{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T10:26:20Z","timestamp":1778840780905,"version":"3.51.4"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2015,9,3]],"date-time":"2015-09-03T00:00:00Z","timestamp":1441238400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2016,7]]},"DOI":"10.1007\/s11227-015-1506-9","type":"journal-article","created":{"date-parts":[[2015,9,2]],"date-time":"2015-09-02T04:28:43Z","timestamp":1441168123000},"page":"2520-2536","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["Host-based intrusion detection system for secure human-centric computing"],"prefix":"10.1007","volume":"72","author":[{"given":"Daesung","family":"Moon","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sung Bum","family":"Pan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ikkyun","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,9,3]]},"reference":[{"key":"1506_CR1","unstructured":"NSHC (2013) 3.20 South Korea Cyber Attack, Red Alert Research Report. http:\/\/training.nshc.net\/KOR\/Document\/virus\/20130321_320CyberTerrorIncidentResponseReportbyRedAlert(EN).pdf . Accessed 24 March 2015"},{"key":"1506_CR2","unstructured":"Command Five Pty Ltd (2011) SK hack by an advanced persistent threat. http:\/\/www.commandfive.com\/papers\/C5_APT_SKHack.pdf . Accessed 24 March 2015"},{"issue":"8","key":"1506_CR3","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/S1353-4858(11)70086-1","volume":"2011","author":"C Tankard","year":"2011","unstructured":"Tankard C (2011) Persistent threats and how to monitor and deter them. Netw Secur 2011(8):16\u201319","journal-title":"Netw Secur"},{"key":"1506_CR4","unstructured":"Symantec (2011) Symantec Internet Security Threat Report. https:\/\/www4.symantec.com\/mktginfo\/downloads\/21182883_GA_REPORT_ISTR_Main-Report_04-11_HI-RES.pdf . Accessed 24 March 2015"},{"key":"1506_CR5","unstructured":"RSA (2011) RSA 2011 cybercrime trends report. Whitepaper"},{"key":"1506_CR6","doi-asserted-by":"crossref","unstructured":"Hu J (2010) Host-based anomaly intrusion detection. In: Handbook of information and communication security. Springer, Berlin, pp 235\u2013255","DOI":"10.1007\/978-3-642-04117-4_13"},{"key":"1506_CR7","unstructured":"Ashoor AS, Gore S (2011) Intrusion detection system: case study. In: Proceedings of international conference on advanced materials engineering, vol 15, pp 6\u20139"},{"key":"1506_CR8","unstructured":"NIST, Special Publication 800-30 Revision 1. Guide for conducting risk assessments. http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-30-rev1\/sp800_30_r1.pdf . Accessed 24 March 2015"},{"key":"1506_CR9","unstructured":"RSA (2011) RSA Security Brief: Mobilizing intelligent security operations for advanced persistent threats. http:\/\/www.emc.com\/collateral\/industry-overview\/11313-apt-brf.pdf , February 2011. Accessed 24 March 2015"},{"issue":"3","key":"1506_CR10","doi-asserted-by":"crossref","first-page":"491","DOI":"10.13089\/JKIISC.2014.24.3.491","volume":"24","author":"K Son","year":"2014","unstructured":"Son K, Lee T, Won D (2014) Design for Zombie PCs and APT Attack Detection based on traffic analysis. J Korea Inst Inf Secur Cryptol 24(3):491\u2013498","journal-title":"J Korea Inst Inf Secur Cryptol"},{"key":"1506_CR11","unstructured":"Verizon. Threats on the horizon\u2014the rise of the advanced persistent threat. http:\/\/www.fortinet.com\/sites\/default\/files\/solutionbrief\/threats-on-the-horizon-rise-of-advanced-persistent-threats.pdf . Accessed 24 March 2015"},{"key":"1506_CR12","unstructured":"Tandon G (2008) Machine learning for host-based anomaly detection. Dissertation, Florida Institue of Technology"},{"key":"1506_CR13","doi-asserted-by":"crossref","unstructured":"Wang W, Guan XH, Zhang XL (2004) Modeling program behaviors by hidden Markov models for intrusion detection. In: Proceedings of international conference on machine learning and cybernetics, pp 2830\u20132835","DOI":"10.1109\/ICMLC.2004.1378514"},{"key":"1506_CR14","doi-asserted-by":"crossref","unstructured":"Warrender C, Forrest S, Pearlmutter B (1999) Detecting intrusions using system calls: alternative data models. In: Proceedings of IEEE symposium on security and privacy, pp 133\u2013145","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"1506_CR15","doi-asserted-by":"crossref","unstructured":"Murtaza SS, Khreich W, Hamou-Lhadj A, Couture M (2013) A host-based anomaly detection approach by representing system calls as states of kernel modules. In: Proceedings of 24th international symposium on software reliability engineering (ISSRE), pp 431\u2013440","DOI":"10.1109\/ISSRE.2013.6698896"},{"issue":"20","key":"1506_CR16","first-page":"5","volume":"74","author":"H Kaur","year":"2013","unstructured":"Kaur H, Gill N (2013) Host based anomaly detection using fuzzy genetic approach (FGA). Int J Comput Appl 74(20):5\u20139","journal-title":"Int J Comput Appl"},{"key":"1506_CR17","doi-asserted-by":"crossref","unstructured":"Santos I et al (2010) Idea: Opcode-sequence-based malware detection. In: Proceedings of the 2nd international symposium on engineering secure software and systems (ESSoS 2010). Lecture notes in computer science, vol 5965, pp 35\u201343","DOI":"10.1007\/978-3-642-11747-3_3"},{"issue":"1","key":"1506_CR18","doi-asserted-by":"publisher","first-page":"154","DOI":"10.4218\/etrij.13.0212.0165","volume":"35","author":"HJ Kim","year":"2013","unstructured":"Kim HJ, Lee S-W (2013) A hardware-based string matching using state transition compression for deep packet inspection. ETRI J 35(1):154\u2013157. doi: 10.4218\/etrij.13.0212.0165","journal-title":"ETRI J"},{"issue":"5","key":"1506_CR19","doi-asserted-by":"publisher","first-page":"865","DOI":"10.4218\/etrij.14.0113.0798","volume":"36","author":"J Song","year":"2014","unstructured":"Song J, Kim H, Gkelias A (2014) iVisher: real-time detection of caller ID spoofing. ETRI J 36(5):865\u2013875. doi: 10.4218\/etrij.14.0113.0798","journal-title":"ETRI J"},{"issue":"2","key":"1506_CR20","doi-asserted-by":"crossref","first-page":"522","DOI":"10.1007\/s11227-011-0698-x","volume":"64","author":"J Cho","year":"2013","unstructured":"Cho J, Shon T, Choi K, Moon J (2013) Dynamic learning model update of hybrid-classifiers for intrusion detection. J Supercomput 64(2):522\u2013526","journal-title":"J Supercomput"},{"issue":"2","key":"1506_CR21","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1007\/s11227-011-0644-y","volume":"64","author":"W Xiong","year":"2013","unstructured":"Xiong W, Xiong N, Yang LT, Park JH, Hu H, Wang Q (2013) An anomaly-based detection in ubiquitous network using the equilibrium state of the catastrophe theory. J Supercomput 64(2):274\u2013294","journal-title":"J Supercomput"},{"issue":"3","key":"1506_CR22","doi-asserted-by":"crossref","first-page":"1133","DOI":"10.1007\/s11227-011-0608-2","volume":"66","author":"H Jin","year":"2013","unstructured":"Jin H, Xiang G, Zou D, Wu S, Zhao F, Li M, Zheng W (2013) A VMM-based intrusion prevention system in cloud computing environment. J Supercomput 66(3):1133\u20131151","journal-title":"J Supercomput"},{"key":"1506_CR23","unstructured":"Cuckoo sandbox. http:\/\/www.cuckoosandbox.org . Accessed 24 March 2015"},{"key":"1506_CR24","unstructured":"Process monitor. http:\/\/technet.microsoft.com\/ko-kr\/sysinternals\/bb896645 . Accessed 24 March 2015"},{"key":"1506_CR25","unstructured":"Malshare. http:\/\/malshare.com\/ . Accessed 24 March 2015"},{"key":"1506_CR26","unstructured":"WEKA Open Sources tools for Data Mining. http:\/\/www.cs.waikato.ac.nz\/ml\/weka\/ . Accessed 24 March 2015"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-015-1506-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11227-015-1506-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-015-1506-9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T06:40:41Z","timestamp":1559371241000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11227-015-1506-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,9,3]]},"references-count":26,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2016,7]]}},"alternative-id":["1506"],"URL":"https:\/\/doi.org\/10.1007\/s11227-015-1506-9","relation":{},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,9,3]]}}}