{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T04:12:38Z","timestamp":1750824758780,"version":"3.41.0"},"publisher-location":"Cham","reference-count":68,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319584232"},{"type":"electronic","value":"9783319584249"}],"license":[{"start":{"date-parts":[[2017,8,13]],"date-time":"2017-08-13T00:00:00Z","timestamp":1502582400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-58424-9_7","type":"book-chapter","created":{"date-parts":[[2017,8,12]],"date-time":"2017-08-12T07:33:44Z","timestamp":1502523224000},"page":"113-134","source":"Crossref","is-referenced-by-count":10,"title":["A Survey and Taxonomy on Data and Pre-processing Techniques of Intrusion Detection Systems"],"prefix":"10.1007","author":[{"given":"Tarfa","family":"Hamed","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jason B.","family":"Ernst","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan C.","family":"Kremer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,8,13]]},"reference":[{"key":"7_CR1","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1109\/SPW.2013.13","volume-title":"2013 IEEE Security and privacy workshops (SPW)","author":"V. Aghaei-Foroushani","year":"2013","unstructured":"Aghaei-Foroushani, V., & Zincir-Heywood, A. N. (2013). On evaluating ip traceback schemes: a practical perspective. In 2013 IEEE Security and privacy workshops (SPW) (pp.\u00a0127\u2013134). Piscataway, NJ: IEEE."},{"issue":"1","key":"7_CR2","first-page":"291","volume":"6","author":"O. Al-Jarrah","year":"2015","unstructured":"Al-Jarrah, O., & Arafat, A. (2015). Network intrusion detection system using neural network classification of attack behavior. Journal of Advances in Information Technology, 6(1), 291\u2013295.","journal-title":"Journal of Advances in Information Technology"},{"doi-asserted-by":"crossref","unstructured":"Alata, E., Nicomette, V., Kaa\u00e2niche, M., Dacier, M., & Herrb, M. (2006). Lessons learned from the deployment of a high-interaction honeypot. In Sixth European Dependable Computing Conference, 2006. EDCC \u201906 (pp.\u00a039\u201346). doi:10.1109\/EDCC.2006.17.","key":"7_CR3","DOI":"10.1109\/EDCC.2006.17"},{"key":"7_CR4","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1007\/11856214_9","volume-title":"Proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection (RAID)","author":"P. Baecher","year":"2006","unstructured":"Baecher, P., Koetter, M., Dornseif, M., & Freiling, F. (2006). The nepenthes platform: An efficient approach to collect malware. In Proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection (RAID) (pp.\u00a0165\u2013184). Berlin: Springer."},{"doi-asserted-by":"crossref","unstructured":"Balkanli, E., & Zincir-Heywood, A. (2014). On the analysis of backscatter traffic. In 2014 IEEE 39th Conference on Local Computer Networks Workshops (LCN Workshops) (pp.\u00a0671\u2013678). doi:10.1109\/LCNW.2014.6927719.","key":"7_CR5","DOI":"10.1109\/LCNW.2014.6927719"},{"unstructured":"Baumann, R. (2005). Honeyd\u2013a low involvement honeypot in action. Originally published as part of the GCIA (GIAC Certified Intrusion Analyst) practical (2003)","key":"7_CR6"},{"issue":"5","key":"7_CR7","doi-asserted-by":"crossref","first-page":"469","DOI":"10.3233\/IDA-2003-7506","volume":"7","author":"F. Bergadano","year":"2003","unstructured":"Bergadano, F., Gunetti, D., & Picardi, C. (2003). Identity verification through dynamic keystroke analysis. Intelligent Data Analysis, 7(5), 469\u2013496. http:\/\/dl.acm.org\/citation.cfm?id=1293861.1293866 .","journal-title":"Intelligent Data Analysis"},{"issue":"1","key":"7_CR8","doi-asserted-by":"crossref","first-page":"33","DOI":"10.3233\/HSN-2006-276","volume":"15","author":"V. Bhuse","year":"2006","unstructured":"Bhuse, V., & Gupta, A. (2006). Anomaly intrusion