{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T02:31:59Z","timestamp":1768444319471,"version":"3.49.0"},"reference-count":120,"publisher":"Springer Science and Business Media LLC","issue":"3-4","license":[{"start":{"date-parts":[[2012,11,15]],"date-time":"2012-11-15T00:00:00Z","timestamp":1352937600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2014,3]]},"DOI":"10.1007\/s00521-012-1263-0","type":"journal-article","created":{"date-parts":[[2012,11,14]],"date-time":"2012-11-14T07:11:43Z","timestamp":1352877103000},"page":"599-611","source":"Crossref","is-referenced-by-count":46,"title":["Flow-based anomaly detection in high-speed links using modified GSA-optimized neural network"],"prefix":"10.1007","volume":"24","author":[{"given":"Mansour","family":"Sheikhan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zahra","family":"Jadidi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2012,11,15]]},"reference":[{"key":"1263_CR1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.asoc.2009.06.019","volume":"10","author":"S Xiaonan Wu","year":"2010","unstructured":"Xiaonan Wu S, Banzhaf W (2010) The use of computational intelligence in intrusion detection systems: a review. Appl Soft Comput 10:1\u201335","journal-title":"Appl Soft Comput"},{"key":"1263_CR2","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro P, Diaz-Verdejo J, Macia-Fernandez G, Vazquez E (2009) Anomaly-base network intrusion detection: techniques, systems and challenges. J Comput Secur 28:18\u201328","journal-title":"J Comput Secur"},{"key":"1263_CR3","doi-asserted-by":"crossref","first-page":"8850","DOI":"10.1016\/j.eswa.2010.06.012","volume":"37","author":"X Li","year":"2010","unstructured":"Li X, Deng Z-H (2010) Mining frequent patterns from network flows for monitoring network. Expert Syst Appl 37:8850\u20138860","journal-title":"Expert Syst Appl"},{"key":"1263_CR4","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1016\/S0031-3203(02)00026-2","volume":"36","author":"DY Yeung","year":"2003","unstructured":"Yeung DY, Ding Y (2003) Host-based intrusion detection using dynamic and static behavioral models. J Pattern Recognit 36:229\u2013243","journal-title":"J Pattern Recognit"},{"key":"1263_CR5","doi-asserted-by":"crossref","first-page":"1185","DOI":"10.1007\/s00521-010-0487-0","volume":"21","author":"M Sheikhan","year":"2012","unstructured":"Sheikhan M, Jadidi Z, Farrokhi A (2012) Intrusion detection using reduced-size RNN based on feature grouping. Neural Comput Appl 21:1185\u20131190","journal-title":"Neural Comput Appl"},{"key":"1263_CR6","doi-asserted-by":"crossref","first-page":"3799","DOI":"10.1016\/j.ins.2007.03.025","volume":"177","author":"T Shon","year":"2007","unstructured":"Shon T, Moon J (2007) A hybrid machine learning approach to network anomaly detection. Inf Sci 177:3799\u20133821","journal-title":"Inf Sci"},{"key":"1263_CR7","unstructured":"Sheikhan M, Jadidi Z (2009) Misuse detection using hybrid of association rule mining and connectionist modeling. World Appl Sci J 7(Special Issue of Computer & IT):31\u201337"},{"key":"1263_CR8","volume-title":"Network intrusion detection","author":"S Northcutt","year":"2003","unstructured":"Northcutt S, Novak J (2003) Network intrusion detection, 3rd edn. New Riders, USA","edition":"3"},{"key":"1263_CR9","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1049\/iet-com:20070231","volume":"2","author":"G Androulidakis","year":"2008","unstructured":"Androulidakis G, Papavassiliou S (2008) Improving network anomaly detection via selective flow-based sampling. IET Commun 2:399\u2013409","journal-title":"IET Commun"},{"key":"1263_CR10","unstructured":"KDD Cup 1999 Data. Available on http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html . Accessed July 2010"},{"key":"1263_CR11","first-page":"1","volume":"6","author":"M Sabhnani","year":"2004","unstructured":"Sabhnani M, Serpen G (2004) Why machine learning algorithms fail in misuse detection on KDD intrusion detection data set. J Intell Data Anal 6:1\u201313","journal-title":"J Intell Data Anal"},{"key":"1263_CR12","unstructured":"Sheikhan M, Sha\u2019bani AA (2009) Fast neural intrusion detection system based on hidden weight optimization algorithm and feature selection. World Appl Sci J 7(Special Issue of Computer & IT):45\u201353"},{"key":"1263_CR13","unstructured":"Sheikhan M, Gharavian D (2009) Combination of Elman neural network and classification-based predictive association rules to improve computer networks\u2019 security. World Appl Sci J 7(Special Issue of Computer & IT):80\u201386"},{"key":"1263_CR14","first-page":"302","volume":"8","author":"M Sheikhan","year":"2010","unstructured":"Sheikhan M, Jadidi Z, Beheshti M (2010) Effects of feature reduction on the performance of attack recognition