{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T00:14:22Z","timestamp":1776730462205,"version":"3.51.2"},"reference-count":64,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2021,1,11]],"date-time":"2021-01-11T00:00:00Z","timestamp":1610323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,11]],"date-time":"2021-01-11T00:00:00Z","timestamp":1610323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Inf Technol Manag"],"published-print":{"date-parts":[[2021,12]]},"DOI":"10.1007\/s10799-020-00319-z","type":"journal-article","created":{"date-parts":[[2021,1,12]],"date-time":"2021-01-12T02:17:06Z","timestamp":1610417826000},"page":"231-244","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Optimal configuration of intrusion detection systems"],"prefix":"10.1007","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5196-8175","authenticated-orcid":false,"given":"Birendra","family":"Mishra","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Inna","family":"Smirnova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,1,11]]},"reference":[{"key":"319_CR1","doi-asserted-by":"crossref","unstructured":"Abraham A, Thomas J (2006) Distributed intrusion detection systems: A computational intelligence approach. Applications of Information Systems to Homeland Security and Defense: pp. 107\u2013137","DOI":"10.4018\/978-1-59140-640-2.ch005"},{"key":"319_CR2","unstructured":"Adamu TD, Rao VS (2014) A cost sensitive machine learning approach for intrusion detection. Global Journal of Computer Science and Technology"},{"key":"319_CR3","first-page":"152","volume":"25","author":"S Aljawarneh","year":"2018","unstructured":"Aljawarneh S, Aldwairi M, Yassein MB (2018) Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model. J ComputSci 25:152\u2013160","journal-title":"J ComputSci"},{"key":"319_CR4","doi-asserted-by":"crossref","unstructured":"Allen J, Christie A, Fithen W, McHugh J, Pickel J (2000) State of the practice of intrusion detection technologies (No. CMU\/SEI-99-TR-028). CMU Pittsburg, PA, Software Engineering Inst","DOI":"10.21236\/ADA375846"},{"key":"319_CR5","unstructured":"Anderson JP (1980) Computer security threat and monitoring surveillance. Technical Report 79F26400, James P. Anderson Co, Fort Washington, PA"},{"key":"319_CR6","unstructured":"Axelsson S (1998) Research in intrusion detection systems: a survey. Technical Report 98\u201317, Dept. of Computer Eng. Chalmers University, Goteborg, Sweden"},{"key":"319_CR7","unstructured":"Axelsson S (2000a) Intrusion detection systems: A taxonomy and survey. Technical Report 99\u201315, Dept. of Computer Eng. Chalmers University, Goteborg, Sweden"},{"issue":"3","key":"319_CR8","first-page":"186","volume":"3","author":"S Axelsson","year":"2000","unstructured":"Axelsson S (2000) The base-rate fallacy and the difficulty of intrusion detection. ACM Trans InfSystSecur 3(3):186\u2013205","journal-title":"ACM Trans InfSystSecur"},{"issue":"2","key":"319_CR9","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1145\/359205.359219","volume":"44","author":"I Bashir","year":"2001","unstructured":"Bashir I, Serafini E, Wall K (2001) Securing network software applications: Introduction. Commun ACM 44(2):29\u201330","journal-title":"Commun ACM"},{"issue":"7","key":"319_CR10","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1145\/1005817.1005828","volume":"47","author":"H Cavusoglu","year":"2004","unstructured":"Cavusoglu H, Mishra B, Raghunathan S (2004) A model for evaluating IT security investments. Commun ACM 47(7):87\u201392","journal-title":"Commun ACM"},{"key":"319_CR11","first-page":"1","volume":"2016","author":"\u00d6 Cepheli","year":"2016","unstructured":"Cepheli \u00d6, B\u00fcy\u00fck\u00e7orak S, Karabulut Kurt G (2016) Hybrid intrusion detection system for ddos attacks. J ElectrComputEng 2016:1","journal-title":"J ElectrComputEng"},{"key":"319_CR12","unstructured":"CERT (Computer Emergency Response Team) Coordination Center (2001) Security for information technology service contracts. CERT Security Improvement Modules"},{"key":"319_CR13","unstructured":"D\u2019haeseleer P, Forrest S, Helman P (1996) An immunological approach to change detection: Algorithms, analysis, and implications. In: IEEE symposium on security and privacy"},{"issue":"7","key":"319_CR14","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1145\/306549.306571","volume":"42","author":"R Durst","year":"1999","unstructured":"Durst R, Champion T, Witten B, Miller E, Spagnuolo L (1999) Testing and evaluating computer intrusion detection systems. Commun ACM 42(7):53\u201361","journal-title":"Commun ACM"},{"issue":"16","key":"319_CR15","first-page":"1569","volume":"27","author":"JM Estevez-Tapiador","year":"2004","unstructured":"Estevez-Tapiador JM, Garcia-Teodoro P, Diaz-Verdejo JE (2004) Anomaly detection methods in wired networks: a survey and taxonomy. ComputCommun 27(16):1569\u20131584","journal-title":"ComputCommun"},{"issue":"1\u20132","key":"319_CR16","first-page":"18","volume":"28","author":"P Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro P, Diaz-Verdejo J, Maci\u00e1-Fern\u00e1ndez G, V\u00e1zquez E (2009) Anomaly-based network intrusion detection: techniques, systems and challenges. ComputSecur 28(1\u20132):18\u201328","journal-title":"ComputSecur"},{"key":"319_CR17","unstructured":"Garvey TD, Lunt TF (1991) Model-based intrusion detection. In: Proceedings of the 14th national computer security conference"},{"issue":"3","key":"319_CR18","first-page":"285","volume":"9","author":"NI Ghali","year":"2009","unstructured":"Ghali NI (2009) Feature selection for effective anomaly-based intrusion detection. Int J ComputSciNetwSecur 9(3):285\u2013289","journal-title":"Int J ComputSciNetwSecur"},{"issue":"4","key":"319_CR19","first-page":"438","volume":"5","author":"LA Gordon","year":"2002","unstructured":"Gordon LA, Loeb MP (2002) The economics of information security investment. ACM Trans InfSystSecur 5(4):438\u2013457","journal-title":"ACM Trans InfSystSecur"},{"key":"319_CR20","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1016\/j.neucom.2016.06.021","volume":"214","author":"C Guo","year":"2016","unstructured":"Guo C, Ping Y, Liu N, Luo SS (2016) A two-level hybrid approach for intrusion detection. Neurocomputing 214:391\u2013400","journal-title":"Neurocomputing"},{"key":"319_CR21","unstructured":"Halme L, Kahn B (1988) Building a security monitor with adaptive user work profiles. In: Proceedings of the 11th national computer security conference. National Institute of Standards and Technology, Gaithersburg, MD"},{"key":"319_CR22","first-page":"1","volume":"49","author":"N Hubballi","year":"2014","unstructured":"Hubballi N, Suryanarayanan V (2014) False alarm minimization techniques in signature-based intrusion detection systems: a survey. ComputCommun 49:1\u201317","journal-title":"ComputCommun"},{"issue":"1","key":"319_CR23","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/TDSC.2007.9","volume":"4","author":"K Hwang","year":"2007","unstructured":"Hwang K, Cai M, Chen Y, Qin M (2007) Hybrid intrusion detection with weighted signature generation over anomalous internet episodes. IEEE Trans Depend Secure Comput 4(1):41\u201355","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"319_CR24","unstructured":"Ilgun K (1992) Ustat: A real-time intrusion detection system for unix. Master\u2019s Thesis, Computer Science Department, UCSB"},{"issue":"2\/3","key":"319_CR25","first-page":"85","volume":"2","author":"S Jajodia","year":"1993","unstructured":"Jajodia S, Millen J (1993) Editor\u2019s preface. J ComputSecur 2(2\/3):85","journal-title":"J ComputSecur"},{"issue":"4","key":"319_CR26","first-page":"235","volume":"23","author":"E Jonsson","year":"1997","unstructured":"Jonsson E, Olovsson T (1997) A quantitative model of security intrusion process based on attacker behavior. IEEE Trans SoftwEng 23(4):235\u2013245","journal-title":"IEEE