{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T05:41:13Z","timestamp":1761716473258},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2009,2,20]],"date-time":"2009-02-20T00:00:00Z","timestamp":1235088000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2009,10]]},"DOI":"10.1007\/s00521-009-0238-2","type":"journal-article","created":{"date-parts":[[2009,2,19]],"date-time":"2009-02-19T06:05:46Z","timestamp":1235023546000},"page":"663-674","source":"Crossref","is-referenced-by-count":16,"title":["Using artificial neural networks to detect unknown computer worms"],"prefix":"10.1007","volume":"18","author":[{"given":"Dima","family":"Stopel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert","family":"Moskovitch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zvi","family":"Boger","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Shahar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,2,20]]},"reference":[{"issue":"2","key":"238_CR1","first-page":"84","volume":"1","author":"P Kabiri","year":"2005","unstructured":"Kabiri P, Ghorbani A (2005) Research on intrusion detection and response: a survey. Int J Netw Secur 1(2):84\u2013102","journal-title":"Int J Netw Secur"},{"key":"238_CR2","doi-asserted-by":"crossref","unstructured":"Barbara D, Wu N, Jajodia S (2001) Detecting novel network intrusions using Bayes estimators. In: Proceedings of the first SIAM international conference on data mining","DOI":"10.1137\/1.9781611972719.28"},{"key":"238_CR3","doi-asserted-by":"crossref","unstructured":"Zanero S, Savaresi S (2004) Unsupervised learning techniques for an intrusion detection system. In: Proceedings of the ACM symposium on applied computing","DOI":"10.1145\/967900.967988"},{"issue":"5","key":"238_CR4","doi-asserted-by":"crossref","first-page":"423","DOI":"10.1016\/S0167-4048(03)00511-X","volume":"22","author":"M Botha","year":"2003","unstructured":"Botha M, Solms R (2003) Utilising fuzzy logic and trend analysis for effective intrusion detection. Comput Secur 22(5):423\u2013434. doi: 10.1016\/S0167-4048(03)00511-X","journal-title":"Comput Secur"},{"key":"238_CR5","doi-asserted-by":"crossref","unstructured":"Kienzle D, Elder M (2003) Recent worms: a survey and trends. In: Proceedings of the ACM workshop on rapid malcode","DOI":"10.1145\/948187.948189"},{"key":"238_CR6","unstructured":"Fosnock C (2005) Computer worms: past, present, and future. Infosec"},{"key":"238_CR7","unstructured":"Henry P (2003) A brief look at the evolution of killer worms. A CyberGuard Corporation White Paper"},{"key":"238_CR8","doi-asserted-by":"crossref","unstructured":"Stopel D, Boger Z, Moskovitch R, Shahar Y, Elovici Y (2006) Application of artificial neural networks techniques to computer worm detection. In: Proceedings of the international joint conference on neural networks","DOI":"10.1109\/IJCNN.2006.247059"},{"key":"238_CR9","first-page":"202","volume":"15","author":"D Stopel","year":"2006","unstructured":"Stopel D, Boger Z, Moskovitch R, Shahar Y, Elovici Y (2006) Improving worm detection with artificial neural networks through feature selection and temporal analysis techniques. Int J Comput Sci Eng 15:202\u2013209","journal-title":"Int J Comput Sci Eng"},{"key":"238_CR10","doi-asserted-by":"crossref","unstructured":"Moore D, Shannon C, Brown J (2002) Code Red: a case study on the spread and victims of an internet worm. In: Proceedings of the internet measurement workshop","DOI":"10.1145\/637201.637244"},{"key":"238_CR11","doi-asserted-by":"crossref","unstructured":"Weaver N, Paxson V, Staniford S, Cunningham R (2003) A taxonomy of computer worms. In: Proceedings of the ACM workshop on rapid malcode","DOI":"10.1145\/948187.948190"},{"key":"238_CR12","unstructured":"CERT CERT Advisory CA-2000-04. Love letter worm. http:\/\/www.cert.org\/advisories\/ca-2000-04.html"},{"key":"238_CR13","unstructured":"Lee W, Stolfo S, Mok K (1999) A data mining framework for building intrusion detection models. In: Proceedings of the IEEE symposium on security and privacy"},{"key":"238_CR14","unstructured":"Lippmann R, Graf I, Wyschogrod D, Webster S, Weber D, Gorton S (1998) The 1998 DARPA\/AFRL off-line intrusion detection evaluation. In: Proceedings of the first international workshop on recent advances in intrusion detection"},{"key":"238_CR15","unstructured":"Gunes H, Kayacik A, Zincir-Heywood