by static and dynamic neural networks. World Appl Sci J 8:302\u2013308","journal-title":"World Appl Sci J"},{"key":"1263_CR15","unstructured":"Sheikhan M, Sharifi Rad M (2010) Misuse detection based on feature selection by fuzzy association rule mining. World Appl Sci J 10(Special Issue of Computer & Electrical Engineering):32\u201340"},{"key":"1263_CR16","first-page":"24","volume":"4","author":"M Sheikhan","year":"2010","unstructured":"Sheikhan M, Khalili A (2010) Intrusion detection based on rule extraction from dynamic cell structure neural network. Majlesi J Elect Eng 4:24\u201334","journal-title":"Majlesi J Elect Eng"},{"key":"1263_CR17","first-page":"772","volume":"14","author":"M Sheikhan","year":"2011","unstructured":"Sheikhan M, Sharifi Rad M (2011) Intrusion detection improvement using GA-optimized fuzzy grids-based rule mining feature selector and fuzzy ARTMAP neural network. World Appl Sci J 14:772\u2013781","journal-title":"World Appl Sci J"},{"key":"1263_CR18","unstructured":"Winter P, Hermann E, Zeilinger M (2011) Inductive intrusion detection in flow-based network data using one-class support vector machines. In: The proceedings of international conference on new technologies, mobility and security, pp 1\u20135. doi: 10.1109\/NMTS.2011.5720582"},{"key":"1263_CR19","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1109\/SURV.2010.032210.00054","volume":"12","author":"A Sperotto","year":"2010","unstructured":"Sperotto A, Schaffrath G, Sadre R, Morariu C, Pras A, Stiller B (2010) An overview of IP flow-based intrusion detection. IEEE Commun Surv Tutor 12:343\u2013356","journal-title":"IEEE Commun Surv Tutor"},{"key":"1263_CR20","unstructured":"Li K, Teng G (2006) Unsupervised SVM based on p-kernels for anomaly detection. In: The proceedings of international conference on innovative computing, information and control, pp 59\u201362"},{"key":"1263_CR21","doi-asserted-by":"crossref","first-page":"3485","DOI":"10.1016\/j.comnet.2011.07.008","volume":"55","author":"B Tellenbach","year":"2011","unstructured":"Tellenbach B, Burkhart M, Schatzmann D, Gugelmann D, Sornette D (2011) Accurate network anomaly classification with generalized entropy metrics. Comput Netw 55:3485\u20133502","journal-title":"Comput Netw"},{"key":"1263_CR22","doi-asserted-by":"crossref","first-page":"1822","DOI":"10.1016\/j.eswa.2011.08.068","volume":"39","author":"CA Catania","year":"2012","unstructured":"Catania CA, Bromberg F, Garino CG (2012) An autonomous labeling approach to support vector machines algorithms for network traffic anomaly detection. Expert Syst Appl 39:1822\u20131829","journal-title":"Expert Syst Appl"},{"key":"1263_CR23","doi-asserted-by":"crossref","unstructured":"Zhang Z, Shen H (2004) Online training of SVMs for real-time intrusion detection. In: The proceedings of international conference on advanced information networking and applications, vol 1, pp 568\u2013573","DOI":"10.1109\/AINA.2004.1283970"},{"key":"1263_CR24","first-page":"943","volume":"10","author":"J Ryan","year":"1998","unstructured":"Ryan J, Lin MJ, Miikkulainen R (1998) Intrusion detection with neural networks. Adv Neural Inf Process Syst 10:943\u2013949","journal-title":"Adv Neural Inf Process Syst"},{"key":"1263_CR25","unstructured":"Ghosh AK, Schwartzbard A (1999) A study in using neural networks for anomaly and misuse detection. In: The proceedings of the USENIX security symposium, vol 8, pp 141\u2013152"},{"key":"1263_CR26","doi-asserted-by":"crossref","unstructured":"Hofmann A, Schmitz C, Sick B (2003) Rule extraction from neural networks for intrusion detection in computer networks. In: The proceedings of the IEEE international conference on systems, man and cybernetics, vol 2, pp 1259\u20131265","DOI":"10.1109\/ICSMC.2003.1244584"},{"key":"1263_CR27","doi-asserted-by":"crossref","unstructured":"Zhang C, Jiang J, Kamel M (2003) Comparison of BPL and RBF network in intrusion detection system. In: The proceedings of the international conference on rough sets, fuzzy sets, data mining, and granular computing, pp 466\u2013470","DOI":"10.1007\/3-540-39205-X_79"},{"key":"1263_CR28","doi-asserted-by":"crossref","unstructured":"Jiang J, Zhang C, Kame M (2003) RBF-based real-time hierarchical intrusion detection systems. In: The proceedings of the international joint conference on neural networks, vol 2, pp 1512\u20131516","DOI":"10.1109\/IJCNN.2003.1223922"},{"key":"1263_CR29","unstructured":"Fox K, Henning R, Reed J (1990) A neural network approach toward intrusion detection. In: The proceedings of the national computer security conference, vol 1, pp 124\u2013134"},{"key":"1263_CR30","doi-asserted-by":"crossref","first-page":"539","DOI":"10.1016\/j.cose.2006.05.005","volume":"25","author":"W Wang","year":"2006","unstructured":"Wang