{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:19:33Z","timestamp":1778494773979,"version":"3.51.4"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_24","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"409-425","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["ZeekFlow: Deep Learning-Based Network Intrusion Detection a\u00a0Multimodal Approach"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7059-8917","authenticated-orcid":false,"given":"Dimitrios","family":"Giagkos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-0492-8762","authenticated-orcid":false,"given":"Orestis","family":"Kompougias","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7658-2559","authenticated-orcid":false,"given":"Antonis","family":"Litke","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0497-9565","authenticated-orcid":false,"given":"Nikolaos","family":"Papadakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"24_CR1","unstructured":"2022 official cybercrime report. https:\/\/www.esentire.com\/resources\/library\/2022-official-cybercrime-report"},{"key":"24_CR2","unstructured":"Digital 2023: Global overview report. https:\/\/datareportal.com\/reports\/digital-2023-global-overview-report"},{"key":"24_CR3","unstructured":"DoHBrw 2020 | Datasets | Research | Canadian Institute for Cybersecurity | UNB \u2013 unb.ca. https:\/\/www.unb.ca\/cic\/datasets\/dohbrw-2020.html Accessed 15 Jun 2023"},{"key":"24_CR4","unstructured":"IDS 2017 | Datasets | Research | Canadian Institute for Cybersecurity | UNB \u2013 unb.ca. https:\/\/www.unb.ca\/cic\/datasets\/ids-2017.html Accessed 14 Jun 2023"},{"key":"24_CR5","unstructured":"tcpdump(1) man page | TCPDUMP & LIBPCAP \u2013 tcpdump.org. https:\/\/www.tcpdump.org\/manpages\/tcpdump.1.html Accessed 12 Jun 2023"},{"key":"24_CR6","unstructured":"The Zeek Network Security Monitor \u2013 zeek.org. https:\/\/zeek.org\/ Accessed 12 Jun 2023"},{"key":"24_CR7","doi-asserted-by":"publisher","unstructured":"Albin, E., Rowe, N.C.: A realistic experimental comparison of the suricata and snort intrusion-detection systems. In: 2012 26th International Conference on Advanced Information Networking and Applications Workshops, pp. 122\u2013127 (2012). https:\/\/doi.org\/10.1109\/WAINA.2012.29","DOI":"10.1109\/WAINA.2012.29"},{"key":"24_CR8","doi-asserted-by":"publisher","unstructured":"Ali, S., Li, Y.: Learning multilevel auto-encoders for ddos attack detection in smart grid network. IEEE Access PP, 1\u20131 (08 2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2933304","DOI":"10.1109\/ACCESS.2019.2933304"},{"key":"24_CR9","doi-asserted-by":"crossref","unstructured":"Alzubaidi, L., et al.: Review of deep learning: concepts, cnn architectures, challenges, applications, future directions. J. Big Data 8, 1\u201374 (2021)","DOI":"10.1186\/s40537-021-00444-8"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"de Azambuja, A.J.G., Plesker, C., Sch\u00fctzer, K., Anderl, R., Schleich, B., Almeida, V.R.: Artificial intelligence-based cyber security in the context of industry 4.0 &\u2014a survey. Electronics 12(8) (2023). https:\/\/www.mdpi.com\/2079-9292\/12\/8\/1920","DOI":"10.3390\/electronics12081920"},{"key":"24_CR11","doi-asserted-by":"publisher","unstructured":"Bhatia, R., Benno, S., Esteban, J., Lakshman, T., Grogan, J.: Unsupervised machine learning for network-centric anomaly detection in Iot. pp. 42\u201348 (12 