N, Heywood M (2003) On the capability of an SOM based intrusion detection system. In: Proceedings of the international joint conference on neural networks"},{"key":"238_CR16","doi-asserted-by":"crossref","unstructured":"Lei J, Ghorbani A (2004) Network intrusion detection using an improved competitive learning neural network. In: Proceedings of the second annual conference on communication networks and services research","DOI":"10.1109\/DNSR.2004.1344728"},{"key":"238_CR17","unstructured":"Hu P, Heywood M (2003) Predicting intrusions with local linear model. In: Proceedings of the international joint conference on neural networks"},{"key":"238_CR18","doi-asserted-by":"crossref","unstructured":"Dickerson J, Dickerson J (2000) Fuzzy network profiling for intrusion detection. In: Proceedings of the 19th international conference of the North American Fuzzy Information Processing Society (NAFIPS)","DOI":"10.1109\/NAFIPS.2000.877441"},{"key":"238_CR19","unstructured":"Bridges S, Vaughn Rayford M (2000) Fuzzy data mining and genetic algorithms applied to intrusion detection. In: Proceedings of the 23rd national information systems security conference"},{"key":"238_CR20","doi-asserted-by":"crossref","unstructured":"Yoo I (2004) Visualizing windows executable viruses using self-organizing maps. In: Proceedings of the ACM workshop on visualization and data mining for computer security","DOI":"10.1145\/1029208.1029222"},{"key":"238_CR21","unstructured":"Ultes-Nitsche U, Yoo I (2002) An integrated network security approach: pairing detecting malicious patterns with anomaly detection. In: Proceedings of the second conference on information security for South Africa"},{"key":"238_CR22","unstructured":"Liu Z, Bridges S, Vaughn R (2003) Classification of anomalous traces of privileged and parallel programs by neural networks. In: Proceedings of the IEEE international conference on fuzzy systems"},{"key":"238_CR23","doi-asserted-by":"crossref","unstructured":"Apap F, Honig A, Hershkop S, Eskin E, Stolfo S (2002) Detecting malicious software by monitoring anomalous windows registry accesses. In: Proceedings of the fifth international symposium on recent advances in intrusion detection","DOI":"10.1007\/3-540-36084-0_3"},{"issue":"4","key":"238_CR24","first-page":"1","volume":"1","author":"S Mukkamala","year":"2003","unstructured":"Mukkamala S, Sung A (2003) Identifying significant features for network forensic analysis using artificial intelligent techniques. Int J Digit Evidence 1(4):1\u201317","journal-title":"Int J Digit Evidence"},{"key":"238_CR25","unstructured":"Handley M, Kreibich C, Paxson V (2001) Network intrusion detection: evasion, traffic normalization. In: Proceedings of the 10th USENIX security symposium"},{"issue":"3","key":"238_CR26","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/65.283931","volume":"8","author":"B Mukherjee","year":"1994","unstructured":"Mukherjee B, Heberlein L, Levitt K (1994) Network intrusion detection. IEEE Netw 8(3):26\u201341. doi: 10.1109\/65.283931","journal-title":"IEEE Netw"},{"key":"238_CR27","doi-asserted-by":"crossref","unstructured":"Warrender C, Forrest S, Pearlmutter B (1999) Detecting intrusions using system calls: alternative data models. In: Proceedings of the IEEE symposium on security and privacy","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"238_CR28","doi-asserted-by":"crossref","unstructured":"Wespi A, Dacier M, Debar H (2000) Intrusion detection using variable-length audit trail patterns. In: Proceedings of the international workshop on recent advances in intrusion detection","DOI":"10.1007\/3-540-39945-3_8"},{"key":"238_CR29","unstructured":"Tandon G, Chan P (2003) Learning rules from system call arguments and sequences for anomaly detection. In: Proceedings of the ICDM workshop on data mining for computer security"},{"key":"238_CR30","doi-asserted-by":"crossref","first-page":"805","DOI":"10.1016\/S1389-1286(98)00017-6","volume":"31","author":"H Debar","year":"1999","unstructured":"Debar H, Dacier M, Wespi A (1999) Towards a taxonomy of intrusion\u2013detection systems. Comput Netw 31:805\u2013822. doi: 10.1016\/S1389-1286(98)00017-6","journal-title":"Comput Netw"},{"key":"238_CR31","unstructured":"Sarle W (2002) Neural Network FAQ, part 1 of 7: Introduction. Periodic posting to the Usenet newsgroup