{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T06:09:11Z","timestamp":1774937351406,"version":"3.50.1"},"reference-count":134,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2021,1,6]],"date-time":"2021-01-06T00:00:00Z","timestamp":1609891200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2021,1,6]],"date-time":"2021-01-06T00:00:00Z","timestamp":1609891200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Reliable Intell Environ"],"published-print":{"date-parts":[[2021,6]]},"DOI":"10.1007\/s40860-020-00120-3","type":"journal-article","created":{"date-parts":[[2021,1,6]],"date-time":"2021-01-06T04:36:35Z","timestamp":1609907795000},"page":"85-114","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":48,"title":["Big data in cybersecurity: a survey of applications and future trends"],"prefix":"10.1007","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4324-1774","authenticated-orcid":false,"given":"Mohammed M.","family":"Alani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,1,6]]},"reference":[{"key":"120_CR1","unstructured":"20 ransomware statistics youre powerless to resist reading - hashed out by the ssl store. https:\/\/www.thesslstore.com\/blog\/ransomware-statistics\/. Accessed on 01 Aug 2020"},{"key":"120_CR2","unstructured":"2019 cyber security statistics trends & data: The ultimate list of cyber security stats\u2014purplesec. https:\/\/purplesec.us\/resources\/cyber-security-statistics\/. Accessed on 30 Jul 2020"},{"key":"120_CR3","unstructured":"2020 trustwave global security report\u2014trustwave. https:\/\/www.trustwave.com\/en-us\/resources\/library\/documents\/2020-trustwave-global-security-report\/. Accessed on 01 Aug 2020"},{"key":"120_CR4","unstructured":"5 cybersecurity threats to be aware of in 2020\u2014ieee computer society. https:\/\/www.computer.org\/publications\/tech-news\/trends\/5-cybersecurity-threats-to-be-aware-of-in-2020\/. Accessed on 30 Jul 2020"},{"key":"120_CR5","unstructured":"Apple reveals windows 10 is four times more popular than the mac. howpublished, https:\/\/www.theverge.com\/2017\/4\/4\/15176766\/apple-microsoft-windows-10-vs-mac-users-figures-stats. Accessed on 3 Dec 2018"},{"key":"120_CR6","unstructured":"Computer science. https:\/\/arxiv.org\/archive\/cs. Accessed on 30 Jul 2020"},{"key":"120_CR7","unstructured":"Cyberthreat trends: 15 cybersecurity threats for 2020\u2014nortonlifelock. https:\/\/us.norton.com\/internetsecurity-emerging-threats-cyberthreat-trends-cybersecurity-threat-review.html. Accessed on 30 Jul 2020"},{"key":"120_CR8","unstructured":"Github\u2014mozilla\/openwpm: A web privacy measurement framework. https:\/\/github.com\/mozilla\/OpenWPM. Accessed on 23 Mar 2019"},{"key":"120_CR9","unstructured":"Global digital population as of april 2020. https:\/\/www.statista.com\/statistics\/617136\/digital-population-worldwide\/. Accessed: 13 May 2020"},{"key":"120_CR10","unstructured":"Global\\_2020\\_forecast\\_highlights. https:\/\/www.cisco.com\/c\/dam\/m\/en_us\/solutions\/service-provider\/vni-forecast-highlights\/pdf\/Global_2020_Forecast_Highlights.pdf. Accessed on 30 Jul 2020"},{"key":"120_CR11","unstructured":"Half of the malware detected in 2019 was classified as zero-day threats, making it the most common malware to date - cynet. https:\/\/www.cynet.com\/blog\/half-of-the-malware-detected-in-2019-was-classified-as-zero-day-threats-making-it-the-most-common-malware-to-date\/. Accessed on 30 Jul 2020"},{"key":"120_CR12","unstructured":"How much data do we create every day? https:\/\/www.forbes.com\/sites\/bernardmarr\/2018\/05\/21\/how-much-data-do-we-create-every-day-the-mind-blowing-stats-everyone-should-read\/. Accessed 22 Oct 2018"},{"key":"120_CR13","unstructured":"The iot rundown for 2020: Stats, risks, and solutions\u2014security today. https:\/\/securitytoday.com\/Articles\/2020\/01\/13\/The-IoT-Rundown-for-2020.aspx. Accessed on 30 Jul 2020"},{"key":"120_CR14","unstructured":"Malware statistics youd better get your computer vaccinated. https:\/\/dataprot.net\/statistics\/malware-statistics\/. Accessed 29 May 2020"},{"key":"120_CR15","unstructured":"Microsoft vulnerabilities more than doubled in 2017. howpublished, https:\/\/www.securitynow.com\/author.asp?section_id=649&doc_id=740671. Accessed 3 Dec 2018"},{"key":"120_CR16","unstructured":"Top cybersecurity threats in 2020. https:\/\/onlinedegrees.sandiego.edu\/top-cyber-security-threats\/. Accessed on 30 Jul 2020"},{"key":"120_CR17","unstructured":"Twitter hack: Us and uk teens arrested over breach of celebrity accounts\u2014twitter\u2014the guardian. https:\/\/www.theguardian.com\/technology\/2020\/jul\/31\/twitter-hack-arrests-florida-uk-teenagers. Accessed on 01 Aug 2020"},{"key":"120_CR18","unstructured":"What is big data analytics, howpublished. https:\/\/searchbusinessanalytics.techtarget.com\/definition\/big-data-analytics. Accessed 24 Nov 2018"},{"key":"120_CR19","unstructured":"Ransomware cyber attacks: Which industries are being hit the hardest? https:\/\/www.bitsighttech.com\/blog\/ransomware-cyber-attacks. Accessed on 08 Dec 