{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T19:41:36Z","timestamp":1780083696920,"version":"3.54.0"},"reference-count":23,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2015,6,1]],"date-time":"2015-06-01T00:00:00Z","timestamp":1433116800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1239021"],"award-info":[{"award-number":["CNS-1239021"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-1237022"],"award-info":[{"award-number":["IIS-1237022"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"ARO","award":["W911NF-11-1-0227"],"award-info":[{"award-number":["W911NF-11-1-0227"]}]},{"name":"ARO","award":["W911NF-12-1-0390"],"award-info":[{"award-number":["W911NF-12-1-0390"]}]},{"name":"ONR","award":["N00014-10-1-0952"],"award-info":[{"award-number":["N00014-10-1-0952"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Control Netw. Syst."],"published-print":{"date-parts":[[2015,6]]},"DOI":"10.1109\/tcns.2014.2378631","type":"journal-article","created":{"date-parts":[[2014,12,8]],"date-time":"2014-12-08T19:28:12Z","timestamp":1418066892000},"page":"100-111","source":"Crossref","is-referenced-by-count":27,"title":["Statistical Traffic Anomaly Detection in Time-Varying Communication Networks"],"prefix":"10.1109","volume":"2","author":[{"given":"Jing","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ioannis Ch.","family":"Paschalidis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/65.642356"},{"key":"ref11","first-page":"53","article-title":"A coordinated view of the temporal evolution of large-scale Internet events","author":"king","year":"2013","journal-title":"Computing"},{"key":"ref12","year":"2013","journal-title":"&#x201C;Global internet phenomena report &#x201D;"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177699803"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177700150"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/1614379.1614386"},{"key":"ref16","year":"2012","journal-title":"Cisco Netflow"},{"key":"ref17","author":"wang","year":"2014","journal-title":"Statitical anomaly detector of Internet traffic (SADIT)"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2011.5935055"},{"key":"ref19","article-title":"Data retrieval over DNS in SQL injection attacks","author":"stampar","year":"2013","journal-title":"arXiv preprint arXiv 1303 3047"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1155\/2009\/837601"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637210"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/1824766.1824773"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2008.2001468"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-5320-4"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2000.821506"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"ref1","first-page":"229","article-title":"Snort-lightweight intrusion detection for networks","author":"roesch","year":"0","journal-title":"Proc 13th USENIX Conf Syst Admin"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2010.293"},{"key":"ref20","year":"2013","journal-title":"The Net Usage Index by Industry"},{"key":"ref22","author":"locke","year":"2012","journal-title":"Anomaly detection techniques for data exfiltration attempts"},{"key":"ref21","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1007\/3-540-46506-5_9","article-title":"Performance characteristics of the world wide web","author":"crovella","year":"2000","journal-title":"Performance Evaluation Origins and Directions"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1987.1057385"}],"container-title":["IEEE Transactions on Control of Network Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6509490\/7127070\/06979214.pdf?arnumber=6979214","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:04:48Z","timestamp":1642003488000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6979214\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,6]]},"references-count":23,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tcns.2014.2378631","relation":{},"ISSN":["2325-5870"],"issn-type":[{"value":"2325-5870","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,6]]}}}