{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T04:12:38Z","timestamp":1750824758531,"version":"3.41.0"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319584232"},{"type":"electronic","value":"9783319584249"}],"license":[{"start":{"date-parts":[[2017,8,13]],"date-time":"2017-08-13T00:00:00Z","timestamp":1502582400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-58424-9_2","type":"book-chapter","created":{"date-parts":[[2017,8,12]],"date-time":"2017-08-12T07:33:44Z","timestamp":1502523224000},"page":"21-39","source":"Crossref","is-referenced-by-count":25,"title":["A Survey and Taxonomy of Classifiers of Intrusion Detection Systems"],"prefix":"10.1007","author":[{"given":"Tarfa","family":"Hamed","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jason B.","family":"Ernst","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan C.","family":"Kremer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,8,13]]},"reference":[{"issue":"5","key":"2_CR1","doi-asserted-by":"crossref","first-page":"469","DOI":"10.3233\/IDA-2003-7506","volume":"7","author":"F Bergadano","year":"2003","unstructured":"Bergadano, F., Gunetti, D., & Picardi, C. (2003). Identity verification through dynamic keystroke analysis. Intelligence Data Analaysis, 7(5), 469\u2013496.","journal-title":"Intelligence Data Analaysis"},{"issue":"1","key":"2_CR2","doi-asserted-by":"crossref","first-page":"33","DOI":"10.3233\/HSN-2006-276","volume":"15","author":"V Bhuse","year":"2006","unstructured":"Bhuse, V., & Gupta, A. (2006). Anomaly intrusion detection in wireless sensor networks. Journal of High Speed Networks, 15(1), 33\u201351.","journal-title":"Journal of High Speed Networks"},{"doi-asserted-by":"publisher","unstructured":"Biggio, B., Fumera, G., & Roli, F. (2010). Multiple classifier systems for robust classifier design in adversarial environments. International Journal of Machine Learning and Cybernetics, 1(1), 27\u201341. doi: 10.1007\/s13042-010-0007-7","key":"2_CR3","DOI":"10.1007\/s13042-010-0007-7"},{"doi-asserted-by":"crossref","unstructured":"Biggio, B., Fumera, G., & Roli, F. (2011). Design of robust classifiers for adversarial environments. In IEEE international conference on systems, man, and cybernetics (SMC) (pp. 977\u2013982). IEEE.","key":"2_CR4","DOI":"10.1109\/ICSMC.2011.6083796"},{"doi-asserted-by":"publisher","unstructured":"Biggio, B., Fumera, G., & Roli, F. (2014). Security evaluation of pattern classifiers under attack. IEEE Transactions on Knowledge and Data Engineering, 26(4), 984\u2013996. doi: 10.1109\/TKDE.2013.57","key":"2_CR5","DOI":"10.1109\/TKDE.2013.57"},{"doi-asserted-by":"publisher","unstructured":"Cho, S. B., & Park, H. J. (2003). Efficient anomaly detection by modeling privilege flows using hidden markov model. Computers & Security, 22(1), 45\u201355. doi: 10.1016\/S0167-4048(03)00112-3","key":"2_CR6","DOI":"10.1016\/S0167-4048(03)00112-3"},{"key":"2_CR7","first-page":"116","volume":"35","author":"AV Dastjerdi","year":"2008","unstructured":"Dastjerdi, A. V., & Bakar, K. A. (2008). A novel hybrid mobile agent based distributed intrusion detection system. Proceedings of World Academy of Science, Engineering and Technology, 35, 116\u2013119.","journal-title":"Proceedings of World Academy of Science, Engineering and Technology"},{"issue":"3","key":"2_CR8","first-page":"686","volume":"2","author":"GM Gandhi","year":"2010","unstructured":"Gandhi, G. M., Appavoo, K., & Srivatsa, S. (2010). Effective network intrusion detection using classifiers decision trees and decision rules. International Journal of Advanced Networking and Applications, 2(3), 686\u2013692.","journal-title":"International Journal of Advanced Networking and Applications"},{"unstructured":"Gong, Y., Mabu, S., Chen, C., Wang, Y., & Hirasawa, K. (2009). Intrusion detection system combining misuse detection and anomaly detection using genetic network programming. In ICCAS-SICE, 2009, (pp. 3463\u20133467).","key":"2_CR9"},{"doi-asserted-by":"publisher","unstructured":"Haidar, G. A., & Boustany, C. (2015). High perception intrusion detection system using neural networks. In 2015 ninth international conference