{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,26]],"date-time":"2026-01-26T15:38:21Z","timestamp":1769441901557,"version":"3.49.0"},"publisher-location":"Cham","reference-count":49,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030385569","type":"print"},{"value":"9783030385576","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-38557-6_16","type":"book-chapter","created":{"date-parts":[[2020,3,18]],"date-time":"2020-03-18T14:10:05Z","timestamp":1584540605000},"page":"343-357","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["A Hybrid Deep Generative Local Metric Learning Method for Intrusion Detection"],"prefix":"10.1007","author":[{"given":"Mahdis","family":"Saharkhizan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amin","family":"Azmoodeh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hamed","family":"HaddadPajouh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9294-7554","authenticated-orcid":false,"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Reza M.","family":"Parizi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gautam","family":"Srivastava","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,3,19]]},"reference":[{"key":"16_CR1","first-page":"1","volume-title":"Big Data and Internet of Things Security and Forensics: Challenges and Opportunities","author":"A Azmoodeh","year":"2019","unstructured":"A. Azmoodeh, A. Dehghantanha, K.K.R. Choo, Big Data and Internet of Things Security and Forensics: Challenges and Opportunities (Springer International Publishing, Cham, 2019), pp. 1\u20134"},{"issue":"4","key":"16_CR2","doi-asserted-by":"publisher","first-page":"1141","DOI":"10.1007\/s12652-017-0558-5","volume":"9","author":"A Azmoodeh","year":"2018","unstructured":"A. Azmoodeh, A. Dehghantanha, M. Conti, K.-K.R. Choo, Detecting crypto-ransomware in IoT networks based on energy consumption footprint. J. Ambient Intell. Humaniz. Comput. 9(4), 1141\u20131152 (2018)","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"16_CR3","doi-asserted-by":"publisher","first-page":"865","DOI":"10.3745\/JIPS.03.0126","volume":"15","author":"PN Bahrami","year":"2019","unstructured":"P.N. Bahrami, A. Dehghantanha, T. Dargahi, R.M. Parizi, K.R. Choo, H.H.S. Javadi, Cyber kill chain-based taxonomy of advanced persistent threat actors: analogy of tactics, techniques, and procedures. J. Inf. Process. Syst. 15, 865\u2013889 (2019). \nhttps:\/\/doi.org\/10.3745\/JIPS.03.0126","journal-title":"J. Inf. Process. Syst."},{"key":"16_CR4","unstructured":"P. Baldi, Autoencoders, unsupervised learning, and deep architectures, in Proceedings of ICML Workshop on Unsupervised and Transfer Learning (2012), pp. 37\u201349"},{"key":"16_CR5","doi-asserted-by":"crossref","unstructured":"D.S. Berman, A.L. Buczak, J.S. Chavis, C.L. Corbett, A survey of deep learning methods for cyber security. Information 10(4), 122 (2019)","DOI":"10.3390\/info10040122"},{"issue":"1","key":"16_CR6","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1109\/SURV.2013.052213.00046","volume":"16","author":"MH Bhuyan","year":"2014","unstructured":"M.H. Bhuyan, D.K. Bhattacharyya, J.K. Kalita, Network anomaly detection: methods, systems and tools. IEEE Commun. Surv. Tutorials 16(1), 303\u2013336 (2014). \nhttps:\/\/doi.org\/10.1109\/SURV.2013.052213.00046","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"16_CR7","unstructured":"M. Conti, A. Dehghantanha, K. Franke, S. Watson, Internet of things security and forensics: challenges and opportunities. Futur. Gener. Comput. Syst. 78, 544\u2013546 (2018). \nhttps:\/\/doi.org\/10.1016\/j.future.2017.07.060\n\n. \nhttp:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167739X17316667"},{"key":"16_CR8","doi-asserted-by":"publisher","unstructured":"M. Damshenas, A. Dehghantanha, R. Mahmoud, S. bin Shamsuddin, Forensics investigation challenges in cloud