAID Symp"},{"key":"ref24","first-page":"7","article-title":"Wide-scale botnet detection and characterization","author":"karasaridis","year":"0","journal-title":"Proc of HotBots"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"ref26","first-page":"7","article-title":"An algorithm for anomaly-based botnet detection","author":"binkley","year":"0","journal-title":"Proc SRUTI"},{"key":"ref25","first-page":"8","article-title":"Rishi: Identify bot contaminated hosts by irc nickname evaluation","author":"goebel","year":"0","journal-title":"Proc of HotBots"}],"container-title":["IEEE Journal on Selected Areas in Communications"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/49\/6969128\/06901257.pdf?arnumber=6901257","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T15:59:20Z","timestamp":1642003160000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6901257\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,10]]},"references-count":36,"journal-issue":{"issue":"10"},"URL":"https:\/\/doi.org\/10.1109\/jsac.2014.2358834","relation":{},"ISSN":["0733-8716"],"issn-type":[{"value":"0733-8716","type":"print"}],"subject":[],"published":{"date-parts":[[2014,10]]}}}