{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T11:07:41Z","timestamp":1780052861635,"version":"3.54.0"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030438869","type":"print"},{"value":"9783030438876","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-43887-6_13","type":"book-chapter","created":{"date-parts":[[2020,3,27]],"date-time":"2020-03-27T15:03:32Z","timestamp":1585321412000},"page":"159-175","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Are Network Attacks Outliers? A Study of Space Representations and Unsupervised Algorithms"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6081-969X","authenticated-orcid":false,"given":"F\u00e9lix","family":"Iglesias","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4376-9605","authenticated-orcid":false,"given":"Alexander","family":"Hartl","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5391-467X","authenticated-orcid":false,"given":"Tanja","family":"Zseby","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7713-4208","authenticated-orcid":false,"given":"Arthur","family":"Zimek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,3,28]]},"reference":[{"key":"13_CR1","unstructured":"RFC 7011 - Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of Flow Information. Technical report Internet Engineering Task Force (IETF), September 2013. https:\/\/www.ietf.org\/rfc\/rfc7011.txt"},{"key":"13_CR2","doi-asserted-by":"crossref","unstructured":"Anderson, B., McGrew, D.: Machine learning for encrypted malware traffic classification: accounting for noisy labels and non-stationarity. In: Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1723\u20131732 (2017)","DOI":"10.1145\/3097983.3098163"},{"key":"13_CR3","doi-asserted-by":"crossref","unstructured":"Anderson, B., McGrew, D.A.: Identifying encrypted malware traffic with contextual flow data. In: Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, AISec@CCS 2016, Vienna, Austria, 28 October 2016, pp. 35\u201346 (2016)","DOI":"10.1145\/2996758.2996768"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Axelsson, S.: The base-rate fallacy and its implications for the difficulty of intrusion detection. In: Proceedings of the 6th ACM Conference on Computer and Communications Security, CCS 1999, pp. 1\u20137 (1999)","DOI":"10.1145\/319709.319710"},{"issue":"99","key":"13_CR5","first-page":"1","volume":"PP","author":"M Bhuyan","year":"2013","unstructured":"Bhuyan, M., Bhattacharyya, D., Kalita, J.: Network anomaly detection: methods, systems and tools. IEEE Commun. Surv. Tutorials PP(99), 1\u201334 (2013)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"13_CR6","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1016\/j.ins.2016.02.023","volume":"348","author":"M Bhuyan","year":"2016","unstructured":"Bhuyan, M., Bhattacharyya, D., Kalita, J.: A multi-step outlier-based anomaly detection approach to network-wide traffic. Inf. Sci. 348, 243\u2013271 (2016)","journal-title":"Inf. Sci."},{"key":"13_CR7","doi-asserted-by":"crossref","unstructured":"Breunig, M.M., Kriegel, H.P., Ng, R., Sander, J.: LOF: identifying density-based local outliers. In: Proceedings of the ACM International Conference on Management of Data (SIGMOD), Dallas, TX, pp. 93\u2013104 (2000)","DOI":"10.1145\/335191.335388"},{"issue":"2","key":"13_CR8","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2016","unstructured":"Buczak, A.L., Guven, E.: A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutorials 18(2), 1153\u20131176 (2016)","journal-title":"IEEE Commun. Surv. Tutorials"},{"issue":"4","key":"13_CR9","doi-asserted-by":"publisher","first-page":"891","DOI":"10.1007\/s10618-015-0444-8","volume":"30","author":"GO Campos","year":"2016","unstructured":"Campos, G.O., et al.: On the evaluation of unsupervised outlier detection: measures, datasets, and an empirical study. Data Min. Knowl. Disc. 30(4), 891\u2013927 (2016)","journal-title":"Data Min. Knowl. Disc."