computing environments, in Proceedings Title: 2012 International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec) (2012), pp. 190\u2013194. \nhttps:\/\/doi.org\/10.1109\/CyberSec.2012.6246092","DOI":"10.1109\/CyberSec.2012.6246092"},{"issue":"4","key":"16_CR9","first-page":"10","volume":"2","author":"M Damshenas","year":"2013","unstructured":"M. Damshenas, A. Dehghantanha, R. Mahmoud, A survey on malware propagation, analysis, and detection. Int. J. Cyber-Secur. Digit. Forensics 2(4), 10\u201330 (2013)","journal-title":"Int. J. Cyber-Secur. Digit. Forensics"},{"key":"16_CR10","first-page":"e5173","volume-title":"An opcode-based technique for polymorphic internet of things malware detection, in Concurrency and Computation: Practice and Experience","author":"H Darabian","year":"2019","unstructured":"H. Darabian, A. Dehghantanha, S. Hashemi, S. Homayoun, K.K.R. Choo, An opcode-based technique for polymorphic internet of things malware detection, in Concurrency and Computation: Practice and Experience (Wiley, Hoboken, 2019), p. e5173"},{"key":"16_CR11","doi-asserted-by":"crossref","unstructured":"F. Daryabar, A. Dehghantanha, N.I. Udzir, N.F.b.M. Sani, S. bin Shamsuddin, Towards secure model for SCADA systems, in 2012 International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec) (June 2012), pp. 60\u201364","DOI":"10.1109\/CyberSec.2012.6246111"},{"key":"16_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.sysarc.2019.01.017","volume":"97","author":"EM Dovom","year":"2019","unstructured":"E.M. Dovom, A. Azmoodeh, A. Dehghantanha, D.E. Newton, R.M. Parizi, H. Karimipour, Fuzzy pattern tree for edge malware detection and categorization in IoT. J. Syst. Archit. 97, 1\u20137 (2019)","journal-title":"J. Syst. Archit."},{"key":"16_CR13","doi-asserted-by":"publisher","DOI":"10.1201\/b10867","volume-title":"Data Mining and Machine Learning in Cybersecurity","author":"S Dua","year":"2016","unstructured":"S. Dua, X. Du, Data Mining and Machine Learning in Cybersecurity (Auerbach Publications, Boca Raton, 2016)"},{"key":"16_CR14","doi-asserted-by":"crossref","unstructured":"G. Epiphaniou, T. French, H. Al-Khateeb, A. Dehghantanha, H. Jahankhani, A novel anonymity quantification and preservation model for undernet relay networks, in ed. by H. Jahankhani, A. Carlile, D. Emm, A. Hosseinian-Far, G. Brown, G. Sexton, A. Jamal. Global Security, Safety and Sustainability - The Security Challenges of the Connected World (Springer International Publishing, Cham, 2016), pp. 371\u2013384","DOI":"10.1007\/978-3-319-51064-4_30"},{"key":"16_CR15","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1016\/j.future.2018.06.055","volume":"89","author":"I Ghafir","year":"2018","unstructured":"I. Ghafir, M. Hammoudeh, V. Prenosil, L. Han, R. Hegarty, K. Rabie, F.J. Aparicio-Navarro, Detection of advanced persistent threat using machine-learning correlation analysis. Futur. Gener. Comput. Syst. 89, 349\u2013359 (2018)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"16_CR16","unstructured":"S. Gerris, H. Karimipour, A feature selection-based approach for joint cyber-attack detection and state estimation, in IEEE International Conference on Smart Energy Grid Engineering (SEGE) (2019), pp. 1\u20135"},{"key":"16_CR17","volume-title":"A survey of intrusion detection systems leveraging host data, in CoRR","author":"TR Glass-Vanderlan","year":"2018","unstructured":"T.R. Glass-Vanderlan, M.D. Iannacone, M.S. Vincent, Q. Chen, R.A. Bridges, A survey of intrusion detection systems leveraging host data, in CoRR (2018). \nhttp:\/\/arxiv.org\/abs\/1805.06070"},{"key":"16_CR18","volume-title":"Deep Learning","author":"I Goodfellow","year":"2016","unstructured":"I. Goodfellow, Y. Bengio, A. Courville, Deep Learning (MIT press, Cambridge, 2016)"},{"key":"16_CR19","first-page":"225","volume-title":"Protecting IoT and