{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:59:04Z","timestamp":1780588744198,"version":"3.54.1"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"S1","license":[{"start":{"date-parts":[[2017,9,27]],"date-time":"2017-09-27T00:00:00Z","timestamp":1506470400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2019,1]]},"DOI":"10.1007\/s10586-017-1117-8","type":"journal-article","created":{"date-parts":[[2017,9,27]],"date-time":"2017-09-27T08:23:04Z","timestamp":1506500584000},"page":"949-961","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":536,"title":["A survey of deep learning-based network anomaly detection"],"prefix":"10.1007","volume":"22","author":[{"given":"Donghwoon","family":"Kwon","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6716-7740","authenticated-orcid":false,"given":"Hyunjoo","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinoh","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sang C.","family":"Suh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ikkyun","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kuinam J.","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,9,27]]},"reference":[{"key":"1117_CR1","unstructured":"Semente: 2016 Internet Security Threat Report (ISTR), vol. 21, p. 8, April 2016"},{"key":"1117_CR2","unstructured":"Gartner Provides Three Immediate Actions to Take as WannaCry Ransomware Spreads. http:\/\/www.gartner.com\/newsroom\/id\/3715918"},{"issue":"5","key":"1117_CR3","first-page":"205","volume":"9","author":"Y Li","year":"2014","unstructured":"Li, Y., Ma, R., Jiao, R.: Hybrid malicious code detection method based on deep learning. Int. J. Secur. Appl. 9(5), 205\u2013216 (2014)","journal-title":"Int. J. Secur. Appl."},{"key":"1117_CR4","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1007\/978-3-642-20505-7_26","volume":"96","author":"MA Salama","year":"2011","unstructured":"Salama, M.A., Eid, H.F., Ramadan, R.A., Darwish, A., Hassanien, A.E.: Hybrid intelligent intrusion detection scheme. Soft Comput. Ind. Appl. 96, 293\u2013303 (2011)","journal-title":"Soft Comput. Ind. Appl."},{"key":"1117_CR5","unstructured":"Niyaz, Q., Sun, W., Javaid, A.Y., Alam, M.: A deep learning approach for network intrusion detection system. In: 9th EAI International Conference on Bio-Inspired Information and Communications Technologies, pp. 1\u201311, May 2016"},{"key":"1117_CR6","unstructured":"Ahmed, A.: Signature-based network inrusion detection system using JESS(SNIDJ). Graduate Project Technical Report, TAMUCC, pp. 2\u20136 (2004)"},{"key":"1117_CR7","doi-asserted-by":"publisher","unstructured":"Ning, P., Jajodia, S.: Intrusion detection techniques. The Internet Encyclopedia. doi: 10.1002\/047148296X.tie097","DOI":"10.1002\/047148296X.tie097"},{"issue":"1","key":"1117_CR8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40537-014-0007-7","volume":"2","author":"MM Najafabadi","year":"2015","unstructured":"Najafabadi, M.M., Villanustre, F., Khoshgoftaar, T.M., Seliya, N., Wald, R., Muharemagic, E.: Deep learning applications and challenges in big data analytics. J. Big Data 2(1), 1 (2015)","journal-title":"J. Big Data"},{"issue":"3\u20134","key":"1117_CR9","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1561\/2000000039","volume":"7","author":"L Deng","year":"2014","unstructured":"Deng, L., Yu, D.: Deep learning: methods and applications. Found. Trends Signal Process. 7(3\u20134), 197\u2013387 (2014)","journal-title":"Found. Trends Signal Process."},{"key":"1117_CR10","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., Ghorbani, A.A.: A detailed analysis of the KDD CUP 99 dataset. In: Proceedings of the 2009 IEEE Symposium on Computational Intelligence in Security and Defense Applications (CISDA 2009), pp. 53\u201358 (2009)","DOI":"10.1109\/CISDA.2009.5356528"},{"issue":"12","key":"1117_CR11","first-page":"1848","volume":"2","author":"S Revathi","year":"2013","unstructured":"Revathi, S., Malathi, A.: A detailed analysis on NSL-KDD dataset using various machine learning techniques for intrusion detection. Int. J. Eng. Res. Technol. 