2018"},{"key":"120_CR20","unstructured":"Us hospital pays $55,000 to hackers after ransomware attack\u2014zdnet. https:\/\/www.zdnet.com\/article\/us-hospital-pays-55000-to-ransomware-operators\/. Accessed on 08 Dec 2018"},{"key":"120_CR21","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/978-3-319-44257-0_7","volume-title":"Information fusion for cyber-security analytics","author":"M Abdlhamed","year":"2017","unstructured":"Abdlhamed M, Kifayat K, Shi Q, Hurst W (2017) Intrusion prediction systems. Information fusion for cyber-security analytics. Springer, New York, pp 155\u2013174"},{"key":"120_CR22","doi-asserted-by":"crossref","unstructured":"Abraham S, Nair S (2015) Predictive cyber-security analytics framework: a non-homogenous markov model for security quantification. arXiv:1501.01901","DOI":"10.5121\/csit.2014.41316"},{"issue":"6","key":"120_CR23","doi-asserted-by":"publisher","first-page":"974","DOI":"10.1109\/TDSC.2017.2768533","volume":"15","author":"S Aditham","year":"2018","unstructured":"Aditham S, Ranganathan N (2018) A system architecture for the detection of insider attacks in big data systems. IEEE Trans Depend Secure Comput 15(6):974\u2013987","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"120_CR24","first-page":"1","volume-title":"Elements of cloud computing security","author":"MM Alani","year":"2016","unstructured":"Alani MM (2016) What is the cloud? Elements of cloud computing security. Springer, New York, pp 1\u201314"},{"key":"120_CR25","first-page":"1","volume-title":"Information fusion for cyber-security analytics","author":"A AlEroud","year":"2017","unstructured":"AlEroud A, Karabatis G (2017) Using contextual information to identify cyber-attacks. Information fusion for cyber-security analytics. Springer, New York, pp 1\u201316"},{"key":"120_CR26","doi-asserted-by":"publisher","first-page":"160","DOI":"10.1016\/j.cose.2017.04.006","volume":"68","author":"A Aleroud","year":"2017","unstructured":"Aleroud A, Zhou L (2017) Phishing environments, techniques, and countermeasures: a survey. Comput Secur 68:160\u2013196","journal-title":"Comput Secur"},{"key":"120_CR27","doi-asserted-by":"crossref","unstructured":"Alguliyev, R., Imamverdiyev, Y.: Big data: big promises for information security. In: Application of Information and Communication Technologies (AICT), 2014 IEEE 8th international conference on. IEEE, pp 1\u20134","DOI":"10.1109\/ICAICT.2014.7035946"},{"key":"120_CR28","unstructured":"Alhuzali A, Gjomemo R, Eshete B, Venkatakrishnan V (2018) $$\\{$$NAVEX$$\\}$$: Precise and scalable exploit generation for dynamic web applications. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18), pp 377\u2013392"},{"issue":"2","key":"120_CR29","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1145\/3175492","volume":"21","author":"S Alrabaee","year":"2018","unstructured":"Alrabaee S, Shirani P, Wang L, Debbabi M (2018) Fossil: a resilient and efficient system for identifying foss functions in malware binaries. ACM Trans Priv Secur 21(2):8","journal-title":"ACM Trans Priv Secur"},{"key":"120_CR30","doi-asserted-by":"crossref","unstructured":"Alsadhan AA, Hussain A, Alani MM (2018) Detecting ndp distributed denial of service attacks using machine learning algorithm based on flow-based representation. In: 2018 11th International Conference on Developments in eSystems Engineering (DeSE). IEEE, pp 134\u2013140","DOI":"10.1109\/DeSE.2018.00028"},{"key":"120_CR31","unstructured":"Amini L, Christodorescu M, Cohen MA, Parthasarathy S, Rao J, Sailer R, Schales DL, Venema WZ, Verscheure O (2015) Adaptive cyber-security analytics. US Patent 9,032,521"},{"key":"120_CR32","unstructured":"Baikalov IA, Froelich C, McConnell T, McGloughlin JP et\u00a0al (2016) Cyber security analytics architecture. US Patent 9,516,041"},{"key":"120_CR33","unstructured":"Balaban D (2020) 11 types of spoofing attacks every security professional should know about\u20142020-03-24\u2014security magazine. https:\/\/www.securitymagazine.com\/articles\/91980-types-of-spoofing-attacks-every-security-professional-should-know-about. Accessed on 01 Aug 2020"},{"key":"120_CR34","unstructured":"Banescu S, Collberg C, Pretschner A (2017) Predicting the resilience of obfuscated code against symbolic execution attacks via machine learning. In: 26th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 17), pp 661\u2013678"},{"key":"120_CR35","unstructured":"Barradas D, Santos N, Rodrigues L (2018) Effective detection of multimedia protocol tunneling using machine learning. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18), pp 169\u2013185"},{"issue":"1","key":"120_CR36","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E Biham","year":"1991","unstructured":"Biham E, Shamir A (1991) Differential cryptanalysis of des-like cryptosystems. J Cryptol 4(1):3\u201372","journal-title":"J Cryptol"},{"key":"120_CR37","doi-asserted-by":"crossref","unstructured":"Bilge L, Han Y, Dell\u2019Amico M (2017) Riskteller: Predicting the risk of cyber incidents. