{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T18:01:16Z","timestamp":1754157676317,"version":"3.41.2"},"reference-count":8,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2003,8,1]],"date-time":"2003-08-01T00:00:00Z","timestamp":1059696000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2003,8,1]]},"abstract":"<jats:p>Nowadays computer and network intrusions have become more common and more complicated, challenging the intrusion detection systems. Also, network traffic has been constantly increasing. As a consequence, the amount of data to be processed by an intrusion detection system has been growing, making it difficult to efficiently detect intrusions online. Proposes an approach for continuous user authentication based on the user\u2019s behaviour, aiming at development of an efficient and portable anomaly intrusion detection system. A prototype of a host\u2010based intrusion detection system was built. It detects masqueraders by comparing the current user behaviour with his\/her stored behavioural model. The model itself is represented by a number of patterns that describe sequential and temporal behavioural regularities of the users. This paper also discusses implementation issues, describes the authors\u2019 solutions, and provides performance results of the prototype.<\/jats:p>","DOI":"10.1108\/09685220310480426","type":"journal-article","created":{"date-parts":[[2003,7,14]],"date-time":"2003-07-14T20:14:02Z","timestamp":1058213642000},"page":"139-145","source":"Crossref","is-referenced-by-count":6,"title":["Using continuous user authentication to detect masqueraders"],"prefix":"10.1108","volume":"11","author":[{"given":"Alexandr","family":"Seleznyov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seppo","family":"Puuronen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022030820450944500_B1","unstructured":"Ali, S. (2000), \u201cAdventures in anomaly detection\u201d, available at www.cs.columbia.edu\/ids\/research\/keypapers\/papers\/anomaly\/final.ps, read (accessed 2002)."},{"key":"key2022030820450944500_B2","doi-asserted-by":"crossref","unstructured":"Allen, J. (1983), \u201cMaintaining knowledge about temporal intervals\u201d, Communications of the ACM, Vol. 26 No. 11, pp. 832\u201043.","DOI":"10.1145\/182.358434"},{"key":"key2022030820450944500_B3","doi-asserted-by":"crossref","unstructured":"Lane, T. and Brodley, C. (1999), \u201cTemporal sequence learning and data reduction for anomaly detection\u201d, ACM Transactions on Information and System Security, Vol. 2 No. 3, pp. 295\u2010331.","DOI":"10.1145\/322510.322526"},{"key":"key2022030820450944500_B4","unstructured":"Lee, W. and Xiang, D. (2001), \u201cInformation\u2010theoretic measures for anomaly detection\u201d, Proceedings of the IEEE Symposium on Security and Privacy, IEEE Computer Society Press, Oakland, CA, pp. 130\u201043."},{"key":"key2022030820450944500_B5","unstructured":"Lee, W., Stolfo, S. and Mok, K. (1999), \u201cA data\u2010mining framework for building intrusion detection models\u201d, Proceedings of the IEEE Symposium on Security and Privacy, IEEE Computer Society Press, Oakland, CA, pp. 120\u201032."},{"key":"key2022030820450944500_B6","doi-asserted-by":"crossref","unstructured":"Seleznyov, A., Mazhelis, O. and Puuronen, S. (2001), \u201cLearning temporal regularities of user behavior for anomaly detection\u201d, in Gorodetski, V., Skormin, V. and Popyack, L. (Eds), Information Assurance in Computer Networks: Methods, Models, and Architectures for Network Security, Springer LNCS 2052, St Petersburg, pp. 143\u201052.","DOI":"10.1007\/3-540-45116-1_16"},{"key":"key2022030820450944500_B7","unstructured":"Tan, K. and Maxion, R. (2002), \u201cWhy 6? Defining the operational limits of STIDE\u201d, Proceedings of the IEEE Symposium on Security and Privacy, IEEE Computer Society Press, Oakland, CA, pp. 188\u2010200."},{"key":"key2022030820450944500_B8","unstructured":"Zhang, Z., Li, J., Manikopoulos, C., Jorgenson, J. and Ucles, J. (2001), \u201cNeural networks in statistical intrusion detection\u201d, CD\u2010ROM Proceedings of the 5th World Multi\u2010conference on Circuits, Systems, Communications and Computers, Crete, Greece, Electrical and Computer Engineering International Reference Book, WSES Press (Internet Press)."}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685220310480426","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220310480426\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685220310480426\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:08:46Z","timestamp":1753402126000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/11\/3\/139-145\/172145"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,8,1]]},"references-count":8,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2003,8,1]]}},"alternative-id":["10.1108\/09685220310480426"],"URL":"https:\/\/doi.org\/10.1108\/09685220310480426","relation":{},"ISSN":["0968-5227"],"issn-type":[{"type":"print","value":"0968-5227"}],"subject":[],"published":{"date-parts":[[2003,8,1]]}}}