{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T08:58:24Z","timestamp":1767085104537,"version":"3.37.3"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2019,5,14]],"date-time":"2019-05-14T00:00:00Z","timestamp":1557792000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2019,5,14]],"date-time":"2019-05-14T00:00:00Z","timestamp":1557792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1526383."],"award-info":[{"award-number":["1526383."]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1186\/s42400-019-0032-0","type":"journal-article","created":{"date-parts":[[2019,5,14]],"date-time":"2019-05-14T13:03:59Z","timestamp":1557839039000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["ASSERT: attack synthesis and separation with entropy redistribution towards predictive cyber defense"],"prefix":"10.1186","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8990-6869","authenticated-orcid":false,"given":"Ahmet","family":"Okutan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shanchieh Jay","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,5,14]]},"reference":[{"key":"32_CR1","doi-asserted-by":"publisher","unstructured":"Al-Mohannadi, H, Mirza Q, Namanya A, Awan I, Cullen A, Disso J (2016) Cyber-attack modeling analysis techniques: An overview In: Proceedings of the 4th International Conference on Future Internet of Things and Cloud Workshops, 69\u201376, Vienna. \n                    https:\/\/doi.org\/10.1109\/W-FiCloud.2016.29\/W-FiCloud.2016.29\n                    \n                  .","DOI":"10.1109\/W-FiCloud.2016.29\/W-FiCloud.2016.29"},{"key":"32_CR2","doi-asserted-by":"publisher","first-page":"1299","DOI":"10.1145\/3133956.3134022","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS)","author":"L Bilge","year":"2017","unstructured":"Bilge, L, Han Y, Dell\u2019Amico M (2017) Riskteller: Predicting the risk of cyber incidents In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS), 1299\u20131311.. ACM, New York. \n                    https:\/\/doi.org\/10.1145\/3133956.3134022\n                    \n                  ."},{"key":"32_CR3","volume-title":"Recent Advances in Intrusion Detection. RAID 2009. Lecture Notes in Computer Science, vol 5758","author":"D Bolzoni","year":"2009","unstructured":"Bolzoni, D, Etalle S, Hartel PH (2009) Panacea: Automating attack classification for anomaly-based network intrusion detection systems. In: Kirda E Jha S (eds)Recent Advances in Intrusion Detection. RAID 2009. Lecture Notes in Computer Science, vol 5758.. Springer, Berlin, Heidelberg."},{"issue":"6","key":"32_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1371\/journal.pone.0131501","volume":"10","author":"YZ Chen","year":"2015","unstructured":"Chen, YZ, Huang ZG, Xu S, Lai YC (2015) Spatiotemporal patterns and predictability of cyberattacks. PLOS ONE 10(6):1\u20131. \n                    https:\/\/doi.org\/10.1371\/journal.pone.0131501\n                    \n                  .","journal-title":"PLOS ONE"},{"key":"32_CR5","unstructured":"CPTC Organizing Committee (2017) Collegiate penetration testing competition at Rochester Institute of Technology. \n                    https:\/\/nationalcptc.org\/\n                    \n                  ."},{"key":"32_CR6","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/978-3-642-19656-0_20","volume-title":"Proceedings of the 4th International Conference on Social Computing, Behavioral-Cultural Modeling and Prediction","author":"H Du","year":"2011","unstructured":"Du, H, Yang SJ (2011) Discovering collaborative cyber attack patterns using social network analysis In: Proceedings of the 4th International Conference on Social Computing, Behavioral-Cultural Modeling and Prediction, 129\u2013136.. Springer Berlin Heidelberg, College Park."},{"key":"32_CR7","unstructured":"Ester, M, Kriegel HP, Sander J, Xu X (1996) A density-based algorithm for discovering clusters a density-based algorithm for discovering clusters in large spatial databases with noise In: Proceedings of the Second International Conference on Knowledge Discovery and Data Mining, 226\u2013231.. AAAI Press, KDD\u201996. \n                    http:\/\/dl.acm.org\/citation.cfm?id=3001460.3001507\n                    \n                  ."