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM, pp 1299\u20131311","DOI":"10.1145\/3133956.3134022"},{"key":"120_CR38","doi-asserted-by":"crossref","unstructured":"Cao P, Badger EC, Kalbarczyk ZT, Iyer RK, Withers A, Slagell AJ (2015) Towards an unified security testbed and security analytics framework. In: Proceedings of the 2015 symposium and bootcamp on the science of security. ACM","DOI":"10.1145\/2746194.2746218"},{"key":"120_CR39","doi-asserted-by":"crossref","unstructured":"Cao Y, Yang J (2015) Towards making systems forget with machine unlearning. In: 2015 IEEE symposium on security and privacy. IEEE, pp 463\u2013480","DOI":"10.1109\/SP.2015.35"},{"issue":"4","key":"120_CR40","doi-asserted-by":"publisher","first-page":"948","DOI":"10.1016\/j.dss.2013.01.004","volume":"55","author":"R Chakraborty","year":"2013","unstructured":"Chakraborty R, Vishik C, Rao HR (2013) Privacy preserving actions of older adults on social media: Exploring the behavior of opting out of information sharing. Decis Support Syst 55(4):948\u2013956","journal-title":"Decis Support Syst"},{"key":"120_CR41","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.eswa.2018.03.050","volume":"106","author":"KL Chiew","year":"2018","unstructured":"Chiew KL, Yong KSC, Tan CL (2018) A survey of phishing attacks: Their types, vectors and technical approaches. Expert Syst Appl 106:1\u201320","journal-title":"Expert Syst Appl"},{"key":"120_CR42","unstructured":"Cinque M, Della Corte R, Pecchia A (2019) Microservices monitoring with event logs and black box execution tracing. IEEE Trans Serv Comput"},{"key":"120_CR43","doi-asserted-by":"publisher","first-page":"668","DOI":"10.1016\/j.future.2019.09.005","volume":"111","author":"M Cinque","year":"2020","unstructured":"Cinque M, Della Corte R, Pecchia A (2020) Contextual filtering and prioritization of computer application logs for security situational awareness. Future Gener Comput Syst 111:668\u2013680","journal-title":"Future Gener Comput Syst"},{"key":"120_CR44","unstructured":"Curtin M, Dolske J (1998) A brute force search of des keyspace. In: 8th Usenix Symposium, January. Citeseer, pp 26\u201329"},{"issue":"4","key":"120_CR45","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/s40860-018-0072-3","volume":"4","author":"A Cuzzocrea","year":"2018","unstructured":"Cuzzocrea A, Martinelli F, Mercaldo F, Grasso GM (2018) Experimenting and assessing machine learning tools for detecting and analyzing malicious behaviors in complex environments. J Reliab Intell Environ 4(4):225\u2013245","journal-title":"J Reliab Intell Environ"},{"key":"120_CR46","unstructured":"DATA G (2018) Malware in 2018: the danger is on the web\u2014g data blog. https:\/\/www.gdatasoftware.com\/blog\/2018\/09\/31037-malware-figures-first-half-2018-danger-web. Accessed on 31 Mar 2019"},{"key":"120_CR47","doi-asserted-by":"crossref","unstructured":"Dias LF, Correia M (2020) Big data analytics for intrusion detection: an overview. In: Handbook of research on machine and deep learning applications for cyber security. IGI Global, pp 292\u2013316","DOI":"10.4018\/978-1-5225-9611-0.ch014"},{"key":"120_CR48","doi-asserted-by":"crossref","unstructured":"Du M, Li F, Zheng G, Srikumar V (2017) Deeplog: Anomaly detection and diagnosis from system logs through deep learning. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 1285\u20131298","DOI":"10.1145\/3133956.3134015"},{"key":"120_CR49","doi-asserted-by":"crossref","unstructured":"Englehardt S, Narayanan A (2016) Online tracking: A 1-million-site measurement and analysis. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. ACM, pp 1388\u20131401","DOI":"10.1145\/2976749.2978313"},{"issue":"5","key":"120_CR50","doi-asserted-by":"publisher","first-page":"544","DOI":"10.1080\/02564602.2016.1215269","volume":"34","author":"W Fang","year":"2017","unstructured":"Fang W, Wen XZ, Zheng Y, Zhou M (2017) A survey of big data security and privacy preserving. IETE Tech Rev 34(5):544\u2013560","journal-title":"IETE Tech Rev"},{"key":"120_CR51","doi-asserted-by":"publisher","unstructured":"Farris KA, Shah A, Cybenko G, Ganesan R, Jajodia S (2018) Vulcon: A system for vulnerability prioritization, mitigation, and management. ACM Trans Priv Secur 21(4):16:1\u201316:28. https:\/\/doi.org\/10.1145\/3196884","DOI":"10.1145\/3196884"},{"key":"120_CR52","doi-asserted-by":"publisher","unstructured":"Feng Q, Zhou R, Xu C, Cheng Y, Testa B, Yin H (2016) Scalable graph-based bug search for firmware images. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 480\u2013491. https:\/\/doi.org\/10.1145\/2976749.2978370","DOI":"10.1145\/2976749.2978370"},{"key":"120_CR53","unstructured":"Funk C, Garnaeva M (2013) Kaspersky security bulletin 2013. overall statistics for 2013, vol 10. Kaspersky Lab"},{"key":"120_CR54","doi-asserted-by":"crossref","unstructured":"Gai K, Qiu M, Elnagdy SA (2016) A novel secure big data cyber incident analytics framework for cloud-based cybersecurity insurance. In: 2016 IEEE 2nd International Conference on Big Data Security on Cloud (BigDataSecurity), IEEE International Conference on High Performance and Smart Computing (HPSC), and IEEE international conference on intelligent data and security (IDS). IEEE, pp 171\u2013176","DOI":"10.1109\/BigDataSecurity-HPSC-IDS.2016.65"},{"issue":"2","key":"120_CR55","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1016\/j.ijinfomgt.2014.10.007","volume":"35","author":"A Gandomi","year":"2015","unstructured":"Gandomi A, Haider M (2015) Beyond the hype: Big data concepts, methods, and analytics. Int J Inf Manag 35(2):137\u2013144","journal-title":"Int J Inf Manag"},{"issue":"1","key":"120_CR56","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1186\/s41044-016-0014-0","volume":"1","author":"S Garc\u00eda","year":"2016","unstructured":"Garc\u00eda S, Ram\u00edrez-Gallego S, Luengo J, Ben\u00edtez JM, Herrera F (2016) Big data preprocessing: methods and prospects. Big Data Anal 1(1):9","journal-title":"Big Data Anal"},{"issue":"1","key":"120_CR57","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/3154793","volume":"21","author":"NZ Gong","year":"2018","unstructured":"Gong NZ, Liu B (2018) Attribute inference attacks in online social networks. ACM Trans Priv Secur 21(1):3","journal-title":"ACM Trans Priv Secur"},{"key":"120_CR58","doi-asserted-by":"crossref","unstructured":"Gou L, Zhou MX, Yang H (2014) Knowme and shareme: understanding automatically discovered personality traits from social media and user sharing preferences. In: Proceedings of the SIGCHI conference on human factors in computing systems. ACM, New York, pp 955\u2013964","DOI":"10.1145\/2556288.2557398"},{"key":"120_CR59","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1007\/978-3-319-44257-0_8","volume-title":"Information fusion for cyber-security analytics","author":"K Grahn","year":"2017","unstructured":"Grahn K, Westerlund M, Pulkkis G (2017) Analytics for network security: a survey and taxonomy. Information fusion for cyber-security analytics. Springer, New York, pp 175\u2013193"},{"key":"120_CR60","doi-asserted-by":"publisher","unstructured":"Guo W, Mu D, Xu J, Su P, Wang G, Xing X (2018) Lemna: explaining deep learning based security applications. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, CCS \u201918. ACM, New York, pp 364\u2013379. https:\/\/doi.org\/10.1145\/3243734.3243792","DOI":"10.1145\/3243734.3243792"},{"issue":"6","key":"120_CR61","doi-asserted-by":"publisher","first-page":"988","DOI":"10.1109\/TDSC.2018.2864993","volume":"15","author":"CN Gutierrez","year":"2018","unstructured":"Gutierrez CN, Kim T, Della Corte R, Avery J, Goldwasser D, Cinque M, Bagchi S (2018) Learning from the ones that got away: Detecting new forms of phishing attacks. IEEE Trans Depend Secure Comput 15(6):988\u20131001","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"120_CR62","doi-asserted-by":"crossref","unstructured":"Gy\u00f6ngyi Z, Garcia-Molina H, Pedersen J (2004) Combating web spam with trustrank. In: Proceedings of the Thirtieth international conference on Very large data bases, vol 30. VLDB Endowment, pp 576\u2013587","DOI":"10.1016\/B978-012088469-8.50052-8"},{"key":"120_CR63","unstructured":"Hale B (2016) Estimating log generation for security information event and log management. Retrieved Sep 15"},{"issue":"6","key":"120_CR64","doi-asserted-by":"publisher","first-page":"931","DOI":"10.1109\/TDSC.2017.2762673","volume":"15","author":"P He","year":"2018","unstructured":"He P, Zhu J, He S, Li J, Lyu MR (2018) Towards automated log parsing for large-scale log data analysis. IEEE Trans Depend Secure Comput 15(6):931\u2013944","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"120_CR65","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1016\/j.comnet.2018.12.009","volume":"150","author":"JB Hong","year":"2019","unstructured":"Hong JB, Nhlabatsi A, Kim DS, Hussein A, Fetais N, Khan KM (2019) Systematic identification of threats in the cloud: a survey. Comput Netw 150:46\u201369","journal-title":"Comput Netw"},{"key":"120_CR66","unstructured":"Hossain MN, Wang J, Weisse O, Sekar R, Genkin D, He B, Stoller SD, Fang G, Piessens F, Downing E, et\u00a0al (2018) Dependence-preserving data compaction for scalable forensic analysis. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18), pp 1723\u20131740"},{"key":"120_CR67","doi-asserted-by":"crossref","unstructured":"Huang DY, Aliapoulios MM, Li VG, Invernizzi L, Bursztein E, McRoberts K, Levin J, Levchenko K, Snoeren AC, McCoy D (2018) Tracking ransomware end-to-end. In: 2018 IEEE symposium on security and privacy (SP). IEEE, pp 618\u2013631","DOI":"10.1109\/SP.2018.00047"},{"issue":"4","key":"120_CR68","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1145\/3121134","volume":"20","author":"M Ikram","year":"2017","unstructured":"Ikram M, Onwuzurike L, Farooqi S, Cristofaro ED, Friedman A, Jourjon G, Kaafar MA, Shafiq MZ (2017) Measuring, characterizing, and detecting facebook like farms. ACM Trans Priv Secur 20(4):13","journal-title":"ACM Trans Priv Secur"},{"key":"120_CR69","doi-asserted-by":"crossref","unstructured":"Jansen K, Sch\u00e4fer M, Moser D, Lenders V, P\u00f6pper C, Schmitt J (2018) Crowd-gps-sec: Leveraging crowdsourcing to detect and localize gps