detection in wireless sensor networks. Journal of High Speed Networks, 15(1), 33\u201351.","journal-title":"Journal of High Speed Networks"},{"doi-asserted-by":"crossref","unstructured":"Casas, P., Mazel, J., & Owezarski, P. (2012). Unsupervised network intrusion detection systems: Detecting the unknown without knowledge. Computer Communications, 35(7), 772\u2013783. http:\/\/dx.doi.org\/10.1016\/j.comcom.2012.01.016 , http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0140366412000266 .","key":"7_CR9","DOI":"10.1016\/j.comcom.2012.01.016"},{"doi-asserted-by":"crossref","unstructured":"Chimedtseren, E., Iwai, K., Tanaka, H., & Kurokawa, T. (2014). Intrusion detection system using discrete Fourier transform. In 2014 Seventh IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA) (pp.\u00a01\u20135). doi:10.1109\/CISDA.2014.7035624.","key":"7_CR10","DOI":"10.1109\/CISDA.2014.7035624"},{"key":"7_CR11","doi-asserted-by":"crossref","first-page":"291","DOI":"10.1109\/ICCUBEA.2015.61","volume-title":"2015 International Conference on Computing Communication Control and Automation (ICCUBEA)","author":"D. Gaikwad","year":"2015","unstructured":"Gaikwad, D., & Thool, R. C. (2015). Intrusion detection system using bagging ensemble method of machine learning. In 2015 International Conference on Computing Communication Control and Automation (ICCUBEA) (pp.\u00a0291\u2013295). Piscataway, NJ: IEEE."},{"unstructured":"Gong, Y., Mabu, S., Chen, C., Wang, Y., & Hirasawa, K. (2009). Intrusion detection system combining misuse detection and anomaly detection using genetic network programming. In ICCAS-SICE, 2009 (pp.\u00a03463\u20133467).","key":"7_CR12"},{"doi-asserted-by":"crossref","unstructured":"Ingre, B., & Yadav, A. (2015). Performance analysis of NSL-KDD dataset using ANN. In 2015 International Conference on Signal Processing and Communication Engineering Systems (SPACES) (pp.\u00a092\u201396). doi:10.1109\/SPACES.2015.7058223.","key":"7_CR13","DOI":"10.1109\/SPACES.2015.7058223"},{"doi-asserted-by":"crossref","unstructured":"Jadhav, A., Jadhav, A., Jadhav, P., & Kulkarni, P. (2013). A novel approach for the design of network intrusion detection system(NIDS). In 2013 International Conference on Sensor Network Security Technology and Privacy Communication System (SNS PCS) (pp.\u00a022\u201327). doi:10.1109\/SNS-PCS.2013.6553828.","key":"7_CR14","DOI":"10.1109\/SNS-PCS.2013.6553828"},{"doi-asserted-by":"crossref","unstructured":"Jamali, S., & Shaker, V. (2014). Defense against {SYN} flooding attacks: A particle swarm optimization approach. Computers and Electrical Engineering, 40(6), 2013\u20132025. http:\/\/dx.doi.org\/10.1016\/j.compeleceng.2014.05.012 , http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0045790614001591 .","key":"7_CR15","DOI":"10.1016\/j.compeleceng.2014.05.012"},{"issue":"1","key":"7_CR16","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/S0957-4174(03)00007-1","volume":"25","author":"D. Joo","year":"2003","unstructured":"Joo, D., Hong, T., & Han, I. (2003). The neural network models for IDS based on the asymmetric costs of false negative errors and false positive errors. Expert Systems with Applications, 25(1), 69\u201375.","journal-title":"Expert Systems with Applications"},{"doi-asserted-by":"crossref","unstructured":"Kayacik, H., & Zincir-Heywood, N. (2005). Analysis of three intrusion detection system benchmark datasets using machine learning algorithms. In P. Kantor, G. Muresan, F. Roberts, D. Zeng, F. Y. Wang, H. Chen, & R. Merkle (Eds.), Intelligence and security informatics. Lecture notes in computer science (Vol. 3495, pp.