{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T17:01:58Z","timestamp":1774630918494,"version":"3.50.1"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"23","license":[{"start":{"date-parts":[[2020,4,30]],"date-time":"2020-04-30T00:00:00Z","timestamp":1588204800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,4,30]],"date-time":"2020-04-30T00:00:00Z","timestamp":1588204800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2020,12]]},"DOI":"10.1007\/s00521-020-04914-7","type":"journal-article","created":{"date-parts":[[2020,4,30]],"date-time":"2020-04-30T16:38:11Z","timestamp":1588264691000},"page":"17169-17179","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":39,"title":["A semi-self-taught network intrusion detection system"],"prefix":"10.1007","volume":"32","author":[{"given":"Feng","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jia","family":"Peng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaohong","family":"Zhuang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sang-Gyun","family":"Na","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,4,30]]},"reference":[{"issue":"1","key":"4914_CR1","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1109\/MITP.2013.7","volume":"15","author":"C Sample","year":"2013","unstructured":"Sample C, Schaffer K (2013) An overview of anomaly detection\u2014IEEE Journals & Magazine. IT Prof 15(1):8\u201311","journal-title":"IT Prof"},{"key":"4914_CR2","unstructured":"Rudd E et al (2016) A survey of stealth malware: attacks, mitigation measures, and steps toward autonomous open world solutions. arXiv preprint arXiv:1603.06028"},{"key":"4914_CR3","doi-asserted-by":"crossref","unstructured":"Novikov D, Yampolskiy RV, Reznik L, (2006) Anomaly detection based intrusion detection. In: Proceedings of the third international conference on information technology: new generations, 10\u201312 April. IEEE Xplore Press, Las Vegas, pp 420\u2013425","DOI":"10.1109\/ITNG.2006.33"},{"issue":"9","key":"4914_CR4","doi-asserted-by":"publisher","first-page":"3372","DOI":"10.1109\/TSP.2006.879308","volume":"54","author":"AG Tartakovsky","year":"2006","unstructured":"Tartakovsky AG, Rozovskii BL, Blazek RB, Kim H (2006) A novel approach to detection of intrusions in computer networks via adaptive sequential and batch-sequential change-point detection methods. IEEE Trans Signal Process 54(9):3372\u20133382","journal-title":"IEEE Trans Signal Process"},{"issue":"3","key":"4914_CR5","doi-asserted-by":"publisher","first-page":"391","DOI":"10.3844\/jcssp.2013.391.403","volume":"9","author":"A Dahlia","year":"2013","unstructured":"Dahlia A, Zainaddin A, Hanapi ZM (2013) Hybrid of fuzzy clustering neural network over nsl dataset for intrusion detection system. J Comput Sci 9(3):391\u2013403. https:\/\/doi.org\/10.3844\/jcssp.2013.391.403","journal-title":"J Comput Sci"},{"issue":"06","key":"4914_CR6","first-page":"2197","volume":"2","author":"K Bharti","year":"2010","unstructured":"Bharti K, Jain S, Shukla S (2010) Fuzzy K-mean clustering via random forest for intrusiion detection system. Int J Comput Sci Eng 2(06):2197\u20132200","journal-title":"Int J Comput Sci Eng"},{"key":"4914_CR7","first-page":"10","volume":"7","author":"A Almubayed","year":"2015","unstructured":"Almubayed A, Hadi A, Atoum J (2015) A model for detecting tor encrypted traffic using supervised machine learning, I. J Comput Netw Inf Secur 7:10\u201323","journal-title":"J Comput Netw Inf Secur"},{"key":"4914_CR8","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1109\/TSMCB.2005.860136","volume":"36","author":"H Sang-Jun","year":"2005","unstructured":"Sang-Jun H, Sung-Bae C (2005) Evolutionary neural networks for anomaly detection based on the behavior of a program. IEEE Trans Syst Man Cybern 36:559\u2013570","journal-title":"IEEE Trans Syst Man Cybern"},{"key":"4914_CR9","first-page":"2721","volume":"7","author":"JZ Kolter","year":"2006","unstructured":"Kolter JZ, Maloof MA (2006) Learning to detect and classify malicious executables in the wild. J ML Res 7:2721\u20132744","journal-title":"J ML Res"},{"key":"4914_CR10","unstructured":"Hsu C-H, Huang C-Y, Chen K-T (2010) Fast-flux bot detection in real time. In: 13th International conference on recent advances in intrusion detection, ser. RAID\u201910"},{"issue":"6","key":"4914_CR11","first-page":"2389","volume":"22","author":"E Soltanaghaei","year":"2015","unstructured":"Soltanaghaei E, Kharrazi M (2015) Detection of fast-flux botnets through DNS traffic analysis. Sci Iran 22(6):2389","journal-title":"Sci Iran"},{"key":"4914_CR12","doi-asserted-by":"crossref","unstructured":"Gardiner J, Nagaraja S (2014) On the reliability of network measurement techniques used for malware traffic analysis. In: Security protocols XXII, pp 321\u2013333","DOI":"10.1007\/978-3-319-12400-1_31"},{"issue":"9","key":"4914_CR13","first-page":"967","volume":"5","author":"EH Cheon","year":"2013","unstructured":"Cheon EH, Huang Z, Lee YS (2013) Preventing SQL injection attack based on machine learning. Int J Adv Comput Technol 5(9):967\u2013974","journal-title":"Int J Adv Comput Technol"},{"key":"4914_CR14","doi-asserted-by":"crossref","unstructured":"Burguera I, Zurutuza U, Nadjm-Tehrani S (2011) Crowdroid: behavior-based malware detection system for android. In: 1st ACM workshop on SPSM. ACM, pp 15\u201326","DOI":"10.1145\/2046614.2046619"},{"key":"4914_CR15","doi-asserted-by":"crossref","unstructured":"Yeo M et al (2018) Flow-based malware detection using convolutional neural network. In: 2018 International conference on information networking (ICOIN), Chiang Mai, pp 910\u2013913","DOI":"10.1109\/ICOIN.2018.8343255"},{"key":"4914_CR16","doi-asserted-by":"crossref","unstructured":"Sethi K, Kumar R, Sethi L, Bera P, Patra PK (2019) A novel machine learning based malware detection and classification framework. In: 2019 International conference on cyber security and protection of digital services (cyber security), Oxford, pp 1\u20134","DOI":"10.1109\/CyberSecPODS.2019.8885196"},{"key":"4914_CR17","doi-asserted-by":"crossref","unstructured":"Halimaa A, Sundarakantham K (2019) Machine learning based intrusion detection system. In: 2019 3rd international conference on trends in electronics and informatics (ICOEI), Tirunelveli, pp 916\u2013920","DOI":"10.1109\/ICOEI.2019.8862784"},{"key":"4914_CR18","doi-asserted-by":"crossref","unstructured":"Dalvi N, Domingos P, Sanghai S, Verma D (2004) Adversarial classification. In Proceedings of the tenth ACM SIGKDD international conference on knowledge discovery and data mining (KDD), Seattle, 22\u201325 Aug 2004, pp 99\u2013108","DOI":"10.1145\/1014052.1014066"},{"key":"4914_CR19","doi-asserted-by":"crossref","unstructured":"Blount JJ, Tauritz DR, Mulder DR (2011) Adaptive rule-based malware detection employing learning classifier systems: a proof of concept. In: 2011 IEEE 35th annual computer software and applications conference workshops, Munich, pp 110\u2013115","DOI":"10.1109\/COMPSACW.2011.28"},{"key":"4914_CR20","doi-asserted-by":"crossref","unstructured":"Lee P, Clark A, Alomair B, Bushnell L, Poovendran R (2016) Distributed adaptive patching strategies against malware propagation: a passivity approach. In: 2016 IEEE 55th conference on decision and control (CDC), Las Vegas, pp 2587\u20132594","DOI":"10.1109\/CDC.2016.7798652"},{"key":"4914_CR21","doi-asserted-by":"crossref","unstructured":"Ali MH, Fadlizolkipi M, Firdaus A, Khidzir NZ (2018) A hybrid particle swarm optimization\u2014extreme learning machine approach for intrusion detection system. In: 2018 IEEE student conference on research and development (SCOReD), Selangor, pp 1\u20134","DOI":"10.1109\/SCORED.2018.8711287"},{"key":"4914_CR22","doi-asserted-by":"crossref","unstructured":"Usama M, Asim M, Latif S, Qadir J, Ala-Al-Fuqaha (2019) Generative adversarial