{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,28]],"date-time":"2026-06-28T05:08:05Z","timestamp":1782623285614,"version":"3.54.5"},"reference-count":46,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2022,1,29]],"date-time":"2022-01-29T00:00:00Z","timestamp":1643414400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,29]],"date-time":"2022-01-29T00:00:00Z","timestamp":1643414400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Wireless Pers Commun"],"published-print":{"date-parts":[[2022,6]]},"DOI":"10.1007\/s11277-022-09482-8","type":"journal-article","created":{"date-parts":[[2022,1,29]],"date-time":"2022-01-29T19:02:16Z","timestamp":1643482936000},"page":"2637-2659","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Enhancing Detection of R2L Attacks by Multistage Clustering Based Outlier Detection"],"prefix":"10.1007","volume":"124","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9246-1522","authenticated-orcid":false,"given":"J. Rene","family":"Beulah","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M.","family":"Nalini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"D. Shiny","family":"Irene","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"D. Shalini","family":"Punithavathani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,1,29]]},"reference":[{"key":"9482_CR1","unstructured":"Yeung D. Y., Chow C. (2002). \u201cParzen-window network intrusion detectors\u201d, In: Object recognition supported by user interaction for service robots, IEEE, vol. 4, pp. 385\u2013388"},{"issue":"2","key":"9482_CR2","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","volume":"18","author":"AL Buczak","year":"2015","unstructured":"Buczak, A. L., & Guven, E. (2015). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys &amp; Tutorials, 18(2), 1153\u20131176.","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"9482_CR3","unstructured":"Ahmad I., Abdullah A. B., Alghamdi A. S., (2010). \u201cRemote to Local attack detection using supervised neural network\u201d, In IEEE International Conference for Internet Technology and Secured Transactions, pp. 1\u20136."},{"key":"9482_CR4","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1109\/TSE.1987.232894","volume":"2","author":"DE Denning","year":"1987","unstructured":"Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, 2, 222\u2013232.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"9482_CR5","doi-asserted-by":"crossref","unstructured":"Lazarevic A., Ertoz L., Kumar V., Ozgur A., Srivastava J. (2003). \u201cA comparative study of anomaly detection schemes in network intrusion detection\u201d, In Proceedings of the 2003 SIAM international conference on data mining, Society for Industrial and Applied Mathematics, pp. 25\u201336.","DOI":"10.1137\/1.9781611972733.3"},{"issue":"5","key":"9482_CR6","doi-asserted-by":"publisher","first-page":"516","DOI":"10.1109\/TSMCC.2010.2048428","volume":"40","author":"M Tavallaee","year":"2010","unstructured":"Tavallaee, M., Stakhanova, N., & Ghorbani, A. A. (2010). \u201cToward credible evaluation of anomaly-based intrusion-detection methods.\u201d IEEE Transactions on Systems, Man and Cybernetics Part C (Applications and Reviews), 40(5), 516\u2013524.","journal-title":"IEEE Transactions on Systems, Man and Cybernetics Part C (Applications and Reviews)"},{"issue":"1","key":"9482_CR7","doi-asserted-by":"publisher","first-page":"95","DOI":"10.4156\/jcit.vol5.issue1.11","volume":"5","author":"P Gogoi","year":"2010","unstructured":"Gogoi, P., Borah, B., & Bhattacharyya, D. K. (2010). Anomaly detection analysis of intrusion data using supervised & unsupervised approach. Journal of Convergence Information Technology, 5(1), 95\u2013110.","journal-title":"Journal