{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T09:29:06Z","timestamp":1763458146688,"version":"3.45.0"},"publisher-location":"New York, NY, USA","reference-count":17,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,4,5]],"date-time":"2017-04-05T00:00:00Z","timestamp":1491350400000},"content-version":"vor","delay-in-days":365,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1524940"],"award-info":[{"award-number":["1524940"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2016,4,5]]},"DOI":"10.1145\/2897795.2897817","type":"proceedings-article","created":{"date-parts":[[2016,4,7]],"date-time":"2016-04-07T18:22:33Z","timestamp":1460053353000},"page":"1-4","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Network Modeling for Security Analytics"],"prefix":"10.1145","author":[{"given":"Bailey","family":"Smith","sequence":"first","affiliation":[{"name":"The University of Tulsa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Whitney","family":"Caruthers","sequence":"additional","affiliation":[{"name":"The University of Tulsa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dalton","family":"Stewart","sequence":"additional","affiliation":[{"name":"The University of Tulsa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peter","family":"Hawrylak","sequence":"additional","affiliation":[{"name":"The University of Tulsa"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John","family":"Hale","sequence":"additional","affiliation":[{"name":"The University of Tulsa"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2016,4,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Raspberry pi. https:\/\/www.adafruit.com\/raspberrypi."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298314"},{"key":"e_1_3_2_1_3_1","first-page":"5","article-title":"Wireshark-network protocol analyzer","volume":"99","author":"Combs G.","year":"2008","unstructured":"G. Combs et al. Wireshark-network protocol analyzer. Version 0.99, 5, 2008.","journal-title":"Version 0"},{"key":"e_1_3_2_1_4_1","volume-title":"An introduction to Nmap. Technical report","author":"Corcoran T.","year":"2001","unstructured":"T. Corcoran. An introduction to Nmap. Technical report, 2001."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/977404.978594"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2005.854116"},{"key":"e_1_3_2_1_8_1","first-page":"104","volume-title":"International Conference on Internet Computing","author":"Louthan G.","year":"2009","unstructured":"G. Louthan, C. McMillan, C. Johnson, and J. Hale. Toward robust and extensible automatic protocol identification. In International Conference on Internet Computing, pages 104--108, 2009."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-005-6263-2"},{"key":"e_1_3_2_1_10_1","volume-title":"DTIC Document","author":"Montigny-Leboeuf D.","year":"2004","unstructured":"D. Montigny-Leboeuf, F. Massicotte, et al. Passive network discovery for real time situation awareness. Technical report, DTIC Document, 2004."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-31966-5_4"},{"key":"e_1_3_2_1_12_1","volume-title":"Ettercap","author":"Ornaghi A.","year":"2005","unstructured":"A. Ornaghi and M. Valleri. Ettercap, 2005."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/310889.310919"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/882494.884423"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","unstructured":"W. Stallings. SNMP SNMPv2 SNMPv3 and RMON 1 and 2. Addison-Wesley Longman 1998.","DOI":"10.5555\/521036"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2006.74"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/1025116.1025334"}],"event":{"name":"CISRC '16: 11th Annual Cyber and Information Security Research","sponsor":["Oak Ridge National Laboratory"],"location":"Oak Ridge TN USA","acronym":"CISRC '16"},"container-title":["Proceedings of the 11th Annual Cyber and Information Security Research Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2897795.2897817","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2897795.2897817","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2897795.2897817","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T09:18:53Z","timestamp":1763457533000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2897795.2897817"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,4,5]]},"references-count":17,"alternative-id":["10.1145\/2897795.2897817","10.1145\/2897795"],"URL":"https:\/\/doi.org\/10.1145\/2897795.2897817","relation":{},"subject":[],"published":{"date-parts":[[2016,4,5]]},"assertion":[{"value":"2016-04-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}