ICS Platforms Against Advanced Persistent Threat Actors: Analysis of APT1, Silent Chollima and Molerats","author":"S Grooby","year":"2019","unstructured":"S. Grooby, T. Dargahi, A. Dehghantanha, Protecting IoT and ICS Platforms Against Advanced Persistent Threat Actors: Analysis of APT1, Silent Chollima and Molerats (Springer International Publishing, Cham, 2019), pp. 225\u2013255"},{"key":"16_CR20","doi-asserted-by":"publisher","unstructured":"S. Homayoun, A. Dehghantanha, M. Ahmadzadeh, S. Hashemi, R. Khayami, Know abnormal, find evil: Frequent pattern mining for ransomware threat hunting and intelligence. IEEE Trans. Emerg. Top. Comput. 1\u20131 (2017). \nhttps:\/\/doi.org\/10.1109\/TETC.2017.2756908","DOI":"10.1109\/TETC.2017.2756908"},{"key":"16_CR21","first-page":"137","volume-title":"BoTShark: A Deep Learning Approach for Botnet Traffic Detection","author":"S Homayoun","year":"2018","unstructured":"S. Homayoun, M. Ahmadzadeh, S. Hashemi, A. Dehghantanha, R. Khayami, BoTShark: A Deep Learning Approach for Botnet Traffic Detection (Springer International Publishing, Cham, 2018), pp. 137\u2013153"},{"key":"16_CR22","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1016\/j.future.2018.07.045","volume":"90","author":"S Homayoun","year":"2019","unstructured":"S. Homayoun, A. Dehghantanha, M. Ahmadzadeh, S. Hashemi, R. Khayami, K.-K.R. Choo, D.E. Newton, DRTHIS: deep ransomware threat hunting and intelligence system at the fog layer. Futur. Gener. Comput. Syst. 90, 94\u2013104 (2019)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"16_CR23","doi-asserted-by":"publisher","first-page":"2984","DOI":"10.1109\/ACCESS.2017.2786584","volume":"6","author":"H Karimipour","year":"2018","unstructured":"H. Karimipour, V. Dinavahi, Robust massively parallel dynamic state estimation of power systems against cyber-attack. IEEE Access 6, 2984\u20132995 (2018). \nhttps:\/\/doi.org\/10.1109\/ACCESS.2017.2786584","journal-title":"IEEE Access"},{"key":"16_CR24","doi-asserted-by":"publisher","first-page":"80778","DOI":"10.1109\/ACCESS.2019.2920326","volume":"7","author":"H Karimipour","year":"2019","unstructured":"H. Karimipour, A. Dehghantanha, R.M. Parizi, K.R. Choo, H. Leung, A deep and scalable unsupervised machine learning system for cyber-attack detection in large-scale smart grids. IEEE Access 7, 80778\u201380788 (2019)","journal-title":"IEEE Access"},{"key":"16_CR25","first-page":"1","volume-title":"Intelligent Anomaly Detection for Large-Scale Smart Grids","author":"H Karimipour","year":"2019","unstructured":"H. Karimipour, S. Geris, A. Dehghantanha, H. Leung, Intelligent Anomaly Detection for Large-Scale Smart Grids (IEEE, Piscataway, 2019), pp. 1\u20134"},{"key":"16_CR26","doi-asserted-by":"crossref","unstructured":"D. Kong, G. Yan:, Discriminant malware distance learning on structural information for automated malware classification, in Proceedings of the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD \u201913 (ACM (2013), pp. 1357\u20131365. \nhttps:\/\/doi.org\/10.1145\/2487575.2488219","DOI":"10.1145\/2487575.2488219"},{"key":"16_CR27","doi-asserted-by":"crossref","unstructured":"Y. LeCun, Y. Bengio, G. Hinton, Deep learning. Nature 521(7553), 436 (2015)","DOI":"10.1038\/nature14539"},{"key":"16_CR28","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1016\/j.compeleceng.2017.02.013","volume":"61","author":"N Milosevic","year":"2017","unstructured":"N. Milosevic, A. Dehghantanha, K.K.R. Choo, Machine learning aided android malware classification. Comput. Electr. Eng. 61, 266\u2013274 (2017)","journal-title":"Comput. Electr. Eng."