},{"key":"13_CR10","unstructured":"CN-Group TUWien: network-attack-outlierness (2019). https:\/\/github.com\/CN-TU\/network-attack-outlierness"},{"key":"13_CR11","unstructured":"Durumeric, Z., Bailey, M., Halderman, J.A.: An internet-wide view of internet-wide scanning. In: Proceedings of the 23rd USENIX Conference on Security Symposium, SEC 2014, pp. 65\u201378. USENIX Association, Berkeley (2014)"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"Fachkha, C., Bou-Harb, E., Debbabi, M.: Towards a forecasting model for distributed denial of service activities. In: 2013 IEEE 12th International Symposium on Network Computing and Applications, pp. 110\u2013117, August 2013","DOI":"10.1109\/NCA.2013.13"},{"key":"13_CR13","doi-asserted-by":"publisher","unstructured":"Ferreira, D.C., Bachl, M., Vormayr, G., Iglesias, F., Zseby, T.: Curated research on network traffic analysis, November 2018. https:\/\/doi.org\/10.5281\/zenodo.1243050","DOI":"10.5281\/zenodo.1243050"},{"key":"13_CR14","doi-asserted-by":"crossref","unstructured":"Ferreira, D.C., V\u00e1zquez, F.I., Vormayr, G., Bachl, M., Zseby, T.: A meta-analysis approach for feature selection in network traffic research. In: Proceedings of the Reproducibility Workshop, Reproducibility 2017, pp. 17\u201320. ACM (2017)","DOI":"10.1145\/3097766.3097771"},{"issue":"1","key":"13_CR15","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P Garc\u00eda-Teodoro","year":"2009","unstructured":"Garc\u00eda-Teodoro, P., D\u00edaz-Verdejo, J., Maci\u00e1-Fern\u00e1ndez, G., V\u00e1zquez, E.: Anomaly-based network intrusion detection: techniques, systems and challenges. Comput. Secur. 28(1), 18\u201328 (2009)","journal-title":"Comput. Secur."},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Gharib, A., Sharafaldin, I., Habibi Lashkari, A., Ghorbani, A.: An evaluation framework for intrusion detection dataset. In: International Conference on Information Science and Security (ICISS), pp. 1\u20136, December 2016","DOI":"10.1109\/ICISSEC.2016.7885840"},{"key":"13_CR17","doi-asserted-by":"crossref","unstructured":"Goeschel, K.: Reducing false positives in intrusion detection systems using data-mining techniques utilizing support vector machines, decision trees, and naive bayes for off-line analysis. In: SoutheastCon 2016, pp. 1\u20136 (2016)","DOI":"10.1109\/SECON.2016.7506774"},{"issue":"4","key":"13_CR18","doi-asserted-by":"publisher","first-page":"570","DOI":"10.1093\/comjnl\/bxr026","volume":"54","author":"P Gogoi","year":"2011","unstructured":"Gogoi, P., Bhattacharyya, D.K., Borah, B., Kalita, J.K.: A survey of outlier detection methods in network anomaly identification. Comput. J. 54(4), 570\u2013588 (2011)","journal-title":"Comput. J."},{"key":"13_CR19","unstructured":"Goldstein, M., Dengel, A.: Histogram-based outlier score (HBOS): a fast unsupervised anomaly detection algorithm. In: KI 2012: Advances in artificial intelligence: 35th Annual German Conference on AI, pp. 59\u201363 (2012)"},{"issue":"1","key":"13_CR20","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/BF01908075","volume":"2","author":"L Hubert","year":"1985","unstructured":"Hubert, L., Arabie, P.: Comparing partitions. J. Classif. 2(1), 193\u2013218 (1985)","journal-title":"J. Classif."},{"issue":"99","key":"13_CR21","first-page":"1","volume":"PP","author":"F Iglesias","year":"2017","unstructured":"Iglesias, F., Zseby, T.: Pattern discovery in internet background radiation. IEEE Tran. Big Data PP(99), 1 (2017)","journal-title":"IEEE Tran. Big Data"},{"issue":"P1","key":"13_CR22","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1016\/j.comnet.2016.03.012","volume":"107","author":"F Iglesias","year":"2016","unstructured":"Iglesias, F., Zseby, T.: Time-activity footprints in IP traffic. Comput. Netw. 107(P1), 64\u201375 (2016)","journal-title":"Comput. Netw."