{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:39:22Z","timestamp":1750307962148,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":16,"publisher":"ACM","license":[{"start":{"date-parts":[[2007,6,12]],"date-time":"2007-06-12T00:00:00Z","timestamp":1181606400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2007,6,12]]},"DOI":"10.1145\/1269880.1269886","type":"proceedings-article","created":{"date-parts":[[2007,9,25]],"date-time":"2007-09-25T19:21:05Z","timestamp":1190748065000},"page":"17-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Authentication anomaly detection"],"prefix":"10.1145","author":[{"given":"Michael J.","family":"Chapple","sequence":"first","affiliation":[{"name":"University of Notre Dame, Notre Dame, IN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nitesh","family":"Chawla","sequence":"additional","affiliation":[{"name":"University of Notre Dame, Notre Dame, IN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aaron","family":"Striegel","sequence":"additional","affiliation":[{"name":"University of Notre Dame, Notre Dame, IN"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2007,6,12]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Computer security threat monitoring and surveillance. Technical report","author":"Anderson J. P.","year":"1980","unstructured":"J. P. Anderson . Computer security threat monitoring and surveillance. Technical report , National Institute of Standards and Technology , 1980 . J. P. Anderson. Computer security threat monitoring and surveillance. Technical report, National Institute of Standards and Technology, 1980."},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of a","author":"Brackney R. C.","year":"2004","unstructured":"R. C. Brackney and R. H. Anderson . Understanding the insider threat . In Proceedings of a March 2004 Workshop, pages 1--137, Santa Monica, CA, USA , 2004. RAND National Security Research Division. R. C. Brackney and R. H. Anderson. Understanding the insider threat. In Proceedings of a March 2004 Workshop, pages 1--137, Santa Monica, CA, USA, 2004. RAND National Security Research Division."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/1045502.1045530"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.5555\/580760.823766"},{"key":"e_1_3_2_1_5_1","volume-title":"Retreived on","author":"Deltac A. C.","year":"2006","unstructured":"A. C. Deltac . Geo::distance perl module, 2005. Retreived on October 8, 2006 from http:\/\/search.cpan.org\/ bluefeet\/Geo-Distance-0.11\/Distance.pm. A. C. Deltac. Geo::distance perl module, 2005. Retreived on October 8, 2006 from http:\/\/search.cpan.org\/ bluefeet\/Geo-Distance-0.11\/Distance.pm."},{"key":"e_1_3_2_1_6_1","first-page":"599","volume-title":"Proceedings of the IEEE\/IFIP Network Operations and Management Symposium","author":"Kim M.-S.","year":"2004","unstructured":"M.-S. Kim , H.-J. Kang , S.-C. Hong , S.-H. Chung , and J. W. Hong . A flow-based method for abnormal network traffic detection . In Proceedings of the IEEE\/IFIP Network Operations and Management Symposium , pages 599 -- 612 . IEEE, 2004 . M.-S. Kim, H.-J. Kang, S.-C. Hong, S.-H. Chung, and J. W. Hong. A flow-based method for abnormal network traffic detection. In Proceedings of the IEEE\/IFIP Network Operations and Management Symposium, pages 599--612. IEEE, 2004."},{"key":"e_1_3_2_1_7_1","volume-title":"Proc. 28th Australasian CS Conf.","volume":"38","author":"Leung K.","year":"2005","unstructured":"K. Leung and C. Leckie . Unsupervised anomaly detection in network intrusion detection using clusters . In Proc. 28th Australasian CS Conf. , volume 38 of CRPITV, 2005 . K. Leung and C. Leckie. Unsupervised anomaly detection in network intrusion detection using clusters. In Proc. 28th Australasian CS Conf., volume 38 of CRPITV, 2005."},{"volume-title":"Geolite city","year":"2006","key":"e_1_3_2_1_8_1","unstructured":"MaxMind. Geolite city , 2006 . Retrieved on October 8, 2006 from http:\/\/www.maxmind.com\/app\/geolitecity. MaxMind. Geolite city, 2006. Retrieved on October 8, 2006 from http:\/\/www.maxmind.com\/app\/geolitecity."