{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,22]],"date-time":"2025-03-22T10:02:26Z","timestamp":1742637746164,"version":"3.37.3"},"reference-count":39,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2015,8,1]],"date-time":"2015-08-01T00:00:00Z","timestamp":1438387200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-13-1-0141"],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2015,8]]},"DOI":"10.1109\/tifs.2015.2422261","type":"journal-article","created":{"date-parts":[[2015,4,13]],"date-time":"2015-04-13T18:43:51Z","timestamp":1428950631000},"page":"1666-1677","source":"Crossref","is-referenced-by-count":86,"title":["Predicting Cyber Attack Rates With Extreme Values"],"prefix":"10.1109","volume":"10","author":[{"family":"Zhenxin Zhan","sequence":"first","affiliation":[]},{"family":"Maochao Xu","sequence":"additional","affiliation":[]},{"family":"Shouhuai Xu","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"journal-title":"Quantitative Risk Management Concepts Techniques and Tools","year":"2010","author":"mcneil","key":"ref39"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/S0927-5398(00)00012-8"},{"journal-title":"Honeypot Dionaea","year":"2014","key":"ref33"},{"journal-title":"Amun honeypot","year":"2014","key":"ref32"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1193207"},{"key":"ref30","first-page":"1","article-title":"A virtual honeypot framework","volume":"13","author":"provos","year":"2004","journal-title":"Proc 13th Conf USENIX Security Symp (SSYM '04)"},{"key":"ref37","first-page":"282","article-title":"Conditional random fields: Probabilistic models for segmenting and labeling sequence data","author":"lafferty","year":"2001","journal-title":"Proc 18th Int Conf Mach Learn"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1198\/00401700152672573"},{"key":"ref35","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1007\/11856214_9","article-title":"The Nepenthes platform: An efficient approach to collect malware","author":"baecher","year":"2006","journal-title":"Proc of the Int Symp on Recent Advances in Intrusion Detection (RAID)"},{"journal-title":"Mwcollector Honeypot","year":"2014","key":"ref34"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2010.2086445"},{"key":"ref11","first-page":"599","article-title":"A flow-based method for abnormal network traffic detection","author":"kim","year":"2004","journal-title":"Proc IEEE\/IFIP NOMS"},{"key":"ref12","first-page":"39","article-title":"A DoS resilient flow-level intrusion detection approach for high-speed networks","author":"gao","year":"2006","journal-title":"Proc 26th IEEE Int Conf Distrib Comput Syst (ICDCS)"},{"key":"ref13","first-page":"1","article-title":"Flow-based worm detection using correlated honeypot logs","author":"dressler","year":"2007","journal-title":"Proc ITG-GI Conf Commun Distrib Syst (KiVS)"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/WETICE.2005.40"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-68768-1_1"},{"key":"ref16","first-page":"967","article-title":"Using machine learning techniques to identify botnet traffic","author":"livadas","year":"2006","journal-title":"Proc 31st IEEE LCN Workshop Netw Security (WoNS)"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/AICCSA.2010.5587041"},{"article-title":"Honeypot traces forensics by means of attack event identification","year":"2009","author":"pham","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/775094.775102"},{"key":"ref28","doi-asserted-by":"crossref","DOI":"10.1201\/9781420010893","author":"zucchini","year":"2009","journal-title":"Hidden Markov Models for Time Series An Introduction Using R"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2008.05.012"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1093\/acprof:oso\/9780199549498.001.0001"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICIMP.2009.9"},{"key":"ref6","first-page":"79","article-title":"Extracting inter-arrival time based behaviour from honeypot traffic using cliques","author":"almotairi","year":"2007","journal-title":"Proc of 5th Australian Digital Forensics Conference"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/882085.882086"},{"key":"ref5","first-page":"1","article-title":"Honeypot-based forensics","author":"pouget","year":"2004","journal-title":"Proc Asia Pacific Inf Technol Secur Conf (AusCERT)"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/NPC.2008.82"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/1029208.1029216"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"ref9","first-page":"21","article-title":"Internet attack knowledge discovery via clusters and cliques of attack traces","volume":"1","author":"clark","year":"2006","journal-title":"Journal of Info Assurance and Security"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2013.2279800"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"ref22","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1145\/2398776.2398781","article-title":"Classifying Internet one-way traffic","author":"glatz","year":"2012","journal-title":"Proc ACM Internet Meas Conf"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879149"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33483-2"},{"key":"ref23","article-title":"A characterization of cybersecurity posture from network telescope data","author":"zhan","year":"2014","journal-title":"Proc 6th Int Conf Trustworthy Syst (InTrust)"},{"key":"ref26","doi-asserted-by":"crossref","DOI":"10.1007\/978-0-387-75959-3","author":"cryer","year":"2008","journal-title":"Time Series Analysis with Applications in R"},{"journal-title":"Heavy-Tail Phenomena Probabilistic and Statistical Modeling","year":"2007","author":"resnick","key":"ref25"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/7127092\/07084651.pdf?arnumber=7084651","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T12:09:56Z","timestamp":1691582996000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7084651\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,8]]},"references-count":39,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2015.2422261","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2015,8]]}}}