{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T20:22:04Z","timestamp":1743106924934,"version":"3.40.3"},"publisher-location":"New York, NY","reference-count":34,"publisher":"Springer New York","isbn-type":[{"type":"print","value":"9781461461692"},{"type":"electronic","value":"9781461461708"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-1-4614-6170-8_354","type":"book-chapter","created":{"date-parts":[[2014,10,4]],"date-time":"2014-10-04T14:49:26Z","timestamp":1412434166000},"page":"1054-1068","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Network Anomaly Detection Using Co-clustering"],"prefix":"10.1007","author":[{"given":"Evangelos E.","family":"Papalexakis","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alex","family":"Beutel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peter","family":"Steenkiste","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,10,5]]},"reference":[{"key":"354_CR14132","doi-asserted-by":"crossref","first-page":"410","DOI":"10.1007\/978-3-642-13672-6_40","volume-title":"Advances in knowledge discovery and data mining","author":"L Akoglu","year":"2010","unstructured":"Akoglu L, McGlohon M, Faloutsos C (2010) OddBall: spotting anomalies in weighted graphs. In: Zaki MJ et al (eds) Advances in knowledge discovery and data mining. Springer, Berlin, pp 410-421"},{"key":"354_CR14133","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1145\/1376916.1376945","volume-title":"Proceedings of the twenty-seventh ACM SIGMOD- SIGACT-SIGART symposium on principles of database systems","author":"A Anagnostopoulos","year":"2008","unstructured":"Anagnostopoulos A, Dasgupta A, Kumar R (2008) Approximation algorithms for co-clustering. In: Proceedings of the twenty-seventh ACM SIGMOD- SIGACT-SIGART symposium on principles of database systems, Vancouver. ACM, pp 201-210"},{"key":"354_CR14134","first-page":"509","volume-title":"A generalized maximum entropy approach to bregman co-clustering and matrix approximation","author":"A Banerjee","year":"2004","unstructured":"Banerjee A, Dhillon I, Ghosh J, Merugu S, Modha D (2004) A generalized maximum entropy approach to bregman co-clustering and matrix approximation. In: Proceedings of the tenth ACM SIGKDD international conference on knowledge discovery and data mining, Seattle. ACM, pp 509-514"},{"key":"354_CR14135","volume-title":"CopyCatch: stopping group attacks by spotting lockstep behavior in social networks","author":"A Beutel","year":"2013","unstructured":"Beutel A, Xu W, Guruswami V, Palow C, Faloutsos C (2013) CopyCatch: stopping group attacks by spotting lockstep behavior in social networks. In: Proceedings of the 22nd WWW international world wide web conference, Rio de Janeiro"},{"key":"354_CR14136","unstructured":"Bro R, Papalexakis E, Acar E, Sidiropoulos N (2011) SMR co-clustering code on-line. http:\/\/www.models.life.ku.dk\/cocluster . Last accessed 19 Sept 2012"},{"key":"354_CR14137","doi-asserted-by":"crossref","first-page":"256","DOI":"10.1002\/cem.1424","volume":"26","author":"R Bro","year":"2012","unstructured":"Bro R, Papalexakis E, Acar E, Sidiropoulos N (2012) Coclustering \u2013 a useful tool for chemometrics. J Chemom 26:256-263","journal-title":"J Chemom"},{"key":"354_CR14138","volume-title":"Minimum sum-squared residue co-clustering of gene expression data","author":"H Cho","year":"2004","unstructured":"Cho H, Dhillon I, Guan Y, Sra S (2004) Minimum sum-squared residue co-clustering of gene expression data. In: Proceedings of the fourth SIAM international conference on data mining, Orlando, vol 114"},{"key":"354_CR14139","first-page":"269","volume-title":"Co-clustering documents and words using bipartite spectral graph partitioning","author":"I Dhillon","year":"2001","unstructured":"Dhillon I (2001) Co-clustering documents and words using bipartite spectral graph partitioning. In: Proceedings of the seventh ACM SIGKDD international conference on knowledge discovery and data mining, San Francisco. ACM, pp 269-274"},{"key":"354_CR14140","unstructured":"Dhillon I (2007) Bregman co-clustering code on-line. http:\/\/www.lans.ece.utexas.edu\/facility.html . Last accessed 19 Sept 2012"},{"key":"354_CR14141","first-page":"89","volume-title":"Information- theoretic co-clustering","author":"I Dhillon","year":"2003","unstructured":"Dhillon I, Mallela S, Modha D (2003) Information- theoretic co-clustering. In: Proceedings of the ninth ACM SIGKDD international conference on knowledge discovery and data mining, Washington, DC. ACM, pp 89-98"},{"key":"354_CR14142","unstructured":"Elkan C (1999) Results of the KDD\u201999 classifier learning contest. http:\/\/cseweb.ucsd.edu\/~elkan\/clresults.html . Last accessed 19 Sept 2012"},{"key":"354_CR14143","first-page":"139","volume-title":"BotMiner: clustering analysis of network traffic for protocol-and structure-independent botnet detection","author":"G Gu","year":"2008","unstructured":"Gu G, Perdisci R, Zhang J, Lee W (2008) BotMiner: clustering analysis of network traffic for protocol-and structure-independent botnet detection. In: Proceedings of the 17th conference on security symposium, San Jose. USENIX Association, pp 139-154"},{"key":"354_CR14144","unstructured":"Guan Y, Ghorbani A, Belacel N et al (2003) Y-means: a clustering method for intrusion detection. In: Canadian conference on electrical and computer engineering, Montr\u00e9al"},{"key":"354_CR14145","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1080\/01621459.1972.10481214","volume":"67","author":"J Hartigan","year":"1972","unstructured":"Hartigan J (1972) Direct clustering of a data matrix. J Am Stat Assoc 67:123-129","journal-title":"J Am Stat Assoc"},{"key":"354_CR14146","doi-asserted-by":"crossref","first-page":"163","DOI":"10.2172\/1114747","volume-title":"Metric forensics: a multi-level approach for mining volatile graphs","author":"K Henderson","year":"2010","unstructured":"Henderson K, Eliassi-Rad T, Faloutsos C, Akoglu L, Li L, Maruhashi K, Prakash B, Tong H (2010) Metric forensics: a multi-level approach for mining volatile graphs. In: Proceedings of the 16th ACM SIGKDD international conference on knowledge discovery and data mining, Washington, DC. ACM, pp 163-172"},{"issue":"9","key":"354_CR14147","first-page":"181","volume":"9","author":"P Kabiri","year":"2009","unstructured":"Kabiri P, Zargar G (2009) Category-based selection of effective parameters for intrusion detection. Int J Com- put Sci Netw Secur (IJCSNS) 9(9):181-188","journal-title":"Int J Com- put Sci Netw Secur (IJCSNS)"},{"key":"354_CR14148","first-page":"333","volume-title":"Unsupervised anomaly detection in network intrusion detection using clusters","author":"K Leung","year":"2005","unstructured":"Leung K, Leckie C (2005) Unsupervised anomaly detection in network intrusion detection using clusters. In: Proceedings of the twenty-eighth Australasian conference on computer sciencevolume 38, Newcastle. Australian Computer Society, pp 333-342"},{"issue":"2","key":"354_CR14149","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1109\/TIT.1982.1056489","volume":"28","author":"S Lloyd","year":"1982","unstructured":"Lloyd S (1982) Least squares quantization in PCM. IEEE Trans Inf Theory 28(2):129-137","journal-title":"IEEE Trans Inf Theory"},{"issue":"1","key":"354_CR14150","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1109\/TCBB.2004.2","volume":"1","author":"S Madeira","year":"2004","unstructured":"Madeira S, Oliveira A (2004) Biclustering algorithms for biological data analysis: a survey. IEEE\/ACM Trans Comput Biol Bioinform 1(1):24\u201345","journal-title":"IEEE\/ACM Trans Comput Biol Bioinform"},{"key":"354_CR14151","volume-title":"MultiAspect- Forensics: pattern mining on large-scale heterogeneous networks with tensor analysis","author":"K Maruhashi","year":"2011","unstructured":"Maruhashi K, Guo F, Faloutsos C (2011) MultiAspect- Forensics: pattern mining on large-scale heterogeneous networks with tensor analysis. In: Proceedings of the third international conference on advances in social network analysis and mining, Kaohsiung"},{"key":"354_CR14152","doi-asserted-by":"crossref","first-page":"9","DOI":"10.21236\/ADA400003","volume-title":"Inferring internet denial-of-service activity","author":"D Moore","year":"2001","unstructured":"Moore D, Voelker G, Savage S (2001) Inferring internet denial-of-service activity. In: Proceedings of the 10th Usenix security symposium, Washington, DC, pp 9-22"},{"issue":"3","key":"354_CR14153","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/65.283931","volume":"8","author":"B Mukherjee","year":"1994","unstructured":"Mukherjee B, Heberlein L, Levitt K (1994) Network intrusion detection. IEEE Netw 8(3):26-41","journal-title":"IEEE Netw"},{"key":"354_CR14154","unstructured":"New