Computer & Network Security Bibliography:

[AbelsonH97a]
Title: "The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption"
Author: "Harold Abelson and Ross Anderson and Steven Bellovin and others"
Journal: "World Wide Web Journal"
Year: 1997
Volume: 2
Number: 3

[AgrawalD03a]
Title: "Measuring Anonymity: The Disclosure Attack"
Author: "Dakshi Agrawal and Dogan Kesdogan"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Nov-Dec"
Volume: 1
Number: 6

[AllenW03a]
Title: "On the Self-Similarity of Synthetic Traffic for the Evaluation of Intrusion Detection Systems"
Author: "William H. Allen and Gerald A. Marin"
Proceedings: "Proceedings, IEEE/IPSJ International Symposium on Applications and the Internet (SAINT)"
Year: 2003

[AllenW03b]
Title: "Analysis, Detection, and Modeling of Attacks in Computer Communication Networks"
Author: "William H. Allen"
School: "University of Central Florida"
Year: 2003

[AllenW04a]
Title: "The LoSS Technique for Detecting New Denial of Service Attacks"
Author: "William H. Allen and Gerald A. Marin"
Proceedings: "Proceedings, IEEE SoutheastCon 2004"
Year: 2004

[AllenW04b]
Title: "MAGNA: Modeling and Generating Network Attacks"
Author: "William H. Allen and Gerald A. Marin"
Proceedings: "Proceedings, IEEE Conference on Local Computer Networks (to appear)"
Year: 2004

[AmatoV00a]
Title: "Cisco Networking Academy Program: First-Year Companion Guide"
Author: "Vito Amato"
Publisher: "Cisco Press"
Year: 2000

[AmorosoE93a]
Title: "A Graduate Course in Computing Security Technology"
Author: "Edward Amoroso"
Proceedings: "Proceedings, 24th SigCSE Technical Symposium"
Year: 1993

[AndersonD95a]
Title: "Next-generation Intrusion Detection Expert System (NIDES) a Summary"
Author: "Debra Anderson and Thane Frivold and Alfonso Valdes"
Institution: "SRI International"
Type: "Technical Report SRI-CSL-95-07"
Month: "May"
Year: 1995

[AndersonE97a]
Title: "Extensible, Scalable Monitoring for Clusters of Computers"
Author: "Eric Anderson and Dave Patterson"
Proceedings: "Proceedings, 11th USENIX LISA Conference"
Year: 1997
Month: "Oct"

[AndersonJ80a]
Title: "Computer Security Threat Monitoring and Surveillance"
Author: "James Anderson"
Institution: "J. P. Anderson Co."
Year: 1980

[AndrewsM03a]
Title: "HEAT: Runtime Interception of Win32 Functions"
Author: "Michael M. Andrews"
Institution: "Florida Institute of Technology"
Type: "Technical Report CS-2003-1"
Year: 2003

[AntonatosS04a]
Title: "Generating Realistic Workloads for Network Intrusion Detection Systems"
Author: "Spyros Antonatos and Kostas Anagnostakis and Evangelos Markatos"
Proceedings: "Proceedings, ACM Workshop on Software Performance"
Year: 2004

[Apache02a]
Title: "Apache HTTP server web site"
Author: "Apache Group"
URL: www.apache.org
Year: 2003

[ApostolopoulosG99a]
Title: "Transport Layer Security: how much does it really cost?"
Author: "George Apostolopoulos and Vinod Peris and Debanjan Saha"
Proceedings: "Proceedings, IEEE INFOCOMM"
Year: 1999

[ApthorpeR01a]
Title: "A Probabilistic Approach to Estimating Computer System Reliability"
Author: "Robert Apthorpe"
Proceedings: "Proceedings, 15th USENIX LISA Conference"
Year: 2001
Month: "Dec"

[ApvrilleA04a]
Title: "Stop Malicious Code Execution at Kernel-Level"
Author: "A. Apvrille and M. Pourzandi and D. Gordon and V. Roy"
Journal: "Linux Journal"
Year: 2004
Month: "Jan"

[ArbaughW00a]
Title: "Windows of Vulnerability: a Case Study Analysis"
Author: "William Arbaugh and William Fithen and John McHugh"
Journal: "IEEE Computer"
Year: 2000
Month: "Dec"

[ArbaughW98a]
Title: "Security for Virtual Private Intranets"
Author: "William Arbaugh and James Davin and others"
Journal: "IEEE Computer"
Year: 1998
Month: "Sep"

[AthanasiadesN03a]
Title: "Intrusion Detection Testing and Benchmarking Methodologies"
Author: "Nicholas Athanansiades and Randal Abler and others"
Proceedings: "Proceedings, IEEE International Workshop on Information Assurance"
Year: 2003

[AxelssonS00a]
Title: "Intrusion Detection Systems: a Survey and Taxonomy"
Author: "Stefan Axelsson"
Institution: "Chalmers University of Technology"
Type: "Technical Report 99-15"
Year: 2000

[AxelssonS98a]
Title: "Research in Intrusion Detection Systems: a Survey"
Author: "Stefan Axelsson"
Institution: "Chalmers University of Technology"
Type: "Technical Report 98-17"
Year: 1998

[AxelssonS99a]
Title: "The Base-rate Fallacy and its Implications for the Difficulty of Intrusion Detection"
Author: "Stefan Axelsson"
Proceedings: "Proceedings, ACM Computer and Communications Security Conference"
Year: 1999

[AyedemirM01a]
Title: "Two tools for network traffic analysis"
Author: "M. Ayedemir and L. Bottomley and M. Coffin and others"
Journal: "Computer Networks"
Year: 2001
Volume: 36

[BaceR00a]
Title: "Intrusion Detection"
Author: "Rebecca G. Bace"
Publisher: "Macmillian Technical Publishing"
Year: 2000

[BalzerR99a]
Title: "Mediating Connectors: A Non-bypassable Process Wrapping Technology"
Author: "Robert Balzer and Neil Goldman"
Proceedings: "Proceedings, Distributed Computer Systems Workshop on E-Commerce and Web-based Applications"
Year: 1999

[BannetJ04a]
Title: "Hack-a-Vote: Security Issues with Electronic Voting Systems"
Author: "Jonathan Bannet and David W. Price and others"
Journal: "IEEE Security and Privacy"
Year: 2004
Month: "Jan-Feb"
Volume: 2
Number: 1

[BarbaraD00a]
Title: "Using the Fractal Dimension to Cluster Datasets"
Author: "Daniel Barbara and Ping Chen"
Proceedings: "Proceedings, 6th International Conference on Knowledge Discovery and Data Mining (KDD 2000)"
Year: 2000

[BarbaraD01a]
Title: "Detecting Novel Network Intrusions Using Bayes Estimators"
Author: "Daniel Barbara and Ningning Wu and Shushil Jajodia"
Proceedings: "Proceedings, SIAM Conference on Data Mining"
Year: 2001
Month: "April"

[BarbaraD01b]
Title: "ADAM: A Testbed for Exploring the Use of Data Mining in Intrusion Detection"
Author: "Daniel Barbara and Julia Couto and Shushil Jajodia and Ningning Wu"
Journal: "SIGMOD Record"
Year: 2001
Month: "Dec"
Volume: 30
Number: 4

[BarbaraD99a]
Title: "Chaotic Mining: Knowledge Discovery Using the Fractal Dimension"
Author: "Daniel Barbara"
Proceedings: "Proceedings, SIGMOD Data Mining and Knowledge Discovery Workshop"
Year: 1999

[BarfieldL93a]
Title: "The User Interface: Concepts and Design"
Author: "Lon Barfield"
Publisher: "Addison-Wesley"
Year: 1993

[BarfordP01a]
Title: "Characteristics of Network Traffic Flow Anomalies"
Author: "Paul Barford and David Plonka"
Proceedings: "Proceedings, ACM SIGCOMM Internet Measurement Workshop"
Year: 2001

[BassT00a]
Title: "Intrusion Detection Systems and Multisensor Data Fusion"
Author: "Tim Bass"
Journal: "Communications of the ACM"
Year: 2000
Month: "Apr"
Volume: 43
Number: 4

[BauerD01a]
Title: "Detecting Anomalous Behavior: Optimization of Network Traffic Parameters Via an Evolutionary Strategy"
Author: "Dennis C. Bauer and James Cannady and Raymond C. Garcia"
Proceedings: "Proceedings, IEEE SoutheastCon 2001"
Year: 2001

[BeckerR88a]
Title: "The S Language"
Author: "Richard Becker and John Chambers and Allan Wilks"
Publisher: "Wadsworth and Brooks/Cole"
Year: 1988

[BeckerR95a]
Title: "Visualizing Network Data"
Author: "Richard Becker and Stephen Eick and Allan Wilks"
Journal: "IEEE Transactions on Visualizations and Computer Graphics"
Year: 1995
Month: "Mar"

[BejtlichR00a]
Title: "Network Intrusion Detection of Third Party Effects"
Author: "Richard Bejtlich"
URL: www.bejtlich.net
Year: 2000

[BellD76a]
Title: "Secure Computer System: unified Exposition and Multics Interpretation"
Author: "David Bell and Leonard LaPadula"
Institution: "Mitre Corporation"
Type: "Technical Report MTR-2997"
Year: 1976

[BellovinS00a]
Title: "ICMP Traceback Messages"
Author: "Steven M. Bellovin"
Year: 2000

[BellovinS89a]
Title: "Security Problems in the TCP/IP Protocol Suite"
Author: "Steven Bellovin"
Journal: "Computer Communications Review"
Year: 1989
Month: "Apr"
Volume: 19
Number: 2

[BellovinS92a]
Title: "There Be Dragons"
Author: "Steven M. Bellovin"
Proceedings: "Proceedings, 3rd USENIX UNIX Security Symposium"
Year: 1992
Month: "Sep"

[BellovinS93a]
Title: "Packets Found on an Internet"
Author: "Steven Bellovin"
Journal: "Computer Communications Review"
Year: 1993
Month: "July"
Volume: 23
Number: 3

[BellovinS96a]
Title: "Problem areas for the IP security protocols"
Author: "Steven M. Bellovin"
Proceedings: "Proceedings, 6th USENIX UNIX Security Symposium"
Year: 1996
Month: "July"

[BellovinS99a]
Title: "Why System Administration is Hard"
Author: "Steven M. Bellovin"
Year: 1999

[BelussiA95a]
Title: "Estimating the Selectivity of Spatial Queries Using the Correlation Fractal Dimension"
Author: "Alberto Belussi and Christos Faloutsos"
Proceedings: "Proceedings, Conference on Very Large Databases"
Year: 1995

[BeranJ94a]
Title: "Statistics for Long-Memory Processes"
Author: "Jan Beran"
Publisher: "Chapman and Hall"
Year: 1994

[BeranJ95a]
Title: "Long-Range Dependence in Variable-Bit-Rate Video Traffic"
Author: "Jan Beran and Robert Sherman and Murad Taqqu and Walter Willinger"
Journal: "IEEE Transactions on Communications"
Year: 1995
Volume: 43
Number: 2
Month: "Feb-Apr"

[BerghelH03a]
Title: "Malware Month"
Author: "Hal Berghel"
Journal: "Communications of the ACM"
Year: 2003
Month: "Dec"
Volume: 46
Number: 12

[BertinJ83a]
Title: "Semiology of Graphics"
Author: "Jacques Bertin"
Publisher: "University of Wisconsin Press"
Year: 1983

[BetserJ01a]
Title: "GlobalGuard: Creating the IETF-IDWG Intrusion Alert Protocol (IAP)"
Author: "J. Betser and A. Walther and M. Erlinger and others"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001
Month: "Jan"

[BillingsL02a]
Title: "A Unified Prediction of Computer Virus Spread in Connected Networks"
Author: "Lora Billings and William Spears and Ira Schwartz"
Journal: "Physics Letters A"
Year: 2002
Volume: 297
Number: 3

[BishopM02a]
Title: "Computer Security Education: Training, Scholarship and Research"
Author: "Matt Bishop"
Journal: "IEEE Computer"
Year: 2003
Month: "April"
Volume: 35
Number: 4

[BishopM03a]
Title: "What is Computer Security?"
Author: "Matt Bishop"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jan-Feb"
Volume: 1
Number: 1

[BishopM04a]
Title: "Teaching Robust Programming"
Author: "Matt Bishop and Deborah Frincke"
Journal: "IEEE Security and Privacy"
Year: 2004
Month: "Mar-Apr"
Volume: 2
Number: 2

[BishopM95a]
Title: "A Standard Audit Trail Format"
Author: "Matt Bishop"
Proceedings: "Proceedings, 18th National Information Systems Security Conference"
Year: 1995
Month: "Oct"

[BishopM96a]
Title: "An Isolated Network for Research"
Author: "Matt Bishop and Todd Heberlein"
Proceedings: "Proceedings, 19th National Information Systems Security Conference"
Year: 1996
Month: "Oct"

[BlattnerM94a]
Title: "In Our Image: Interface Design in the 1990's"
Author: "Meera Blattner"
Journal: "IEEE Multimedia"
Year: 1994
Month: "Spring"

[BlazeM00a]
Title: "Tapping at my network door"
Author: "Mark Blaze and Steven Bellovin"
Journal: "Communications of the ACM"
Year: 2000
Month: "Oct"
Volume: 43
Number: 10

[BloedornE01a]
Title: "Data Mining for Network Intrusion Detection: How to Get Started"
Author: "Eric Bloedorn and Alan Christiansen and William Hill and others"
Institution: "Mitre Corporation"
Type: "Technical Report"
Year: 2001

[BowenT00a]
Title: "Remediation of Application Specific Security Vunerabilities at Runtime"
Author: "Thomas Bowen and Mark Segal"
Journal: "IEEE Software"
Year: 2000
Month: "Sep"

[BowenT00b]
Title: "Building Survivable Systems: an integerated approach based on intrusion detection and damage containment"
Author: "Thomas Bowen and D. Chee and M. Segal and others"
Proceedings: "Proceedings, DARPA Information Survivability Conference"
Year: 2000

[BoxG78a]
Title: "Statistics for Experimenters"
Author: "George Box and William Hunter and Stuart Hunter"
Publisher: "John Wiley and Sons"
Year: 1978

[BradleyK98a]
Title: "Detecting Disruptive Routers: A Distributed Network Monitoring Approach"
Author: "Kirk A. Bradley and Steven Cheung and Nicholas Puketza and others"
Journal: "IEEE Network"
Year: 1998
Month: "Sept"