spoofing attacks. In: 2018 IEEE symposium on security and privacy (SP). IEEE, pp 1018\u20131031","DOI":"10.1109\/SP.2018.00012"},{"issue":"3","key":"120_CR70","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1080\/10714421.2013.807119","volume":"16","author":"NA John","year":"2013","unstructured":"John NA (2013) The social logics of sharing. Commun Rev 16(3):113\u2013131","journal-title":"Commun Rev"},{"key":"120_CR71","doi-asserted-by":"crossref","unstructured":"Johnstone M, Peacock M (2020) Seven pitfalls of using data science in cybersecurity. In: Data Science in Cybersecurity and Cyberthreat Intelligence. Springer, Nwe York","DOI":"10.1007\/978-3-030-38788-4_6"},{"key":"120_CR72","unstructured":"Jurgens D (2013) That\u2019s what friends are for: Inferring location in online social media platforms based on social relationships. In: Seventh International AAAI conference on weblogs and social media"},{"key":"120_CR73","first-page":"237","volume-title":"Annual International Cryptology Conference","author":"J Kelsey","year":"1996","unstructured":"Kelsey J, Schneier B, Wagner D (1996) Key-schedule cryptanalysis of idea, g-des, gost, safer, and triple-des. Annual International Cryptology Conference. Springer, New York, pp 237\u2013251"},{"issue":"2","key":"120_CR74","doi-asserted-by":"publisher","first-page":"541","DOI":"10.1109\/TIFS.2018.2856189","volume":"14","author":"MUK Khan","year":"2019","unstructured":"Khan MUK, Park HS, Kyung CM (2019) Rejecting motion outliers for efficient crowd anomaly detection. IEEE Trans Inf Forensics Secur 14(2):541\u2013556","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"120_CR75","unstructured":"Kim D, Kwon BJ, Koz\u00e1k K, Gates C, Dumitras T (2018) The broken shield: Measuring revocation effectiveness in the windows code-signing $$\\{$$PKI$$\\}$$. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18), pp 851\u2013868"},{"key":"120_CR76","doi-asserted-by":"crossref","unstructured":"Kim S, Woo S, Lee H, Oh H (2017) Vuddy: A scalable approach for vulnerable code clone discovery. In: 2017 IEEE symposium on security and privacy (SP). IEEE, pp 595\u2013614","DOI":"10.1109\/SP.2017.62"},{"key":"120_CR77","doi-asserted-by":"crossref","unstructured":"Koli J (2018) Randroid: Android malware detection using random machine learning classifiers. In: 2018 Technologies for smart-city energy security and power (ICSESP). IEEE, pp 1\u20136","DOI":"10.1109\/ICSESP.2018.8376705"},{"key":"120_CR78","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/978-3-030-38788-4_4","volume-title":"Data science in cybersecurity and cyberthreat intelligence","author":"I Kotenko","year":"2020","unstructured":"Kotenko I, Saenko I, Branitskiy A (2020) Machine learning and big data processing for cybersecurity data analysis. Data science in cybersecurity and cyberthreat intelligence. Springer, New York, pp 61\u201385"},{"key":"120_CR79","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2019.05.002","volume":"33","author":"R Kumar","year":"2019","unstructured":"Kumar R, Goyal R (2019) On cloud security requirements, threats, vulnerabilities and countermeasures: a survey. Comput Sci Rev 33:1\u201348","journal-title":"Comput Sci Rev"},{"key":"120_CR80","doi-asserted-by":"crossref","unstructured":"Kwon BJ, Mondal J, Jang J, Bilge L, Dumitra\u015f T (2015) The dropper effect: insights into malware distribution with downloader graph analytics. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. ACM, New York, pp 1118\u20131129","DOI":"10.1145\/2810103.2813724"},{"issue":"70","key":"120_CR81","first-page":"1","volume":"6","author":"D Laney","year":"2001","unstructured":"Laney D (2001) 3d data management: controlling data volume, velocity and variety. META Group Res Note 6(70):1","journal-title":"META Group Res Note"},{"key":"120_CR82","doi-asserted-by":"crossref","unstructured":"Li H, Xu X, Liu C, Ren T, Wu K, Cao X, Zhang W, Yu Y, Song D (2018) A machine learning approach to prevent malicious calls over telephony networks. In: 2018 IEEE symposium on security and privacy (SP). IEEE, pp 53\u201369","DOI":"10.1109\/SP.2018.00034"},{"key":"120_CR83","doi-asserted-by":"crossref","unstructured":"Liao X, Yuan K, Wang X, Li Z, Xing L, Beyah R (2016) Acing the ioc game: Toward automatic discovery and analysis of open-source cyber threat intelligence. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 755\u2013766","DOI":"10.1145\/2976749.2978315"},{"key":"120_CR84","doi-asserted-by":"crossref","unstructured":"Liao X, Yuan K, Wang X, Pei Z, Yang H, Chen J, Duan H, Du K, Alowaisheq E, Alrwais S, et\u00a0al (2016) Seeking nonsense, looking for trouble: Efficient promotional-infection detection through semantic inconsistency search. In: 2016 IEEE symposium on security and privacy (SP). IEEE, pp 707\u2013723","DOI":"10.1109\/SP.2016.48"},{"key":"120_CR85","unstructured":"MacDonald N (2012) Information security is becoming a big data analytics problem. https:\/\/www.gartner.com\/en\/documents\/1960615. Accessed on 13 May 2020"},{"issue":"1","key":"120_CR86","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3267339","volume":"22","author":"T Madi","year":"2018","unstructured":"Madi T, Jarraya Y, Alimohammadifar A, Majumdar S, Wang Y, Pourzandi M, Wang L, Debbabi M (2018) Isotop: auditing virtual networks isolation across cloud layers in openstack. ACM Trans Priv Secur 22(1):1","journal-title":"ACM Trans Priv Secur"},{"key":"120_CR87","doi-asserted-by":"crossref","unstructured":"Mahmood T, Afzal U (2013) Security analytics: big data analytics for cybersecurity: a review of trends, techniques and tools. In: Information assurance (ncia), 2013 2nd national conference on. IEEE, pp 129\u2013134","DOI":"10.1109\/NCIA.2013.6725337"},{"key":"120_CR88","doi-asserted-by":"crossref","unstructured":"Majumdar S, Tabiban A, Jarraya Y, Oqaily M, Alimohammadifar A, Pourzandi M, Wang L, Debbabi M (2018) Learning probabilistic dependencies among events for proactive security auditing in clouds. J Comput Secur:1\u201338 (preprint)","DOI":"10.1007\/978-3-030-23128-6_1"},{"key":"120_CR89","unstructured":"Maltby D (2011) Big data analytics. In: 74th Annual Meeting of the Association for Information Science and Technology (ASIST), pp 1\u20136"},{"key":"120_CR90","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/978-81-322-2494-5_3","volume-title":"Big data","author":"V Martha","year":"2015","unstructured":"Martha V (2015) Big data processing algorithms. Big data. Springer, New York, pp 61\u201391"},{"key":"120_CR91","first-page":"386","volume-title":"Workshop on the Theory and Application of of Cryptographic Techniques","author":"M Matsui","year":"1993","unstructured":"Matsui M (1993) Linear cryptanalysis method for des cipher. Workshop on the Theory and Application of of Cryptographic Techniques. Springer, New York, pp 386\u2013397"},{"key":"120_CR92","doi-asserted-by":"crossref","unstructured":"Nadgowda S, Isci C, Bal M (2018) D\u00e9j\u00e0vu: bringing black-box security analytics to cloud. In: Proceedings of the 19th International middleware conference industry. ACM, New York, pp 17\u201324","DOI":"10.1145\/3284028.3284031"},{"key":"120_CR93","doi-asserted-by":"crossref","unstructured":"Nilizadeh S, Labr\u00e8che F, Sedighian A, Zand A, Fernandez J, Kruegel C, Stringhini G, Vigna G (2017) Poised: Spotting twitter spam off the beaten paths. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 1159\u20131174","DOI":"10.1145\/3133956.3134055"},{"key":"120_CR94","volume-title":"The big data security analytics era is here","author":"J Oltisk","year":"2013","unstructured":"Oltisk J (2013) The big data security analytics era is here. Tech. rep, Enterprise Strategy Group"},{"key":"120_CR95","doi-asserted-by":"crossref","unstructured":"Pearce P, Ensafi R, Li F, Feamster N, Paxson V (2017) Augur: Internet-wide detection of connectivity disruptions. In: 2017 IEEE symposium on security and privacy (SP). IEEE, pp 427\u2013443","DOI":"10.1109\/SP.2017.55"},{"key":"120_CR96","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1016\/j.cose.2015.10.003","volume":"56","author":"F Pierazzi","year":"2016","unstructured":"Pierazzi F, Casolari S, Colajanni M, Marchetti M (2016) Exploratory security analytics for anomaly detection. Comput Secur 56:28\u201349","journal-title":"Comput Secur"},{"issue":"1","key":"120_CR97","first-page":"2","volume":"22","author":"B Reaves","year":"2018","unstructured":"Reaves B, Vargas L, Scaife N, Tian D, Blue L, Traynor P, Butler KR (2018) Characterizing the security of the sms ecosystem with public gateways. ACM Trans Priv Secur 22(1):2","journal-title":"ACM Trans Priv Secur"},{"issue":"1","key":"120_CR98","first-page":"10","volume":"13","author":"R Richardson","year":"2017","unstructured":"Richardson R, North MM (2017) Ransomware: evolution, mitigation and prevention. Int Manag Rev 13(1):10","journal-title":"Int Manag Rev"},{"key":"120_CR99","first-page":"108","volume-title":"International conference on detection of intrusions and malware, and vulnerability assessment","author":"K Rieck","year":"2008","unstructured":"Rieck K, Holz T, Willems C, D\u00fcssel P, Laskov P (2008) Learning and classification of malware behavior. International conference on detection of intrusions and malware, and vulnerability assessment. Springer, New York, pp 108\u2013125"},{"key":"120_CR100","unstructured":"Rijmen V, Daemen J (2001) Advanced encryption standard. In: Proceedings of federal information processing standards publications. National Institute of Standards and Technology, pp 19\u201322"},{"key":"120_CR101","doi-asserted-by":"crossref","unstructured":"Rose C (2011) The security implications of ubiquitous social media","DOI":"10.19030\/ijmis.v15i1.1593"},{"key":"120_CR102","doi-asserted-by":"crossref","unstructured":"Salva S, Regainia L (2019) A catalogue associating security patterns and attack steps to design secure applications. J Comput Secur:1\u201326 (Preprint)","DOI":"10.3233\/JCS-171063"},{"key":"120_CR103","doi-asserted-by":"crossref","unstructured":"Shen Y, Mariconti E, Vervier PA, Stringhini G (2018) Tiresias: predicting security events through deep learning. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 592\u2013605","DOI":"10.1145\/3243734.3243811"},{"key":"120_CR104","doi-asserted-by":"crossref","unstructured":"Shu X, Araujo F, Schales DL, Stoecklin MP, Jang J, Huang H, Rao JR (2018) Threat intelligence computing. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 1883\u20131898","DOI":"10.1145\/3243734.3243829"},{"issue":"4","key":"120_CR105","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1145\/3105761","volume":"20","author":"X Shu","year":"2017","unstructured":"Shu X, Yao DD, Ramakrishnan N, Jaeger T (2017) Long-span program behavior modeling and attack detection. ACM Trans Priv Secur 20(4):12","journal-title":"ACM Trans Priv Secur"},{"key":"120_CR106","doi-asserted-by":"crossref","unstructured":"Siadati H, Memon N (2017) Detecting structurally anomalous logins within enterprise networks. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 1273\u20131284","DOI":"10.1145\/3133956.3134003"},{"key":"120_CR107","doi-asserted-by":"publisher","DOI":"10.1093\/wentk\/9780199918096.001.0001","volume-title":"Cybersecurity: what everyone needs to know","author":"PW Singer","year":"2014","unstructured":"Singer PW, Friedman A (2014) Cybersecurity: what everyone needs to know. Oxford University Press, Oxford"},{"key":"120_CR108","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/978-3-319-18302-2_12","volume-title":"Cyber security: analytics, technology and automation","author":"T Sipola","year":"2015","unstructured":"Sipola T (2015) Knowledge discovery from network logs. Cyber security: analytics, technology and automation. Springer, New York, pp 195\u2013203"},{"key":"120_CR109","unstructured":"Siwicki B (2016) Ransomware attackers collect ransom from kansas hospital, dont unlock all the data, then demand more money. Healthcare IT News"},{"key":"120_CR110","unstructured":"Standard DE et\u00a0al (1977) Federal information processing standards publication 46. National Bureau of Standards, US Department of Commerce, vol 23"},{"key":"120_CR111","unstructured":"Suciu O, Marginean R, Kaya Y, Daume\u00a0III H, Dumitras T (2018) When does machine learning $$\\{$$FAIL$$\\}$$? generalized transferability for evasion and poisoning attacks. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18), pp 1299\u20131316"},{"key":"120_CR112","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-030-38788-4_3","volume-title":"Data science in cybersecurity and cyberthreat intelligence","author":"B Sun","year":"2020","unstructured":"Sun B, Takahashi T, Zhu L, Mori T (2020) Discovering malicious urls using machine learning techniques. Data science in cybersecurity and cyberthreat intelligence. Springer, New York, pp 33\u201360"},{"key":"120_CR113","doi-asserted-by":"crossref","unstructured":"Talabis M, McPherson R, Miyamoto I, Martin J (2014) Information security analytics: finding security insights, patterns, and anomalies in big data. Syngress","DOI":"10.1016\/B978-0-12-800207-0.00001-0"},{"issue":"3","key":"120_CR114","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/MCC.2014.53","volume":"1","author":"Z Tan","year":"2014","unstructured":"Tan Z, Nagar UT, He X, Nanda P, Liu RP, Wang S, Hu J (2014) Enhancing big data security with collaborative intrusion detection. IEEE Cloud Comput 1(3):27\u201333","journal-title":"IEEE Cloud Comput"},{"issue":"7","key":"120_CR115","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1353-4858(12)70063-6","volume":"2012","author":"C Tankard","year":"2012","unstructured":"Tankard C (2012) Big data security. Netw Secur 2012(7):5\u20138","journal-title":"Big data security. Netw Secur"},{"key":"120_CR116","doi-asserted-by":"crossref","unstructured":"Terzi DS, Terzi R, Sagiroglu S (2015) A survey on security and privacy issues in big data. In: 2015 10th international conference for internet technology and secured transactions (ICITST). IEEE, pp 202\u2013207","DOI":"10.1109\/ICITST.2015.7412089"},{"issue":"1","key":"120_CR117","first-page":"55","volume":"5","author":"J Thirumaran","year":"2018","unstructured":"Thirumaran J et al (2018) Applications of big data analytics-network security. Int J Res Sci Eng Technol 5(1):55\u201359","journal-title":"Int J Res Sci Eng Technol"},{"key":"120_CR118","doi-asserted-by":"publisher","DOI":"10.1201\/9781351073547","volume-title":"Information security management handbook","author":"H Tipton","year":"2019","unstructured":"Tipton H (2019) Information security management handbook, vol IV. CRC Press, Boca Raton"},{"issue":"1","key":"120_CR119","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1145\/3291061","volume":"22","author":"X Ugarte-Pedrero","year":"2019","unstructured":"Ugarte-Pedrero X, Graziano M, Balzarotti D (2019) A close look at a daily dataset of malware samples. ACM Trans Priv Secur 22(1):6","journal-title":"ACM Trans Priv Secur"},{"key":"120_CR120","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1016\/j.jss.2019.01.051","volume":"151","author":"F Ullah","year":"2019","unstructured":"Ullah F, Babar MA (2019) Architectural tactics for big data cybersecurity analytics systems: a review. J Syst Softw 151:81\u2013118","journal-title":"J