},{"key":"16_CR29","doi-asserted-by":"publisher","unstructured":"S. Mohammadi, V. Desai, H. Karimipour, Multivariate Mutual Information-Based Feature Selection for Cyber Intrusion Detection (2018), pp. 1\u20136. \nhttps:\/\/doi.org\/10.1109\/EPEC.2018.8598326","DOI":"10.1109\/EPEC.2018.8598326"},{"key":"16_CR30","unstructured":"S. Mohammadi, H. Mirvaziri, M. Ghazizadeh-Ahsaee, H. Karimipour, Cyber intrusion detection by combined feature selection algorithm. J. Inf. Secur. Appl. 44, 80\u201388 (2019). \nhttps:\/\/doi.org\/10.1016\/j.jisa.2018.11.007\n\n. \nhttp:\/\/www.sciencedirect.com\/science\/article\/pii\/S2214212618304617"},{"issue":"1","key":"16_CR31","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1109\/TPAMI.2017.2666151","volume":"40","author":"Y Noh","year":"2018","unstructured":"Y. Noh, B. Zhang, D.D. Lee, Generative local metric learning for nearest neighbor classification. IEEE Trans. Pattern Anal. Mach. Intell. 40(1), 106\u2013118 (2018). \nhttps:\/\/doi.org\/10.1109\/TPAMI.2017.2666151","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"16_CR32","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1016\/j.jnca.2016.01.001","volume":"67","author":"O Osanaiye","year":"2016","unstructured":"O. Osanaiye, K.K.R. Choo, M. Dlodlo, Distributed denial of service (DDoS) resilience in cloud: review and conceptual cloud ddos mitigation framework. J. Netw. Comput. Appl. 67, 147\u2013165 (2016)","journal-title":"J. Netw. Comput. Appl."},{"key":"16_CR33","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1109\/TETC.2016.2633228","volume":"7","author":"HH Pajouh","year":"2016","unstructured":"H.H. Pajouh, R. Javidan, R. Khayami, D. Ali, K.K.R. Choo, A two-layer dimension reduction and two-tier classification model for anomaly-based intrusion detection in iot backbone networks. IEEE Trans. Emerg. Top. Comput. 7, 314\u2013323 (2016)","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"issue":"1","key":"16_CR34","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/s10844-015-0388-x","volume":"48","author":"HH Pajouh","year":"2017","unstructured":"H.H. Pajouh, G. Dastghaibyfard, S. Hashemi, Two-tier network anomaly detection model: a machine learning approach. J. Intell. Inf. Syst. 48(1), 61\u201374 (2017)","journal-title":"J. Intell. Inf. Syst."},{"key":"16_CR35","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.proeng.2012.01.827","volume":"30","author":"M Panda","year":"2012","unstructured":"M. Panda, A. Abraham, M.R. Patra, A hybrid intelligent approach for network intrusion detection. Proc. Eng. 30, 1\u20139 (2012)","journal-title":"Proc. Eng."},{"key":"16_CR36","unstructured":"J. Sakhnini, H. Karimipour, A. Dehghantanha, Smart grid cyber attacks detection using supervised learning and heuristic feature selection, in IEEE International Conference on Smart Energy Grid Engineering (SEGE) (2019), pp. 1\u20135"},{"key":"16_CR37","doi-asserted-by":"crossref","unstructured":"J. Sakhnini, H. Karimipour, A. Dehghantanha, R. Parizi, G. Srivastava, Security aspects of internet of things aided smart grids: a bibliometric survey. Elsevier J. Internet Things 1\u201313 (2019). \nhttps:\/\/doi.org\/10.1016\/j.iot.2019.100111","DOI":"10.1016\/j.iot.2019.100111"},{"key":"16_CR38","unstructured":"F. Salo, A.B. Nassif, A. Essex, Dimensionality reduction with IG-PCA and ensemble classifier for network intrusion detection. Comput. Netw. 148, 164\u2013175 (2019). \nhttps:\/\/doi.org\/10.1016\/j.comnet.2018.11.010\n\n. \nhttp:\/\/www.sciencedirect.com\/science\/article\/pii\/S1389128618303037"},{"key":"16_CR39","unstructured":"K. Selvakumar, M. Karuppiah, L. SaiRamesh, S.H. Islam, M.M. Hassan, G. Fortino, K.K.R. Choo, Intelligent temporal classification and fuzzy rough set-based feature selection algorithm for intrusion detection system in WSNs. Inf. Sci. 497, 77\u201390 (2019). \nhttps:\/\/doi.org\/10.1016\/j.ins.2019.05.040\n\n. \nhttp:\/\/www.sciencedirect.com\/science\/article\/pii\/S0020025519304438"},{"key":"16_CR40","first-page":"7","volume-title":"Machine Learning Aided Static Malware Analysis: A Survey and Tutorial","author":"A