[BrownJ00a]
Title: "Network Performance Visualization: Insight Through Animation"
Author: "Jeff Brown and Anthony McGregor and Hans-Werner Braun"
Proceedings: "Proceedings, Passive and Active Measurement Workshop"
Year: 2000
Month: "Apr"

[BujaA86a]
Title: "Grand Tour Methods: An Outline"
Author: "Andreas Buja and Daniel Asimov"
Proceedings: "Proceedings, 17th Symposium on The Interface"
Year: 1986

[BujaA91a]
Title: "Interactive Data Visualization using Focusing and Linking"
Author: "Andreas Buja and John McDonald and others"
Proceedings: "Proceedings, IEEE Visualization '91"
Year: 1991

[BulatovicD99a]
Title: "A Distributed Intrusion Detection System Based on Bayesian Alarm Networks"
Author: "Dusan Bulatovic and Dusan Velasevic"
Journal: "Lecture Notes in Computer Science"
Year: 1999
Number: 1740

[BurchH00a]
Title: "Tracing anonymous packets to their approximate source"
Author: "Hal Burch and Bill Cheswick"
Proceedings: "Proceedings, 14th USENIX System Admin Conference"
Year: 2000

[BurgessM02a]
Title: "Measuring System Normality"
Author: "Mark Burgess and Harek Haugerud and others"
Journal: "ACM Transactions on Computer Systems"
Year: 2002
Month: "May"
Volume: 20
Number: 2

[BurroughsD02a]
Title: "Analysis of Distributed Intrusion Detection Systems Using Bayesian Methods"
Author: "Daniel J. Burroughs and Linda F. Wilson and George V. Cybenko"
Proceedings: "Proceedings, IEEE Conference on Performance, Computing and Communications"
Year: 2002

[ByersS04a]
Title: "Information Leakage Caused by Hidden Data in Published Documents"
Author: "Simon Byers"
Journal: "IEEE Security and Privacy"
Year: 2004
Month: "Mar-Apr"
Volume: 2
Number: 2

[BykovaM01a]
Title: "Detecting Network Intrusions via a Statistical Analysis of Network Packet Characteristics"
Author: "Marina Bykova and Shawn Ostermann and Brett Tjaden"
Proceedings: "Proceedings, 33rd Southeastern Symposium on System Theory"
Year: "2001"

[BykovaM02a]
Title: "Statistical Analysis of Malformed Packets and Their Origins in the Modern Internet"
Author: "Marina Bykova"
School: "Ohio University"
Year: 2002

[BykovaM02b]
Title: "Statistical Analysis of Malformed Packets and Their Origins in the Modern Internet"
Author: "Marina Bykova"
Proceedings: "Proceedings, ACM Internet Measurement Workshop"
Year: 2002

[CEI03a]
Title: "Computer Economics Inc. web site"
Author: "Computer Economics"
URL: www.computereconomics.com
Year: 2003

[CERT03a]
Title: "CERT Coordination Center at Carnegie Mellon University"
Author: "Computer Emergency Response Team"
URL: www.cert.org
Year: 2003

[CabreraJ00a]
Title: "Statistical Traffic Modeling for Network Intrusion Detection"
Author: "Joao Cabrera and B. Ravichandran and Raman Mehra"
Proceedings: "Proceedings, 8th IEEE Symposium on Modeling, Analysis and Simulation of Computers and Telecommunications"
Year: 2000

[CabreraJ02a]
Title: "Control and Estimation Methods in Information Assurance - A Tutorial on Intrusion Detection Systems"
Author: "Joao Cabrera and Raman Mehra"
Proceedings: "Proceedings, 41st IEEE Conference on Decision and Control"
Year: 2002

[CaloyannidesM03a]
Title: "Digital Evidence and Reasonable Doubt"
Author: "Michael A. Caloyannides"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Nov-Dec"
Volume: 1
Number: 6

[CanoJ00a]
Title: "On the Use and Calculation of the Hurst Parameter with MPEG Videos Data Traffic"
Author: "J. C. Cano and Pietro Manzoni"
Proceedings: "Proceedings, 26th IEEE Euromicro Conference"
Year: 2000

[CaoJ01a]
Title: "On the Nonstationarity of Internet Traffic"
Author: "Jin Cao and William S. Cleveland and Dong Lin and Don X. Sun"
Proceedings: "Proceedings, ACM SIGMETRICS"
Year: 2001
Month: "June"

[CaoJ02a]
Title: "Nonlinear Estimation and Classification"
Chapter: "Internet Traffic Tends Toward Poisson and Independent as the Load Increases"
Author: "Jin Cao and William S. Cleveland and Dong Lin and Don X. Sun"
Publisher: "Springer-Verlag"
Year: 2002

[CaoJ02b]
Title: "S-Net: A Software System for Analyzing Packet Header Databases"
Author: "Jin Cao and William S. Cleveland and Don X. Sun"
Proceedings: "Proceedings, Conference on Passive and Active Measurement"
Year: 2002

[ChampionT01a]
Title: "A Benchmark Evaluation of Network Intrusion Detection Systems"
Author: "Terrence Champion and Mary Denz"
Proceedings: "Proceedings, IEEE Conference on Aerospace Systems"
Year: 2001

[ChanP03a]
Title: "A Machine Learning Approach to Anomaly Detection"
Author: "Philip K. Chan and Matthew Mahoney and Muhammad H. Arshad"
Institution: "Florida Institute of Technology"
Type: "Technical Report CS-2003-6"
Year: 2003

[ChanTK01a]
Title: "A Measurement-based Congestion Alarm for Self-Similar Traffic"
Author: "Tat-Keung Chan and Wing-Cheong Lau and Victor Li"
Proceedings: "Proceedings, IEEE International Conference on Communications"
Year: 2001

[CharniakE91a]
Title: "Bayesian Networks without Tears"
Author: "Eugene Charniak"
Journal: "AI Magazine"
Year: 1991
Month: "Winter"

[ChenZ03a]
Title: "Modeling the Spread of Active Worms"
Author: "Zesheng Chen and Lixin Gao and Kevin Kwiat"
Proceedings: "Proceedings, IEEE INFOCOMM"
Year: 2003

[CheswickW92a]
Title: "An evening with Berferd, in which a cracker is lured, endured and studied"
Author: "Bill Cheswick"
Proceedings: "Proceedings, USENIX Winter Technical Conference"
Year: 1992

[CheswickW94a]
Title: "Firewalls and Internet Security: Repelling the Wily Hacker"
Author: "William Cheswick and Steven Bellovin"
Publisher: "Addison-Wesley Publishing"
Year: 1994

[CheungS97a]
Title: "Protecting Routing Infrastructures from Denial of Service Using Cooperative Intrusion Detection"
Author: "Steven Cheung and Karl Levitt"
Proceedings: "Proceedings, Workshop on New Security Paradigms"
Year: 1997

[ChinSK99a]
Title: "High-Confidence Design for Security"
Author: "Shiu-Kai Chin"
Journal: "Communications of the ACM"
Year: 1999
Month: "July"
Volume: 42
Number: 7

[ChoK02a]
Title: "An Aggregation Technique for Traffic Monitoring"
Author: "Kenjiro Cho and Ryo Kaizaki and Akira Kato"
Proceedings: "Proceedings, IEEE/IPSJ International Symposium on Applications and the Internet (SAINT)"
Year: 2002

[CohenF91a]
Title: "Current Best Practice Against Computer Viruses"
Author: "Fred Cohen"
Proceedings: "Proceedings, IEEE Carnahan Conference on Security Technology"
Year: 1991

[CoitC01a]
Title: "Towards Faster String Matching for Intrusion Detection or Exceeding the Speed of Snort"
Author: "C. Jason Coit and Stuart Staniford and Joseph McAlerney"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001
Month: "Jan"

[ComerfordR01a]
Title: "No longer in denial"
Author: "Richard Comerford"
Journal: "IEEE Spectrum"
Year: 2001
Month: "Jan"

[CotSE03a]
Title: "Church of the Swimming Elephant web site"
Author: "Steven K. Gielda"
URL: www.cotse.com
Year: 2003

[CouchA96a]
Title: "Visualizing Huge Tracefiles with Xscal"
Author: "Alva Couch"
Proceedings: "Proceedings, 10th USENIX LISA Conference"
Year: 1996
Month: "Sep-Oct"

[CowanC03a]
Title: "Software Security for Open-Source Systems"
Author: "Crispin Cowan"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jan-Feb"
Volume: 1
Number: 1

[CrovellaM95a]
Title: "Explaining World Wide Web Traffic Self-Similarity"
Author: "Mark E. Crovella and Azer Bestavros"
Institution: "Boston University"
Type: "Boston University Technical Report TR-95-015"
Year: 1995

[CrovellaM97a]
Title: "Self-Similarity in World Wide Web Traffic: Evidence and Possible Causes"
Author: "Mark Crovella and Azer Bestavros"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1997
Month: "Dec"
Volume: 5
Number: 6

[CunninghamR01a]
Title: "Robert K. Cunningham and Richard P. Lippmann and Seth E. Webster"
Author: "Detecting and Displaying Novel Computer Attacks with Macroscope"
Journal: "IEEE Transactions on Systems, Man and Cybernetics, Part A: Systems and Humans"
Year: 2001
Volume: 31
Number: 4

[CurryD02a]
Title: "Intrusion Detection Message Exchange Format Data Model and eXtensible Markup Language (XML) Document Type Definition"
Author: "David Curry and Herve Debar"
URL: www.silicondefense.com/idwg
Year: 2002
Month: "Feb"

[DAmicoA01a]
Title: "Methods of Visualizing Temporal Patterns in and Mission Impact of Computer Security Breaches"
Author: "Anita D'Amico and Mark Larkin"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001

[DacierM99a]
Title: "Guest Editorial: Intrusion Detection"
Author: "Marc Dacier and Kathleen Jackson"
Journal: "Computer Networks"
Year: 1999
Month: "Dec"
Volume: 31

[DanzigP91a]
Title: "tcplib: A Library of TCP Internetwork Traffic Characteristics"
Author: "Peter B. Danzig and Sugih Jamin"
Institution: "University of Southern California"
Type: "USC CS Technical Report USC-CS-91-495"
Year: 1991

[DasK00a]
Title: "Attack Development for Intrusion Detection Evaluation"
Author: "Kumar Das"
School: "Massachusetts Institute of Technology"
Year: 2000

[DasK01a]
Title: "Protocol Anomaly Detection for Network-based Intrusion Detection"
Author: "Kumar Das"
Institution: "SANS Institute"
Type: "SANS GSEC White Paper"
Year: 2001

[DavisJ03a]
Title: "Teaching Students to Design Secure Systems"
Author: "Jim Davis and Melissa Dark"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Mar-Apr"
Volume: 1
Number: 2

[DavisN04a]
Title: "Processes for Producing Secure Software"
Author: "Noopur Davis and Watts Humphrey and Samuel T. Redwine and others"
Journal: "IEEE Security and Privacy"
Year: 2004
Month: "May-Jun"
Volume: 2
Number: 3

[DebarH92a]
Title: "A Neural Network Component for an Intrusion Detection System"
Author: "Herve Debar and Monique Becker and Didier Siboni"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1992

[DebarH98a]
Title: "An Experimentation Workbench for Intrusion Detection Systems"
Author: "Herve Debar and Marc Dacier and others"
Institution: "IBM Research, Zurich"
Type: "IBM Research Report RZ 2998"
Year: 1998

[DebarH99a]
Title: "Towards a Taxonomy of Intrusion-Detection Systems"
Author: "Herve Debar and Marc Dacier and Andreas Wespi"
Journal: "Computer Networks"
Year: 1999
Month: "Dec"
Volume: 31

[DecasperD98a]
Title: "Router Plugins, a software architecture for next generation routers"
Author: "Dan Decasper and Zubin Dittia and Guru Parulkar and Bernhard Plattner"
Proceedings: "Proceedings, ACM SigCOMM Conference on Applied Architecures and Protocols for Computer Communications"
Year: 1998

[DelvecchioA01a]
Title: "Building Network Intrusion Detection Systems Using Open Source Software"
Author: "Anthony DelVecchio"
URL: www.sans.org
Year: 2001

[DemersA89a]
Title: "Analysis and Simulation of a Fair Queuing Algorithm"
Author: "Alan Demers and Srinivasan Keshav and Scott Shenker"
Proceedings: "Proceedings, ACM SIGCOMM '89"
Year: 1989

[DenningD79a]
Title: "Secure Personal Computing in an Insecure Network"
Author: "Dorothy E. Denning"
Journal: "Communications of the ACM"
Year: 1979
Month: "Aug"
Volume: 22
Number: 8

[DenningD87a]
Title: "An Intrusion Detection Model"
Author: "Dorothy E. Denning"
Journal: "IEEE Transactions on Software Engineering"
Year: 1987
Month: "Feb"
Volume: 13
Number: 2

[DenningD99a]
Title: "Information Warfare and Security"
Author: "Dorothy E. Denning"
Publisher: "Addison-Wesley"
Year: 1999

[DharmapurikarS04a]
Title: "Deep Packet Inspection using Parallel Bloom Filters"
Author: "Sarang Dharmapurikar and Praveen Krishnamurthy and Todd S. Sproull and John W. Lockwood"
Journal: "IEEE Micro"
Year: 2004
Month: "Jan-Feb"
Volume: 24
Number: 1

[DickersonJ01a]
Title: "Fuzzy Intrusion Detection"
Author: "John E. Dickerson and Jukka Juslin and Ourania Koukousoula and Julie Dickerson"
Proceedings: "Proceedings, IEEE/IFSA World Congress"
Year: 2001

[DodgeR03a]
Title: "Network Traffic Analysis from the Cyber Defense Exercise"
Author: "Ronald C. Dodge and Terrance Wilson"
Proceedings: "Proceedings, IEEE Conference on Systems, Man and Cybernetics"
Year: 2003

[DosSantosA00a]
Title: "Security Testing of the Online Banking Service of a Large International Bank"
Author: "Andre Dos Santos and Giovanni Vigna and Richard Kemmerer"
Proceedings: "Proceedings, Workshop on Security and Privacy in E-Commerce"
Year: 2000

[DowneyJ98a]
Title: "Denial of Service Attacks: Can't Say No"
Author: "Jeff Downey"
Journal: "PC Magazine"
Year: 1998
Month: "Apr"