},{"key":"13_CR23","doi-asserted-by":"crossref","unstructured":"Iglesias V\u00e1zquez, F., Zseby, T., Zimek, A.: Outlier detection based on low density models. In: 2018 IEEE International Conference on Data Mining Workshops, ICDM Workshops, Singapore, Singapore, 17\u201320 November 2018, pp. 970\u2013979 (2018)","DOI":"10.1109\/ICDMW.2018.00140"},{"issue":"4","key":"13_CR24","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1145\/1090191.1080119","volume":"35","author":"T Karagiannis","year":"2005","unstructured":"Karagiannis, T., Papagiannaki, K., Faloutsos, M.: Blinc: multilevel traffic classification in the dark. SIGCOMM Comput. Commun. Rev. 35(4), 229\u2013240 (2005)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"issue":"3","key":"13_CR25","doi-asserted-by":"publisher","first-page":"1520","DOI":"10.1109\/SURV.2014.022714.00160","volume":"16","author":"R Kaur","year":"2014","unstructured":"Kaur, R., Singh, M.: A survey on zero-day polymorphic worm detection techniques. IEEE Commun. Surv. Tutorials 16(3), 1520\u20131549 (2014)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"13_CR26","doi-asserted-by":"crossref","unstructured":"Lim, Y.S., Kim, H.C., Jeong, J., Kim, C.K., Kwon, T.T., Choi, Y.: Internet traffic classification demystified: on the sources of the discriminative power. In: Proceedings of the 6th International Conference, Co-NEXT 2010, pp. 9:1\u20139:12. ACM, New York (2010)","DOI":"10.1145\/1921168.1921180"},{"issue":"1","key":"13_CR27","doi-asserted-by":"publisher","first-page":"3:1","DOI":"10.1145\/2133360.2133363","volume":"6","author":"FT Liu","year":"2012","unstructured":"Liu, F.T., Ting, K.M., Zhou, Z.H.: Isolation-based anomaly detection. ACM Trans. Knowl. Discovery Data (TKDD) 6(1), 3:1\u20133:39 (2012). https:\/\/doi.org\/10.1145\/2133360.2133363","journal-title":"ACM Trans. Knowl. Discovery Data (TKDD)"},{"issue":"11","key":"13_CR28","doi-asserted-by":"publisher","first-page":"2196","DOI":"10.3390\/app8112196","volume":"8","author":"F Meghdouri","year":"2018","unstructured":"Meghdouri, F., Zseby, T., Iglesias Vazquez, F.: Analysis of lightweight feature vectors for attack detection in network traffic. Appl. Sci. 8(11), 2196 (2018)","journal-title":"Appl. Sci."},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"Moustafa, N., Slay, J.: The evaluation of network anomaly detection systems: statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Inf. Sec. J. Global Perspect. 25(1\u20133), 18\u201331 (2016)","DOI":"10.1080\/19393555.2015.1125974"},{"issue":"4","key":"13_CR30","doi-asserted-by":"publisher","first-page":"228","DOI":"10.1023\/A:1024974810270","volume":"29","author":"MI Petrovskiy","year":"2003","unstructured":"Petrovskiy, M.I.: Outlier detection algorithms in data mining systems. Program. Comput. Softw. 29(4), 228\u2013237 (2003)","journal-title":"Program. Comput. Softw."},{"issue":"1","key":"13_CR31","first-page":"37","volume":"2","author":"DMW Powers","year":"2011","unstructured":"Powers, D.M.W.: Evaluation: from precision, recall and F-measure to ROC, informedness, markedness and correlation. J. Mach. Learn. Technol. 2(1), 37\u201363 (2011)","journal-title":"J. Mach. Learn. Technol."},{"key":"13_CR32","doi-asserted-by":"crossref","unstructured":"Ramaswamy, S., Rastogi, R., Shim, K.: Efficient algorithms for mining outliers from large data sets. In: Proceedings of the ACM International Conference on Management of Data (SIGMOD), Dallas, TX, pp. 427\u2013438 (2000)","DOI":"10.1145\/335191.335437"},{"issue":"1","key":"13_CR33","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/s10618-012-0300-z","volume":"28","author":"E Schubert","year":"2014","unstructured":"Schubert, E., Zimek, A., Kriegel, H.P.: Local outlier detection reconsidered: a generalized view on locality with applications to spatial, video, and network outlier detection. Data Min. Knowl. Disc. 28(1), 190\u2013237 (2014). https:\/\/doi.org\/10.1007\/s10618-012-0300-z","journal-title":"Data Min. Knowl. Disc."