{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T02:13:56Z","timestamp":1760494436645,"version":"build-2065373602"},"reference-count":25,"publisher":"Springer Science and Business Media LLC","issue":"1-2","license":[{"start":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T00:00:00Z","timestamp":1743379200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T00:00:00Z","timestamp":1743379200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"University Of South-Eastern Norway"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mobile Netw Appl"],"published-print":{"date-parts":[[2025,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>In security defense of MSN (MSN), attackers often impersonate themselves as other users, making it difficult to detect network user attacks based on user behavior. Multi-order Markov chains can consider the front-to-back correlation of user behavior, thereby more accurately identifying disguised users. Therefore, this paper proposes a user impersonation attack detection method based on multi-order Markov chains. First, the relevance coefficient method is used to determine the order of the multi-order Markov chain, and by defining appropriate multi-order Markov chain states to capture key features in user behavior, a multi-order Markov chain is established. Then, through the multi-order Markov chain combined with Shell commands, the normal behavior profile of legitimate users is established, and based on this, the probability of occurrence of the state sequence is calculated to complete the detection of userimpersonation attacks. The experimental results show that the similarity between the results of the proposed method and the actual situation in detecting impersonation attacks is more than 97%, indicating that this method can detect MSN user impersonation attacks with high accuracy.\n<\/jats:p>","DOI":"10.1007\/s11036-025-02449-6","type":"journal-article","created":{"date-parts":[[2025,4,2]],"date-time":"2025-04-02T20:28:40Z","timestamp":1743625720000},"page":"191-200","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Detection for User Impersonation Attacks in Mobile Social Networks Based on High-order Markov Chains"],"prefix":"10.1007","volume":"30","author":[{"given":"Wenhui","family":"Gong","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Youcef","family":"Djenouri","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Syed Atif","family":"Moqurrab","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,3,31]]},"reference":[{"issue":"1","key":"2449_CR1","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1504\/IJESDF.2024.136021","volume":"16","author":"A Annamalai","year":"2024","unstructured":"Annamalai A, Poonia RC, Shanmugasundaram S (2024) Internet of things-based virtual private social networks on a text messaging strategy on mobile platforms. Int J Electron Secur Digit Forensics 16(1):40\u201362","journal-title":"Int J Electron Secur Digit Forensics"},{"issue":"12","key":"2449_CR2","doi-asserted-by":"publisher","first-page":"2130","DOI":"10.1109\/JPROC.2011.2169033","volume":"99","author":"N Kayastha","year":"2011","unstructured":"Kayastha N, Niyato D, Wang P, Hossain E (2011) Applications, architectures, and protocol design issues for mobile social networks: a survey. Proc IEEE 99(12):2130\u20132158","journal-title":"Proc IEEE"},{"issue":"10","key":"2449_CR3","first-page":"404","volume":"40","author":"D Zhu","year":"2023","unstructured":"Zhu D, Lu L (2023) Simulation of malicious network behavior detection based on hyper-converged architecture. Computer Simulation 40(10):404\u2013407,510","journal-title":"Computer Simulation"},{"issue":"3","key":"2449_CR4","doi-asserted-by":"publisher","first-page":"736","DOI":"10.1109\/TCSS.2018.2855047","volume":"5","author":"W Wei","year":"2018","unstructured":"Wei W, Liu S, Li W, Atiquzzaman M, Li S, Du D (2018) Fractal intelligent privacy protection in online social network using attribute-based encryption schemes. IEEE Transactions on Computational Social Systems 5(3):736\u2013747","journal-title":"IEEE Transactions on Computational Social Systems"},{"issue":"2","key":"2449_CR5","doi-asserted-by":"publisher","DOI":"10.3390\/fi16020048","volume":"16","author":"A Assiri","year":"2024","unstructured":"Assiri A, Sallay H (2024) Efficient privacy-aware forwarding for enhanced communication privacy in opportunistic mobile social networks. Future Internet 