[DowneyJ98b]
Title: "For Whose Eyes Only?"
Author: "Jeff Downey"
Journal: "PC Magazine"
Year: 1998
Month: "May"

[DuBoisP00a]
Title: "MySQL"
Author: "Paul DuBois"
Publisher: "New Riders"
Year: 2000

[DucklinP01a]
Title: "Is Virus Writing Really That Bad?"
Author: "Paul Ducklin "
Proceedings: "Proceedings, Fourth Anti-Virus Asia Researchers Conference"
Year: 2001

[DuniganT99a]
Title: "Intrusion detection and intrusion prevention on a large network: a case study"
Author: "Tom Dunigan and Greg Hinkel"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[DurstR99a]
Title: "Testing and Evaluating Computer Intrusion Detection Systems"
Author: "Robert Durst and Terrence Champion and Brian Witten and others"
Journal: "Communications of the ACM"
Year: 1999
Month: "July"
Volume: 42
Number: 7

[EdwardsJ01a]
Title: "Next-Generation Viruses Present New Challenges"
Author: "John Edwards"
Journal: "IEEE Computer"
Year: 2001
Month: "May"

[ElliotJ00a]
Title: "Distributed Denial of Service Attacks and the Zombie Ant Effect"
Author: "John Elliot"
Journal: "IT Pro"
Year: 2000
Month: "Mar-Apr"

[EllisonC00a]
Title: "Ten Risks of PKI: What you're not being told about public key infrastructure"
Author: "Carl Ellison and Bruce Schneier"
Journal: "Computer Security Journal"
Year: 2000
Volume: 16
Number: 1

[EmotoM99a]
Title: "The Interactive Data Visualization with Java3D"
Author: "M. Emoto and M. Shoji and S. Suzuki and others"
Proceedings: "Proceedings, Workshop on PCs and Particle Accelerator Control"
Year: 1999

[EndlerD98a]
Title: "Intrusion Detection Applying Machine Learning to Solaris Audit Data"
Author: "David Endler"
Proceedings: "Proceedings, IEEE 14th Computer Security Applications Conference"
Year: 1998

[Enterasys02a]
Title: "Dragon Intrusion Detection System"
Author: "Enterasys Networks"
URL: www.enterasys.com/ids
Year: 2002

[ErbacherR01a]
Title: "Visual Behavior Characterization for Intrusion and Misuse Detection"
Author: "Robert Erbacher and Deborah Frincke"
Proceedings: "Proceedings, SPIE Conference on Visual Data Exploration and Analysis"
Year: 2001

[ErbacherR01b]
Title: "Visual Traffic Monitoring and Evaluation"
Author: "Robert Erbacher"
Proceedings: "Proceedings, Conference on Internet Performance and Control of Network Systems"
Year: 2001

[ErbacherR01c]
Title: "User Issues in Visual Monitoring Environments"
Author: "Robert Erbacher"
Proceedings: "Proceedings, CISST '01"
Year: 2001

[ErbacherR01d]
Title: "Visual Behavior Characterization for Intrusion Detection in Large Scale Systems"
Author: "Robert Erbacher"
Proceedings: "Proceedings, IASTED International Conference on Visualization, Imaging and Image Processing"
Year: 2001

[ErbacherR02a]
Title: "Intrusion and Misuse Detection in Large-Scale Systems"
Author: "Robert Erbacher and Kenneth Walker and Deborah Frincke"
Journal: "IEEE Computer Graphics and Applications"
Year: 2002
Month: "Jan-Feb"

[ErbacherR02b]
Title: "Intrusion Detection Data: Collection and Analysis"
Author: "Robert Erbacher and Bill Augustine"
Proceedings: "Proceedings, International Conference on Security and Management"
Year: 2002

[ErbacherR02c]
Title: "A Component-based Event-driven Interactive Visualization Software Architecture"
Author: "Robert Erbacher"
Proceedings: "Proceedings, International Symposium on Information Systems and Engineering"
Year: 2002

[ErbacherR95a]
Title: "Issues in the Development of 3D Icons"
Author: "Robert Erbacher and Georges Grinstein"
Journal: "Visualization in Scientific Computing"
Publisher: "Springer-Verlag"
Year: 1995

[ErlingssonU99a]
Title: "SASI Enforcement of Security Policies: A Retrospective"
Author: "Ulfar Erlingsson and Fred B. Schneider"
Proceedings: "Proceedings, ACM Workshop on New Security Paradigms"
Year: 1999

[ErramilliA94a]
Title: "Monitoring Packet Traffic Levels"
Author: "Ashok Erramilli and Jonathan L. Wang"
Proceedings: "Proceedings, IEEE Global Telecommunications Conference"
Year: 1994

[EskinE00a]
Title: "Adaptive Model Generation for Intrusion Detection Systems"
Author: "Eleazar Eskin and Mathew Miller and Zhi-Da Zhong and others"
Proceedings: "Proceedings, 7th ACM Conference on Computer Security"
Year: 2000

[Ethereal03a]
Title: "Ethereal Network Analyzer"
Author: "Gerald Combs"
URL: www.ethereal.com
Year: 2003

[EvansD99a]
Title: "Flexible Policy-Directed Code Safety"
Author: "David Evans and Andrew Twyman"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1999

[FaloutsosC97a]
Title: "Relaxing the Uniformity and Independence Assumptions Using the Concept of Fractal Dimension"
Author: "Christos Faloutsos and Ibrahim Kamel"
Journal: "Journal of Computer and System Sciences"
Year: 1997
Volume: 55

[FanW01a]
Title: "Using Artifical Anomalies to Detect Unknown and Known Network Intrusions"
Author: "Wei Fan and Mathew Miller and Salvatore Stolfo and Wenke Lee and Philip K. Chan"
Proceedings: "Proceedings, IEEE International Conference on Data Mining"
Year: 2001

[FarmerD90a]
Title: "The COPS Security Checker System"
Author: "Daniel Farmer and Eugene Spafford"
Proceedings: "Proceedings, USENIX Summer Technical Conference"
Year: 1990

[FayyadU97a]
Title: "Data Mining and Knowledge Discovery in Databases: Implications for Scientific Databases"
Author: "Usama Fayyad"
Proceedings: "Proceedings, 9th International Conference on Scientific and Statistical Database Management"
Year: 1997

[FeinsteinB02a]
Title: "The Intrusion Detection Exchange Protocol"
Author: "Ben Feinstein and Greg Matthews and J. White"
URL: www.silicondefense.com/idwg
Year: 2002
Month: "Jan"

[FeldmannA97a]
Title: "Looking behind and beyond self-similarity: On scaling phenomena in measured WAN traffic"
Author: "Anja Feldmann and A. Gilbert and Walter Willinger and T. Kurtz"
Proceedings: "Proceedings, 35th Allerton Conference on Communications, Control and Computing"
Year: 1997

[FeltenE04a]
Title: "Understanding Trusted Computing: Will Its Benefits Outweigh Its Drawbacks?"
Author: "Edward W. Felten"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "May-Jun"
Volume: 1
Number: 3

[FergusonN00a]
Title: "A Cryptographic Evaluation of IPSec"
Author: "Niels Ferguson and Bruce Schneier"
URL: www.counterpane.com/ipsec.html
Year: 2000

[FioriniP99a]
Title: "On Modeling Concurrent Heavy-Tailed Network Traffic Sources and its Impact on QoS"
Author: "P. M. Fiorini"
Proceedings: "Proceedings, IEEE INFOCOMM '99"
Year: 1999

[FiskM02a]
Title: "Agile and Scalable Analysis of Network Events"
Author: "Mike Fisk and George Varghese"
Proceedings: "Proceedings, ACM Internet Measurement Workshop"
Year: 2002

[FloydS93a]
Title: "Random Early Detection Gateways for Congestion Avoidance"
Author: "Sally Floyd and Van Jacobson"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1993
Month: "Aug"
Volume: 1
Number: 4

[FloydS94a]
Title: "The Synchonization of Periodic Routing Messages"
Author: "Sally Floyd and Van Jacobson"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1994
Month: "Apr"
Volume: 2
Number: 2

[FloydS95a]
Title: "Link-Sharing and Resource Management Models for Packet Networks"
Author: "Sally Floyd and Van Jacobson"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1995
Month: "Aug"
Volume: 3
Number: 4

[FloydS98a]
Title: "Internet Research: Comments on Formulating the Problem"
Author: "Sally Floyd and others"
Year: 1998

[FloydS98b]
Title: "Estimating Arrival Rates from the RED Packet Drop History"
Author: "Sally Floyd and Kevin Fall and Kinh Tieu"
Year: 1998

[FloydS99a]
Title: "Promoting the Use of End-to-End Congestion Control in the Internet"
Author: "Sally Floyd and Kevin Fall"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1999
Month: "Aug"
Volume: 7
Number: 4

[ForrestS96a]
Title: "A Sense of Self for Unix Processes"
Author: "Stephanie Forrest and Steven Hofmeyr and Anil Somayaji and Thomas Longstaff"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1996

[ForrestS97a]
Title: "Computer Immunology"
Author: "Stephanie Forrest and Steven A. Hofmeyr and Anil Somayaji"
Journal: "Communications of the ACM"
Year: 1997
Month: "Oct"
Volume: 40
Number: 10

[FowlerH91a]
Title: "Local Area Network Traffic Characteristics, with Implications for Broadband Network Congestion Management"
Author: "Henry Fowler and Will Leland"
Journal: "IEEE Journal on Selected Areas of Communications"
Year: 1991
Volume: 9
Number: 7

[FraserT99a]
Title: "Hardening COTS software with generic software wrappers"
Author: "Timothy Fraser and Lee Badger and Mark Feldman"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy "
Year: 1999

[FrinckeD00a]
Title: "Recent advances in intrusion detection systems"
Author: "Deborah Frincke and Ming-Yuh Huang"
Journal: "Computer Networks"
Year: 2000
Volume: 34

[FrinckeD01a]
Title: "Distributed Network Defense"
Author: "Deborah Frincke and Elizabeth Wilhite"
Proceedings: "Proceedings, IEEE Workshop on Information Assurance and Security"
Year: 2001

[FrinckeD03a]
Title: "Who Watches the Security Educators"
Author: "Deborah Frincke"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "May-Jun"
Volume: 1
Number: 3

[FrinckeD04a]
Title: "Guarding the Castel Keep: Teaching with the Fortress Metaphor"
Author: "Deborah Frincke and Matt Bishop"
Journal: "IEEE Security and Privacy"
Year: 2004
Month: "May-Jun"
Volume: 2
Number: 3

[FrinckeD98a]
Title: "A Framework for Cooperative Intrusion Detection"
Author: "Deborah Frincke and Don Tobin and Jesse McConnell and others"
Proceedings: "Proceedings, 21th National Information Systems Security Conference"
Year: 1998

[GabrilovichE02a]
Title: "The Homograph Attack"
Author: "Evgeniy Gabrilovich and Alex Gontmakher"
Journal: "Communications of the ACM"
Year: 2002
Month: "Feb"
Volume: 45
Number: 2

[GaffneyJ01a]
Title: "Evaluation of Intrusion Detectors: a Decision Theory Approach"
Author: "John E. Gaffney and Jacob W. Ulvila"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 2001

[GallaherR95a]
Title: "Computer Visualization: Graphic Techniques for Scientific and Engineering Analysis"
Author: "Richard Gallagher"
Publisher: "CRC Press"
Year: 1995

[GarberL00a]
Title: "Denial-of-Service Attacks Rip the Internet"
Author: "Lee Garber"
Journal: "IEEE Computer"
Year: 2000
Month: "Apr"

[GarciaR02a]
Title: "WAID: Wavelet Analysis Intrusion Detection"
Author: "Raymond C. Garcia and Matthew N. Sadiku and James D. Cannady"
Proceedings: "Proceedings, IEEE Midwest Symposium on Circuits and Systems"
Year: 2002

[GarfinkelS03a]
Title: "Rememberance of Data Passed: a Study of Disk Sanitization Practices"
Author: "Simpson Garfinkel and Abhi Shelat"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jan-Feb"
Volume: 1
Number: 1

[GelbordB01a]
Title: "Graphical Techniques in Intrusion Detection Systems"
Author: "Boaz Gelbord"
Proceedings: "Proceedings, 15th IEEE International Conference on Information Networking"
Year: 2001

[GengX00a]
Title: "Defeating Distributed Denial of Service Attacks"
Author: "Xianjun Geng and Andrew B. Whinston"
Journal: "IT Pro"
Year: 2000
Month: "July-Aug"

[GhoshA01a]
Title: "Software Security and Privacy Risks in Mobile E-Commerce"
Author: "Anup Ghosh and Tara Swaminatha"
Journal: "Communications of the ACM"
Year: 2001
Month: "Feb"
Volume: 44
Number: 2

[GhoshA99a]
Title: "Learning Program Behavior Profiles for Intrusion Detection"
Author: "Anup Ghosh and Aaron Schwartzbard and Michael Schatz"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[GhoshA99b]
Title: "Inoculating Software for Survivability"
Author: "Anup Ghosh and Jeffery Voas"
Journal: "Communications of the ACM"
Year: 1999
Month: "July"
Volume: 42
Number: 7

[GirardinL98a]
Title: "A Visual Approach for Monitoring Logs"
Author: "Luc Girardin and Dominique Brodbeck"
Proceedings: "Proceedings, 12th USENIX LISA Conference"
Year: 1998
Month: "Dec"

[GirardinL99a]
Title: "An Eye on Network Intruder-Administrator Shootouts"
Author: "Luc Girardin"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[GleickJ87a]
Title: "Chaos: Making a new Science"
Author: "James Gleick"
Publisher: "Penguin"
Year: 1987

[GlobusA94a]
Title: "Fourteen Ways to Say Nothing with Scientific Visualization"
Author: "Al Globus and Eric Raible"
Journal: "IEEE Computer"
Year: 1994
Month: "July"

[GoanT99a]
Title: "A Cop on the Beat: Collecting and Appraising Intrusion"
Author: "Terrance Goan"
Journal: "Communications of the ACM"
Year: 1999
Month: "July"
Volume: 42
Number: 7

[GoldbergI96a]
Title: "A secure environment for untrusted helper applications (confining the wily hacker)"
Author: "Ian Goldberg and David Wagner and Randi Thomas and Eric Brewer"
Proceedings: "Proceedings, 6th USENIX UNIX Security Symposium"
Year: 1996
Month: "July"