Trans SoftwEng"},{"issue":"7","key":"319_CR27","first-page":"26","volume":"28","author":"V Jyothsna","year":"2011","unstructured":"Jyothsna V, Prasad VVR, Prasad KM (2011) A review of anomaly based intrusion detection systems. Int J ComputAppl 28(7):26\u201335","journal-title":"Int J ComputAppl"},{"issue":"2","key":"319_CR28","first-page":"84","volume":"1","author":"P Kabiri","year":"2005","unstructured":"Kabiri P, Ghorbani AA (2005) Research on intrusion detection and response: A survey. IJ Network Security 1(2):84\u2013102","journal-title":"IJ Network Security"},{"issue":"4","key":"319_CR29","doi-asserted-by":"publisher","first-page":"l27","DOI":"10.1109\/MC.2002.1012428","volume":"35","author":"RA Kemmerer","year":"2002","unstructured":"Kemmerer RA, Vigna G (2002) Intrusion detection: a brief history and overview. Computer 35(4):l27\u2013l30","journal-title":"Computer"},{"issue":"4","key":"319_CR30","doi-asserted-by":"publisher","first-page":"1690","DOI":"10.1016\/j.eswa.2013.08.066","volume":"41","author":"G Kim","year":"2014","unstructured":"Kim G, Lee S, Kim S (2014) A novel hybrid intrusion detection method integrating anomaly detection with misuse detection. Expert SystAppl 41(4):1690\u20131700","journal-title":"Expert SystAppl"},{"key":"319_CR31","doi-asserted-by":"crossref","unstructured":"Kruegel C, Toth T (2003) Using decision trees to improve signature-based intrusion detection. In: International workshop on recent advances in intrusion detection. Springer, Berlin, Heidelberg","DOI":"10.1007\/978-3-540-45248-5_10"},{"issue":"11","key":"319_CR32","first-page":"11","volume":"2","author":"G Kumar","year":"2014","unstructured":"Kumar G (2014) Evaluation metrics for intrusion detection systems\u2013a study. Evaluation 2(11):11","journal-title":"Evaluation"},{"key":"319_CR33","volume-title":"A pattern matching model for misuse intrusion detection. The COAST Project","author":"S Kumar","year":"1996","unstructured":"Kumar S, Spafford EH (1996) A pattern matching model for misuse intrusion detection. The COAST Project. Purdue University, West Lafayette"},{"key":"319_CR34","volume-title":"Managing cyber threats: Issues, approaches, and challenges","author":"A Lazarevic","year":"2005","unstructured":"Lazarevic A, Kumar V, Srivastava J (2005) Managing cyber threats: Issues, approaches, and challenges. Springer, New York"},{"issue":"1\u20132","key":"319_CR35","first-page":"5","volume":"10","author":"W Lee","year":"2002","unstructured":"Lee W, Fan W, Miller M, Stolfo SJ, Zadok E (2002) Toward cost-sensitive modeling for intrusion detection and response. J ComputSecur 10(1\u20132):5\u201322","journal-title":"J ComputSecur"},{"key":"319_CR36","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/1-84628-253-5_8","volume-title":"Machine learning and data mining for computer security","author":"W Lee","year":"2006","unstructured":"Lee W, Fan W, Stolfo SJ, Miller M (2006) Cost-sensitive modeling for intrusion detection. Machine learning and data mining for computer security. Springer, London, pp 125\u2013136"},{"issue":"1","key":"319_CR37","first-page":"16","volume":"36","author":"HJ Liao","year":"2013","unstructured":"Liao HJ, Lin CHR, Lin YC, Tung KY (2013) Intrusion detection system: a comprehensive review. J NetwComputAppl 36(1):16\u201324","journal-title":"J NetwComputAppl"},{"key":"319_CR38","unstructured":"Lunt TF (1990) Ides: an intelligent system for detecting intruders. In: Proceedings of the symposium: computer security, threat and countermeasures."},{"key":"319_CR39","first-page":"405","volume":"12","author":"TF Lunt","year":"1993","unstructured":"Lunt TF (1993) A survey of intrusion detection systems. ComputSecur 12:405\u2013418","journal-title":"ComputSecur"},{"key":"319_CR40","unstructured":"Lunt TF, Jagannathan R (1988) A prototype real-time intrusion detection system. In: Proceedings of the 1988 IEEE symposium on security and privacy."