{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T23:30:03Z","timestamp":1780961403439,"version":"3.54.1"},"publisher-location":"Berlin, Heidelberg","reference-count":12,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540715481","type":"print"},{"value":"9783540715498","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-71549-8_13","type":"book-chapter","created":{"date-parts":[[2007,6,28]],"date-time":"2007-06-28T05:11:58Z","timestamp":1183007518000},"page":"152-159","source":"Crossref","is-referenced-by-count":9,"title":["Research on Hidden Markov Model for System Call Anomaly Detection"],"prefix":"10.1007","author":[{"given":"Quan","family":"Qian","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingjun","family":"Xin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"13_CR1","unstructured":"Anderson, R., Khattak, A.: The use of information retrieval techniques for intrusion detection (2004), \n                      \n                        http:\/\/www.raid-symposium.org\/raid98\/index.html"},{"key":"13_CR2","first-page":"35","volume-title":"Proceedings of the IJCAI-99 Workshop on Learning about Users","author":"L. Terran","year":"1999","unstructured":"Terran, L.: Hidden markov models for human\/computer interface modeling. In: Proceedings of the IJCAI-99 Workshop on Learning about Users, Stockholm, Sweden, pp. 35\u201344. Morgan Kaufmann Publishers, San Francisco (1999)"},{"key":"13_CR3","first-page":"171","volume-title":"Proceedings of the 2000 IEEE Systems, Man, and Cybernetics Information Assurance and Security Workshop","author":"Y. Nong","year":"2000","unstructured":"Nong, Y.: A Markov chain model of temporal behavior for anomaly detection. In: Proceedings of the 2000 IEEE Systems, Man, and Cybernetics Information Assurance and Security Workshop, pp. 171\u2013174. IEEE Computer Society Press, New York (2000)"},{"issue":"1","key":"13_CR4","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1016\/S0167-4048(03)00112-3","volume":"22","author":"B.C. Sung","year":"2003","unstructured":"Sung, B.C., Hyuk, J.P.: Efficient anomaly detection by modeling privilege flows using hidden Markov model. Computers & Security\u00a022(1), 45\u201355 (2003)","journal-title":"Computers & Security"},{"key":"13_CR5","first-page":"120","volume-title":"Proceedings of the 1996 IEEE Symposium on Security and Privacy","author":"F. Stephanie","year":"1996","unstructured":"Stephanie, F., et al.: A sense of self for unix processes. In: Proceedings of the 1996 IEEE Symposium on Security and Privacy, pp. 120\u2013128. IEEE Computer Society Press, Los Alamitos (1996)"},{"issue":"3","key":"13_CR6","doi-asserted-by":"crossref","first-page":"151","DOI":"10.3233\/JCS-980109","volume":"6","author":"A.H. Steven","year":"1998","unstructured":"Steven, A.H., Stephanie, F., Anil, S.: Intrusion detection using sequences of system calls. Journal of Computer Security\u00a06(3), 151\u2013180 (1998)","journal-title":"Journal of Computer Security"},{"issue":"4","key":"13_CR7","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1109\/3468.594912","volume":"27","author":"P. Helman","year":"1997","unstructured":"Helman, P., Bhangoo, J.: A statistically based system for prioritizing information exploration under uncertainty. IEEE Transactions on Systems, Man and Cyberneticsm, Part A: Systems and Humans\u00a027(4), 449\u2013466 (1997)","journal-title":"IEEE Transactions on Systems, Man and Cyberneticsm, Part A: Systems and Humans"},{"key":"13_CR8","first-page":"50","volume-title":"AAAI Workshop on AI Approaches to Fraud Detection and Risk Management","author":"L. Wenke","year":"1997","unstructured":"Wenke, L., Salvatore, J.S., Chan, P.K.: Learning patterns from UNIX process execution traces for intrusion detection. In: AAAI Workshop on AI Approaches to Fraud Detection and Risk Management, pp. 50\u201356. AAAI press, Menlo Park (1997)"},{"key":"13_CR9","first-page":"133","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"W. Christina","year":"1999","unstructured":"Christina, W., Stephanie, F., Barak, P.: Detecting intrusions using system calls: alternative data models. In: Proceedings of IEEE Symposium on Security and Privacy, Oakland, California, pp. 133\u2013145. IEEE Computer Society Press, Los Alamitos (1999)"},{"key":"13_CR10","unstructured":"Snyder, D.: On-line intrusion detection using sequences of system calls. Master\u2019s thesis, Department of Computer Science, Florida State University (2001)"},{"key":"13_CR11","unstructured":"Jinhui-xie: HMM and its application in speech recognition (in Chinese). Huazhong University of Technology Press, Wuhan (1995)"},{"key":"13_CR12","unstructured":"Computer Immune Systems Data Sets. University of New Mexico (2004), \n                      \n                        http:\/\/www.cs.unm.edu\/~immsec\/data\/synth-sm.html"}],"container-title":["Lecture Notes in Computer Science","Intelligence and Security Informatics"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-71549-8_13.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T00:22:38Z","timestamp":1605745358000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-71549-8_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540715481","9783540715498"],"references-count":12,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-71549-8_13","relation":{},"subject":[]}}