Syst Softw"},{"key":"120_CR121","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","volume":"38","author":"R Von Solms","year":"2013","unstructured":"Von Solms R, Van Niekerk J (2013) From information security to cyber security. Comput Secur 38:97\u2013102","journal-title":"Comput Secur"},{"key":"120_CR122","doi-asserted-by":"crossref","unstructured":"Wohlin C (2014) Guidelines for snowballing in systematic literature studies and a replication in software engineering. In: Proceedings of the 18th international conference on evaluation and assessment in software engineering, pp 1\u201310","DOI":"10.1145\/2601248.2601268"},{"key":"120_CR123","doi-asserted-by":"crossref","unstructured":"Xu Z, Wu Z, Li Z, Jee K, Rhee J, Xiao X, Xu F, Wang H, Jiang G (2016) High fidelity data reduction for big data security dependency analyses. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 504\u2013516","DOI":"10.1145\/2976749.2978378"},{"key":"120_CR124","doi-asserted-by":"crossref","unstructured":"Yang X, Ma T, Shi Y (2007) Typical dos\/ddos threats under ipv6. In: 2007 International multi-conference on computing in the global information technology (ICCGI\u201907). IEEE","DOI":"10.1109\/ICCGI.2007.61"},{"key":"120_CR125","doi-asserted-by":"crossref","unstructured":"Yao Y, Viswanath B, Cryan J, Zheng H, Zhao BY (2017) Automated crowdturfing attacks and defenses in online review systems. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM, New York, pp 1143\u20131158","DOI":"10.1145\/3133956.3133990"},{"key":"120_CR126","doi-asserted-by":"crossref","unstructured":"You I, Yim K (2010) Malware obfuscation techniques: a brief survey. In: 2010 International conference on broadband, wireless computing, communication and applications. IEEE, pp 297\u2013300","DOI":"10.1109\/BWCCA.2010.85"},{"key":"120_CR127","doi-asserted-by":"crossref","unstructured":"Yuan Y, Adhatarao SS, Lin M, Yuan Y, Liu Z, Fu X (2020) Ada: Adaptive deep log anomaly detector. In: IEEE INFOCOM 2020-IEEE conference on computer communications. IEEE, pp 2449\u20132458","DOI":"10.1109\/INFOCOM41043.2020.9155487"},{"key":"120_CR128","doi-asserted-by":"crossref","unstructured":"Zhang D (2018) Big data security and privacy protection. In: 8th International conference on management and computer science (ICMCS 2018). Atlantis Press","DOI":"10.2991\/icmcs-18.2018.56"},{"key":"120_CR129","unstructured":"Zhang J, Zhang R, Zhang Y, Yan G (2016) The rise of social botnets: Attacks and countermeasures. IEEE Trans Depend Secure Comput"},{"key":"120_CR130","doi-asserted-by":"publisher","first-page":"389","DOI":"10.1016\/j.jss.2018.06.072","volume":"232","author":"JY Zhao","year":"2018","unstructured":"Zhao JY, Kessler EG, Yu J, Jalal K, Cooper CA, Brewer JJ, Schwaitzberg SD, Guo WA (2018) Impact of trauma hospital ransomware attack on surgical residency training. J Surg Res 232:389\u2013397","journal-title":"J Surg Res"},{"key":"120_CR131","doi-asserted-by":"crossref","unstructured":"Zhu Z, Dumitra\u015f T (2016) Featuresmith: automatically engineering features for malware detection by mining the security literature. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp 767\u2013778. ACM, New York","DOI":"10.1145\/2976749.2978304"},{"key":"120_CR132","unstructured":"Zoldi S, Athwal J, Li H, Kennel M, Xue X (2015) Cyber security adaptive analytics threat monitoring system and method. US Patent 9,191,403"},{"issue":"1","key":"120_CR133","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1186\/s40537-015-0013-4","volume":"2","author":"R Zuech","year":"2015","unstructured":"Zuech R, Khoshgoftaar TM, Wald R (2015) Intrusion detection and big heterogeneous data: a survey. J Big Data 2(1):3","journal-title":"J Big Data"},{"key":"120_CR134","doi-asserted-by":"crossref","unstructured":"Zuo Y, Wu Y, Min G, Huang C, Pei K (2020) An intelligent anomaly detection scheme for micro-services architectures with temporal and spatial data analysis. IEEE Trans Cogn Commun Netw","DOI":"10.1109\/TCCN.2020.2966615"}],"container-title":["Journal of Reliable Intelligent Environments"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s40860-020-00120-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s40860-020-00120-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s40860-020-00120-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,27]],"date-time":"2023-01-27T20:11:44Z","timestamp":1674850304000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s40860-020-00120-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,6]]},"references-count":134,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,6]]}},"alternative-id":["120"],"URL":"https:\/\/doi.org\/10.1007\/s40860-020-00120-3","relation":{},"ISSN":["2199-4668","2199-4676"],"issn-type":[{"value":"2199-4668","type":"print"},{"value":"2199-4676","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,6]]},"assertion":[{"value":"13 May 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 November 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 January 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}