\u00a0362\u2013367). Berlin\/Heidelberg: Springer. doi:10.1007\/11427995_29, http:\/\/dx.doi.org\/10.1007\/11427995_29 .","key":"7_CR17","DOI":"10.1007\/11427995_29"},{"key":"7_CR18","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1145\/2103380.2103435","volume-title":"Proceedings of the 2011 ACM Symposium on Research in Applied Computation","author":"H. G. Kim","year":"2011","unstructured":"Kim, H. G., Kim, D. J., Cho, S. J., Park, M., & Park, M. (2011). An efficient visitation algorithm to improve the detection speed of high-interaction client honeypots. In Proceedings of the 2011 ACM Symposium on Research in Applied Computation (pp.\u00a0266\u2013271). New York: ACM. doi:10.1145\/2103380.2103435, http:\/\/doi.acm.org\/10.1145\/2103380.2103435 ."},{"issue":"4","key":"7_CR19","doi-asserted-by":"crossref","first-page":"413","DOI":"10.1007\/s11047-006-9026-4","volume":"6","author":"J. Kim","year":"2007","unstructured":"Kim, J., Bentley, P. J., Aickelin, U., Greensmith, J., Tedesco, G., & Twycross, J. (2007). Immune system approaches to intrusion detection\u2013a review. Natural Computing, 6(4), 413\u2013466.","journal-title":"Natural Computing"},{"unstructured":"Lan, F., Chunlei, W., & Guoqing, M. (2010). A framework for network security situation awareness based on knowledge discovery. In 2010 2nd International Conference on Computer Engineering and Technology (ICCET) (Vol.\u00a01, pp.\u00a0226\u2013231). Piscataway, NJ: IEEE.","key":"7_CR20"},{"key":"7_CR21","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/1-84628-253-5_10","volume-title":"Machine learning and data mining for computer security","author":"T. Lane","year":"2006","unstructured":"Lane, T. (2006). A decision-theoretic, semi-supervised model for intrusion detection. In Machine learning and data mining for computer security (pp.\u00a0157\u2013177). London: Springer."},{"unstructured":"Lane, T., & Brodley, C. E. (1997). An application of machine learning to anomaly detection. In Proceedings of the 20th National Information Systems Security Conference (pp.\u00a0366\u2013377).","key":"7_CR22"},{"doi-asserted-by":"crossref","unstructured":"Li, Y., Fang, B. X., Chen, Y., & Guo, L. (2006). A lightweight intrusion detection model based on feature selection and maximum entropy model. In 2006 International Conference on Communication Technology (pp.\u00a01\u20134). doi:10.1109\/ICCT.2006.341771.","key":"7_CR23","DOI":"10.1109\/ICCT.2006.341771"},{"key":"7_CR24","volume-title":"Malware analyst\u2019s cookbook and DVD: Tools and techniques for fighting malicious code","author":"M. Ligh","year":"2011","unstructured":"Ligh, M., Adair, S., Hartstein, B., & Richard, M. (2011). Malware analyst\u2019s cookbook and DVD: Tools and techniques for fighting malicious code. Hoboken: Wiley Publishing."},{"doi-asserted-by":"crossref","unstructured":"Lin, W. C., Ke, S. W., & Tsai, C. F. (2015). CANN: An intrusion detection system based on combining cluster centers and nearest neighbors. Knowledge-Based Systems, 78(0), 13\u201321. http:\/\/dx.doi.org\/10.1016\/j.knosys.2015.01.009 , http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0950705115000167 .","key":"7_CR25","DOI":"10.1016\/j.knosys.2015.01.009"},{"issue":"4","key":"7_CR26","doi-asserted-by":"publisher","first-page":"491","DOI":"10.1109\/TKDE.2005.66","volume":"17","author":"H. Liu","year":"2005","unstructured":"Liu, H., & Yu, L. (2005). Toward integrating feature selection algorithms for classification and clustering. IEEE Transactions on Knowledge and Data Engineering, 17(4), 491\u2013502. doi:10.1109\/TKDE.2005.66.