{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:27:22Z","timestamp":1784392042638,"version":"3.55.0"},"reference-count":160,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2018,7,2]],"date-time":"2018-07-02T00:00:00Z","timestamp":1530489600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"name":"Conselho Nacional de Desenvolvimento Cient\u00edfico e Tecnol\u00f3gico - CNPq","award":["309335\/2017-5"],"award-info":[{"award-number":["309335\/2017-5"]}]},{"name":"Conselho Nacional de Desenvolvimento Cient\u00edfico e Tecnol\u00f3gico - CNPq","award":["249794\/2013-6"],"award-info":[{"award-number":["249794\/2013-6"]}]},{"name":"Conselho Nacional de Desenvolvimento Cient\u00edfico e Tecnol\u00f3gico - CNPq","award":["Project 308348\/2016-8"],"award-info":[{"award-number":["Project 308348\/2016-8"]}]},{"DOI":"10.13039\/501100001871","name":"Funda\u00e7\u00e3o para a Ci\u00eancia e a Tecnologia","doi-asserted-by":"publisher","award":["UID\/EEA\/500008\/2013 Project"],"award-info":[{"award-number":["UID\/EEA\/500008\/2013 Project"]}],"id":[{"id":"10.13039\/501100001871","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Government of the Russian Federation","award":["Grant 074-U01"],"award-info":[{"award-number":["Grant 074-U01"]}]},{"DOI":"10.13039\/501100007258","name":"Funttel","doi-asserted-by":"crossref","award":["Grant no. 01.14.0231.00"],"award-info":[{"award-number":["Grant no. 01.14.0231.00"]}],"id":[{"id":"10.13039\/501100007258","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Telecommun Syst"],"published-print":{"date-parts":[[2019,3]]},"DOI":"10.1007\/s11235-018-0475-8","type":"journal-article","created":{"date-parts":[[2018,7,2]],"date-time":"2018-07-02T16:41:37Z","timestamp":1530549697000},"page":"447-489","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":323,"title":["A comprehensive survey on network anomaly detection"],"prefix":"10.1007","volume":"70","author":[{"suffix":"Jr.","given":"Gilberto","family":"Fernandes","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8657-3800","authenticated-orcid":false,"given":"Joel J. P. C.","family":"Rodrigues","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luiz Fernando","family":"Carvalho","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jalal F.","family":"Al-Muhtadi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"suffix":"Jr.","given":"Mario Lemes","family":"Proen\u00e7a","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,7,2]]},"reference":[{"key":"475_CR1","doi-asserted-by":"publisher","first-page":"268","DOI":"10.1109\/TNSM.2010.1012.0360","volume":"7","author":"F Hashim","year":"2010","unstructured":"Hashim, F., Munasinghe, K. S., & Jamalipour, A. (2010). Biologically inspired anomaly detection and security control frameworks for complex heterogeneous networks. IEEE Transactions on Network and Service Management, 7, 268\u2013281. https:\/\/doi.org\/10.1109\/TNSM.2010.1012.0360 .","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"475_CR2","doi-asserted-by":"crossref","unstructured":"Xiao, X., Zhang, S., Mercaldo, F., Hu, G., & Sangaiah, A. K. (2017). Android malware detection based on system call sequences and LSTM. Multimedia Tools and Applications. https:\/\/doi.org\/10.1007\/s11042-017-5104-0 .","DOI":"10.1007\/s11042-017-5104-0"},{"key":"475_CR3","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1016\/j.future.2016.08.006","volume":"74","author":"SM Balakrishnan","year":"2017","unstructured":"Balakrishnan, S. M., & Sangaiah, A. K. (2017). MIFIM\u2014Middleware solution for service centric anomaly in future internet models. Future Generation Computer Systems, 74, 349\u2013365. https:\/\/doi.org\/10.1016\/j.future.2016.08.006 .","journal-title":"Future Generation Computer Systems"},{"key":"475_CR4","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1016\/j.eswa.2018.03.027","volume":"104","author":"LF Carvalho","year":"2018","unstructured":"Carvalho, L. F., Abr\u00e3o, T., Mendes, L. S., & Proen\u00e7a, M. L. (2018). An ecosystem for anomaly detection and mitigation in software-defined networking. Expert Systems with Applications, 104, 121\u2013133. https:\/\/doi.org\/10.1016\/J.ESWA.2018.03.027 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR5","doi-asserted-by":"crossref","unstructured":"Lu, S., Wang, X., & Mao, L. (2014). Network security situation awareness based on network simulation. In 2014 IEEE workshop on electronics, computer and applications (pp. 512\u2013517). https:\/\/doi.org\/10.1109\/IWECA.2014.6845671 .","DOI":"10.1109\/IWECA.2014.6845671"},{"key":"475_CR6","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1016\/j.knosys.2017.03.012","volume":"126","author":"SM Hosseini Bamakan","year":"2017","unstructured":"Hosseini Bamakan, S. M., Wang, H., & Shi, Y. (2017). Ramp loss K-support vector classification-regression: A robust and sparse multi-class approach to the intrusion detection problem. Knowledge-Based Systems, 126, 113\u2013126. https:\/\/doi.org\/10.1016\/j.knosys.2017.03.012 .","journal-title":"Knowledge-Based Systems"},{"key":"475_CR7","doi-asserted-by":"crossref","unstructured":"Lof, A., & Nelson, R. (2014). Annotating network trace data for anomaly detection research. In 2014 IEEE 39th conference on local computer networks workshops (LCN workshops) (pp. 679\u2013684). https:\/\/doi.org\/10.1109\/LCNW.2014.6927720 .","DOI":"10.1109\/LCNW.2014.6927720"},{"key":"475_CR8","volume-title":"Outliers in statistical data","author":"V Barnett","year":"1994","unstructured":"Barnett, V., & Lewis, T. (1994). Outliers in statistical data (3rd ed.). New York: Wiley.","edition":"3"},{"key":"475_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V Chandola","year":"2009","unstructured":"Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41, 1\u201358. https:\/\/doi.org\/10.1145\/1541880.1541882 .","journal-title":"ACM Computing Surveys"},{"key":"475_CR10","doi-asserted-by":"crossref","unstructured":"Lakhina, A., Crovella, M., & Diot, C. (2004). Diagnosing network-wide traffic anomalies. In ACM SIGCOMM computer communication review (Vol. 34, p. 219). https:\/\/doi.org\/10.1145\/1030194.1015492 .","DOI":"10.1145\/1030194.1015492"},{"key":"475_CR11","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1016\/j.jnca.2013.08.001","volume":"40","author":"N Hoque","year":"2014","unstructured":"Hoque, N., Bhuyan, M. H., Baishya, R. C., Bhattacharyya, D. K., & Kalita, J. K. (2014). Network attacks: Taxonomy, tools and systems. Journal of Network and Computer Applications, 40, 307\u2013324. https:\/\/doi.org\/10.1016\/j.jnca.2013.08.001 .","journal-title":"Journal of Network and Computer Applications"},{"key":"475_CR12","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-1-84882-765-3_11","volume-title":"Algorithms for next generation networks","author":"M Thottan","year":"2010","unstructured":"Thottan, M., Liu, G., & Ji, C. (2010). Anomaly detection approaches for communication networks. In G. Cormode & M. Thottan (Eds.), Algorithms for next generation networks (pp. 239\u2013261). London: Springer. https:\/\/doi.org\/10.1007\/978-1-84882-765-3_11 ."},{"key":"475_CR13","doi-asserted-by":"publisher","first-page":"3448","DOI":"10.1016\/j.comnet.2007.02.001","volume":"51","author":"A Patcha","year":"2007","unstructured":"Patcha, A., & Park, J.-M. (2007). An overview of anomaly detection techniques: Existing solutions and latest technological trends. Computer Networks, 51, 3448\u20133470. https:\/\/doi.org\/10.1016\/j.comnet.2007.02.001 .","journal-title":"Computer Networks"},{"key":"475_CR14","first-page":"9","volume":"28","author":"Y Yu","year":"2012","unstructured":"Yu, Y. (2012). A survey of anomaly intrusion detection techniques. Journal of Computing Sciences in Colleges, 28, 9\u201317.","journal-title":"Journal of Computing Sciences in Colleges"},{"key":"475_CR15","doi-asserted-by":"crossref","unstructured":"Weiyu, Z., Qingbo, Y., & Yushui, G. (2009). A survey of anomaly detection methods in networks. In International symposium on computer network and multimedia technology, 2009. CNMT 2009 (pp. 1\u20133). https:\/\/doi.org\/10.1109\/CNMT.2009.5374676 .","DOI":"10.1109\/CNMT.2009.5374676"},{"key":"475_CR16","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1016\/j.comnet.2014.08.007","volume":"73","author":"AK Marnerides","year":"2014","unstructured":"Marnerides, A. K., Schaeffer-Filho, A., & Mauthe, A. (2014). Traffic anomaly diagnosis in Internet backbone networks: A survey. Computer Networks, 73, 224\u2013243. https:\/\/doi.org\/10.1016\/j.comnet.2014.08.007 .","journal-title":"Computer Networks"},{"key":"475_CR17","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1109\/SURV.2013.052213.00046","volume":"16","author":"MH Bhuyan","year":"2014","unstructured":"Bhuyan, M. H., Bhattacharyya, D. K., & Kalita, J. K. (2014). Network anomaly detection: Methods, systems and tools. IEEE Communications Surveys & Tutorials, 16, 303\u2013336. https:\/\/doi.org\/10.1109\/SURV.2013.052213.00046 .","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"475_CR18","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/j.jnca.2015.11.016","volume":"60","author":"M Ahmed","year":"2016","unstructured":"Ahmed, M., Naser Mahmood, A., & Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, 60, 19\u201331. https:\/\/doi.org\/10.1016\/j.jnca.2015.11.016 .","journal-title":"Journal of Network and Computer Applications"},{"key":"475_CR19","doi-asserted-by":"publisher","first-page":"631","DOI":"10.1109\/TKDE.2007.1009","volume":"19","author":"S Xiuyao","year":"2007","unstructured":"Xiuyao, S., Mingxi, W., Jermaine, C., & Ranka, S. (2007). Conditional anomaly detection. IEEE Transactions on Knowledge and Data Engineering, 19, 631\u2013644. https:\/\/doi.org\/10.1109\/TKDE.2007.1009 .","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"475_CR20","doi-asserted-by":"crossref","unstructured":"Barford, P., Kline, J., Plonka, D., & Ron, A. (2002). A signal analysis of network traffic anomalies. In Proceedings of the 2nd ACM SIGCOMM workshop on internet measurment\u2014IMW \u201902. ACM Press, New York, NY, USA (p. 71). https:\/\/doi.org\/10.1145\/637201.637210 .","DOI":"10.1145\/637201.637210"},{"key":"475_CR21","doi-asserted-by":"crossref","unstructured":"Barford, P., & Plonka, D. (2001). Characteristics of network traffic flow anomalies. Proceedings of the 1st ACM SIGCOMM workshop on internet measurement (pp. 69\u201373). https:\/\/doi.org\/10.1145\/505202.505211 .","DOI":"10.1145\/505202.505211"},{"key":"475_CR22","doi-asserted-by":"crossref","unstructured":"Jung, J., Krishnamurthy, B., & Rabinovich, M. (2002). Flash crowds and denial of service attacks. In Proceedings of the 11th international conference on World Wide Web\u2014WWW \u201902 (p. 293). https:\/\/doi.org\/10.1145\/511446.511485 .","DOI":"10.1145\/511446.511485"},{"key":"475_CR23","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1016\/j.physa.2014.06.085","volume":"413","author":"J Pan","year":"2014","unstructured":"Pan, J., Hu, H., & Liu, Y. (2014). Human behavior during Flash Crowd in web surfing. Physica A: Statistical Mechanics and Its Applications, 413, 212\u2013219. https:\/\/doi.org\/10.1016\/j.physa.2014.06.085 .","journal-title":"Physica A: Statistical Mechanics and Its Applications"},{"key":"475_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-0-387-88771-5_1","volume":"47","author":"AA Ghorbani","year":"2010","unstructured":"Ghorbani, A. A., Lu, W., & Tavallaee, M. (2010). Network attacks. Advances in Information Security, 47, 1\u201325. https:\/\/doi.org\/10.1007\/978-0-387-88771-5_1 .","journal-title":"Advances in Information Security"},{"key":"475_CR25","doi-asserted-by":"crossref","unstructured":"Mouton, F., Malan, M. M., & Venter, H. S. (2013). Social engineering from a normative ethics perspective. In Information security for South Africa, 2013 (pp. 1\u20138). https:\/\/doi.org\/10.1109\/ISSA.2013.6641064 .","DOI":"10.1109\/ISSA.2013.6641064"},{"key":"475_CR26","doi-asserted-by":"crossref","unstructured":"Maxion, R. A., & Townsend, T. N. (2002). Masquerade detection using truncated command lines. In International conference on dependable systems and networks, 2002. DSN 2002. Proceedings (pp. 219\u2013228). https:\/\/doi.org\/10.1109\/DSN.2002.1028903 .","DOI":"10.1109\/DSN.2002.1028903"},{"key":"475_CR27","volume-title":"The art of computer virus research and defense","author":"P Szor","year":"2005","unstructured":"Szor, P. (2005). The art of computer virus research and defense. Reading: Addison-Wesley."},{"key":"475_CR28","doi-asserted-by":"crossref","unstructured":"Weaver, N., Paxson, V., Staniford, S., & Cunningham, R., (2003). A taxonomy of computer worms. In Proceedings of the 2003 ACM workshop on Rapid malcode (pp. 11\u201318). https:\/\/doi.org\/10.1145\/948187.948190 .","DOI":"10.1145\/948187.948190"},{"key":"475_CR29","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1216370.1216373","volume":"39","author":"T Peng","year":"2007","unstructured":"Peng, T., Leckie, C., & Ramamohanarao, K. (2007). Survey of network-based defense mechanisms countering the DoS and DDoS problems. ACM Computing Surveys, 39, 3. https:\/\/doi.org\/10.1145\/1216370.1216373 .","journal-title":"ACM Computing Surveys"},{"key":"475_CR30","doi-asserted-by":"crossref","unstructured":"Mohana Priya, P., Akilandeswari, V., Mercy Shalinie, S., Lavanya, V., & Shanmuga Priya, M. (2014). The protocol independent detection and classification (PIDC) system for DRDoS attack. In 2014 International conference on recent trends in information technology (ICRTIT) (pp. 1\u20137). IEEE. https:\/\/doi.org\/10.1109\/ICRTIT.2014.6996154 .","DOI":"10.1109\/ICRTIT.2014.6996154"},{"key":"475_CR31","doi-asserted-by":"crossref","unstructured":"Muller, T., & Freiling, F. C. (2014). A systematic assessment of the security of full disk encryption. IEEE Transactions on Dependable and Secure Computing. https:\/\/doi.org\/10.1109\/TDSC.2014.2369041 .","DOI":"10.1109\/TDSC.2014.2369041"},{"key":"475_CR32","doi-asserted-by":"publisher","first-page":"439","DOI":"10.5829\/idosi.wasj.2012.19.04.1837","volume":"19","author":"M Raza","year":"2012","unstructured":"Raza, M., & Haider, W. (2012). A survey of password attacks and comparative analysis on methods for secure authentication. World Applied Sciences Journal, 19, 439\u2013444. https:\/\/doi.org\/10.5829\/idosi.wasj.2012.19.04.1837 .","journal-title":"World Applied Sciences Journal"},{"key":"475_CR33","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1016\/B978-0-12-801308-3.00002-0","volume-title":"Cyber Reconnaissance, surveillance and defense","author":"R Shimonski","year":"2015","unstructured":"Shimonski, R., Zenir, J., & Bishop, A. (2015). Chapter 2: Information gathering. In R. S. Z. Bishop (Ed.), Cyber Reconnaissance, surveillance and defense (pp. 45\u201384). Boston: Syngress. https:\/\/doi.org\/10.1016\/B978-0-12-801308-3.00002-0 ."},{"key":"475_CR34","unstructured":"Harrington, D., Presuhn, R., & Wijnen, B. (2002). RFC 3411: An architecture for describing simple network management protocol (SNMP) management frameworks (pp. 1\u201364). https:\/\/tools.ietf.org\/html\/rfc3411 . Accessed 23 Oct 2017."},{"key":"475_CR35","doi-asserted-by":"publisher","first-page":"2191","DOI":"10.1109\/TSP.2003.814797","volume":"51","author":"M Thottan","year":"2003","unstructured":"Thottan, M., & Ji, C. (2003). Anomaly detection in IP networks. IEEE Transactions on Signal Processing, 51, 2191\u20132204. https:\/\/doi.org\/10.1109\/TSP.2003.814797 .","journal-title":"IEEE Transactions on Signal Processing"},{"key":"475_CR36","doi-asserted-by":"crossref","unstructured":"Cabrera, J. B. D., Lewis, L., Qin, X., Lee, W., Prasanth, R. K., Ravichandran, B., & Mehra, R. K. (2001). Proactive detection of distributed denial of service attacks using MIB traffic variables: A feasibility study. In 2001 IEEE\/IFIP International symposium on integrated network management proceedings. VII. Integr. Manag. Strateg. New Millenn. (Cat. No. 01EX470) (pp. 609\u2013622). IEEE. https:\/\/doi.org\/10.1109\/INM.2001.918069 .","DOI":"10.1109\/INM.2001.918069"},{"key":"475_CR37","doi-asserted-by":"publisher","first-page":"4212","DOI":"10.1016\/j.comcom.2008.09.018","volume":"31","author":"J Yu","year":"2008","unstructured":"Yu, J., Lee, H., Kim, M.