{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,4]],"date-time":"2025-11-04T15:35:27Z","timestamp":1762270527040},"reference-count":22,"publisher":"Elsevier BV","issue":"7","license":[{"start":{"date-parts":[[2003,10,1]],"date-time":"2003-10-01T00:00:00Z","timestamp":1064966400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2003,10]]},"DOI":"10.1016\/s0167-4048(03)00711-9","type":"journal-article","created":{"date-parts":[[2003,11,7]],"date-time":"2003-11-07T14:21:42Z","timestamp":1068214902000},"page":"613-623","source":"Crossref","is-referenced-by-count":35,"title":["Detecting intrusion with rule-based integration of multiple models"],"prefix":"10.1016","volume":"22","author":[{"given":"Sang-Jun","family":"Han","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sung-Bae","family":"Cho","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0167-4048(03)00711-9_BIB1","unstructured":"CERTCC-KR, Security Incident Statistic in Korea, http:\/\/www.certcc.or.kr\/english, 2002."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB2","doi-asserted-by":"crossref","unstructured":"H.S. Vaccaro and G.E. Liepins, \u201cDetection of anomalous computer session activity,\u201d In Proceedings of IEEE Symposium on Research in Security and Privacy, pp. 280\u2013289, 1989.","DOI":"10.1109\/SECPRI.1989.36302"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB3","unstructured":"S. Axelsson, \u201cIntrusion detection systems: A survey and taxonomy,\u201d Technical Report 99-15, Department of Computer Engineering, Chalmers University, March 2000."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB4","doi-asserted-by":"crossref","unstructured":"E. Biermann, E. Cloete and L. M. Venter, \u201cA comparison of intrusion detection systems,\u201d Computers & Security, vol 20, no. 8, pp. 676\u2013683, December 2001.","DOI":"10.1016\/S0167-4048(01)00806-9"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB5","doi-asserted-by":"crossref","unstructured":"T. Heberlein, G. Dias, K. Levitt, B. Mukherjee, J. Wood and D. Wolber, \u201cA network security monitor,\u201d In Proceedings of the 1990 IEEE Symposium on Research in Security and Privacy, pp. 296\u2013304, Los Alamitos, CA, USA, 1990.","DOI":"10.1109\/RISP.1990.63859"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB6","unstructured":"T.F. Lunt, A. Tamaru, F. Gilham, R. Jagannathan, C. Jalali, and P.G. Neuman, \u201cA real-time intrusion-detection expert system (IDES),\u201d Technical Report Project 6784, CSL, SRI International, Computer Science Laboratory, SRI International, February 1992."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB7","unstructured":"D. Anderson, T.F. Lunt, H. Javits, A. Tamaru and A. Valdes, \u201cDetecting unusual program behavior using the statistical components of NIDES,\u201d NIDES Technical Report, SRI International, May 1995."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB8","unstructured":"P.A. Porras and P.G. Neumann, \u201cEMERALD: Event monitoring enabling responses to anomalous live disturbances,\u201d In Proceedings of the 20th National Information Systems Security Conference, pp. 353\u2013365, Baltimore, Maryland, USA, October 1997."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB9","doi-asserted-by":"crossref","unstructured":"H. Debar, M. Becker and D. Siboni, \u201cA neural network component for an intrusion detection system,\u201d In Proceedings of 1992 IEEE Computer Society Symposium on Research in Security and Privacy, pp. 240\u2013250, Oakland, CA, May 1992.","DOI":"10.1109\/RISP.1992.213257"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB10","doi-asserted-by":"crossref","unstructured":"C. Warrender, S. Forrest and B. Pearlmutter, \u201cDetecting intrusion using calls: Alternative data models,\u201d In Proceedings of IEEE Symposium on Security and Privacy, pp. 133\u2013145, May 1999.","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB11","doi-asserted-by":"crossref","unstructured":"S.