[GoldschlagD99a]
Title: "Onion Routing"
Author: "David Goldschlag and Michael Reed and Paul Syverson"
Journal: "Communications of the ACM"
Year: 1999
Month: "Feb"
Volume: 42
Number: 2

[GorodetskiV02a]
Title: "Software Development Kit for Multi-agent Systems Design and Implementation"
Author: "Vladimir Gorodetski and Oleg Karsayev and Igor Kotenko and Alexey Khabalov"
Journal: "Lecture Notes in Artificial Intelligence"
Year: 2002
Volume: 2296

[GorodetskiV02b]
Title: "The Multi-agent Systems for Computer Network Security Assurance: Frameworks and Case Studies"
Author: "Vladimir Gorodetski and Igor Kotenko"
Proceedings: "Proceedings, IEEE Conference on Artificial Intelligence Systems (ICAIS'02)"
Year: 2002

[GrassbergerP83a]
Title: "Measuring the Strangeness of Strange Attractors"
Author: "Peter Grassberger and Itamar Procaccia"
Journal: "Physica D"
Year: 1983
Volume: 9

[GrassbergerP83b]
Title: "Characterization of Strange Attractors"
Author: "Peter Grassberger and Itamar Procaccia"
Journal: "Physical Review Letters"
Year: 1983
Volume: 50
Number: 5

[GreenJ99a]
Title: "Analysis Techniques for Detecting Coordinated Attacks and Probes"
Author: "John Green and David Marchette and Stephen Northcutt and Bill Ralph"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[GuhaB97a]
Title: "Network Security via Reverse Engineering of TCP Code: Vulnerability Analysis and Proposed Solutions"
Author: "Biswaroop Guha and Biswanath Mukherjee"
Journal: "IEEE Network"
Year: 1997
Month: "Jul-Aug"

[GuoL01a]
Title: "How does TCP generate Pseudo-self-similarity?"
Author: "Liang Guo and Mark Crovella and Ibrahim Matta"
Proceedings: "Proceedings, 9th IEEE Symposium on Modeling, Analysis and Simulation of Computers and Telecommunications"
Year: 2001

[HabraN92a]
Title: "ASAX: Software Architecture and Rule-based Language for Universal Audit Trail Analysis"
Author: "Naji Habra and Baudouin Le Charlier and Abdelaziz Mounji and Isabelle Mathieu"
Proceedings: "Proceedings, European Symposium on Research in Computer Security"
Year: 1992
Month: "Nov"

[HabraN94a]
Title: "Advanced Security Audit Trail Analysis on uniX, Implementation design of the NADF evaluator"
Author: "Naji Habra and Baudouin Le Charlier and Abdelaziz Mounji"
Year: 1994

[HagiwaraT00a]
Title: "High-Speed Calculation Method of the Hurst Parameter Based on Real Traffic"
Author: "Tatsuya Hagiwara and Hiroki Doi and Hideki Tode and Hiromasa Ikeda"
Proceedings: "Proceedings, IEEE Conference on Local Computer Networks"
Year: 2000

[HainesJ01a]
Title: "Extending the DARPA Off-line Intrusion Detection Evaluations"
Author: "Joshua Haines and Lee Rossey and Richard Lippmann"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001

[HainesJ01b]
Title: "1999 DARPA Intrusion Detection Evaluation: Design and Procedures"
Author: "Joshua Haines and Robert Lippmann and David Fried and others"
Institution: "Massachusetts Institute of Technology"
Type: "Lincoln Laboratory Technical Report 1062"
Year: 2001

[HainesJ03a]
Title: "LLSIM: Network Simulation for Correlation and Response Testing"
Author: "Joshua W. Haines and Stephen A. Goulet and Robert S. Durst and Terrance G. Champion"
Proceedings: "Proceedings, DARPA Information Survivability Conference and Exposition (DISCEX'03)"
Year: 2003

[HandleyM01a]
Title: "Network Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics"
Author: "Mark Handley and Vern Paxson and Christian Kreibich"
Proceedings: "Proceedings, 10th USENIX UNIX Security Symposium"
Year: 2001
Month: "Aug"

[HaririS03a]
Title: "Impact Analysis of Faults and Attacks in Large-Scale Networks"
Author: "Salim Hariri and Guangzhi Qu and others"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Sep-Oct"
Volume: 1
Number: 5

[HastingsN96a]
Title: "TCP/IP Spoofing Fundamentals"
Author: "Nelson Hastings and Paul McLean"
Proceedings: "Proceedings, IEEE Phoenix Conference on Computers and Communications"
Year: 1996

[HaughE03a]
Title: "Testing C programs for Buffer Overflow Vulnerabilities"
Author: "Eric Haugh and Matt Bishop"
Proceedings: "Proceedings, Internet Society Symposium on Network and Distributed System Security"
Year: 2003

[HaykinS97a]
Title: "Chaotic Dynamics of Sea Clutter"
Author: "Simon Haykin and Sadasivan Puthusserypady"
Journal: "Chaos"
Year: 1997
Volume: 7
Number: 4

[HazelegerD01a]
Title: "A Crash Course in Packet Sniffing"
Author: "Dick Hazeleger"
URL: www.hazeleger.net
Year: 2001

[HealeyC98a]
Title: "On the Use of Perceptual Cues and Data Mining for Effective Visualization of Scientific Datasets"
Author: "Christopher G. Healey"
Proceedings: "Proceedings, Graphics Interface Conference '98, Vancouver"
Year: 1998

[HeberleinL90a]
Title: "A Network Security Monitor"
Author: "L. Heberlein and Gihan Dias and Karl Levitt and others"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1990

[HiraishiH01a]
Title: "Design of a visual browser for network itrusion detection"
Author: "Hironori Hiraishi and Fumio Mizoguchi"
Proceedings: "Proceedings, 10th IEEE Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises"
Year: 2001

[HlavacsH99a]
Title: "Traffic Source Modeling"
Author: "Helmut Hlavacs and Gabriele Kotsis and Christine Steinkellner"
Institution: "Institute of Applied Computer Science and Information Systems, University of Vienna"
Type: "Technical Report TR-99101"
Year: 1999

[HoaglandJ95a]
Title: "Audit Log Analysis Using the Visual Audit Browser Toolkit"
Author: "James Hoagland and Christopher Wee and Karl Levitt"
Institution: "UC Davis Computer Science Department"
Type: "Technical Report CSE-95-11"
Year: 1995

[HoodC98a]
Title: "Intelligent Agents for Proactive Fault Detection"
Author: "Cynthia S. Hood and Chuanyi Ji"
Journal: "IEEE Internet Computing"
Year: 1998
Month: "Mar-Apr"

[HowardM03a]
Title: "Inside the Windows Security Push"
Author: "Michael Howard and Steve Lipner"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jan-Feb"
Volume: 2
Number: 1

[HuaY03a]
Title: "Intrusion Detection Based on Artificial Immune System with Self-Similar Traffic"
Author: "Yu Hua and Chan-Le Wu"
Proceedings: "Proceedings, Conference on Machine Learning and Cybernetics"
Year: 2003

[HuangMY99a]
Title: "A large scale distributed intrusion detection framework based on attack strategy analysis"
Author: "Ming-Yuh Huang and Robert Jasper and Thomas Wicks"
Journal: "Computer Networks"
Year: 1999
Month: "Dec"
Volume: 31

[HuangY03a]
Title: "A Cooperative Intrusion Detection System for Ad Hoc Networks"
Author: "Yi-an Huang and Wenke Lee"
Proceedings: "Proceedings, ACM Workshop on Security of Ad Hoc and Sensor Networks"
Year: 2003

[HughesD96a]
Title: "Using Visualization in System and Network Administration"
Author: "Doug Hughes"
Proceedings: "Proceedings, 10th USENIX LISA Conference"
Year: 1996
Month: "Sep-Oct"

[ITA03a]
Title: "Internet Traffic Archive Wed Site"
Author: "Lawrence Berkeley National Laboratory"
URL: "ita.ee.lbl.gov"
Year: 2003

[IguchiM99a]
Title: "Network Surveillance for Detecting Intrusions"
Author: "Makoto Iguchi and Shigeki Goto"
Proceedings: "Proceedings, IEEE Internet Workshop"
Year: 1999

[IlgunK93a]
Title: "USTAT: a Real-time Intrusion Detection System for UNIX"
Author: "Koral Ilgun"
Journal: "IEEE Transactions on Software Engineering"
Year: 1993
Month: "Mar"
Volume: 21
Number: 3

[IlgunK95a]
Title: "State Transition Analysis: a Rule-Based Intrusion Detection Approach"
Author: "Koral Ilgun and Richard Kemmerer and Phillip Porras"
Journal: "IEEE Transactions on Software Engineering"
Year: 1995
Month: "Mar"
Volume: 21
Number: 3

[JacobsonV88a]
Title: "Congestion Avoidance and Control"
Author: "Van Jacobson"
Proceedings: "Proceedings, ACM SIGCOMM '88"
Year: 1988

[JacobsonV89a]
Title: "tcpdump, a network packet capture program"
Author: "Van Jacobson and Craig Leres and Steven McCanne"
URL: www.tcpdump.org
Year: 1989

[JanecekP99a]
Title: "Applying Visualization Research Towards Design"
Author: "Paul Janecek"
Proceedings: "Proceedings, 3rd International Conference on Visual Information and Information Systems"
Year: 1999

[JavitzH91a]
Title: "The SRI IDES Statistical Anomaly Detector"
Author: "Harold Javitz and Alfonso Valdes"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1991
Month: "May"

[JohnsonB91a]
Title: "Tree-Maps: A Space-Filling Approach to the Visualization of Hierarchical Information Structures"
Author: "Brian Johnson and Ben Schneiderman"
Proceedings: "Proceedings, IEEE Visualization '91"
Year: 1991

[JonckheereE02a]
Title: "Dynamic Modeling of Internet Traffic for Intrusion Detection"
Author: "E. Jonckheere and K. Shah and S. Bohacek"
Proceedings: "Proceedings, American Control Conference"
Year: 2002

[JonesA00a]
Title: "Computer System Intrusion Detection: a Survey"
Author: "Anita Jones and Robert Sielken"
Institution: "University of Virginia"
Year: 2000

[JouY00a]
Title: "Design and Implementation of a Scalable Intrusion Detection System for the Protection of Network Infrastructure"
Author: "Y. Frank Jou and Fengmin Gong and Chandru Sargor and others"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX I)"
Year: 2000
Month: "Jan"

[JungJ02a]
Title: "Flash Crowds and Denial of Service Attacks: Characterization and Implications for CDNs and Wed Sites"
Author: "Jaeyeon Jung and Balachander Krishnamurthy and Michael Rabinovich"
Proceedings: "Proceedings, 11th World Wide Web Conference"
Year: 2002

[KahnD73a]
Title: "The Code Breakers"
Author: "David Kahn"
Publisher: "The New American Library"
Year: 1973

[KarglF01a]
Title: "Protecting Web Servers from Distributed Denial of Service Attacks"
Author: "Frank Kargl and Joern Maier and Michael Weber"
Proceedings: "Proceedings, 10th International Conference on the World Wide Web"
Year: 2001

[KeimD02a]
Title: "Information Visualization and Visual Data Mining"
Author: "Daniel A. Keim"
Journal: "IEEE Transactions on Visualization and Computer Graphics"
Year: 2002
Month: "Jan"
Volume: 8
Number: 1

[KelseyJ00a]
Title: "Side Channel Cryptanalysis of Product Ciphers"
Author: "John Kelsey and Bruce Schneier and David Wagner and Chris Hall"
Journal: "Journal of Computer Security"
Year: 2000
Volume: 8
Number: 2

[KendallK99a]
Title: "A Database of Computer Attacks for the Evaluation of Intrusion Detection Systems"
Author: "Kristopher Kendall"
School: "Massachusetts Institute of Technology"
Year: 1999

[KentS00a]
Title: "On the Train of Intrusions into Information Systems"
Author: "Stephen Kent"
Journal: "IEEE Spectrum"
Year: 2000
Month: "Dec"

[KephartJ93a]
Title: "Measuring and Modeling Computer Virus Prevalence"
Author: "Jeffrey O. Kephart and Steve R. White"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1993

[KienzleD03a]
Title: "Recent Worms: a Survey and Trends"
Author: "Darrell M. Kienzle and Matthew C. Elder"
Proceedings: "Proceedings, ACM Workshop on Rapid Malcode"
Year: 2003

[KimG94a]
Title: "The Design and Implementation of Tripwire: a file system integrity checker"
Author: "Gene Kim and Eugene Spafford"
Proceedings: "Proceedings, ACM Computer and Communications Security Conference"
Year: 1994

[KoC00a]
Title: "Logic Induction of Valid Behavior Specifications for Intrusion Detection"
Author: "Calvin Ko"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 2000

[KoC94a]
Title: "Automated Detection of Vulnerabilities in Privileged Programs by Execution Monitoring"
Author: "Calvin Ko"
Proceedings: "Proceedings, Computer Security Applications Conference"
Year: 1994

[KoilpillaiJ00a]
Title: "Recon - a Tool for Incident Detection, Tracking and Response"
Author: "Jaunita Koilpillai and John Beavers and Paul Swinton"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX I)"
Year: 2000
Month: "Jan"

[KorbaJ00a]
Title: "Windows NT Attacks for the Evaluation of Intrusion Detection Systems"
Author: "Jonothan Korba"
School: "Massachusetts Institute of Technology"
Year: 2000

[KotenkoI03a]
Title: "Active Vulnerability Assessment of Computer Networks by Simulation of Complex Remote Attacks"
Author: "Igor Kotenko"
Proceedings: "Proceedings, International Conference on Computer Networks and Mobile Computing (ICCNMC'03)"
Year: 2003

[KotenkoI03b]
Title: "Formal Framework for Modeling and Simulation of DDoS Attacks Based on Teamwork of Hackers-Agents"
Author: "Igor Kotenko and Alexey Alexeev and Evgeny Mankov"
Proceedings: "Proceedings, IEEE Conference on Intelligent Agent Technology"
Year: 2003

[KrsulI97a]
Title: "Computer Vulnerability Analysis - thesis proposal"
Author: "Ivan Krsul"
Year: 1997

[KruegelC02a]
Title: "Service Specific Anomaly Detection for Network Intrusion Detection"
Author: "Christopher Kruegel and Thomas Toth and Engin Kirda"
Proceedings: "Proceedings, ACM Symposium on Applied Computing"
Year: 2002

