{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T01:17:14Z","timestamp":1782782234876,"version":"3.54.5"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100012774","name":"Innovation Fund Denmark, Industrial Ph.D. Programme","doi-asserted-by":"publisher","award":["5016-00018"],"award-info":[{"award-number":["5016-00018"]}],"id":[{"id":"10.13039\/100012774","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.3001374","type":"journal-article","created":{"date-parts":[[2020,6,10]],"date-time":"2020-06-10T20:26:39Z","timestamp":1591820799000},"page":"108748-108765","source":"Crossref","is-referenced-by-count":13,"title":["Featureless Discovery of Correlated and False Intrusion Alerts"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0542-5334","authenticated-orcid":false,"given":"Egon","family":"Kidmose","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9579-4901","authenticated-orcid":false,"given":"Matija","family":"Stevanovic","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5745-6573","authenticated-orcid":false,"given":"Soren","family":"Brandbyge","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1903-2921","authenticated-orcid":false,"given":"Jens M.","family":"Pedersen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","volume":"20","author":"hagan","year":"1996","journal-title":"Neural Network Design"},{"key":"ref38","doi-asserted-by":"crossref","DOI":"10.1093\/oso\/9780198538493.001.0001","author":"bishop","year":"1995","journal-title":"Neural Networks for Pattern Recognition"},{"key":"ref33","year":"2000","journal-title":"MIT 2000 DARPA intrusion detection evaluation data set"},{"key":"ref32","year":"2000","journal-title":"Defcon 8 CTF Data Set"},{"key":"ref31","first-page":"49","article-title":"AI2: Training a big data machine to defend","author":"veeramachaneni","year":"2016","journal-title":"Proc IEEE 2nd Int Conf Big Data Secur Cloud (BigDataSecurity) Int Conf High Perform Smart Comput (HPSC) IEEE Int Conf Intell Data Secur (IDS)"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.12.003"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecPODS.2016.7502344"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.12.012"},{"key":"ref34","year":"1999","journal-title":"1999 DARPA Intrusion Detection Evaluation Data Sets"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"ref40","author":"sarle","year":"1997","journal-title":"Neural Network FAQ Periodic Posting to Usenet Newsgroup Compai Neural-Nets"},{"key":"ref11","author":"julien","year":"2015","journal-title":"Suricata IDS Open Information Security Foundation"},{"key":"ref12","first-page":"107","article-title":"Undetectable computer viruses","author":"chess","year":"2000","journal-title":"Proc Virus Bulletin Conf"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CNSM.2010.5691262"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45474-8_4"},{"key":"ref15","first-page":"244","article-title":"Alert correlation for extracting attack strategies","volume":"3","author":"zhu","year":"2006","journal-title":"Netw Secur"},{"key":"ref16","first-page":"1","article-title":"Fusing a heterogeneous alert stream into scenarios","volume":"13","author":"dain","year":"2001","journal-title":"Proceedings of the ACM Workshop on Data Mining Applied to Security"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2002.1004372"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.02.001"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.21236\/ADA436839"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.03.005"},{"key":"ref4","author":"lewis","year":"2017","journal-title":"Economic Impact of Cybercrime&#x2014;No Slowing Down"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/586143.586144"},{"key":"ref3","author":"demarest","year":"2014","journal-title":"Statement Before the Senate Judiciary Committee Subcommittee on Crime and Terrorism Taking Down Botnetss"},{"key":"ref6","first-page":"12","article-title":"Bothunter: Detecting malware infection through IDS-driven dialog correlation","author":"gu","year":"2007","journal-title":"Proc 16th USENIX Security Symp"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.05.011"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.98"},{"key":"ref8","first-page":"1","article-title":"BotSniffer: Detecting botnet command and control channels in network traffic","author":"gu","year":"2008","journal-title":"Proc 15th Annu Netw Distrib Syst Secur Symp (NDSS)"},{"key":"ref7","first-page":"139","article-title":"Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection","author":"gu","year":"2008","journal-title":"Proc Usenix Secur Symp"},{"key":"ref2","author":"finkle","year":"2013","journal-title":"Exclusive Microsoft and Symantec Disrupt Cyber Crime Ring"},{"key":"ref9","first-page":"229","article-title":"Snort: Lightweight intrusion detection for networks","author":"roesch","year":"1999","journal-title":"Proc LISA"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2014.6925787"},{"key":"ref22","first-page":"1","article-title":"Brainwash: A data system for feature engineering","author":"anderson","year":"2013","journal-title":"Proc CIDR"},{"key":"ref21","first-page":"458","article-title":"Automatic feature engineering for answer selection and extraction","author":"severyn","year":"2013","journal-title":"Proc Conf Empirical Methods Natural Lang Process"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1080\/01638539809545028"},{"key":"ref24","first-page":"35","article-title":"The Netflix prize","author":"bennett","year":"2007","journal-title":"Proc KDD Cup Workshop"},{"key":"ref41","author":"heaton","year":"2008","journal-title":"Introduction to Neural Networks with Java"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2016.0190"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45474-8_6"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v31i3.2303"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/09113304.pdf?arnumber=9113304","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T11:22:54Z","timestamp":1723029774000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9113304\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/access.2020.3001374","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]}}}