{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T05:49:40Z","timestamp":1750830580855},"reference-count":25,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1109\/noms.2004.1317747","type":"proceedings-article","created":{"date-parts":[[2004,8,13]],"date-time":"2004-08-13T09:09:39Z","timestamp":1092388179000},"page":"599-612","source":"Crossref","is-referenced-by-count":16,"title":["A flow-based method for abnormal network traffic detection"],"prefix":"10.1109","author":[{"family":"Myung-Sup Kim","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"family":"Hun-Jeong Kong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"family":"Seong-Cheol Hong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"family":"Seung-Hwa Chung","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"J.W.","family":"Hong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"journal-title":"Fyodor","article-title":"The Art of Port Scanning","year":"0","key":"ref10"},{"key":"ref11","article-title":"Inferring Internet Denial-of-Service Activity","author":"moore","year":"2001","journal-title":"Proc of USENIX Security Symposium"},{"journal-title":"Common Vulnerabilities and Exposures (CVE)","article-title":"Ping-of-Death (CVE-1999&#x2013;0 128)","year":"0","key":"ref12"},{"journal-title":"Common Vulnerabilities and Exposures (CYE)","article-title":"Land (CVE-1999&#x2013;0016)","year":"0","key":"ref13"},{"journal-title":"Common Vulnerabilities and Exposures (CVE)","article-title":"SYN flood (CYE-1999&#x2013;0116)","year":"0","key":"ref14"},{"journal-title":"Common Vulnerabilities and Exposures (CVE)","article-title":"Smurf(CVE-1999&#x2013;0513)","year":"0","key":"ref15"},{"journal-title":"Common Vulnerabilities and Exposures (CVE)","article-title":"UDP packet storm (CVE-1999&#x2013;0) 03)","year":"0","key":"ref16"},{"journal-title":"Common Vulnerabilities and Exposures (CVE)","article-title":"Fraggle (CVE-1999&#x2013;0514)","year":"0","key":"ref17"},{"journal-title":"Common Vulnerabilities and Exposures (CVE)","article-title":"HTTP request flood (CVE-1999&#x2013;0867)","year":"0","key":"ref18"},{"article-title":"Snort - lightweight intrusion detection for networks","year":"0","author":"roesch","key":"ref19"},{"key":"ref4","article-title":"Implementing pushback: Router-based defense against DDoS attacks","author":"john loannidis","year":"2002","journal-title":"Proceedings of the Symposium on Network and Distributed System Security NDSS-95"},{"key":"ref3","article-title":"An algebraic approach to ip traceback","author":"drew","year":"2001","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref6","article-title":"Effect of Malicious Traffic on the Network","author":"kun-chan","year":"2003","journal-title":"Proc of the PAM 2003"},{"key":"ref5","article-title":"Practical network support for IP traceback","author":"stefan","year":"2000","journal-title":"Proc ACM SIGCOMM 2000"},{"article-title":"Using Flows for Analysis and Measurement of Internet Traffic","year":"1997","author":"siegfried","key":"ref8"},{"key":"ref7","first-page":"16","article-title":"The Architecture of NG-MON: A Passive Network Monitoring System","author":"se-hee","year":"2002","journal-title":"Lecture Notes in Computer Science 2506 13th IFIP\/IEEE International Workshop on Distributed Systems Operations and Management (DSOM 2002)"},{"journal-title":"CNN Cyber-attacks batter web heavyweights","year":"2000","key":"ref2"},{"journal-title":"Cisco Syst White Papers","article-title":"NetFlow Services and Applications","year":"0","key":"ref9"},{"journal-title":"CNN Immense network assault takes down yahoo","year":"2000","key":"ref1"},{"key":"ref20","article-title":"A novel approach to detection of denial-of-service attacks via adaptive sequential and batch sequential change-point detection methods","author":"blazek","year":"2001","journal-title":"IEEE Systems Man and Cybernetics Information Assurance Workshop"},{"article-title":"Detecting Distributed Denial of Service Attacks Using Source IP Address Monitoring","year":"0","author":"tao","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/IWQoS.2002.1006572"},{"key":"ref24","article-title":"A Rule-based Approach for Port Scanning Detection","author":"urupoj","year":"2000","journal-title":"Proc of the 23nd Electrical Engineering Conference (EECON-23)"},{"journal-title":"Edonkey","year":"0","key":"ref23"},{"journal-title":"Welchia Internet Worm","year":"0","key":"ref25"}],"event":{"name":"2004 IEEE\/IFIP Network Operations and Management Symposium","acronym":"NOMS-04","location":"Seoul, South Korea"},"container-title":["2004 IEEE\/IFIP Network Operations and Management Symposium (IEEE Cat. No.04CH37507)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/9208\/29204\/01317747.pdf?arnumber=1317747","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,3,13]],"date-time":"2017-03-13T18:16:07Z","timestamp":1489428967000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/1317747\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"references-count":25,"URL":"https:\/\/doi.org\/10.1109\/noms.2004.1317747","relation":{},"subject":[]}}