{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T09:13:50Z","timestamp":1783674830479,"version":"3.55.0"},"reference-count":76,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T00:00:00Z","timestamp":1783641600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T00:00:00Z","timestamp":1783641600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100010418","name":"Defence Science and Technology Laboratory","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100010418","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Event-based datasets are crucial for cybersecurity analysis. A key use case is detecting event-based signatures, which represent attacks spanning multiple events and can only be understood once the relevant events are identified and linked. Analysing event datasets is essential for monitoring system security, but their growing volume and frequency create significant scalability and processing difficulties. Researchers rely on these datasets to develop and test techniques for automatically identifying signatures. However, because real datasets are security-sensitive and rarely shared, it becomes difficult to perform meaningful comparative evaluation between different approaches. This work addresses this evaluation limitation by offering a systematic method for generating event logs with known ground truth, enabling reproducible and comparable research. We present a novel parametrised generation technique capable of producing synthetic event datasets that contain event-based signatures for discovery. To demonstrate the capabilities of the technique, we provide a benchmark in signature detection. Our benchmarking demonstrated the suitability of DBSCAN, achieving a score greater than 0.95 Adjusted Rand Index on most generated datasets. This work enhances the ability of researchers to develop and benchmark new cybersecurity techniques, ultimately contributing to more robust and effective cybersecurity measures.<\/jats:p>","DOI":"10.1007\/s10207-026-01294-2","type":"journal-article","created":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T08:17:32Z","timestamp":1783671452000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Reproducibility in event-log research: a parametrised generator and benchmark for event-based signatures"],"prefix":"10.1007","volume":"25","author":[{"given":"Saad","family":"Khan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1747-9914","authenticated-orcid":false,"given":"Simon","family":"Parkinson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Monika","family":"Roopak","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,10]]},"reference":[{"key":"1294_CR1","doi-asserted-by":"publisher","first-page":"214","DOI":"10.1016\/j.cose.2018.03.001","volume":"76","author":"J Navarro","year":"2018","unstructured":"Navarro, J., Deruyver, A., Parrend, P.: A systematic survey on multi-step attack detection. Computers & Security 76, 214\u2013249 (2018)","journal-title":"Computers & Security"},{"issue":"8","key":"1294_CR2","doi-asserted-by":"publisher","first-page":"8547","DOI":"10.1007\/s10462-022-10381-4","volume":"56","author":"D Levshun","year":"2023","unstructured":"Levshun, D., Kotenko, I.: A survey on artificial intelligence techniques for security event correlation: models, challenges, and opportunities. Artif. Intell. Rev. 56(8), 8547\u20138590 (2023)","journal-title":"Artif. Intell. Rev."},{"key":"1294_CR3","doi-asserted-by":"crossref","unstructured":"Shaukat, S.U., Khan, S., Parkinson, S.: A review on multi-step attack detection. IEEE Access, (2025)","DOI":"10.1109\/ACCESS.2025.3607497"},{"issue":"7","key":"1294_CR4","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1353-4858(17)30069-7","volume":"2017","author":"S Parkinson","year":"2017","unstructured":"Parkinson, S.: Use of access control to minimise ransomware impact. Netw. Secur. 2017(7), 5\u20138 (2017)","journal-title":"Netw. Secur."