-S., & Park, D. (2008). Traffic flooding attack detection with SNMP MIB using SVM. Computer Communications, 31, 4212\u20134219. https:\/\/doi.org\/10.1016\/j.comcom.2008.09.018 .","journal-title":"Computer Communications"},{"key":"475_CR38","doi-asserted-by":"crossref","unstructured":"Lima, M. F., Sampaio, L. D. H., Zarpelao, B. B., Rodrigues, J. J. P. C., Abrao, T., & Proenca, M. L., Jr. (2010). Networking anomaly detection using DSNs and particle swarm optimization with re-clustering. In 2010 IEEE global telecommunications conference GLOBECOM 2010 (pp. 1\u20136). IEEE. https:\/\/doi.org\/10.1109\/GLOCOM.2010.5683910 .","DOI":"10.1109\/GLOCOM.2010.5683910"},{"key":"475_CR39","doi-asserted-by":"crossref","unstructured":"Zarpelao, B. B., Mendes, L. S., Proenca Jr., M. L., & Rodrigues, J. J. P. C. (2009). Parameterized anomaly detection system with automatic configuration. In GLOBECOM 2009\u20142009 IEEE global telecommunications conference (pp. 1\u20136). IEEE. https:\/\/doi.org\/10.1109\/GLOCOM.2009.5426189 .","DOI":"10.1109\/GLOCOM.2009.5426189"},{"key":"475_CR40","doi-asserted-by":"crossref","unstructured":"Duffield, N., Haffner, P., Krishnamurthy, B., & Ringberg, H. (2009). Rule-based anomaly detection on IP flows. In IEEE INFOCOM 2009\u201428th Conference on Computer Communications (pp. 424\u2013432). IEEE. https:\/\/doi.org\/10.1109\/INFCOM.2009.5061947 .","DOI":"10.1109\/INFCOM.2009.5061947"},{"key":"475_CR41","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1145\/2034594.2034598","volume":"11","author":"R Fontugne","year":"2011","unstructured":"Fontugne, R., & Fukuda, K. (2011). A Hough-transform-based anomaly detector with an adaptive time interval. ACM SIGAPP Applied Computing Review, 11, 41\u201351. https:\/\/doi.org\/10.1145\/2034594.2034598 .","journal-title":"ACM SIGAPP Applied Computing Review"},{"key":"475_CR42","unstructured":"Introduction to Cisco IOS\u00aeNetFlow (White Paper), (2012) 1\u201316. http:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/ios-nx-os software\/iosnetflow\/prod_white_paper0900aecd80406232.pdf . Accessed 10 Dec 2017."},{"key":"475_CR43","unstructured":"Claise, B. (2004). RFC 3954: Cisco systems netflow services export version 9 (pp. 1\u201333). https:\/\/tools.ietf.org\/html\/rfc3954 . Accessed September 2, 2016."},{"key":"475_CR44","unstructured":"Trammell, B., & Claise, B. (2013). RFC 7011: Specification of the IP flow information export (IPFIX) protocol for the exchange of flow information, 1\u201353. 2070-1721."},{"key":"475_CR45","doi-asserted-by":"crossref","unstructured":"Chapman, C. (2016). Chapter 10: Traffic performance testing in the network. In Network performance and security (pp. 295\u2013317). https:\/\/doi.org\/10.1016\/B978-0-12-803584-9.00010-X .","DOI":"10.1016\/B978-0-12-803584-9.00010-X"},{"key":"475_CR46","unstructured":"NfSen: NetFlow sensor. (2011). http:\/\/nfsen.sourceforge.net\/ . Accessed September 2, 2016."},{"key":"475_CR47","unstructured":"nTop. (2016). http:\/\/www.ntop.org\/ . Accessed September 2, 2016."},{"key":"475_CR48","unstructured":"Panchen, S., Phaal, P., & McKee, N. (2001). RFC 3176: InMon Corporation\u2019s sFlow: A method for monitoring traffic in switched and routed networks, 1\u201331. https:\/\/tools.ietf.org\/html\/rfc3176 . Accessed September 2, 2016."},{"key":"475_CR49","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1214\/088342304000000206","volume":"19","author":"N Duffield","year":"2004","unstructured":"Duffield, N. (2004). Sampling for passive internet measurement: A review. Statistical Science, 19, 472\u2013498. https:\/\/doi.org\/10.1214\/088342304000000206 .","journal-title":"Statistical Science"},{"key":"475_CR50","unstructured":"Cisco NetFlow-Lite Solution Overview, Cisco. (2016). http:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/switches\/catalyst-2960-x-series-switches\/solution_overview_c22-728776.html . Accessed September 2, 2016."},{"key":"475_CR51","unstructured":"Deri, L., Chou, E., Cherian, Z., Karmarkar, K., & Patterson, M. (2011). Increasing data center network visibility with cisco NetFlow-Lite. In International conference on network and service management (pp. 1\u20136)."},{"key":"475_CR52","doi-asserted-by":"crossref","unstructured":"Jadidi, Z., Muthukkumarasamy, V., Sithirasenan, E., & Singh, K. (2015). Flow-based anomaly detection in big data. In Network big data (pp. 257\u2013279). Chapman and Hall\/CRC. https:\/\/doi.org\/10.1201\/b18772-17 .","DOI":"10.1201\/b18772-17"},{"key":"475_CR53","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1109\/SURV.2010.032210.00054","volume":"12","author":"A Sperotto","year":"2010","unstructured":"Sperotto, A., Schaffrath, G., Sadre, R., Morariu, C., Pras, A., & Stiller, B. (2010). An overview of IP flow-based intrusion detection. IEEE Communications Surveys and Tutorials, 12, 343\u2013356. https:\/\/doi.org\/10.1109\/SURV.2010.032210.00054 .","journal-title":"IEEE Communications Surveys and Tutorials"},{"key":"475_CR54","doi-asserted-by":"crossref","unstructured":"Winter, P., Hermann, E., & Zeilinger, M. (2011). Inductive intrusion detection in flow-based network data using one-class support vector machines. In 2011 4th IFIP international conference on new technologies, mobility and security (pp. 1\u20135). IEEE. https:\/\/doi.org\/10.1109\/NTMS.2011.5720582 .","DOI":"10.1109\/NTMS.2011.5720582"},{"key":"475_CR55","doi-asserted-by":"crossref","unstructured":"Bartos, K., Rehak, M., & Krmicek, V. (2011). Optimizing flow sampling for network anomaly detection. In 2011 7th international wireless communications and mobile computing conference (pp. 1304\u20131309). IEEE. https:\/\/doi.org\/10.1109\/IWCMC.2011.5982728 .","DOI":"10.1109\/IWCMC.2011.5982728"},{"key":"475_CR56","doi-asserted-by":"publisher","first-page":"1162","DOI":"10.1587\/transinf.E93.D.1162","volume":"E93\u2013D","author":"Y Zhang","year":"2010","unstructured":"Zhang, Y., Fang, B., & Luo, H. (2010). Identifying high-rate flows based on sequential sampling. IEICE Transactions on Information and Systems, E93\u2013D, 1162\u20131174. https:\/\/doi.org\/10.1587\/transinf.E93.D.1162 .","journal-title":"IEICE Transactions on Information and Systems"},{"key":"475_CR57","doi-asserted-by":"crossref","unstructured":"Silva, J. M. C., Carvalho, P., & Lima, S. R. (2015). Analysing traffic flows through sampling: A comparative study. In 2015 IEEE symposium on computers and communications (pp. 341\u2013346). https:\/\/doi.org\/10.1109\/ISCC.2015.7405538 .","DOI":"10.1109\/ISCC.2015.7405538"},{"key":"475_CR58","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/MC.2002.1012428","volume":"35","author":"RA Kemmerer","year":"2002","unstructured":"Kemmerer, R. A., & Vigna, G. (2002). Intrusion detection: A brief history and overview. Computer, 35, 27\u201330. https:\/\/doi.org\/10.1109\/MC.2002.1012428 .","journal-title":"Computer"},{"key":"475_CR59","unstructured":"Lee, W., & Stolfo, S. (1998). Data mining approaches for intrusion detection. In Proceedings of 7th {USENIX} security symposium, USENIX Association (pp. 6\u20136). https:\/\/dl.acm.org\/citation.cfm?id=1267555 . Accessed November 1, 2017."},{"key":"475_CR60","doi-asserted-by":"publisher","first-page":"981","DOI":"10.1016\/j.jcss.2014.12.012","volume":"81","author":"W Bul\u2019ajoul","year":"2015","unstructured":"Bul\u2019ajoul, W., James, A., & Pannu, M. (2015). Improving network intrusion detection system performance through quality of service configuration and parallel technology. Journal of Computer and System Sciences, 81, 981\u2013999. https:\/\/doi.org\/10.1016\/j.jcss.2014.12.012 .","journal-title":"Journal of Computer and System Sciences"},{"key":"475_CR61","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1016\/j.comcom.2016.12.001","volume":"98","author":"H Bostani","year":"2017","unstructured":"Bostani, H., & Sheikhan, M. (2017). Hybrid of anomaly-based and specification-based IDS for Internet of Things using unsupervised OPF based on MapReduce approach. Computer Communications, 98, 52\u201371. https:\/\/doi.org\/10.1016\/j.comcom.2016.12.001 .","journal-title":"Computer Communications"},{"key":"475_CR62","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2808691","volume":"48","author":"A Milenkoski","year":"2015","unstructured":"Milenkoski, A., Vieira, M., Kounev, S., Avritzer, A., & Payne, B. D. (2015). Evaluating computer intrusion detection systems: A survey of common practices. ACM Computing Surveys, 48, 1\u201341. https:\/\/doi.org\/10.1145\/2808691 .","journal-title":"ACM Computing