W, Guan X, Zhang X, Yang L (2006) Profiling program behavior for anomaly intrusion detection based on the transition and frequency property of computer audit data. Comput Secur 25:539\u2013550","journal-title":"Comput Secur"},{"key":"1263_CR31","doi-asserted-by":"crossref","first-page":"559","DOI":"10.1109\/TSMCB.2005.860136","volume":"36","author":"SJ Han","year":"2006","unstructured":"Han SJ, Cho SB (2006) Evolutionary neural networks for anomaly detection based on the behavior of a program. IEEE Trans Syst Man Cybern Part B 36:559\u2013570","journal-title":"IEEE Trans Syst Man Cybern Part B"},{"key":"1263_CR32","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1016\/j.jnca.2005.08.005","volume":"30","author":"Y Liao","year":"2007","unstructured":"Liao Y, Vemuri VR, Pasos A (2007) Adaptive anomaly detection with evolving connectionist systems. J Netw Comput Appl 30:60\u201380","journal-title":"J Netw Comput Appl"},{"key":"1263_CR33","unstructured":"Bridges SM, Vaughn RB (2000) Intrusion detection via fuzzy data mining. In: The proceedings of the annual Canadian information technology security symposium, pp 111\u2013121"},{"key":"1263_CR34","doi-asserted-by":"crossref","unstructured":"Shah H, Undercoffer J, Joshi A (2003) Fuzzy clustering for intrusion detection. In: The proceedings of the IEEE international conference on fuzzy systems, vol 2, pp 1274\u20131278","DOI":"10.1109\/FUZZ.2003.1206614"},{"key":"1263_CR35","doi-asserted-by":"crossref","first-page":"433","DOI":"10.1007\/11538356_45","volume":"3645","author":"H He","year":"2005","unstructured":"He H, Luo X, Liu B (2005) Detecting anomalous network traffic with combined fuzzy based approaches. Lect Notes Comput Sci 3645:433\u2013442","journal-title":"Lect Notes Comput Sci"},{"key":"1263_CR36","unstructured":"Chimphlee W, Sap MNM, Abdullah AH, Chimphlee S, Srinoy S (2006) To identify suspicious activity in anomaly detection based on soft computing. In: The proceedings of the IASTED international conference on artificial intelligence and applications, pp 359\u2013364"},{"key":"1263_CR37","doi-asserted-by":"crossref","unstructured":"Forrest S, Perelson AS, Allen L, Cherukuri R (1994) Self-nonself discrimination in a computer. In: The proceedings of the IEEE computer society symposium on research in security and privacy, pp 202\u2013212","DOI":"10.1109\/RISP.1994.296580"},{"key":"1263_CR38","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1007\/3-540-45474-8_8","volume":"2212","author":"PD Williams","year":"2001","unstructured":"Williams PD, Anchor KP, Bebo JL, Gunsch GH, Lamont GD (2001) CDIS: towards a computer immune system for detecting network intrusions. Lect Notes Comput Sci 2212:117\u2013133","journal-title":"Lect Notes Comput Sci"},{"key":"1263_CR39","doi-asserted-by":"crossref","first-page":"316","DOI":"10.1007\/978-3-540-30220-9_26","volume":"3239","author":"U Aickelin","year":"2004","unstructured":"Aickelin U, Greensmith J, Twycross J (2004) Immune system approaches to intrusion detection: a review. Lect Notes Comput Sci 3239:316\u2013329","journal-title":"Lect Notes Comput Sci"},{"key":"1263_CR40","doi-asserted-by":"crossref","first-page":"413","DOI":"10.1007\/s11047-006-9026-4","volume":"6","author":"J Kim","year":"2007","unstructured":"Kim J, Bentley P, Aickelin U, Greensmith J, Tedesco G, Twycross J (2007) Immune system approaches to intrusion detection- a review. Nat Comput Int J 6:413\u2013466","journal-title":"Nat Comput Int J"},{"key":"1263_CR41","doi-asserted-by":"crossref","first-page":"1275","DOI":"10.1016\/j.asoc.2010.03.004","volume":"11","author":"TS Sobh","year":"2011","unstructured":"Sobh TS, Mostafa WM (2011) A cooperative immunological approach for detecting network anomaly. Appl Soft Comput 11:1275\u20131283","journal-title":"Appl Soft Comput"},{"key":"1263_CR42","doi-asserted-by":"crossref","first-page":"625","DOI":"10.1016\/j.cose.2011.08.009","volume":"30","author":"C Kolias","year":"2011","unstructured":"Kolias C, Kambourakis G, Maragoudakis M (2011) Swarm intelligence in intrusion detection: a survey. Comput Secur 30:625\u2013642","journal-title":"Comput Secur"},{"key":"1263_CR43","doi-asserted-by":"crossref","first-page":"3492","DOI":"10.1016\/j.eswa.2010.08.137","volume":"38","author":"M-Y Su","year":"2011","unstructured":"Su M-Y (2011) Real-time anomaly detection systems for denial-of-service attacks by weighted k-nearest-neighbor classifiers. Expert Syst Appl 38:3492\u20133498","journal-title":"Expert Syst Appl"},{"key":"1263_CR44","doi-asserted-by":"crossref","first-page":"737","DOI":"10.1016\/j.cose.2010.05.002","volume":"29","author":"F Palmieri","year":"2010","unstructured":"Palmieri F, Fiore U (2010) Network anomaly detection through nonlinear analysis. Comput Secur 