},{"key":"1294_CR5","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1016\/j.eswa.2018.07.006","volume":"113","author":"S Khan","year":"2018","unstructured":"Khan, S., Parkinson, S.: Eliciting and utilising knowledge for security event log analysis: an association rule mining and automated planning approach. Expert Syst. Appl. 113, 116\u2013127 (2018)","journal-title":"Expert Syst. Appl."},{"key":"1294_CR6","doi-asserted-by":"crossref","unstructured":"Bose, R.J.C., Aalst, W.M.: Discovering signature patterns from event logs. In: 2013 IEEE Symposium on Computational Intelligence and Data Mining (CIDM), pp. 111\u2013118. IEEE (2013)","DOI":"10.1109\/CIDM.2013.6597225"},{"key":"1294_CR7","doi-asserted-by":"publisher","first-page":"43387","DOI":"10.1109\/ACCESS.2022.3168976","volume":"10","author":"I Kotenko","year":"2022","unstructured":"Kotenko, I., Gaifulina, D., Zelichenok, I.: Systematic literature review of security event correlation methods. Ieee Access 10, 43387\u201343420 (2022)","journal-title":"Ieee Access"},{"issue":"1","key":"1294_CR8","doi-asserted-by":"publisher","first-page":"70151","DOI":"10.1002\/spy2.70151","volume":"9","author":"SU Shaukat","year":"2026","unstructured":"Shaukat, S.U., Khan, S., Parkinson, S.: Event log correlation for multi-step attack detection. Security and Privacy 9(1), 70151 (2026)","journal-title":"Security and Privacy"},{"key":"1294_CR9","doi-asserted-by":"publisher","first-page":"132","DOI":"10.1016\/j.is.2016.07.011","volume":"64","author":"S Suriadi","year":"2017","unstructured":"Suriadi, S., Andrews, R., Hofstede, A.H., Wynn, M.T.: Event log imperfection patterns for process mining: Towards a systematic approach to cleaning event logs. Inf. Syst. 64, 132\u2013150 (2017)","journal-title":"Inf. Syst."},{"key":"1294_CR10","doi-asserted-by":"crossref","unstructured":"Ghahfarokhi, A.F., Park, G., Berti, A., Aalst, W.M.: Ocel: A standard for object-centric event logs. In: European Conference on Advances in Databases and Information Systems, pp. 169\u2013175. Springer (2021)","DOI":"10.1007\/978-3-030-85082-1_16"},{"key":"1294_CR11","doi-asserted-by":"crossref","unstructured":"Alshaikh, O., Parkinson, S., Khan, S.: On the variability in the application and measurement of supervised machine learning in cyber security. In: International Conference on Ubiquitous Security, pp. 545\u2013555. Springer (2022)","DOI":"10.1007\/978-981-99-0272-9_38"},{"key":"1294_CR12","unstructured":"Bulut, M.F., Liu, Y., Ahmad, N., Turner, M., Ouahmane, S.A., Andrews, C., Greenwald, L.: Secencoder: Logs are all you need in security, (2024). arXiv:2411.07528 arXiv preprint"},{"key":"1294_CR13","doi-asserted-by":"crossref","unstructured":"Egunjobi, S., Parkinson, S., Crampton, A.: Classifying ransomware using machine learning algorithms. In: International Conference on Intelligent Data Engineering and Automated Learning, pp. 45\u201352. Springer (2019)","DOI":"10.1007\/978-3-030-33617-2_5"},{"issue":"16","key":"1294_CR14","doi-asserted-by":"publisher","first-page":"4433","DOI":"10.1002\/cpe.4433","volume":"30","author":"S Parkinson","year":"2018","unstructured":"Parkinson, S., Vallati, M., Crampton, A., Sohrabi, S.: Graphbad: A general technique for anomaly detection in security information and event management. Concurrency and Computation: Practice and Experience 30(16), 4433 (2018)","journal-title":"Concurrency and Computation: Practice and Experience"},{"key":"1294_CR15","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1016\/j.jisa.2018.03.003","volume":"40","author":"S Parkinson","year":"2018","unstructured":"Parkinson, S., Khan, S.: Identifying irregularities in security event logs through an object-based chi-squared test of independence. Journal of information security and applications 40, 52\u201362 (2018)","journal-title":"Journal of information security and applications"},{"key":"1294_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2019.102375","volume":"48","author":"S