Surveys"},{"key":"475_CR63","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1109\/SURV.2013.050113.00191","volume":"16","author":"I Butun","year":"2014","unstructured":"Butun, I., Morgera, S. D., & Sankar, R. (2014). A survey of intrusion detection systems in wireless sensor networks. IEEE Communications Surveys & Tutorials, 16, 266\u2013282. https:\/\/doi.org\/10.1109\/SURV.2013.050113.00191 .","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"475_CR64","doi-asserted-by":"publisher","first-page":"805","DOI":"10.1016\/S1389-1286(98)00017-6","volume":"31","author":"H Debar","year":"1999","unstructured":"Debar, H., Dacier, M., & Wespi, A. (1999). Towards a taxonomy of intrusion\u2013detection systems. Computer Networks, 31, 805\u2013822. https:\/\/doi.org\/10.1016\/S1389-1286(98)00017-6 .","journal-title":"Computer Networks"},{"key":"475_CR65","doi-asserted-by":"crossref","unstructured":"Meng Hui, L., & Jones, A. (2008). Network anomaly detection system: The state of art of network behaviour analysis. In International conference on convergence and hybrid information technology 2008. ICHIT \u201908 (pp. 459\u2013465). https:\/\/doi.org\/10.1109\/ICHIT.2008.249 .","DOI":"10.1109\/ICHIT.2008.249"},{"key":"475_CR66","doi-asserted-by":"publisher","first-page":"670","DOI":"10.1016\/j.csi.2005.07.002","volume":"28","author":"TS Sobh","year":"2006","unstructured":"Sobh, T. S. (2006). Wired and wireless intrusion detection system: Classifications, good characteristics and state-of-the-art. Computer Standards & Interfaces, 28, 670\u2013694. https:\/\/doi.org\/10.1016\/j.csi.2005.07.002 .","journal-title":"Computer Standards & Interfaces"},{"key":"475_CR67","doi-asserted-by":"publisher","first-page":"900","DOI":"10.1016\/j.ins.2014.03.102","volume":"278","author":"MVO Assis de","year":"2014","unstructured":"de Assis, M. V. O., Rodrigues, J. J. P. C., & Proen\u00e7a, M. L. (2014). A seven-dimensional flow analysis to help autonomous network management. Information Sciences, 278, 900\u2013913. https:\/\/doi.org\/10.1016\/j.ins.2014.03.102 .","journal-title":"Information Sciences"},{"key":"475_CR68","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1016\/j.cose.2009.08.007","volume":"29","author":"N Stakhanova","year":"2010","unstructured":"Stakhanova, N., Basu, S., & Wong, J. (2010). On the symbiosis of specification-based and anomaly-based detection. Computers & Security, 29, 253\u2013268. https:\/\/doi.org\/10.1016\/j.cose.2009.08.007 .","journal-title":"Computers & Security"},{"key":"475_CR69","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1145\/1012888.1005697","volume":"32","author":"A Lakhina","year":"2004","unstructured":"Lakhina, A., Papagiannaki, K., Crovella, M., Diot, C., Kolaczyk, E. D., & Taft, N. (2004). Structural analysis of network traffic flows. ACM SIGMETRICS Performance Evaluation Review, 32, 61. https:\/\/doi.org\/10.1145\/1012888.1005697 .","journal-title":"ACM SIGMETRICS Performance Evaluation Review"},{"key":"475_CR70","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1145\/1090191.1080118","volume":"35","author":"A Lakhina","year":"2005","unstructured":"Lakhina, A., Crovella, M., & Diot, C. (2005). Mining anomalies using traffic feature distributions. ACM SIGCOMM Computer Communication Review, 35, 217. https:\/\/doi.org\/10.1145\/1090191.1080118 .","journal-title":"ACM SIGCOMM Computer Communication Review"},{"key":"475_CR71","doi-asserted-by":"publisher","first-page":"692","DOI":"10.1016\/j.cose.2011.08.006","volume":"30","author":"C Callegari","year":"2011","unstructured":"Callegari, C., Giordano, S., Pagano, M., & Pepe, T. (2011). Combining sketches and wavelet analysis for multi time-scale network anomaly detection. Computers & Security, 30, 692\u2013704. https:\/\/doi.org\/10.1016\/j.cose.2011.08.006 .","journal-title":"Computers & Security"},{"key":"475_CR72","doi-asserted-by":"publisher","first-page":"3203","DOI":"10.1016\/j.comcom.2007.05.061","volume":"30","author":"M Hamdi","year":"2007","unstructured":"Hamdi, M., & Boudriga, N. (2007). Detecting Denial-of-Service attacks using the wavelet transform. Computer Communications, 30, 3203\u20133213. https:\/\/doi.org\/10.1016\/j.comcom.2007.05.061 .","journal-title":"Computer Communications"},{"key":"475_CR73","volume-title":"Principal component analysis","author":"IT Jolliffe","year":"2002","unstructured":"Jolliffe, I. T. (2002). Principal component analysis. Berlin: Springer."},{"key":"475_CR74","volume-title":"A user\u2019s guide to principal components","author":"JE Jackson","year":"2005","unstructured":"Jackson, J. E. (2005). A user\u2019s guide to principal components. New York: Wiley."},{"key":"475_CR75","doi-asserted-by":"publisher","first-page":"109","DOI":"10.1145\/1269899.1254895","volume":"35","author":"H Ringberg","year":"2007","unstructured":"Ringberg, H., Soule, A., Rexford, J., & Diot, C. (2007). Sensitivity of PCA for traffic anomaly detection. SIGMETRICS Performance Evaluation Review, 35, 109\u2013120. https:\/\/doi.org\/10.1145\/1269899.1254895 .","journal-title":"SIGMETRICS Performance Evaluation Review"},{"key":"475_CR76","unstructured":"Wright, J., Ganesh, A., Rao, S., Peng, Y., & Ma, Y. (2009). Robust principal component analysis: Exact recovery of corrupted low-rank matrices via convex optimization. In Y. Bengio, D. Schuurmans, J. D. Lafferty, C. K. I. Williams, & A. Culotta (Eds.), Advances in neural information processing systems (Vol. 22, pp. 2080\u20132088). Curran Associates, Inc. http:\/\/papers.nips.cc\/paper\/3704-robust-principal-component-analysis-exact-recovery-of-corrupted-low-rank-matrices-via-convex-optimization.pdf ."},{"key":"475_CR77","doi-asserted-by":"publisher","first-page":"11:1","DOI":"10.1145\/1970392.1970395","volume":"58","author":"EJ Cand\u00e8s","year":"2011","unstructured":"Cand\u00e8s, E. J., Li, X., Ma, Y., & Wright, J. (2011). Robust principal component analysis? Journal of the ACM, 58, 11:1\u201311:37. https:\/\/doi.org\/10.1145\/1970392.1970395 .","journal-title":"Journal of the ACM"},{"key":"475_CR78","doi-asserted-by":"crossref","unstructured":"Pascoal, C., Rosario de Oliveira, M., Valadas, R., Filzmoser, P., Salvador, P., & Pacheco, A. (2012). Robust feature selection and robust PCA for internet traffic anomaly detection. In INFOCOM, 2012 Proceedings of IEEE (pp. 1755\u20131763). https:\/\/doi.org\/10.1109\/INFCOM.2012.6195548 .","DOI":"10.1109\/INFCOM.2012.6195548"},{"key":"475_CR79","doi-asserted-by":"publisher","first-page":"575","DOI":"10.1016\/j.comcom.2012.12.002","volume":"36","author":"Y Kanda","year":"2013","unstructured":"Kanda, Y., Fontugne, R., Fukuda, K., & Sugawara, T. (2013). ADMIRE: Anomaly detection method using entropy-based PCA with three-step sketches. Computer Communications, 36, 575\u2013588. https:\/\/doi.org\/10.1016\/j.comcom.2012.12.002 .","journal-title":"Computer Communications"},{"key":"475_CR80","doi-asserted-by":"publisher","first-page":"2320","DOI":"10.1109\/TKDE.2016.2555804","volume":"28","author":"C OReilly","year":"2016","unstructured":"OReilly, C., Gluhak, A., & Imran, M. A. (2016). Distributed anomaly detection using minimum volume elliptical principal component analysis. IEEE Transactions on Knowledge and Data Engineering, 28, 2320\u20132333. https:\/\/doi.org\/10.1109\/TKDE.2016.2555804 .","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"475_CR81","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1016\/j.cose.2016.02.008","volume":"59","author":"J Camacho","year":"2016","unstructured":"Camacho, J., P\u00e9rez-Villegas, A., Garc\u00eda-Teodoro, P., & Maci\u00e1-Fern\u00e1ndez, G. (2016). PCA-based multivariate statistical network monitoring for anomaly detection. Computers & Security, 59, 118\u2013137. https:\/\/doi.org\/10.1016\/j.cose.2016.02.008 .","journal-title":"Computers & Security"},{"key":"475_CR82","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jnca.2015.11.024","volume":"64","author":"G Fernandes","year":"2016","unstructured":"Fernandes, G., Carvalho, L. F., Rodrigues, J. J. P. C., & Proen\u00e7a, M. L. (2016). Network anomaly detection using IP flows with principal component analysis and ant colony optimization. Journal of Network and Computer Applications, 64, 1\u201311. https:\/\/doi.org\/10.1016\/j.jnca.2015.11.024 .","journal-title":"Journal of Network and Computer