29:737\u2013755","journal-title":"Comput Secur"},{"key":"1263_CR45","doi-asserted-by":"crossref","first-page":"692","DOI":"10.1016\/j.cose.2011.08.006","volume":"30","author":"C Callegari","year":"2011","unstructured":"Callegari C, Giordano S, Pagano M, Pepe T (2011) Combining sketches and wavelet analysis for multi time-scale network anomaly detection. Comput Secur 30:692\u2013704","journal-title":"Comput Secur"},{"key":"1263_CR46","doi-asserted-by":"crossref","first-page":"501","DOI":"10.1016\/j.camwa.2011.08.020","volume":"63","author":"SM Lee","year":"2012","unstructured":"Lee SM, Kim DS, Lee JH, Park JS (2012) Detection of DDoS attacks using optimized traffic matrix. Comput Math Appl 63:501\u2013510","journal-title":"Comput Math Appl"},{"key":"1263_CR47","doi-asserted-by":"crossref","first-page":"4018","DOI":"10.1016\/j.comcom.2008.08.009","volume":"31","author":"Y Li","year":"2008","unstructured":"Li Y, Guo L, Tian Z-H, Lu T-B (2008) A lightweight web server anomaly detection method based on transductive scheme and genetic algorithms. Comput Commun 31:4018\u20134025","journal-title":"Comput Commun"},{"key":"1263_CR48","doi-asserted-by":"crossref","first-page":"1732","DOI":"10.1016\/j.jnca.2011.06.006","volume":"34","author":"T Qin","year":"2011","unstructured":"Qin T, Guan X, Li W, Wang P, Huang Q (2011) Monitoring abnormal network traffic based on blind source separation approach. J Netw Comput Appl 34:1732\u20131742","journal-title":"J Netw Comput Appl"},{"key":"1263_CR49","unstructured":"Liu X, Wang H, Lai J, Liang Y (2007) Network security situation awareness model based on heterogeneous multi-sensor data fusion. In: The proceedings of the international symposium on computer and information sciences, pp 1\u20136"},{"key":"1263_CR50","doi-asserted-by":"crossref","unstructured":"Alshammari R, Zincir-Heywood AN (2009) Machine learning based encrypted traffic classification: identifying SSH and skype. In: The proceedings of the IEEE international conference on computational intelligence for security and defense applications, pp 289\u2013296","DOI":"10.1109\/CISDA.2009.5356534"},{"key":"1263_CR51","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1016\/S0167-4048(03)00112-3","volume":"22","author":"S-B Cho","year":"2003","unstructured":"Cho S-B, Park H-J (2003) Efficient anomaly detection by modeling privilege flows using hidden Markov model. Comput Secur 22:45\u201355","journal-title":"Comput Secur"},{"key":"1263_CR52","doi-asserted-by":"crossref","unstructured":"Braga R, Mota E, Passito A (2010) Lightweight DDOS flooding attack detection using NOX\/OpenFlow. In: The proceedings of IEEE conference on local computer networks, pp 408\u2013415","DOI":"10.1109\/LCN.2010.5735752"},{"key":"1263_CR53","unstructured":"Dai L, Chen Y, Yun X (2007) Optimizing IP flow classification using feature selection. In: The proceedings of the international conference on parallel and distributed computing, applications and technologies, pp 39\u201345"},{"key":"1263_CR54","doi-asserted-by":"crossref","first-page":"8850","DOI":"10.1016\/j.eswa.2010.06.012","volume":"37","author":"X Li","year":"2010","unstructured":"Li X, Deng Z-H (2010) Mining frequent patterns from network flows for monitoring network. Expert Syst Appl 37:8850\u20138860","journal-title":"Expert Syst Appl"},{"key":"1263_CR55","doi-asserted-by":"crossref","unstructured":"Shahrestani A, Feily M, Ahmad R, Ramadass S (2009) Architecture for applying data mining and visualization on network flow for botnet traffic detection. In: The proceedings of the international conference on computer technology and development, pp 33\u201337","DOI":"10.1109\/ICCTD.2009.82"},{"key":"1263_CR56","doi-asserted-by":"crossref","unstructured":"Barford P, Plonka D (2001) Characteristics of network traffic flow anomalies. In: The proceedings of the ACM SIGCOMM workshop on Internet measurement, pp 69\u201373","DOI":"10.1145\/505202.505211"},{"key":"1263_CR57","doi-asserted-by":"crossref","unstructured":"Chapple MJ, Wright TE, Winding RM (2006) Flow anomaly detection in firewalled networks. In: The proceedings of the securecomm and workshops, pp 1\u20136","DOI":"10.1109\/SECCOMW.2006.359576"},{"key":"1263_CR58","unstructured":"Muraleedharan N, Parmar A, Kumar M (2010) A flow based anomaly detection system using Chi square technique. In: The proceedings of the IEEE international conference on advance computing, pp 285\u2013289"},{"key":"1263_CR59","doi-asserted-by":"crossref","first-page":"319","DOI":"10.1016\/S0925-2312(02)00570-2","volume":"50","author":"P RoyChowdhury","year":"2003","unstructured":"RoyChowdhury P, Shukla KK (2003) Incorporating fuzzy concepts along with dynamic tunneling for fast and robust training of multilayer perceptrons. Neurocomputing 