[KruegelC03a]
Title: "Anomaly Detection of Web-based Attacks"
Author: "Christopher Kruegel and Giovanni Vigna"
Proceedings: "Proceedings, ACM Computer and Communications Security"
Year: 2003

[KumarS95a]
Title: "A Pattern-Matching Model for Misuse Instrusion Detection"
Author: "Sandeep Kumar and E. H. Spafford"
Proceedings: "Proceedings, 18th National Computer Security Conference"
Year: "1995"

[KumarS95a]
Title: "Classification and Detection of Computer Intrusions"
Author: "Sandeep Kumar"
School: "Purdue University"
Year: 1995

[KushidaT98a]
Title: "The Traffic Measurement and the Empirical Studies for the Internet"
Author: "Takayuki Kushida"
Proceedings: "Proceedings, IEEE Global Telecommunications Conference"
Year: 1998

[LLNL01a]
Title: "Online NID Overview"
Author: "Lawrence Livermore National Laboratory"
URL: www.ciac.llnl.gov
Year: 2001

[LamportL86a]
Title: "LaTeX: User's Guide and Reference Manual"
Author: "Leslie Lamport"
Publisher: "Addison-Wesley Publishing"
Year: 1986

[LaneT99a]
Title: "Temporal Sequence Learning and Data Reduction for Anomaly Detection"
Author: "Terran Lane and Carla W. Brodley"
Journal: "ACM Transactions on Information and Systems Security"
Year: 1999
Month: "Aug"
Volume: 2
Number: 3

[LauWC95b]
Title: "Self-Similar Traffic Generation: The Random Midpoint Displacement Algorithm and Its Properties"
Author: "Wing-Cheong Lau and Ashok Erramilli and Jonathan Wang and Walter Willinger"
Proceedings: "Proceedings, IEEE International Conference on Communications"
Year: 1995

[LeeS01a]
Title: "Training a Neural-Network Based Intrusion Detector to Recognize Novel Attacks"
Author: "Susan C. Lee and David V. Heinbuch"
Journal: "IEEE Transactions on Systems, Man and Cybernetics, Part A: Systems and Humans"
Year: 2001
Volume: 31
Number: 4

[LeeW01a]
Title: "Real Time Data Mining-based Intrusion Detection"
Author: "Wenke Lee and Salvatore Stolfo and Philip Chan and others"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001
Month: "Jan"

[LeeW99a]
Title: "Automated Intrusion Detection using NFR: Methods and Experiences"
Author: "Wenke Lee and Christopher Park and Salvatore Stolfo"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[LeeW99b]
Title: "A Data Mining Framework for Building Intrusion Detection Models"
Author: "Wenke Lee and Salvatore Stolfo and Kui Mok"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 1999

[LeinerB00a]
Title: "A Brief History of the Internet"
Author: "Barry Leiner and Vinton Cerf and David Clark and Robert Kahn and Leonard Kleinrock and others"
URL: www.isoc.org/internet/history/brief.html
Year: 2000
Month: "Aug"

[LelandW91a]
Title: "High Time-Resolution Measurement and Analysis of LAN Traffic: Implications for LAN Interconnection"
Author: "Will Leland and Daniel Wilson"
Proceedings: "Proceedings, IEEE INFOCOMM '91"
Year: 1991

[LelandW94a]
Title: "On the Self-Similar Nature of Ethernet Traffic (Extended Version)"
Author: "Will Leland and Murad Taqqu and Walter Willinger and Daniel Wilson"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1994
Month: "Feb"
Volume: 2
Number: 1

[LeungH90a]
Title: "Is There a Radar Clutter Attractor?"
Author: "Henry Leung and Simon Haykin"
Journal: "Applied Physics Letters"
Year: 1990
Volume: 56
Number: 6

[LevesonN94a]
Title: "High-Pressure Steam Engines and Computer Software"
Author: "Nancy G. Leveson"
Journal: "IEEE Computer"
Year: 1994
Month: "Oct"

[LevyE03a]
Title: "Poisoning the Software Supply Chain"
Author: "Elias Levy"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "May-Jun"
Volume: 2
Number: 3

[LiM01a]
Title: "Decision Analysis of Network-based Intrusion Detection Systems for Denial-of-Service Attacks"
Author: "Ming Li and Weija Jia and Wei Zhao"
Proceedings: "Proceedings, IEEE Conferences on Info-tech and Info-net"
Year: 2001

[LiM01b]
Title: "Modeling WWW-Traffic Data by Autocorrelations"
Author: "Ming Li and Weija Jia and Wei Zhao"
Proceedings: "Proceedings, IEEE Conferences on Distributed Multimedia Systems"
Year: 2001

[Libnet03a]
Title: "Libnet - a library for packet construction/injection"
Author: "Mike Schiffman"
URL: www.packetfactory.net
Year: 2003

[Libpcap03a]
Title: "tcpdump/libpcap website"
Author: "tcpdump-workers"
URL: www.tcpdump.org
Year: 2003

[LiebovitchL89a]
Title: "A Fast Algorithm to Determine Fractal Dimensions by Box Counting"
Author: "Larry Liebovitch and Tibor Toth"
Journal: "Physics Letters A"
Year: 1989
Volume: 141
Number: 8

[LinD97a]
Title: "Dynamics of Random Early Detection"
Author: "Dong Lin and Robert Morris"
Proceedings: "Proceedings, ACM SIGCOMM '97"
Year: 1997

[LincolnLab02a]
Title: "Intrusion Detection Evaluation Web Site"
Author: "MIT Lincoln Laboratory"
URL: www.ll.mit.edu/IST/ideval
Year: 2002

[LindqvistU97a]
Title: "How to Systematically Classify Security Intrusions"
Author: "Ulf Lindqvist and Erland Jonsson"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1997

[LindqvistU98a]
Title: "A Map of Security Risks Associated with Using COTS"
Author: "Ulf Lindqvist and Erland Jonsson"
Journal: "IEEE Computer"
Year: 1998
Month: "June"

[LindqvistU99a]
Title: "Detecting Computer and Network Misuse Through the Production-Based Expert System Toolkit (P-BEST)"
Author: "Ulf Lindqvist and Phillip Porras"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1999
Month: "May"

[LippmannR00a]
Title: "The 1999 DARPA Off-Line Intrusion Detection Evaluation"
Author: "Richard Lippmann and Joshua Haines and David Fried and others"
Journal: "Computer Networks"
Year: 2000
Volume: 34

[LippmannR00b]
Title: "Improving intrusion detection performance using keyword selection and neural networks"
Author: "Richard Lippmann and Robert Cunningham"
Journal: "Computer Networks"
Year: 2000
Volume: 34

[LockwoodJ03a]
Title: "Internet Worm and Virus Protection in Dynamically Reconfigurable Hardware"
Author: "John W. Lockwood and James Moscola and Matthew Kulig and others"
Proceedings: "Proceedings, Conference on Military and Aerospace Programmable Logic Devices"
Year: 2003

[LuntT88a]
Title: "Automated Audit Trail Analysis and Intrusion Detection: a Survey"
Author: "Teresa Lunt"
Proceedings: "Proceedings, 11th National Computer Security Conference"
Month: "Oct"
Year: 1988

[LuntT93a]
Title: "Detecting Intruders on Computer Systems"
Author: "Teresa Lunt"
Proceedings: "Proceedings, Conference on Auditing and Computer Technology"
Year: 1993

[MahoneyM01a]
Title: "Detecting Novel Attacks by Identifying Anomolous Network Packet Headers"
Author: "Matthew Mahoney and Philip Chan"
Institution: "Florida Institute of Technology"
Type: "Technical Report CS-2001-2"
Year: 2001

[MandelbrotB83a]
Title: "The Fractal Geometry of Nature"
Author: "Benoit B. Mandelbrot"
Publisher: "W. H. Freeman"
Year: 1983

[MandiaK01a]
Title: "Incident Response: Investigating Computer Crime"
Author: "Kevin Mandia and Chris Prosise"
Publisher: "McGraw-Hill"
Year: 2001

[MannD99a]
Title: "Towards a Common Enumeration of Vulnerabilities"
Author: "David Mann and Steven Christey"
Proceedings: "Proceedings, 2nd Workshop on Research with Security Vulnerability Databases"
Year: 1999

[MansfieldG01a]
Title: "Self-similar and Fractal Nature of Internet Traffic Data"
Author: "G. Mansfield and T. K. Roy and N. Shiratori"
Proceedings: "Proceedings, International Conference on Information Networking"
Year: 2001

[MansouriM93a]
Title: "Monitoring Distributed Systems"
Author: "Masoud Mansouri-Samani and Morris Sloman"
Journal: "IEEE Network"
Year: 1993
Month: "Nov"

[MarchetteD01a]
Title: "Computer Intrusion Detection and Network Monitoring: A Statistical Viewpoint"
Author: "David Marchette"
Publisher: "Springer-Verlag"
Year: 2001

[MarchetteD99a]
Title: "A Statistical Method for Profiling Network Traffic"
Author: "David Marchette"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[MarinJ01a]
Title: "A Hybrid Approach to the Profile Creation and Intrusion Detection"
Author: "Jack Marin and Daniel Ragsdale and John Surdu"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001
Month: "Jan"

[MartinD01a]
Title: "The privacy practices of web browser extensions"
Author: "David Martin and Richard Smith and Michael Brittain and others"
Journal: "Communications of the ACM"
Year: 2001
Month: "Feb"
Volume: 44
Number: 2

[MartinR01a]
Title: "Managing Vulnerabilities in Networked Systems"
Author: "Robert Martin"
Journal: "IEEE Computer"
Year: 2001
Month: "Nov"

[MaxionR00a]
Title: "Benchmarking Anomaly-Based Detection Systems"
Author: "Roy Maxion and Kymie Tan"
Proceedings: "Proceedings, International Conference on Dependable Systems and Networks"
Year: 2000

[McAlerneyJ02a]
Title: "Intrusion Detection Working Group repository"
Author: "Joe McAlerney"
URL: www.silicondefense.com/idwg
Year: 2002

[McAuliffeN90a]
Title: "Is Your Computer Being Misused? A survey of Current Intrusion Detection System Technology"
Author: "Noelle McAuliffe and Dawn Wolcott and Lorrayne Schaefer and others"
Proceedings: "Proceedings, IEEE 6th Computer Security Applications Conference"
Year: 1990

[McCanneS93a]
Title: "The BSD Packet Filter: a New Architecture for User-level Packet Capture"
Author: "Steven McCanne and Van Jacobson"
Proceedings: "Proceedings, USENIX Winter Technical Conference"
Year: 1993
Month: "Jan"

[McCartyB03a]
Title: "Botnets: Big and Bigger"
Author: "Bill McCarty"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "July-Aug"
Volume: 1
Number: 4

[McCartyB03b]
Title: "Automated Identity Theft"
Author: "Bill McCarty"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Sep-Oct"
Volume: 1
Number: 5

[McGrawG00a]
Title: "Will openish source really improve security?"
Author: "Gary McGraw"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 2000

[McGrawG00b]
Title: "Attacking malicious code: a report to the Infosec Research Council"
Author: "Gary McGraw and Greg Morrisett"
Journal: "IEEE Software"
Year: 2000
Month: "Sep-Oct"

[McHughJ00a]
Title: "Defending Yourself: The Role of Intrusion Detection Systems"
Author: "John McHugh and Alan Christie and Julia Allen"
Journal: "IEEE Software"
Year: 2000
Month: "Sep-Oct"

[McHughJ00b]
Title: "Testing Intrusion Detection Systems: a Critique of the 1998 and 1999 DARPA Intrusion Detection System Evaluations as Performed by Lincoln Laboratory"
Author: "John McHugh"
Journal: "ACM Transactions on Information and Systems Security"
Year: 2000
Month: "Nov"
Volume: 3
Number: 4

[McLaughlinL03a]
Title: "Virus-Writing 101: College Class Stirs Up Controversy"
Author: "Laurianne McLaughlin"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jul-Aug"
Volume: 1
Number: 4

[McLeanJ90a]
Title: "The Specification and Modeling of Computer Security"
Author: "John McLean"
Journal: "IEEE Computer"
Year: 1990
Month: "Jan"

[MellP00a]
Title: "A Denial-of-Service Resistant Intrusion Detection Architecture"
Author: "Peter Mell and Donald Marks and Mark McLarnon"
Journal: "Computer Networks"
Year: 2000
Volume: 34

[MitchellC96a]
Title: "Models for the Design of Human Interaction with Complex Dynamic Systems"
Author: "Christine Mitchell"
Proceedings: "Proceedings, Conference on Cognitive Engineering Systems in Process Control"
Year: 1996

[Mitre02a]
Title: "CVE: Common Vulnerabilities and Exposures"
Author: "Mitre Corporation"
URL: "cve.mitre.org"
Year: 2002

[Mixter99a]
Title: "FAQ and Guide to Cracking"
Author: "Mixter"
URL: www.counterpane.com/crypto-gram.html
Year: 2000
Month: "Mar"

[MogulJ87a]
Title: "The Packet Filter: an Efficient Mechanism for User-level Network Code"
Author: "Jeffery Mogul and Richard Rashid and Michael Accetta"
Proceedings: "Proceedings, 11th Symposium on Operating Systems Principles"
Year: 1987
Month: "Nov"

[MolnarS01a]
Title: "A General Fractal Model of Internet Traffic"
Author: "Sandor Molnar and Gyorgy Terdik"
Proceedings: "Proceedings, IEEE Conference on Local Computer Networks"
Year: 2001

[MooreD01a]
Title: "Inferring Internet Denial-of-Service Activity"
Author: "David Moore and Geoffrey Voelker and Stefan Savage"
Proceedings: "Proceedings, 10th USENIX UNIX Security Symposium"
Year: 2001
Month: "Aug"

[MorrisR79a]
Title: "Password Security: a case history"
Author: "Robert Morris and Ken Thompson"
Journal: "Communications of the ACM"
Year: 1979
Month: "Nov"
Volume: 22
Number: 11

[MuellerP01a]
Title: "Dragon Claws its Way to the Top"
Author: "Patrick Mueller and Greg Shipley"
Journal: "Network Computing"
Year: 2001
Month: "Aug"

[MukherjeeB94a]
Title: "Network Intrusion Detection"
Author: "Biswanath Mukherjee and Todd Heberlein and Karl Levitt"
Journal: "IEEE Network"
Year: 1994
Month: "May-June"