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"unstructured":"Mahoney, M. V., & Chan, P. K. (2001). Phad: Packet header anomaly detection for identifying hostile network traffic (Tech. Rep. CS-2001-4), Florida Institute of Technology, Melbourne, FL, USA.","key":"7_CR27"},{"issue":"5","key":"7_CR28","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1109\/52.877857","volume":"17","author":"G. McGraw","year":"2000","unstructured":"McGraw, G., & Morrisett, G. (2000). Attacking malicious code: A report to the infosec research council. IEEE Software, 17(5), 33\u201341.","journal-title":"IEEE Software"},{"issue":"3","key":"7_CR29","first-page":"686","volume":"2","author":"G. MeeraGandhi","year":"2010","unstructured":"MeeraGandhi, G., & Appavoo, K. (2010). Effective network intrusion detection using classifiers decision trees and decision rules. International Journal of Advanced Networking and Applications, 2(3), 686\u2013692.","journal-title":"International Journal of Advanced Networking and Applications"},{"doi-asserted-by":"crossref","unstructured":"Mehta, V., Bahadur, P., Kapoor, M., Singh, P., & Rajpoot, S. (2015). Threat prediction using honeypot and machine learning. In 2015 International Conference on Futuristic Trends on Computational Analysis and Knowledge Management (ABLAZE) (pp.\u00a0278\u2013282). doi:10.1109\/ABLAZE.2015.7155011.","key":"7_CR30","DOI":"10.1109\/ABLAZE.2015.7155011"},{"doi-asserted-by":"crossref","unstructured":"Mo, Y., Ma, Y., & Xu, L. (2008). Design and implementation of intrusion detection based on mobile agents. In: IEEE International Symposium on IT in Medicine and Education, 2008 (pp.\u00a0278\u2013281). doi:10.1109\/ITME.2008.4743870.","key":"7_CR31","DOI":"10.1109\/ITME.2008.4743870"},{"doi-asserted-by":"crossref","unstructured":"Mohanapriya, M., & Krishnamurthi, I. (2014). Modified DSR protocol for detection and removal of selective black hole attack in MANET. Computers and Electrical Engineering, 40(2), 530\u2013538. http:\/\/dx.doi.org\/10.1016\/j.compeleceng.2013.06.001 , http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0045790613001596 .","key":"7_CR32","DOI":"10.1016\/j.compeleceng.2013.06.001"},{"key":"7_CR33","doi-asserted-by":"crossref","first-page":"247","DOI":"10.1145\/2396556.2396604","volume-title":"Proceedings of the Eighth ACM\/IEEE Symposium on Architectures for Networking and Communications Systems","author":"S. Muehlbach","year":"2012","unstructured":"Muehlbach, S., & Koch, A. (2012). Malacoda: Towards high-level compilation of network security applications on reconfigurable hardware. In Proceedings of the Eighth ACM\/IEEE Symposium on Architectures for Networking and Communications Systems (pp.\u00a0247\u2013258). New York: ACM."},{"doi-asserted-by":"crossref","unstructured":"Muzammil, M., Qazi, S., & Ali, T. (2013). Comparative analysis of classification algorithms performance for statistical based intrusion detection system. In 2013 3rd International Conference on Computer, Control Communication (IC4) (pp.\u00a01\u20136). doi:10.1109\/IC4.2013.6653738.","key":"7_CR34","DOI":"10.1109\/IC4.2013.6653738"},{"unstructured":"Nechaev, B., Allman, M., Paxson, V., & Gurtov, A. (2010). A preliminary analysis of TCP performance in an enterprise network. In Proceedings of the 2010 Internet Network Management Conference on Research on Enterprise Networking, USENIX Association (pp.\u00a01\u20136).","key":"7_CR35"},{"doi-asserted-by":"crossref","unstructured":"Ng, J., Joshi, D., & Banik, S. (2015). Applying data mining techniques to intrusion detection. In 2015 12th International Conference on Information Technology \u2013 New Generations (ITNG) (pp.\u00a0800\u2013801). doi:10.1109\/ITNG.2015.146.","key":"7_CR36","DOI":"10.1109\/ITNG.2015.146"},{"key":"7_CR37","volume-title":"Network intrusion detection","author":"S. Northcutt","year":"2003","unstructured":"Northcutt, S., & Novak, J. (2003). Network intrusion detection. Indianapolis: Sams Publishing."},{"unstructured":"Pannell, G., & Ashman, H. (2010). Anomaly detection over user profiles for intrusion detection. In Proceedings of the 8th Australian Information Security Management Conference, School of Computer and Information Science, Edith Cowan University, Perth, Western Australia (pp.