50:319\u2013340","journal-title":"Neurocomputing"},{"key":"1263_CR60","first-page":"762","volume":"1","author":"DJ Montana","year":"1989","unstructured":"Montana DJ, Davis L (1989) Training feed forward neural networks using genetic algorithms. Mach Learn 1:762\u2013767","journal-title":"Mach Learn"},{"key":"1263_CR61","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1016\/0925-2312(95)00088-7","volume":"13","author":"Q Zhao","year":"1996","unstructured":"Zhao Q, Higuchi T (1996) Efficient learning of NN-MLP based on individual evolutionary algorithm. Neurocomputing 13:201\u2013215","journal-title":"Neurocomputing"},{"key":"1263_CR62","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1016\/S0167-9236(00)00086-5","volume":"30","author":"RS Sexton","year":"2000","unstructured":"Sexton RS, Dorsey RE (2000) Reliable classification using neural network: a genetic algorithm and back propagation computation. Decis Support Syst 30:11\u201322","journal-title":"Decis Support Syst"},{"key":"1263_CR63","doi-asserted-by":"crossref","first-page":"732","DOI":"10.1016\/j.engappai.2009.01.013","volume":"22","author":"M Castellani","year":"2009","unstructured":"Castellani M, Rowlands H (2009) Evolutionary artificial neural network design and training for wood veneer classification. Eng Appl Artif Intell 22:732\u2013741","journal-title":"Eng Appl Artif Intell"},{"key":"1263_CR64","doi-asserted-by":"crossref","first-page":"1452","DOI":"10.1016\/j.patrec.2007.03.004","volume":"28","author":"T Marwala","year":"2007","unstructured":"Marwala T (2007) Bayesian training of neural networks using genetic programming. Pattern Recogn Lett 28:1452\u20131458","journal-title":"Pattern Recogn Lett"},{"key":"1263_CR65","doi-asserted-by":"crossref","first-page":"207","DOI":"10.1016\/0925-2312(91)90003-T","volume":"3","author":"S Amato","year":"1991","unstructured":"Amato S, Apolloni B, Caporali G, Madesani U, Zanaboni A (1991) Simulated annealing approach in backpropagation. Neurocomputing 3:207\u2013220","journal-title":"Neurocomputing"},{"key":"1263_CR66","doi-asserted-by":"crossref","unstructured":"Pasti R, De Castro LN (2007) The influence of diversity in an immune-based algorithm to train MLP networks. In: The proceedings of the international conference on artificial immune systems, pp 71\u201382","DOI":"10.1007\/978-3-540-73922-7_7"},{"key":"1263_CR67","unstructured":"Marcio C, Teresa BL (2006) An analysis of PSO hybrid algorithms for feed-forward neural networks training. In: The proceedings of the Brazilian symposium on neural networks, pp 2\u20137"},{"key":"1263_CR68","doi-asserted-by":"crossref","first-page":"8450","DOI":"10.1016\/j.eswa.2010.05.033","volume":"37","author":"T Ince","year":"2010","unstructured":"Ince T, Kiranyaz S, Pulkkinen J, Gabbouj M (2010) Evaluation of global and local training techniques over feed-forward neural network architecture spaces for computer-aided medical diagnosis. Expert Syst Appl 37:8450\u20138461","journal-title":"Expert Syst Appl"},{"key":"1263_CR69","doi-asserted-by":"crossref","first-page":"626","DOI":"10.1016\/j.phpro.2012.02.092","volume":"24","author":"Z Pian","year":"2012","unstructured":"Pian Z, Li S, Zhang H, Zhang N (2012) The application of the PSO based BP network in short-term load forecasting. Phys Procedia 24:626\u2013632","journal-title":"Phys Procedia"},{"key":"1263_CR70","doi-asserted-by":"crossref","first-page":"1054","DOI":"10.1016\/j.neucom.2007.10.013","volume":"71","author":"J Yu","year":"2008","unstructured":"Yu J, Wang S, Xi L (2008) Evolving artificial neural networks using an improved PSO and DPSO. Neurocomputing 71:1054\u20131060","journal-title":"Neurocomputing"},{"key":"1263_CR71","doi-asserted-by":"crossref","first-page":"2707","DOI":"10.1016\/j.asoc.2012.03.022","volume":"12","author":"MA Cavuslu","year":"2012","unstructured":"Cavuslu MA, Karakuzu C, Karakaya F (2012) Neural identification of dynamic systems on FPGA with improved PSO learning. Appl Soft Comput 12:2707\u20132718","journal-title":"Appl Soft Comput"},{"key":"1263_CR72","doi-asserted-by":"crossref","first-page":"378","DOI":"10.1016\/j.knosys.2010.11.001","volume":"24","author":"W Shen","year":"2011","unstructured":"Shen W, Guo X, Wu C, Wu D (2011) Forecasting stock indices using radial basis function neural networks optimized by artificial swarm algorithm. Knowl Based Syst 24:378\u2013385","journal-title":"Knowl Based Syst"},{"key":"1263_CR73","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1016\/j.engappai.2011.07.006","volume":"25","author":"S Kulluk","year":"2012","unstructured":"Kulluk S, Ozbakir L, Baykasoglu A (2012) Training neural networks with harmony search algorithms for classification problems. Eng Appl Artif Intell 25:11\u201319","journal-title":"Eng Appl Artif