},{"key":"319_CR41","doi-asserted-by":"crossref","unstructured":"Lunt TF (1988) Automated audit trial analysis and intrusion detection. In: Proceedings of the 11th national computer security conference. National Institute of Standards and Technology, Gaithersburg, MD","DOI":"10.1016\/0167-4048(92)90256-Q"},{"key":"319_CR42","unstructured":"Lunt TF, Tamaru A, Gilham F, Jagannathan R, Jalali RC, Javitz H, Valdos A, Neumann P, Garvey T (1992) A real-time intrusion detection expert system. Technical Report, Consumer Science Laboratory, SRI International"},{"key":"319_CR43","volume-title":"Intranet security-stories from the trenches","author":"L McCarthy","year":"1998","unstructured":"McCarthy L (1998) Intranet security-stories from the trenches. Sun Microsystems Press, California"},{"issue":"4","key":"319_CR44","first-page":"262","volume":"3","author":"J McHugh","year":"2000","unstructured":"McHugh J (2000) Testing intrusion detection systems: a critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by lincoln laboratory. ACM Trans InfSystSecur 3(4):262\u2013294","journal-title":"ACM Trans InfSystSecur"},{"key":"319_CR45","first-page":"189","volume":"43","author":"W Meng","year":"2014","unstructured":"Meng W, Li W, Kwok LF (2014) EFM: enhancing the performance of signature-based network intrusion detection systems using enhanced filter mechanism. ComputSecur 43:189\u2013204","journal-title":"ComputSecur"},{"key":"319_CR46","doi-asserted-by":"publisher","first-page":"483","DOI":"10.1007\/978-981-13-1274-8_36","volume-title":"Data management, analytics and innovation","author":"T Nathiya","year":"2019","unstructured":"Nathiya T, Suseendran G (2019) An effective hybrid intrusion detection system for use in security monitoring in the virtual network layer of cloud computing technology. Data management, analytics and innovation. Springer, Singapore, pp 483\u2013497"},{"key":"319_CR47","volume-title":"Configuration management and performance verification of explosives-detection systems, Publication NMAB-482-3","author":"NMAB (National Materials Advisory B","year":"1998","unstructured":"NMAB (National Materials Advisory Board), (1998) Configuration management and performance verification of explosives-detection systems, Publication NMAB-482-3. National Academy Press, Washington"},{"issue":"5","key":"319_CR48","first-page":"633","volume":"25","author":"R Ortalo","year":"1999","unstructured":"Ortalo R, Deswarte Y, Ka\u00e2niche M (1999) Experimenting with quantitative evaluation tools for monitoring operational security. IEEE Trans SoftwEng 25(5):633\u2013650","journal-title":"IEEE Trans SoftwEng"},{"issue":"12","key":"319_CR49","first-page":"3448","volume":"51","author":"A Patcha","year":"2007","unstructured":"Patcha A, Park JM (2007) An overview of anomaly detection techniques: existing solutions and latest technological trends. ComputNetw 51(12):3448\u20133470","journal-title":"ComputNetw"},{"key":"319_CR50","unstructured":"Porras PA, Kemmerer RA (1992) Penetration state transition analysis\u2013a rule-based intrusion detection approach. In: IEEE eight annual computer security applications conference"},{"key":"319_CR51","unstructured":"Porras PA, Neumann PG (1997) Emerald: event monitoring enabling responses to anomalous live disturbances. In: Proceedings of the 20th national information systems security conference"},{"key":"319_CR52","unstructured":"Provost F, Fawcett T (1997) Analysis and visualization of classifier performance: comparison under imprecise class and cost distributions. In: Proceedings of KDD-97. AAAI Press"},{"issue":"11","key":"319_CR53","doi-asserted-by":"publisher","first-page":"1457","DOI":"10.1287\/mnsc.47.11.1457.10253","volume":"47","author":"S Sarkar","year":"2001","unstructured":"Sarkar S, Sriram RS (2001) Bayesian models for early warnings of bank failures. ManagSci 47(11):1457\u20131475","journal-title":"ManagSci"},{"issue":"4","key":"319_CR54","first-page":"699","volume":"18","author":"D Singh","year":"2016","unstructured":"Singh