of Convergence Information Technology"},{"key":"9482_CR8","doi-asserted-by":"crossref","unstructured":"Bhuyan M. H., Bhattacharyya D. K., Kalita J. K. (2011). \u201cNADO: Network anomaly detection using outlier approach\u201d, In Proceedings of the International Conference on Communication, Computing & Security, ACM, pp. 531\u2013536, 2011.","DOI":"10.1145\/1947940.1948050"},{"issue":"1","key":"9482_CR9","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1109\/SURV.2013.052213.00046","volume":"16","author":"MH Bhuyan","year":"2014","unstructured":"Bhuyan, M. H., Bhattacharyya, D. K., & Kalita, J. K. (2014). Network anomaly detection: methods, systems and tools. IEEE Communications Surveys &amp; Tutorials, 16(1), 303\u2013336.","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"24","key":"9482_CR10","first-page":"30795","volume":"9","author":"M Nalini","year":"2014","unstructured":"Nalini, M., & Anbu, S. (2014). Anomaly detection via eliminating data redundancy and rectifying data error in uncertain data streams. International Journal of Applied Engineering Research, 9(24), 30795\u201330812.","journal-title":"International Journal of Applied Engineering Research"},{"key":"9482_CR11","doi-asserted-by":"crossref","unstructured":"Nalini M., Priyadarsini U. (2019). \u201cTo improve the performance of wireless networks for resizing the buffer\u201d, In Proceedings of the 1st International Conference on Innovations in Information and Communication Technology, pp. 1\u20135, IEEE, 2019.","DOI":"10.1109\/ICIICT1.2019.8741406"},{"key":"9482_CR12","first-page":"197","volume":"8","author":"M Nalini","year":"2019","unstructured":"Nalini, M., & Chakram, A. (2019). \u201cDigital risk management for data attacks against state evaluation.\u201d International Journal of Innovative Technology and Exploring Engineering, 8, 197\u2013201.","journal-title":"International Journal of Innovative Technology and Exploring Engineering"},{"key":"9482_CR13","unstructured":"Lee W., Stolfo S. (1998). \u201cData mining approaches for intrusion detection\u201d, In Proceedings of USENIX Security, pp. 79\u201393."},{"issue":"1","key":"9482_CR14","doi-asserted-by":"publisher","first-page":"18","DOI":"10.4018\/IJISP.2017010102","volume":"11","author":"MA Boudia","year":"2017","unstructured":"Boudia, M. A., Hamou, R. M., & Amine, A. (2017). A new meta-heuristics for intrusion detection system inspired from the protection system of social bees. International Journal of Information Security and Privacy (IJISP), 11(1), 18\u201334.","journal-title":"International Journal of Information Security and Privacy (IJISP)"},{"key":"9482_CR15","doi-asserted-by":"crossref","unstructured":"Arul R., Moorthy R. S., Bashir A. K., (2019) \u201cEnsemble learning mechanisms for threat detection: A Survey\u201d, In Machine Learning and Cognitive Science Applications in Cyber Security, IGI Global, pp. 240\u2013281.","DOI":"10.4018\/978-1-5225-8100-0.ch010"},{"key":"9482_CR16","unstructured":"Blazquez-Gracia A., Conde A., Mori U., Lozano J. A. \u201cA review on outlier\/anomaly detection in time series data\u201d arXiv preprint arXiv:2002.04236 (2020)."},{"key":"9482_CR17","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1016\/j.neucom.2014.09.083","volume":"164","author":"E De la Hoz","year":"2015","unstructured":"De la Hoz, E., De la Hoz, E., Ortiz, A., Ortega, J., & Prie, B. (2015). PCA filtering and probabilistic SOM for network anomaly detection. Neurocomputing, 164, 71\u201381.","journal-title":"Neurocomputing"},{"key":"9482_CR18","unstructured":"Mohamad Tahir H., Hasan W., Md Said A., Zakaria N. H., Katuk N., Kabir N. F., Omar M. H., Ghazali O., & Yahaya N. I., (2015). \u201cHybrid machine learning technique for intrusion detection system\u201d, In Proc. ICOCI, pp. 464\u2013472."