[1]CVE, http://web.nvd.nist.gov/view/vuln/statistics?execution=e2s2
[2]CERT/CC Statistics 1998-2003, http://www.cert.org/stats/
[3]Identity Theft Resource Center | A Nonprofit Organization, http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC_2008_Breach_List.shtml
[4]Symantec Report on the Underground Economy, http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf
[5]O. Dain and R. Cunningham, “Fusing a Heterogeneous Alert Stream into Scenarios,” Proc. of the 2001 ACM Workshop on Data Mining for Security Applications, Nov. 2001.
[6]F. Valeur, G. Vigna, C. Kruegel, and R. A. Kemmerer, “A Comprehensive Approach to Intrusion Detection Alert Correlation,” IEEE Transactions on Dependable and Secure Computing, vol. 1, no. 3, pp. 146–169, 2004.
[7]Daniel Liang “White Paper - Build Your mini-SOC,” http://www.secure-engine.com/download/mini-SOC%20white%20Paper-Traditional%20Chinese.pdf
[8]R. Bidou, “Security Operation Center Concepts &; Implementation,” http://www.iv2-technologies.com/images/Iv2-WP-SOCConcept.pdf, August 1, 2005
[9]C. C. Lin, H. K. Wong, and T. C. Wu. “Enhancing Interoperability of Security Operation Center to Heterogeneous Intrusion Detection Systems”. Security Technology, CCST '05. 39th Annual 2005 International Carnahan Conference, 11-14, Oct. 2005.
[10]Malware, http://en.wikipedia.org/wiki/Malware
[11]Vulnerability, http://en.wikipedia.org/wiki/Vulnerability_(computing)
[12]SANS, http://www.sans.org/top20/
[13]歐士源、黃世昆,“網路攻擊模式簡介”,http://www.ascc.sinica.edu.tw/nl/89/1603/2.txt
[14]denial-of-service attack, http://en.wikipedia.org/wiki/Denial_of_service
[15]SYN flood, http://en.wikipedia.org/wiki/SYN_flood
[16]ping flood, http://en.wikipedia.org/wiki/Ping_flood
[17]ping of death ,http://en.wikipedia.org/wiki/Ping_of_Death
[18]LAND, http://en.wikipedia.org/wiki/LAND_attack
[19]十大 Web 資安漏洞列表, http://www.owasp.org/index.php/Taiwan
[20]The Honeynet Project, http://www.honeynet.org/
[21]IDMEF, http://www.ietf.org/rfc/rfc4765.txt
[22]http://en.wikipedia.org/wiki/Firewall
[23]SANS Institute, Intrusion Detection Systems: Definition, Need and Challenges, 2001.
[24]Snort, http://www.snort.org/
[25]L. T. Heberlein, G. V. Dias, K. N. Levitt, B. Mukherjee, J. Wood and D. Wolber, “A Network Security Monitor,” Research in Security and Privacy, Proceeding of IEEE Computer Society Symposium, pp. 296-304, May 1990.
[26]G. Vigna and R. A. Kemmerer, “NetSTAT: A Network-Based Intrusion Detection Approach,” Proceedings of the 14th Annual Computer Security Conference, pp.25-34, 1998.
[27]LIDS, http://www.lids.org/
[28]tripwire, http://www.tripwire.com/
[29]The Snort Project, Snort Users Manual, http://www.snort.org/assets/82/snort_manual.pdf
[30]Nmap, http://nmap.org/
[31]Nessus, http:// www.nessus.org
[32]Juniper, http://www.juniper.net/us/en/
[33]王智弘、郭力瑋、游柏銓、楊博仁,“入侵防禦之異常偵測與警訊整合機制之研究現況及分析”,資通安全專論,2007。
[34]R. Yusof, S. R. Selamat, S. Sahib, “Intrusion Alert Correlation Technique Analysis for Heterogeneous Log,” IJCSNS International Journal of Computer Science and Network Security, vol. 8, no. 9, September 2008.
[35]P. Ning, D. S. Reeves, Y. Cui, “Correlating Alerts Using Prerequisites of Intrusions,” Technical Report, TR-2001-13, North Carolina State University, Department of Computer Science, 2001.
[36]F. Cuppens. “Managing Alerts in A Multi-Intrusion Detection Environment,” Proceedings of the 17th Annual Computer Security Applications Conference, December 2001.
[37]F. Cuppens, A. Mi&;egrave;ge, “Alert Correlation in a Cooperative Intrusion Detection Framework,” IEEE Symposium on Research in Security and Privacy, 2002.
[38]S. Cheung, U. Lindqvist, M. W. Fong, “Modeling Multistep Cyber Attacks for Scenario Recognition,” DARPA Information Survivability Conference and Exposition (DISCEX III), 2003.
[39]B. Zhu and A. A. Ghorbani, “Alert Correlation for Extracting Attack Strategies,” International Journal of Network Security, vol. 3, no. 3, pp. 244-258, Nov. 2006.
[40]A. Valdes and K. Skinner, “Probabilistic Alert Correlation,” Lecture Notes in Computer Science, LNCS 2212, pp. 53–68, 2001.
[41]L. Wang, A. Liu, S. Jajodia, “Using Attack Graphs for Correlating, Hypothesizing, and Predicting Intrusion Alerts,” Comput. Commun. vol. 29, pp. 2917–2933, 2006.
[42]林崇頤,適應於多量弱點資訊之智慧型攻擊圖形產生器,中原大學資訊工程學系碩士學位論文,2003。[43]MIT Lincoln Lab, 2000 DARPA intrusion detection scenario specific datasets, http://www.ll.mit.edu/mission/communications/ist/corpora/ideval/data/2000data.html, 2009.
[44]The DEFCON Data Set, http://cctf.shmoo.com/data/cctf-defcon8/
[45]Snort Rule Search, http://www.snort.org/pub-bin/sigs-search.cgi