\u00a081\u201394)","key":"7_CR38"},{"issue":"5","key":"7_CR39","doi-asserted-by":"crossref","first-page":"1256","DOI":"10.1016\/j.comnet.2006.09.005","volume":"51","author":"G. Portokalidis","year":"2007","unstructured":"Portokalidis, G., & Bos, H. (2007). Sweetbait: Zero-hour worm detection and containment using low-and high-interaction honeypots. Computer Networks, 51(5), 1256\u20131274.","journal-title":"Computer Networks"},{"key":"7_CR40","volume-title":"Dionaea","author":"T. H. Project","year":"2009","unstructured":"Project, T. H. (2009). Dionaea. http:\/\/dionaea.carnivore.it . Accessed February 2013."},{"unstructured":"Provos N (2004) A virtual honeypot framework. In: Proceedings of the 13th Conference on USENIX Security Symposium - Volume 13, USENIX Association, Berkeley, CA, USA, SSYM\u201904, pp 1-14, http:\/\/dl.acm.org\/citation.cfm?id=1251375.1251376 .","key":"7_CR41"},{"issue":"3","key":"7_CR42","first-page":"126","volume":"2","author":"V. Richharya","year":"2013","unstructured":"Richharya, V., Rana, D. J., Jain, D. R., & Pandey, D. K. (2013). Design of trust model for efficient cyber attack detection on fuzzified large data using data mining techniques. International Journal of Research in Computer and Communication Technology, 2(3), 126\u2013130.","journal-title":"International Journal of Research in Computer and Communication Technology"},{"doi-asserted-by":"crossref","unstructured":"Rieck, K., Schwenk, G., Limmer, T., Holz, T., & Laskov, P. (2010). Botzilla: Detecting the phoning home of malicious software. In proceedings of the 2010 ACM Symposium on Applied Computing (pp.\u00a01978\u20131984). New York: ACM.","key":"7_CR43","DOI":"10.1145\/1774088.1774506"},{"issue":"1","key":"7_CR44","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1214\/ss\/998929476","volume":"16","author":"M. Schonlau","year":"2001","unstructured":"Schonlau, M., DuMouchel, W., Ju, W. H., Karr, A. F., Theus, M., & Vardi, Y. (2001). Computer intrusion: Detecting masquerades. Statistical Science, 16(1), 58\u201374.","journal-title":"Statistical Science"},{"key":"7_CR45","doi-asserted-by":"crossref","first-page":"1426","DOI":"10.1145\/1363686.1364018","volume-title":"Proceedings of the 2008 ACM Symposium on Applied Computing","author":"C. Seifert","year":"2008","unstructured":"Seifert, C., Welch, I., & Komisarczuk, P. (2008). Application of divide-and-conquer algorithm paradigm to improve the detection speed of high interaction client honeypots. In Proceedings of the 2008 ACM Symposium on Applied Computing, pp.\u00a01426\u20131432. New York: ACM."},{"key":"7_CR46","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1145\/586110.586146","volume-title":"Proceedings of the 9th ACM Conference on Computer and Communications Security","author":"R. Sekar","year":"2002","unstructured":"Sekar, R., Gupta, A., Frullo, J., Shanbhag, T., Tiwari, A., Yang, H., et al. (2002). Specification-based anomaly detection: A new approach for detecting network intrusions. In Proceedings of the 9th ACM Conference on Computer and Communications Security (pp.\u00a0265\u2013274). New York: ACM."},{"doi-asserted-by":"crossref","unstructured":"Sen, J. (2010). Efficient routing anomaly detection in wireless mesh networks. In 2010 First International Conference on Integrated Intelligent Computing (ICIIC) (pp.\u00a0302\u2013307). doi:10.1109\/ICIIC.2010.22.","key":"7_CR47","DOI":"10.1109\/ICIIC.2010.22"},{"issue":"1","key":"7_CR48","first-page":"101","volume":"2","author":"R. Shanmugavadivu","year":"2011","unstructured":"Shanmugavadivu, R., & Nagarajan, N. (2011). Network intrusion detection system using fuzzy logic. Indian Journal of Computer Science and Engineering (IJCSE), 2(1), 101\u2013111.","journal-title":"Indian Journal of Computer Science and Engineering (IJCSE)"},{"doi-asserted-by":"crossref","unstructured":"Sharma, V., & Nema, A. (2013). Innovative genetic approach for intrusion detection by using decision tree. In 2013 International Conference on Communication Systems and Network Technologies (CSNT) (pp.