{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,19]],"date-time":"2026-08-19T19:19:27Z","timestamp":1787167167531,"version":"build-2736575974"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"11","license":[{"start":{"date-parts":[[2023,1,17]],"date-time":"2023-01-17T00:00:00Z","timestamp":1673913600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,1,17]],"date-time":"2023-01-17T00:00:00Z","timestamp":1673913600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2023,7]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Nowadays, the speed of the user and application logs is so quick that it is almost impossible to analyse them in real time without using high-performance systems and platforms. In cybersecurity, human behaviour is responsible directly or indirectly for the most common attacks (i.e. ransomware and phishing). To monitor user behaviour, it is necessary to process fast user logs coming from different and heterogeneous sources, having part of the data or some entire sources missing. A framework based on the elastic stack (ELK) to process and store log data in real time from different users and applications is proposed for this aim. This system generates an ensemble of models to classify user behaviour and detect anomalies in real time, exploiting the advantages of the ELK-based software architecture and of the Kubernetes platform. In addition, a distributed evolutionary algorithm is used to classify the users by exploiting their digital footprints derived from many data sources. Experiments conducted on two real-life data sets verify the approach\u2019s goodness in detecting anomalies in user behaviour, coping with missing data and lowering the number of false alarms.<\/jats:p>","DOI":"10.1007\/s11227-023-05049-x","type":"journal-article","created":{"date-parts":[[2023,1,17]],"date-time":"2023-01-17T06:39:53Z","timestamp":1673937593000},"page":"11660-11683","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["An ensemble-based framework for user behaviour anomaly detection and classification for cybersecurity"],"prefix":"10.1007","volume":"79","author":[{"given":"Gianluigi","family":"Folino","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carla","family":"Otranto Godano","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Francesco Sergio","family":"Pisani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,1,17]]},"reference":[{"key":"5049_CR1","unstructured":"CERT Australia (2012) Cyber crime and security survey report. Technical report"},{"key":"5049_CR2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-25760-0","volume-title":"The global cyber-vulnerability report","author":"VS Subrahmanian","year":"2015","unstructured":"Subrahmanian VS, Ovelgonne M, Dumitras T, Prakash BA (2015) The global cyber-vulnerability report, 1st edn. Springer, NewYork","edition":"1"},{"key":"5049_CR3","unstructured":"van Zadelhoff M (2016) The biggest cybersecurity threats are inside your company. Digital article - harvard business review"},{"issue":"C","key":"5049_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jnca.2016.03.011","volume":"66","author":"G Folino","year":"2016","unstructured":"Folino G, Sabatino P (2016) Ensemble based collaborative and distributed intrusion detection systems: a survey. J Netw Comput Appl 66(C):1\u201316","journal-title":"J Netw Comput Appl"},{"key":"5049_CR5","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1016\/j.asoc.2018.11.009","volume":"75","author":"G Folino","year":"2019","unstructured":"Folino G, Guarascio M, Papuzzo G (2019) Exploiting fractal dimension and a distributed evolutionary approach to classify data streams with concept drifts. Appl Soft Comput 75:284\u2013297","journal-title":"Appl Soft Comput"},{"issue":"2","key":"5049_CR6","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/BF00058655","volume":"24","author":"L Breiman","year":"1996","unstructured":"Breiman L (1996) Bagging predictors. Mach Learn 24(2):123\u2013140","journal-title":"Mach Learn"},{"key":"5049_CR7","unstructured":"Freund Y, Shapire R (1996) Experiments with a new boosting algorithm. In: Machine Learning, Proceedings of the Thirteenth International Conference (ICML 96), pp 148\u2013156. Morgan Kaufmann"},{"key":"5049_CR8","doi-asserted-by":"crossref","unstructured":"Folino G, Godano CO, Pisani FS (2022) A scalable architecture exploiting elastic stack and meta ensemble of classifiers for profiling user behaviour. In: Gonz\u00e1lez-Escribano A, Jos\u00e9\u00a0Daniel Garc\u00eda, Torquati M, and Skavhaug (eds) 30th Euromicro International Conference on Parallel, Distributed and Network-Based Processing, PDP 2022, Valladolid, Spain, March 9-11, 2022, pp 189\u2013196. IEEE","DOI":"10.1109\/PDP55904.2022.00037"},{"key":"5049_CR9","doi-asserted-by":"crossref","unstructured":"Hilal W, Gadsden SA, Yawney J (2022) Financial fraud: a review of anomaly detection techniques and recent advances. Expert Syst Appl, 193(C), May 2022","DOI":"10.1016\/j.eswa.2021.116429"},{"key":"5049_CR10","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.jnca.2015.11.016","volume":"60","author":"M Ahmed","year":"2016","unstructured":"Ahmed M, Mahmood AN, Hu J (2016) A survey of network anomaly detection techniques. J Netw Comp Appl 60:19\u201331","journal-title":"J Netw Comp Appl"},{"key":"5049_CR11","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1109\/IAW.2006.1652076","volume-title":"2006 IEEE information assurance workshop","author":"R Garg","year":"2006","unstructured":"Garg R, Upadhyaya K (2006) Profiling users in GUI based systems for masquerade detection. 