-B. Cho and H.-J. Park, \u201cEfficient anomaly detection by modeling privilege flows with hidden Markov model,\u201d Computers & Security, vol. 22, no. 1, pp. 45\u201355, 2003.","DOI":"10.1016\/S0167-4048(03)00112-3"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB12","doi-asserted-by":"crossref","unstructured":"R. Lippmann and S. Cunningham, \u201cImproving intrusion detection performance using keyword selection and neural networks,\u201d Computer Networks, vol. 34, no. 4, pp. 594\u2013603, 2000.","DOI":"10.1016\/S1389-1286(00)00140-7"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB13","unstructured":"W. Lee, S.J. Stolfo and K.W. Mok, \u201cA data mining framework for building intrusion detection models,\u201d In Proceedings of IEEE Symposium on Security and Privacy, pp. 120\u2013132, 1999."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB14","doi-asserted-by":"crossref","unstructured":"A. Lazarevic, L. Ertoz, V. Kumar, A. Ozgur and J. Srivastava, \u201cA comparative study of anomaly detection schemes in network intrusion detection,\u201d In Proceedings of Third SIAM Conference on Data Mining, May 2003.","DOI":"10.1137\/1.9781611972733.3"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB15","doi-asserted-by":"crossref","unstructured":"W.W. Cohen, \u201cFast effective rule induction,\u201d In Proceedings of the 12th International Conference on Machine Learning, pp. 115\u2013123, July 1995.","DOI":"10.1016\/B978-1-55860-377-6.50023-2"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB16","doi-asserted-by":"crossref","unstructured":"S.-B. Cho, \u201cIncorporating soft computing techniques into a probabilistic intrusion detection system,\u201d IEEE Trans. on Systems, Man and Cybernetics-Part C:Applications and Reviews, vol. 32, no. 2, pp. 154\u2013160, May 2002.","DOI":"10.1109\/TSMCC.2002.801356"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB17","doi-asserted-by":"crossref","unstructured":"L.R. Rabiner, \u201cA tutorial on hidden Markov models and selected applications in speech recognition,\u201d Proceedings of the IEEE, vol. 77, no. 2, pp. 257\u2013286, 1989.","DOI":"10.1109\/5.18626"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB18","doi-asserted-by":"crossref","unstructured":"L.R. Rabiner and B.H. Juang, \u201cAn introduction to hidden Markov models,\u201d IEEE ASSP Magazine, pp. 4\u201316, January 1986.","DOI":"10.1109\/MASSP.1986.1165342"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB19","unstructured":"H.S. Javitz and A. Valdes, \u201cThe SRI IDES statistical anomaly detector,\u201d NIDES Technical Report, SRI International, 1991."},{"key":"10.1016\/S0167-4048(03)00711-9_BIB20","doi-asserted-by":"crossref","unstructured":"D.E. Bell and L.J. LaPadula, \u201cSecure computer systems: Unified exposition and multics interpretation,\u201d Mitre Technical Report ESD-TR-75-306, Mitre Corporation, March 1976.","DOI":"10.21236\/ADA023588"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB21","doi-asserted-by":"crossref","unstructured":"A.G. Amoroso, Fundamentals of Computer Security Technology, PTR Prentice Hall, New Jersy, 1994.","DOI":"10.1016\/0142-0496(94)90187-2"},{"key":"10.1016\/S0167-4048(03)00711-9_BIB22","unstructured":"N.A. Macmillan and C.D. Creelman, Detection Theory: A User\u2019s Guide, Cambridge University Press, Cambridge, 1991."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803007119?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803007119?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2020,3,26]],"date-time":"2020-03-26T17:05:28Z","timestamp":1585242328000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404803007119"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,10]]},"references-count":22,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2003,10]]}},"alternative-id":["S0167404803007119"],"URL":"https:\/\/doi.org\/10.1016\/s0167-4048(03)00711-9","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2003,10]]}}}