{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T13:54:32Z","timestamp":1763474072323,"version":"3.45.0"},"publisher-location":"New York, NY, USA","reference-count":77,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,12,5]],"date-time":"2017-12-05T00:00:00Z","timestamp":1512432000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,12,5]]},"DOI":"10.1145\/3147234.3148137","type":"proceedings-article","created":{"date-parts":[[2017,12,6]],"date-time":"2017-12-06T16:25:26Z","timestamp":1512577526000},"page":"107-112","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Autonomic and Integrated Management for Proactive Cyber Security (AIM-PSC)"],"prefix":"10.1145","author":[{"given":"Fabian","family":"De La Pe\u00f1a Montero","sequence":"first","affiliation":[{"name":"AVIRTEK, INC, Tucson, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Salim","family":"Hariri","sequence":"additional","affiliation":[{"name":"University of Arizona, Tucson, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,12,5]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Retrieved","author":"Snider Mike","year":"2017","unstructured":"Mike Snider and Elizabeth Weise. 500 million Yahoo accounts breached. Retrieved August 11, 2017 from http:\/\/www.usatoday.com\/story\/tech\/2016\/09\/22\/report-yahoo-may-confirm-massive-data-breach\/90824934"},{"key":"e_1_3_2_1_2_1","volume-title":"Retrieved","author":"Hackett Robert","year":"2016","unstructured":"Robert Hackett. 2016. Quest Diagnostics Breach Exposes Health Data of 34,000 Customers. (December 2016). Retrieved August 11, 2017 from http:\/\/fortune.com\/2016\/12\/13\/quest-diagnostics-data-breach-health\/"},{"key":"e_1_3_2_1_3_1","volume-title":"Retrieved","author":"Weise Elizabeth","year":"2017","unstructured":"Elizabeth Weise. 360 million Myspace accounts breached. Retrieved August 11, 2017 from http:\/\/www.usatoday.com\/story\/tech\/2016\/05\/31\/360-million-myspace-accounts-breached\/85183200\/"},{"key":"e_1_3_2_1_4_1","volume-title":"2015 Cost of Data Breach Study: Global Analysis. (May","author":"Ponemon Institute LLC. 2015.","year":"2015","unstructured":"Ponemon Institute LLC. 2015. 2015 Cost of Data Breach Study: Global Analysis. (May 2015)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/1317532.1318041"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-006-4893-0"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/1538595"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5555\/784589.784632"},{"key":"e_1_3_2_1_9_1","first-page":"146","volume-title":"Proceedings of the 1999 IEEE Symposium on Security and Privacy.","author":"Lindqvista U.","unstructured":"U. Lindqvista and P.A. Porras, \"Detecting Computer and Network Misuse through the Production-Based Expert System Toolset (P-BEST)\", In Proceedings of the 1999 IEEE Symposium on Security and Privacy. pp. 146--161."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","first-page":"367","DOI":"10.1109\/DISCEX.2001.932231","volume-title":"Proceedings of the DARPA Information Survivability Conference & Exposition II, DISCEX '01","volume":"1","author":"Coit C.J.","unstructured":"C.J. Coit, S. Staniford, and J. McAlerney. \"Towards faster string matching for intrusion detection or exceeding the speed of snort\". In Proceedings of the DARPA Information Survivability Conference & Exposition II, DISCEX '01, volume 1, pages 367--373."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948145"},{"key":"e_1_3_2_1_13_1","unstructured":"L. Ert\u00f6z E. Eilertson A. Lazarevic P. Tan V. Kumar J. Srivastava and P. Dokas \"Minds - minnesota intrusion detection system\"."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"key":"e_1_3_2_1_15_1","unstructured":"H. S. Javitz and A. Valdes \"The nides statistical component: Description and justification\" Technical Report SRI International Menlo Park California 1994."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/1949221.1949232"},{"key":"e_1_3_2_1_17_1","unstructured":"D. Anderson T. F. Lunt H. Javitz A. Tamaru and A. Valdes \"Detecting unusual program behavior using the statistical component of the next-generation intrusion detection expert system nides\" Technical Report SRI-CSL-95-06 Computer Science Laboratory SRI International 1995."