Shalaginov","year":"2018","unstructured":"A. Shalaginov, S. Banin, A. Dehghantanha, K. Franke, Machine Learning Aided Static Malware Analysis: A Survey and Tutorial (Springer International Publishing, Cham, 2018), pp. 7\u201345"},{"issue":"10","key":"16_CR41","doi-asserted-by":"publisher","first-page":"1675","DOI":"10.1109\/TCSVT.2013.2255413","volume":"23","author":"D Tao","year":"2013","unstructured":"D. Tao, L. Jin, Y. Wang, Y. Yuan, X. Li, Person re-identification by regularized smoothing kiss metric learning. IEEE Trans. Circuits Syst. Video Tech. 23(10), 1675\u20131685 (2013)","journal-title":"IEEE Trans. Circuits Syst. Video Tech."},{"key":"16_CR42","first-page":"1","volume-title":"A detailed analysis of the kdd cup 99 data set, in 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications","author":"M Tavallaee","year":"2009","unstructured":"M. Tavallaee, E. Bagheri, W. Lu, A.A. Ghorbani, A detailed analysis of the kdd cup 99 data set, in 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications (IEEE, Piscataway, 2009), pp. 1\u20136"},{"key":"16_CR43","doi-asserted-by":"publisher","first-page":"25399","DOI":"10.1109\/ACCESS.2018.2833746","volume":"6","author":"T Wen","year":"2018","unstructured":"T.Wen, Z. Zhang, Deep convolution neural network and autoencoders-based unsupervised feature learning of eeg signals. IEEE Access 6, 25399\u201325410 (2018)","journal-title":"IEEE Access"},{"key":"16_CR44","doi-asserted-by":"publisher","first-page":"35365","DOI":"10.1109\/ACCESS.2018.2836950","volume":"6","author":"Y Xin","year":"2018","unstructured":"Y. Xin, L. Kong, Z. Liu, Y. Chen, Y. Li, H. Zhu, M. Gao, H. Hou, C. Wang, Machine learning and deep learning methods for cybersecurity. IEEE Access 6, 35365\u201335381 (2018)","journal-title":"IEEE Access"},{"key":"16_CR45","unstructured":"W. Xuren, H. Famei, X. Rongsheng, Modeling intrusion detection system by discovering association rule in rough set theory framework, in 2006 International Conference on Computational Inteligence for Modelling Control and Automation and International Conference on Intelligent Agents Web Technologies and International Commerce (CIMCA\u201906) (2006), pp. 24\u201324"},{"key":"16_CR46","unstructured":"L. Yang, R. Jin, Distance metric learning: a comprehensive survey. Mich. State Univ. 2(2), (2006)"},{"key":"16_CR47","doi-asserted-by":"publisher","unstructured":"M. Yousefi-Azar, V. Varadharajan, L. Hamey, U. Tupakula, Autoencoder-based feature learning for cyber security applications, 2017 International Joint Conference on Neural Networks (IJCNN) (2017), pp. 3854\u20133861. \nhttps:\/\/doi.org\/10.1109\/IJCNN.2017.7966342","DOI":"10.1109\/IJCNN.2017.7966342"},{"key":"16_CR48","unstructured":"J. Zhang, M. Zulkernine, A. Haque, Random-forests-based network intrusion detection systems. IEEE Trans. Syst. Man, Cybern., Part C (Applications and Reviews) 38, 649\u2013659 (2008)"},{"key":"16_CR49","doi-asserted-by":"publisher","unstructured":"F. Zhang, H.A.D.E. Kodituwakku, W. Hines, J.B. Coble, Multi-layer data-driven cyber-attack detection system for industrial control systems based on network, system and process data. IEEE Trans. Indust. Inf., 1\u20131 (2019). \nhttps:\/\/doi.org\/10.1109\/TII.2019.2891261","DOI":"10.1109\/TII.2019.2891261"}],"container-title":["Handbook of Big Data Privacy"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-38557-6_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,3,19]],"date-time":"2020-03-19T00:27:49Z","timestamp":1584577669000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-38557-6_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030385569","9783030385576"],"references-count":49,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-38557-6_16","relation":{},"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"19 March 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}