[MySQL03a]
Title: "MySQL database system web site"
Author: "MySQL AB"
URL: www.mysql.com
Year: 2003

[MyersonJ02a]
Title: "Identifying Enterprise Network Vulnerabilities"
Author: "Judith M. Myerson"
Journal: "International Journal of Network Management"
Year: 2002
Month: "Feb"
Number: 12

[NCSC85a]
Title: "Trusted Computer System Evaluation Criteria"
Author: "National Computer Security Center"
Institution: "Department of Defense"
Type: "Technical Report DOD 5200.28-STD (Orange Book)"
Year: 1985

[NSS03a]
Title: "NSS Group Web Site"
Author: "The NSS Group"
URL: www.nss.co.uk
Year: 2003

[NSWC02a]
Title: "Shadow Intrusion Detection System"
Author: "Naval Surface Warfare Center, Dahlgren Lab"
URL: www.nswc.navy.mil/ISSEC/CID
Year: 2002

[NashD01a]
Title: "Simulation of Self-Similarity in Network Utilization Patterns as a Precursor to Automated Testing of Intrusion Detection Systems"
Author: "David Nash and Daniel Ragsdale"
Journal: "IEEE Transactions on Systems, Man and Cybernetics, Part A: Systems and Humans"
Year: 2001
Volume: 31
Number: 4

[NeriF00a]
Title: "Comparing local search with respect to genetic evolution to detect intrusions in computer networks"
Author: "F. Neri"
Proceedings: "Proceedings, Congress on Evolutionary Computation"
Year: 2000

[NeumanB94a]
Title: "Kerboros: An Authentication Service for Computer Networks"
Author: "B. Clifford Neuman and Theodore Ts'o"
Journal: "IEEE Communications"
Year: 1994
Month: "Sep"

[NeumannP99a]
Title: "Experience with EMERALD to Date"
Author: "Peter Neumann and Phillip Porras"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[NewmanD02a]
Title: "Crying wolf: False alarms hide attacks"
Author: "David Newman and Joel Snyder and Rodney Thayer"
URL: www.nwfusion.com
Year: 2002

[NewmanM02a]
Title: "Email Networks and the Spread of Computer Viruses"
Author: "M. E. J. Newman and Stephanie Forrest and Justin Balthrop"
Journal: "Physical Review E"
Year: 2002
Volume: 66
Number: 035101

[Nfr01a]
Title: "Overview of NFR Network Intrusion Detection"
Author: "NFR Security"
URL: www.nfr.net
Year: 2001

[NiggemannO01a]
Title: "Visualization of Traffic Structures"
Author: "Oliver Niggemann and Benno Stein and Jens Tolle"
Proceedings: "Proceedings, Recent Advances in Intrusion Detection (RAID 2000)"
Year: 2001

[NorthcuttS01a]
Title: "Network Intrusion Detection: an Analyst's Handbook"
Author: "Stephen Northcutt and Judy Novak"
Publisher: "New Riders Publishing"
Edition: "Second"
Year: 2001

[NortonP00a]
Title: "Network Security Fundimentals"
Author: "Peter Norton and Mark Stockman"
Publisher: "Sams Publishing"
Year: 2000

[NyarkoK02a]
Title: "Network Intrusion Visualization with NIVA, and Intrusion Detection Visual Analyzer with Haptic Integration"
Author: "Kofi Nyarko and Tanya Capers and Craig Scott and Kemi Ladeji-Osias"
Proceedings: "Proceedings, Symposium on Haptic Interfaces for Virtual Environments"
Year: 2002

[ObertM95a]
Title: "Fractal Reviews in the Natural and Applied Sciences"
Chapter: "Analysis of an Image of the Human Brain obtained by Positron Emission Tomography in terms of Fractal Geometry"
Author: "M. Obert and R. Bergmann and others"
Publisher: "Chapman and Hall"
Year: 1995

[OetikerT98a]
Title: "MRTG the Multi Router Traffic Grapher"
Author: "Tobias Oetiker"
Proceedings: "Proceedings, 12th USENIX LISA Conference"
Year: 1998
Month: "Dec"

[OkazakiY02a]
Title: "A New Intrusion Detection Method based on Process Profiling"
Author: "Yoshinori Okazaki and Izuru Sato and Shigeki Goto"
Proceedings: "Proceedings, IEEE/IPSJ International Symposium on Applications and the Internet (SAINT)"
Year: 2002

[OppligerR03a]
Title: "Digital Evidence: Dream and Reality"
Author: "Rolf Oppliger and Ruedi Rytz"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Sep-Oct"
Volume: 1
Number: 5

[OppligerR98a]
Title: "Security at the Internet Layer"
Author: "Rolf Oppliger"
Journal: "IEEE Computer"
Year: 1998
Month: "Sep"

[ParkK96a]
Title: "On the relationship between file sizes, transport protocols and self-similar network traffic"
Author: "Kihong Park and Gitae Kim and Mark Crovella"
Proceedings: "Proceedings, IEEE Conference on Network Protocols"
Year: 1996

[ParnasD72a]
Title: "On the Criteria To Be Used in Decomposing Systems into Modules"
Author: "David L. Parnas"
Journal: "Communications of the ACM"
Year: 1972
Month: "Dec"
Volume: 15
Number: 12

[PaxsonV01a]
Title: "An Analysis of Using Reflectors for Distributed Denial-of-Service Attacks"
Author: "Vern Paxson"
Journal: "Computer Communication Review"
Year: 2001
Month: "July"
Volume: 31
Number: 3

[PaxsonV02a]
Title: "Experiences with NIMI"
Author: "Vern Paxson and Andrew Adams and Matt Mathis"
Proceedings: "Proceedings, IEEE/IPSJ International Symposium on Applications and the Internet (SAINT)"
Year: 2002

[PaxsonV94a]
Title: "Empirically-Derived Analytic Models of Wide-Area TCP Connections"
Author: "Vern Paxson"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1994
Month: "Aug"
Volume: 2
Number: 4

[PaxsonV95a]
Title: "Wide-Area Traffic: The Failure of Poisson Modeling"
Author: "Vern Paxson and Sally Floyd"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1995
Month: "June"
Volume: 3
Number: 3

[PaxsonV95b]
Title: "Fast Approximation of Self-Similar Network Traffic"
Author: "Vern Paxson"
Institution: "Lawrence Berkley Laboratory"
Type: "Technical Report LBL-36750"
Year: 1995

[PaxsonV97a]
Title: "Why We Don't Know How to Simulate the Internet"
Author: "Vern Paxson and Sally Floyd"
Proceedings: "Proceedings, Winter Simulation Conference"
Year: 1997
Month: "Dec"

[PaxsonV97b]
Title: "Automatic Packet Trace Analysis of TCP Implementations"
Author: "Vern Paxson"
Proceedings: "Proceedings, ACM SIGCOMM '97"
Year: 1997

[PaxsonV99a]
Title: "Bro: A System for Detecting Network Intruders in Real-Time"
Author: "Vern Paxson"
Journal: "Computer Networks"
Year: 1999
Month: "Dec"
Volume: 31

[PleasK99a]
Title: "Certificates, Keys and Security"
Author: "Keith Pleas"
Journal: "PC Magazine"
Year: 1999
Month: "Apr"

[PorrasP97a]
Title: "EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances"
Author: "Phillip Porras and Peter Neumann"
Proceedings: "Proceedings, 20th National Information Systems Security Conference"
Year: 1997
Month: "Oct"

[PorrasP98a]
Title: "Live Traffic Analysis of TCP/IP Gateways"
Author: "Phillip Porras and Alfonso Valdes"
Proceedings: "Proceedings, Internet Society Symposium on Network and Distributed Systems Security"
Year: 1998

[PrevelakisV99a]
Title: "A secure station for network monitoring and control"
Author: "Vassilis Prevelakis"
Proceedings: "Proceedings, 8th USENIX Security Symposium"
Year: 1999
Month: "Aug"

[PriceK97a]
Title: "Host-based Misuse Detection and Conventional Operating Systems' Audit Data Collection"
Author: "Katherine Price"
School: "Purdue University"
Year: 1997

[PtacekT98a]
Title: "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection"
Author: "Thomas Ptacek and Timothy Newsham"
URL: www.nai.com
Year: 1998

[PuketzaN96a]
Title: "A Methodology for Testing Intrusion Detection Systems"
Author: "Nicholas Puketza and Kui Zhang and others"
Journal: "IEEE Transactions on Software Engineering"
Year: 1996
Volume: 22
Number: 10

[PuketzaN97a]
Title: "A Software Platform for Testing Intrusion Detection Systems"
Author: "Nicholas Puketza and Mandy Chung and Ronald Olsson and Biswanath Mukherjee"
Journal: "IEEE Software"
Year: 1997
Month: "Sep-Oct"

[QiaoY02a]
Title: "Anomaly intrusion detection method based on HMM"
Author: "Y. Qiao and X. Xin and Y. Bin and S. Ge"
Journal: "Electronics Letters"
Year: 2002
Volume: 38
Number: 13

[RabekJ03a]
Title: "Detection of Injected, Dynamically Generated, and Obfuscated Malicious Code"
Author: "Jesse Rabek and Roger I. Khazan and others"
Proceedings: "Proceedings, ACM Workshop on Rapid Malcode"
Year: 2003

[RalphW01a]
Title: "SHADOW Version 1.7 Installation Manual"
Author: "William Ralph"
URL: www.nswc.navy.mil
Year: 2001

[RamosJ01a]
Title: "DRAGON - an Intrusion Detection System"
Author: "Joni Ramos"
URL: www.sans.org
Year: 2001

[RanumM97a]
Title: "Implementing a Generalized Tool for Network Monitoring"
Author: "Marcus Ranum and Kent Landfield and Mike Stolarchuk and others"
Proceedings: "Proceedings, 11th USENIX Systems Administration Conference"
Year: 1997
Month: "Oct"

[RawlinsG92a]
Title: "Compared to What? An Introduction to the Analysis of Algorithms"
Author: "Gregory J. E. Rawlins"
Publisher: "W. H. Freeman and Co."
Year: 1992

[Rfc2827]
Title: "Network Ingress Filtering: defeating DoS attacks which employ IP source address spoofing (RFC 2877)"
Author: "P. Ferguson and D. Senie"
URL: www.rfc-editor.org
Year: 2000

[Rfc3067]
Title: "TERENA's Incident Object Description and Exchange Format Requirements (RFC 3067)"
Author: "Jimmy Arvidsson and Andrew Cormack and others"
URL: www.rfc-editor.org
Year: 2001

[Rfc896]
Title: "Congestion Control in IP / TCP Internetworks (RFC 896)"
Author: "John Nagle"
URL: www.rfc-editor.org
Year: 1984

[RitcheyR00a]
Title: "Using Model Checking to Analyze Network Vulnerabilities"
Author: "Ronald Ritchey and Paul Ammann"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 2000

[RitchieD74a]
Title: "The UNIX Time-Sharing System"
Author: "Dennis Ritchie and Ken Thompson"
Journal: "Communications of the ACM"
Year: 1974
Month: "July"
Volume: 17
Number: 7

[RivestR78a]
Title: "A Method for Obtaining Digital Signatures and Public-Key Cryptosystems"
Author: "Ronald Rivest and Adi Shamir and Leonard Adleman"
Journal: "Communications of the ACM"
Year: 1978
Month: "Feb"
Volume: 21
Number: 2

[RobelA95a]
Title: "Neural Networks for Modeling Time Series of Musical Instruments"
Author: "Axel Robel"
Proceedings: "Proceedings, International Computer Music Conference"
Year: 1995

[RobertsJ00a]
Title: "Multiple-View and Multiform Visualization"
Author: "Jonathan Roberts"
Proceedings: "Proceedings, SPIE Conference on Visual Data Exploration and Analysis VIII"
Year: 2000

[RobertsJ98a]
Title: "On Encouraging Multiple Views for Visualization"
Author: "Jonathan Roberts"
Proceedings: "Proceedings, IEEE Conference on Information Visualization IV"
Year: 1998

[RobertsJ98b]
Title: "Waltz - An Exploratory Visualization tool for Volume Data, using Multifirm Abstract Displays"
Author: "Jonathan Roberts"
Proceedings: "Proceedings, SPIE Conference on Visual Data Exploration and Analysis VI"
Year: 1998

[RobertsJ99a]
Title: "On Encouraging Coupled Views for Visualization"
Author: "Jonathan Roberts"
Proceedings: "Proceedings, SPIE Conference on Visual Data Exploration and Analysis VII"
Year: 1999

[RobertsonG91a]
Title: "Cone Trees: Animated 3D Visualizations of Hierarchical Information"
Author: "George Robertson and Jock Mackinlay and Stuart Card"
Proceedings: "Proceedings, ACM Conference on Human Factors in Computing Systems and Information Visualization"
Year: 1991

[RobertsonG93a]
Title: "Information Visualization using 3D Interactive Animation"
Author: "George Robertson and Stuart Card and Jock Mackinlay"
Journal: "Communications of the ACM"
Year: 1993
Month: "Apr"
Volume: 36
Number: 4

[RoeschM99a]
Title: "Snort - Lightweight Intrusion Detection for Networks"
Author: "Martin Roesch"
Proceedings: "Proceedings, 13th USENIX Systems Administration Conference"
Year: 1999
Month: "Nov"

[RosenM98a]
Title: "Internet Security Standards"
Author: "Michele Rosen"
Journal: "PC Magazine"
Year: 1998
Month: "Jan"

[RosseyL02a]
Title: "LARIAT: Lincoln Adaptable Real-time Information Assurance Testbed"
Author: "Lee M. Rossey and Robert K. Cunningham and others"
Proceedings: "Proceedings, IEEE Aerospace Conference"
Year: 2002

[RoughanM99a]
Title: "Measuring Long-Range Dependence under Changing Traffic Conditions"
Author: "Mathew Roughan and Darryl Veitch"
Proceedings: "Proceedings, IEEE INFOCOMM"
Year: 1999

[Rproject02a]
Title: "The R Environment for Statistical Computing and Graphics"
Author: "Robert Gentleman and Ross Ihaka"
URL: www.r-project.org
Year: 2002

[RubinA98a]
Title: "A Survey of Web Security"
Author: "Aviel Rubin and Daniel Geer Jr."
Journal: "IEEE Computer"
Year: 1998
Month: "Sep"

