{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T21:45:27Z","timestamp":1772833527425,"version":"3.50.1"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2010,12,1]],"date-time":"2010-12-01T00:00:00Z","timestamp":1291161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2010,12]]},"DOI":"10.1109\/tifs.2010.2066970","type":"journal-article","created":{"date-parts":[[2010,8,18]],"date-time":"2010-08-18T19:31:29Z","timestamp":1282159889000},"page":"905-919","source":"Crossref","is-referenced-by-count":21,"title":["Dynamic Feature Analysis and Measurement for Large-Scale Network Traffic Monitoring"],"prefix":"10.1109","volume":"5","author":[{"given":"Xiaohong","family":"Guan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tao","family":"Qin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pinghui","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCW.2008.45"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1012888.1005697"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.896150"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177102"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICIMP.2008.18"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1012888.1005699"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028813"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/948205.948236"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0000(85)90041-8"},{"key":"ref34","first-page":"29","article-title":"an improved data stream summary: the count-min sketch and its applications","author":"cormode","year":"2004","journal-title":"Proc Latin American Theoretical Informatics"},{"key":"ref10","first-page":"15","article-title":"role classification of hosts within enterprise networks based on connection patterns","author":"tan","year":"2003","journal-title":"Proc Usenix 2003 Ann Technical Conf"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330124"},{"key":"ref11","first-page":"1","article-title":"enterprise security: a community of interest based approach","author":"mcdaniel","year":"2006","journal-title":"Proc 3th Annu Network and Distributed System Security Symp"},{"key":"ref12","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1007\/978-3-540-31966-5_7","article-title":"analysis of communities of interest in data networks","author":"aiello","year":"2005","journal-title":"Proceedings of the Passive and Active Network Measurement Workshop"},{"key":"ref13","year":"0","journal-title":"Cisco Netflow"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2002.805796"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2003.814797"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924294"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1090191.1080112"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330126"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2004.1301325"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.852874"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637210"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330146"},{"key":"ref3","first-page":"599","article-title":"a flow-based method for abnormal network traffic detection","author":"kim","year":"2004","journal-title":"Proc IEEE\/IFIP Network Operations and Management Symp"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TIM.2008.926046"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637225"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/952589.952601"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298321"},{"key":"ref7","first-page":"2056","article-title":"a study of analyzing network traffic as images in real-time","author":"kim","year":"2005","journal-title":"Proc IEEE InfoCom"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1012888.1005745"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2006.886288"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2006.04.003"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2005.857113"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2007.21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1273445.1273448"},{"key":"ref21","first-page":"1","article-title":"worm detection using local networks","author":"qin","year":"2004","journal-title":"Recent Advances Intrusion Detection"},{"key":"ref42","article-title":"measuring network change: renyi cross entropy and the second order degree distribution","author":"edward","year":"2006","journal-title":"Proc Passive and Active Measurement Conf 2006"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31966-5_25"},{"key":"ref41","article-title":"the architecture of the coralreef: internet traffic monitoring software suite","author":"keys","year":"2001","journal-title":"Proc Passive Active Measurement Workshop"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/90.779192"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330148"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/1129582.1129589"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/1452520.1452539"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/NAS.2007.6"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/10206\/5623286\/05546965.pdf?arnumber=5546965","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,11]],"date-time":"2021-10-11T00:45:23Z","timestamp":1633913123000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/5546965\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,12]]},"references-count":45,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2010.2066970","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010,12]]}}}