2019). https:\/\/doi.org\/10.1145\/3359992.3366641","DOI":"10.1145\/3359992.3366641"},{"key":"24_CR12","doi-asserted-by":"publisher","unstructured":"Mohi-ud din, G.: Nsl-kdd (2018). https:\/\/doi.org\/10.21227\/425a-3e55","DOI":"10.21227\/425a-3e55"},{"key":"24_CR13","doi-asserted-by":"publisher","unstructured":"D\u00edaz-Verdejo, J., Mu\u00f1oz-Calle, J., Estepa Alonso, A., Estepa Alonso, R., Madinabeitia, G.: On the detection capabilities of signature-based intrusion detection systems in the context of web attacks. Applied Sciences 12(2) (2022). https:\/\/doi.org\/10.3390\/app12020852, https:\/\/www.mdpi.com\/2076-3417\/12\/2\/852","DOI":"10.3390\/app12020852"},{"key":"24_CR14","doi-asserted-by":"publisher","unstructured":"Engelen, G., Rimmer, V., Joosen, W.: Troubleshooting an intrusion detection dataset: the cicids2017 case study. In: 2021 IEEE Security and Privacy Workshops (SPW), pp. 7\u201312 (2021). https:\/\/doi.org\/10.1109\/SPW53761.2021.00009","DOI":"10.1109\/SPW53761.2021.00009"},{"key":"24_CR15","doi-asserted-by":"publisher","unstructured":"Gu, Y., Li, K., Guo, Z., Wang, Y.: Semi-supervised k-means ddos detection method using hybrid feature selection algorithm. IEEE Access PP, 1\u20131 (05 2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2917532","DOI":"10.1109\/ACCESS.2019.2917532"},{"key":"24_CR16","doi-asserted-by":"publisher","unstructured":"Ianni, M., Masciari, E.: Scout: Security by computing outliers on activity logs. Computers & Security 132, 103355 (2023). https:\/\/doi.org\/10.1016\/j.cose.2023.103355, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404823002651","DOI":"10.1016\/j.cose.2023.103355"},{"key":"24_CR17","doi-asserted-by":"publisher","unstructured":"Khraisat, A., Gondal, I., Vamplew, P., Kamruzzaman, J.: Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity 2 (12 2019). https:\/\/doi.org\/10.1186\/s42400-019-0038-7","DOI":"10.1186\/s42400-019-0038-7"},{"key":"24_CR18","doi-asserted-by":"publisher","unstructured":"Kim, H., Kim, J., Kim, Y., Kim, I., Kim, K.: Design of network threat detection and classification based on machine learning on cloud computing. Cluster Comput. 22, 2341\u20132350 (2019). https:\/\/doi.org\/10.1007\/s10586-018-1841-8","DOI":"10.1007\/s10586-018-1841-8"},{"key":"24_CR19","doi-asserted-by":"publisher","unstructured":"Kompougias, O., et al.: Iot botnet detection on flow data using autoencoders. In: 2021 IEEE International Mediterranean Conference on Communications and Networking (MeditCom), pp. 506\u2013511 (2021). https:\/\/doi.org\/10.1109\/MeditCom49071.2021.9647639","DOI":"10.1109\/MeditCom49071.2021.9647639"},{"issue":"4","key":"24_CR20","doi-asserted-by":"publisher","first-page":"2762","DOI":"10.1109\/TDSC.2022.3162857","volume":"20","author":"X Li","year":"2023","unstructured":"Li, X., Chen, P., Jing, L., He, Z., Yu, G.: Swisslog: robust anomaly detection and localization for interleaved unstructured logs. IEEE Trans. Depend. Secure Comput. 20(4), 2762\u20132780 (2023). https:\/\/doi.org\/10.1109\/TDSC.2022.3162857","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"24_CR21","unstructured":"Mandiant: Move, patch, get out the way: 2022 zero-day exploitation continues at an elevated pace (Mar 2023). https:\/\/www.mandiant.com\/resources\/blog\/zero-days-exploited-2022"},{"key":"24_CR22","doi-asserted-by":"publisher","unstructured":"Manimurugan, S.: IoT-Fog-Cloud model for anomaly detection using improved Na\u00efve Bayes and principal component analysis. J. Amb. Intell. Human. Comput. 