Khan","year":"2019","unstructured":"Khan, S., Parkinson, S.: Discovering and utilising expert knowledge from security event logs. Journal of Information Security and Applications 48, 102375 (2019). https:\/\/doi.org\/10.1016\/j.jisa.2019.102375","journal-title":"Journal of Information Security and Applications"},{"issue":"22","key":"1294_CR17","doi-asserted-by":"publisher","first-page":"10556","DOI":"10.3390\/app112210556","volume":"11","author":"HM Marin-Castro","year":"2021","unstructured":"Marin-Castro, H.M., Tello-Leal, E.: Event log preprocessing for process mining: a review. Appl. Sci. 11(22), 10556 (2021)","journal-title":"Appl. Sci."},{"key":"1294_CR18","doi-asserted-by":"crossref","unstructured":"He, P., Zhu, J., He, S., Li, J., Lyu, M.R.: An evaluation study on log parsing and its use in log mining. In: 2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 654\u2013661 (2016). IEEE","DOI":"10.1109\/DSN.2016.66"},{"key":"1294_CR19","unstructured":"Akhtar, S., Khan, S., Parkinson, S.: Evaluating prompt engineering for event log parsing with large language models: A comparative study. (Available at SSRN 5351870)"},{"issue":"2","key":"1294_CR20","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1504\/IJESDF.2017.083992","volume":"9","author":"MI Al-Saleh","year":"2017","unstructured":"Al-Saleh, M.I., Al-Shamaileh, M.J.: Forensic artefacts associated with intentionally deleted user accounts. Int. J. Electron. Secur. Digit. Forensics 9(2), 167\u2013179 (2017)","journal-title":"Int. J. Electron. Secur. Digit. Forensics"},{"issue":"3","key":"1294_CR21","first-page":"1346","volume":"10","author":"K Diba","year":"2020","unstructured":"Diba, K., Batoulis, K., Weidlich, M., Weske, M.: Extraction, correlation, and abstraction of event data for process mining. Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery 10(3), 1346 (2020)","journal-title":"Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery"},{"key":"1294_CR22","doi-asserted-by":"crossref","unstructured":"Goossens, A., De Smedt, J., Vanthienen, J., Aalst, W.M.: Enhancing data-awareness of object-centric event logs. In: International Conference on Process Mining, pp. 18\u201330. Springer (2022)","DOI":"10.1007\/978-3-031-27815-0_2"},{"key":"1294_CR23","doi-asserted-by":"publisher","unstructured":"Alzhrani, F.: Bela: A blockchain event log app (2023). (). https:\/\/doi.org\/10.5281\/zenodo.7620035","DOI":"10.5281\/zenodo.7620035"},{"key":"1294_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.dib.2022.108188","volume":"42","author":"S \u0160pa\u010dek","year":"2022","unstructured":"\u0160pa\u010dek, S., Velan, P., \u010celeda, P., Tovar\u0148\u00e1k, D.: Encrypted web traffic dataset: Event logs and packet traces. Data Brief 42, 108188 (2022)","journal-title":"Data Brief"},{"key":"1294_CR25","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102696","volume":"117","author":"S Wu","year":"2022","unstructured":"Wu, S., Wang, B., Wang, Z., Fan, S., Yang, J., Li, J.: Joint prediction on security event and time interval through deep learning. Computers & Security 117, 102696 (2022)","journal-title":"Computers & Security"},{"issue":"7","key":"1294_CR26","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1016\/S1361-3723(21)00074-9","volume":"2021","author":"I Kara","year":"2021","unstructured":"Kara, I.: Read the digital fingerprints: log analysis for digital forensics and security. Computer Fraud & Security 2021(7), 11\u201316 (2021)","journal-title":"Computer Fraud & Security"},{"key":"1294_CR27","doi-asserted-by":"publisher","first-page":"668","DOI":"10.1016\/j.future.2019.09.005","volume":"111","author":"M Cinque","year":"2020","unstructured":"Cinque, M., Della Corte, R., Pecchia, A.: Contextual filtering and prioritization of computer application logs for security situational awareness. Futur. Gener. Comput. Syst. 111, 668\u2013680 (2020)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"1294_CR28","unstructured":"De