{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T21:41:54Z","timestamp":1743025314609,"version":"3.40.3"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030954048"},{"type":"electronic","value":"9783030954055"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-95405-5_25","type":"book-chapter","created":{"date-parts":[[2022,1,31]],"date-time":"2022-01-31T19:03:13Z","timestamp":1643655793000},"page":"353-367","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Comprehensive Feature Importance Evaluation for DDoS Attacks Detection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4273-9562","authenticated-orcid":false,"given":"Lu","family":"Zhou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4776-4932","authenticated-orcid":false,"given":"Ye","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3545-7863","authenticated-orcid":false,"given":"Yong","family":"Xiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,1,31]]},"reference":[{"key":"25_CR1","unstructured":"Center for Applied Internet Data Analysis (CAIDA). https:\/\/www.caida.org\/data\/passive\/ddos-20070804_dataset.xml. accessed 8 Jun 2021"},{"key":"25_CR2","unstructured":"Information marketplace for policy and analysis of cyber-risk & trust. http:\/\/www.impactcybertrust.org. Accessed 8 Jun 2021"},{"key":"25_CR3","unstructured":"Information security centre of excellence. https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html. Accessed 8 Jun 2021"},{"key":"25_CR4","unstructured":"Netscout\u2019s 14th annual worldwide infrastructure security report. https:\/\/www.netscout.com\/report\/. Accessed 8 Jun 2021"},{"key":"25_CR5","unstructured":"scikit-learn. https:\/\/scikit-learn.org\/stable\/. Accessed 8 Jun 2021"},{"issue":"4","key":"25_CR6","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1109\/72.298224","volume":"5","author":"R Battiti","year":"1994","unstructured":"Battiti, R.: Using mutual information for selecting features in supervised neural net learning. IEEE Trans. Neural Netw. 5(4), 537\u2013550 (1994)","journal-title":"IEEE Trans. Neural Netw."},{"issue":"7","key":"25_CR7","doi-asserted-by":"publisher","first-page":"1145","DOI":"10.1016\/S0031-3203(96)00142-2","volume":"30","author":"AP Bradley","year":"1997","unstructured":"Bradley, A.P.: The use of the area under the ROC curve in the evaluation of machine learning algorithms. Pattern Recognit. 30(7), 1145\u20131159 (1997)","journal-title":"Pattern Recognit."},{"issue":"1","key":"25_CR8","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1023\/A:1010933404324","volume":"45","author":"L Breiman","year":"2001","unstructured":"Breiman, L.: Random forests. Mach. Learn. 45(1), 5\u201332 (2001)","journal-title":"Mach. Learn."},{"key":"25_CR9","doi-asserted-by":"publisher","unstructured":"Chen, X., Wasikowski, M.: FAST: a ROC-based feature selection metric for small samples and imbalanced data classification problems. In: 14th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 124\u2013132. ACM, New York (2008). https:\/\/doi.org\/10.1145\/1401890.1401910","DOI":"10.1145\/1401890.1401910"},{"issue":"1","key":"25_CR10","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1109\/TIT.1967.1053964","volume":"13","author":"T Cover","year":"1967","unstructured":"Cover, T., Hart, P.: Nearest neighbor pattern classification. IEEE Trans. Inf. Theor. 13(1), 21\u201327 (1967)","journal-title":"IEEE Trans. Inf. Theor."},{"key":"25_CR11","doi-asserted-by":"publisher","first-page":"5039","DOI":"10.1109\/ACCESS.2019.2963077","volume":"8","author":"S Dong","year":"2020","unstructured":"Dong, S., Sarem, M.: DDoS attack detection method based on improved KNN with the degree of DDoS attack in software-defined networks. IEEE Access 8, 5039\u20135048 (2020)","journal-title":"IEEE Access"},{"issue":"4","key":"25_CR12","doi-asserted-by":"publisher","first-page":"882","DOI":"10.1109\/TNNLS.2016.2610465","volume":"29","author":"J Hu","year":"2018","unstructured":"Hu, J., Yang, H., Lyu, R., King, I., Man-Cho, A.: Online nonlinear AUC maximization for imbalanced data sets. IEEE Trans. Neural Netw. Learn. Syst 29(4), 882\u2013895 (2018)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst"},{"issue":"10","key":"25_CR13","doi-asserted-by":"publisher","first-page":"9552","DOI":"10.1109\/JIOT.2020.2993782","volume":"7","author":"Y Jia","year":"2020","unstructured":"Jia, Y., Zhong, F., Alrawais, A., Gong, B., Cheng, X.: FlowGuard: an intelligent edge defense mechanism against IoT DDoS attacks. IEEE Internet Things J. 7(10), 9552\u20139562 (2020)","journal-title":"IEEE Internet Things J."},{"key":"25_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-540-89173-4_16","volume-title":"Critical Information Infrastructures Security","author":"G Kambourakis","year":"2008","unstructured":"Kambourakis, G., Moschos, T., Geneiatakis, D., Gritzalis, S.: Detecting DNS amplification attacks. In: Lopez, J., H\u00e4mmerli, B.M. (eds.) CRITIS 2007. LNCS, vol. 5141, pp. 185\u2013196. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-89173-4_16"},{"key":"25_CR15","doi-asserted-by":"publisher","unstructured":"Kleinbaum, D.G., Klein, M.: Logistic Regression. Springer, New York (2002). https:\/\/doi.org\/10.1007\/b97379","DOI":"10.1007\/b97379"},{"issue":"4","key":"25_CR16","doi-asserted-by":"publisher","first-page":"1545","DOI":"10.1109\/TNSM.2018.2861741","volume":"15","author":"P Kumar","year":"2018","unstructured":"Kumar, P., Tripathi, M., Nehra, A., Conti, M., Lal, C.: SAFETY: early detection and mitigation of TCP SYN flood utilizing entropy in SDN. IEEE Trans. Netw. Serv. Manag. 