},{"issue":"3","key":"32_CR8","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1109\/TIFS.2008.924605","volume":"3","author":"DS Fava","year":"2008","unstructured":"Fava, DS, Byers SR, Yang SJ (2008) Projecting cyberattacks through variable-length markov models. IEEE Trans Inf Forensic Secur 3(3):359\u2013369. \n                    https:\/\/doi.org\/10.1109\/TIFS.2008.924605\n                    \n                  .","journal-title":"IEEE Trans Inf Forensic Secur"},{"key":"32_CR9","unstructured":"Hackmageddon (2018) Hackmageddon information security timelines and statistics. \n                    http:\/\/www.hackmageddon.com\/\n                    \n                  . Accessed 6 Feb 2018."},{"key":"32_CR10","doi-asserted-by":"publisher","unstructured":"Haddadi, F, Khanchi S, Shetabi M, Derhami V (2010) Intrusion detection and attack classification using feed-forward neural network In: Proceedings of the 2010 Second International Conference on Computer and Network Technology, IEEE Computer Society, 262\u2013266, Washington, DC. \n                    https:\/\/doi.org\/10.1109\/ICCNT.2010.28\n                    \n                  . ICCNT \u201910.","DOI":"10.1109\/ICCNT.2010.28"},{"issue":"1","key":"32_CR11","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1016\/j.cose.2004.06.011","volume":"24","author":"S Hansman","year":"2005","unstructured":"Hansman, S, Hunt R (2005) A taxonomy of network and computer attacks. Comput Secur 24(1):31\u201343.","journal-title":"Comput Secur"},{"key":"32_CR12","doi-asserted-by":"publisher","unstructured":"Homer, J, Varikuti A, Ou X, Mcqueen MA (68) Improving attack graph visualization through data reduction and attack grouping In: Proceedings of the 5th International Workshop on Visualization for Computer Security. Springer-Verlag, Berlin. \n                    https:\/\/doi.org\/10.1007\/978-3-540-85933-8_7\n                    \n                  .","DOI":"10.1007\/978-3-540-85933-8_7"},{"key":"32_CR13","unstructured":"Kov\u00e1cs, F, Leg\u00e1ny C, Babos A (2005) Cluster validity measurement techniques In: 6th International symposium of hungarian researchers on computational intelligence."},{"issue":"1","key":"32_CR14","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1214\/aoms\/1177729694","volume":"22","author":"S Kullback","year":"1951","unstructured":"Kullback, S, Leibler RA (1951) On information and sufficiency. Ann Math Stat 22(1):79\u201386[\n                    https:\/\/doi.org\/10.1214\/aoms\/1177729694\n                    \n                  ].","journal-title":"Ann Math Stat"},{"key":"32_CR15","unstructured":"Kuncheva, LI (2008) Classifier ensembles for detecting concept change in streaming data: Overview and perspectives In: 2nd Workshop SUEMA, 5\u201310."},{"key":"32_CR16","first-page":"388","volume-title":"Proceedings of the 5th WSEAS International Conference on Artificial Intelligence, Knowledge Engineering and Data Bases, World Scientific and Engineering Academy and Society (WSEAS) AIKED\u201906","author":"C Legany","year":"2006","unstructured":"Legany, C, Juhasz S, Babos A (2006) Cluster validity measurement techniques In: Proceedings of the 5th WSEAS International Conference on Artificial Intelligence, Knowledge Engineering and Data Bases, World Scientific and Engineering Academy and Society (WSEAS) AIKED\u201906, 388\u2013393.. Stevens Point, Wisconsin."