Applications"},{"key":"475_CR83","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1016\/j.asoc.2015.05.019","volume":"34","author":"G Fernandes","year":"2015","unstructured":"Fernandes, G., Rodrigues, J. J. P. C., & Proen\u00e7a, M. L. (2015). Autonomous profile-based anomaly detection system using principal component analysis and flow analysis. Applied Soft Computing, 34, 513\u2013525. https:\/\/doi.org\/10.1016\/j.asoc.2015.05.019 .","journal-title":"Applied Soft Computing"},{"key":"475_CR84","doi-asserted-by":"crossref","unstructured":"Fernandes, G., Zacaron, A. M., Rodrigues, J. J. P. C., & Proenca, M. L. (2013). Digital signature to help network management using principal component analysis and K-means clustering. In 2013 IEEE international conference on communications (pp. 2519\u20132523). IEEE. https:\/\/doi.org\/10.1109\/ICC.2013.6654912 .","DOI":"10.1109\/ICC.2013.6654912"},{"key":"475_CR85","doi-asserted-by":"publisher","first-page":"157","DOI":"10.1109\/TSMCA.2006.889480","volume":"37","author":"DS Yeung","year":"2007","unstructured":"Yeung, D. S., Shuyuan, J., & Xizhao, W. (2007). Covariance-matrix modeling and detecting various flooding attacks. IEEE Transactions on Systems, Man, and Cybernetics-Part A: Systems and Humans, 37, 157\u2013169. https:\/\/doi.org\/10.1109\/TSMCA.2006.889480 .","journal-title":"IEEE Transactions on Systems, Man, and Cybernetics-Part A: Systems and Humans"},{"key":"475_CR86","doi-asserted-by":"publisher","first-page":"574","DOI":"10.1109\/TPDS.2014.2308198","volume":"26","author":"M Xie","year":"2015","unstructured":"Xie, M., Hu, J., & Guo, S. (2015). Segment-based anomaly detection with approximated sample covariance matrix in wireless sensor networks. IEEE Transactions on Parallel and Distributed Systems, 26, 574\u2013583. https:\/\/doi.org\/10.1109\/TPDS.2014.2308198 .","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"key":"475_CR87","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1109\/TNSM.2016.2597125","volume":"13","author":"T Huang","year":"2016","unstructured":"Huang, T., Sethu, H., & Kandasamy, N. (2016). A new approach to dimensionality reduction for anomaly detection in data traffic. IEEE Transactions on Network and Service Management, 13, 651\u2013665. https:\/\/doi.org\/10.1109\/TNSM.2016.2597125 .","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"475_CR88","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1016\/j.comnet.2016.08.023","volume":"108","author":"K Kalkan","year":"2016","unstructured":"Kalkan, K., & Alag\u00f6z, F. (2016). A distributed filtering mechanism against DDoS attacks: ScoreForCore. Computer Networks, 108, 199\u2013209. https:\/\/doi.org\/10.1016\/j.comnet.2016.08.023 .","journal-title":"Computer Networks"},{"key":"475_CR89","doi-asserted-by":"publisher","first-page":"1435","DOI":"10.1109\/TSP.2015.2504345","volume":"64","author":"H Ozkan","year":"2016","unstructured":"Ozkan, H., Ozkan, F., & Kozat, S. S. (2016). Online anomaly detection under Markov statistics with controllable type-I error. IEEE Transactions on Signal Processing, 64, 1435\u20131445. https:\/\/doi.org\/10.1109\/TSP.2015.2504345 .","journal-title":"IEEE Transactions on Signal Processing"},{"key":"475_CR90","doi-asserted-by":"crossref","unstructured":"Proen\u00e7a, M. L., Coppelmans, C., Bottoli, M., Alberti, A., & Mendes, L. S. (2004). The hurst parameter for digital signature of network segment. In J. N. de Souza, P. Dini, & P. Lorenz (Eds.), Telecommunications and networking\u2014ICT 2004 11th international conference on telecommunications, Fortaleza, Brazil, August 1\u20136, 2004. Proceedings (pp. 772\u2013781). Berlin: Springer. https:\/\/doi.org\/10.1007\/978-3-540-27824-5_103 .","DOI":"10.1007\/978-3-540-27824-5_103"},{"key":"475_CR91","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1016\/j.ins.2017.08.074","volume":"420","author":"EHM Pena","year":"2017","unstructured":"Pena, E. H. M., Carvalho, L. F., Barbon, S, Jr., Rodrigues, J. J. P. C., & Proen\u00e7a, M. L, Jr. (2017). Anomaly detection using the correlational paraconsistent machine with digital signatures of network segment. Information Sciences, 420, 313\u2013328. https:\/\/doi.org\/10.1016\/j.ins.2017.08.074 .","journal-title":"Information Sciences"},{"key":"475_CR92","doi-asserted-by":"crossref","unstructured":"Pena, E. H. M., Carvalho, L. F., Barbon, S., Rodrigues, J. J. P. C., & Proenca, M. L. (2014). Correlational paraconsistent machine for anomaly detection. In 2014 IEEE global communications conference (pp. 551\u2013556). IEEE. https:\/\/doi.org\/10.1109\/GLOCOM.2014.7036865 .","DOI":"10.1109\/GLOCOM.2014.7036865"},{"key":"475_CR93","doi-asserted-by":"publisher","first-page":"108","DOI":"10.1016\/j.cose.2016.11.008","volume":"65","author":"J Bang","year":"2017","unstructured":"Bang, J., Cho, Y.-J., & Kang, K. (2017). Anomaly detection of network-initiated LTE signaling traffic in wireless sensor and actuator networks based on a Hidden semi-Markov Model. Computers & Security, 65, 108\u2013120. https:\/\/doi.org\/10.1016\/j.cose.2016.11.008 .","journal-title":"Computers & Security"},{"key":"475_CR94","doi-asserted-by":"crossref","unstructured":"Ren, H., Ye, Z., & Li, Z. (2017). Anomaly detection based on a dynamic Markov model. Computers & Security. https:\/\/doi.org\/10.1016\/j.ins.2017.05.021 .","DOI":"10.1016\/j.ins.2017.05.021"},{"key":"475_CR95","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/j.comnet.2017.03.018","volume":"121","author":"HH Jazi","year":"2017","unstructured":"Jazi, H. H., Gonzalez, H., Stakhanova, N., & Ghorbani, A. A. (2017). Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling. Computer Networks, 121, 25\u201336. https:\/\/doi.org\/10.1016\/j.comnet.2017.03.018 .","journal-title":"Computer Networks"},{"key":"475_CR96","doi-asserted-by":"crossref","unstructured":"Han, J., Kamber, M., & Pei, J. (2012). 10: Cluster analysis: Basic concepts and methods. In J. H. Kamber, & J. Pei (Eds.), Data mininig (3d edn., pp. 443\u2013495). Boston: Morgan Kaufmann. https:\/\/doi.org\/10.1016\/B978-0-12-381479-1.00010-1 .","DOI":"10.1016\/B978-0-12-381479-1.00010-1"},{"key":"475_CR97","doi-asserted-by":"publisher","first-page":"1833","DOI":"10.1016\/j.jpdc.2013.09.005","volume":"74","author":"S Rajasegarar","year":"2014","unstructured":"Rajasegarar, S., Leckie, C., & Palaniswami, M. (2014). Hyperspherical cluster based distributed anomaly detection in wireless sensor networks. Journal of Parallel and Distributed Computing, 74, 1833\u20131847. https:\/\/doi.org\/10.1016\/j.jpdc.2013.09.005 .","journal-title":"Journal of Parallel and Distributed Computing"},{"key":"475_CR98","unstructured":"Mazel, J., Casas, P., Labit, Y., & Owezarski, P. (2011). Sub-space clustering, inter-clustering results association and anomaly correlation for unsupervised network anomaly detection. In CNSM \u201911 Proceedings of the 7th international conference on network and services management (pp. 73\u201380). http:\/\/dl.acm.org\/citation.cfm?id=2147683 ."},{"key":"475_CR99","doi-asserted-by":"publisher","first-page":"1253","DOI":"10.1016\/j.neucom.2014.08.070","volume":"149","author":"A Karami","year":"2015","unstructured":"Karami, A., & Guerrero-Zapata, M. A. (2015). Fuzzy anomaly detection system based on hybrid PSO-K means algorithm in content-centric networks. Neurocomputing, 149, 1253\u20131269. https:\/\/doi.org\/10.1016\/j.neucom.2014.08.070 .","journal-title":"Neurocomputing"},{"key":"475_CR100","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1016\/j.eswa.2016.01.032","volume":"54","author":"LF Carvalho","year":"2016","unstructured":"Carvalho, L. F., Barbon, S., Mendes, L. S., & Proen\u00e7a, M. L. (2016). Unsupervised learning clustering and self-organized agents applied to help network management. Expert Systems with Applications, 54, 29\u201347. https:\/\/doi.org\/10.1016\/j.eswa.2016.01.032 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR101","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1109\/TNSM.2016.2627340","volume":"14","author":"J Dromard","year":"2017","unstructured":"Dromard, J., Roudiere, G., & Owezarski, P. (2017). Online and scalable unsupervised network anomaly detection method. IEEE Transactions on Network and Service Management, 14, 34\u201347. https:\/\/doi.org\/10.1109\/TNSM.2016.2627340 .","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"475_CR102","doi-asserted-by":"crossref","unstructured":"He, D., Chan, S., Ni, X., & Guizani, M. (2017). Software-defined-networking-enabled traffic anomaly detection and mitigation. IEEE Internet of Things Journal. https:\/\/doi.org\/10.1109\/JIOT.2017.2694702 .","DOI":"10.1109\/JIOT.2017.2694702"},{"key":"475_CR103","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1016\/j.ins.2017.11.023","volume":"429","author":"E Bigdeli","year":"2018","unstructured":"Bigdeli, E., Mohammadi, M., Raahemi, B., & Matwin, S. (2018). Incremental anomaly detection using two-layer cluster-based structure. Information Sciences, 429, 315\u2013331. https:\/\/doi.org\/10.1016\/j.ins.2017.11.023 .","journal-title":"Information Sciences"},{"key":"475_CR104","doi-asserted-by":"crossref","unstructured":"Estevez-Tapiador, J. M., Garcia-Teodoro, P., & Diaz-Verdejo, J. E. (2003). Stochastic protocol modeling for anomaly based network intrusion detection. In Information assurance. 