{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T00:17:35Z","timestamp":1775175455508,"version":"3.50.1"},"reference-count":13,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009,7]]},"DOI":"10.1109\/cisda.2009.5356522","type":"proceedings-article","created":{"date-parts":[[2009,12,24]],"date-time":"2009-12-24T18:27:59Z","timestamp":1261679279000},"page":"1-7","source":"Crossref","is-referenced-by-count":47,"title":["Analysis of the 1999 DARPA\/Lincoln Laboratory IDS evaluation data with NetADHICT"],"prefix":"10.1109","author":[{"given":"Carson","family":"Brown","sequence":"first","affiliation":[]},{"given":"Alex","family":"Cowperthwaite","sequence":"additional","affiliation":[]},{"given":"Abdulrahman","family":"Hijazi","sequence":"additional","affiliation":[]},{"given":"Anil","family":"Somayaji","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382923"},{"key":"ref11","first-page":"5","article-title":"Intrusion detection with unlabeled data using clustering","author":"portnoy","year":"2001","journal-title":"In Proceedings of ACM CSS Workshop on Data Mining Applied to Security (DMSA-2001)"},{"key":"ref12","first-page":"203","article-title":"Recent Advances in Intrusion Detection","author":"wang","year":"2004","journal-title":"Anomalous Payload-based Network Intrusion Detection"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2006.6"},{"key":"ref4","article-title":"KDD Cup 1999 data","year":"1999"},{"key":"ref3","article-title":"Lightweight hierarchical clustering of network packets using (p, n)-grams","author":"hijazi","year":"2009","journal-title":"Technical Report TR-09&#x2013;03"},{"key":"ref6","article-title":"Lincoln Laboratory, MIT. DARPA intrusion detection data sets","year":"2008"},{"key":"ref5","article-title":"NetADHICT: A tool for understanding network traffic","author":"inoue","year":"2007","journal-title":"Proceedings of the 21st Large Installation System Administration Conference (LISA'07)"},{"key":"ref8","first-page":"601","author":"mahoney","year":"2003","journal-title":"Learning rules for anomaly detection of hostile network traffic"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2008.15"},{"key":"ref1","article-title":"DARPA intrusion detection evaluation: Design and procedures","author":"haines","year":"2001","journal-title":"Technical Report TR-1062"},{"key":"ref9","doi-asserted-by":"crossref","first-page":"220","DOI":"10.1007\/978-3-540-45248-5_13","article-title":"An analysis of the 1999 DARPA\/Lincoln Laboratory evaluation data for network anomaly detection","author":"mahoney","year":"2003","journal-title":"Proceedings of the Sixth International Symposium on Recent Advances in Intrusion Detection"}],"event":{"name":"2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA)","location":"Ottawa, ON, Canada","start":{"date-parts":[[2009,7,8]]},"end":{"date-parts":[[2009,7,10]]}},"container-title":["2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/5351161\/5356514\/05356522.pdf?arnumber=5356522","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,19]],"date-time":"2017-06-19T03:13:12Z","timestamp":1497841992000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/5356522\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,7]]},"references-count":13,"URL":"https:\/\/doi.org\/10.1109\/cisda.2009.5356522","relation":{},"subject":[],"published":{"date-parts":[[2009,7]]}}}