{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T04:03:20Z","timestamp":1746158600964,"version":"3.40.4"},"reference-count":13,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2024,4,3]],"date-time":"2024-04-03T00:00:00Z","timestamp":1712102400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,4,3]],"date-time":"2024-04-03T00:00:00Z","timestamp":1712102400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Minufiya University"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The enhancement of Intrusion Detection Systems (IDS) is required to ensure protection of network resources and services. This is a hot research\u00a0topic, especially in the\u00a0presence of advanced intrusions and attacks. This paper provides a comparison between Distributed Cumulative Histogram (DCH) as a Feature Selection (FS) technique, Information Gain Ratio (IGR) FS and wrapper-based FS in terms of accuracy and Root Mean Square Error (RMSE). The utilization of DCH of the traffic instances in normal and attack cases allows us to compare the traffic charts. We can observe the difference between effective features and less effective ones. We verify the feasibility of using DCH as an FS technique in the field of anomaly detection with just six selected features giving more accurate results with most classifiers compared to the IGR and wrapper-based FS. We applied our experiments on the modern UNSW dataset with the WEKA simulation platform that contains a group of classification, feature reduction and selection techniques.<\/jats:p>","DOI":"10.1007\/s11042-023-17617-7","type":"journal-article","created":{"date-parts":[[2024,4,3]],"date-time":"2024-04-03T06:01:46Z","timestamp":1712124106000},"page":"10095-10107","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Cumulative histogram as a feature selection technique for anomaly detection"],"prefix":"10.1007","volume":"84","author":[{"given":"Mostafa","family":"Nassar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4117-3496","authenticated-orcid":false,"given":"Rania A.","family":"Salama","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adel A.","family":"Saleeb","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4542-323X","authenticated-orcid":false,"given":"Nirmeen A.","family":"El-bahnasawy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hossam Eldin H.","family":"Ahmed","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8749-9518","authenticated-orcid":false,"given":"Fathi E.","family":"Abd El-Samie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,4,3]]},"reference":[{"issue":"5","key":"17617_CR1","first-page":"47","volume":"2","author":"K Kumar","year":"2013","unstructured":"Kumar K, Kumar G, Kumar Y (2013) Feature selection approach for intrusion detection system. Int J Adv Trends Comput Sci Eng (IJATCSE) 2(5):47\u201353","journal-title":"Int J Adv Trends Comput Sci Eng (IJATCSE)"},{"key":"17617_CR2","volume-title":"Designing an online and reliable statistical anomaly detection framework for dealing with large high-speed network traffic","author":"N Moustafa","year":"2017","unstructured":"Moustafa N (2017) Designing an online and reliable statistical anomaly detection framework for dealing with large high-speed network traffic. Diss. University of New South Wales, Canberra, Australia"},{"key":"17617_CR3","unstructured":"Bhumika P et al (2018) Hybrid relabeled model for network intrusion detection. 2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData). IEEE"},{"issue":"6","key":"17617_CR4","doi-asserted-by":"publisher","first-page":"466","DOI":"10.1016\/j.cose.2009.01.001","volume":"28","author":"Y Li","year":"2009","unstructured":"Li Y et al (2009) Building lightweight intrusion detection system using wrapper-based feature selection mechanisms. Comput Secur 28(6):466\u2013475","journal-title":"Comput Secur"},{"issue":"2","key":"17617_CR5","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1109\/TNSM.2009.090604","volume":"6","author":"A Kind","year":"2009","unstructured":"Kind A, Xenofontas Dimitropoulos (2009) Histogram-based traffic anomaly detection. IEEE Trans Netw Serv Manage 6(2):110\u2013121","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"17617_CR6","doi-asserted-by":"crossref","unstructured":"Melnyk R, Tushnytskyy R (2019) Piece-wise approximation of distributed cumulative histogram features for face classification. 2019 3rd International Conference on Advanced Information and Communications Technologies (AICT). IEEE","DOI":"10.1109\/AIACT.2019.8847823"},{"key":"17617_CR7","doi-asserted-by":"crossref","unstructured":"Melnyk RA, Kalychak YI (2020) Face image barcodes by distributed cumulative histogram and clustering. 2020 IEEE 15th International Conference on Advanced Trends in Radioelectronics, Telecommunications and Computer Engineering (TCSET). IEEE","DOI":"10.1109\/TCSET49122.2020.235589"},{"key":"17617_CR8","doi-asserted-by":"crossref","unstructured":"Melnyk RA, Kalychak YI (2018) Detection of defects in printed circuit boards by flood-fill algorithm and distributed cumulative histogram. IEEE 13th International Scientific and Technical Conference on Computer Sciences and Information Technologies (CSIT). Vol. 1. IEEE","DOI":"10.1109\/STC-CSIT.2018.8526733"},{"key":"17617_CR9","doi-asserted-by":"crossref","unstructured":"Hareesh I et al (2011) Anomaly detection system based on analysis of packet header and payload histograms. 2011 International Conference on Recent Trends in Information Technology (ICRTIT). IEEE","DOI":"10.1109\/ICRTIT.2011.5972283"},{"issue":"4","key":"17617_CR10","doi-asserted-by":"publisher","first-page":"735","DOI":"10.1007\/s10922-017-9421-4","volume":"25","author":"R Hofstede","year":"2017","unstructured":"Hofstede R et al (2017) Flow-based web application brute-force Attack and compromise detection. J Netw Syst Manage 25(4):735\u2013758","journal-title":"J Netw Syst Manage"},{"key":"17617_CR11","doi-asserted-by":"crossref","unstructured":"Sen S (2015) A survey of intrusion detection systems using evolutionary computation. Bio-inspired computation in telecommunications. Morgan Kaufmann, pp 73\u201394","DOI":"10.1016\/B978-0-12-801538-4.00004-5"},{"issue":"4","key":"17617_CR12","doi-asserted-by":"publisher","first-page":"1689","DOI":"10.1007\/s11277-018-5662-0","volume":"100","author":"RA Ghazy","year":"2018","unstructured":"Ghazy RA et al (2018) Efficient techniques for Attack detection using different features selection algorithms and classifiers. Wireless Pers Commun 100(4):1689\u20131706","journal-title":"Wireless Pers Commun"},{"key":"17617_CR13","doi-asserted-by":"crossref","unstructured":"Alshawabkeh M et al (2010) Effective virtual machine monitor intrusion detection using feature selection on highly imbalanced data. 2010 Ninth International Conference on Machine Learning and Applications. IEEE","DOI":"10.1109\/ICMLA.2010.127"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-023-17617-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-023-17617-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-023-17617-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T05:04:46Z","timestamp":1746075886000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-023-17617-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,3]]},"references-count":13,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,4]]}},"alternative-id":["17617"],"URL":"https:\/\/doi.org\/10.1007\/s11042-023-17617-7","relation":{},"ISSN":["1573-7721"],"issn-type":[{"type":"electronic","value":"1573-7721"}],"subject":[],"published":{"date-parts":[[2024,4,3]]},"assertion":[{"value":"15 April 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 December 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 October 2023","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 April 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"There are no conflict of interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflict of Interests"}}]}}