on complex, intelligent, and software intensive systems (pp. 497\u2013501). doi: 10.1109\/CISIS.2015.73","key":"2_CR10","DOI":"10.1109\/CISIS.2015.73"},{"doi-asserted-by":"publisher","unstructured":"Jalil, K. A., Kamarudin, M. H., & Masrek, M. N. (2010) Comparison of machine learning algorithms performance in detecting network intrusion. In 2010 international conference on networking and information technology (pp. 221\u2013226). doi: 10.1109\/ICNIT.2010.5508526","key":"2_CR11","DOI":"10.1109\/ICNIT.2010.5508526"},{"doi-asserted-by":"publisher","unstructured":"Kumar, M., Hanumanthappa, M., & Kumar, T. V. S. (2012). Intrusion detection system using decision tree algorithm. In 2012 IEEE 14th international conference on communication technology (pp. 629\u2013634). doi: 10.1109\/ICCT.2012.6511281","key":"2_CR12","DOI":"10.1109\/ICCT.2012.6511281"},{"key":"2_CR13","doi-asserted-by":"publisher","first-page":"V1\u2013226","DOI":"10.1109\/ICCET.2010.5486194","volume-title":"2010 2nd international conference on computer engineering and technology","author":"F Lan","year":"2010","unstructured":"Lan, F., Chunlei, W., & Guoqing, M. (2010). A framework for network security situation awareness based on knowledge discovery. In 2010 2nd international conference on computer engineering and technology (Vol. 1, pp. V1\u2013226\u2013V1\u2013231). doi: 10.1109\/ICCET.2010.5486194 ."},{"key":"2_CR14","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/1-84628-253-5_10","volume-title":"Machine learning and data mining for computer security","author":"T Lane","year":"2006","unstructured":"Lane, T. (2006). A decision-theoritic, semi-supervised model for intrusion detection. In Machine learning and data mining for computer security (pp. 157\u2013177). London: Springer."},{"key":"2_CR15","first-page":"366","volume-title":"Proceedings of the 20th national information systems security conference","author":"T Lane","year":"1997","unstructured":"Lane, T., & Brodley, C. E. (1997). An application of machine learning to anomaly detection. In Proceedings of the 20th national information systems security conference (Vol. 377, pp. 366\u2013380)."},{"doi-asserted-by":"publisher","unstructured":"Lin, W. C., Ke, S. W., & Tsai, C. F. (2015). Cann: An intrusion detection system based on combining cluster centers and nearest neighbors. Knowledge-Based Systems, 78, 13\u201321. doi: 10.1016\/j.knosys.2015.01.009","key":"2_CR16","DOI":"10.1016\/j.knosys.2015.01.009"},{"doi-asserted-by":"publisher","unstructured":"Lin, Y., Zhang, Y., & Ou, Y-J (2010). The design and implementation of host-based intrusion detection system. In 2010 third international symposium on intelligent information technology and security informatics (pp. 595\u2013598). doi: 10.1109\/IITSI.2010.127","key":"2_CR17","DOI":"10.1109\/IITSI.2010.127"},{"unstructured":"Maiwald, E. (2001). Network security: A beginner\u2019s guide. New York, NY: New York Osborne\/McGraw-Hill. http:\/\/openlibary.org.\/books\/OL3967503M","key":"2_CR18"},{"doi-asserted-by":"publisher","unstructured":"Mantur, B., Desai, A., & Nagegowda, K. S. (2015). Centralized control signature-based firewall and statistical-based network intrusion detection system (NIDS) in software defined networks (SDN) (pp. 497\u2013506). New Delhi: Springer. doi: 10.1007\/978-81-322-2550-8_48","key":"2_CR19","DOI":"10.1007\/978-81-322-2550-8_48"},{"doi-asserted-by":"publisher","unstructured":"Mitchell, R., & Chen, I. R. (2015). Behavior rule specification-based intrusion detection for safety critical medical cyber physical systems. IEEE Transactions on Dependable and Secure Computing, 12(1), 16\u201330. doi: 10.1109\/TDSC.2014.2312327","key":"2_CR20","DOI":"10.1109\/TDSC.2014.2312327"},{"doi-asserted-by":"publisher","unstructured":"Mo, Y., Ma, Y., & Xu, L. (2008). Design and implementation of intrusion detection based on mobile agents. In 2008 IEEE international symposium on IT in medicine and education (pp. 278\u2013281). doi: 10.1109\/ITME.2008.4743870","key":"2_CR21","DOI":"10.1109\/ITME.2008.4743870"},{"key":"2_CR22","first-page":"1702","volume":"2","author":"S