},{"issue":"1","key":"32_CR17","doi-asserted-by":"publisher","first-page":"424","DOI":"10.1016\/j.eswa.2011.07.032","volume":"39","author":"Y Li","year":"2012","unstructured":"Li, Y, Xia J, Zhang S, Yan J, Ai X, Dai K (2012) An efficient intrusion detection system based on support vector machines and gradually feature removal method. Expert Syst Appl 39(1):424\u2013430[\n                    http:\/\/doi.org\/10.1016\/j.eswa.2011.07.032\n                    \n                  ].","journal-title":"Expert Syst Appl"},{"key":"32_CR18","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1109\/18.61115","volume":"37","author":"J Lin","year":"1991","unstructured":"Lin, J (1991) Divergence measures based on the shannon entropy. IEEE Trans Inf Theory 37:145\u2013151.","journal-title":"IEEE Trans Inf Theory"},{"key":"32_CR19","first-page":"1009","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Y Liu","year":"2015","unstructured":"Liu, Y, Sarabi A, Zhang J, Naghizadeh P, Karir M, Bailey M, Liu M (2015) Cloudy with a chance of breach: Forecasting cyber security incidents In: 24th USENIX Security Symposium (USENIX Security 15), 1009\u20131024.. USENIX Association, Washington, D.C."},{"key":"32_CR20","doi-asserted-by":"crossref","unstructured":"Luo, G, Wen Y, Lingyun X (2016) Network attack classification and recognition using hmm and improved evidence theory. Int J Adv Comput Sci Appl 7(4).","DOI":"10.14569\/IJACSA.2016.070404"},{"key":"32_CR21","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-540-24668-8_21","volume-title":"Passive and Active Network Measurement","author":"A McGregor","year":"2004","unstructured":"McGregor, A, Hall M, Lorier P, Brunskill J (2004) Flow clustering using machine learning techniques. In: Pratt I Barakat C (eds)Passive and Active Network Measurement, 205\u2013214.. Springer Berlin Heidelberg, Berlin."},{"key":"32_CR22","unstructured":"Ning, P, Xu D, Healey CG, Amant RS (2004) Building attack scenarios through integration of complementary alert correlation methods In: Proceedings of the 11th Annual Network and Distributed System Security Symposium, 97\u2013111."},{"key":"32_CR23","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1016\/bs.host.2016.07.001","volume-title":"Handbook of Statistics","author":"S. Noel","year":"2016","unstructured":"Noel, S, Harley E, Tam K, Limiero M, Share M (2016) Chapter 4 \u2013 CyGraph: Graph-based analytics and visualization for cybersecurity. In: Gudivada VN, Raghavan VV, Govindaraju V, Rao C (eds)Cognitive Computing: Theory and Applications, Handbook of Statistics, vol 35, 117\u2013167.. Elsevier. \n                    https:\/\/doi.org\/10.1016\/bs.host.2016.07.001\n                    \n                  ."},{"key":"32_CR24","doi-asserted-by":"publisher","unstructured":"O\u2019Callaghan, L, Mishra N, Meyerson A, Guha S, Motwani R (2002) Streaming-data algorithms for high-quality clustering In: Proceedings of the 18th International Conference on Data Engineering, 685\u2013694. \n                    https:\/\/doi.org\/10.1109\/ICDE.2002.994785\n                    \n                  .","DOI":"10.1109\/ICDE.2002.994785"},{"key":"32_CR25","doi-asserted-by":"publisher","unstructured":"Salerno, JJ, Yang SJ, Kadar I, Sudit M, Tadda GP, Holsopple J (2010) Issues and challenges in higher level fusion: Threat\/impact assessment and intent modeling (a panel summary) In: 2010 13th International Conference on Information Fusion. \n                    https:\/\/doi.org\/10.1109\/ICIF.2010.5711862\n                    \n                  .","DOI":"10.1109\/ICIF.2010.5711862"},{"key":"32_CR26","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1145\/3098593.3098598","volume-title":"Proceedings of the Workshop on Big Data Analytics and Machine Learning for Data Communication Networks","author":"K Shadi","year":"2017","unstructured":"Shadi, K, Natarajan P, Dovrolis C (2017) Hierarchical ip flow clustering In: Proceedings of the Workshop on Big Data Analytics and Machine Learning for Data Communication Networks, 25\u201330.. ACM, New York Big-DAMA \u201917. \n                    http:\/\/doi.acm.org\/10.1145\/3098593.3098598\n                    \n                  ."