{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T16:42:08Z","timestamp":1774456928200,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":23,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540437048","type":"print"},{"value":"9783540478874","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2002]]},"DOI":"10.1007\/3-540-47887-6_49","type":"book-chapter","created":{"date-parts":[[2007,5,19]],"date-time":"2007-05-19T15:21:04Z","timestamp":1179588064000},"page":"494-505","source":"Crossref","is-referenced-by-count":7,"title":["User Profiling for Intrusion Detection Using Dynamic and Static Behavioral Models"],"prefix":"10.1007","author":[{"given":"Dit-Yan","family":"Yeung","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuxin","family":"Ding","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2002,4,29]]},"reference":[{"issue":"1","key":"49_CR1","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1214\/aoms\/1177697196","volume":"41","author":"L.E. Baum","year":"1970","unstructured":"L.E. Baum, T. Petrie, G. Soules, and N. Weiss. A maximization technique occurring in the statistical analysis of probabilistic functions of Markov chains. Annals of Mathematical Statistics, 41(1):164\u2013171, 1970.","journal-title":"Annals of Mathematical Statistics"},{"issue":"4","key":"49_CR2","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1049\/ip-vis:19941330","volume":"141","author":"C.M. Bishop","year":"1994","unstructured":"C.M. Bishop. Novelty detection and neural network validation. IEE Proceedings: Vision, Image and Signal Processing, 141(4):217\u2013222, 1994.","journal-title":"IEE Proceedings: Vision, Image and Signal Processing"},{"key":"49_CR3","unstructured":"P.R. Cohen. Empirical Methods for Artificial Intelligence. MIT Press, Cambridge, MA, USA, 1995."},{"issue":"5025","key":"49_CR4","doi-asserted-by":"publisher","first-page":"1289","DOI":"10.1126\/science.1891718","volume":"253","author":"W. J. Daunicht","year":"1991","unstructured":"W. J. Daunicht. Autoassociation and novelty detection by neuromechanics. Science, 253(5025):1289\u20131291, 1991.","journal-title":"Science"},{"key":"49_CR5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1111\/j.2517-6161.1977.tb01600.x","volume":"39","author":"A.P. Dempster","year":"1977","unstructured":"A.P. Dempster, N.M. Laird, and D.B. Rubin. Maximum likelihood from incomplete data via the EM algorithm (with discussion). Journal of the Royal Statistical Society, Series B, 39:1\u201338, 1977.","journal-title":"Journal of the Royal Statistical Society, Series B"},{"issue":"2","key":"49_CR6","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1109\/TSE.1987.232894","volume":"13","author":"D.E. Denning","year":"1987","unstructured":"D.E. Denning. An intrusion-detection model. IEEE Transactions on Software Engineering, 13(2):222\u2013232, 1987.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"49_CR7","doi-asserted-by":"crossref","unstructured":"D. Endler. Intrusion detection: applying machine learning to Solaris audit data. In Proceedings of the Fourteenth Annual Computer Security Applications Conference, pages 268\u2013279, Phoenix, AZ, USA, 7\u201311 December 1998.","DOI":"10.1109\/CSAC.1998.738647"},{"key":"49_CR8","doi-asserted-by":"crossref","unstructured":"S. Forrest, S.A. Hofmeyr, A. Somayaji, and T.A. Longstaff. A sense of self for Unix processes. In Proceedings of the IEEE Symposium on Security and Privacy, pages 120\u2013128, Oakland, CA, USA, 6\u20138 May 1996.","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"49_CR9","doi-asserted-by":"crossref","unstructured":"D. Gunetti and G. Ruffo. Intrusion detection through behavioral data. In Proceedings of the Third International Symposium on Intelligent Data Analysis, pages 383\u2013394, Amsterdam, Netherlands, 9\u201311 August 1999.","DOI":"10.1007\/3-540-48412-4_32"},{"key":"49_CR10","doi-asserted-by":"crossref","unstructured":"G.G. Helmer, J.S.K. Wong, V. Honavar, and L. Miller. Intelligent agents for intrusion detection. In Proceedings of the 1998 IEEE Information Technology Conference \u2014 Information Environment for the Future, pages 121\u2013124, Syracuse, NY, USA, 1\u20133 September 1998.","DOI":"10.1109\/IT.1998.713396"},{"key":"49_CR11","unstructured":"N. Japkowicz, C. Myers, and M. Gluck. A novelty detection approach to classification. In Proceedings of the Fourteenth International Joint Conference on Artificial Intelligence, volume 1, pages 518\u2013523, Montr\u00e9al, Quebec, Canada, 20\u201325 August 1995."