[1]. M. Bailey et al. (2005). “The internet motion sensor: A
distributed blackhole monitoring system,” presented at
the NDSS.
[2]. J. Caballero, H. Yin, Z. Liang, and D. Song, (2007).
“Polyglot: automatic extraction of protocol message
format using dynamic binary analysis,” in Proc. ACM CCS,
pp. 317–329.
[3]. W. Cui, V. Paxson, and N. Weaver, (2006). “GQ: Realizing a system to catch worms in a quarter million
places”, ICSI, Tech. Rep. TR-06-004, 2006.
[4]. P. Fogla, and W. Lee, (2006). “Evading network
anomaly detection systems: formal reasoning and
practical techniques,” in Proc. CCS, pp.59-68.
[5]. Y. Gao, Z. Li, and Y. Chen, (2006). “A DoS resilient flowlevel
intrusion detection approach for high-speed
networks,” in Proc. ICDCS, Article No. 39.
[6]. Z. Lin, X. Jiang, D. Xu, and X. Zhang, (2008).
“Automatic protocol format reverse engineering through
concept-aware monitored execution,” presented at the
[7]. J. Newsome, B. Karp, and D. Song, (2005).
“Polygraph: Automatically generating signatures for
polymorphic worms,” in Proc. IEEE S&P, pp. 226-241.
[8]. R. Pang et al. (2006). “BINPAC: A yacc for writing application protocol parsers,” in Proc. ACM/USENIX IMC,
pp. 289-300.
[9]. M. Polychronakis, K.G. Anagnostakis, and E.P.
Markatos, (2007). “Emulation-based detection of nonself-
contained polymorphic shellcode”, in Proc. RAID, pp.
[10]. G. Wondracek, P.M. Comparetti, C. Kruegel, and E.
Kirda, (2008). “Automatic network protocol analysis”,
presented at the NDSS.
[11]. X. Wang et al., (2006). “Sigfree: A signature-free
buffer overflow attack blocker,” in Proc. USENIX Security
Symp., Article No. 16.
[12]. V. Yegneswaran, P. Barford, and D. Plonka, (2004).
“On the design and use of Internet sinks for network abuse
monitoring,” in Proc. RAID, pp. 146-165.