},{"key":"32_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2014\/818957","volume":"2014","author":"Vivek Shandilya","year":"2014","unstructured":"Shandilya, V, Simmons CB, Shiva S (2014) Use of attack graphs in security systems. J Comput Netw Commun:13. \n                    http:\/\/doi.org\/10.1155\/2014\/818957\n                    \n                  .","journal-title":"Journal of Computer Networks and Communications"},{"key":"32_CR28","doi-asserted-by":"publisher","unstructured":"Song, S, Chen Z (2007) Adaptive network flow clustering In: Proceedings of the IEEE International Conference on Networking, Sensing and Control, 596\u2013601, London. \n                    https:\/\/doi.org\/10.1109\/ICNSC.2007.372846\n                    \n                  .","DOI":"10.1109\/ICNSC.2007.372846"},{"key":"32_CR29","doi-asserted-by":"crossref","unstructured":"Strapp, S, Yang SJ (2014) Segmenting large-scale cyber attacks for online behavior model generation. In: Kennedy WG, Agarwal N, Yang SJ (eds)Social Computing, Behavioral-Cultural Modeling and Prediction, 169\u2013177.. Springer International Publishing.","DOI":"10.1007\/978-3-319-05579-4_21"},{"key":"32_CR30","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1145\/502512.502568","volume-title":"Proceedings of the Seventh ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"WN Street","year":"2001","unstructured":"Street, WN, Kim Y (2001) A streaming ensemble algorithm (sea) for large-scale classification In: Proceedings of the Seventh ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 377\u2013382.. ACM, New York KDD \u201901. \n                    https:\/\/doi.org\/10.1145\/502512.502568\n                    \n                   \n                    http:\/\/doi.acm.org\/10.1145\/502512.502568\n                    \n                  ."},{"key":"32_CR31","doi-asserted-by":"publisher","unstructured":"Subba, B, Biswas S, Karmakar S (2016) A neural network based system for intrusion detection and attack classification In: Proceedings of the National Conference on Communication (NCC). \n                    https:\/\/doi.org\/10.1109\/NCC.2016.7561088\n                    \n                  .","DOI":"10.1109\/NCC.2016.7561088"},{"key":"32_CR32","unstructured":"Suricata (2019) An open source-based intrusion detection system (ids). \n                    https:\/\/suricata-ids.org\/\n                    \n                  . Accessed 15 Jan 2019."},{"key":"32_CR33","unstructured":"Symantec (2017) Internet security threat report. \n                    https:\/\/www.symantec.com\/security-center\/threat-report\n                    \n                  . Accessed 25 Apr 2017."},{"issue":"3","key":"32_CR34","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1109\/TDSC.2004.21","volume":"1","author":"F Valeur","year":"2004","unstructured":"Valeur, F, Vigna G, Kruegel C, Kemmerer RA (2004) Comprehensive approach to intrusion detection alert correlation. IEEE Trans Dependable Secure Comput 1(3):146\u2013169.","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"32_CR35","unstructured":"VERIS (2018) Veris community database (vcdb). \n                    http:\/\/veriscommunity.net\/index.html\n                    \n                  . Accessed 6 Sept 2018."},{"key":"32_CR36","doi-asserted-by":"publisher","first-page":"88","DOI":"10.2481\/dsj.007-020","volume":"8","author":"K Wang","year":"2009","unstructured":"Wang, K, Wang B, Peng L (2009) CVAP: validation for cluster analyses. Data Sci J 8:88\u201393.","journal-title":"Data Sci J"},{"issue":"15","key":"32_CR37","doi-asserted-by":"publisher","first-page":"2917","DOI":"10.1016\/j.comcom.2006.04.001","volume":"29","author":"L Wang","year":"2006","unstructured":"Wang, L, Liu A, Jajodia S (2006) Using attack graphs for correlating, hypothesizing, and predicting intrusion alerts. Comput Commun 29(15):2917\u20132933. \n                    https:\/\/doi.org\/10.1016\/j.comcom.2006.04.001\n                    \n                  .","journal-title":"Comput Commun"},{"key":"32_CR38","volume-title":"k-Zero Day Safety: Measuring the Security Risk of Networks against Unknown Attacks","author":"L Wang","year":"2010","unstructured":"Wang, L, Jajodia S, Singhal A, Noel S (2010) k-Zero Day Safety: Measuring the Security Risk of Networks against Unknown Attacks. Springer Berlin Heidelberg, Berlin."