York Times (2009) Twitter restores service after attack. http:\/\/bits.blogs.nytimes.com\/2009\/08\/06\/twitter-overwhelmed-by-web-attack\/ . Last accessed 19 Sept 2012"},{"key":"354_CR14155","first-page":"2064","volume-title":"Co-clustering as multilinear decomposition with sparse latent factors","author":"E Papalexakis","year":"2011","unstructured":"Papalexakis E, Sidiropoulos N (2011) Co-clustering as multilinear decomposition with sparse latent factors. In: IEEE international conference on acoustics, speech and signal processing (ICASSP), Prague, 2011. IEEE, pp 2064-2067"},{"key":"354_CR14156","first-page":"1214","volume-title":"Reviewer profiling using sparse matrix regression","author":"E Papalexakis","year":"2010","unstructured":"Papalexakis E, Sidiropoulos N, Garofalakis M (2010) Reviewer profiling using sparse matrix regression. In: IEEE international conference on data mining workshops (ICDMW), Sydney, 2010. IEEE, pp 1214-1219"},{"issue":"2","key":"354_CR14157","doi-asserted-by":"crossref","first-page":"493","DOI":"10.1109\/TSP.2012.2225052","volume":"61","author":"E Papalexakis","year":"2013","unstructured":"Papalexakis E, Sidiropoulos N, Bro R (2013) From k-means to higher-way co-clustering: multilinear decomposition with sparse latent factors. IEEE Trans Signal Process 61(2):493-506","journal-title":"IEEE Trans Signal Process"},{"issue":"12","key":"354_CR14158","doi-asserted-by":"crossref","first-page":"3448","DOI":"10.1016\/j.comnet.2007.02.001","volume":"51","author":"A Patcha","year":"2007","unstructured":"Patcha A, Park J (2007) An overview of anomaly detection techniques: existing solutions and latest technological trends. Comput Netw 51(12):3448-3470","journal-title":"Comput Netw"},{"issue":"3","key":"354_CR14159","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1007\/s10115-010-0289-9","volume":"26","author":"W Peng","year":"2011","unstructured":"Peng W, Li T (2011) Temporal relation co-clustering on directional social network and author-topic evolution. Knowl Inf Syst 26(3):467-486","journal-title":"Knowl Inf Syst"},{"key":"354_CR14160","doi-asserted-by":"crossref","unstructured":"Pfahringer B (2000) Winning the KDD99 classification cup: bagged boosting. http:\/\/www.sigkdd.org\/explorations\/issues\/1-2-2000-01\/pfahringer.pdf . Last accessed 19 Sept 2012","DOI":"10.1145\/846183.846200"},{"key":"354_CR14161","volume-title":"Intrusion detection with unlabeled data using clustering","author":"L Portnoy","year":"2001","unstructured":"Portnoy L, Eskin E, Stolfo S (2001) Intrusion detection with unlabeled data using clustering. In: Proceedings of ACM CSS workshop on data mining applied to security (DMSA-2001), Philadelphia. Citeseer"},{"key":"354_CR14162","first-page":"1274","volume-title":"Fuzzy clustering for intrusion detection","author":"H Shah","year":"2003","unstructured":"Shah H, Undercoffer J, Joshi A (2003) Fuzzy clustering for intrusion detection. In: The 12th IEEE international conference on fuzzy systems, FUZZ\u201903, St. Louis, 2003, vol 2. IEEE, pp 1274-1278"},{"key":"354_CR14163","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1111\/j.2517-6161.1996.tb02080.x","volume":"58","author":"R Tibshirani","year":"1996","unstructured":"Tibshirani R (1996) Regression shrinkage and selection via the lasso. J R Stat Soc Ser B (Methodological) 58:267-288","journal-title":"J R Stat Soc Ser B (Methodological)"},{"key":"354_CR14164","unstructured":"UCI (1999) KDD 99 cup dataset. http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html . Last accessed 19 Sept 2012"},{"key":"354_CR14165","unstructured":"Wired (2010) Google hack attack was ultra sophisticated, new details show. http:\/\/www.wired.com\/threatlevel\/2010\/01\/operation-aurora\/ . Last accessed 19 Sept 2012"}],"container-title":["Encyclopedia of Social Network Analysis and Mining"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-6170-8_354","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,3]],"date-time":"2024-06-03T12:30:53Z","timestamp":1717417853000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-1-4614-6170-8_354"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9781461461692","9781461461708"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-6170-8_354","relation":{},"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"5 October 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}