{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T16:40:06Z","timestamp":1775061606063,"version":"3.50.1"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032054609","type":"print"},{"value":"9783032054616","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,10,5]],"date-time":"2025-10-05T00:00:00Z","timestamp":1759622400000},"content-version":"vor","delay-in-days":277,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The increasing frequency and sophistication of Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, pose significant challenges to modern cybersecurity systems. These threats are further complicated by stealthy variants such as slow DoS attacks, which often evade timely detection. While Deep Learning (DL)-based Intrusion Detection Systems (IDSs) have shown promise in analyzing complex network traffic, their effectiveness is hindered by challenges like limited labeled data, noise, and the presence of Out-of-Distribution (OOD) samples. This paper proposes a hybrid DL-based IDS framework (<jats:italic>ENE4<\/jats:italic>) that integrates unsupervised and supervised components to improve detection performance under label-scarce conditions. The unsupervised module extracts task-independent features from network traffic, while the supervised one learns task-specific representations. These complementary features are fused to enable robust detection even in few-shot learning settings. Additionally, the model incorporates an adaptation mechanism to leverage knowledge from more frequent and related attack types, enhancing generalization to rare patterns. Experimental results on two standard benchmark datasets demonstrate the effectiveness and robustness of the proposed approach in detecting evasive DoS attacks.<\/jats:p>","DOI":"10.1007\/978-3-032-05461-6_23","type":"book-chapter","created":{"date-parts":[[2025,10,4]],"date-time":"2025-10-04T09:08:15Z","timestamp":1759568895000},"page":"347-362","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Learning Fast to\u00a0Detect Slow: A Few-Shot Neural Approach to\u00a0Slow DoS Attack Detection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-5224-0910","authenticated-orcid":false,"given":"Francesco","family":"Scala","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7711-9833","authenticated-orcid":false,"given":"Massimo","family":"Guarascio","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1371-4872","authenticated-orcid":false,"given":"Carlo","family":"Parrotta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4513-0362","authenticated-orcid":false,"given":"Luigi","family":"Pontieri","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,5]]},"reference":[{"issue":"1","key":"23_CR1","doi-asserted-by":"publisher","first-page":"e4150","DOI":"10.1002\/ett.4150","volume":"32","author":"Z Ahmad","year":"2021","unstructured":"Ahmad, Z., et al.: Network intrusion detection system: a systematic study of machine learning and deep learning approaches. Trans. Emerg. Telecommun. Technol. 32(1), e4150 (2021)","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"23_CR2","doi-asserted-by":"publisher","first-page":"706","DOI":"10.1016\/j.ins.2021.05.016","volume":"569","author":"G Andresini","year":"2021","unstructured":"Andresini, G., Appice, A., Malerba, D.: Autoencoder-based deep metric learning for network intrusion detection. Inf. Sci. 569, 706\u2013727 (2021)","journal-title":"Inf. Sci."},{"issue":"3","key":"23_CR3","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1145\/357830.357849","volume":"3","author":"S Axelsson","year":"2000","unstructured":"Axelsson, S.: The base-rate fallacy and the difficulty of intrusion detection. ACM Trans. Inf. Syst. Secur. 3(3), 186\u2013205 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"23_CR4","doi-asserted-by":"publisher","first-page":"108399","DOI":"10.1016\/j.comnet.2021.108399","volume":"199","author":"EM B\u00e5rli","year":"2021","unstructured":"B\u00e5rli, E.M., Yazidi, A., Viedma, E.H., Haugerud, H.: Dos and DDoS mitigation using variational autoencoders. Comput. Netw. 199, 108399 (2021)","journal-title":"Comput. Netw."