1\u201310 (2021). https:\/\/doi.org\/10.1007\/s12652-020-02723-3","DOI":"10.1007\/s12652-020-02723-3"},{"key":"24_CR23","doi-asserted-by":"publisher","unstructured":"Nguyen, T.T., Shieh, C.S., Chen, C.H., Miu, D.: Detection of unknown ddos attacks with deep learning and gaussian mixture model. In: 2021 4th International Conference on Information and Computer Technologies (ICICT), pp. 27\u201332 (2021). https:\/\/doi.org\/10.1109\/ICICT52872.2021.00012","DOI":"10.1109\/ICICT52872.2021.00012"},{"key":"24_CR24","doi-asserted-by":"publisher","unstructured":"Sarker, I., Kayes, A.S.M., Badsha, S., Alqahtani, H., Watters, P., Ng, A.: Cybersecurity data science: an overview from machine learning perspective. J. Big Data 7 (07 2020). https:\/\/doi.org\/10.1186\/s40537-020-00318-5","DOI":"10.1186\/s40537-020-00318-5"},{"key":"24_CR25","doi-asserted-by":"publisher","unstructured":"Simpson, K., Rogers, S., Pezaros, D.: Per-host ddos mitigation by direct-control reinforcement learning. IEEE Trans. Netw. Serv. Manage. PP 1 (12 2019). https:\/\/doi.org\/10.1109\/TNSM.2019.2960202","DOI":"10.1109\/TNSM.2019.2960202"},{"key":"24_CR26","doi-asserted-by":"publisher","unstructured":"Stolfo, Salvatore, F.W.L.W.P.A., Chan, P.: KDD Cup 1999 Data. UCI Machine Learning Repository (1999). https:\/\/doi.org\/10.24432\/C51C7N","DOI":"10.24432\/C51C7N"},{"key":"24_CR27","doi-asserted-by":"publisher","unstructured":"Vanerio, J., Casas, P.: Ensemble-learning approaches for network security and anomaly detection, pp. 1\u20136 (08 2017). https:\/\/doi.org\/10.1145\/3098593.3098594","DOI":"10.1145\/3098593.3098594"},{"key":"24_CR28","doi-asserted-by":"publisher","unstructured":"Waagsnes, H., Ulltveit-Moe, N.: Intrusion detection system test framework for scada systems, pp. 275\u2013285 (2018). https:\/\/doi.org\/10.5220\/0006588202750285","DOI":"10.5220\/0006588202750285"},{"key":"24_CR29","doi-asserted-by":"publisher","unstructured":"Wang, W., Zhu, M., Zeng, X., Ye, X., Sheng, Y.: Malware traffic classification using convolutional neural network for representation learning. In: 2017 International Conference on Information Networking (ICOIN), pp. 712\u2013717 (2017). https:\/\/doi.org\/10.1109\/ICOIN.2017.7899588","DOI":"10.1109\/ICOIN.2017.7899588"},{"key":"24_CR30","unstructured":"Wikipedia contributors: Netflow \u2013 Wikipedia, the free encyclopedia (2023). https:\/\/en.wikipedia.org\/w\/index.php?title=NetFlow &oldid=1153303931 Accessed 15 June 2023"},{"key":"24_CR31","doi-asserted-by":"publisher","first-page":"108346","DOI":"10.1109\/ACCESS.2020.3001350","volume":"8","author":"S Zavrak","year":"2020","unstructured":"Zavrak, S., \u0130skefiyeli, M.: Anomaly-based intrusion detection from network flow features using variational autoencoder. IEEE Access 8, 108346\u2013108358 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.3001350","journal-title":"IEEE Access"},{"issue":"1","key":"24_CR32","doi-asserted-by":"publisher","first-page":"570","DOI":"10.1109\/TII.2022.3170149","volume":"19","author":"X Zhou","year":"2023","unstructured":"Zhou, X., Hu, Y., Wu, J., Liang, W., Ma, J., Jin, Q.: Distribution bias aware collaborative generative adversarial network for imbalanced deep learning in industrial iot. IEEE Trans. Industr. Inf. 19(1), 570\u2013580 (2023). https:\/\/doi.org\/10.1109\/TII.2022.3170149","journal-title":"IEEE Trans. Industr. Inf."}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:06:35Z","timestamp":1710194795000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}