{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T03:38:36Z","timestamp":1784605116994,"version":"3.55.0"},"reference-count":17,"publisher":"Elsevier BV","issue":"1","license":[{"start":{"date-parts":[[2003,1,1]],"date-time":"2003-01-01T00:00:00Z","timestamp":1041379200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2003,1]]},"DOI":"10.1016\/s0167-4048(03)00112-3","type":"journal-article","created":{"date-parts":[[2003,2,17]],"date-time":"2003-02-17T18:07:53Z","timestamp":1045505273000},"page":"45-55","source":"Crossref","is-referenced-by-count":104,"title":["Efficient anomaly detection by modeling privilege flows using hidden Markov model"],"prefix":"10.1016","volume":"22","author":[{"given":"Sung-Bae","family":"Cho","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hyuk-Jang","family":"Park","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/S0167-4048(03)00112-3_BIB1","doi-asserted-by":"crossref","unstructured":"Vaccaro, H.S. and Liepins, G.E., 1989. Detection of anomalous computer session activity. Proc. IEEE Symp. on Research in Security and Privacy, 1989, pp. 280-289.","DOI":"10.1109\/SECPRI.1989.36302"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB2","unstructured":"Price, K.E., 1997. Host-based misuse detection and conventional operating system\u2019s audit data collection. MSc. Dissertaion, Purdue University, Purdue, IN, USA, 1997."},{"key":"10.1016\/S0167-4048(03)00112-3_BIB3","doi-asserted-by":"crossref","unstructured":"Lunt, T.F., 1993. A survey of intrusion detection techniques, Computers & Security, Vol. 12, No. 4, 1993.","DOI":"10.1016\/0167-4048(93)90029-5"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB4","unstructured":"Javitz, H.S. and Valdes, A., 1994. The SRI IDES statistical anomaly detector. NIDES Technical Report, 1994."},{"key":"10.1016\/S0167-4048(03)00112-3_BIB5","doi-asserted-by":"crossref","unstructured":"Hochberg, J. et al., 1993. Nadir: An automated system for detecting network intrusion and misuse. Computers & Security, Vol. 12, No. 3, 1993, pp. 235-248.","DOI":"10.1016\/0167-4048(93)90110-Q"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB6","doi-asserted-by":"crossref","unstructured":"Debar, H., Becker, M. and Siboni, D., 1992. A neural network component for an intrusion detection system. Proc. 1992 IEEE Computer Society Symposium on Research in Security and Privacy, Oakland, CA, USA, 1992, pp. 240-250.","DOI":"10.1109\/RISP.1992.213257"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB7","doi-asserted-by":"crossref","unstructured":"Hofmeyr, S. and Forrest, S., 2000. Architecture for an artificial immune system. Evolutionary Computation Journal, 2000.","DOI":"10.1162\/106365600568257"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB8","doi-asserted-by":"crossref","unstructured":"Warrender, C., Forrest, S. and Pearlmutter, B., 1999. Detecting intrusion using calls: Alternative data models. IEEE Symposium on Security and Privacy, May 1999.","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB9","doi-asserted-by":"crossref","unstructured":"Choy, J. and Cho, S.-B., 2000. Intrusion detection by combining multiple hidden Markov models. Lecture Note in Artificial Intelligence, Vol. 1886, 2000, pp. 829.","DOI":"10.1007\/3-540-44533-1_118"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB10","unstructured":"Yeung, D.Y. and Ding, Y., 2001. Host-based intrusion detection using dynamic and static behavioral models. The Journal of the Pattern Recognition Society, December 2001."},{"key":"10.1016\/S0167-4048(03)00112-3_BIB11","doi-asserted-by":"crossref","unstructured":"Liepins, G.E. and Vaccaro, H.S., 1992. Intrusion detection: Its role and validation. Computers & Security, Vol. 11, No. 4, 1992, pp. 347-355.","DOI":"10.1016\/0167-4048(92)90175-Q"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB12","doi-asserted-by":"crossref","unstructured":"Smaha, S.E., 1988. Haystack: An intrusion detection system. Aerospace Computer Security Applications Conference, 1988, pp. 37-44.","DOI":"10.1109\/ACSAC.1988.113412"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB13","unstructured":"CERTCC-KR, Korea Information Security Agency, http:\/\/www.certcc.or.kr\/ (in Korean)."},{"key":"10.1016\/S0167-4048(03)00112-3_BIB14","unstructured":"Axelsson, S., 1999. Research in intrusion-detection systems: A survey. Chalmers University of Technology, 1999."},{"key":"10.1016\/S0167-4048(03)00112-3_BIB15","unstructured":"Kuperman, B.A. and Spafford, E.H., 1998. Generation of application level audit data via library interposition. CERIAS TR 99-11, COAST Laboratory, Purdue University, West Lafaytte, IN, USA, 1998."},{"key":"10.1016\/S0167-4048(03)00112-3_BIB16","doi-asserted-by":"crossref","unstructured":"Rabiner, L.R., 1989. A tutorial on hidden Markov models and selected applications in speech recognition. Proc. of the IEEE, Vol. 77, No. 2, 1989.","DOI":"10.1109\/5.18626"},{"key":"10.1016\/S0167-4048(03)00112-3_BIB17","doi-asserted-by":"crossref","unstructured":"Rabiner, L.R. and Juang, B.H., 1986. An introduction to hidden Markov models. IEEE ASSP Magazine, 1986.","DOI":"10.1109\/MASSP.1986.1165342"}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803001123?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803001123?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2019,3,27]],"date-time":"2019-03-27T11:52:16Z","timestamp":1553687536000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404803001123"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,1]]},"references-count":17,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2003,1]]}},"alternative-id":["S0167404803001123"],"URL":"https:\/\/doi.org\/10.1016\/s0167-4048(03)00112-3","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2003,1]]}}}