},{"key":"23_CR5","doi-asserted-by":"publisher","unstructured":"Cassavia, N., Folino, F., Guarascio, M.: Detecting dos and DDoS attacks through sparse U-net-like autoencoders. In: Reformat, M.Z., Zhang, D., Bourbakis, N.G. (eds.) 34th IEEE International Conference on Tools with Artificial Intelligence, ICTAI 2022, Macao, China, 31 October\u20132 November 2022, pp. 1342\u20131346. IEEE (2022). https:\/\/doi.org\/10.1109\/ICTAI56018.2022.00203","DOI":"10.1109\/ICTAI56018.2022.00203"},{"key":"23_CR6","doi-asserted-by":"crossref","unstructured":"Coppolillo, E., et\u00a0al.: Generative methods for out-of-distribution prediction and applications for threat detection and analysis: a short review. In: Digital Sovereignty in Cyber Security: New Challenges in Future Vision (CyberSec4Europe 2022), vol.\u00a01807, pp. 65\u201379 (2022)","DOI":"10.1007\/978-3-031-36096-1_5"},{"key":"23_CR7","unstructured":"ENISA: ENISA threat landscape 2020 - list of top 15 threats (2020). https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-2020-list-of-top-15-threats"},{"key":"23_CR8","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1016\/J.INFFUS.2021.02.007","volume":"72","author":"F Folino","year":"2021","unstructured":"Folino, F., Folino, G., Guarascio, M., Pisani, F.S., Pontieri, L.: On learning effective ensembles of deep neural networks for intrusion detection. Inf. Fusion 72, 48\u201369 (2021). https:\/\/doi.org\/10.1016\/J.INFFUS.2021.02.007","journal-title":"Inf. Fusion"},{"key":"23_CR9","first-page":"634","volume":"1\u20133","author":"M Guarascio","year":"2018","unstructured":"Guarascio, M., Manco, G., Ritacco, E.: Deep learning. Encycl. Bioinform. Comput. Biol.: ABC Bioinform. 1\u20133, 634\u2013647 (2018)","journal-title":"Encycl. Bioinform. Comput. Biol.: ABC Bioinform."},{"key":"23_CR10","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.future.2022.04.028","volume":"135","author":"M Guarascio","year":"2022","unstructured":"Guarascio, M., Cassavia, N., Pisani, F.S., Manco, G.: Boosting cyber-threat intelligence via collaborative intrusion detection. Future Gener. Comput. Syst. 135, 30\u201343 (2022)","journal-title":"Future Gener. Comput. Syst."},{"key":"23_CR11","doi-asserted-by":"publisher","unstructured":"Hosseini, S., Azizi, M.: The hybrid technique for DDoS detection with supervised learning algorithms. Comput. Netw. 158, 35\u201345 (2019). https:\/\/doi.org\/10.1016\/j.comnet.2019.04.027, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S1389128618306881","DOI":"10.1016\/j.comnet.2019.04.027"},{"key":"23_CR12","doi-asserted-by":"publisher","unstructured":"Iliyasu, A.A., et\u00a0al.: A few-shot network intrusion detection method based on mutual information maximization. Sci. Rep. 15, 93185 (2025). https:\/\/doi.org\/10.1038\/s41598-025-93185-0, https:\/\/www.nature.com\/articles\/s41598-025-93185-0","DOI":"10.1038\/s41598-025-93185-0"},{"key":"23_CR13","doi-asserted-by":"publisher","unstructured":"Iliyasu, A.S., Abdurrahman, U.A., Zheng, L.: Few-shot network intrusion detection using discriminative representation learning with supervised autoencoder. Appl. Sci. 12(5) (2022). https:\/\/doi.org\/10.3390\/app12052351, https:\/\/www.mdpi.com\/2076-3417\/12\/5\/2351","DOI":"10.3390\/app12052351"},{"key":"23_CR14","unstructured":"Kingma, D.P., Welling, M.: Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114 (2013)"},{"issue":"15","key":"23_CR15","doi-asserted-by":"publisher","first-page":"9731","DOI":"10.1007\/s00500-021-05893-0","volume":"25","author":"G Kocher","year":"2021","unstructured":"Kocher, G., Kumar, G.: Machine learning and deep learning methods for intrusion detection systems: recent developments and challenges. Soft. Comput. 25(15), 9731\u20139763 (2021)","journal-title":"Soft. Comput."},{"key":"23_CR16","doi-asserted-by":"publisher","unstructured":"Lin, T.Y., Goyal, P., Girshick, R., He, K., Doll\u00e1r, P.: Focal loss for dense object detection. In: 2017 IEEE International Conference on Computer Vision (ICCV), pp. 2999\u20133007 (2017). https:\/\/doi.org\/10.1109\/ICCV.2017.324","DOI":"10.1109\/ICCV.2017.324"},{"key":"23_CR17","doi-asserted-by":"publisher","unstructured":"Mabel, P., Nagappasetty, R.: An intelligent system to detect slow denial of service attacks in software-defined networks. Int. J. Electr. Comput. Eng. (IJECE) 13, 3099 (2023). https:\/\/doi.org\/10.11591\/ijece.v13i3.pp3099-3110","DOI":"10.11591\/ijece.v13i3.pp3099-3110"},{"issue":"1","key":"23_CR18","doi-asserted-by":"publisher","first-page":"686","DOI":"10.1109\/COMST.2018.2847722","volume":"21","author":"P Mishra","year":"2019","unstructured":"Mishra, P., Varadharajan, V., Tupakula, U., Pilli, E.S.: A detailed investigation and analysis of using machine learning techniques for intrusion detection. IEEE Commun. Surv. Tutor. 