},{"issue":"22","key":"9482_CR19","doi-asserted-by":"publisher","first-page":"8609","DOI":"10.1016\/j.eswa.2015.07.015","volume":"42","author":"R Singh","year":"2015","unstructured":"Singh, R., Kumar, H., & Singla, R. K. (2015). An intrusion detection system using network traffic profiling and online sequential extreme learning machine. Expert Systems with Applications, 42(22), 8609\u20138624.","journal-title":"Expert Systems with Applications"},{"key":"9482_CR20","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1016\/j.ins.2016.02.023","volume":"348","author":"MH Bhuyan","year":"2016","unstructured":"Bhuyan, M. H., Bhattacharyya, D. K., & Kalita, J. K. (2016). A multi-step outlier-based anomaly detection approach to network-wide traffic. Information Science, 348, 243\u2013271.","journal-title":"Information Science"},{"key":"9482_CR21","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.neucom.2016.03.031","volume":"199","author":"SMH Bamakan","year":"2016","unstructured":"Bamakan, S. M. H., Wang, H., Yingjie, T., & Shi, Y. (2016). An effective intrusion detection framework based on MCLP\/SVM optimized by time-varying chaos particle swarm optimization. Neurocomputing, 199, 90\u2013102.","journal-title":"Neurocomputing"},{"key":"9482_CR22","doi-asserted-by":"crossref","unstructured":"Enache A. C., Sgarciu V., (2015) \u201cAnomaly intrusions detection based on support vector machines with an improved bat algorithm\u201d, In Proc. CSCS, pp. 317\u2013321.","DOI":"10.1109\/CSCS.2015.12"},{"issue":"2","key":"9482_CR23","doi-asserted-by":"publisher","first-page":"124","DOI":"10.14445\/22312803\/IJCTT-V43P118","volume":"43","author":"D Hassan","year":"2017","unstructured":"Hassan, D. (2017). Cost-sensitive access control for detecting remote to local (R2L) and user to root (U2R) attacks. International Journal of Computer Trends and Technology (IJCTT), 43(2), 124\u2013129.","journal-title":"International Journal of Computer Trends and Technology (IJCTT)"},{"issue":"19","key":"9482_CR24","first-page":"57","volume":"60","author":"S Paliwal","year":"2012","unstructured":"Paliwal, S., & Gupta, R. (2012). Denial-of-service, probing & remote to user (R2L) attack detection using genetic algorithm. International Journal of Computer Applications, 60(19), 57\u201362.","journal-title":"International Journal of Computer Applications"},{"issue":"5","key":"9482_CR25","first-page":"317","volume":"3","author":"S Revathi","year":"2014","unstructured":"Revathi, S., & Malathi, A. (2014). Effective analysis on remote to user (R2L) attacks using random forest algorithm. International Journal of Engineering Sciences &amp; Research Technology, 3(5), 317\u2013319.","journal-title":"International Journal of Engineering Sciences & Research Technology"},{"issue":"21","key":"9482_CR26","first-page":"28","volume":"45","author":"PG Jeya","year":"2012","unstructured":"Jeya, P. G., Ravichandran, M., & Ravichandran, C. S. (2012). Efficient classifier for R2L and U2R attacks. International Journal of Computer Applications, 45(21), 28\u201332.","journal-title":"International Journal of Computer Applications"},{"key":"9482_CR27","doi-asserted-by":"crossref","unstructured":"Nguyen V.Q., Nguyen V. H., Le-Khac N. A., Cao V. L., (2020) \u201cClustering-Based Deep Autoencoders for Network Anomaly Detection\u201d, in International Conference on Future Data and Security Engineering, pp. 290\u2013303, Springer, Cham.","DOI":"10.1007\/978-3-030-63924-2_17"},{"issue":"2","key":"9482_CR28","doi-asserted-by":"publisher","first-page":"146","DOI":"10.26599\/TST.2019.9010051","volume":"26","author":"G Pu","year":"2020","unstructured":"Pu, G., Wang, L., Shen, J., & Dong, F. (2020). A hybrid