networks for launching and thwarting adversarial attacks on network intrusion detection systems. In: 2019 15th international wireless communications & mobile computing conference (IWCMC), Tangier, pp 78\u201383","DOI":"10.1109\/IWCMC.2019.8766353"},{"key":"4914_CR23","doi-asserted-by":"crossref","unstructured":"Al-Dujaili A, Huang A, Hemberg E, O\u2019Reilly U (2018) Adversarial deep learning for robust detection of binary encoded malware. In: 2018 IEEE security and privacy workshops (SPW), San Francisco, pp 76\u201382","DOI":"10.1109\/SPW.2018.00020"},{"key":"4914_CR24","doi-asserted-by":"crossref","unstructured":"Haffner P, Sen S, Spatscheck O, Wang D (2005) ACAS: automated construction of application signatures. In: Proceedings of the ACM SIGCOMM, pp 197\u2013202","DOI":"10.1145\/1080173.1080183"},{"key":"4914_CR25","unstructured":"Guntuku SC, Narang P, Hota C (2013) Real-time peer-to-peer botnet detection framework based on Bayesian regularized neural network. arXiv:1307.7464 [cs.NI]"},{"issue":"9","key":"4914_CR26","doi-asserted-by":"publisher","first-page":"1058","DOI":"10.1093\/comjnl\/bxr131","volume":"55","author":"J Gou","year":"2012","unstructured":"Gou J, Yi Z, Du L, Xiong T (2012) A local mean-based k-nearest centroid neighbor classifier. Comput J 55(9):1058\u20131071","journal-title":"Comput J"},{"key":"4914_CR27","doi-asserted-by":"crossref","unstructured":"Shah S, Singh M (2012) Comparison of a time efficient modified K-mean algorithm with K-mean and K-medoid algorithm. In: 2012 International conference on communication systems and network technologies, Rajkot, pp 435\u2013437","DOI":"10.1109\/CSNT.2012.100"},{"key":"4914_CR28","doi-asserted-by":"crossref","unstructured":"Chen Z, Yeo CK, Lee BS, Lau CT (2018) Autoencoder-based network anomaly detection. In: 2018 Wireless telecommunications symposium (WTS), Phoenix, pp 1\u20135","DOI":"10.1109\/WTS.2018.8363930"},{"key":"4914_CR29","unstructured":"Chapelle O, Sch\u00f6lkopf B, Zien A (2006) Semi-supervised learning in practice. In Semi-supervised learning, MITP, pp 331\u2013331"},{"key":"4914_CR30","volume-title":"Deep learning","author":"I Goodfellow","year":"2016","unstructured":"Goodfellow I, Bengio Y, Courville A (2016) Deep learning. MIT Press, Cambridge"},{"key":"4914_CR31","volume-title":"Mathematical statistics with applications","author":"D Wackerly","year":"2008","unstructured":"Wackerly D, Mendenhall W, Scheaffer RL (2008) Mathematical statistics with applications, 7th edn. Thomson Higher Education, Belmont","edition":"7"},{"key":"4914_CR32","doi-asserted-by":"crossref","unstructured":"El-Khamy SE, Sadek RA, El-Khoreby MA (2015) An efficient brain mass detection with adaptive clustered based fuzzy C-mean and thresholding. In: 2015 IEEE international conference on signal and image processing applications (ICSIPA), pp 429\u2013433","DOI":"10.1109\/ICSIPA.2015.7412229"},{"key":"4914_CR33","unstructured":"https:\/\/www.unb.ca\/cic\/datasets\/ids-2018.html"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-020-04914-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-020-04914-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-020-04914-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,30]],"date-time":"2021-04-30T00:11:54Z","timestamp":1619741514000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-020-04914-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,4,30]]},"references-count":33,"journal-issue":{"issue":"23","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["4914"],"URL":"https:\/\/doi.org\/10.1007\/s00521-020-04914-7","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,4,30]]},"assertion":[{"value":"2 March 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 April 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 April 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"The author declares that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}