Intell"},{"key":"1263_CR74","doi-asserted-by":"crossref","first-page":"11125","DOI":"10.1016\/j.amc.2012.04.069","volume":"218","author":"SA Mirjalili","year":"2012","unstructured":"Mirjalili SA, Mohd Hashim SZ, Moradian Sardroudi H (2012) Training feedforward neural networks using hybrid particle swarm optimization and gravitational search algorithm. Appl Math Comput 218:11125\u201311137","journal-title":"Appl Math Comput"},{"key":"1263_CR75","doi-asserted-by":"crossref","first-page":"913","DOI":"10.1016\/j.atmosenv.2005.10.042","volume":"40","author":"D Wang","year":"2006","unstructured":"Wang D, Lu W-Z (2006) Forecasting of ozone level in time series using MLP model with a novel hybrid training algorithm. Atmos Environ 40:913\u2013924","journal-title":"Atmos Environ"},{"key":"1263_CR76","doi-asserted-by":"crossref","first-page":"1026","DOI":"10.1016\/j.amc.2006.07.025","volume":"185","author":"JR Zhang","year":"2007","unstructured":"Zhang JR, Zhang J, Lok TM, Lyu MR (2007) A hybrid particle swarm optimization-back propagation algorithm for feedforward neural network training. Appl Math Comput 185:1026\u20131037","journal-title":"Appl Math Comput"},{"key":"1263_CR77","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1016\/j.eswa.2011.07.028","volume":"39","author":"SYS Leung","year":"2012","unstructured":"Leung SYS, Tang Y, Wong WK (2012) A hybrid particle swarm optimization and its application in neural networks. Exp Syst Appl 39:395\u2013405","journal-title":"Exp Syst Appl"},{"key":"1263_CR78","doi-asserted-by":"crossref","first-page":"819","DOI":"10.1016\/j.asoc.2011.10.008","volume":"12","author":"A Bahrololoum","year":"2012","unstructured":"Bahrololoum A, Nezamabadi-pour H, Bahrololoum H, Saeed M (2012) A prototype classifier based on gravitational search algorithm. Appl Soft Comput 12:819\u2013825","journal-title":"Appl Soft Comput"},{"key":"1263_CR79","doi-asserted-by":"crossref","unstructured":"Ou C, Lin W (2006) Comparison between PSO and GA for parameters optimization of PID controller. In: The proceedings of the IEEE international conference on mechatronics and automation, pp 2471\u20132475","DOI":"10.1109\/ICMA.2006.257739"},{"key":"1263_CR80","doi-asserted-by":"crossref","first-page":"2232","DOI":"10.1016\/j.ins.2009.03.004","volume":"179","author":"E Rashedi","year":"2009","unstructured":"Rashedi E, Nezamabadi-pour H, Saryazdi S (2009) GSA: a gravitational search algorithm. Inf Sci 179:2232\u20132248","journal-title":"Inf Sci"},{"key":"1263_CR81","unstructured":"Nguyen HA, Tam Van Nguyen T, Kim DI, Choi D (2008) Network traffic anomalies detection and identification with flow monitoring. In: The proceedings of the IFIP international conference on wireless and optical communications networks, pp 1\u20135"},{"key":"1263_CR82","unstructured":"Chang S, Qiu X, Gao Z, Liu K, Qi F (2010) A flow-based anomaly detection method using sketch and combinations of traffic features. In: The proceedings of the international conference on network and service management, pp 302\u2013305"},{"key":"1263_CR83","doi-asserted-by":"crossref","first-page":"1282","DOI":"10.1016\/j.comnet.2009.10.016","volume":"54","author":"Z Li","year":"2010","unstructured":"Li Z, Gao Y, Chen Y (2010) HiFIND: a high-speed flow-level intrusion detection approach with DoS resiliency. Comput Netw 54:1282\u20131299","journal-title":"Comput Netw"},{"key":"1263_CR84","unstructured":"Gao Y, Li Z, Chen Y (2006) A DoS resilient flow-level intrusion detection approach for high-speed networks. In: The proceedings of the IEEE international conference on distributed computing systems, pp 39\u201346"},{"key":"1263_CR85","unstructured":"Sui S, Li l, Manikopoulo CN (2006) Flow-based statistical aggregation schemes for network anomaly detection. In: The proceedings of the IEEE international conference on networking, sensing and control, pp 786\u2013791"},{"key":"1263_CR86","doi-asserted-by":"crossref","first-page":"276","DOI":"10.1016\/j.cose.2008.12.003","volume":"28","author":"H Choi","year":"2009","unstructured":"Choi H, Lee H, Kim H (2009) Fast detection and visualization of network attacks on parallel coordinates. Comput Secur 28:276\u2013288","journal-title":"Comput Secur"},{"key":"1263_CR87","doi-asserted-by":"crossref","first-page":"451","DOI":"10.1016\/j.peva.2010.01.001","volume":"67","author":"M Soysal","year":"2010","unstructured":"Soysal M, Schmidt EG (2010) Machine learning algorithms for accurate flow-based network traffic classification: evaluation and comparison. Perform Evaluat 67:451\u2013467","journal-title":"Perform Evaluat"},{"key":"1263_CR88","unstructured":"Chen Y, Dai L, Cheng X-Q (2008) GATS-C4.5: an algorithm for optimizing features in flow classification. In: The proceedings of the IEEE international conference on consumer communications and