{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:50:43Z","timestamp":1742914243121,"version":"3.40.3"},"publisher-location":"Singapore","reference-count":15,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789811982842"},{"type":"electronic","value":"9789811982859"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,10]],"date-time":"2022-12-10T00:00:00Z","timestamp":1670630400000},"content-version":"vor","delay-in-days":343,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Econnoisseur refers to users who obtain high returns from the Internet at low cost. It is of great significance for platform to identify econnoisseur to reduce unnecessary losses. At present, econnoisseur is mainly intercepted by rules. This method will fail when the new get the best deal method appears, and there is a certain lag. This paper identifies the econnoisseur from Knownsec Security Intelligence Brain\u2019s e-commerce website visitors. First of all, it is found that the precision and recall of the Isolation Forest are better than the Local Outlier Factor and DBSCAN in econnoisseur detection. Secondly, we merged the similar URLs visited by users with Bi-directional Long Short-Term Memory (BiLSTM), then use the merged data in Isolation Forest Model. It is found that the improved Isolation Forest model based on BiLSTM can further improve the detection ability. Practical case studies showed that this method has certain validity and reference for the detection of econnoisseur.<\/jats:p>","DOI":"10.1007\/978-981-19-8285-9_6","type":"book-chapter","created":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T20:02:48Z","timestamp":1670616168000},"page":"86-98","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Anomaly Detection of E-commerce Econnoisseur Based on User Behavior"],"prefix":"10.1007","author":[{"given":"Yangyu","family":"Long","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jilong","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jincheng","family":"Deng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangming","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,12,10]]},"reference":[{"key":"6_CR1","doi-asserted-by":"crossref","unstructured":"Bohara, A., Noureddine, M.A., Fawaz, A., et al.: An unsupervised multi-detector approach for identifying malicious lateral movement. In: Reliable Distributed Systems. IEEE (2017)","DOI":"10.1109\/SRDS.2017.31"},{"key":"6_CR2","unstructured":"Yao, Z.: Research and implementation of advanced persistent threats detection method based on data mining. Beijing University of Posts and Telecommunications (2019)"},{"issue":"7","key":"6_CR3","first-page":"122","volume":"52","author":"X Ren","year":"2016","unstructured":"Ren, X., Jiao, W., Zhou, D.: Intrusion detection model of Weighted Navie Bayes based on Particle Swarm Optimization algorithm. Comput. Eng. Appl. 52(7), 122\u2013126 (2016)","journal-title":"Comput. Eng. Appl."},{"issue":"01","key":"6_CR4","first-page":"33","volume":"41","author":"W Sun","year":"2020","unstructured":"Sun, W., Zhang, P., He, Y., et al.: Attack detection method based on spatiotemporal event correlation in intranet environment. J. Commun. 41(01), 33\u201341 (2020)","journal-title":"J. Commun."},{"issue":"03","key":"6_CR5","first-page":"109","volume":"31","author":"X Duan","year":"2010","unstructured":"Duan, X., Jia, C., Liu, C.: Intrusion detection method based on hierarchical hidden Markov model and variable-length semantic pattern. Journal on Communications 31(03), 109\u2013114 (2010)","journal-title":"Journal on Communications"},{"issue":"99","key":"6_CR6","first-page":"1","volume":"PP","author":"X Li","year":"2021","unstructured":"Li, X., Zhu, M., Yang, L.T., et al.: Sustainable ensemble learning driving intrusion detection model. IEEE Trans. Dependable Secure Comput. PP(99), 1\u20131 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"6_CR7","doi-asserted-by":"publisher","first-page":"721","DOI":"10.1007\/s11276-021-02866-x","volume":"28","author":"M Otair","year":"2022","unstructured":"Otair, M., Ibrahim, O.T., Abualigah, L., et al.: An enhanced Grey Wolf Optimizer based Particle Swarm Optimizer for intrusion detection system in wireless sensor networks. Wireless Netw. 28, 721\u2013744 (2022)","journal-title":"Wireless Netw."},{"key":"6_CR8","unstructured":"Yang, J.: An improved intrusion detection algorithm based on DBSCAN. Microcomput. Inf. 25 (2009)"},{"key":"6_CR9","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1016\/j.measurement.2014.04.034","volume":"55","author":"S Shamshirband","year":"2014","unstructured":"Shamshirband, S., Amini, A., Anuar, N.B., et al.: D-FICCA: a density-based fuzzy imperialist competitive clustering algorithm for intrusion detection in wireless sensor networks. Measurement 55, 212\u2013226 (2014)","journal-title":"Measurement"},{"issue":"8","key":"6_CR10","first-page":"1","volume":"25","author":"N Veeraiah","year":"2019","unstructured":"Veeraiah, N., Krishna, B.T.: Trust-aware FuzzyClus-Fuzzy NB: intrusion detection scheme based on fuzzy clustering and Bayesian rule. Wireless Netw. 25(8), 1\u201315 (2019)","journal-title":"Wireless Netw."},{"issue":"4","key":"6_CR11","doi-asserted-by":"publisher","first-page":"507","DOI":"10.1007\/s00778-006-0002-5","volume":"16","author":"L Khan","year":"2007","unstructured":"Khan, L., Awad, M., Thuraisingham, B.: A new intrusion detection system using support vector machines and hierarchical clustering. VLDB J. 16(4), 507\u2013521 (2007)","journal-title":"VLDB J."},{"key":"6_CR12","unstructured":"Dandan, Y.: Research and application of community detection algorithm based on node importance. Xidian University(2020)"},{"key":"6_CR13","unstructured":"Fei, T.L., Kai, M.T., Zhou, Z.H.: Isolation Forest. In: IEEE International Conference on Data Mining. IEEE (2008)"},{"key":"6_CR14","doi-asserted-by":"crossref","unstructured":"Breunig, M.M., Kriegel, H.P., Ng, R.T., et al.: LOF: identifying density-based local outliers. In: Proceedings of the ACM SIGMOD International Conference on Management of Data (2000)","DOI":"10.1145\/342009.335388"},{"key":"6_CR15","unstructured":"B\u00e4cklund, H., Hedblom, A., Neijman, N.: A density-based spatial clustering of application with noise. Data Min. (2011)"}],"container-title":["Communications in Computer and Information Science","Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-19-8285-9_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,24]],"date-time":"2022-12-24T00:02:57Z","timestamp":1671840177000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-19-8285-9_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9789811982842","9789811982859"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-981-19-8285-9_6","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"10 December 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CNCERT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China Cyber Security Annual Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cncert2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.cert.org.cn","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}