},{"key":"e_1_3_2_1_18_1","first-page":"353","volume-title":"Proceedings of the National Information Systems Security Conference 1997","author":"Porras P.A.","year":"1997","unstructured":"P.A. Porras and P.G. Neumann, \"Emerald: Event monitoring enabling responses to anomalous live disturbances\", In Proceedings of the National Information Systems Security Conference 1997, pages 353--365, 1997."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/597917.597922"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/775047.775103"},{"key":"e_1_3_2_1_21_1","first-page":"171","volume-title":"Proceedings of the 2000 IEEE Systems, Man, and Cybernetics Information Assurance and Security Workshop, 2000","author":"N. Ye.","year":"2000","unstructured":"N. Ye. \"A markov chain model of temporal behavior for anomaly detection\". In Proceedings of the 2000 IEEE Systems, Man, and Cybernetics Information Assurance and Security Workshop, 2000, pages 171--174, 2000."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/347090.347160"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1002\/qre.392"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-0953-0_4"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/375663.375668"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335388"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/645924.671334"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335437"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586146"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2007.03.025"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972719.28"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/784590.784673"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251421.1251433"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/1267549.1267555"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00140-7"},{"key":"e_1_3_2_1_36_1","volume-title":"Mississippi State Univ.","author":"Luo J.","year":"1999","unstructured":"J. Luo, \"Integrating fuzzy logic with data mining methods for intrusion detection.\", Master's thesis, Mississippi State Univ., 1999."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972740.30"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"R. Agarwal and M. V. Joshi \"Pnrule: A new framework for learning classifier models in data mining.\" Technical Report 00-015 Department of Computer Science University of Minnesota 2000.","DOI":"10.1137\/1.9781611972719.29"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00138-9"},{"key":"e_1_3_2_1_40_1","unstructured":"A. Lazarevic N. V. Chawla L. O. Hall and K. W. Bowyer \"Smoteboost: Improving the prediction of minority class in boosting.\" Technical Report 00-015 AHPCRC 2002."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/312129.312212"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1006624031083"},{"key":"e_1_3_2_1_43_1","unstructured":"S. M. Bridges \"Fuzzy data mining and genetic algorithms applied to intrusion detection\"."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/903866.903873"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.5555\/302528.302863"},{"key":"e_1_3_2_1_46_1","unstructured":"K. Das \"Protocol anomaly detection for network-based intrusion detection.\""},{"key":"e_1_3_2_1_47_1","unstructured":"E. Lemonnier \"Protocol anomaly detection in network-based idss 2001.\""},{"key":"e_1_3_2_1_48_1","unstructured":"S. Beetle \"A strict anomoly detection model for ids\" 2000."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.5555\/857183.857562"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/11576259_43"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.5555\/977403.978316"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/65.642356"},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the 13th ITC Specialist Seminar on Internet Traffic Measurement and Modeling","author":"McCreary S.","year":"2000","unstructured":"S. McCreary and K. Claffy, \"Trends in wide area IP traffic patterns - A view from ames Internet exchange.\", Proceedings of the 13th ITC Specialist Seminar on Internet Traffic Measurement and Modeling, Monterey, CA, 2000."},{"key":"e_1_3_2_1_54_1","volume-title":"Beyond folklore: Observations on fragmented traffic","author":"Shannon C.","year":"2002","unstructured":"C. Shannon, D. Moore, and K. Claffy, \"Beyond folklore: Observations on fragmented traffic\", 2002."