16(2):48","journal-title":"Future Internet"},{"issue":"3","key":"2449_CR6","doi-asserted-by":"publisher","first-page":"1162","DOI":"10.1007\/s11036-022-01950-6","volume":"27","author":"Y Li","year":"2022","unstructured":"Li Y, Zhu J, Fu W (2022) Intelligent privacy protection of end user in long distance education. Mobile Networks & Applications 27(3):1162\u20131173","journal-title":"Mobile Networks & Applications"},{"key":"2449_CR7","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.120703","volume":"231","author":"D Sagar","year":"2023","unstructured":"Sagar D, Saidireddy M (2023) Security measurement in lte\/lte-a network based on zs-lr feature selection technique and um-tgan attack detection technique. Expert Syst Appl 231:120703","journal-title":"Expert Syst Appl"},{"issue":"5","key":"2449_CR8","doi-asserted-by":"publisher","first-page":"3930","DOI":"10.1109\/JIOT.2021.3100755","volume":"9","author":"SI Popoola","year":"2021","unstructured":"Popoola SI, Ande R, Adebisi B, Gui G, Jogunola O (2021) Federated deep learning for zero-day botnet attack detection in iot edge devices. IEEE Internet Things J 9(5):3930\u20133944","journal-title":"IEEE Internet Things J"},{"issue":"3","key":"2449_CR9","first-page":"911","volume":"21","author":"M Kumar","year":"2022","unstructured":"Kumar M, Ali J (2022) Taylor sailfish optimizer-based deep stacked auto encoder for blackhole attack detection in wireless sensor network. Journal of Web Engineering 21(3):911\u2013940","journal-title":"Journal of Web Engineering"},{"key":"2449_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2022.109140","volume":"214","author":"RF Fouladi","year":"2022","unstructured":"Fouladi RF, Ermi\u015f O, Anarim E (2022) A DDoS attack detection and countermeasure scheme based on DWT and auto-encoder neural network for SDN. Comput Netw 214:109140","journal-title":"Comput Netw"},{"issue":"1","key":"2449_CR11","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/s10586-021-03401-5","volume":"26","author":"AM Hilal","year":"2023","unstructured":"Hilal AM, Alohali MA, Al-Wesabi FN, Nemri N, Alyamani HJ, Gupta D (2023) Enhancing quality of experience in mobile edge computing using deep learning based data offloading and cyberattack detection technique. Clust Comput 26(1):59\u201370","journal-title":"Clust Comput"},{"key":"2449_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.peva.2023.102356","volume":"162","author":"G Somashekar","year":"2023","unstructured":"Somashekar G, Gandhi A, Delasay M (2023) Efficient and accurate lyapunov function-based truncation technique for multi-dimensional Markov chains with applications to discriminatory processor sharing and priority queues. Perform Eval 162:102356","journal-title":"Perform Eval"},{"issue":"1","key":"2449_CR13","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1137\/18M1209416","volume":"59","author":"M Briani","year":"2021","unstructured":"Briani M, Caramellino L, Terenzi G (2021) Convergence rate of markov chains and hybrid numerical schemes to jump-diffusion with application to the bates model. SIAM J Numer Anal 59(1):477\u2013502","journal-title":"SIAM J Numer Anal"},{"issue":"2","key":"2449_CR14","doi-asserted-by":"publisher","first-page":"1288","DOI":"10.1109\/TAC.2022.3170333","volume":"68","author":"G Oliva","year":"2023","unstructured":"Oliva G, Setola R, Gasparri A (2023) Distributed Markov chain redesign for multiagent decision-making problems. IEEE Trans Autom Control 68(2):1288\u20131295","journal-title":"IEEE Trans Autom Control"},{"issue":"2","key":"2449_CR15","first-page":"157","volume":"39","author":"Y Sun","year":"2023","unstructured":"Sun Y (2023) A prediction model of massive 5G network users\u2019 revisit behavior based on telecom big data. Telecommun Sci 39(2):157\u2013162","journal-title":"Telecommun Sci"},{"key":"2449_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.epsr.2021.107711","volume":"204","author":"A Pepiciello","year":"2022","unstructured":"Pepiciello A, Caro FD, Vaccaro A, Djoki S (2022) Affine arithmetic-based reliable estimation of transition state boundaries for uncertain Markov chains. Electric Power Systems Research 204:107711","journal-title":"Electric Power Systems Research"},{"issue":"2","key":"2449_CR17","doi-asserted-by":"publisher","first-page":"706","DOI":"10.1109\/TCNS.2021.3091631","volume":"9","author":"A Shefaei","year":"2021","unstructured":"Shefaei A, Mohammadpourfard M, Mohammadi-Ivatloo