2(12), 1848\u20131853 (2013)","journal-title":"Int. J. Eng. Res. Technol."},{"issue":"2","key":"1117_CR12","first-page":"54","volume":"1","author":"DP Vinchurkar","year":"2012","unstructured":"Vinchurkar, D.P., Reshamwala, A.: A review of intrusion detectiom system using neural network and machine learning technique. Int. J. Eng. Sci. Innov. Technol. 1(2), 54\u201363 (2012)","journal-title":"Int. J. Eng. Sci. Innov. Technol."},{"key":"1117_CR13","doi-asserted-by":"crossref","unstructured":"Das, S., Kalita, H.K.: Advanced dimensionality reduction method for big data. In: Research advances in the integration of big data and smart computing, information science reference (an imprint of IGI global), p. 200 (2016)","DOI":"10.4018\/978-1-4666-8737-0.ch011"},{"issue":"10","key":"1117_CR14","first-page":"21","volume":"5","author":"SS Panwar","year":"2014","unstructured":"Panwar, S.S., Raiwani, Y.P.: Data reduction techniques to analyze NSL-KDD Dataset. Int. J. Comput. Eng. Technol. 5(10), 21\u201331 (2014)","journal-title":"Int. J. Comput. Eng. Technol."},{"issue":"8","key":"1117_CR15","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1016\/j.patrec.2009.09.011","volume":"31","author":"AK Jain","year":"2010","unstructured":"Jain, A.K.: Data clustering: 50 years beyond K-means. J. Pattern Recognit. Lett. 31(8), 651\u2013666 (2010)","journal-title":"J. Pattern Recognit. Lett."},{"key":"1117_CR16","unstructured":"John, G.H., Langley, P.: Static versus dynamic sampling for data mining, KDD 96. In: Proceedings of the Second International Conference on Knowledge Discovery and Data Mining, pp. 367\u2013370 (1996)"},{"issue":"2","key":"1117_CR17","first-page":"67","volume":"5","author":"H Motoda","year":"2002","unstructured":"Motoda, H., Liu, H.: Feature selection, extraction, and construction. Commun. Inst. Inf. Comput. Mach. Taiwan 5(2), 67\u201372 (2002)","journal-title":"Commun. Inst. Inf. Comput. Mach. Taiwan"},{"issue":"4","key":"1117_CR18","doi-asserted-by":"publisher","first-page":"147","DOI":"10.5121\/ijcnc.2013.5412","volume":"5","author":"MF Elrawy","year":"2013","unstructured":"Elrawy, M.F., Abdelhamid, T.K., Mohamed, A.M.: IDS in telecommunication network using PCA. Int. J. Comput. Netw. Commun. 5(4), 147\u2013157 (2013)","journal-title":"Int. J. Comput. Netw. Commun."},{"issue":"1","key":"1117_CR19","first-page":"332","volume":"3","author":"R Datti","year":"2012","unstructured":"Datti, R., Lakhina, S.: Performance comparison of features reduction techniques for intrusion detection system. Int. J. Comput. Sci. Technol. 3(1), 332\u2013335 (2012)","journal-title":"Int. J. Comput. Sci. Technol."},{"issue":"4","key":"1117_CR20","first-page":"324","volume":"10","author":"K Bajaj","year":"2013","unstructured":"Bajaj, K., Arora, A.: Dimension reduction in intrusion detection features using discriminative machine learning approach. Int. J. Comput. Sci. Issues 10(4), 324\u2013328 (2013)","journal-title":"Int. J. Comput. Sci. Issues"},{"key":"1117_CR21","doi-asserted-by":"crossref","unstructured":"Ibraheem, N.B., Jawhar, M.M.T., Osman, H.M.: Principle components analysis and multi-layer perceptron based intrusion detection system. In: Fifth Scientific Conference Information Technology, vol. 10(1), pp. 127\u2013135 (2013)","DOI":"10.33899\/csmj.2013.163430"},{"key":"1117_CR22","unstructured":"Chae, H., Jo, B., Choi, S., Park, T.: Feature selection for intrusion detection using NSL-KDD. In: Proceedings of the 12th WSEAS International Conference on Information Security and Privacy, pp. 184\u2013187, November 2013"},{"issue":"6","key":"1117_CR23","doi-asserted-by":"publisher","first-page":"23","DOI":"10.9790\/0661-0462330","volume":"4","author":"M Namratha","year":"2012","unstructured":"Namratha, M., Prajwala, T.R.: A comprehensive overview of clustering algorithms in pattern recognition. IOSR J. Comput. Eng. 4(6), 23\u201330 (2012)","journal-title":"IOSR J. Comput. Eng."