\u00a0418\u2013422). doi:10.1109\/CSNT.2013.93.","key":"7_CR49","DOI":"10.1109\/CSNT.2013.93"},{"doi-asserted-by":"crossref","unstructured":"Shiravi, A., Shiravi, H., Tavallaee, M., & Ghorbani, A. A. (2012). Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Computers and Security, 31(3), 357\u2013374. http:\/\/dx.doi.org\/10.1016\/j.cose.2011.12.012 , http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404811001672 .","key":"7_CR50","DOI":"10.1016\/j.cose.2011.12.012"},{"issue":"18","key":"7_CR51","doi-asserted-by":"crossref","first-page":"3799","DOI":"10.1016\/j.ins.2007.03.025","volume":"177","author":"T. Shon","year":"2007","unstructured":"Shon, T., & Moon, J. (2007). A hybrid machine learning approach to network anomaly detection. Information Sciences, 177(18), 3799\u20133821.","journal-title":"Information Sciences"},{"issue":"5","key":"7_CR52","first-page":"1","volume":"9","author":"S. Singh","year":"2009","unstructured":"Singh, S., & Silakari, S. (2009). A survey of cyber attack detection systems. International Journal of Computer Science and Network Security (IJCSNS), 9(5), 1\u201310.","journal-title":"International Journal of Computer Science and Network Security (IJCSNS)"},{"issue":"1","key":"7_CR53","doi-asserted-by":"crossref","first-page":"85","DOI":"10.7763\/JACN.2014.V2.87","volume":"2","author":"U. Subramanian","year":"2014","unstructured":"Subramanian, U., & Ong, H. S. (2014). Analysis of the effect of clustering the training data in naive bayes classifier for anomaly network intrusion detection. Journal of Advances in Computer Networks, 2(1), 85\u201388.","journal-title":"Journal of Advances in Computer Networks"},{"issue":"9","key":"7_CR54","doi-asserted-by":"publisher","first-page":"2519","DOI":"10.1109\/TC.2014.2375218","volume":"64","author":"Z. Tan","year":"2015","unstructured":"Tan, Z., Jamdagni, A., He, X., Nanda, P., Liu, R. P., & Hu, J. (2015). Detection of denial-of-service attacks based on computer vision techniques. IEEE Transactions on Computers, 64(9), 2519\u20132533. doi:10.1109\/TC.2014.2375218.","journal-title":"IEEE Transactions on Computers"},{"doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. A. (2009). A detailed analysis of the KDD CUP 99 data set. In Proceedings of the Second IEEE Symposium on Computational Intelligence for Security and Defence Applications 2009 (pp.\u00a053\u201358).","key":"7_CR55","DOI":"10.1109\/CISDA.2009.5356528"},{"doi-asserted-by":"crossref","unstructured":"Teng, L., Teng, S., Tang, F., Zhu, H., Zhang, W., Liu, D., et al. (2014). A collaborative and adaptive intrusion detection based on SVMs and decision trees. In 2014 IEEE International Conference on Data Mining Workshop (ICDMW) (pp.\u00a0898\u2013905). doi:10.1109\/ICDMW.2014.147.","key":"7_CR56","DOI":"10.1109\/ICDMW.2014.147"},{"unstructured":"Terry, S., & Chow, B. J. (2005). An assessment of the DARPA IDS evaluation dataset using snort (Tech. rep.), UC Davis Technical Report.","key":"7_CR57"},{"doi-asserted-by":"crossref","unstructured":"Thaseen, S., & Kumar, C. A. (2013). An analysis of supervised tree based classifiers for intrusion detection system. In 2013 International Conference on Pattern Recognition, Informatics and Mobile Engineering (pp.\u00a0294\u2013299). doi:10.1109\/ICPRIME.2013.6496489.","key":"7_CR58","DOI":"10.1109\/ICPRIME.2013.6496489"},{"doi-asserted-by":"crossref","unstructured":"Thomas, C., Sharma, V., & Balakrishnan, N. (2008). Usefulness of darpa dataset for intrusion detection system evaluation. In SPIE Defense and Security Symposium, International Society for Optics and Photonics (pp.