{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T15:54:16Z","timestamp":1773762856220,"version":"3.50.1"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319584232","type":"print"},{"value":"9783319584249","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,8,13]],"date-time":"2017-08-13T00:00:00Z","timestamp":1502582400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-58424-9_32","type":"book-chapter","created":{"date-parts":[[2017,8,12]],"date-time":"2017-08-12T07:33:44Z","timestamp":1502523224000},"page":"555-568","source":"Crossref","is-referenced-by-count":2,"title":["A Survey and Comparison of Performance Evaluation in Intrusion Detection Systems"],"prefix":"10.1007","author":[{"given":"Jason","family":"Ernst","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tarfa","family":"Hamed","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Kremer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,8,13]]},"reference":[{"key":"32_CR1","unstructured":"Cup, K. (1999). Dataset. Available at the following website http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html"},{"key":"32_CR2","doi-asserted-by":"crossref","unstructured":"Sharma, V., & Nema, A. (2013). Innovative genetic approach for intrusion detection by using decision tree. In 2013 international conference on communication systems and network technologies (pp. 418\u2013422).","DOI":"10.1109\/CSNT.2013.93"},{"issue":"4","key":"32_CR3","doi-asserted-by":"crossref","first-page":"579","DOI":"10.1016\/S1389-1286(00)00139-0","volume":"34","author":"R Lippmann","year":"2000","unstructured":"Lippmann, R., Haines, J. W., Fried, D. J., Korba, J., & Das, K. (2000). The 1999 DARPA off-line intrusion detection evaluation. Computer Networks, 34(4), 579\u2013595.","journal-title":"Computer Networks"},{"key":"32_CR4","unstructured":"J. G. Elevate Communications (2016). Terabit-scale multi-vector DDoS attacks to become the new normal in 2017, Predict DDoS Experts, Business Wire."},{"key":"32_CR5","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garc\u00eda","year":"2014","unstructured":"Garc\u00eda, S., Grill, M., Stiborek, J., & Zunino, A. (2014). An empirical comparison of botnet detection methods. Computers & Security, 45, 100\u2013123.","journal-title":"Computers & Security"},{"key":"32_CR6","unstructured":"Ma\u0142owidzki, M., Berezinski, P., & Mazur, M. (2015). Network intrusion detection: half a kingdom for a good dataset. In Proceedings of NATO STO SAS-139 Workshop. Portugal."},{"key":"32_CR7","unstructured":"Scully, P. (2016). Where can I get the latest dataset for a network intrusion detection system?. Quora [Online]. Available: https:\/\/www.quora.com\/Where-can-I-get-the-latest-dataset-for-a-network-intrusion-detection-system . Accessed January 12, 2017."},{"key":"32_CR8","unstructured":"ubershmekel (2012). Precision, recall, sensitivity and specificity. Ubershmekel\u2019s Uberpython Pythonlog [Online]. Available: https:\/\/uberpython.wordpress.com\/2012\/01\/01\/precision-recall-sensitivity-and-specificity\/ . Accessed February 09, 2017 ."},{"issue":"7","key":"32_CR9","doi-asserted-by":"crossref","first-page":"1041","DOI":"10.3844\/jcssp.2012.1041.1048","volume":"8","author":"P Natesan","year":"2012","unstructured":"Natesan, P., Balasubramanie, P., & Gowrison, G. (2012). Improving the attack detection rate in network intrusion detection using adaboost algorithm. Journal of Computer Science, 8(7), 1041\u20131048.","journal-title":"Journal of Computer Science"},{"key":"32_CR10","doi-asserted-by":"crossref","unstructured":"Mo, Y., Ma, Y., & Xu, L. (2008). Design and implementation of intrusion detection based on mobile agents. In 2008 IEEE international symposium on IT in medicine and education (pp. 278\u2013281).","DOI":"10.1109\/ITME.2008.4743870"},{"key":"32_CR11","doi-asserted-by":"crossref","unstructured":"Uppuluri, P., & Sekar, R. (2001). Experiences with specification-based intrusion detection. In Recent advances in intrusion detection (pp. 172\u2013189).","DOI":"10.1007\/3-540-45474-8_11"},{"key":"32_CR12","doi-asserted-by":"crossref","unstructured":"Sekar, R. et al. (2002). Specification-based anomaly detection: A new approach for detecting network intrusions. In Proceedings of the 9th ACM conference on computer and communications security (pp. 265\u2013274). Washington, DC, USA.","DOI":"10.1145\/586110.586146"},{"issue":"18","key":"32_CR13","doi-asserted-by":"crossref","first-page":"3799","DOI":"10.1016\/j.ins.2007.03.025","volume":"177","author":"T Shon","year":"2007","unstructured":"Shon, T., & Moon, J. (2007). A hybrid machine learning approach to network anomaly detection. Information Science, 177(18), 3799\u20133821.","journal-title":"Information Science"},{"key":"32_CR14","unstructured":"MeeraGandhi, G., Appavoo, K., & Srivasta, S. (2010). Effective network intrusion detection using classifiers decision trees and decision rules. International Journal Advanced network and Application, 2(3), 686\u2013692."