Mukkamala","year":"2002","unstructured":"Mukkamala, S., Janoski, G., & Sung, A. (2002). Intrusion detection: Support vector machines and neural networks. IEEE International Joint Conference on Neural Networks (ANNIE), 2, 1702\u20131707.","journal-title":"IEEE International Joint Conference on Neural Networks (ANNIE)"},{"unstructured":"Muntean, C., Dojen, R., & Coffey, T. (2009). Establishing and preventing a new replay attackon a non-repudiation protocol. In IEEE 5th international conference on intelligent computer communication and processing, ICCP 2009 (pp. 283\u2013290). IEEE.","key":"2_CR23"},{"doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., & Song D. (2005). Polygraph: Automatically generating signatures for polymorphic worms. In 2005 IEEE symposium on security and privacy (S&P\u201905) (pp. 226\u2013241). IEEE.","key":"2_CR24","DOI":"10.1109\/SP.2005.15"},{"key":"2_CR25","first-page":"81","volume-title":"Proceedings of the 8th Australian information security management conference","author":"G Pannell","year":"2010","unstructured":"Pannell, G., & Ashman, H. (2010). Anomaly detection over user profiles for intrusion detection. In Proceedings of the 8th Australian information security management conference (pp. 81\u201394). Perth, Western Australia: School of Computer and Information Science, Edith Cowan University."},{"key":"2_CR26","volume-title":"Security in computing","author":"CP Pfleeger","year":"2006","unstructured":"Pfleeger, C. P., & Pfleeger, S. L. (2006). Security in computing (4th ed.). Upper Saddle River, NJ: Prentice Hall PTR.","edition":"4"},{"doi-asserted-by":"crossref","unstructured":"Rieck, K., Schwenk, G., Limmer, T., Holz, T., & Laskov, P. (2010). Botzilla: Detecting the phoning home of malicious software. In Proceedings of the 2010 ACM symposium on applied computing (pp. 1978\u20131984). ACM.","key":"2_CR27","DOI":"10.1145\/1774088.1774506"},{"unstructured":"Di Pietro, R., & Mancini, L. V. (2008). Intrusion detection systems (Vol. 38). New York, NY: Springer Science & Business Media.","key":"2_CR28"},{"doi-asserted-by":"publisher","unstructured":"Sadeghi, Z., & Bahrami, A. S. (2013). Improving the speed of the network intrusion detection. In The 5th conference on information and knowledge technology (pp. 88\u201391). doi: 10.1109\/IKT.2013.6620044","key":"2_CR29","DOI":"10.1109\/IKT.2013.6620044"},{"doi-asserted-by":"publisher","unstructured":"Sarvari, H., & Keikha, M. M. (2010). Improving the accuracy of intrusion detection systems by using the combination of machine learning approaches. In 2010 international conference of soft computing and pattern recognition (pp. 334\u2013337). doi: 10.1109\/SOCPAR.2010.5686163","key":"2_CR30","DOI":"10.1109\/SOCPAR.2010.5686163"},{"issue":"1","key":"2_CR31","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1214\/ss\/998929476","volume":"16","author":"M Schonlau","year":"2001","unstructured":"Schonlau, M., DuMouchel, W., Ju, W. H., Karr, A. F., Theus, M., & Vardi, Y. (2001). Computer intrusion: Detecting masquerades. Statistical Science, 16(1), 58\u201374.","journal-title":"Statistical Science"},{"doi-asserted-by":"publisher","unstructured":"Sekar, R., Gupta, A., Frullo, J., Shanbhag, T., Tiwari, A., Yang, H., & Zhou, S. (2002). Specification-based anomaly detection: A new approach for detecting network intrusions. In Proceedings of the 9th ACM conference on computer and communications security, CCS \u201802 (pp. 265\u2013274). New York, NY: ACM. doi: 10.1145\/586110.586146","key":"2_CR32","DOI":"10.1145\/586110.586146"},{"issue":"1","key":"2_CR33","first-page":"101","volume":"2","author":"R Shanmugavadivu","year":"2011","unstructured":"Shanmugavadivu, R., & Nagarajan, N. (2011). Network intrusion detection system using fuzzy logic. Indian Journal of Computer Science and Engineering (IJCSE), 2(1), 101\u2013111.","journal-title":"Indian Journal of Computer Science and Engineering (IJCSE)"},{"doi-asserted-by":"publisher","unstructured":"Sheng Gan, X., Shun Duanmu, J., Fu Wang, J., & Cong, W. (2013). Anomaly intrusion detection based on {PLS} feature extraction and core vector machine. Knowledge-Based Systems, 40, 1\u20136. doi: 