comp.ai.neural-nets. ftp:\/\/ftp.sas.com\/pub\/neural\/FAQ.html"},{"key":"238_CR32","doi-asserted-by":"crossref","DOI":"10.1093\/oso\/9780198538493.001.0001","volume-title":"Neural networks for pattern recognition","author":"C Bishop","year":"1995","unstructured":"Bishop C (1995) Neural networks for pattern recognition. Clarendon Press, Oxford"},{"key":"238_CR33","unstructured":"Boger Z (2003) Finding patient\u2019s cluster\u2019s attributes by auto-associative ANN modeling. In: Proceedings of the international joint conference on neural networks"},{"issue":"6","key":"238_CR34","doi-asserted-by":"crossref","first-page":"989","DOI":"10.1109\/72.329697","volume":"5","author":"M Hagan","year":"1994","unstructured":"Hagan M, Menhaj M (1994) Training feed forward networks with the Marquardt algorithm. IEEE Trans Neural Netw 5(6):989\u2013993. doi: 10.1109\/72.329697","journal-title":"IEEE Trans Neural Netw"},{"key":"238_CR35","volume-title":"Neural network toolbox for use with Matlab","author":"H Demuth","year":"1993","unstructured":"Demuth H, Beale M (1993) Neural network toolbox for use with Matlab. The Mathworks Inc., MA"},{"key":"238_CR36","unstructured":"Quinlan J (1993) C4.5: Programs for machine learning. Morgan Kaufmann, San Francisco"},{"key":"238_CR37","unstructured":"Mitchell T (1997) Machine learning. McGraw-Hill, New York"},{"issue":"3","key":"238_CR38","first-page":"273","volume":"20","author":"C Cortes","year":"1995","unstructured":"Cortes C, Vapnik V (1995) Support-vector networks. Mach Learn 20(3):273\u2013297","journal-title":"Mach Learn"},{"key":"238_CR39","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4615-5689-3","volume-title":"Feature selection for knowledge discovery and data mining. Kluwer Academic Publishers","author":"H Liu","year":"1998","unstructured":"Liu H, Motorda H (1998) Feature selection for knowledge discovery and data mining. Kluwer Academic Publishers. Norwell, MA"},{"issue":"1\u20132","key":"238_CR40","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1016\/S0003-2670(03)00349-0","volume":"490","author":"Z Boger","year":"2003","unstructured":"Boger Z (2003) Selection of the quasi-optimal inputs in chemometric modeling by artificial neural network analysis. Anal Chim Acta 490(1\u20132):31\u201340. doi: 10.1016\/S0003-2670(03)00349-0","journal-title":"Anal Chim Acta"},{"key":"238_CR41","doi-asserted-by":"crossref","first-page":"531","DOI":"10.1126\/science.286.5439.531","volume":"286","author":"T Golub","year":"1997","unstructured":"Golub T, Slonim D, Tamaya P, Huard C, Gaasenbeek M, Mesirov J, Coller H, Loh M, Downing J, Caligiuri M, Bloomfield C, Lander E (1997) Molecular classification of cancer: class discovery and class prediction by gene expression monitoring. Science 286:531\u2013537. doi: 10.1126\/science.286.5439.531","journal-title":"Science"},{"key":"238_CR42","doi-asserted-by":"crossref","unstructured":"Baba K, Enbutu I, Yoda M (1990) Explicit representation of knowledge acquired from plant historical data using neural network. In: Proceedings of the international joint conference on neural networks","DOI":"10.1109\/IJCNN.1990.137838"},{"issue":"10","key":"238_CR43","first-page":"86","volume":"15","author":"J Lorch","year":"2000","unstructured":"Lorch J, Smith A (2000) The VTrace tool: building a system tracer for Windows NT, Windows 2000. MSDN Mag 15(10):86\u2013102","journal-title":"MSDN Mag"},{"key":"238_CR44","volume-title":"Data Mining: practical machine learning tools and techniques","author":"I Witten","year":"2005","unstructured":"Witten I, Frank E (2005) Data Mining: practical machine learning tools and techniques, 2nd edn. Morgan Kaufmann, San Francisco","edition":"2"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-009-0238-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00521-009-0238-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-009-0238-2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,10]],"date-time":"2024-03-10T19:10:36Z","timestamp":1710097836000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00521-009-0238-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,2,20]]},"references-count":44,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2009,10]]}},"alternative-id":["238"],"URL":"https:\/\/doi.org\/10.1007\/s00521-009-0238-2","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,2,20]]}}}