2003. IWIAS 2003. Proceedings. First IEEE international workshop on (pp. 3\u201312). https:\/\/doi.org\/10.1109\/IWIAS.2003.1192454 .","DOI":"10.1109\/IWIAS.2003.1192454"},{"key":"475_CR105","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1016\/j.jnca.2009.10.003","volume":"33","author":"M-Y Su","year":"2010","unstructured":"Su, M.-Y. (2010). Discovery and prevention of attack episodes by frequent episodes mining and finite state machines. Journal of Network and Computer Applications, 33, 156\u2013167. https:\/\/doi.org\/10.1016\/j.jnca.2009.10.003 .","journal-title":"Journal of Network and Computer Applications"},{"key":"475_CR106","doi-asserted-by":"crossref","unstructured":"Hammerschmidt, C., Marchal, S., State, R., Pellegrino, G., & Verwer, S., (2016). Efficient learning of communication profiles from IP flow records. In 2016 IEEE 41st conference on local computer networks (pp. 559\u2013562). IEEE. https:\/\/doi.org\/10.1109\/LCN.2016.92 .","DOI":"10.1109\/LCN.2016.92"},{"key":"475_CR107","volume-title":"Pattern classification","author":"RO Duda","year":"2012","unstructured":"Duda, R. O., Hart, P. E., & Stork, D. G. (2012). Pattern classification. New York: Wiley."},{"key":"475_CR108","doi-asserted-by":"crossref","unstructured":"Klassen, M., & Ning, Y. (2012). Anomaly based intrusion detection in wireless networks using Bayesian classifier. In 2012 IEEE fifth international conference on advanced computational intelligence (ICACI) (pp. 257\u2013264). https:\/\/doi.org\/10.1109\/ICACI.2012.6463163 .","DOI":"10.1109\/ICACI.2012.6463163"},{"key":"475_CR109","doi-asserted-by":"crossref","unstructured":"Tao, L., Ailing, Q., Yuanbin, H., & Xintan, C. (2008). Method for network anomaly detection based on Bayesian statistical model with time slicing. In 7th world congress on intelligent control and automation, 2008. WCICA 2008 (pp. 3359\u20133362). https:\/\/doi.org\/10.1109\/WCICA.2008.4593458 .","DOI":"10.1109\/WCICA.2008.4593458"},{"key":"475_CR110","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1016\/j.eswa.2016.07.036","volume":"64","author":"M Swarnkar","year":"2016","unstructured":"Swarnkar, M., & Hubballi, N. (2016). OCPAD: One class Naive Bayes classifier for payload based anomaly detection. Expert Systems with Applications, 64, 330\u2013339. https:\/\/doi.org\/10.1016\/j.eswa.2016.07.036 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR111","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4757-2440-0","volume-title":"The nature of statistical learning theory","author":"VN Vapnik","year":"1995","unstructured":"Vapnik, V. N. (1995). The nature of statistical learning theory. New York: Springer."},{"key":"475_CR112","doi-asserted-by":"publisher","first-page":"1822","DOI":"10.1016\/j.eswa.2011.08.068","volume":"39","author":"CA Catania","year":"2012","unstructured":"Catania, C. A., Bromberg, F., & Garino, C. G. (2012). An autonomous labeling approach to support vector machines algorithms for network traffic anomaly detection. Expert Systems with Applications, 39, 1822\u20131829. https:\/\/doi.org\/10.1016\/j.eswa.2011.08.068 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR113","doi-asserted-by":"crossref","unstructured":"Amer, M., Goldstein, M., & Abdennadher, S. (2013). Enhancing one-class support vector machines for unsupervised anomaly detection. In Proceedings of the ACM SIGKDD workshop on outlier detection and description (pp. 8\u201315). https:\/\/doi.org\/10.1145\/2500853.2500857 .","DOI":"10.1145\/2500853.2500857"},{"key":"475_CR114","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1016\/j.patcog.2016.03.028","volume":"58","author":"SM Erfani","year":"2016","unstructured":"Erfani, S. M., Rajasegarar, S., Karunasekera, S., & Leckie, C. (2016). High-dimensional and large-scale anomaly detection using a linear one-class SVM with deep learning. Pattern Recognition, 58, 121\u2013134. https:\/\/doi.org\/10.1016\/j.patcog.2016.03.028 .","journal-title":"Pattern Recognition"},{"key":"475_CR115","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1016\/j.knosys.2017.09.014","volume":"136","author":"H Wang","year":"2017","unstructured":"Wang, H., Gu, J., & Wang, S. (2017). An effective intrusion detection framework based on SVM with feature augmentation. Knowledge-Based Systems, 136, 130\u2013139. https:\/\/doi.org\/10.1016\/j.knosys.2017.09.014 .","journal-title":"Knowledge-Based Systems"},{"key":"475_CR116","doi-asserted-by":"crossref","unstructured":"Kabir, E., Hu, J., Wang, H., & Zhuo, G. (2017). A novel statistical technique for intrusion detection systems. Future Generation Computer Systems. https:\/\/doi.org\/10.1016\/j.future.2017.01.029 .","DOI":"10.1016\/j.future.2017.01.029"},{"key":"475_CR117","doi-asserted-by":"crossref","unstructured":"Subba, B., Biswas, S., & Karmakar, S. (2016). A neural network based system for intrusion detection and attack classification. In 2016 Twenty second national conference on communication (pp. 1\u20136). IEEE. https:\/\/doi.org\/10.1109\/NCC.2016.7561088 .","DOI":"10.1109\/NCC.2016.7561088"},{"key":"475_CR118","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2990499","volume":"16","author":"A Saeed","year":"2016","unstructured":"Saeed, A., Ahmadinia, A., Javed, A., & Larijani, H. (2016). Intelligent intrusion detection in low-power IoTs. ACM Transactions on Internet Technology, 16, 1\u201325. https:\/\/doi.org\/10.1145\/2990499 .","journal-title":"ACM Transactions on Internet Technology"},{"key":"475_CR119","doi-asserted-by":"crossref","unstructured":"Brown, J., Anwar, M., & Dozier, G. (2016). An evolutionary general regression neural network classifier for intrusion detection. In 2016 25th International conference on computer communication and networks (ICCCN) (pp. 1\u20135). IEEE. https:\/\/doi.org\/10.1109\/ICCCN.2016.7568493 .","DOI":"10.1109\/ICCCN.2016.7568493"},{"key":"475_CR120","doi-asserted-by":"publisher","first-page":"484","DOI":"10.1016\/j.ins.2016.04.019","volume":"378","author":"RAR Ashfaq","year":"2017","unstructured":"Ashfaq, R. A. R., Wang, X.-Z., Huang, J. Z., Abbas, H., & He, Y.