unsupervised clustering-based anomaly detection method. Tsinghua Science and Technology, 26(2), 146\u2013153.","journal-title":"Tsinghua Science and Technology"},{"issue":"4","key":"9482_CR29","doi-asserted-by":"publisher","first-page":"24","DOI":"10.3390\/bdcc4040024","volume":"4","author":"M Li","year":"2020","unstructured":"Li, M., Kashef, R., & Ibrahim, A. (2020). Multi-level clustering-based outlier\u2019s detection (MCOD) using self-organizing maps. Big Data and Cognitive Computing, 4(4), 24.","journal-title":"Big Data and Cognitive Computing"},{"issue":"1","key":"9482_CR30","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3390\/data6010001","volume":"6","author":"A Elmogy","year":"2021","unstructured":"Elmogy, A., Rizk, H., & Sarhan, A. M. (2021). OFCOD: On the fly clustering based outlier detection framework. Data, 6(1), 1\u201320.","journal-title":"Data"},{"key":"9482_CR31","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1016\/j.jocs.2017.03.006","volume":"25","author":"S Aljawarneh","year":"2018","unstructured":"Aljawarneh, S., Aldwairi, M., & Yassein, M. B. (2018). Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model. Journal of Computational Science, 25, 152\u2013160.","journal-title":"Journal of Computational Science"},{"key":"9482_CR32","doi-asserted-by":"publisher","first-page":"94497","DOI":"10.1109\/ACCESS.2019.2928048","volume":"7","author":"BA Tama","year":"2019","unstructured":"Tama, B. A., Comuzzi, M., & Rhee, K. H. (2019). TSE-IDS: A two-stage classifier ensemble for intelligent anomaly-based intrusion detection system. IEEE Access, 7, 94497\u201394507.","journal-title":"IEEE Access"},{"issue":"7","key":"9482_CR33","doi-asserted-by":"publisher","first-page":"1069","DOI":"10.30684\/etj.v39i7.1695","volume":"39","author":"B Mohammed","year":"2021","unstructured":"Mohammed, B., & Gbashi, E. K. (2021). Intrusion detection system for NSL-KDD dataset based on deep learning and recursive feature eimination. Engineering and Technology Journal, 39(7), 1069\u20131079.","journal-title":"Engineering and Technology Journal"},{"key":"9482_CR34","doi-asserted-by":"publisher","first-page":"103261","DOI":"10.1016\/j.micpro.2020.103261","volume":"79","author":"S Manimurugan","year":"2020","unstructured":"Manimurugan, S., Majdi, A. Q., Mohammed, M., Narmatha, C., & Varatharajan, R. (2020). Intrusion detection in networks using crow search optimization algorithm with adaptive neuro-fuzzy inference system. Microprocessors and Microsystems, 79, 103261.","journal-title":"Microprocessors and Microsystems"},{"issue":"4","key":"9482_CR35","doi-asserted-by":"publisher","first-page":"570","DOI":"10.1093\/comjnl\/bxr026","volume":"54","author":"P Gogoi","year":"2011","unstructured":"Gogoi, P., Bhattacharyya, D. K., Borah, B., & Kalita, J. K. (2011). A survey of outlier detection methods in network anomaly identification. The Computer Journal, 54(4), 570\u2013588.","journal-title":"The Computer Journal"},{"issue":"19","key":"9482_CR36","first-page":"40488","volume":"10","author":"JR Beulah","year":"2015","unstructured":"Beulah, J. R., & Punithavathani, D. S. (2015). Outlier detection methods for identifying network intrusions\u2014A survey. International Journal of Applied Engineering Research, 10(19), 40488\u201340496.","journal-title":"International Journal of Applied Engineering Research"},{"key":"9482_CR37","unstructured":"Hassani M., Seidl T., (2011) \u201cNetwork intrusion detection using a secure ranking of hidden outliers\u201d, In Proceedings of the Seventh International Computing Conference in Arabic, pp. 1\u201310."