D, Patel D, Borisaniya B, Modi C (2016) Collaborative ids framework for cloud. Int J NetwSecur 18(4):699\u2013709","journal-title":"Int J NetwSecur"},{"key":"319_CR55","volume-title":"Blocking virus requests in Novell bordermanager\u2019s HTTP accelerator","author":"T Sriram","year":"2002","unstructured":"Sriram T (2002) Blocking virus requests in Novell bordermanager\u2019s HTTP accelerator. Feature article, Novell Appnotes, Waltham"},{"issue":"2\u20133","key":"319_CR56","first-page":"169","volume":"20","author":"N Stakhanova","year":"2012","unstructured":"Stakhanova N, Strasburg C, Basu S, Wong JS (2012) Towards cost-sensitive assessment of intrusion response selection. J ComputSecur 20(2\u20133):169\u2013198","journal-title":"J ComputSecur"},{"key":"319_CR57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04117-4","volume-title":"Handbook of information and communication security","author":"P Stavroulakis","year":"2010","unstructured":"Stavroulakis P, Stamp M (2010) Handbook of information and communication security. Springer, New York"},{"key":"319_CR58","unstructured":"Steingold S, Wherry R, Piatetsky-Shapiro G (2001) Measuring real-time predictive models. In: Proceedings of IEEE international conference on data mining"},{"issue":"3","key":"319_CR59","first-page":"35","volume":"7","author":"A Tesfahun","year":"2015","unstructured":"Tesfahun A, Bhaskari DL (2015) Effective hybrid intrusion detection system: a layered approach. Int J ComputNetwInfSecur 7(3):35\u201341","journal-title":"Int J ComputNetwInfSecur"},{"issue":"2","key":"319_CR60","first-page":"97","volume":"15","author":"M Uddin","year":"2013","unstructured":"Uddin M, Rahman AA, Uddin N, Memon J, Alsaqour RA, Kazi S (2013) Signature-based multi-layer distributed intrusion detection system using mobile agents. IJ NetwSecur 15(2):97\u2013105","journal-title":"IJ NetwSecur"},{"key":"319_CR61","doi-asserted-by":"publisher","DOI":"10.1002\/0471221090","volume-title":"Detection, estimation and modulation theory\u2013part I","author":"HL Van Trees","year":"2001","unstructured":"Van Trees HL (2001) Detection, estimation and modulation theory\u2013part I. Wiley, New York"},{"issue":"47","key":"319_CR62","first-page":"16","volume":"34","author":"D Verton","year":"2000","unstructured":"Verton D (2000) Attorneys debate making cybercrime laws tougher. Computerworld 34(47):16","journal-title":"Computerworld"},{"key":"319_CR63","first-page":"63","volume":"30","author":"C Xenakis","year":"2011","unstructured":"Xenakis C, Panos C, Stavrakakis I (2011) A comparative evaluation of intrusion detection architectures for mobile ad hoc networks. ComputSecur 30:63\u201380","journal-title":"ComputSecur"},{"issue":"5","key":"319_CR64","first-page":"249","volume":"23","author":"N Zhang","year":"2006","unstructured":"Zhang N, Zeng FP, Jiang F (2006) Research on the intrusion response system based on cost-sensitive model. ComputSimul 23(5):249\u2013253","journal-title":"ComputSimul"}],"container-title":["Information Technology and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10799-020-00319-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10799-020-00319-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10799-020-00319-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,9]],"date-time":"2021-10-09T16:16:54Z","timestamp":1633796214000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10799-020-00319-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,11]]},"references-count":64,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["319"],"URL":"https:\/\/doi.org\/10.1007\/s10799-020-00319-z","relation":{},"ISSN":["1385-951X","1573-7667"],"issn-type":[{"value":"1385-951X","type":"print"},{"value":"1573-7667","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,11]]},"assertion":[{"value":"24 November 2020","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 January 2021","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}