{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T10:01:26Z","timestamp":1766484086591,"version":"build-2065373602"},"reference-count":38,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,4]]},"DOI":"10.1109\/noms.2016.7502852","type":"proceedings-article","created":{"date-parts":[[2016,7,4]],"date-time":"2016-07-04T17:07:22Z","timestamp":1467652042000},"page":"516-522","source":"Crossref","is-referenced-by-count":18,"title":["Collaborative DDoS defense using flow-based security event information"],"prefix":"10.1109","author":[{"given":"Jessica","family":"Steinberger","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benjamin","family":"Kuhnert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anna","family":"Sperotto","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Harald","family":"Baier","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aiko","family":"Pras","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.23"},{"key":"ref33","article-title":"CARIS Workshop Summary and Reflection","author":"moriarty","year":"2015","journal-title":"Internet Architecture Board and the Internet Society"},{"year":"2013","key":"ref32","article-title":"D1.7.1 - Data Format Specification"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.99"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2015.7140407"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/1619258.1619291"},{"journal-title":"Internet Architecture Board and the Internet Society","article-title":"CARIS Workshop Template Submissions","year":"2015","key":"ref36"},{"year":"2015","key":"ref35","article-title":"ACDC Deliverables"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"ref10","article-title":"The Intrusion Detection Message Exchange Format (IDMEF) RFC 4765 (Experimental)","author":"debar","year":"2007","journal-title":"IETF"},{"key":"ref11","article-title":"An Extensible Format for Email Feedback Reports RFC 5965 (Proposed Standard)","author":"shafranovich","year":"2010","journal-title":"IETF"},{"year":"0","key":"ref12","article-title":"x-arf Network Abuse Reporting 2.0"},{"key":"ref13","article-title":"Exchanging Security Events of flow-based Intrusion Detection Systems at Internet Scale","author":"steinberger","year":"2015","journal-title":"Internet Architecture Board and the Internet Society"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2015.7140300"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CYCON.2014.6916403"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-38998-6_7"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2010.032210.00054"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2014.2321898"},{"key":"ref19","article-title":"DDoS Open Threat Signaling (DOTS) Working Group Operational Requirements","volume":"93","author":"morrow","year":"2015","journal-title":"IETF"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2009.54"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2007.374774"},{"key":"ref27","doi-asserted-by":"crossref","DOI":"10.31274\/etd-180810-185","article-title":"A framework for cost-sensitive automated selection of intrusion response","author":"strasburg","year":"2009"},{"key":"ref3","article-title":"LADS: Large-scale Automated DDoS Detection System","author":"sekar","year":"2006","journal-title":"Proceedings of USENIX Annual Conference"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23233"},{"key":"ref29","doi-asserted-by":"crossref","DOI":"10.31274\/etd-180810-284","article-title":"Intrusion detection and response for system and network attacks","author":"stanley","year":"2009"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2012.04.008"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.5"},{"key":"ref7","doi-asserted-by":"crossref","DOI":"10.1109\/TNET.2012.2194508","article-title":"Firecol: A collaborative protection network for the detection of flooding DDoS attacks","author":"fran\u00e7ois","year":"2012","journal-title":"IEEE\/ACM Transactions on Networking"},{"article-title":"ENISA Threat Landscape 2013: Overview of current and emerging cyber-threats","year":"2013","author":"marinos","key":"ref2"},{"year":"2015","key":"ref1","article-title":"akamai's [state of the internet]\/security Q1 [2015 report]"},{"year":"2007","author":"danyliw","key":"ref9"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.89"},{"journal-title":"Applied Network Security Monitoring - Collection Detection and Analysis","year":"2013","author":"sanders","key":"ref22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.164"},{"key":"ref24","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-20757-0_1","article-title":"BotTrack: Tracking Botnets Using NetFlow and PageRank","author":"fran\u00e7ois","year":"2011","journal-title":"NETWORKING 2011"},{"key":"ref23","article-title":"Towards cyber defense: research in intrusion detection and intrusion prevention systems","volume":"10","author":"faysel","year":"2010","journal-title":"IJCSNS International Journal of Computer Science and Network Security"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420969"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/2413176.2413217"}],"event":{"name":"NOMS 2016 - 2016 IEEE\/IFIP Network Operations and Management Symposium","start":{"date-parts":[[2016,4,25]]},"location":"Istanbul, Turkey","end":{"date-parts":[[2016,4,29]]}},"container-title":["NOMS 2016 - 2016 IEEE\/IFIP Network Operations and Management Symposium"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/7499631\/7502779\/07502852.pdf?arnumber=7502852","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,10]],"date-time":"2019-09-10T13:42:04Z","timestamp":1568122924000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7502852\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,4]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/noms.2016.7502852","relation":{},"subject":[],"published":{"date-parts":[[2016,4]]}}}