},{"issue":"11","key":"1117_CR24","first-page":"1","volume":"1","author":"P Koturwar","year":"2014","unstructured":"Koturwar, P., Girase, S., Mukhopadhyay, D.: A survey of classification techniques in the area of big data. Int. J. Adv. Found. Res. Comput. 1(11), 1\u20137 (2014)","journal-title":"Int. J. Adv. Found. Res. Comput."},{"key":"1117_CR25","doi-asserted-by":"crossref","unstructured":"Caruana, R., Niculescu-Mizil, A.: An empirical comparison of supervised learning algorithms. In: Proceedings of the 23rd International Conference on Machine Learning, pp. 161\u2013168, June 2006","DOI":"10.1145\/1143844.1143865"},{"key":"1117_CR26","doi-asserted-by":"crossref","unstructured":"Lin, F., Cohen, W.W.: Semi-supervised classification of network data using very few labels. In: Proceedings of the 2010 International Conference on Advances in Social Networks and Mining, pp. 192\u2013198, August 2010","DOI":"10.1109\/ASONAM.2010.19"},{"key":"1117_CR27","doi-asserted-by":"crossref","unstructured":"Deng, L., Yu, D.: Deep learning methods and applications. Found. Trends Signal Process., 7(3\u20134), 199\u2013201, 217 (2014)","DOI":"10.1561\/2000000039"},{"issue":"5","key":"1117_CR28","doi-asserted-by":"publisher","first-page":"1668","DOI":"10.4249\/scholarpedia.1668","volume":"2","author":"GE Hinton","year":"2007","unstructured":"Hinton, G.E.: Boltzmann machine. Scholarpedia 2(5), 1668 (2007)","journal-title":"Scholarpedia"},{"key":"1117_CR29","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/j.patcog.2013.05.025","volume":"47","author":"A Fischer","year":"2014","unstructured":"Fischer, A., Igel, C.: Training restricted Boltzmann machines: an introduction. Pattern Recognit. 47, 25\u201339 (2014)","journal-title":"Pattern Recognit."},{"issue":"2","key":"1117_CR30","first-page":"35","volume":"3","author":"MZ Alom","year":"2015","unstructured":"Alom, M.Z., Bontupalli, V., Taha, T.M.: Intrusion detection using deep belief networks. Int. J. Monit. Surveill. Technol. Res. 3(2), 35\u201356 (2015)","journal-title":"Int. J. Monit. Surveill. Technol. Res."},{"key":"1117_CR31","doi-asserted-by":"crossref","unstructured":"Kim, S.K., McMahon, P.L., Olulotun, K.: A large-scale architecture for restricted Boltzmann machines. In: Proceedings of the 2010 18th IEEE Annual International Symposium on Field-Programmable Custom Computing Machines, pp. 201\u2013208, May 2010","DOI":"10.1109\/FCCM.2010.38"},{"issue":"6","key":"1117_CR32","doi-asserted-by":"publisher","first-page":"e0155781","DOI":"10.1371\/journal.pone.0155781","volume":"11","author":"M Kang","year":"2016","unstructured":"Kang, M., Kang, J.: Intrusion detection system using deep neural network for in-vehicle network security. PLoS ONE 11(6), e0155781 (2016). doi: 10.1371\/journal.pone.0155781e0155781","journal-title":"PLoS ONE"},{"key":"1117_CR33","unstructured":"Hinton, G.E.: A practical guide to training restricted Boltzmann machines. UTML Technical Report 2010-003, University of Toronto, August 2010"},{"key":"1117_CR34","doi-asserted-by":"crossref","unstructured":"Yamashita, T., Tanaka, M., Yoshida, E., Yamauchi, Y., Fujiyoshii, H.: To be Bernoulli or to be Gaussian, for a restricted boltzmann machine. In: 2014 22nd International Conference on Pattern Recognition (ICPR), pp. 1520\u20131525. IEEE (2014)","DOI":"10.1109\/ICPR.2014.270"},{"key":"1117_CR35","doi-asserted-by":"crossref","unstructured":"Sze, V., Chen, Y.-H., Yang, T.