},{"issue":"6","key":"49_CR12","doi-asserted-by":"publisher","first-page":"942","DOI":"10.1109\/TIT.1983.1056747","volume":"29","author":"R.W. Johnson","year":"1983","unstructured":"R.W. Johnson and J.E. Shore. Comments on and correction to \u2018axiomatic derivation of the principle of maximum entropy and the principle of minimum cross-entropy\u2019 (Jan 80 26\u201337). IEEE Transactions on Information Theory, 29(6):942\u2013943, 1983.","journal-title":"IEEE Transactions on Information Theory"},{"key":"49_CR13","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1214\/aoms\/1177729694","volume":"22","author":"S. Kullback","year":"1951","unstructured":"S. Kullback and R.A. Leibler. On information and sufficiency. Annals of Mathematical Statistics, 22:79\u201386, 1951.","journal-title":"Annals of Mathematical Statistics"},{"key":"49_CR14","unstructured":"T. Lane. Hidden Markov models for human\/computer interface modeling. In Proceedings of the IJCAI-99 Workshop on Learning about Users, pages 35\u201344, Stockholm, Sweden, 31 July 1999."},{"key":"49_CR15","doi-asserted-by":"crossref","unstructured":"T. Lane and C.E. Brodley. Temporal sequence learning and data reduction for anomaly detection. In Proceedings of the Fifth ACM Conference on Computer and Communications Security, pages 150\u2013158, San Francisco, CA, USA, 2\u20135 November 1998.","DOI":"10.1145\/288090.288122"},{"issue":"3","key":"49_CR16","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1145\/322510.322526","volume":"2","author":"T. Lane","year":"1999","unstructured":"T. Lane and C.E. Brodley. Temporal sequence learning and data reduction for anomaly detection. ACM Transactions on Information and System Security, 2(3):295\u2013331, 1999.","journal-title":"ACM Transactions on Information and System Security"},{"key":"49_CR17","unstructured":"W. Lee and S.J. Stolfo. Data mining approaches for intrusion detection. In Proceedings of the Seventh USENIX Security Symposium, pages 79\u201393, San Antonio, TX, USA, 26\u201329 January 1998."},{"key":"49_CR18","unstructured":"W. Lee, S.J. Stolfo, and K.W. Mok. A data mining framework for building intrusion detection models. In Proceedings of the IEEE Symposium on Security and Privacy, pages 120\u2013132, Oakland, CA, USA, 9\u201312 May 1999."},{"issue":"2","key":"49_CR19","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1109\/5.18626","volume":"77","author":"L.R. Rabiner","year":"1989","unstructured":"L.R. Rabiner. A tutorial on hidden Markov models and selected applications in speech recognition. Proceedings of the IEEE, 77(2):257\u2013286, 1989.","journal-title":"Proceedings of the IEEE"},{"key":"49_CR20","unstructured":"J. Ryan, M.J. Lin, and R. Miikkulainen. Intrusion detection with neural networks. In M.I. Jordan, M.J. Kearns, and S.A. Solla, editors, Advances in Neural Information Processing Systems 10, pages 943\u2013949. MIT Press, 1998."},{"issue":"1\/2","key":"49_CR21","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1016\/S0020-0190(00)00122-8","volume":"76","author":"M. Schonlau","year":"2000","unstructured":"M. Schonlau and M. Theus. Detecting masquerades in intrusion detection based on unpopular commands. Information Processing Letters, 76(1\/2):33\u201338, 2000.","journal-title":"Information Processing Letters"},{"issue":"1","key":"49_CR22","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1109\/TIT.1980.1056144","volume":"26","author":"J.E. Shore","year":"1980","unstructured":"J.E. Shore and R.W. Johnson. Axiomatic derivation of the principle of maximum entropy and the principle of minimum cross-entropy. IEEE Transactions on Information Theory, 26(1):26\u201337, 1980.","journal-title":"IEEE Transactions on Information Theory"},{"key":"49_CR23","doi-asserted-by":"crossref","unstructured":"C. Warrender, S. Forrest, and B. Pearlmutter. Detecting intrusions using system calls: alternative data models. In Proceedings of the IEEE Symposium on Security and Privacy, pages 133\u2013145, Oakland, CA, USA, 9\u201312 May 1999.","DOI":"10.1109\/SECPRI.1999.766910"}],"container-title":["Lecture Notes in Computer Science","Advances in Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/3-540-47887-6_49","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,16]],"date-time":"2025-01-16T13:11:55Z","timestamp":1737033115000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/3-540-47887-6_49"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2002]]},"ISBN":["9783540437048","9783540478874"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/3-540-47887-6_49","relation":{},"ISSN":["0302-9743"],"issn-type":[{"value":"0302-9743","type":"print"}],"subject":[],"published":{"date-parts":[[2002]]}}}