{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,21]],"date-time":"2025-05-21T05:27:32Z","timestamp":1747805252930,"version":"3.28.0"},"reference-count":14,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1109\/icon.2003.1266245","type":"proceedings-article","created":{"date-parts":[[2004,7,8]],"date-time":"2004-07-08T16:05:44Z","timestamp":1089302744000},"page":"531-536","source":"Crossref","is-referenced-by-count":11,"title":["A multi-layer model for anomaly intrusion detection using program sequences of system calls"],"prefix":"10.1109","author":[{"family":"Xuan Dau Hoang","sequence":"first","affiliation":[]},{"family":"Jiankun Hu","sequence":"additional","affiliation":[]},{"given":"P.","family":"Bertok","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924295"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1049\/el:20020467"},{"journal-title":"University of New Mexico's Computer Immune Systems Project","year":"0","key":"ref12"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ECBS.2001.922429"},{"journal-title":"Approaches to Online Learning and Concept Drift for User Identification in Computer Security","year":"1998","author":"lane","key":"ref14"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"ref6","article-title":"A tutorial on Hidden Markov Models","author":"dugad","year":"1996","journal-title":"Technical Report No SPANN-96 1"},{"key":"ref5","article-title":"An introduction to Hidden Markov Models","author":"rabiner","year":"1996","journal-title":"IEEE ASSP Magazine"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/382912.382914"},{"journal-title":"Hidden Markov Models","year":"0","author":"kanungo","key":"ref7"},{"key":"ref2","doi-asserted-by":"crossref","first-page":"151","DOI":"10.3233\/JCS-980109","article-title":"Intrusion detection using sequences of system calls","volume":"6","author":"forrest","year":"1998","journal-title":"Journal of Computer Securit y"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/545186.545187"}],"event":{"name":"The 11th IEEE International Conference on Networks, 2003. ICON2003.","location":"Sydney, Australia"},"container-title":["The 11th IEEE International Conference on Networks, 2003. ICON2003."],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/8945\/28322\/01266245.pdf?arnumber=1266245","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,6,11]],"date-time":"2018-06-11T16:08:20Z","timestamp":1528733300000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/1266245\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"references-count":14,"URL":"https:\/\/doi.org\/10.1109\/icon.2003.1266245","relation":{},"subject":[]}}