networking, pp 466\u2013470"},{"key":"1263_CR89","doi-asserted-by":"crossref","first-page":"2453","DOI":"10.1016\/S0305-0548(03)00198-9","volume":"31","author":"HF Wang","year":"2004","unstructured":"Wang HF, Wu KY (2004) Hybrid genetic algorithm for optimization problems with permutation property. Comput Oper Res 31:2453\u20132471","journal-title":"Comput Oper Res"},{"key":"1263_CR90","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1016\/S0965-9978(00)00070-3","volume":"32","author":"J Andre","year":"2001","unstructured":"Andre J, Siarry P, Dognon T (2001) An improvement of the standard genetic algorithm fighting premature convergence in continuous optimization. Adv Eng Softw 32:49\u201360","journal-title":"Adv Eng Softw"},{"key":"1263_CR91","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1016\/0305-0548(93)E0024-N","volume":"22","author":"PW Poon","year":"1995","unstructured":"Poon PW, Carter JN (1995) Genetic algorithm crossover operations for ordering applications. Comput Oper Res 22:135\u2013147","journal-title":"Comput Oper Res"},{"key":"1263_CR92","doi-asserted-by":"crossref","first-page":"1157","DOI":"10.1016\/S0890-6955(03)00105-6","volume":"43","author":"X Wen","year":"2003","unstructured":"Wen X, Song A (2003) An improved genetic algorithm for planar and spatial straightness error evaluation. Int J Mach Tools Manuf 43:1157\u20131162","journal-title":"Int J Mach Tools Manuf"},{"key":"1263_CR93","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1016\/j.ress.2009.09.001","volume":"95","author":"Z Ye","year":"2010","unstructured":"Ye Z, Li Z, Xie M (2010) Some improvements on adaptive genetic algorithms for reliability-related applications. Reliab Eng Syst Saf 95:120\u2013126","journal-title":"Reliab Eng Syst Saf"},{"key":"1263_CR94","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1016\/j.amc.2007.03.047","volume":"193","author":"Y Jiang","year":"2007","unstructured":"Jiang Y, Hu T, Huang C, Wu X (2007) An improved particle swarm optimization algorithm. Appl Math Comput 193:231\u2013239","journal-title":"Appl Math Comput"},{"key":"1263_CR95","doi-asserted-by":"crossref","first-page":"615","DOI":"10.1016\/j.epsr.2008.08.013","volume":"79","author":"G Baskar","year":"2009","unstructured":"Baskar G, Mohan MR (2009) Contingency constrained economic load dispatch using improved particle swarm optimization for security enhancement. Electric Power Syst Res 79:615\u2013621","journal-title":"Electric Power Syst Res"},{"key":"1263_CR96","doi-asserted-by":"crossref","first-page":"324","DOI":"10.1016\/j.asoc.2007.01.010","volume":"8","author":"MS Arumugam","year":"2008","unstructured":"Arumugam MS, Rao MVC (2008) On the improved performances of the particle swarm optimization algorithms with adaptive parameters, cross-over operators and root mean square (RMS) variants for computing optimal control of a class of hybrid systems. Appl Soft Comput 8:324\u2013336","journal-title":"Appl Soft Comput"},{"key":"1263_CR97","unstructured":"Lin H-C, Chen C-M, Tzeng J-Y (2009) Flow based botnet detection. In: The proceedings of the international conference on innovative computing, information and control, pp 1538\u20131541"},{"key":"1263_CR98","doi-asserted-by":"crossref","unstructured":"Lee M, Shon T, Cho K, Chung M, Seo J, Moon J (2007) An approach for classifying internet worms based on temporal behaviors and packet flows. In: The proceedings of the international conference on intelligent computing, pp 646\u2013655","DOI":"10.1007\/978-3-540-74171-8_64"},{"key":"1263_CR99","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1007\/978-3-642-04968-2_4","volume":"5843","author":"A Sperotto","year":"2009","unstructured":"Sperotto A, Sadre R, van Vilet F, Pras A (2009) A labeled data set for flow-based intrusion detection. Lect Notes Comput Sci 5843:39\u201350","journal-title":"Lect Notes Comput Sci"},{"key":"1263_CR100","doi-asserted-by":"crossref","unstructured":"Case J, Fedor M, Schoffstall M, Davin J (1990) Simple network management protocol (SNMP). RFC 1157. www.ietf.org\/rfc\/rfc1157.txt","DOI":"10.17487\/rfc1157"},{"key":"1263_CR101","unstructured":"Conta Transwitch A, Deering S (2006) Internet control message protocol (ICMPv6) for the Internet protocol version 6 (IPv6) specification. RFC 4443. tools.ietf.org\/html\/rfc4443"},{"key":"1263_CR102","unstructured":"Richardson M, Fenner B (1999) tcpdump packet analyzer. http:\/\/www.tcpdump.org"},{"key":"1263_CR103","unstructured":"Cisco Systems (2011) NetFlow services solutions guide. http:\/\/www.cisco.com"},{"key":"1263_CR104","unstructured":"Cisco Systems (2008) Cisco IOS NetFlow configuration guide, release 12.4. http:\/\/www.cisco.com"},{"key":"1263_CR105","unstructured":"Claise B (2008) Cisco systems NetFlow services export version 9. RFC 