{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T00:35:01Z","timestamp":1781656501577,"version":"3.54.5"},"reference-count":22,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2021,5,12]],"date-time":"2021-05-12T00:00:00Z","timestamp":1620777600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,5,12]],"date-time":"2021-05-12T00:00:00Z","timestamp":1620777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["833115"],"award-info":[{"award-number":["833115"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Pattern Anal Applic"],"published-print":{"date-parts":[[2021,11]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The Internet of Things (IoT) appliances often expose sensitive data, either directly or indirectly. They may, for instance, tell whether you are at home right now or what your long or short-term habits are. Therefore, it is crucial to protect such devices against adversaries and has in place an early warning system which indicates compromised devices in a quick and efficient manner. In this paper, we propose time window embedding solutions that efficiently process a massive amount of data and have a low-memory-footprint at the same time. On top of the proposed embedding vectors, we use the core anomaly detection unit. It is a classifier that is based on the transformer\u2019s encoder component followed by a feed-forward neural network. We have compared the proposed method with other classical machine-learning algorithms. Therefore, in the paper, we formally evaluate various machine-learning schemes and discuss their effectiveness in the IoT-related context. Our proposal is supported by detailed experiments that have been conducted on the recently published Aposemat IoT-23 dataset.<\/jats:p>","DOI":"10.1007\/s10044-021-00980-2","type":"journal-article","created":{"date-parts":[[2021,5,12]],"date-time":"2021-05-12T06:10:04Z","timestamp":1620799804000},"page":"1441-1449","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":56,"title":["A new method of hybrid time window embedding with transformer-based traffic data classification in IoT-networked environment"],"prefix":"10.1007","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7122-3306","authenticated-orcid":false,"given":"Rafa\u0142","family":"Kozik","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5881-6406","authenticated-orcid":false,"given":"Marek","family":"Pawlicki","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1405-9911","authenticated-orcid":false,"given":"Micha\u0142","family":"Chora\u015b","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,5,12]]},"reference":[{"key":"980_CR1","doi-asserted-by":"crossref","unstructured":"Andrysiak T, Saganowski \u0141, Chora\u015b M, Kozik R (2014) Network traffic prediction and anomaly detection based on arfima model. In: International Joint Conference SOCO\u201914-CISIS\u201914-ICEUTE\u201914, pp. 545\u2013554. Springer","DOI":"10.1007\/978-3-319-07995-0_54"},{"key":"980_CR2","unstructured":"BitDefender: Ring video doorbell pro under the scope (2019). https:\/\/www.bitdefender.com\/files\/News\/CaseStudies\/study\/294\/Bitdefender-WhitePaper-RDoor-CREA3949-en-EN-GenericUse.pdf"},{"key":"980_CR3","doi-asserted-by":"crossref","unstructured":"Caviglione L, Chora\u015b M, Corona I, Janicki A, Mazurczyk W, Pawlicki M, Wasielewska K (2020) Tight arms race: overview of current malware threats and trends in their detection. IEEE Access","DOI":"10.1109\/ACCESS.2020.3048319"},{"key":"980_CR4","doi-asserted-by":"crossref","unstructured":"Cheng Z, Beshley M, Beshley H, Kochan O, Urikova O (2020) Development of deep packet inspection system for network traffic analysis and intrusion detection. In: 2020 IEEE 15th International Conference on Advanced Trends in Radioelectronics, Telecommunications and Computer Engineering (TCSET), pp. 877\u2013881","DOI":"10.1109\/TCSET49122.2020.235562"},{"key":"980_CR5","doi-asserted-by":"crossref","unstructured":"Chora\u015b M, Pawlicki M (2020) Intrusion detection approach based on optimised artificial neural network. Neurocomputing","DOI":"10.1016\/j.neucom.2020.07.138"},{"key":"980_CR6","doi-asserted-by":"crossref","unstructured":"Claise B (2004) Cisco systems netflow services export version 9. rfc 3954 (informational)","DOI":"10.17487\/rfc3954"},{"key":"980_CR7","unstructured":"F-Secure: the f-secure attack landscape report H1-2020 (2020). https:\/\/www.f-secure.com\/content\/dam\/press\/de\/media-library\/reports\/F-Secure-attack-landscape-h12020.pdf"},{"key":"980_CR8","doi-asserted-by":"crossref","unstructured":"Flanagan K, Fallon E, Awad A, Connolly P (2017) Self-configuring netflow anomaly detection using cluster density analysis. In: 2017 19th International Conference on Advanced Communication Technology (ICACT), pp. 421\u2013427","DOI":"10.23919\/ICACT.2017.7890124"},{"key":"980_CR9","doi-asserted-by":"crossref","unstructured":"Fu R, Zhang Z, Li L (2016) Using lstm and gru neural network methods for traffic flow prediction. In: 2016 31st Youth Academic Annual Conference of Chinese Association of Automation (YAC), pp. 324\u2013328","DOI":"10.1109\/YAC.2016.7804912"},{"key":"980_CR10","unstructured":"Garcia S (2014) dentifying, modeling and detecting botnet behaviors in the network. Ph.D. thesis, Instituto Superior