},{"key":"9482_CR38","unstructured":"NSL-KDD Dataset [Online] Available: https:\/\/web.archive.org\/web\/20150205070216\/http:\/\/nsl.cs.unb.ca\/NSL-KDD\/"},{"issue":"3","key":"9482_CR39","doi-asserted-by":"publisher","first-page":"129","DOI":"10.4236\/jis.2016.73009","volume":"7","author":"MAM Hasan","year":"2016","unstructured":"Hasan, M. A. M., Nasser, M., Ahmad, S., & Molla, K. I. (2016). Feature selection for intrusion detection using random forest. Journal of Information Security, 7(3), 129\u2013140.","journal-title":"Journal of Information Security"},{"issue":"2","key":"9482_CR40","doi-asserted-by":"publisher","first-page":"1853","DOI":"10.1007\/s11277-017-4949-x","volume":"98","author":"JR Beulah","year":"2018","unstructured":"Beulah, J. R., & Punithavathani, D. S. (2018). A hybrid feature selection method for improved detection of wired\/wireless network intrusions. Wireless Personal Communications, 98(2), 1853\u20131869.","journal-title":"Wireless Personal Communications"},{"key":"9482_CR41","unstructured":"Hall M.A. (1999) \u201cCorrelation-based feature selection for machine learning\u201d Ph.D. dissertation, Dept. of Computer Science, The University of Waikato, Hamilton."},{"issue":"1","key":"9482_CR42","doi-asserted-by":"publisher","first-page":"191","DOI":"10.2307\/2347628","volume":"41","author":"S Le Cessie","year":"1992","unstructured":"Le Cessie, S., & Van Houwelingen, J. C. (1992). Ridge estimators in logistic regression. Applied Statistics, 41(1), 191\u2013201.","journal-title":"Applied Statistics"},{"issue":"1","key":"9482_CR43","first-page":"37","volume":"6","author":"DW Aha","year":"1991","unstructured":"Aha, D. W., Kibler, D., & Albert, M. K. (1991). Instance-based learning algorithms. Machine Learning, 6(1), 37\u201366.","journal-title":"Machine Learning"},{"key":"9482_CR44","unstructured":"Kohavi R. (1996) \u201cScaling up the accuracy of na\u00efve-Bayes classifiers: A decision tree hybrid\u201d, In Proc. International Conference on KDD, pp. 202\u2013207."},{"issue":"3","key":"9482_CR45","doi-asserted-by":"publisher","first-page":"115","DOI":"10.4018\/IJISP.2020070107","volume":"14","author":"JR Beulah","year":"2020","unstructured":"Beulah, J. R., & Shalini Punithavathani, D. S. (2020). An efficient mixed attribute outlier detection method for identifying network intrusions. International Journal of Information Security and Privacy (IJISP), 14(3), 115\u2013133.","journal-title":"International Journal of Information Security and Privacy (IJISP)"},{"key":"9482_CR46","doi-asserted-by":"crossref","unstructured":"Kemiche M., Beghdad R. (2014). \u201cCAC-UA: A communicating ant for clustering to detect unknown attacks\u201d, In Proceedings of Science and Information Conference, IEEE, pp. 515\u2013522,","DOI":"10.1109\/SAI.2014.6918236"}],"container-title":["Wireless Personal Communications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-022-09482-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11277-022-09482-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-022-09482-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,23]],"date-time":"2022-05-23T10:25:31Z","timestamp":1653301531000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11277-022-09482-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,29]]},"references-count":46,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,6]]}},"alternative-id":["9482"],"URL":"https:\/\/doi.org\/10.1007\/s11277-022-09482-8","relation":{},"ISSN":["0929-6212","1572-834X"],"issn-type":[{"value":"0929-6212","type":"print"},{"value":"1572-834X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,29]]},"assertion":[{"value":"4 January 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 January 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no relevant financial or non-financial interests to disclose.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}