},{"key":"32_CR39","unstructured":"WASC (2018) The web hacking incident database. \n                    http:\/\/projects.webappsec.org\/w\/page\/13246995\/Web-Hacking-Incident-Database\n                    \n                  . Accessed 6 Sept 2018."},{"issue":"01","key":"32_CR40","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1142\/S0218213000000069","volume":"9","author":"C Wemmert","year":"2000","unstructured":"Wemmert, C, Gan\u010barski P, Korczak JJ (2000) A collaborative approach to combine multiple learning methods. Int J Artif Intell Tools 9(01):59\u201378.","journal-title":"Int J Artif Intell Tools"},{"key":"32_CR41","doi-asserted-by":"publisher","unstructured":"Xu, K, Wang F, Gu L (2011) Network-aware behavior clustering of internet end hosts In: 2011 Proceedings of the IEEE INFOCOM, 2078\u20132086. \n                    https:\/\/doi.org\/10.1109\/INFCOM.2011.5935017\n                    \n                  .","DOI":"10.1109\/INFCOM.2011.5935017"},{"issue":"1","key":"32_CR42","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1016\/j.inffus.2007.06.002","volume":"10","author":"SJ Yang","year":"2009","unstructured":"Yang, SJ, Stotz A, Holsopple J, Sudit M, Kuhl M (2009) High level information fusion for tracking and projection of multistage cyber attacks. Inf Fusion 10(1):107\u2013121. \n                    https:\/\/doi.org\/10.1016\/j.inffus.2007.06.002\n                    \n                  .","journal-title":"Inf Fusion"},{"key":"32_CR43","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1007\/978-3-319-11391-3_12","volume-title":"Cyber Defense and Situational Awareness","author":"SJ Yang","year":"2014","unstructured":"Yang, SJ, Du H, Holsopple J, Sudit M (2014) Attack projection. In: Kott A, Wang C, Erbacher RF (eds)Cyber Defense and Situational Awareness, 239\u2013261.. Springer International Publishing, New York City, chap Attack Projection."},{"key":"32_CR44","doi-asserted-by":"publisher","first-page":"1117","DOI":"10.1145\/2660267.2660330","volume-title":"Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security (CCS)","author":"TF Yen","year":"2014","unstructured":"Yen, TF, Heorhiadi V, Oprea A, Reiter MK, Juels A (2014) An epidemiological study of malware encounters in a large enterprise In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security (CCS), 1117\u20131130.. ACM, New York, CCS \u201914. \n                    https:\/\/doi.org\/10.1145\/2660267.2660330\n                    \n                  ."},{"issue":"5","key":"32_CR45","doi-asserted-by":"publisher","first-page":"649","DOI":"10.1109\/TSMCC.2008.923876","volume":"38","author":"J Zhang","year":"2008","unstructured":"Zhang, J, Zulkernine M, Haque A (2008) Random-forests-based network intrusion detection systems. IEEE Transactions on Systems, Man, and Cybernetics, Part C 38(5):649\u2013659. \n                    https:\/\/doi.org\/10.1109\/TSMCC.2008.923876\n                    \n                  .","journal-title":"IEEE Transactions on Systems, Man, and Cybernetics, Part C"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-019-0032-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s42400-019-0032-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-019-0032-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,14]],"date-time":"2020-05-14T10:12:00Z","timestamp":1589451120000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-019-0032-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,5,14]]},"references-count":45,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,12]]}},"alternative-id":["32"],"URL":"https:\/\/doi.org\/10.1186\/s42400-019-0032-0","relation":{},"ISSN":["2523-3246"],"issn-type":[{"type":"electronic","value":"2523-3246"}],"subject":[],"published":{"date-parts":[[2019,5,14]]},"assertion":[{"value":"16 January 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 April 2019","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 May 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"All authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Publisher\u2019s Note"}}],"article-number":"15"}}