3954 (Informational). http:\/\/www.ietf.org\/rfc\/rfc3954.txt"},{"key":"1263_CR106","doi-asserted-by":"crossref","unstructured":"Claise B (2008) Specification of the IP flow information export (IPFIX) protocol for the exchange of IP traffic flow information. RFC 5101. http:\/\/www.ietf.org\/rfc\/rfc5101.txt","DOI":"10.17487\/rfc5101"},{"key":"1263_CR107","doi-asserted-by":"crossref","unstructured":"Quittek J, Zseby T, Claise B, Zander S (2008) Requirements for IP flow information export (IPFIX). RFC 3917 (Informational). http:\/\/www.ietf.org\/rfc\/rfc3917.txt","DOI":"10.17487\/rfc5102"},{"key":"1263_CR108","doi-asserted-by":"crossref","unstructured":"Song S, Chen Z (2007) Adaptive network flow clustering. In: The proceedings of the IEEE international conference on networking, sensing and control, pp 596\u2013601","DOI":"10.1109\/ICNSC.2007.372846"},{"key":"1263_CR109","unstructured":"Pouget F, Dacier M (2004) Honeypot-based forensics. In: The proceedings of the Asia Pacific information technology security conference, pp 1\u201315"},{"key":"1263_CR110","doi-asserted-by":"crossref","unstructured":"Dressler F, Munz G (2006) Flexible flow aggregation for adaptive network monitoring. In: The proceedings of the IEEE international conference on local computer networks, pp 702\u2013709","DOI":"10.1109\/LCN.2006.322180"},{"key":"1263_CR111","doi-asserted-by":"crossref","unstructured":"Ylonen T (2006) The secure shell (SSH) protocol architecture. http:\/\/www.ietf.org\/rfc\/rfc4251.txt","DOI":"10.17487\/rfc4251"},{"key":"1263_CR112","doi-asserted-by":"crossref","unstructured":"Ramakrishnan K, Floyd S, Black D (2001) The addition of explicit congestion notification (ECN) to IP. RFC 3168. http:\/\/www.ietf.org\/rfc\/rfc3168.txt","DOI":"10.17487\/rfc3168"},{"key":"1263_CR113","doi-asserted-by":"crossref","first-page":"539","DOI":"10.1016\/j.scient.2011.04.003","volume":"18","author":"S Sarafrazi","year":"2011","unstructured":"Sarafrazi S, Nezamabadi-pour H, Saryazdi S (2011) Disruption: a new operator in gravitational search algorithm. Sci Iranica D 18:539\u2013548","journal-title":"Sci Iranica D"},{"key":"1263_CR114","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4757-2928-3","volume-title":"The astrophysical concepts","author":"M Harwit","year":"1998","unstructured":"Harwit M (1998) The astrophysical concepts, 3rd edn. Springer, New York","edition":"3"},{"key":"1263_CR115","doi-asserted-by":"crossref","unstructured":"Kennedy J, Eberhart R (1995) Particle swarm optimization. In: The proceedings of the IEEE international conference on neural networks, vol 4, pp 1942\u20131948","DOI":"10.1109\/ICNN.1995.488968"},{"key":"1263_CR116","doi-asserted-by":"crossref","unstructured":"Shi Y, Eberhart R (1998) Parameter selection in particle swarm optimization. In: The proceedings of international conference on evolutionary programming, pp 591\u2013601","DOI":"10.1007\/BFb0040810"},{"key":"1263_CR117","volume-title":"Machine learning and data mining for computer security: methods and applications","author":"MA Maloof","year":"2005","unstructured":"Maloof MA (2005) Machine learning and data mining for computer security: methods and applications. Springer, New York"},{"key":"1263_CR118","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"Shiravi A, Shiravi H, Tavallaee M, Ghorbani AA (2012) Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput Secur 31:357\u2013374","journal-title":"Comput Secur"},{"key":"1263_CR119","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1016\/j.neucom.2011.02.021","volume":"75","author":"JZ Lei","year":"2012","unstructured":"Lei JZ, Ghorbani AA (2012) Improved competitive learning neural networks for network intrusion and fraud detection. Neurocomputing 75:135\u2013145","journal-title":"Neurocomputing"},{"key":"1263_CR120","doi-asserted-by":"crossref","unstructured":"Perdisci R, Ariu D, Giacinto G (2012) Scalable fine-grained behavioral clustering of HTTP-based malware. Computer networks. Article in press, available online 8 Aug 2012. doi: 10.1016\/j.comnet.2012.06.022","DOI":"10.1016\/j.comnet.2012.06.022"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-012-1263-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00521-012-1263-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-012-1263-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,5]],"date-time":"2019-07-05T16:25:26Z","timestamp":1562343926000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00521-012-1263-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,11,15]]},"references-count":120,"journal-issue":{"issue":"3-4","published-print":{"date-parts":[[2014,3]]}},"alternative-id":["1263"],"URL":"https:\/\/doi.org\/10.1007\/s00521-012-1263-0","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,11,15]]}}}