{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:47:38Z","timestamp":1784735258312,"version":"3.55.0"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2010,6,1]],"date-time":"2010-06-01T00:00:00Z","timestamp":1275350400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2010,6]]},"DOI":"10.1109\/tifs.2010.2041808","type":"journal-article","created":{"date-parts":[[2010,2,17]],"date-time":"2010-02-17T15:49:40Z","timestamp":1266421780000},"page":"288-299","source":"Crossref","is-referenced-by-count":35,"title":["Predictive Network Anomaly Detection and Visualization"],"prefix":"10.1109","volume":"5","author":[{"given":"Mehmet","family":"Celenk","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Conley","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Willis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"James","family":"Graham","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","author":"stallings","year":"2004","journal-title":"Data and Computer Communications (7th Edition)"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICDIM.2008.4746810"},{"key":"ref33","author":"asmoredjo","year":"2005","journal-title":"A Probabilistic Model for Cyber Attacks and Protection"},{"key":"ref32","author":"porat","year":"1994","journal-title":"Digital Processing of Random Signals Theory and Methods"},{"key":"ref31","author":"theodoridis","year":"2006","journal-title":"Pattern Recognition"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2009.4804318"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevE.64.026110"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/1103626.1103637"},{"key":"ref35","author":"travis","year":"2003","journal-title":"Analysis of the SQL Slammer Worm and Its Effects on Indiana University and Related Institutions"},{"key":"ref34","author":"schneider","year":"2009","journal-title":"Methods of Internet Worm Propagation"},{"key":"ref10","first-page":"305","article-title":"a network traffic flow reporting and visualization tool","author":"plonka","year":"2000","journal-title":"Proc 15th USENIX Systems Administration Conf"},{"key":"ref40","author":"lim","year":"1990","journal-title":"Two-Dimensional Signal and Image Processing"},{"key":"ref11","author":"gong","year":"2004","journal-title":"Security Focus Article Detecting Worms and Abnormal Activities With NetFlows Part 1"},{"key":"ref12","author":"gong","year":"2004","journal-title":"Security Focus Article Detecting Worms and Abnormal Activities With NetFlows Part 1"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCC.2004.843217"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330148"},{"key":"ref15","author":"lakhina","year":"2005","journal-title":"Mining Anomalies Using Traffic Distributions"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/MCG.2006.49"},{"key":"ref17","author":"eimann","year":"2005","journal-title":"Network Event Detection With T-Entropy"},{"key":"ref18","author":"lall","year":"2005","journal-title":"Data Streaming Algorithms for Estimating Entropy of Network Traffic"},{"key":"ref19","article-title":"measuring network change: rnyi cross entropy and the second order degree distribution","author":"harrington","year":"2006","journal-title":"Proc Passive and Active Measurement (PAM) Conf"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/LCOMM.2007.070761"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2006.12.010"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2007.44"},{"key":"ref3","first-page":"7","article-title":"wide-scale botnet detection and characterization","author":"karasaridis","year":"2007","journal-title":"HotBots 07 -Proceedings-of-the-first-conference-on- First- Workshop- on- Hot- Topics- in- Understanding-Botnets"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SAINTW.2002.994556"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.902685"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(01)00304-8"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/285243.285256"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/WICOM.2007.551"},{"key":"ref9","article-title":"internet security visualization case study: instrumenting a network for netflow security visualization tools","author":"yurcik","year":"2005","journal-title":"Proc Ann Computer Security Applications Conf (ACSAC)"},{"key":"ref1","first-page":"37","article-title":"unsupervised anomaly detection in network traffic by means of robust pca","author":"kwitt","year":"2007","journal-title":"Proc Int Conf Computing in the Global Information Technology (ICCGI)"},{"key":"ref20","first-page":"307","article-title":"detecting covert timing channels: an entropy-based approach","author":"gianvecchio","year":"2007","journal-title":"Proc ACM Conf Computer and Communications Security"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICSMC.2008.4811848"},{"key":"ref21","first-page":"1047","volume":"3042","author":"kim","year":"2004","journal-title":"Network"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1093\/biomet\/56.1.1"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/WETICE.2005.35"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.2307\/2965471"},{"key":"ref23","first-page":"340","article-title":"on effectiveness of link padding for statistical traffic analysis attacks","author":"fu","year":"2003","journal-title":"Proc 23rd IEEE Int Conf Distributed Computing Systems (ICDCS '03)"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.2005.853414"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2003.814797"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/10206\/5464437\/05411760.pdf?arnumber=5411760","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,11]],"date-time":"2021-10-11T01:36:37Z","timestamp":1633916197000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/5411760\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,6]]},"references-count":42,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2010.2041808","relation":{},"ISSN":["1556-6013"],"issn-type":[{"value":"1556-6013","type":"print"}],"subject":[],"published":{"date-parts":[[2010,6]]}}}