Leoni, M., Mannhardt, F.: Road traffic fine management process. Dataset 284, (2015) Eindhoven University of Technology"},{"key":"1294_CR29","unstructured":"Mannhardt, F.: Hospital billing-event log, pp. 326\u2013347. Eindhoven University of Technology. Dataset (2017)"},{"key":"1294_CR30","unstructured":"Buijs, J.: Receipt phase of an environmental permit application process (\u2018wabo\u2019), coselog project, Eindhoven University of Technology (2014)"},{"key":"1294_CR31","volume-title":"Bpi challenge 2013","author":"W Steeman","year":"2013","unstructured":"Steeman, W.: Bpi challenge 2013. Ghent University, Dataset (2013)"},{"key":"1294_CR32","unstructured":"Mannhardt, F.: Sepsis cases-event log. Eindhoven university of technology 10, (2016)"},{"key":"1294_CR33","doi-asserted-by":"crossref","unstructured":"Turcotte, M.J., Kent, A.D., Hash, C.: Unified host and network data set. In: Data Science for Cyber-security, pp. 1\u201322. World Scientific, (2019)","DOI":"10.1142\/9781786345646_001"},{"key":"1294_CR34","doi-asserted-by":"publisher","unstructured":"Zhu, J., He, S., He, P., Liu, J., Lyu, M.R.: Loghub: A large collection of system log datasets for ai-driven log analytics. In: 2023 IEEE 34th International Symposium on Software Reliability Engineering (ISSRE), pp. 355\u2013366 (2023). https:\/\/doi.org\/10.1109\/ISSRE59848.2023.00071","DOI":"10.1109\/ISSRE59848.2023.00071"},{"key":"1294_CR35","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104312","volume":"151","author":"R Flynn","year":"2025","unstructured":"Flynn, R., Olukoya, O.: Using approximate matching and machine learning to uncover malicious activity in logs. Computers & Security 151, 104312 (2025)","journal-title":"Computers & Security"},{"key":"1294_CR36","doi-asserted-by":"crossref","unstructured":"M\u00e4ntyl\u00e4, M.V., Wang, Y., Nyyss\u00f6l\u00e4, J.: Loglead-fast and integrated log loader, enhancer, and anomaly detector. In: 2024 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER), pp. 395\u2013399. IEEE (2024)","DOI":"10.1109\/SANER60148.2024.00046"},{"key":"1294_CR37","doi-asserted-by":"crossref","unstructured":"Xie, Y., Zhang, H., Babar, M.A.: Logsd: Detecting anomalies from system logs through self-supervised learning and frequency-based masking. Proceedings of the ACM on Software Engineering 1(FSE), 2098\u20132120 (2024)","DOI":"10.1145\/3660800"},{"key":"1294_CR38","doi-asserted-by":"crossref","unstructured":"Sommers, D., Sidorova, N., Dongen, B.: A Ground Truth Approach for Assessing Process Mining Techniques (2025). arxiv: 2501.14345","DOI":"10.1007\/s44311-025-00006-8"},{"key":"1294_CR39","unstructured":"Burattin, A.: Plg2: multiperspective processes randomization and simulation for online and offline settings, (2015). arXiv:1506.08415 arXiv preprint"},{"key":"1294_CR40","doi-asserted-by":"crossref","unstructured":"Burattin, A., Re, B., Rossi, L., Tiezzi, F.: A purpose-guided log generation framework. In: Business Process Management: 20th International Conference, BPM 2022, M\u00fcnster, Germany, September 11\u201316, 2022, Proceedings, pp. 181\u2013198 (2022). Springer","DOI":"10.1007\/978-3-031-16103-2_14"},{"key":"1294_CR41","doi-asserted-by":"crossref","unstructured":"Gr\u00fcger, J., Geyer, T., Jilg, D., Bergmann, R.: Sample: A semantic approach for multi-perspective event log generation. In: Process Mining Workshops: ICPM 2022 International Workshops, Bozen-Bolzano, Italy, October 23\u201328, 2022, Revised Selected Papers, pp. 328\u2013340 (2023). Springer","DOI":"10.1007\/978-3-031-27815-0_24"},{"key":"1294_CR42","doi-asserted-by":"crossref","unstructured":"Esgin, E., Karagoz, P.: Process profiling based synthetic event log generation, pp. 516\u2013524. KDIR (2019)","DOI":"10.5220\/0008363805160524"},{"key":"1294_CR43","doi-asserted-by":"crossref","unstructured":"Pradhan, S.K., Jans, M., Martin, N.: Getting the data in shape for your process