\u00a01\u20138)","key":"7_CR59","DOI":"10.1117\/12.777341"},{"unstructured":"Trinius, P., Holz, T., Willems, C., & Rieck, K. (2009). A malware instruction set for behavior-based analysis (Tech. Rep. TR-2009-07), University of Mannheim.","key":"7_CR60"},{"unstructured":"Van\u00a0Jacobson, C. L., & McCanne, S. (1987). Tcpdump. http:\/\/www.tcpdump.org\/tcpdump_man.html#index . Accessed January 7, 2014.","key":"7_CR61"},{"doi-asserted-by":"crossref","unstructured":"Wang, W., Guyet, T., Quiniou, R., Cordier, M. O., Masseglia, F., & Zhang, X. (2014). Autonomic intrusion detection: Adaptively detecting anomalies over unlabeled audit data streams in computer networks. Knowledge-Based Systems, 70(0), 103\u2013117. http:\/\/dx.doi.org\/10.1016\/j.knosys.2014.06.018 , http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0950705114002391 .","key":"7_CR62","DOI":"10.1016\/j.knosys.2014.06.018"},{"doi-asserted-by":"crossref","unstructured":"Warrender, C., Forrest, S., & Pearlmutter, B. (1999). Detecting intrusions using system calls: Alternative data models. In: Proceedings of the 1999 IEEE Symposium on Security and Privacy, 1999 (pp.\u00a0133\u2013145). doi:10.1109\/SECPRI.1999.766910.","key":"7_CR63","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"7_CR64","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1109\/ICIME.2010.5477694","volume-title":"2010 The 2nd IEEE International Conference on Information Management and Engineering (ICIME)","author":"G. Xiaoqing","year":"2010","unstructured":"Xiaoqing, G., Hebin, G., & Luyi, C. (2010). Network intrusion detection method based on agent and SVM. In 2010 The 2nd IEEE International Conference on Information Management and Engineering (ICIME) (pp.\u00a0399\u2013402). Piscataway, NJ: IEEE."},{"doi-asserted-by":"crossref","unstructured":"Yanjun, Z., Jun, W. M., & Jing, W. (2013). Realization of intrusion detection system based on the improved data mining technology. In 2013 8th International Conference on Computer Science Education (ICCSE) (pp.\u00a0982\u2013987). doi:10.1109\/ICCSE.2013.6554056.","key":"7_CR65","DOI":"10.1109\/ICCSE.2013.6554056"},{"doi-asserted-by":"crossref","unstructured":"Yassin, W., Udzir, N. I., Abdullah, A., Abdullah, M. T., Zulzalil, H., & Muda, Z. (2014). Signature-based anomaly intrusion detection using integrated data mining classifiers. In 2014 International Symposium on Biometrics and Security Technologies (ISBAST) (pp.\u00a0232\u2013237). doi:10.1109\/ISBAST.2014.7013127.","key":"7_CR66","DOI":"10.1109\/ISBAST.2014.7013127"},{"doi-asserted-by":"crossref","unstructured":"Ying, L., Yan, Z., & Yang-Jia, O. (2010). The design and implementation of host-based intrusion detection system. In 2010 Third International Symposium on Intelligent Information Technology and Security Informatics (IITSI) (pp.\u00a0595\u2013598). doi:10.1109\/IITSI.2010.127.","key":"7_CR67","DOI":"10.1109\/IITSI.2010.127"},{"key":"7_CR68","doi-asserted-by":"crossref","DOI":"10.1142\/6297","volume-title":"Trust and security in collaborative computing","author":"X. Zou","year":"2008","unstructured":"Zou, X., Pan, Y., & Dai, Y.-S. (2008). Trust and security in collaborative computing. Singapore: World Scientific."}],"container-title":["Computer and Network Security Essentials"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-58424-9_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,24]],"date-time":"2025-06-24T22:27:09Z","timestamp":1750804029000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-58424-9_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,13]]},"ISBN":["9783319584232","9783319584249"],"references-count":68,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-58424-9_7","relation":{},"subject":[],"published":{"date-parts":[[2017,8,13]]}}}