{"id":"https://openalex.org/W2106560376","doi":"https://doi.org/10.1007/978-3-540-89862-7_17","title":"Incorporation of Application Layer Protocol Syntax into Anomaly Detection","display_name":"Incorporation of Application Layer Protocol Syntax into Anomaly Detection","publication_year":2008,"publication_date":"2008-01-01","ids":{"openalex":"https://openalex.org/W2106560376","doi":"https://doi.org/10.1007/978-3-540-89862-7_17","mag":"2106560376"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-540-89862-7_17","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-540-89862-7_17","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087841637","display_name":"Patrick D\u00fcssel","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Patrick D\u00fcssel","raw_affiliation_strings":["Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011941114","display_name":"Christian Gehl","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Christian Gehl","raw_affiliation_strings":["Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089735573","display_name":"Pavel Laskov","orcid":"https://orcid.org/0000-0002-3212-7167"},"institutions":[{"id":"https://openalex.org/I8087733","display_name":"University of T\u00fcbingen","ror":"https://ror.org/03a1kwz48","country_code":"DE","type":"education","lineage":["https://openalex.org/I8087733"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Pavel Laskov","raw_affiliation_strings":["Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany","Wilhelm-Schickard-Institute for Computer Science, University of T\u00fcbingen, T\u00fcbingen, Germany","Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany and Wilhelm-Schickard-Institute for Computer Science, University of T\u00fcbingen, T\u00fcbingen, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany","institution_ids":[]},{"raw_affiliation_string":"Wilhelm-Schickard-Institute for Computer Science, University of T\u00fcbingen, T\u00fcbingen, Germany","institution_ids":["https://openalex.org/I8087733"]},{"raw_affiliation_string":"Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany and Wilhelm-Schickard-Institute for Computer Science, University of T\u00fcbingen, T\u00fcbingen, Germany","institution_ids":["https://openalex.org/I8087733"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5066077721","display_name":"Konrad Rieck","orcid":"https://orcid.org/0000-0002-5054-8758"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Konrad Rieck","raw_affiliation_strings":["Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute FIRST, Intelligent Data Analysis, Berlin, Germany","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":null,"fwci":5.1672,"has_fulltext":false,"cited_by_count":26,"citation_normalized_percentile":{"value":0.96006298,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"188","last_page":"202"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8492554426193237},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.8071826696395874},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7868410348892212},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.6103502511978149},{"id":"https://openalex.org/keywords/byte","display_name":"Byte","score":0.5833421945571899},{"id":"https://openalex.org/keywords/anomaly-based-intrusion-detection-system","display_name":"Anomaly-based intrusion detection system","score":0.5586997270584106},{"id":"https://openalex.org/keywords/application-layer","display_name":"Application layer","score":0.5348381400108337},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.5234860181808472},{"id":"https://openalex.org/keywords/buffer-overflow","display_name":"Buffer overflow","score":0.45701128244400024},{"id":"https://openalex.org/keywords/ipv4","display_name":"IPv4","score":0.43042391538619995},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.4296988248825073},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.40045902132987976},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.26763880252838135},{"id":"https://openalex.org/keywords/ipv6","display_name":"IPv6","score":0.15660834312438965},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.13550028204917908},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.13162696361541748},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.10775759816169739},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.09773701429367065}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8492554426193237},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.8071826696395874},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7868410348892212},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.6103502511978149},{"id":"https://openalex.org/C43364308","wikidata":"https://www.wikidata.org/wiki/Q8799","display_name":"Byte","level":2,"score":0.5833421945571899},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.5586997270584106},{"id":"https://openalex.org/C190793597","wikidata":"https://www.wikidata.org/wiki/Q189768","display_name":"Application layer","level":3,"score":0.5348381400108337},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.5234860181808472},{"id":"https://openalex.org/C40842320","wikidata":"https://www.wikidata.org/wiki/Q19423","display_name":"Buffer overflow","level":2,"score":0.45701128244400024},{"id":"https://openalex.org/C2779233093","wikidata":"https://www.wikidata.org/wiki/Q11103","display_name":"IPv4","level":4,"score":0.43042391538619995},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.4296988248825073},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.40045902132987976},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.26763880252838135},{"id":"https://openalex.org/C84555802","wikidata":"https://www.wikidata.org/wiki/Q2551624","display_name":"IPv6","level":3,"score":0.15660834312438965},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.13550028204917908},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.13162696361541748},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.10775759816169739},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.09773701429367065},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1007/978-3-540-89862-7_17","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-540-89862-7_17","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.193.9601","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.193.9601","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www-rsec.cs.uni-tuebingen.de/laskov/papers/iciss2008.pdf","raw_type":"text"},{"id":"pmh:oai:fraunhofer.de:N-92362","is_oa":false,"landing_page_url":"http://publica.fraunhofer.de/documents/N-92362.html","pdf_url":null,"source":{"id":"https://openalex.org/S4306400801","display_name":"Publikationsdatenbank der Fraunhofer-Gesellschaft (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Fraunhofer FIRST","raw_type":"Conference Paper"},{"id":"pmh:oai:publica.fraunhofer.de:publica/359800","is_oa":false,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/359800","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W44307044","https://openalex.org/W1482382132","https://openalex.org/W1510073064","https://openalex.org/W1516506771","https://openalex.org/W1560130852","https://openalex.org/W1594536929","https://openalex.org/W1601009504","https://openalex.org/W1674877186","https://openalex.org/W1993426957","https://openalex.org/W2020816856","https://openalex.org/W2085305295","https://openalex.org/W2086437504","https://openalex.org/W2097101478","https://openalex.org/W2103154003","https://openalex.org/W2103378897","https://openalex.org/W2108601876","https://openalex.org/W2108995755","https://openalex.org/W2116065364","https://openalex.org/W2126862902","https://openalex.org/W2134073393","https://openalex.org/W2141950720","https://openalex.org/W2147191819","https://openalex.org/W3136767761","https://openalex.org/W3202272593"],"related_works":["https://openalex.org/W2479612266","https://openalex.org/W2180474751","https://openalex.org/W2047431599","https://openalex.org/W1964132576","https://openalex.org/W1973040075","https://openalex.org/W2379601516","https://openalex.org/W2097742961","https://openalex.org/W4251562766","https://openalex.org/W2741094575","https://openalex.org/W1606232132"],"abstract_inverted_index":null,"counts_by_year":[{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2016,"cited_by_count":3},{"year":2015,"cited_by_count":3},{"year":2013,"cited_by_count":2},{"year":2012,"cited_by_count":4}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