15(4), 1545\u20131559 (2018)","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"issue":"7553","key":"25_CR17","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun, Y., Bengio, Y., Hinton, G.: Deep learning. Nature 521(7553), 436\u2013444 (2015)","journal-title":"Nature"},{"issue":"4","key":"25_CR18","doi-asserted-by":"publisher","first-page":"1098","DOI":"10.1109\/TIFS.2018.2870828","volume":"14","author":"Z Liu","year":"2019","unstructured":"Liu, Z., Cao, Y., Zhu, M., Ge, W.: Umbrella: enabling ISPs to offer readily deployable and privacy-preserving DDoS prevention services. IEEE Trans. Inf. Forensics Secur. 14(4), 1098\u20131108 (2019)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"25_CR19","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-319-23204-1_14","volume-title":"Genetic and Evolutionary Computing","author":"KK Oo","year":"2016","unstructured":"Oo, K.K., Ye, K.Z., Tun, H., Lin, K.Z., Portnov, E.M.: Enhancement of preventing application layer based on DDOS attacks by using hidden semi-Markov model. In: Zin, T.T., Lin, J.C.-W., Pan, J.-S., Tin, P., Yokota, M. (eds.) Genetic and Evolutionary Computing. AISC, vol. 387, pp. 125\u2013135. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-23204-1_14"},{"key":"25_CR20","doi-asserted-by":"publisher","unstructured":"Rasti, R., Murthy, M., Weaver, N., Paxson, V.: Temporal lensing and its application in pulsing denial-of-service attacks. In: 2015 IEEE Symposium on Security and Privacy, San Jose, CA, USA, pp. 187\u2013198 (2015). https:\/\/doi.org\/10.1109\/SP.2015.19","DOI":"10.1109\/SP.2015.19"},{"issue":"3","key":"25_CR21","doi-asserted-by":"publisher","first-page":"660","DOI":"10.1109\/21.97458","volume":"21","author":"S Safavian","year":"1991","unstructured":"Safavian, S., Landgrebe, D.: A survey of decision tree classifier methodology. IEEE Trans. Syst. Man Cybern. Syst. 21(3), 660\u2013674 (1991)","journal-title":"IEEE Trans. Syst. Man Cybern. Syst."},{"issue":"3","key":"25_CR22","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1023\/A:1018628609742","volume":"9","author":"JA Suykens","year":"1999","unstructured":"Suykens, J.A., Vandewalle, J.: Least squares support vector machine classifiers. Neural Process. Lett. 9(3), 293\u2013300 (1999)","journal-title":"Neural Process. Lett."},{"issue":"6","key":"25_CR23","doi-asserted-by":"publisher","first-page":"2843","DOI":"10.1109\/TNET.2018.2874896","volume":"26","author":"A Wang","year":"2018","unstructured":"Wang, A., Chang, W., Chen, S., Mohaisen, A.: Delving into internet DDoS attacks by botnets: characterization and analysis. IEEE\/ACM Trans. Netw. 26(6), 2843\u20132855 (2018)","journal-title":"IEEE\/ACM Trans. Netw."},{"issue":"2","key":"25_CR24","doi-asserted-by":"publisher","first-page":"426","DOI":"10.1109\/TIFS.2011.2107320","volume":"6","author":"Y Xiang","year":"2011","unstructured":"Xiang, Y., Li, K., Zhou, W.: Low-rate DDoS attacks detection and traceback by using new information metrics. IEEE Trans. Inf. Forensics Secur. 6(2), 426\u2013437 (2011)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"3","key":"25_CR25","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1109\/TPDS.2010.97","volume":"22","author":"S Yu","year":"2011","unstructured":"Yu, S., Zhou, W., Doss, R., Jia, W.: Traceback of DDoS attacks using entropy variations. IEEE Trans. Parallel Distrib. Syst. 22(3), 412\u2013425 (2011)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"issue":"7","key":"25_CR26","doi-asserted-by":"publisher","first-page":"1838","DOI":"10.1109\/TIFS.2018.2805600","volume":"13","author":"J Zheng","year":"2018","unstructured":"Zheng, J., Li, Q., Gu, G., Cao, J., Yau, D.K.Y., Wu, J.: Realtime DDoS defense using COTS SDN switches via adaptive correlation analysis. IEEE Trans. Inf. Forensics Secur. 13(7), 1838\u20131853 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"25_CR27","first-page":"14","volume":"2017","author":"L Zhou","year":"2017","unstructured":"Zhou, L., Liao, M., Yuan, C., Zhang, H.: Low-rate DDoS attack detection using expectation of packet size. Secur. Commun. Netw. 2017, 14 (2017)","journal-title":"Secur. Commun. Netw."},{"issue":"10","key":"25_CR28","doi-asserted-by":"publisher","first-page":"1700","DOI":"10.1109\/LCOMM.2019.2931832","volume":"23","author":"L Zhou","year":"2019","unstructured":"Zhou, L., Sood, K., Xiang, Y.: ERM: an accurate approach to detect DDoS attacks using entropy rate measurement. IEEE Commun. Lett. 23(10), 1700\u20131703 (2019)","journal-title":"IEEE Commun. Lett."}],"container-title":["Lecture Notes in Computer Science","Advanced Data Mining and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-95405-5_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,31]],"date-time":"2022-01-31T19:06:51Z","timestamp":1643656011000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-95405-5_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030954048","9783030954055"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-95405-5_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"31 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ADMA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Advanced Data Mining and Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sydney, NSW","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 February 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 February 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"adma2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/adma2021.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"CMT3","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"116","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"22% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}