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382923"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.IR.7007","volume-title":"An overview of issues in testing intrusion detection systems","author":"Mell P.","year":"2003","unstructured":"P. Mell , V. Hu , R. Lippmann , J. Haines , and M. Zissman . An overview of issues in testing intrusion detection systems . 2003 . NIST IR 7046. P. Mell, V. Hu, R. Lippmann, J. Haines, and M. Zissman. An overview of issues in testing intrusion detection systems. 2003. NIST IR 7046."},{"key":"e_1_3_2_1_11_1","first-page":"731","volume-title":"Proceedings of the 2004 IEEE International Conference on Networking, Sensing and Control","author":"Pai T.-L.","year":"2004","unstructured":"T.-L. Pai and P.-W. Wang . Netflow based intrusion detection system . In Proceedings of the 2004 IEEE International Conference on Networking, Sensing and Control , pages 731 -- 736 . IEEE, 2004 . T.-L. Pai and P.-W. Wang. Netflow based intrusion detection system. In Proceedings of the 2004 IEEE International Conference on Networking, Sensing and Control, pages 731--736. IEEE, 2004."},{"key":"e_1_3_2_1_12_1","volume-title":"ACM Workshop on Data Mining Applied to Security","author":"Portnoy L.","year":"2001","unstructured":"L. Portnoy , E. Eskin , and S. Stolfo . Intrusion detection with unlabeled data using clustering . In ACM Workshop on Data Mining Applied to Security , 2001 . L. Portnoy, E. Eskin, and S. Stolfo. Intrusion detection with unlabeled data using clustering. In ACM Workshop on Data Mining Applied to Security, 2001."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_1"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/645450.653063"},{"key":"e_1_3_2_1_15_1","volume-title":"Waikato environment for data analysis v3.5.3","author":"N. Z. University of Waikato.","year":"2005","unstructured":"N. Z. University of Waikato. Waikato environment for data analysis v3.5.3 , 2005 . Retrieved on October 8, 2006 from http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/. N. Z. University of Waikato. Waikato environment for data analysis v3.5.3, 2005. Retrieved on October 8, 2006 from http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/."},{"key":"e_1_3_2_1_16_1","volume-title":"Data Mining: Practical Machine Learning Tools and Techniques. Morgan Kaufmann Series in Data Management Systems. Morgan Kaufmann","author":"Witten I. H.","year":"2005","unstructured":"I. H. Witten and E. Frank . Data Mining: Practical Machine Learning Tools and Techniques. Morgan Kaufmann Series in Data Management Systems. Morgan Kaufmann , second edition, June 2005 . I. H. Witten and E. Frank. Data Mining: Practical Machine Learning Tools and Techniques. Morgan Kaufmann Series in Data Management Systems. Morgan Kaufmann, second edition, June 2005."}],"event":{"name":"SIGMETRICS07: ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems","sponsor":["SIGMETRICS ACM Special Interest Group on Measurement and Evaluation","ACM Association for Computing Machinery"],"location":"San Diego California USA","acronym":"SIGMETRICS07"},"container-title":["Proceedings of the 3rd annual ACM workshop on Mining network data"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1269880.1269886","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1269880.1269886","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T14:58:05Z","timestamp":1750258685000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1269880.1269886"}},"subtitle":["a case study on a virtual private network"],"short-title":[],"issued":{"date-parts":[[2007,6,12]]},"references-count":16,"alternative-id":["10.1145\/1269880.1269886","10.1145\/1269880"],"URL":"https:\/\/doi.org\/10.1145\/1269880.1269886","relation":{},"subject":[],"published":{"date-parts":[[2007,6,12]]},"assertion":[{"value":"2007-06-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}