21(1), 686\u2013728 (2019)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"23_CR19","doi-asserted-by":"publisher","unstructured":"Nugraha, B., Murthy, R.N.: Deep learning-based slow DDoS attack detection in SDN-based networks. In: 2020 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), pp. 51\u201356 (2020). https:\/\/doi.org\/10.1109\/NFV-SDN50289.2020.9289894","DOI":"10.1109\/NFV-SDN50289.2020.9289894"},{"key":"23_CR20","doi-asserted-by":"crossref","unstructured":"Pinheiro\u00a0Cinelli, L., Ara\u00fajo\u00a0Marins, M., Barros\u00a0da Silva, E.A., Lima\u00a0Netto, S.: Variational autoencoder. In: Variational Methods for Machine Learning with Applications to Deep Networks, pp. 111\u2013149 (2021)","DOI":"10.1007\/978-3-030-70679-1_5"},{"key":"23_CR21","doi-asserted-by":"publisher","unstructured":"Rios, V., Inacio, P., Magoni, D., Freire, M.: Detection of slowloris attacks using machine learning algorithms, SAC 2024, pp. 1321\u20131330. Association for Computing Machinery, New York (2024). https:\/\/doi.org\/10.1145\/3605098.3635919","DOI":"10.1145\/3605098.3635919"},{"key":"23_CR22","doi-asserted-by":"publisher","unstructured":"Samarakoon, S., et al.: 5G-NIDD: a comprehensive network intrusion detection dataset generated over 5g wireless network (2022). https:\/\/doi.org\/10.21227\/xtep-hv36","DOI":"10.21227\/xtep-hv36"},{"key":"23_CR23","doi-asserted-by":"publisher","unstructured":"Schwartz, R., Dodge, J., Smith, N.A., Etzioni, O.: Green AI. Commun. ACM 63(12), 54\u201363 (2020). https:\/\/doi.org\/10.1145\/3381831","DOI":"10.1145\/3381831"},{"key":"23_CR24","doi-asserted-by":"publisher","unstructured":"Sharafaldin., I., Habibi Lashkari., A., Ghorbani., A.A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th International Conference on Information Systems Security and Privacy - ICISSP, pp. 108\u2013116. INSTICC, SciTePress (2018). https:\/\/doi.org\/10.5220\/0006639801080116","DOI":"10.5220\/0006639801080116"},{"key":"23_CR25","doi-asserted-by":"publisher","unstructured":"Sun, H., Wan, L., Liu, M., Wang, B.: Few-shot network intrusion detection based on prototypical capsule network with attention mechanism. PLOS ONE 18(4), 1\u201318 (2023). https:\/\/doi.org\/10.1371\/journal.pone.0284632","DOI":"10.1371\/journal.pone.0284632"},{"key":"23_CR26","doi-asserted-by":"crossref","unstructured":"Tang, D., Dai, R., Tang, L., Li, X.: Low-rate dos attack detection based on two-step cluster analysis and UTR analysis. Hum.-Cent. Comput. Inf. Sci. 10, 1\u201320 (2020). https:\/\/hcis-journal.springeropen.com\/articles\/10.1186\/s13673-020-00235-2","DOI":"10.1186\/s13673-020-0210-9"},{"key":"23_CR27","doi-asserted-by":"publisher","unstructured":"Tang, D., Man, J., Tang, L., Feng, Y., Yang, Q.: WEDMS: an advanced mean shift clustering algorithm for LDoS attacks detection. Ad Hoc Netw. 102, 102145 (2020). https:\/\/doi.org\/10.1016\/j.adhoc.2020.102145, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S1570870519302653","DOI":"10.1016\/j.adhoc.2020.102145"},{"key":"23_CR28","doi-asserted-by":"publisher","unstructured":"Tang, D., Zhang, S., Chen, J., Wang, X.: The detection of low-rate DoS attacks using the SADBSCAN algorithm. Inf. Sci. 565, 229\u2013247 (2021). https:\/\/doi.org\/10.1016\/j.ins.2021.02.038, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0020025521001808","DOI":"10.1016\/j.ins.2021.02.038"},{"key":"23_CR29","doi-asserted-by":"publisher","unstructured":"Yu, Y., Bian, N.: An intrusion detection method using few-shot learning. IEEE Access 8, 49730\u201349740 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.2980136","DOI":"10.1109\/ACCESS.2020.2980136"}],"container-title":["Lecture Notes in Computer Science","Discovery Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-05461-6_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,4]],"date-time":"2025-10-04T09:08:19Z","timestamp":1759568899000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-05461-6_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032054609","9783032054616"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-05461-6_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"5 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Discovery Science","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ljubljana","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Slovenia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dis2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ds2025.ijs.si\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}