-L. (2017). Fuzziness based semi-supervised learning approach for intrusion detection system. Information Sciences, 378, 484\u2013497. https:\/\/doi.org\/10.1016\/j.ins.2016.04.019 .","journal-title":"Information Sciences"},{"key":"475_CR121","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1016\/j.jnca.2005.06.003","volume":"30","author":"S Peddabachigari","year":"2007","unstructured":"Peddabachigari, S., Abraham, A., Grosan, C., & Thomas, J. (2007). Modeling intrusion detection system using hybrid intelligent systems. Journal of Network and Computer Applications, 30, 114\u2013132. https:\/\/doi.org\/10.1016\/j.jnca.2005.06.003 .","journal-title":"Journal of Network and Computer Applications"},{"key":"475_CR122","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1016\/j.asoc.2015.10.011","volume":"38","author":"AA Aburomman","year":"2016","unstructured":"Aburomman, A. A., & Bin Ibne Reaz, M. (2016). A novel SVM-kNN-PSO ensemble method for intrusion detection system. Applied Soft Computing, 38, 360\u2013372. https:\/\/doi.org\/10.1016\/j.asoc.2015.10.011 .","journal-title":"Applied Soft Computing"},{"key":"475_CR123","doi-asserted-by":"crossref","unstructured":"Sornsuwit, P., & Jaiyen, S. (2015). Intrusion detection model based on ensemble learning for U2R and R2L attacks. In 2015 7th international conference on information technology and electrical engineering (ICITEE) (pp. 354\u2013359). IEEE. https:\/\/doi.org\/10.1109\/ICITEED.2015.7408971 .","DOI":"10.1109\/ICITEED.2015.7408971"},{"key":"475_CR124","doi-asserted-by":"crossref","unstructured":"Bukhtoyarov, V., & Zhukov, V. (2014). Ensemble-distributed approach in classification problem solution for intrusion detection systems. In E. Corchado, J. A. Lozano, H. Quinti\u00e1n, & H. Yin (Eds.), 2014 15th International conference on intelligent data engineering automated learning\u2014IDEAL, Salamanca, Spain, September 10\u201312, 2014. Proceedings (pp. 255\u2013265). Cham: Springer. https:\/\/doi.org\/10.1007\/978-3-319-10840-7_32 .","DOI":"10.1007\/978-3-319-10840-7_32"},{"key":"475_CR125","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","volume":"27","author":"CE Shannon","year":"1948","unstructured":"Shannon, C. E. (1948). A mathematical theory of communication. Bell System Technical Journal, 27, 379\u2013423. https:\/\/doi.org\/10.1002\/j.1538-7305.1948.tb01338.x .","journal-title":"Bell System Technical Journal"},{"key":"475_CR126","volume-title":"Elements of information theory","author":"TM Cover","year":"2006","unstructured":"Cover, T. M., & Thomas, J. A. (2006). Elements of information theory (2nd ed.). New York: Wiley.","edition":"2"},{"key":"475_CR127","doi-asserted-by":"crossref","unstructured":"Lee, W., & Xiang, D. (2001). Information-theoretic measures for anomaly detection. In Proceedings of 2001 IEEE symposium on security and privacy, S&P 2001 (pp. 130\u2013143). IEEE Comput. Soc, n.d. https:\/\/doi.org\/10.1109\/SECPRI.2001.924294 .","DOI":"10.1109\/SECPRI.2001.924294"},{"key":"475_CR128","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.procs.2015.04.007","volume":"50","author":"J David","year":"2015","unstructured":"David, J., & Thomas, C. (2015). DDoS attack detection using fast entropy approach on flow- based network traffic. Procedia Computer Science, 50, 30\u201336. https:\/\/doi.org\/10.1016\/j.procs.2015.04.007 .","journal-title":"Procedia Computer Science"},{"key":"475_CR129","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1016\/j.comcom.2016.12.007","volume":"98","author":"AA Amaral","year":"2017","unstructured":"Amaral, A. A., Mendes, L. S., Zarpel\u00e3o, B. B., & Junior, M. L. P. (2017). Deep IP flow inspection to detect beyond network anomalies. Computer Communications, 98, 80\u201396. https:\/\/doi.org\/10.1016\/j.comcom.2016.12.007 .","journal-title":"Computer Communications"},{"key":"475_CR130","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1016\/j.ins.2016.02.023","volume":"348","author":"MH Bhuyan","year":"2016","unstructured":"Bhuyan, M. H., Bhattacharyya, D. K., & Kalita, J. K. (2016). A multi-step outlier-based anomaly detection approach to network-wide traffic. Information Sciences, 348, 243\u2013271. https:\/\/doi.org\/10.1016\/j.ins.2016.02.023 .","journal-title":"Information Sciences"},{"key":"475_CR131","doi-asserted-by":"publisher","first-page":"2367","DOI":"10.3390\/e17042367","volume":"17","author":"P Berezi\u0144ski","year":"2015","unstructured":"Berezi\u0144ski, P., Jasiul, B., & Szpyrka, M. (2015). An entropy-based network anomaly detection method. Entropy, 17, 2367\u20132408. https:\/\/doi.org\/10.3390\/e17042367 .","journal-title":"Entropy"},{"key":"475_CR132","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1016\/j.comnet.2017.02.015","volume":"116","author":"S Behal","year":"2017","unstructured":"Behal, S., & Kumar, K. (2017). Detection of DDoS attacks and flash events using novel information theory metrics. Computer Networks, 116, 96\u2013110. https:\/\/doi.org\/10.1016\/j.comnet.2017.02.015 .","journal-title":"Computer Networks"},{"key":"475_CR133","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1109\/TIFS.2016.2603961","volume":"12","author":"M Xie","year":"2017","unstructured":"Xie, M., Hu, J., Guo, S., & Zomaya, A. Y. (2017). Distributed segment-based anomaly detection with Kullback\u2013Leibler divergence in wireless sensor networks. IEEE Transactions on Information Forensics and Security, 12, 101\u2013110. https:\/\/doi.org\/10.1109\/TIFS.2016.2603961 .","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"475_CR134","doi-asserted-by":"crossref","unstructured":"Li, G., & Wang, Y. (2012). Differential Kullback\u2013Leibler divergence based anomaly detection scheme in sensor networks. In 2012 IEEE 12th international conference on computer and information technology (pp. 966\u2013970). IEEE. https:\/\/doi.org\/10.1109\/CIT.2012.197 .","DOI":"10.1109\/CIT.2012.197"},{"key":"475_CR135","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1016\/j.eswa.2016.04.018","volume":"59","author":"AK Kar","year":"2016","unstructured":"Kar, A. K. (2016). Bio inspired computing: A review of algorithms and scope of applications. Expert Systems with Applications, 59, 20\u201332. https:\/\/doi.org\/10.1016\/j.eswa.2016.04.018 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR136","doi-asserted-by":"crossref","unstructured":"Firdaus, A., Anuar, N. B., Razak, M. F. A., & Sangaiah, A. K. (2017). Bio-inspired computational paradigm for feature investigation and malware detection: Interactive analytics. Multimedia Tools and Applications. https:\/\/doi.org\/10.1007\/s11042-017-4586-0 .","DOI":"10.1007\/s11042-017-4586-0"},{"key":"475_CR137","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2016","unstructured":"Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18, 1153\u20131176. https:\/\/doi.org\/10.1109\/COMST.2015.2494502 .","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"475_CR138","doi-asserted-by":"crossref","unstructured":"Sen, S. (2015). A survey of intrusion detection systems using evolutionary computation. In Bio-inspired computation in telecommunications (pp. 73\u201394). Elsevier. https:\/\/doi.org\/10.1016\/B978-0-12-801538-4.00004-5 .","DOI":"10.1016\/B978-0-12-801538-4.00004-5"},{"key":"475_CR139","volume-title":"Artificial immune systems: A new computational intelligence approach","author":"LN Castro de","year":"2002","unstructured":"de Castro, L. N., & Timmis, J. (2002). Artificial immune systems: A new computational intelligence approach. London: Springer."},{"key":"475_CR140","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1016\/j.eswa.2016.03.042","volume":"60","author":"P Saurabh","year":"2016","unstructured":"Saurabh, P., & Verma, B. (2016). An efficient proactive artificial immune system based anomaly detection and prevention system. Expert Systems with Applications, 60, 311\u2013320. https:\/\/doi.org\/10.1016\/j.eswa.2016.03.042 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR141","doi-asserted-by":"crossref","unstructured":"Igbe, O., Darwish, I., & Saadawi, T. (2016). Distributed network intrusion detection systems: An artificial immune system approach. In 2016 IEEE First international conference on connected health: applications, systems and engineering technologies (pp. 101\u2013106). IEEE. https:\/\/doi.org\/10.1109\/CHASE.2016.36 .","DOI":"10.1109\/CHASE.2016.36"},{"key":"475_CR142","doi-asserted-by":"publisher","first-page":"102","DOI":"10.1016\/j.jnca.2014.03.012","volume":"42","author":"S Shamshirband","year":"2014","unstructured":"Shamshirband, S., Anuar, N. B., Kiah, M. L. M., Rohani, V. A., Petkovi\u0107, D., Misra, S., et al. (2014). Co-FAIS: Cooperative fuzzy artificial immune system for detecting intrusion in wireless sensor networks. Journal of Network and Computer Applications, 42, 102\u2013117. https:\/\/doi.org\/10.1016\/j.jnca.2014.03.012 .","journal-title":"Journal of Network and Computer Applications"},{"key":"475_CR143","doi-asserted-by":"publisher","first-page":"1669","DOI":"10.1007\/s00521-015-1964-2","volume":"27","author":"BM Aslahi-Shahri","year":"2016","unstructured":"Aslahi-Shahri, B. M., Rahmani, R., Chizari, M., Maralani, A., Eslami, M., Golkar, M. J., et al. (2016). A hybrid method consisting of GA and SVM for intrusion detection system. Neural Computing and Applications, 27, 1669\u20131676. https:\/\/doi.org\/10.1007\/s00521-015-1964-2 .","journal-title":"Neural Computing and Applications"},{"key":"475_CR144","doi-asserted-by":"crossref","unstructured":"Singh, S., & Kushwah, R. S. (2016). Energy