{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T19:02:51Z","timestamp":1779822171612,"version":"3.53.1"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032017987","type":"print"},{"value":"9783032017994","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,23]],"date-time":"2025-10-23T00:00:00Z","timestamp":1761177600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,23]],"date-time":"2025-10-23T00:00:00Z","timestamp":1761177600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-01799-4_12","type":"book-chapter","created":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T07:47:49Z","timestamp":1761119269000},"page":"204-221","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["LAPIS: Layered Anomaly Detection System for\u00a0IoT Security"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-1065-9642","authenticated-orcid":false,"given":"Cheng","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7640-2821","authenticated-orcid":false,"given":"Yan Lin","family":"Aung","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2105-8047","authenticated-orcid":false,"given":"Ye","family":"Dong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2603-1046","authenticated-orcid":false,"given":"Trupil","family":"Limbasiya","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0594-0432","authenticated-orcid":false,"given":"Jianying","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,23]]},"reference":[{"key":"12_CR1","doi-asserted-by":"crossref","unstructured":"Netscout threat intelligence report 2h 2020. Comput. Fraud Sec. 2021(7), 4\u20134 (2021)","DOI":"10.1016\/S1361-3723(21)00071-3"},{"key":"12_CR2","doi-asserted-by":"publisher","unstructured":"Alalade, E.D.: Intrusion detection system in smart home network using artificial immune system and extreme learning machine hybrid approach. In: 2020 IEEE 6th World Forum on Internet of Things (WF-IoT), pp.\u00a01\u20132 (2020). https:\/\/doi.org\/10.1109\/WF-IoT48130.2020.9221151","DOI":"10.1109\/WF-IoT48130.2020.9221151"},{"key":"12_CR3","doi-asserted-by":"publisher","unstructured":"Anthi, E., Williams, L., Burnap, P.: Pulse: an adaptive intrusion detection for the Internet of Things. In: Living in the Internet of Things: Cybersecurity of the IoT - 2018, pp.\u00a01\u20134 (2018). https:\/\/doi.org\/10.1049\/cp.2018.0035","DOI":"10.1049\/cp.2018.0035"},{"key":"12_CR4","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/978-3-031-22390-7_19","volume-title":"Information Security","author":"YL Aung","year":"2022","unstructured":"Aung, Y.L., Ochoa, M., Zhou, J.: ATLAS: a practical attack detection and live malware analysis system for IoT threat intelligence. In: Susilo, W., Chen, X., Guo, F., Zhang, Y., Intan, R. (eds.) Information Security, pp. 319\u2013338. Springer International Publishing, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22390-7_19"},{"key":"12_CR5","doi-asserted-by":"publisher","unstructured":"Aung, Y.L., Tiang, H.H., Wijaya, H., Ochoa, M., Zhou, J.: Scalable VPN-forwarded honeypots: dataset and threat intelligence insights, ICSS 2020, pp. 21\u201330. Association for Computing Machinery, New York (2020). https:\/\/doi.org\/10.1145\/3442144.3442146","DOI":"10.1145\/3442144.3442146"},{"key":"12_CR6","doi-asserted-by":"publisher","unstructured":"Bekerman, D., Shapira, B., Rokach, L., Bar, A.: Unknown malware detection using network traffic classification. In: 2015 IEEE Conference on Communications and Network Security (CNS), pp. 134\u2013142 (2015). https:\/\/doi.org\/10.1109\/CNS.2015.7346821","DOI":"10.1109\/CNS.2015.7346821"},{"key":"12_CR7","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1016\/j.asoc.2015.07.029","volume":"36","author":"G D\u2019angelo","year":"2015","unstructured":"D\u2019angelo, G., Palmieri, F., Ficco, M., Rampone, S.: An uncertainty-managing batch relevance-based approach to network anomaly detection. Appl. Soft Comput. 