10.1016\/j.knosys.2012.09.004","key":"2_CR34","DOI":"10.1016\/j.knosys.2012.09.004"},{"doi-asserted-by":"publisher","unstructured":"Shon, T., & Moon, J. (2007). A hybrid machine learning approach to network anomaly detection. Information Sciences, 177(18), 3799\u20133821. doi: 10.1016\/j.ins.2007.03.025","key":"2_CR35","DOI":"10.1016\/j.ins.2007.03.025"},{"issue":"5","key":"2_CR36","first-page":"1","volume":"9","author":"S Singh","year":"2009","unstructured":"Singh, S., & Silakari, S. (2009). A survey of cyber attack detection systems. IJCSNS International Journal of Computer Science and Network Security, 9(5), 1\u201310.","journal-title":"IJCSNS International Journal of Computer Science and Network Security"},{"unstructured":"Terry, S., & Chow, B. J. (2005). An assessment of the DARPA IDS evaluation dataset using snort (Technical report, UC Davis Technical Report).","key":"2_CR37"},{"unstructured":"Trinius, P., Willems, C., Rieck, K., & Holz, T. (2009). A malware instruction set for behavior-based analysis (Technical Report TR-2009-07). University of Mannheim.","key":"2_CR38"},{"doi-asserted-by":"crossref","unstructured":"Vasudevan, A., Harshini, E., & Selvakumar, S. (2011). Ssenet-2011: a network intrusion detection system dataset and its comparison with kdd cup 99 dataset. In 2011 second asian himalayas international conference on internet (AH-ICI) (pp. 1\u20135). IEEE.","key":"2_CR39","DOI":"10.1109\/AHICI.2011.6113948"},{"doi-asserted-by":"publisher","unstructured":"Wang, W., Guyet, T., Quiniou, R., Cordier, M. O., Masseglia, F., & Zhang, X. (2014). Autonomic intrusion detection: Adaptively detecting anomalies over unlabeled audit data streams in computer networks. Knowledge-Based Systems, 70, 103\u2013117. doi: 10.1016\/j.knosys.2014.06.018","key":"2_CR40","DOI":"10.1016\/j.knosys.2014.06.018"},{"issue":"12","key":"2_CR41","doi-asserted-by":"crossref","first-page":"3564","DOI":"10.1016\/j.comnet.2007.02.011","volume":"51","author":"Y Wang","year":"2007","unstructured":"Wang, Y., Lin, C., Li, Q. L., & Fang, Y. (2007). A queueing analysis for the denial of service (dos) attacks in computer networks. Computer Networks, 51(12), 3564\u20133573.","journal-title":"Computer Networks"},{"doi-asserted-by":"publisher","unstructured":"Xiaoqing, G., Hebin, G., & Luyi, C. (2010). Network intrusion detection method based on agent and svm. In 2010 2nd IEEE international conference on information management and engineering (pp. 399\u2013402). doi: 10.1109\/ICIME.2010.5477694","key":"2_CR42","DOI":"10.1109\/ICIME.2010.5477694"},{"doi-asserted-by":"publisher","unstructured":"Xu, J., & Wu, S. (2010). Intrusion detection model of mobile agent based on aglets. In 2010 international conference on computer application and system modeling (ICCASM 2010) (Vol. 4, pp. V4-347\u2013V4-350). doi: 10.1109\/ICCASM.2010.5620189","key":"2_CR43","DOI":"10.1109\/ICCASM.2010.5620189"},{"doi-asserted-by":"publisher","unstructured":"Xue-qin, Z., Chun-hua, G., & Jia-jun, L. (2006). Intrusion detection system based on feature selection and support vector machine. In 2006 first international conference on communications and networking in China (pp. 1\u20135). doi: 10.1109\/CHINACOM.2006.344739","key":"2_CR44","DOI":"10.1109\/CHINACOM.2006.344739"},{"doi-asserted-by":"publisher","unstructured":"Yang, W., Wan, W., Guo, L., & Zhang, L. J. (2007). An efficient intrusion detection model based on fast inductive learning. In 2007 international conference on machine learning and cybernetics, (Vol. 6, pp. 3249\u20133254). doi: 10.1109\/ICMLC.2007.4370708","key":"2_CR45","DOI":"10.1109\/ICMLC.2007.4370708"}],"container-title":["Computer and Network Security Essentials"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-58424-9_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,24]],"date-time":"2025-06-24T22:27:06Z","timestamp":1750804026000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-58424-9_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,13]]},"ISBN":["9783319584232","9783319584249"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-58424-9_2","relation":{},"subject":[],"published":{"date-parts":[[2017,8,13]]}}}