2006 IEEE information assurance workshop. IEEE Computer Society Press, Washington, DC, pp 48\u201354"},{"key":"5049_CR12","doi-asserted-by":"crossref","unstructured":"Tabia K, Benferhat S (2008) On the use of decision trees as behavioral approaches in intrusion detection. In 2008 Seventh International Conference on Machine Learning and Applications, pp 665\u2013670","DOI":"10.1109\/ICMLA.2008.63"},{"key":"5049_CR13","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/978-3-642-13470-8_20","volume-title":"User modeling, adaptation, and personalization","author":"G Pannell","year":"2010","unstructured":"Pannell G, Ashman H (2010) User modelling for exclusion and anomaly detection: a behavioural intrusion detection system. In: De Bra P, Kobsa A, Chin D (eds) User modeling, adaptation, and personalization. Springer, Berlin Heidelberg, Berlin, Heidelberg, pp 207\u2013218"},{"key":"5049_CR14","unstructured":"Corney M, Mohay G, Clark A (2011) Detection of anomalies from user profiles generated from system logs. In: Proceedings of the Ninth Australasian Information Security Conference - Vol 116, AISC 11, pp 23-32. Australian Computer Society, Inc"},{"issue":"1","key":"5049_CR15","first-page":"54","volume":"9","author":"A Harilal","year":"2018","unstructured":"Harilal A, Toffalini F, Homoliak I, Castellanos JH, Guarnizo J, Mondal S, Ochoa M (2018) The wolf of SUTD (TWOS): a dataset of malicious insider threat behavior based on a gamified competition. J Wirel Mob Netw Ubiquitous Comput Depend Appl 9(1):54\u201385","journal-title":"J Wirel Mob Netw Ubiquitous Comput Depend Appl"},{"issue":"19","key":"5049_CR16","doi-asserted-by":"publisher","first-page":"4018","DOI":"10.3390\/app9194018","volume":"9","author":"J Kim","year":"2019","unstructured":"Kim J, Park M, Kim H, Cho S, Kang P (2019) Insider threat detection based on user behavior modeling and anomaly detection algorithms. Appl Sci 9(19):4018","journal-title":"Appl Sci"},{"issue":"1\u20132","key":"5049_CR17","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1016\/S0020-0190(00)00122-8","volume":"76","author":"M Schonlau","year":"2000","unstructured":"Schonlau M, Theus M (2000) Detecting masquerades in intrusion detection based on unpopular commands. Inf Process Lett 76(1\u20132):33\u201338","journal-title":"Inf Process Lett"},{"issue":"5","key":"5049_CR18","doi-asserted-by":"publisher","first-page":"854","DOI":"10.1109\/TKDE.2011.17","volume":"24","author":"JA Iglesias","year":"2012","unstructured":"Iglesias JA, Angelov P, Ledezma A, Sanchis A (2012) Creating evolving user behavior profiles automatically. IEEE Trans Knowl Data Eng 24(5):854\u2013867","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"5049_CR19","doi-asserted-by":"crossref","unstructured":"Prarthana TS, Gangadhar ND (2017) User behaviour anomaly detection in multidimensional data. In: 2017 IEEE International Conference on Cloud Computing in Emerging Markets (CCEM), pp 3\u201310","DOI":"10.1109\/CCEM.2017.19"},{"key":"5049_CR20","unstructured":"Garchery M (2021) User-centered intrusion detection using heterogeneous data. PhD thesis, Universit\u00e4t Passau"},{"key":"5049_CR21","volume-title":"Statistical analysis with missing data","author":"RJA Little","year":"1986","unstructured":"Little RJA, Rubin DB (1986) Statistical analysis with missing data. John Wiley & Sons Inc, New York, NY, USA"},{"key":"5049_CR22","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1016\/j.asoc.2016.05.044","volume":"47","author":"G Folino","year":"2016","unstructured":"Folino G, Pisani FS (2016) Evolving meta-ensemble of classifiers for handling incomplete and unbalanced datasets in the cyber security domain. Appl Soft Comput 47:179\u2013190","journal-title":"Appl Soft Comput"},{"key":"5049_CR23","doi-asserted-by":"crossref","unstructured":"Folino G, Pizzuti C, Spezzano G (2001) Cage: A tool for parallel genetic programming applications. In: Miller JF, Tomassini M, Lanzi PL, Ryan C, Tettamanzi AGB, Langdon WB (eds), Proceedings of EuroGP 2001, vol 2038 of LNCS, pp 64\u201373, Lake Como, Italy, 18-20 April 2001. Springer-Verlag","DOI":"10.1007\/3-540-45355-5_6"},{"key":"5049_CR24","doi-asserted-by":"publisher","first-page":"108709","DOI":"10.1016\/j.knosys.2022.108709","volume":"46","author":"A Solomon","year":"2022","unstructured":"Solomon A, Michaelshvili M, Bitton R, Shapira B, Rokach L, Puzis R, Shabtai A (2022) Contextual security awareness: a context-based approach for assessing the security awareness of users. Knowl Based Syst 46:108709","journal-title":"Knowl Based Syst"},{"issue":"1","key":"5049_CR25","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1109\/TEVC.2002.806168","volume":"7","author":"G Folino","year":"2003","unstructured":"Folino G, Pizzuti C, Spezzano G (2003) A scalable cellular implementation of parallel genetic programming. IEEE Trans Evol Comput 7(1):37\u201353","journal-title":"IEEE Trans Evol Comput"},{"key":"5049_CR26","unstructured":"Greenberg S (1988) Using unix: collected traces of 168 users. In: Research Report 88\/333\/45. Department of Computer Science, University of Calgary, Calgary, Canada"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-023-05049-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11227-023-05049-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-023-05049-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,9]],"date-time":"2023-06-09T03:09:35Z","timestamp":1686280175000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11227-023-05049-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,17]]},"references-count":26,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2023,7]]}},"alternative-id":["5049"],"URL":"https:\/\/doi.org\/10.1007\/s11227-023-05049-x","relation":{},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,17]]},"assertion":[{"value":"5 January 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 January 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 March 2023","order":3,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Update","order":4,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Missing Open Access funding information has been added in the Funding Note.","order":5,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This declaration is not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}