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2003.1248656"},{"key":"e_1_3_2_1_56_1","unstructured":"K. Pentikousis and H. Badr \"Quantifying the deployment of tcp options - a comparative study\""},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"M. Allman \"A web server's view of the transport layer\" 2000.","DOI":"10.1145\/505672.505674"},{"key":"e_1_3_2_1_58_1","volume-title":"Measuring the evolution of transport protocols in the internet","author":"Medina A.","year":"2004","unstructured":"A. Medina, M. Allman, and S. Floyd, \"Measuring the evolution of transport protocols in the internet.\", 2004."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.5555\/311445"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_12"},{"key":"e_1_3_2_1_61_1","volume-title":"Columbia University","author":"Network K. Wang","year":"2007","unstructured":"K. Wang \"Network payload-based anomaly detection and content-based alert correlation.\", PhD thesis, Columbia University, 2007."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/362686.362692"},{"key":"e_1_3_2_1_63_1","unstructured":"A. Partow \"The general purpose hash function algorithm library.\""},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2005.136"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.5555\/3091622.3091637"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC.2008.25"},{"key":"e_1_3_2_1_67_1","unstructured":"C. M. Bishop \"Pattern Recognition and Machine Learning\" Springer 2007."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.5555\/784592.784788"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"crossref","first-page":"136","DOI":"10.1007\/978-3-540-45248-5_8","article-title":"et al, \"Using Specification-Based Intrusion Detection for Automated Response","volume":"2820","author":"Balepin I.","unstructured":"I. Balepin and S. Maltsev, et al, \"Using Specification-Based Intrusion Detection for Automated Response\" Lecture Notes in Computer Science, Volume 2820\/2003, Page 136--154","journal-title":"Lecture Notes in Computer Science"},{"key":"e_1_3_2_1_70_1","unstructured":"K. Lye and J. Wing \"Game Strategies in Network Security\" Carnegie Mellon University-CS-02-136 may 2002"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.5555\/248676"},{"key":"e_1_3_2_1_72_1","volume-title":"Game Theory\" MIT Press","author":"Fudenberg D.","year":"1991","unstructured":"D. Fudenberg and J. Tirole. \"Game Theory\" MIT Press, 1991."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.5555\/336277"},{"key":"e_1_3_2_1_74_1","article-title":"Autonomic Network Security Management: Design and Evaluation","author":"Hariri S.","year":"2007","unstructured":"S. Hariri, G. Qu, H. Chen, Y. Al-Nashif, M. Yousif, \"Autonomic Network Security Management: Design and Evaluation\", ACM Transactions on Autonomous and Adaptive Systems - Special Issue on Adaptive Learning in Autonomic Communication, 2007.","journal-title":"ACM Transactions on Autonomous and Adaptive Systems - Special Issue on Adaptive Learning in Autonomic Communication"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.5555\/534133"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","unstructured":"R. Hecht-Nielsen \"Neurocomputing.\" Addison-Wesley Reading MA 1990.","DOI":"10.5555\/103996"},{"key":"e_1_3_2_1_77_1","volume-title":"John Wiley and Sons","author":"Ross S. M.","year":"1987","unstructured":"S. M. Ross, \"Introduction to probability and statistics for engineers and scientists.\", John Wiley and Sons, New York, NY, 1987."}],"event":{"name":"UCC '17: 10th International Conference on Utility and Cloud Computing","sponsor":["IEEE TCSC IEEE Technical Committee on Scalable Computing","SIGARCH ACM Special Interest Group on Computer Architecture"],"location":"Austin Texas USA","acronym":"UCC '17"},"container-title":["Companion Proceedings of the10th International Conference on Utility and Cloud Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3147234.3148137","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3147234.3148137","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T13:52:31Z","timestamp":1763473951000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3147234.3148137"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,12,5]]},"references-count":77,"alternative-id":["10.1145\/3147234.3148137","10.1145\/3147234"],"URL":"https:\/\/doi.org\/10.1145\/3147234.3148137","relation":{},"subject":[],"published":{"date-parts":[[2017,12,5]]},"assertion":[{"value":"2017-12-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}