{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T06:29:16Z","timestamp":1760596156232},"reference-count":7,"publisher":"Elsevier BV","issue":"1-2","license":[{"start":{"date-parts":[[2000,11,1]],"date-time":"2000-11-01T00:00:00Z","timestamp":973036800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information Processing Letters"],"published-print":{"date-parts":[[2000,11]]},"DOI":"10.1016\/s0020-0190(00)00122-8","type":"journal-article","created":{"date-parts":[[2002,7,25]],"date-time":"2002-07-25T13:19:59Z","timestamp":1027603199000},"page":"33-38","source":"Crossref","is-referenced-by-count":61,"title":["Detecting masquerades in intrusion detection based on unpopular commands"],"prefix":"10.1016","volume":"76","author":[{"given":"Matthias","family":"Schonlau","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Theus","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0020-0190(00)00122-8_ID001","series-title":"Intrusion detection: An introduction to Internet surveillance, correlation, trace back, traps, and response","author":"Amoroso","year":"1999"},{"key":"10.1016\/S0020-0190(00)00122-8_ID002","article-title":"CSI\/FBI computer crime and security survey results quantify financial losses","volume":"Vol. 181","author":"Computer Security Institute","year":"1998","journal-title":"Comput. Security Alert"},{"key":"10.1016\/S0020-0190(00)00122-8_ID003","series-title":"Proc. IEEE Symposium on Security and Privacy, Oakland, CA","first-page":"222","article-title":"An intrusion-detection model","author":"Denning","year":"1986"},{"key":"10.1016\/S0020-0190(00)00122-8_ID004","series-title":"Internet Besieged","year":"1997"},{"key":"10.1016\/S0020-0190(00)00122-8_ID005","first-page":"404","article-title":"A comparison of test statistics for computer intrusion detection based on principal components regression of transition probabilities","volume":"Vol. 30","author":"DuMouchel","year":"1999","journal-title":"Proc. 30th Symposium on the Interface, Computing Science and Statistics"},{"key":"10.1016\/S0020-0190(00)00122-8_ID006","series-title":"Proc. 11th National Computer Security Conference","article-title":"Automated audit trail analysis and intrusion detection","author":"Lunt","year":"1988"},{"issue":"1","key":"10.1016\/S0020-0190(00)00122-8_ID007","first-page":"12","article-title":"Intrusion detection based on structural zeroes","volume":"Vol. 9","author":"Theus","year":"1998","journal-title":"Statist. Comput. Graphics Newslett."}],"container-title":["Information Processing Letters"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0020019000001228?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0020019000001228?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2019,4,24]],"date-time":"2019-04-24T22:22:04Z","timestamp":1556144524000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0020019000001228"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2000,11]]},"references-count":7,"journal-issue":{"issue":"1-2","published-print":{"date-parts":[[2000,11]]}},"alternative-id":["S0020019000001228"],"URL":"https:\/\/doi.org\/10.1016\/s0020-0190(00)00122-8","relation":{},"ISSN":["0020-0190"],"issn-type":[{"value":"0020-0190","type":"print"}],"subject":[],"published":{"date-parts":[[2000,11]]}}}