[SANS00a]
Title: "Egress Filtering"
Author: "SANS Institute"
URL: www.sans.org
Year: 2000

[SaltzerJ74a]
Title: "The Protection of Information in Computer Systems"
Author: "Jerome H. Saltzer and Michael D. Schroeder"
Journal: "Communications of the ACM"
Year: 1974
Month: "July"
Volume: 17
Number: 7

[SarvothamS01a]
Title: "Connection-level Analysis and Modeling of Network Traffic"
Author: "Shriram Sarvotham and Rudolf Riedi and Richard Baraniuk"
Proceedings: "Proceedings, ACM SIGCOMM Internet Measurement Workshop"
Year: 2001

[SavageS00a]
Title: "Practical Network Support for IP Traceback"
Author: "Stefan Savage and David Wetherall and Anna Karlin and Tom Anderson"
Proceedings: "Proceedings, ACM SIGCOMM '00"
Year: 2000
Month: "Aug"

[SchaenS91a]
Title: "Network Auditing: Issues and Recommendations"
Author: "Samuel Schaen and Brian McKenney"
Proceedings: "Proceedings, IEEE 7th Computer Security Applications Conference"
Year: 1991

[SchiffmanM03a]
Title: "Building Open Source Network Security Tools"
Author: "Mike Schiffman"
Publisher: "Wiley Publishing"
Year: 2003

[SchleiferW01a]
Title: "Online Error Detection through Observation of Traffic Self-similarity"
Author: "W. Schleifer and M. Mannle"
Journal: "IEE Proceedings on Communications"
Year: 2001
Month: "Feb"
Volume: 148
Number: 1

[SchnackenbergD00a]
Title: "Infrastructure for Intrusion Detection and Response"
Author: "Dan Schnackenberg and Kelly Djahandari and Dan Sterne"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX I)"
Year: 2000

[SchnackenbergD01a]
Title: "Cooperative Intrusion Traceback and Response Architecture CITRA"
Author: "Dan Schnackenberg and Harley Holliday and Randall Smith and others"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001

[SchneiderF00a]
Title: "Open Source in Security: Visiting the Bizarre"
Author: "Fred Schneider"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 2000

[SchneidermanB92a]
Title: "Designing the User Interface"
Author: "Ben Schneiderman"
Publisher: "Addison-Wesley"
Edition: "Second"
Year: 1992

[SchneidermanB96a]
Title: "The Eyes Have It: A Task by Data Type Taxonomy for Information Visualization"
Author: "Ben Schneiderman"
Institution: "University of Maryland HCI Lab"
Type: "Technical Report CS-TR-3665"
Year: 1996

[SchneidermanB96b]
Title: "Advanced Graphic User Interfaces: Elastic and Tightly Coupled Windows"
Author: "Ben Schneiderman"
Journal: "ACM Computing Surveys"
Year: 1996
Month: "Dec"

[SchneierB00a]
Title: "Distributed Denial-of-Service Attacks"
Author: "Bruce Schneier"
URL: www.counterpane.com/crypto-gram.html
Year: 2000
Month: "Feb"

[SchneierB01a]
Title: "802.11 Wireless LAN Security Issues"
Author: "Bruce Schneier"
URL: www.counterpane.com/crypto-gram.html
Year: 2001
Month: "Mar"

[SchneierB03a]
Title: "We Are All Security Consumers"
Author: "Bruce Schneier"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jan-Feb"
Volume: 1
Number: 1

[SchneierB97a]
Title: "An Improved E-Mail Security Protocol"
Author: "Bruce Schneier and Chris Hall"
Proceedings: "Proceedings, IEEE Computer Security Applications Conference"
Year: 1997

[SchneierB97b]
Title: "Why Cryptography is harder than it looks"
Author: "Bruce Schneier"
Journal: "Information Security Bulletin"
Year: 1997
Month: "Mar"

[SchneierB98a]
Title: "Cryptographic design vulnerabilities"
Author: "Bruce Schneier"
Journal: "IEEE Computer"
Year: 1998
Month: "Sep"

[SchneierB98b]
Title: "Electronic Commerce: The future of fraud"
Author: "Bruce Schneier"
URL: www.counterpane.com/crypto-gram.html
Year: 1998
Month: "Nov"

[SchneierB98c]
Title: "Security Pitfalls in Cryptography"
Author: "Bruce Schneier"
Year: 1998

[SchneierB99a]
Title: "Cryptography: the importance of Not being different"
Author: "Bruce Schneier"
Journal: "IEEE Computer"
Year: 1999
Month: "Mar"

[SchneierB99b]
Title: "Security in the Real World: how to evaluate security technology"
Author: "Bruce Schneier"
Journal: "Computer Security Journal"
Year: 2000
Volume: 15
Number: 4

[SchneierB99c]
Title: "Secure Audit Logs to Support Computer Forensics"
Author: "Bruce Schneier and John Kelsey"
Journal: "ACM Transactions on Information and System Security"
Year: 1999
Month: "May"
Volume: 2
Number: 2

[SchoutenJ94a]
Title: "Estimation of the Dimension of a Noisy Attractor"
Author: "Jaap Schouten and Floris Takens and Cor M. van den Bleek"
Journal: "Physical Review E"
Year: 1994
Volume: 50
Number: 3

[SchusterH89a]
Title: "Deterministic Chaos: An Introduction"
Author: "Heinz Georg Schuster"
Publisher: "VCH"
Year: 1987

[SekarR02a]
Title: "Specification-based Anomaly Detection: a New Approach for Detecting Network Intrusions"
Author: "R. Sekar and A. Gupta and J. Frullo and others"
Proceedings: "Proceedings, ACM Computer and Communications Security Conference"
Year: 2002

[SekarR99a]
Title: "On Preventing Intrusions by Process Behavior Monitoring"
Author: "R. Sekar and T. Bowen and M. Segal"
Proceedings: "Proceedings, USENIX Workshop on Intrusion Detection and Network Monitoring"
Year: 1999
Month: "Apr"

[SekarR99b]
Title: "A High-Performance Network Intrusion Detection System"
Author: "R. Sekar and Y. Guang and S. Verma and T Shanbhag"
Proceedings: "Proceedings, ACM Computer and Communications Security Conference"
Year: 1999

[ShannonC48a]
Title: "A Mathematical Theory of Communication"
Author: "Claude E. Shanon"
Journal: "Bell System Technical Journal"
Year: 1948
Month: "July"

[ShochJ80a]
Title: "Measuring Performance of an Ethernet Local Network"
Author: "John Shoch and Jon Hupp"
Journal: "Communications of the ACM"
Year: 1980
Month: "Dec"
Volume: 23
Number: 12

[ShochJ82a]
Title: "The Worm Programs - Early Experience with a Distributed Computation"
Author: "John F. Shoch and Jon A. Hupp"
Journal: "Communications of the ACM"
Year: 1982
Month: "March"
Volume: 25
Number: 3

[ShyneS01a]
Title: "Using active networking to thwart distributed denial of service attacks"
Author: "Scott Shyne and Adam Hovak and Joseph Riolo"
Proceedings: "Proceedings, IEEE Conference on Aerospace Systems"
Year: 2001

[SilberschatzA02a]
Title: "Operating System Concepts"
Author: "Abraham Silberschatz and Peter Galvin and Greg Gagne"
Publisher: "John Wiley and Sons"
Edition: "Sixth"
Year: 2002

[SinghH01a]
Title: "Investigating and Evaluating Behavioural Profiling and Intrusion Detection Using Data Mining"
Author: "Harjit Singh and Steven Furnell and Benn Lines and Paul Dowland"
Journal: "Lecture Notes in Computer Science"
Year: 2001
Number: 2052

[SmahaS88a]
Title: "Haystack: an Intrusion Detection System"
Author: "Stephen Smaha"
Proceedings: "Proceedings, IEEE 4th Aerospace Computer Security Applications Conference"
Month: "Dec"
Year: 1988

[SmahaS94a]
Title: "svr4++, A Common Audit Trail Interchange Format for Unix"
Author: "Stephen Smaha"
Institution: "Haystack Laboratories"
Year: 1994

[SmithS04a]
Title: "Grand Challenges in Information Security: Process and Output"
Author: "Sean W. Smith and Eugene H. Spafford"
Journal: "IEEE Security and Privacy"
Year: 2004
Month: "Jan-Feb"
Volume: 2
Number: 1

[SnappS91a]
Title: "DIDS (Distributed Intrusion Detection System) - Motivation, Architecture and an Early Prototype"
Author: "Steven Snapp and James Brentano and Gihan Dias and others"
Proceedings: "Proceedings, 14th National Computer Security Conference"
Month: "Oct"
Year: 1991

[Snort03a]
Title: "Snort: the Open Source Network Intrusion Detection System"
Author: "Brian Caswell and Marty Roesch"
URL: www.snort.org
Year: 2003

[SommerP99a]
Title: "Intrusion detection systems as evidence"
Author: "Peter Sommer"
Journal: "Computer Networks"
Year: 1999
Volume: 31

[SpaffordE00a]
Title: "Intrusion Detection using autonomous agents"
Author: "Eugene Spafford and Diego Zamboni"
Journal: "Computer Networks"
Year: 2000
Volume: 34

[SpaffordE00b]
Title: "Data collection mechanisms for intrusion detection systems"
Author: "Eugene Spafford and Diego Zamboni"
Institution: "Purdue University"
Type: "CERIAS Technical Report 2000-08"
Year: 2000

[SpenceR01a]
Title: "Information Visualization"
Author: "Robert Spence"
Publisher: "ACM Press"
Year: 2001

[StallingsW00a]
Title: "Data & Computer Communications"
Author: "William Stallings"
Publisher: "Prentice-Hall"
Edition: "Sixth"
Year: 2000

[StallingsW00b]
Title: "Network Security Essentials: Applications and Standards"
Author: "William Stallings"
Publisher: "Prentice-Hall"
Year: 2000

[StanifordS02a]
Title: "How to 0wn the Internet in Your Spare Time"
Author: "Stuart Staniford and Vern Paxson and Nicholas Weaver"
Proceedings: "Proceedings, USENIX Security Symposium"
Year: 2002

[StanifordS95a]
Title: "Holding Intruders Accountable on the Internet"
Author: "S. Staniford-Chen and L. Todd Heberlein"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy"
Year: 1995

[StanifordS96a]
Title: "GrIDS - a Graph-based Intrusion Detection System for Large Networks"
Author: "S. Staniford-Chen and S. Cheung and R. Crawford and others"
Proceedings: "Proceedings, 19th National Computer Security Conference"
Month: "Oct"
Year: 1996

[SteinauerD99a]
Title: "Basic Intrusion Protection: the first line of defense"
Author: "Dennis Steinauer and Stuart Katzke and Shirley Radack"
Journal: "IT Pro"
Year: 1999
Month: "Jan-Feb"

[StephensonP00a]
Title: "The Application of Intrusion Detection Systems in a Forensic Environment"
Author: "Peter Stephenson"
Proceedings: "Proceedings, Recent Advances in Intrusion Detection (RAID 2000)"
Year: 2000
Month: "Oct"

[StevensR94a]
Title: "TCP/IP Illustrated: the protocols"
Author: "Richard Stevens"
Volume: 1
Publisher: "Addison-Wesley Publishing"
Year: 1994

[StevensR95a]
Title: "TCP/IP Illustrated: the implementation"
Author: "Richard Stevens"
Volume: 2
Publisher: "Addison-Wesley Publishing"
Year: 1995

[StolfoS01a]
Title: "Data Mining-based Intrusion Detectors: An Overview of the Columbia IDS Project"
Author: "Salvatore Stolfo and Wenke Lee and Philip K. Chan and others"
Journal: "SIGMOD Record"
Year: 2001
Month: "Dec"
Volume: 30
Number: 4

[StolfoS97a]
Title: "JAM: Java Agents for Meta-Learning over Distributed Databases"
Author: "Salvatore Stolfo and Andreas Prodromidis and others"
Proceedings: "Proceedings, 3rd International Conference on Knowledge Discovery and Data Mining"
Year: 1997

[StollC88a]
Title: "Stalking the Wily Hacker"
Author: "Clifford Stoll"
Journal: "Communications of the ACM"
Year: 1988
Month: "May"
Volume: 31
Number: 5

[StollC90a]
Title: "The Cuckoo's Egg: tracking a spy through a maze of computer espionage"
Author: "Cliff Stoll"
Publisher: "Simon and Schuster"
Year: 1990

[StoneD01a]
Title: "Preventing and curing Word macro viruses"
Author: "David Stone"
Journal: "PC Magazine"
Year: 2001
Month: "Feb"

[StringerD02a]
Title: "Digital Evidence"
Author: "David Stringer-Calvert"
Journal: "Communications of the ACM"
Year: 2002
Month: "April"
Volume: 45
Number: 4

[StytzM03a]
Title: "Software Protection: Security's Last Stand"
Author: "Martin Stytz and James Whittaker"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jan-Feb"
Volume: 1
Number: 1

[StytzM03b]
Title: "Caution: This Product Contains Security Code"
Author: "Martin R. Stytz and James A. Whittaker"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Sep-Oct"
Volume: 1
Number: 5

[SwayneD91a]
Title: "XGobi Meets S: Integrating Software for Data Analysis"
Author: "Deborah F. Swayne and Andreas Buja and Nancy Hubbell"
Proceedings: "Proceedings, 23rd Symposium on The Interface"
Year: 1991

[SwingE98a]
Title: "Flodar: Flow Visualization of Network Traffic"
Author: "Edward Swing"
Journal: "IEEE Computer Graphics and Applications"
Year: 1998
Month: "Sep-Oct"

[TanenbaumA96a]
Title: "Computer Networks"
Author: "Andrew Tanenbaum"
Publisher: "Prentice-Hall"
Edition: "Third"
Year: 1996

[TapiadorJ03a]
Title: "Stochastic Protocol Modeling for Anomaly Based Network Intrusion Detection"
Author: "Juan M. Estavez-Tapiador and Padro Garcia-Teodoro and Jesus E. Diaz-Verdejo"
Proceedings: "Proceedings, IEEE International Workshop on Information Assurance"
Year: 2003

[TaqquM03a]
Title: "Murad Taqqu's Web Page at Boston University"
Author: "Murad Taqqu"
URL: "math.bu.edu/people/murad"
Year: 2003