},{"key":"32_CR15","unstructured":"Trinius, P., Willems, C., Holz, T., & Rieck, K. (2009). A malware instruction set for behavior-based analysis. Tech. Rep. TR-2009-07, University of Mannheim."},{"key":"32_CR16","unstructured":"Xu, J., & Wu, S. (2010). Intrusion detection model of mobile agent based on Aglets. In 2010 international conference on computer application and system modeling (ICCASM 2010) (Vol. 4, pp. V4-347\u2013V4-350)."},{"key":"32_CR17","unstructured":"Gong, Y., Mabu, S., Chen, C., Wang, Y., & Hirasawa, K. (2009). Intrusion detection system combining misuse detection and anomaly detection using Genetic Network Programming. ICCAS-SICE, 2009."},{"key":"32_CR18","doi-asserted-by":"crossref","unstructured":"Yang, W., Wan, W., Guo, L., & Zhang L. J. (2007). An efficient intrusion detection model based on fast inductive learning. In 2007 international conference on machine learning and cybernetics (Vol. 6, pp. 3249\u20133254).","DOI":"10.1109\/ICMLC.2007.4370708"},{"key":"32_CR19","unstructured":"Lan, F., Chunlei, W., & Guoqing, M. (2010). A framework for network security situation awareness based on knowledge discovery. In 2nd international conference on computer engineering and technology (Vol. 1, pp. V1-226\u2013V1-231)."},{"key":"32_CR20","doi-asserted-by":"crossref","unstructured":"Jaiganesh, V., Sumathi, P., & Mangayarkarasi, S. (2013). An analysis of intrusion detection system using back propagation neural network. In 2013 international conference on information communication and embedded systems (ICICES) (pp. 232\u2013236).","DOI":"10.1109\/ICICES.2013.6508202"},{"issue":"1","key":"32_CR21","first-page":"101","volume":"2","author":"R Shanmugavadivu","year":"2011","unstructured":"Shanmugavadivu, R., & Nagarajan, N. (2011). Network intrusion detection system using fuzzy logic. Indian Journal of Computer Science and Engineering (IJCSE), 2(1), 101\u2013111.","journal-title":"Indian Journal of Computer Science and Engineering (IJCSE)"},{"key":"32_CR22","doi-asserted-by":"crossref","unstructured":"Sen, J. (2010). Efficient routing anomaly detection in wireless mesh networks. In 2010 first international conference on integrated intelligent computing (pp. 302\u2013307).","DOI":"10.1109\/ICIIC.2010.22"},{"key":"32_CR23","doi-asserted-by":"crossref","unstructured":"Aggarwal, P., & Sharma, S. K. (2015). An empirical comparison of classifiers to analyze intrusion detection. In 2015 fifth international conference on advanced computing communication technologies (pp. 446\u2013450).","DOI":"10.1109\/ACCT.2015.59"},{"key":"32_CR24","doi-asserted-by":"crossref","unstructured":"Vyas, T., Prajapati, P., & Gadhwal, S. (2015). A survey and evaluation of supervised machine learning techniques for spam e-mail filtering. In 2015 IEEE international conference on electrical, computer and communication technologies (ICECCT) (pp. 1\u20137).","DOI":"10.1109\/ICECCT.2015.7226077"},{"key":"32_CR25","doi-asserted-by":"crossref","unstructured":"Rieck, K., Schwenk, G., Limmer, T., Holz, T., & Laskov, P. (2010). Botzilla: Detecting the phoning home of malicious software. In Proceedings of the 2010 ACM symposium on applied computing (pp. 1978\u20131984).","DOI":"10.1145\/1774088.1774506"},{"key":"32_CR26","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/1-84628-253-5_10","volume-title":"Machine learning and data mining for computer security","author":"T Lane","year":"2006","unstructured":"Lane, T. (2006). A decision-theoretic, semi-supervised model for intrusion detection. In M. A. Maloof (Ed.), Machine learning and data mining for computer security (pp. 157\u2013177). London: Springer."