mining analysis: An in-depth analysis of the pre-analysis stage, ACM Computing Surveys (2025)","DOI":"10.1145\/3712587"},{"key":"1294_CR44","doi-asserted-by":"crossref","unstructured":"Zisgen, Y., Janssen, D., Koschmider, A.: Generating synthetic sensor event logs for process mining. In: Intelligent Information Systems: CAiSE Forum 2022, Leuven, Belgium, June 6\u201310, 2022, Proceedings, pp. 130\u2013137 (2022). Springer","DOI":"10.1007\/978-3-031-07481-3_15"},{"key":"1294_CR45","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110239","volume":"264","author":"M Li","year":"2023","unstructured":"Li, M., Zhuang, D., Chang, J.M.: Mc-gen: Multi-level clustering for private synthetic data generation. Knowl.-Based Syst. 264, 110239 (2023)","journal-title":"Knowl.-Based Syst."},{"key":"1294_CR46","doi-asserted-by":"crossref","unstructured":"Oyamada, R.S., Marques\u00a0Tavares, G., Barbon\u00a0Junior, S., Ceravolo, P.: Cosmo: A framework to instantiate conditioned process simulation models. In: International Conference on Business Process Management, pp. 328\u2013344 (2024). Springer","DOI":"10.1007\/978-3-031-70396-6_19"},{"issue":"2","key":"1294_CR47","doi-asserted-by":"publisher","first-page":"322","DOI":"10.3390\/electronics13020322","volume":"13","author":"G Agrawal","year":"2024","unstructured":"Agrawal, G., Kaur, A., Myneni, S.: A review of generative models in generating synthetic attack data for cybersecurity. Electronics 13(2), 322 (2024)","journal-title":"Electronics"},{"key":"1294_CR48","unstructured":"Ammara, D.A., Ding, J., Tutschku, K.: Synthetic data generation in cybersecurity: A comparative analysis, (2024). arXiv:2410.16326 arXiv preprint"},{"issue":"4","key":"1294_CR49","doi-asserted-by":"publisher","first-page":"429","DOI":"10.62411\/faith.3048-3719-52","volume":"1","author":"MA Rahman","year":"2025","unstructured":"Rahman, M.A., Francia, G.A., Shahriar, H.: Leveraging gans for synthetic data generation to improve intrusion detection systems. Journal of Future Artificial Intelligence and Technologies 1(4), 429\u2013439 (2025)","journal-title":"Journal of Future Artificial Intelligence and Technologies"},{"key":"1294_CR50","doi-asserted-by":"publisher","first-page":"165607","DOI":"10.1109\/ACCESS.2019.2953095","volume":"7","author":"J Lee","year":"2019","unstructured":"Lee, J., Kim, J., Kim, I., Han, K.: Cyber threat detection based on artificial neural networks using event profiles. Ieee Access 7, 165607\u2013165626 (2019)","journal-title":"Ieee Access"},{"key":"1294_CR51","doi-asserted-by":"publisher","first-page":"132","DOI":"10.1016\/j.knosys.2017.10.016","volume":"139","author":"Y Djenouri","year":"2018","unstructured":"Djenouri, Y., Belhadi, A., Fournier-Viger, P.: Extracting useful knowledge from event logs: A frequent itemset mining approach. Knowl.-Based Syst. 139, 132\u2013148 (2018)","journal-title":"Knowl.-Based Syst."},{"key":"1294_CR52","doi-asserted-by":"crossref","unstructured":"Arun\u00a0Bhanage, D., Vishal\u00a0Pawar, A., Joshi, A., G\u00a0Pawar, R.: An efficient failure predictive and remediation system for windows infrastructure with analysis of log-event records. International Journal of Computing and Digital Systems 16(1), 1123\u20131134 (2024)","DOI":"10.12785\/ijcds\/1601127"},{"key":"1294_CR53","doi-asserted-by":"crossref","unstructured":"Guo, H., Yang, J., Liu, J., Bai, J., Wang, B., Li, Z., Zheng, T., Zhang, B., Peng, J., Tian, Q.: Logformer: A pre-train and tuning pipeline for log anomaly detection. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 38, pp. 135\u2013143. (2024)","DOI":"10.1609\/aaai.v38i1.27764"},{"key":"1294_CR54","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.120991","volume":"233","author":"S Khan","year":"2023","unstructured":"Khan, S., Parkinson, S., Murphy, C.: Context-based irregular activity detection in event logs for forensic investigations: An itemset mining approach. Expert Syst. Appl. 233, 120991 (2023)","journal-title":"Expert Syst. Appl."