B, Weng Y (2021) Revealing a new vulnerability of distributed state estimation: a data integrity attack and an unsupervised detection algorithm. IEEE Transactions on Control of Network Systems 9(2):706\u2013718","journal-title":"IEEE Transactions on Control of Network Systems"},{"issue":"6","key":"2449_CR18","doi-asserted-by":"publisher","first-page":"6825","DOI":"10.1007\/s11227-022-04921-6","volume":"79","author":"PS Nandhini","year":"2023","unstructured":"Nandhini PS, Kuppuswami S, Malliga S, Devipriya R (2023) Enhanced rank attack detection algorithm (E-EAD) for securing RPL-based IoT networks by early detection and isolation of rank attackers. Journal of Supercomputing 79(6):6825\u20136848","journal-title":"Journal of Supercomputing"},{"key":"2449_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110132","volume":"261","author":"SGSR Emil","year":"2023","unstructured":"Emil SGSR, Ganeshan R, Jingle IDJ, Ananth JP (2023) FACVO-DNFN: deep learning-based feature fusion and distributed denial of service attack detection in cloud computing. Knowl-Based Syst 261:110132","journal-title":"Knowl-Based Syst"},{"issue":"2","key":"2449_CR20","doi-asserted-by":"publisher","first-page":"1705","DOI":"10.1007\/s11277-021-08716-5","volume":"127","author":"A Alqahtani","year":"2021","unstructured":"Alqahtani A, Abuhasel K, Alquraish M (2021) A novel decentralized analytical methodology for cyber physical networks attack detection. Wireless Pers Commun 127(2):1705\u20131716","journal-title":"Wireless Pers Commun"},{"issue":"8","key":"2449_CR21","first-page":"78","volume":"49","author":"Y Chen","year":"2022","unstructured":"Chen Y, Jiang Y (2022) Analysis method of APP user behavior based on convolutional neural network. Computer Science 49(8):78\u201385","journal-title":"Computer Science"},{"key":"2449_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.119606","volume":"218","author":"O Sanda","year":"2023","unstructured":"Sanda O, Pavlidis M, Seraj S, Polatidis N (2023) Long-range attack detection on permissionless blockchains using deep learning. Expert Systems with Application 218:119606","journal-title":"Expert Systems with Application"},{"issue":"7","key":"2449_CR23","doi-asserted-by":"publisher","first-page":"4498","DOI":"10.1002\/ett.4498","volume":"33","author":"RA Kumar","year":"2022","unstructured":"Kumar RA, Vinuthna K (2022) Multi-channel attack detection based on lightweight message authentication code access Control using internet of things design. Transactions on Emerging Telecommunications Technologies 33(7):4498\u20134516","journal-title":"Transactions on Emerging Telecommunications Technologies"},{"key":"2449_CR24","doi-asserted-by":"crossref","unstructured":"Demim F, Rouigueb A, Nemra A, Bouguessa R, Chahmi A (2022) A new filtering strategy for target tracking application using the second form of smooth variable structure filter. Proceedings of the Institution of Mechanical Engineers, Part I. J Syst Control Eng 236(6):1224\u20131249","DOI":"10.1177\/09596518221079485"},{"issue":"3","key":"2449_CR25","doi-asserted-by":"publisher","first-page":"4489","DOI":"10.32604\/cmc.2024.048813","volume":"78","author":"Y Wang","year":"2024","unstructured":"Wang Y, Xia Y, Liu S (2024) BCCLR: a skeleton-based action recognition with graph convolutional network combining behavior dependence and context clues. Computers, Materials & Continua 78(3):4489\u20134507","journal-title":"Computers, Materials & Continua"}],"container-title":["Mobile Networks and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-025-02449-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11036-025-02449-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11036-025-02449-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T01:42:58Z","timestamp":1760492578000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11036-025-02449-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,31]]},"references-count":25,"journal-issue":{"issue":"1-2","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["2449"],"URL":"https:\/\/doi.org\/10.1007\/s11036-025-02449-6","relation":{},"ISSN":["1383-469X","1572-8153"],"issn-type":[{"type":"print","value":"1383-469X"},{"type":"electronic","value":"1572-8153"}],"subject":[],"published":{"date-parts":[[2025,3,31]]},"assertion":[{"value":"17 March 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 March 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}}]}}