{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T22:40:08Z","timestamp":1769640008277,"version":"3.49.0"},"reference-count":20,"publisher":"Elsevier BV","issue":"7","license":[{"start":{"date-parts":[[2003,10,1]],"date-time":"2003-10-01T00:00:00Z","timestamp":1064966400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2003,10]]},"DOI":"10.1016\/s0167-4048(03)00710-7","type":"journal-article","created":{"date-parts":[[2003,11,7]],"date-time":"2003-11-07T14:21:42Z","timestamp":1068214902000},"page":"596-612","source":"Crossref","is-referenced-by-count":66,"title":["An anomaly intrusion detection method by clustering normal user behavior"],"prefix":"10.1016","volume":"22","author":[{"given":"Sang","family":"Hyun Oh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Won","family":"Suk Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0167-4048(03)00710-7_BIB1","doi-asserted-by":"crossref","unstructured":"H.S. Javitz, A. Valdes, \u201cThe SRI IDES Statistical Anomaly Detector,\u201d In Proc. of the 1991 IEEE Symposium on Research in Security and Privacy, May 1991.","DOI":"10.1109\/RISP.1991.130799"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB2","unstructured":"Harold S.Javitz and Alfonso Valdes, The NIDES Statistical Component Description and Justification, Annual report, SRI International, 333 Ravenwood Avenue, Menlo Park, CA 94025, March 1994."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB3","unstructured":"Phillip A. Porras and Peter G. Neumann, \u201cEMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances,\u201d 20th NISSC, October 1997."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB4","unstructured":"R. Agrawal, R. Srikant: \u201cFast Algorithms for Mining Association Rules,\u201d Proc. of the 20th Int'l Conference on Very Large Databases, Santiago, Chile, Sept. 1994."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB5","doi-asserted-by":"crossref","unstructured":"R. Agrawal, R. Srikant: \u201cMining Sequential Patterns,\u201d Proc. of the Int'l Conference on Data Engineering (ICDE), Taipei, Taiwan, March 1995.","DOI":"10.1109\/ICDE.1995.380415"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB6","unstructured":"MacQueen, J., \u201cSome Methods for Classification and Analysis of Multivariate Observations,\u201d Proc. 5th Berkeley Symp., 1967, Pages 281\u2013297."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB7","doi-asserted-by":"crossref","unstructured":"Tian Zhang, Raghu Ramakrishnan, and Miron Livny, \u201cBirch: An Efficient data clustering method for very large databases,\u201d Proceedings for the ACM SIGMOD Conference on Management of Data, Montreal, Canada, June 1996.","DOI":"10.1145\/233269.233324"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB8","doi-asserted-by":"crossref","unstructured":"Sudipto Guha, Rajeev Rastogi and Kyuseok Shim, \u201cCURE: An Efficient Clustering Algorithm for Large Databases,\u201d ACM SIGMOD International Conference on Management of Data, Seattle, Washington, 1998.","DOI":"10.1145\/276304.276312"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB9","unstructured":"M. Ester, H.-P. Kriegel, J. Sander, X. Xu: \u201cA Density-Based Algorithm for Discovering Clusters in Large Spatial Databases with Noise,\u201d Proc. 2nd int. Conf. on Knowledge Discovery and Data Mining (KDD \u201896), Portland, Oregon, 1996, AAAI Press, 1996."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB10","doi-asserted-by":"crossref","unstructured":"Rakesh Agrawal, Johannes Gehrke, Dimitrios Gunopulos, Prabhakar Raghavan, \u201cAutomatic Subspace Clustering of High Dimensional Data for Data Mining Applications,\u201d Proc. of the ACM SIGMOD Int'l Conference on Management of Data, Seattle, Washington, June 1998.","DOI":"10.1145\/276304.276314"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB11","unstructured":"T. F. Lunt, A. Tamaru, F. Gilham, R. Jagannathan, P. G. Neumann, H. S. Javitz, A. Valdes and T. D. Garvey \u201cA Real Time Intrusion Detection Expert System (IDES)- Final Technical Report,\u201d Computer Science Laboratory, SRI International, Menlo Park, California, February 1992."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB12","doi-asserted-by":"crossref","unstructured":"K. Illgun, R. Kemmerer, Phillip A. Porras, \u201cState Transition Analysis : A rule-based intrusion detection approach,\u201d IEEE Transaction on Software Engineering pp 181\u2013199, March. 1995","DOI":"10.1109\/32.372146"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB13","doi-asserted-by":"crossref","unstructured":"K. Illgun, \u201cUSTAT: A Real-Time Intrusion Detection System for UNIX,\u201d in Proc. Of the 1993 Symposium Security and Privacy, pp. 16\u201328, May 24\u201326, 1993.","DOI":"10.1109\/RISP.1993.287646"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB14","doi-asserted-by":"crossref","unstructured":"Karlton Sequeira and Mohammed Zaki, \u201cADMIT: Anomaly-based Data Mining for Intrusions\u201d, SIGKDD 2002, Edmonton, Alberta, Canada.","DOI":"10.1145\/775047.775103"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB15","doi-asserted-by":"crossref","unstructured":"Henry S. Teng, Kaihu Chen, and Stephen C. Lu \u201cSecurity Audit Trail Analysis Using Inductively Generated Predictive Rules,\u201d In Proceedings of the Sixth Conference on Artificial Intelligence Applications. pages 24\u201329, Piscataway, New Jersey, March 1990 IEEE.","DOI":"10.1109\/CAIA.1990.89167"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB16","doi-asserted-by":"crossref","unstructured":"W. Lee and S. Stolfo, \u201cData Mining Approaches for Intrusion Detection,\u201d In Proc. of the 7th USENIX Security Symposium, San Antonio, Texas, January 26\u201329, 1998.","DOI":"10.21236\/ADA401496"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB17","unstructured":"S.J. Stolfo, A.L. Prodromidis, S. Tselepis, W. Lee, D. Fan, P.K. Chan, \u201cJAM:Java agents for Meta-Learning over Distributed Databases,\u201d .Proc. KDD-97 and AAAI97 Work. on AI Methods in Fraud and Risk Management), 1997."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB18","doi-asserted-by":"crossref","unstructured":"H. Mannila, H. Toivonen and I. Verkamo, \u201cDiscovery of frequent episodes in event sequences,\u201d Data Mining and Knowledge Discovery, 1,3 (1997), 259\u2013289.","DOI":"10.1023\/A:1009748302351"},{"key":"10.1016\/S0167-4048(03)00710-7_BIB19","unstructured":"Sun Microsystems. SunShield Basic Security Module Guide."},{"key":"10.1016\/S0167-4048(03)00710-7_BIB20","unstructured":"http:\/\/www.ll.mit.edu\/IST\/ideval\/index.html"}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803007107?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803007107?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2019,2,17]],"date-time":"2019-02-17T08:58:56Z","timestamp":1550393936000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404803007107"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,10]]},"references-count":20,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2003,10]]}},"alternative-id":["S0167404803007107"],"URL":"https:\/\/doi.org\/10.1016\/s0167-4048(03)00710-7","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2003,10]]}}}