[TaylorC02a]
Title: "An Empirical Analysis of NATE - Network Analysis of Anomalous Traffic Events"
Author: "Carol Taylor and Jim Alves-Foss"
Proceedings: "Proceedings, ACM Workshop on New Security Paradigms"
Year: 2002

[TempletonS01a]
Title: "A Requires/Provides Model for Computer Attacks"
Author: "Steven Templeton and Karl Levitt"
Proceedings: "Proceedings, ACM Workshop on New Security Paradigms"
Year: 2001

[TeohS02a]
Title: "Case Study: Interactive Visualization for Internet Security"
Author: "Soon Tee Teoh and Kwan-Liu Ma and S. Felix Wu and Xiaoliang Zhao"
Proceedings: "Proceedings, IEEE Visualization 2002"
Year: 2002

[ThompsonH03a]
Title: "Why Security Testing is Hard"
Author: "Herbert H. Thompson"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Jul-Aug"
Volume: 1
Number: 4

[ThompsonK84a]
Title: "Reflections on trusting trust"
Author: "Ken Thompson"
Journal: "Communications of the ACM"
Year: 1984
Month: "Aug"
Volume: 27
Number: 8

[ThottanM98a]
Title: "Proactive Anomaly Detection Using Distributed Intelligent Agents"
Author: "Marina Thottan and Chuanyi Ji"
Journal: "IEEE Network"
Year: 1998
Month: "Sept"

[TolleJ00a]
Title: "Supporting Intrusion Detection by Graph Clustering and Graph Drawing"
Author: "Jens Tolle and Oliver Niggemann"
Proceedings: "Proceedings, Recent Advances in Intrusion Detection (RAID 2000)"
Year: 2000
Month: "Oct"

[TufteE83a]
Title: "The Visual Display of Quantitative Information"
Author: "Edward R. Tufte"
Publisher: "Graphics Press"
Year: 1983

[TufteE90a]
Title: "Envisioning Information"
Author: "Edward R. Tufte"
Publisher: "Graphics Press"
Year: 1990

[TufteE97a]
Title: "Visual Explanations: images and quantities, evidence and narrative"
Author: "Edward R. Tufte"
Publisher: "Graphics Press"
Year: 1997

[TungB00a]
Title: "The Common Intrusion Specification Language: a Retrospective"
Author: "Brian Tung"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX I)"
Year: 2000

[UppuluriP01a]
Title: "Experiences with Specification-based Intrusion Detection"
Author: "P. Uppuluri and R. Sekar"
Proceedings: "Proceedings, Recent Advances in Intrusion Detection (RAID 2001)"
Year: 2001
Month: "Oct"

[UpsonC89a]
Title: "The Application Visualization System: a Computational Environment for Scientific Visualization"
Author: "Craig Upson and Thomas Faulhaber and David Kamins and others"
Journal: "IEEE Computer Graphics and Applications"
Year: 1989
Month: "July"

[VaccaroH89a]
Title: "Detection of Anomalous Computer Session Activity"
Author: "H. Vaccaro and G. Liepins"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy "
Year: 1989

[ValdesA00a]
Title: "Adaptive, Model-based Monitoring for Cyber Attack Detection"
Author: "Alfonso Valdes and Keith Skinner"
Proceedings: "Proceedings, Recent Advances in Intrusion Detection (RAID 2000)"
Year: 2000
Month: "Oct"

[ValdesA03a]
Title: "Dependable Intrusion Tolerance: Technology Demo"
Author: "Alfonso Valdes and Magnus Almgren and Steven Cheung and others "
Proceedings: "Proceedings, DARPA Information Survivability Conference and Exposition (DISCEX'03)"
Year: 2003

[VenablesW00a]
Title: "S Programming"
Author: "W. N. Venables and B. D. Ripley"
Publisher: "Springer-Verlag"
Year: 2000

[VenemaW92a]
Title: "TCP Wrapper: network monitoring, access control and booby traps"
Author: "Wietse Venema"
Proceedings: "Proceedings, 3rd USENIX UNIX Security Symposium"
Year: 1992
Month: "Sep"

[VenemaW96a]
Title: "Murphy's law and computer security"
Author: "Wietse Venema"
Proceedings: "Proceedings, 6th USENIX UNIX Security Symposium"
Year: 1996
Month: "July"

[VertG98a]
Title: "A Visual Mathematical Model for Intrusion Detection"
Author: "Greg Vert and Deborah Frincke and Jesse McConnell"
Proceedings: "Proceedings, 21th National Information Systems Security Conference"
Year: 1998

[ViegaJ01a]
Title: "Trust (and mistrust) in secure applications"
Author: "John Viega and Tadayoshi Kohno and Bruce Potter"
Journal: "Communications of the ACM"
Year: 2001
Month: "Feb"
Volume: 44
Number: 2

[VignaG98a]
Title: "NetSTAT: a Network-based Intrusion Detection System"
Author: "Giovanni Vigna and Richard Kemmerer"
Proceedings: "Proceedings, 14th Computer Security Conference"
Year: 1998

[VikenB99a]
Title: "Passive Monitoring of Internet Traffic at Supercomputing '98"
Author: "Brynjar Viken"
Proceedings: "Proceedings, EUNICE '99, Barcelona"
Year: 1999

[WagnerD01a]
Title: "Intrusion Detection via Statis Analysis"
Author: "David Wagner and Drew Dean"
Proceedings: "Proceedings, IEEE Symposium on Security and Privacy"
Year: 2001

[WagnerD02a]
Title: "Mimicry Attacks on Host-based Intrusion Detection Systems"
Author: "David Wagner and Paolo Soto"
Proceedings: "Proceedings, ACM Conference on Computer and Communications Security"
Year: 2002

[WagnerD96a]
Title: "Analysis of the SSL 3.0 Protocol"
Author: "David Wagner and Bruce Schneier"
Proceedings: "Proceedings, 2nd USENIX Workshop on Electronic Commerce"
Year: 1996
Month: "Nov"

[WahbeR93a]
Title: "Efficient Software-based Isolation"
Author: "Robert Wahbe and Steven Lucco and Thomas Anderson and Susan Graham"
Journal: "Operating System Review"
Year: 1993
Volume: 27
Number: 3

[WainerH97a]
Title: "Visual Revelations"
Author: "Howard Wainer"
Publisher: "Copernicus/Springer-Verlag"
Year: 1997

[WanT01a]
Title: "IntruDetector: A Software Platform for Testing Network Intrusion Detection Algorithms"
Author: "Tao Wan and Xue Dong Yang"
Proceedings: "Proceedings, IEEE 17th Computer Security Applications Conference"
Year: 2001

[WangC00a]
Title: "On Computer Viral Infection and the Effect of Immunization"
Author: "Chenxi Wang and John Knight and Matthew Elder"
Proceedings: "Proceedings, 16th IEEE Computer Security Applications Conference"
Year: 2000

[WardM94a]
Title: "XmdvTool: Integrating Multiple Methods for Visualizing Multivariate Data"
Author: "Matthew Ward"
Proceedings: "Proceedings, IEEE Visualization '94"
Year: 1994

[WarrenderC99a]
Title: "Detecting Intrusions Using System Calls: Alternative Data Models"
Author: "Christina Warrender and Stephanie Forrest and Barak Pearlmutter"
Proceedings: "Proceedings, IEEE Symposium on Research in Security and Privacy "
Year: 1999

[WebsterS98a]
Title: "The Development and Analysis of Intrusion Detection Algorithms"
Author: "Seth Webster"
School: "Massachusetts Institute of Technology"
Year: 1998

[WegmanE86a]
Title: "Statistical Image Processing and Graphics"
Author: "Edward Wegman and Douglas DePriest"
Publisher: "Marcel Dekker"
Year: 1986

[WesselsD03a]
Title: "Wow, That's a Lot of Packets"
Author: "Duane Wessels and Marina Fomenkov"
Proceedings: "Proceedings, Passive and Active Measurement Workshop"
Year: 2003

[WhiteG96a]
Title: "Cooperating Security Managers: A Peer-based Intrusion Detection System"
Author: "Gregory White and Eric Fisch and Udo Pooch"
Journal: "IEEE Network"
Year: 1996
Month: "Jan-Feb"

[WhittakerJ00a]
Title: "What is Software Testing? And why is it so hard?"
Author: "James A. Whittaker"
Journal: "IEEE Software"
Year: 2000
Month: "Jan-Feb"

[WhittakerJ00b]
Title: "Toward a more reliable theory of software reliability"
Author: "James A. Whittaker and Jeffery Voas"
Journal: "IEEE Computer"
Year: 2000
Month: "Dec"

[WhittakerJ00c]
Title: "Neutralizing Windows-based malicious mobile code "
Author: "James A. Whittaker and Andres De Vivanco"
Year: 2000

[WhittakerJ01a]
Title: "Software's Invisible Users"
Author: "James A. Whittaker"
Journal: "IEEE Software"
Year: 2001
Month: "May-June"

[WhittakerJ01b]
Title: "Proactive, Selective Behaviour filtering with Data restoration: a new technique for runtime neutralization of malicious mobile code"
Author: "James A. Whittaker and Ronaldo Menezes and others"
Year: 2001

[WhittakerJ02a]
Title: "50 Years of Software: Key Principles for Quality"
Author: "James A. Whittaker and Jeffrey M Voas"
Journal: "IT Pro"
Year: 2002
Month: "Nov-Dec"

[WhittakerJ02b]
Title: "Software Engineering is Not Enough"
Author: "James A. Whittaker and Steven Atkin"
Journal: "IEEE Software"
Year: 2002
Month: "Jul-Aug"

[WhittakerJ03a]
Title: "No Clear Answers on Monoculture Issues"
Author: "James A. Whittaker"
Journal: "IEEE Security and Privacy"
Year: 2003
Month: "Nov-Dec"
Volume: 1
Number: 6

[WillingerW02a]
Title: "Scaling phenomena in the Internet: Critically examining criticality"
Author: "Walter Willinger and Ramesh Govindan and Sugih Jamin and Vern Paxson and Scott Shenker"
Year: 2002

[WillingerW97a]
Title: "Self-Similarity through High-Variability: Statistical Analysis of Ethernet LAN Traffic at the Source Level"
Author: "Walter Willinger and Murad Taqqu and Robert Sherman and Daniel Wilson"
Journal: "IEEE-ACM Transactions on Networking"
Year: 1997
Month: "Aug"
Volume: 5
Number: 1

[WillingerW98a]
Title: "Where Mathematics meets the Internet"
Author: "Walter Willinger and Vern Paxson"
Journal: "Notices of the American Mathematical Society"
Year: 1998
Month: "Sep"
Volume: 45
Number: 8

[WillsG99a]
Title: "NicheWorks - Interactive Visualization of Very Large Graphs"
Author: "Graham Wills"
Journal: "Journal of Computational and Graphical Statistics"
Year: 1999
Volume: 8
Number: 2

[WinklerJ89a]
Title: "Intrusion and Anomaly Detection in Trusted Systems"
Author: "J. Winkler and W. Page"
Proceedings: "Proceedings, 5th IEEE Computer Security Applications Conference"
Year: 1989
Month: "Dec"

[WirthN71a]
Title: "Program Development by Stepwise Refinement"
Author: "Niklaus Wirth"
Journal: "Communications of the ACM"
Year: 1971
Month: "April"
Volume: 14
Number: 4

[WoodM02a]
Title: "Intrusion Detection Message Exchange Requirements"
Author: "Mark Wood and Michael Erlinger"
URL: www.silicondefense.com/idwg
Year: 2002
Month: "Feb"

[YangJ00a]
Title: "CARDS: a Distributed System for Detecting Coordinated Attacks"
Author: "Jiahai Yang and Peng Ning X. Sean Wang and Sushil Jajodia"
Proceedings: "Proceedings, 16th Conference on Information Security"
Month: "Aug"
Year: 2000

[YeN00a]
Title: "Probabilistic Networks with Undirected Links for Anomaly Detection"
Author: "Nong Ye and Mingming Xu"
Proceedings: "Proceedings, IEEE Workshop on Information Assurance and Security"
Year: 2000

[YeN01a]
Title: "Statistical Process Control for Computer Intrusion Detection"
Author: "Nong Ye and Syed Masum Emran and Xiagyang Li and Qiang Chen"
Proceedings: "Proceedings, IEEE DARPA Information Survivability Conference and Exposition (DISCEX II)"
Year: 2001
Month: "Jan"

[YeN01b]
Title: "A Process Control Approach to Cyber Attack Detection"
Author: "Nong Ye and Joseph Giordano and John Feldman"
Journal: "Communications of the ACM"
Year: 2001
Month: "Aug"
Volume: 44
Number: 8

[YeN98a]
Title: "Information Fusion Techniques for Network Intrusion Detection"
Author: "Nong Ye and Joseph Giordano and John Feldman and Qiu Zhong"
Proceedings: "Proceedings, IEEE Information Technology Conference"
Year: 1998

[YlonenT96a]
Title: "SSH - secure login connections over the Internet"
Author: "Tatu Ylonen"
Proceedings: "Proceedings, 6th USENIX UNIX Security Symposium"
Year: 1996
Month: "July"

[ZalewskiM00a]
Title: "I don't think I really love you... or writing internet worms for fun and profit"
Author: "Michal Zalewski"
URL: "lcamtuf.coredump.cx/worm.txt"
Year: 2000

[ZamboniD00a]
Title: "Doing intrusion detection using embedded sensors - thesis proposal"
Author: "Diego Zamboni"
Year: 2000

[ZamboniD01a]
Title: "Using Internal Sensors for Computer Intrusion Detection"
Author: "Diego Zamboni"
School: "Purdue University"
Year: 2001

[ZhangH97a]
Title: "Estimation of Hurst Parameter by Variance-Time Plots"
Author: "H. F. Zhang and Y. T. Shu and Oliver Yang"
Proceedings: "Proceedings, IEEE Pacific Rim Conference on Communications, Computers and Signal Processing"
Year: 1997

[ZhangY00a]
Title: "Detecting Backdoors"
Author: "Yin Zhang and Vern Paxson"
Proceedings: "Proceedings, 9th USENIX UNIX Security Symposium"
Year: 2000
Month: "Aug"

[ZhangYG02a]
Title: "An Integrated Environment for Testing Mobile Ad-Hoc Networks"
Author: "Yongguang Zhang and Wei Li"
Proceedings: "Proceedings, ACM Conference on Mobile Ad Hoc Networking and Computing"
Year: 2002


Contains 511 items.   Last updated: 07/31/2004. Converted using bib2html.