{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T16:57:37Z","timestamp":1778345857615,"version":"3.51.4"},"reference-count":42,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,1]]},"DOI":"10.1109\/comsnets.2012.6151337","type":"proceedings-article","created":{"date-parts":[[2012,2,15]],"date-time":"2012-02-15T15:20:00Z","timestamp":1329319200000},"page":"1-10","source":"Crossref","is-referenced-by-count":8,"title":["Pairgram: Modeling frequency information of lookahead pairs for system call based anomaly detection"],"prefix":"10.1109","author":[{"given":"Neminath","family":"Hubballi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45215-7_17"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"ref33","first-page":"229","article-title":"Snort - lightweight intrusion detection for networks","author":"roesch","year":"1999","journal-title":"LISA '99 Proceedings of the 13th USENIX conference on System administration"},{"key":"ref32","first-page":"1","article-title":"Improving host security with system call policies","author":"provos","year":"2003","journal-title":"USENIX '03 Proceedings of the 12th Conference on USENIX Security Symposium"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2007.02.001"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24707-4_66"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924296"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1142\/S0218213006003028"},{"key":"ref34","first-page":"14","article-title":"Automated response using system-call delays","author":"somayaji","year":"2000","journal-title":"SSYM'00 Proceedings of the 9th conference on USENIX Security Symposium"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"ref40","doi-asserted-by":"crossref","first-page":"159","DOI":"10.3233\/JCS-2000-82-305","article-title":"Fixed- vs. variablelength patterns for detecting suspicious process behavior","volume":"8","author":"wespi","year":"2000","journal-title":"Journal of Computer Security"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/RISP.1994.296580"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_2"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030126"},{"key":"ref14","first-page":"61","article-title":"Detecting manipulated remote call streams","author":"giffin","year":"2002","journal-title":"USENIX '02 Proceedings of the 11th USENIX Security Symposium"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_3"},{"key":"ref16","doi-asserted-by":"crossref","first-page":"151","DOI":"10.3233\/JCS-980109","article-title":"Intrusion detection using sequences of system calls","volume":"6","author":"hofmeyr","year":"1998","journal-title":"Journal of Computer Security"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2010.31"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/COMSNETS.2011.5716416"},{"key":"ref19","first-page":"1","article-title":"Lookahead pairs and full sequences: A tale of two anomaly detection methods","author":"inoue","year":"2007","journal-title":"Proceedings of the 2nd Annual Symposium on Information Assurance"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/1127345.1127348"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1852666.1852703"},{"key":"ref27","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/978-3-540-74320-0_1","article-title":"Exploiting execution context for the detection of anomalous system calls","author":"mutz","year":"2007","journal-title":"RAID '07 Proceedings of the 10th International Conference on Recent Advances in Intrusion Detection"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972795.17"},{"key":"ref6","first-page":"1","article-title":"Formalizing sensitivity in static analysis for intrusion detection","author":"feng","year":"2004","journal-title":"S&P '04 Proceedings of the 24th IEEE Symposium on Security and Privacy"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SMCSIA.2003.1232400"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2001.932213"},{"key":"ref8","article-title":"Computer immune systems- datasets and software","author":"forrest","year":"2006"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2003.1199328"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.54"},{"key":"ref1","article-title":"Anomaly detection for discrete sequences","author":"chandola","year":"0","journal-title":"IEEE Transactions on Knowledge and Data Engineering (In press)"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2001.991561"},{"key":"ref22","first-page":"1","article-title":"A comparative study of anomaly detection scehemes in network intrusion detection","author":"lazarevic","year":"2003","journal-title":"ICDM 03' Proceedings of 3rd SIAM International Conference on Data Mining"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/52.605929"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_2"},{"key":"ref24","first-page":"101","article-title":"Characterizing the behavior of a program using multiplelength n-grams","author":"marceau","year":"2000","journal-title":"Proceedings New Security Paradigms Workshop NSPW"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2010.26"},{"key":"ref23","first-page":"164","article-title":"Combining static analysis and dynamic learning to build accurate intrusion detection models","author":"liu","year":"2005","journal-title":"Proc IEE Int Workshop IE"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2000.898854"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/545186.545187"}],"event":{"name":"2012 Fourth International Conference on Communication Systems and Networks (COMSNETS)","location":"Bangalore, India","start":{"date-parts":[[2012,1,3]]},"end":{"date-parts":[[2012,1,7]]}},"container-title":["2012 Fourth International Conference on Communication Systems and Networks (COMSNETS 2012)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/6145051\/6151271\/06151337.pdf?arnumber=6151337","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,23]],"date-time":"2019-06-23T19:25:28Z","timestamp":1561317928000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6151337\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,1]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/comsnets.2012.6151337","relation":{},"subject":[],"published":{"date-parts":[[2012,1]]}}}