{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T01:24:59Z","timestamp":1785806699757,"version":"3.56.0"},"reference-count":18,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,11,10]],"date-time":"2021-11-10T00:00:00Z","timestamp":1636502400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,11,10]],"date-time":"2021-11-10T00:00:00Z","timestamp":1636502400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mobile Netw Appl"],"published-print":{"date-parts":[[2022,2]]},"DOI":"10.1007\/s11036-021-01843-0","type":"journal-article","created":{"date-parts":[[2021,11,10]],"date-time":"2021-11-10T03:04:32Z","timestamp":1636513472000},"page":"357-370","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":346,"title":["Towards a Standard Feature Set for Network Intrusion Detection System Datasets"],"prefix":"10.1007","volume":"27","author":[{"given":"Mohanad","family":"Sarhan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siamak","family":"Layeghy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marius","family":"Portmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,11,10]]},"reference":[{"key":"1843_CR1","doi-asserted-by":"publisher","first-page":"165130","DOI":"10.1109\/ACCESS.2020.3022862","volume":"8","author":"A Alsaedi","year":"2020","unstructured":"Alsaedi A, Moustafa N, Tari Z, Mahmood A, Anwar A (2020) Ton_iot telemetry dataset: A new generation dataset of iot and iiot for data-driven intrusion detection systems. IEEE Access 8:165130\u2013165150. https:\/\/doi.org\/10.1109\/ACCESS.2020.3022862","journal-title":"IEEE Access"},{"key":"1843_CR2","doi-asserted-by":"publisher","unstructured":"Binbusayyis A, Vaiyapuri T (2019) Identifying and benchmarking key features for cyber intrusion detection: An ensemble approach, vol 7. https:\/\/doi.org\/10.1109\/access.2019.2929487","DOI":"10.1109\/access.2019.2929487"},{"key":"1843_CR3","unstructured":"Cisco Systems (2011) Cisco IOS NetFlow Version 9 Flow-Record Format - White Paper https:\/\/www.cisco.com\/en\/US\/technologies\/tk648\/tk362\/technologies_white_paper09186a00800a3db9.pdf"},{"key":"1843_CR4","doi-asserted-by":"crossref","unstructured":"Claise B, Sadasivan G, Valluri V, Djernaes M (2004) Cisco systems netflow services export version, 9","DOI":"10.17487\/rfc3954"},{"issue":"1-2","key":"1843_CR5","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro P, Diaz-Verdejo J, Maci\u00e1-Fern\u00e1ndez G, V\u00e1zquez E (2009) Anomaly-based network intrusion detection: Techniques, systems and challenges. Comput Secur 28(1-2):18\u201328","journal-title":"Comput Secur"},{"key":"1843_CR6","unstructured":"Kerr DR, Bruins BL (2001) Network flow switching and flow data export"},{"key":"1843_CR7","doi-asserted-by":"crossref","unstructured":"Koroniotis N, Moustafa N, Sitnikova E, Turnbull B (2018) Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset. arXiv:1811.00701","DOI":"10.1016\/j.future.2019.05.041"},{"issue":"2","key":"1843_CR8","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1016\/j.jnca.2012.12.020","volume":"36","author":"B Li","year":"2013","unstructured":"Li B, Springer J, Bebis G, Hadi Gunes M (2013) A survey of network flow applications. J Netw Comput Appl 36(2):567\u2013581. https:\/\/doi.org\/10.1016\/j.jnca.2012.12.020","journal-title":"J Netw Comput Appl"},{"key":"1843_CR9","doi-asserted-by":"crossref","unstructured":"Modi CN, Patel DR, Patel A, Muttukrishnan R (2012) Bayesian classifier and snort based network intrusion detection system in cloud computing. In: 2012 Third international conference on computing, communication and networking technologies (ICCCNT\u201912). IEEE, pp 1\u20137","DOI":"10.1109\/ICCCNT.2012.6396086"},{"key":"1843_CR10","doi-asserted-by":"publisher","unstructured":"Moustafa N, Slay J (2015) Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set) 2015 Military Communications and Information Systems Conference (MilCIS). https:\/\/doi.org\/10.1109\/milcis.2015.7348942","DOI":"10.1109\/milcis.2015.7348942"},{"key":"1843_CR11","unstructured":"Ntop (2017) nProbe, An Extensible NetFlow v5\/v9\/IPFIX Probe for IPv4\/v6. https:\/\/www.ntop.org\/guides\/nprobe\/cli_options.html"},{"key":"1843_CR12","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1016\/j.cose.2019.06.005","volume":"86","author":"M Ring","year":"2019","unstructured":"Ring M, Wunderlich S, Scheuring D, Landes D, Hotho A (2019) A survey of network-based intrusion detection data sets. Comput Secur 86:147\u2013167. https:\/\/doi.org\/10.1016\/j.cose.2019.06.005","journal-title":"Comput Secur"},{"key":"1843_CR13","doi-asserted-by":"publisher","unstructured":"Sahu SK, Sarangi S, Jena SK (2014) A detail analysis on intrusion detection datasets. In: 2014 IEEE International advance computing conference (IACC). https:\/\/doi.org\/10.1109\/IAdCC.2014.6779523, pp 1348\u20131353","DOI":"10.1109\/IAdCC.2014.6779523"},{"key":"1843_CR14","unstructured":"Sarhan M (2020) Netflow datasets. http:\/\/staff.itee.uq.edu.au\/marius\/NIDS_datasets\/"},{"key":"1843_CR15","doi-asserted-by":"crossref","unstructured":"Sarhan M, Layeghy S, Moustafa N, Portmann M (2020) Netflow datasets for machine learning-based network intrusion detection systems. arXiv:2011.09144","DOI":"10.1007\/978-3-030-72802-1_9"},{"key":"1843_CR16","doi-asserted-by":"publisher","unstructured":"Sharafaldin I, Habibi Lashkari A, Ghorbani AA (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th international conference on information systems security and privacy. https:\/\/doi.org\/10.5220\/0006639801080116. https:\/\/registry.opendata.aws\/cse-cic-ids2018\/","DOI":"10.5220\/0006639801080116"},{"issue":"3","key":"1843_CR17","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"Shiravi A, Shiravi H, Tavallaee M, Ghorbani AA (2012) Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput Secur 31(3):357\u2013374. https:\/\/doi.org\/10.1016\/j.cose.2011.12.012. http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404811001672","journal-title":"Comput Secur"},{"key":"1843_CR18","doi-asserted-by":"publisher","unstructured":"Sommer R, Paxson V (2010) Outside the closed world: On using machine learning for network intrusion detection. In: 2010 IEEE Symposium on security and privacy. https:\/\/doi.org\/10.1109\/sp.2010.25","DOI":"10.1109\/sp.2010.25"}],"container-title":["Mobile Networks and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-021-01843-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11036-021-01843-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-021-01843-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,25]],"date-time":"2022-03-25T18:08:26Z","timestamp":1648231706000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11036-021-01843-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,10]]},"references-count":18,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,2]]}},"alternative-id":["1843"],"URL":"https:\/\/doi.org\/10.1007\/s11036-021-01843-0","relation":{},"ISSN":["1383-469X","1572-8153"],"issn-type":[{"value":"1383-469X","type":"print"},{"value":"1572-8153","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,10]]},"assertion":[{"value":"31 August 2021","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 November 2021","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflict of Interests"}}]}}