},{"key":"13_CR34","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Habibi Lashkari, A., Ghorbani, A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: 4th International Conference on Information Systems Security and Privacy, pp. 108\u2013116, January 2018","DOI":"10.5220\/0006639801080116"},{"key":"13_CR35","doi-asserted-by":"crossref","unstructured":"Vl\u0103dutu, A., Com\u0103neci, D., Dobre, C.: Internet traffic classification based on flows\u2019 statistical properties with machine learning. Int. J. Netw. Manag. 27(3), e1929-n\/a (2017)","DOI":"10.1002\/nem.1929"},{"issue":"5","key":"13_CR36","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1145\/1163593.1163596","volume":"36","author":"N Williams","year":"2006","unstructured":"Williams, N., Zander, S., Armitage, G.: A preliminary performance comparison of five machine learning algorithms for practical ip traffic flow classification. SIGCOMM Comput. Commun. Rev. 36(5), 5\u201316 (2006)","journal-title":"SIGCOMM Comput. Commun. Rev."},{"issue":"4","key":"13_CR37","doi-asserted-by":"publisher","first-page":"1257","DOI":"10.1109\/TNET.2014.2320577","volume":"23","author":"J Zhang","year":"2015","unstructured":"Zhang, J., Chen, X., Xiang, Y., Zhou, W., Wu, J.: Robust network traffic classification. IEEE\/ACM Trans. Networking 23(4), 1257\u20131270 (2015)","journal-title":"IEEE\/ACM Trans. Networking"},{"key":"13_CR38","doi-asserted-by":"crossref","unstructured":"Zhang, J., Zulkernine, M.: Anomaly based network intrusion detection with unsupervised outlier detection. In: 2006 IEEE International Conference on Communications, vol. 5, pp. 2388\u20132393 (2006)","DOI":"10.1109\/ICC.2006.255127"},{"issue":"6","key":"13_CR39","doi-asserted-by":"publisher","first-page":"e1280","DOI":"10.1002\/widm.1280","volume":"8","author":"A Zimek","year":"2018","unstructured":"Zimek, A., Filzmoser, P.: There and back again: outlier detection between statistical reasoning and data mining algorithms. Wiley Interdisc. Rev. Data Min. Knowl. Discov. 8(6), e1280 (2018). https:\/\/doi.org\/10.1002\/widm.1280","journal-title":"Wiley Interdisc. Rev. Data Min. Knowl. Discov."}],"container-title":["Communications in Computer and Information Science","Machine Learning and Knowledge Discovery in Databases"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-43887-6_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,13]],"date-time":"2024-02-13T01:05:23Z","timestamp":1707786323000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-43887-6_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030438869","9783030438876"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-43887-6_13","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"28 March 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"W\u00fcrzburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ecmlpkdd2019.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Microsoft CMT","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"733","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"130","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.04","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5.3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"ECML PKDD Workshops Information: single-blind review, submissions: 200, full papers accepted: 70, short papers accepted: 46","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}