de Ingenier\u2019\u0131a de Software Tandil Departamento de Computacio\u2019n y Sistemas"},{"key":"980_CR11","doi-asserted-by":"crossref","unstructured":"Hardegen C, Pf\u00fclb B, Rieger S, Gepperth A (2020) Predicting network flow characteristics using deep learning and real-world network traffic. IEEE Transactions on Network and Service Management pp. 1\u20131","DOI":"10.23919\/CNSM46954.2019.9012716"},{"key":"980_CR12","doi-asserted-by":"crossref","unstructured":"Komisarek M, Chora\u015b M, Kozik R, Pawlicki M (2020) Real-time stream processing tool for detecting suspicious network patterns using machine learning. In: Proceedings of the 15th International Conference on Availability, Reliability and Security, pp. 1\u20137","DOI":"10.1145\/3407023.3409189"},{"key":"980_CR13","doi-asserted-by":"crossref","unstructured":"Liu X, Tang Z, Yang B (2019) Predicting network attacks with cnn by constructing images from netflow data. In: 2019 IEEE 5th Intl Conference on Big Data Security on Cloud (BigDataSecurity), IEEE Intl Conference on High Performance and Smart Computing, (HPSC) and IEEE Intl Conference on Intelligent Data and Security (IDS), pp. 61\u201366","DOI":"10.1109\/BigDataSecurity-HPSC-IDS.2019.00022"},{"key":"980_CR14","doi-asserted-by":"publisher","first-page":"48231","DOI":"10.1109\/ACCESS.2018.2863036","volume":"6","author":"S Naseer","year":"2018","unstructured":"Naseer S, Saleem Y, Khalid S, Bashir MK, Han J, Iqbal MM, Han K (2018) Enhanced network anomaly detection based on deep neural networks. IEEE Access 6:48231\u201348246. https:\/\/doi.org\/10.1109\/ACCESS.2018.2863036","journal-title":"IEEE Access"},{"issue":"4","key":"980_CR15","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1109\/MTS.2020.3031848","volume":"39","author":"A Pawlicka","year":"2020","unstructured":"Pawlicka A, Jaroszewska-Choras D, Choras M, Pawlicki M (2020) Guidelines for stego\/malware detection tools: achieving gdpr compliance. IEEE Technol Soc Mag 39(4):60\u201370","journal-title":"IEEE Technol Soc Mag"},{"key":"980_CR16","unstructured":"Tenable: Blink XT2 sync module multiple vulnerabilities (2019). https:\/\/www.tenable.com\/security\/research\/tra-2019-51"},{"key":"980_CR17","doi-asserted-by":"publisher","first-page":"27","DOI":"10.13164\/mendel.2019.2.027","volume":"25","author":"CT Thanh","year":"2019","unstructured":"Thanh CT, Zelinka I (2019) A survey on artificial intelligence in malware as next-generation threats. Mendel 25:27\u201334","journal-title":"Mendel"},{"key":"980_CR18","doi-asserted-by":"publisher","first-page":"48697","DOI":"10.1109\/ACCESS.2018.2867564","volume":"6","author":"C Xu","year":"2018","unstructured":"Xu C, Shen J, Du X, Zhang F (2018) An intrusion detection system using a deep neural network with gated recurrent units. IEEE Access 6:48697\u201348707. https:\/\/doi.org\/10.1109\/ACCESS.2018.2867564","journal-title":"IEEE Access"},{"key":"980_CR19","doi-asserted-by":"publisher","first-page":"7842","DOI":"10.1109\/ACCESS.2019.2963716","volume":"8","author":"C Yang","year":"2020","unstructured":"Yang C, Liu J, Kristiani E, Liu M, You I, Pau G (2020) Netflow monitoring and cyberattack detection using deep learning with ceph. IEEE Access 8:7842\u20137850","journal-title":"IEEE Access"},{"key":"980_CR20","doi-asserted-by":"publisher","unstructured":"Yeo M, Koo Y, Yoon Y, Hwang T, Ryu J, Song J, Park C (2018) Flow-based malware detection using convolutional neural network. In: 2018 International Conference on Information Networking (ICOIN), pp. 910\u2013913. https:\/\/doi.org\/10.1109\/ICOIN.2018.8343255","DOI":"10.1109\/ICOIN.2018.8343255"},{"key":"980_CR21","doi-asserted-by":"crossref","unstructured":"Zaman M, Lung C (2018) Evaluation of machine learning techniques for network intrusion detection. In: NOMS 2018 - 2018 IEEE\/IFIP Network Operations and Management Symposium, pp. 1\u20135","DOI":"10.1109\/NOMS.2018.8406212"},{"key":"980_CR22","doi-asserted-by":"crossref","unstructured":"Zhang H, Dai S, Li Y, Zhang W (2018) Real-time distributed-random-forest-based network intrusion detection system using apache spark. In: 2018 IEEE 37th International Performance Computing and Communications Conference (IPCCC), pp. 1\u20137","DOI":"10.1109\/PCCC.2018.8711068"}],"container-title":["Pattern Analysis and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10044-021-00980-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10044-021-00980-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10044-021-00980-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,27]],"date-time":"2022-12-27T02:34:01Z","timestamp":1672108441000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10044-021-00980-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,12]]},"references-count":22,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,11]]}},"alternative-id":["980"],"URL":"https:\/\/doi.org\/10.1007\/s10044-021-00980-2","relation":{},"ISSN":["1433-7541","1433-755X"],"issn-type":[{"value":"1433-7541","type":"print"},{"value":"1433-755X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,12]]},"assertion":[{"value":"15 January 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 April 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 May 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}