-J., Emer, J.: Efficient processing of deep neural networks: a tutorial and survey. arXiv preprint, arXiv:1703.09039 (2017)","DOI":"10.1109\/JPROC.2017.2761740"},{"key":"1117_CR36","doi-asserted-by":"publisher","first-page":"504","DOI":"10.1126\/science.1127647","volume":"313","author":"GE Hinton","year":"2006","unstructured":"Hinton, G.E., Salakhutdinov, R.: Reducing the dimensionality of data with neural networks. Science 313, 504\u2013507 (2006)","journal-title":"Science"},{"key":"1117_CR37","unstructured":"Kayack, H.G., Zincir-Heywood, A.N., Heywood, M.I.: Selecting features for intrusion detection: a feature relevance analysis on KDD 99 intrusion detection datasets. In: Proceedings of the 3rd Annual Conference on Privacy Security and Trust, October 2005"},{"key":"1117_CR38","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., Ghorbani, A.A.: A detailed analysis of the kdd cup 99 data set. In: CISDA 2009. IEEE Symposium on Computational Intelligence for Security and Defense Applications, 2009, pp. 1\u20136. IEEE (2009)"},{"issue":"2","key":"1117_CR39","doi-asserted-by":"publisher","first-page":"20","DOI":"10.3390\/info7020020","volume":"7","author":"X Tao","year":"2016","unstructured":"Tao, X., Kong, D., Wei, Y., Wang, Y.: A big network traffic data fusion approach based on fisher and deep auto-encoder. Information 7(2), 20 (2016)","journal-title":"Information"},{"key":"1117_CR40","doi-asserted-by":"crossref","unstructured":"Kim, J., Kim, J., Thu, H.L.T., Kim, H.: Long short term memory recurrent neural network classifier for intrusion detection. In: 2016 International Conference on Platform Technology and Service (PlatCon), pp. 1\u20135, Feb 2016","DOI":"10.1109\/PlatCon.2016.7456805"},{"key":"1117_CR41","doi-asserted-by":"crossref","unstructured":"Tang, T.A., Mhamdi, L., McLernon, D., Zaidi, S.A.R., Ghogho, M.: Deep learning approach for network intrusion detection in software defined networking. In: 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM), pp. 258\u2013263. IEEE (2016)","DOI":"10.1109\/WINCOM.2016.7777224"},{"key":"1117_CR42","doi-asserted-by":"crossref","unstructured":"Baek, S., Kwon, D., Kim, J., Suh, S., Kim, H., Kim, I.: Unsupervised labeling for supervised anomaly detection in enterprise and cloud networks. In: The 4th IEEE International Conference on Cyber Security and Cloud Computing (IEEE CSCloud 2017), July 2017","DOI":"10.1109\/CSCloud.2017.26"},{"key":"1117_CR43","doi-asserted-by":"crossref","unstructured":"Schlegl, T., Seeb\u00f6ck, P., Waldstein, S.M., Schmidt-Erfurth, U., Langs, G.: Unsupervised anomaly detection with generative adversarial networks to guide marker discovery. arXiv preprint, arXiv:1703.05921 (2017)","DOI":"10.1007\/978-3-319-59050-9_12"},{"key":"1117_CR44","doi-asserted-by":"crossref","unstructured":"Xue, Y., Xu, T., Zhang, H., Long, R., Huang, X.: Segan: adversarial network with multi-scale $$ l_1 $$ l 1 loss for medical image segmentation. arXiv preprint, arXiv:1706.01805 (2017)","DOI":"10.1007\/s12021-018-9377-x"},{"key":"1117_CR45","unstructured":"Goodfellow, I.: Nips 2016 tutorial: generative adversarial networks. arXiv preprint, arXiv:1701.00160 (2016)"}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-017-1117-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10586-017-1117-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-017-1117-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,3]],"date-time":"2022-08-03T14:23:31Z","timestamp":1659536611000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10586-017-1117-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,9,27]]},"references-count":45,"journal-issue":{"issue":"S1","published-print":{"date-parts":[[2019,1]]}},"alternative-id":["1117"],"URL":"https:\/\/doi.org\/10.1007\/s10586-017-1117-8","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"value":"1386-7857","type":"print"},{"value":"1573-7543","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,9,27]]},"assertion":[{"value":"30 April 2017","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 July 2017","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 August 2017","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 September 2017","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}