},{"key":"32_CR27","doi-asserted-by":"crossref","unstructured":"Warrender, C., Forrest, S., & Pearlmutter, B. (1999). Detecting intrusions using system calls: alternative data models. In Proceedings of the 1999 IEEE symposium on security and privacy (Cat. No.99CB36344) (pp. 133\u2013145).","DOI":"10.1109\/SECPRI.1999.766910"},{"issue":"1","key":"32_CR28","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/S0957-4174(03)00007-1","volume":"25","author":"D Joo","year":"2003","unstructured":"Joo, D., Hong, T., & Han, I. (2003). The neural network models for IDS based on the asymmetric costs of false negative errors and false positive errors. Expert System with Applications, 25(1), 69\u201375.","journal-title":"Expert System with Applications"},{"issue":"1","key":"32_CR29","doi-asserted-by":"crossref","first-page":"184","DOI":"10.1109\/COMST.2015.2402161","volume":"18","author":"C Kolias","year":"2016","unstructured":"Kolias, C., Kambourakis, G., Stavrou, A., & Gritzalis, S. (2016). Intrusion detection in 802.11 networks: Empirical evaluation of threats and a public dataset. IEEE Communications Surveys Tutorials, 18(1), 184\u2013208.","journal-title":"IEEE Communications Surveys Tutorials"},{"issue":"1","key":"32_CR30","doi-asserted-by":"crossref","first-page":"91","DOI":"10.7763\/JACN.2014.V2.87","volume":"2","author":"U Subramanian","year":"2014","unstructured":"Subramanian, U., & Ong, H. S. (2014). Analysis of the effect of clustering the training data in Naive Bayes classifier for anomaly network intrusion detection. Journal of Advances in Computer Networks, 2(1), 91\u201394.","journal-title":"Journal of Advances in Computer Networks"},{"issue":"7","key":"32_CR31","doi-asserted-by":"crossref","first-page":"772","DOI":"10.1016\/j.comcom.2012.01.016","volume":"35","author":"P Casas","year":"2012","unstructured":"Casas, P., Mazel, J., & Owezarski, P. (2012). Unsupervised network intrusion detection systems: Detecting the unknown without knowledge. Computer Communications, 35(7), 772\u2013783.","journal-title":"Computer Communications"},{"key":"32_CR32","doi-asserted-by":"crossref","unstructured":"Muzammil, M. J., Qazi, S., & Ali, T. (2013). Comparative analysis of classification algorithms performance for statistical based intrusion detection system. In 3rd IEEE international conference on computer, control and communication (IC4) (pp. 1\u20136).","DOI":"10.1109\/IC4.2013.6653738"},{"issue":"9","key":"32_CR33","doi-asserted-by":"crossref","first-page":"2519","DOI":"10.1109\/TC.2014.2375218","volume":"64","author":"Z Tan","year":"2015","unstructured":"Tan, Z., Jamdagni, A., He, X., Nanda, P., Liu, R. P., & Hu, J. (2015). Detection of denial-of-service attacks based on computer vision techniques. IEEE Transactions Computers, 64(9), 2519\u20132533.","journal-title":"IEEE Transactions Computers"},{"issue":"1","key":"32_CR34","doi-asserted-by":"crossref","first-page":"33","DOI":"10.3233\/HSN-2006-276","volume":"15","author":"V Bhuse","year":"2006","unstructured":"Bhuse, V., & Gupta, A. (2006). Anomaly intrusion detection in wireless sensor networks. Journal of High Speed Networks, 15(1), 33\u201351.","journal-title":"Journal of High Speed Networks"},{"key":"32_CR35","doi-asserted-by":"crossref","unstructured":"Zhao, Y. J., Wei, M. J., & Wang, J. (2013). Realization of intrusion detection system based on the improved data mining technology. In 8th international conference on Computer Science and Education. Colombo, Sri Lanka.","DOI":"10.1109\/ICCSE.2013.6554056"},{"key":"32_CR36","unstructured":"Mahoney, M. V., & Chan, P. K. (2001). PHAD: Packet header anomaly detection for identifying hostile network traffic (Tech. Rep. CS-2001-4). Melbourne, FL: Florida Institute of Technology."},{"key":"32_CR37","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1016\/j.compeleceng.2015.02.018","volume":"43","author":"H Sedjelmaci","year":"2015","unstructured":"Sedjelmaci, H., & Senouci, S. M. (2015). An accurate and efficient collaborative intrusion detection framework to secure vehicular networks. Computers and Electrical Engineering, 43, 33\u201347.","journal-title":"Computers and Electrical Engineering"}],"container-title":["Computer and Network Security Essentials"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-58424-9_32","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,24]],"date-time":"2025-06-24T22:27:14Z","timestamp":1750804034000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-58424-9_32"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,13]]},"ISBN":["9783319584232","9783319584249"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-58424-9_32","relation":{},"subject":[],"published":{"date-parts":[[2017,8,13]]}}}