efficient approach for intrusion detection system for WSN by applying optimal clustering and genetic algorithm. In Proceedings of the international conference on advances in information communication technology & computing\u2014AICTC \u201916 (pp. 1\u20136). New York, NY: ACM Press. https:\/\/doi.org\/10.1145\/2979779.2979840 .","DOI":"10.1145\/2979779.2979840"},{"key":"475_CR145","doi-asserted-by":"publisher","first-page":"390","DOI":"10.1016\/j.eswa.2017.09.013","volume":"92","author":"AH Hamamoto","year":"2018","unstructured":"Hamamoto, A. H., Carvalho, L. F., Sampaio, L. D. H., Abr\u00e3o, T., & Proen\u00e7a, M. L. (2018). Network anomaly detection system using genetic algorithm and fuzzy logic. Expert Systems with Applications, 92, 390\u2013402. https:\/\/doi.org\/10.1016\/j.eswa.2017.09.013 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR146","doi-asserted-by":"crossref","unstructured":"Elsayed, S., Sarker, R., & Slay, J. (2015). Evaluating the performance of a differential evolution algorithm in anomaly detection. In 2015 IEEE congress on evolutionary computation (pp. 2490\u20132497). IEEE. https:\/\/doi.org\/10.1109\/CEC.2015.7257194 .","DOI":"10.1109\/CEC.2015.7257194"},{"key":"475_CR147","doi-asserted-by":"publisher","first-page":"1381","DOI":"10.1016\/j.asoc.2007.10.007","volume":"8","author":"C-L Huang","year":"2008","unstructured":"Huang, C.-L., & Dun, J.-F. (2008). A distributed PSO-SVM hybrid system with feature selection and parameter optimization. Applied Soft Computing, 8, 1381\u20131391. https:\/\/doi.org\/10.1016\/j.asoc.2007.10.007 .","journal-title":"Applied Soft Computing"},{"key":"475_CR148","doi-asserted-by":"publisher","first-page":"1817","DOI":"10.1016\/j.eswa.2007.08.088","volume":"35","author":"S-W Lin","year":"2008","unstructured":"Lin, S.-W., Ying, K.-C., Chen, S.-C., & Lee, Z.-J. (2008). Particle swarm optimization for parameter determination and feature selection of support vector machines. Expert Systems with Applications, 35, 1817\u20131824. https:\/\/doi.org\/10.1016\/j.eswa.2007.08.088 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR149","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.neucom.2016.03.031","volume":"199","author":"SM Hosseini Bamakan","year":"2016","unstructured":"Hosseini Bamakan, S. M., Wang, H., Yingjie, T., & Shi, Y. (2016). An effective intrusion detection framework based on MCLP\/SVM optimized by time-varying chaos particle swarm optimization. Neurocomputing, 199, 90\u2013102. https:\/\/doi.org\/10.1016\/j.neucom.2016.03.031 .","journal-title":"Neurocomputing"},{"key":"475_CR150","doi-asserted-by":"crossref","unstructured":"de Assis, M. V. O., Hamamoto, A. H., Abrao, T., & Proenca, M. L. (2017). A game theoretical based system using holt-winters and genetic algorithm with fuzzy logic for DoS\/DDoS mitigation on SDN networks. IEEE Access. https:\/\/doi.org\/10.1109\/ACCESS.2017.2702341 .","DOI":"10.1109\/ACCESS.2017.2702341"},{"key":"475_CR151","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1016\/j.comnet.2016.05.021","volume":"107","author":"M Grill","year":"2016","unstructured":"Grill, M., & Pevn\u00fd, T. (2016). Learning combination of anomaly detectors for security domain. Computer Networks, 107, 55\u201363. https:\/\/doi.org\/10.1016\/j.comnet.2016.05.021 .","journal-title":"Computer Networks"},{"key":"475_CR152","doi-asserted-by":"publisher","first-page":"296","DOI":"10.1016\/j.eswa.2016.09.041","volume":"67","author":"WL Al-Yaseen","year":"2017","unstructured":"Al-Yaseen, W. L., Othman, Z. A., & Nazri, M. Z. A. (2017). Multi-level hybrid support vector machine and extreme learning machine based on modified K-means for intrusion detection system. Expert Systems with Applications, 67, 296\u2013303. https:\/\/doi.org\/10.1016\/j.eswa.2016.09.041 .","journal-title":"Expert Systems with Applications"},{"key":"475_CR153","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1016\/j.ins.2016.09.007","volume":"373","author":"A Forestiero","year":"2016","unstructured":"Forestiero, A. (2016). Self-organizing anomaly detection in data streams. Information Sciences, 373, 321\u2013336. https:\/\/doi.org\/10.1016\/j.ins.2016.09.007 .","journal-title":"Information Sciences"},{"key":"475_CR154","doi-asserted-by":"publisher","first-page":"20","DOI":"10.4018\/ijehmc.2014010102","volume":"5","author":"O Salem","year":"2014","unstructured":"Salem, O., Guerassimov, A., Mehaoua, A., Marcus, A., & Furht, B. (2014). Anomaly detection in medical wireless sensor networks using SVM and linear regression models. International Journal of E-Health and Medical Communications, 5, 20\u201345. https:\/\/doi.org\/10.4018\/ijehmc.2014010102 .","journal-title":"International Journal of E-Health and Medical Communications"},{"key":"475_CR155","doi-asserted-by":"crossref","unstructured":"Wang, W., Liu, J., Pitsilis, G., & Zhang, X. (2016). Abstracting massive data for lightweight intrusion detection in computer networks. Information Sciences. https:\/\/doi.org\/10.1016\/j.ins.2016.10.023 .","DOI":"10.1016\/j.ins.2016.10.023"},{"key":"475_CR156","doi-asserted-by":"publisher","first-page":"82","DOI":"10.4304\/jnw.8.1.82-91","volume":"8","author":"MHAC Adaniya","year":"2013","unstructured":"Adaniya, M. H. A. C., Abr\u00e3o, T., & Proen\u00e7a, M. L, Jr. (2013). Anomaly detection using metaheuristic firefly harmonic clustering. Journal of Networks, 8, 82\u201391. https:\/\/doi.org\/10.4304\/jnw.8.1.82-91 .","journal-title":"Journal of Networks"},{"key":"475_CR157","doi-asserted-by":"crossref","unstructured":"Proenca, M. L., Zarpelao, B. B., & Mendes, L. S. (2005). Anomaly detection for network servers using digital signature of network segment. In Advanced industrial conference on telecommunications\/service assurance with partial and intermittent resources conference\/e-learning on telecommunications workshop (pp. 290\u2013295). IEEE. https:\/\/doi.org\/10.1109\/AICT.2005.26 .","DOI":"10.1109\/AICT.2005.26"},{"key":"475_CR158","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1016\/j.engappai.2016.01.020","volume":"51","author":"M-H Chen","year":"2016","unstructured":"Chen, M.-H., Chang, P.-C., & Wu, J.-L. (2016). A population-based incremental learning approach with artificial immune system for network intrusion detection. Engineering Applications of Artificial Intelligence, 51, 171\u2013181. https:\/\/doi.org\/10.1016\/j.engappai.2016.01.020 .","journal-title":"Engineering Applications of Artificial Intelligence"},{"key":"475_CR159","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1016\/j.jcss.2016.03.007","volume":"83","author":"M Grill","year":"2017","unstructured":"Grill, M., Pevn\u00fd, T., & Rehak, M. (2017). Reducing false positives of network anomaly detection by local adaptive multivariate smoothing. Journal of Computer and System Sciences, 83, 43\u201357. https:\/\/doi.org\/10.1016\/j.jcss.2016.03.007 .","journal-title":"Journal of Computer and System Sciences"},{"key":"475_CR160","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1016\/j.neucom.2016.06.021","volume":"214","author":"C Guo","year":"2016","unstructured":"Guo, C., Ping, Y., Liu, N., & Luo, S.-S. (2016). A two-level hybrid approach for intrusion detection. Neurocomputing, 214, 391\u2013400. https:\/\/doi.org\/10.1016\/j.neucom.2016.06.021 .","journal-title":"Neurocomputing"}],"container-title":["Telecommunication Systems"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11235-018-0475-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11235-018-0475-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11235-018-0475-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,4]],"date-time":"2020-11-04T23:09:40Z","timestamp":1604531380000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11235-018-0475-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,7,2]]},"references-count":160,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2019,3]]}},"alternative-id":["475"],"URL":"https:\/\/doi.org\/10.1007\/s11235-018-0475-8","relation":{},"ISSN":["1018-4864","1572-9451"],"issn-type":[{"value":"1018-4864","type":"print"},{"value":"1572-9451","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,7,2]]},"assertion":[{"value":"2 July 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}