36, 408\u2013418 (2015). https:\/\/doi.org\/10.1016\/j.asoc.2015.07.029","journal-title":"Appl. Soft Comput."},{"key":"12_CR8","doi-asserted-by":"publisher","first-page":"761","DOI":"10.1016\/j.future.2017.08.043","volume":"82","author":"AA Diro","year":"2018","unstructured":"Diro, A.A., Chilamkurti, N.: Distributed attack detection scheme using deep learning approach for Internet of Things. Futur. Gener. Comput. Syst. 82, 761\u2013768 (2018). https:\/\/doi.org\/10.1016\/j.future.2017.08.043","journal-title":"Futur. Gener. Comput. Syst."},{"key":"12_CR9","unstructured":"Garcia, S., Parmisano, A., Erquiaga, M.J.: IoT-23 dataset: a labeled dataset of malware and benign IoT traffic (2020). https:\/\/www.stratosphereips.org\/datasets-iot23"},{"issue":"7","key":"12_CR10","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MC.2017.201","volume":"50","author":"C Kolias","year":"2017","unstructured":"Kolias, C., Kambourakis, G., Stavrou, A., Voas, J.: DDoS in the IoT: Mirai and other botnets. Computer 50(7), 80\u201384 (2017). https:\/\/doi.org\/10.1109\/MC.2017.201","journal-title":"Computer"},{"key":"12_CR11","doi-asserted-by":"publisher","unstructured":"Kozik, R., Chora\u015b, M., Ficco, M., Palmieri, F.: A scalable distributed machine learning approach for attack detection in edge computing environments. J. Parallel Distrib. Comput. 119(C), 18\u201326 (2018). https:\/\/doi.org\/10.1016\/j.jpdc.2018.03.006","DOI":"10.1016\/j.jpdc.2018.03.006"},{"key":"12_CR12","doi-asserted-by":"publisher","unstructured":"Kumar, A., Lim, T.J.: EDIMA: early detection of IoT malware network activity using machine learning techniques. In: 2019 IEEE 5th World Forum on Internet of Things (WF-IoT), pp. 289\u2013294 (2019). https:\/\/doi.org\/10.1109\/WF-IoT.2019.8767194","DOI":"10.1109\/WF-IoT.2019.8767194"},{"key":"12_CR13","doi-asserted-by":"publisher","unstructured":"Kumar, M., Singh, A.K.: Distributed intrusion detection system using blockchain and cloud computing infrastructure. In: 2020 4th International Conference on Trends in Electronics and Informatics (ICOEI)(48184), pp. 248\u2013252 (2020). https:\/\/doi.org\/10.1109\/ICOEI48184.2020.9142954","DOI":"10.1109\/ICOEI48184.2020.9142954"},{"key":"12_CR14","doi-asserted-by":"publisher","unstructured":"Kumar, M., Mathur, R.: Unsupervised outlier detection technique for intrusion detection in cloud computing. In: International Conference for Convergence for Technology-2014, pp.\u00a01\u20134 (2014). https:\/\/doi.org\/10.1109\/I2CT.2014.7092027","DOI":"10.1109\/I2CT.2014.7092027"},{"key":"12_CR15","unstructured":"Li, Y., Xiang, Z., Bastian, N.D., Song, D., Li, B.: IDS-Agent: an LLM agent for explainable intrusion detection in IoT networks. In: NeurIPS 2024 Workshop on Open-World Agents (2024). https:\/\/openreview.net\/forum?id=iiK0pRyLkw"},{"issue":"9","key":"12_CR16","doi-asserted-by":"publisher","first-page":"3801","DOI":"10.1109\/TII.2018.2836150","volume":"14","author":"X Liu","year":"2018","unstructured":"Liu, X., Liu, Y., Liu, A., Yang, L.T.: Defending on\u2013off attacks using light probing messages in smart sensors for industrial communication systems. IEEE Trans. Industr. Inf. 14(9), 3801\u20133811 (2018). https:\/\/doi.org\/10.1109\/TII.2018.2836150","journal-title":"IEEE Trans. Industr. Inf."