},{"key":"1294_CR55","doi-asserted-by":"crossref","unstructured":"Shen, Y., Mariconti, E., Vervier, P.A., Stringhini, G.: Tiresias: Predicting security events through deep learning. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 592\u2013605. (2018)","DOI":"10.1145\/3243734.3243811"},{"key":"1294_CR56","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/s10844-017-0450-y","volume":"50","author":"B Fazzinga","year":"2018","unstructured":"Fazzinga, B., Flesca, S., Furfaro, F., Pontieri, L.: Online and offline classification of traces of event logs on the basis of security risks. Journal of Intelligent Information Systems 50, 195\u2013230 (2018)","journal-title":"Journal of Intelligent Information Systems"},{"key":"1294_CR57","unstructured":"Ester, M., Kriegel, H.-P., Sander, J., Xu, X.: A density-based algorithm for discovering clusters in large spatial databases with noise. In: Kdd 96, 226\u2013231 (1996)"},{"key":"1294_CR58","doi-asserted-by":"crossref","unstructured":"Ankerst, M., Breunig, M., Kriegel, H., Sander, J.: Acm sigmod record, pp. 49\u201360. ACM (1999)","DOI":"10.1145\/304182.304187"},{"issue":"2","key":"1294_CR59","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1016\/j.icte.2021.08.017","volume":"8","author":"S Abdulah","year":"2022","unstructured":"Abdulah, S., Atwa, W., Abdelmoniem, A.M.: Active clustering data streams with affinity propagation. ICT Express 8(2), 276\u2013282 (2022)","journal-title":"ICT Express"},{"key":"1294_CR60","doi-asserted-by":"publisher","DOI":"10.1016\/j.ascom.2022.100588","volume":"40","author":"T Zhu","year":"2022","unstructured":"Zhu, T., Wang, X., Zhang, J., Yu, S., Molotov, I.: Mean-shift clustering approach to the tracklets association with angular measurements of resident space objects. Astronomy and Computing 40, 100588 (2022)","journal-title":"Astronomy and Computing"},{"key":"1294_CR61","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109517","volume":"139","author":"X Han","year":"2023","unstructured":"Han, X., Zhu, Y., Ting, K.M., Li, G.: The impact of isolation kernel on agglomerative hierarchical clustering algorithms. Pattern Recogn. 139, 109517 (2023)","journal-title":"Pattern Recogn."},{"key":"1294_CR62","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1007\/BF01908075","volume":"2","author":"L Hubert","year":"1985","unstructured":"Hubert, L., Arabie, P.: Comparing partitions. Journal of classification 2, 193\u2013218 (1985)","journal-title":"Comparing partitions. Journal of classification"},{"key":"1294_CR63","doi-asserted-by":"crossref","unstructured":"Shahapure, K.R., Nicholas, C.: Cluster quality analysis using silhouette score. In: 2020 IEEE 7th International Conference on Data Science and Advanced Analytics (DSAA), pp. 747\u2013748. IEEE (2020)","DOI":"10.1109\/DSAA49011.2020.00096"},{"issue":"2","key":"1294_CR64","doi-asserted-by":"publisher","first-page":"1157","DOI":"10.1007\/s11192-017-2305-2","volume":"111","author":"R Koopman","year":"2017","unstructured":"Koopman, R., Wang, S.: Mutual information based labelling and comparing clusters. Scientometrics 111(2), 1157\u20131167 (2017)","journal-title":"Scientometrics"},{"key":"1294_CR65","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1007\/s00357-020-09367-0","volume":"38","author":"A D\u2019Ambrosio","year":"2021","unstructured":"D\u2019Ambrosio, A., Amodio, S., Iorio, C., Pandolfo, G., Siciliano, R.: Adjusted concordance index: an extensionl of the adjusted rand index to fuzzy partitions. J. Classif. 38, 112\u2013128 (2021)","journal-title":"J. Classif."},{"key":"1294_CR66","doi-asserted-by":"publisher","DOI":"10.1016\/j.array.2022.100229","volume":"15","author":"FJ Abdullayeva","year":"2022","unstructured":"Abdullayeva, F.J.: Distributed denial of service attack detection in e-government cloud via data clustering. Array 15, 100229 (2022)","journal-title":"Array"},{"key":"1294_CR67","doi-asserted-by":"crossref","unstructured":"Sinnott, R., Duan, H., Sun, Y.: Chapter 15-a case study in big data analytics: exploring twitter sentiment analysis and the weather. Big Data, pp. 357\u2013388. (2016)","DOI":"10.1016\/B978-0-12-805394-2.00015-5"},{"issue":"1","key":"1294_CR68","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/s003579900043","volume":"16","author":"AM Krieger","year":"1999","unstructured":"Krieger, A.M., Green, P.E.: A generalized rand-index method for consensus clustering of separate partitions of the same data base. J. Classif. 16(1), 63\u201389 (1999)","journal-title":"J. Classif."},{"key":"1294_CR69","doi-asserted-by":"crossref","unstructured":"Dudek, A.: Silhouette index as clustering evaluation tool. In: Conference of the Section on Classification and Data Analysis of the Polish Statistical Association, pp. 19\u201333. Springer (2019)","DOI":"10.1007\/978-3-030-52348-0_2"},{"key":"1294_CR70","unstructured":"Romano, S., Bailey, J., Nguyen, V., Verspoor, K.: Standardized mutual information for clustering comparisons: one step further in adjustment for chance. In: International Conference on Machine Learning, pp. 1143\u20131151. (2014). (PMLR)"},{"key":"1294_CR71","doi-asserted-by":"crossref","unstructured":"Yu, J., Xia, C., Xie, J., Zhang, H.: Research on feature importance of gait mechanomyography signal based on random forest. In: 2020 International Conference on Computer Vision, Image and Deep Learning (CVIDL), pp. 191\u2013196. IEEE (2020)","DOI":"10.1109\/CVIDL51233.2020.00045"},{"key":"1294_CR72","doi-asserted-by":"crossref","unstructured":"Alkuhlani, A., Gad, W., Roushdy, M., Salem, A.-B.M.: O-glycosylation site prediction using randome forest importance and support vector machine. In: 2022 IEEE 3rd International Conference on System Analysis & Intelligent Computing (SAIC), pp. 1\u20135 (2022). IEEE","DOI":"10.1109\/SAIC57818.2022.9922979"},{"key":"1294_CR73","doi-asserted-by":"crossref","unstructured":"Saputra, E.S., Putrada, A.G., Abdurohman, M.: Selection of vape sensing features in iot-based gas monitoring with feature importance techniques. In: 2019 Fourth International Conference on Informatics and Computing (ICIC), pp. 1\u20135 (2019). IEEE","DOI":"10.1109\/ICIC47613.2019.8985807"},{"key":"1294_CR74","doi-asserted-by":"crossref","unstructured":"Gr\u00f6mping, U.: Variable importance in regression models. Wiley interdisciplinary reviews: Computational statistics 7(2), 137\u2013152 (2015)","DOI":"10.1002\/wics.1346"},{"key":"1294_CR75","doi-asserted-by":"crossref","unstructured":"Wang, H.-M., Hsiao, C.-L., Hsieh, A.-R., Lin, Y.-C., Fann, C.S.: Constructing endophenotypes of complex diseases using non-negative matrix factorization and adjusted rand index. PLoS ONE 7(7), 40996 (2012)","DOI":"10.1371\/journal.pone.0040996"},{"key":"1294_CR76","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/s40745-015-0040-1","volume":"2","author":"D Xu","year":"2015","unstructured":"Xu, D., Tian, Y.: A comprehensive survey of clustering algorithms. Annals of Data Science 2, 165\u2013193 (2015)","journal-title":"Annals of Data Science"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01294-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-026-01294-2","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01294-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T08:17:41Z","timestamp":1783671461000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-026-01294-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,10]]},"references-count":76,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,8]]}},"alternative-id":["1294"],"URL":"https:\/\/doi.org\/10.1007\/s10207-026-01294-2","relation":{},"ISSN":["1615-5270"],"issn-type":[{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,10]]},"assertion":[{"value":"19 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 July 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"121"}}