},{"key":"12_CR17","doi-asserted-by":"publisher","unstructured":"Malek, Z.S., Trivedi, B., Shah, A.: User behavior pattern -signature based intrusion detection. In: 2020 Fourth World Conference on Smart Trends in Systems, Security and Sustainability (WorldS4), pp. 549\u2013552 (2020). https:\/\/doi.org\/10.1109\/WorldS450073.2020.9210368","DOI":"10.1109\/WorldS450073.2020.9210368"},{"issue":"3","key":"12_CR18","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","volume":"17","author":"Y Meidan","year":"2018","unstructured":"Meidan, Y., et al.: N-BaIoT\u2013network-based detection of IoT botnet attacks using deep autoencoders. IEEE Pervasive Comput. 17(3), 12\u201322 (2018). https:\/\/doi.org\/10.1109\/MPRV.2018.03367731","journal-title":"IEEE Pervasive Comput."},{"key":"12_CR19","unstructured":"Nawrocki, M., W\u00e4hlisch, M., Schmidt, T.C., Keil, C., Sch\u00f6nfelder, J.: A survey on honeypot software and data analysis (2016)"},{"issue":"2","key":"12_CR20","doi-asserted-by":"publisher","first-page":"314","DOI":"10.1109\/TETC.2016.2633228","volume":"7","author":"HH Pajouh","year":"2019","unstructured":"Pajouh, H.H., Javidan, R., Khayami, R., Dehghantanha, A., Choo, K.K.R.: A two-layer dimension reduction and two-tier classification model for anomaly-based intrusion detection in IoT backbone networks. IEEE Trans. Emerg. Top. Comput. 7(2), 314\u2013323 (2019). https:\/\/doi.org\/10.1109\/TETC.2016.2633228","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"issue":"3","key":"12_CR21","doi-asserted-by":"publisher","first-page":"1389","DOI":"10.1109\/SURV.2012.111412.00158","volume":"15","author":"MR Palattella","year":"2013","unstructured":"Palattella, M.R., et al.: Standardized protocol stack for the Internet of (important) Things. IEEE Commun. Surv. Tutorials 15(3), 1389\u20131406 (2013). https:\/\/doi.org\/10.1109\/SURV.2012.111412.00158","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"12_CR22","doi-asserted-by":"publisher","unstructured":"Saxena, A.K., Sinha, S., Shukla, P.: General study of intrusion detection system and survey of agent based intrusion detection system. In: 2017 International Conference on Computing, Communication and Automation (ICCCA), pp. 421\u2013471 (2017). https:\/\/doi.org\/10.1109\/CCAA.2017.8229866","DOI":"10.1109\/CCAA.2017.8229866"},{"key":"12_CR23","doi-asserted-by":"publisher","unstructured":"Tambe, A., et al.: Detection of threats to IoT devices using scalable VPN-forwarded honeypots. In: Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy, CODASPY 2019, pp. 85\u201396. Association for Computing Machinery, New York (2019). https:\/\/doi.org\/10.1145\/3292006.3300024","DOI":"10.1145\/3292006.3300024"},{"key":"12_CR24","doi-asserted-by":"crossref","unstructured":"Vishwakarma, R., Jain, A.K.: A honeypot with machine learning based detection framework for defending IoT based botnet DDoS attacks. In: 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI), pp. 1019\u20131024. IEEE (2019)","DOI":"10.1109\/ICOEI.2019.8862720"},{"key":"12_CR25","doi-asserted-by":"publisher","unstructured":"Wang, Z., Fok, K.W., Thing, V.L.: Machine learning for encrypted malicious traffic detection: approaches, datasets and comparative study. Comput. Secur. 113(C) (2022). https:\/\/doi.org\/10.1016\/j.cose.2021.102542","DOI":"10.1016\/j.cose.2021.102542"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-01799-4_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T18:23:59Z","timestamp":1779819839000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-01799-4_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,23]]},"ISBN":["9783032017987","9783032017994"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-01799-4_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,23]]},"assertion":[{"value":"23 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Munich","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/acns2025.fordaysec.de\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}