{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T16:06:40Z","timestamp":1772726800035,"version":"3.50.1"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2016,5,1]],"date-time":"2016-05-01T00:00:00Z","timestamp":1462060800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2016,5]]},"DOI":"10.1109\/tifs.2015.2512522","type":"journal-article","created":{"date-parts":[[2015,12,25]],"date-time":"2015-12-25T19:03:40Z","timestamp":1451070220000},"page":"893-906","source":"Crossref","is-referenced-by-count":89,"title":["An Efficient Data-Driven Clustering Technique to Detect Attacks in SCADA Systems"],"prefix":"10.1109","volume":"11","author":[{"given":"Abdulmohsen","family":"Almalawi","sequence":"first","affiliation":[]},{"given":"Adil","family":"Fahad","sequence":"additional","affiliation":[]},{"given":"Zahir","family":"Tari","sequence":"additional","affiliation":[]},{"given":"Abdullah","family":"Alamri","sequence":"additional","affiliation":[]},{"given":"Rayed","family":"AlGhamdi","sequence":"additional","affiliation":[]},{"given":"Albert Y.","family":"Zomaya","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref38","first-page":"164","article-title":"A linear method for deviation detection in large databases","author":"arning","year":"1996","journal-title":"Proc ACM Conf Knowledge Discovery Data Mining (KDD)"},{"key":"ref33","first-page":"226","article-title":"A density based algorithm for discovering clusters in large spatial databases with noise","volume":"7","author":"ester","year":"1996","journal-title":"Proc KDD"},{"key":"ref32","first-page":"186","article-title":"STING: A statistical information grid approach to spatial data mining","author":"wang","year":"1997","journal-title":"Proc 23rd Int Conf Very Large Data Bases"},{"key":"ref31","first-page":"428","article-title":"WaveCluster: A wavelet-based clustering approach for spatial data in very large databases","author":"sheikholeslami","year":"1998","journal-title":"Proc 24th Int Conf Very Large Data Bases"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/235968.233324"},{"key":"ref37","doi-asserted-by":"crossref","first-page":"399","DOI":"10.15388\/Informatica.2004.068","article-title":"Outlier detection based on the distribution of distances between data points","volume":"15","author":"\u0161altenis","year":"2004","journal-title":"Informatica"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/502512.502554"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-48247-5_28"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/342009.335388"},{"key":"ref10","first-page":"1","article-title":"On SCADA control system command and response injection and intrusion detection","author":"gao","year":"2010","journal-title":"Proc eCrime Res Summit (eCrime)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1002\/we.319"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1049\/el.2014.2897"},{"key":"ref13","first-page":"45","article-title":"A real time OCSVM intrusion detection module with low overhead for SCADA systems","volume":"3","author":"maglaras","year":"2014","journal-title":"Int J Adv Res Artificial Intell"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2009.5178592"},{"key":"ref15","first-page":"127","article-title":"Using model-based intrusion detection for SCADA networks","author":"cheung","year":"2007","journal-title":"Proc SCADA Security Sci Symp"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2009.5168010"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2013.06.030"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2013.10.002"},{"key":"ref19","first-page":"5","article-title":"Intrusion detection with unlabeled data using clustering","author":"portnoy","year":"2001","journal-title":"Proc ACM CSS Workshop on Data Mining Applied to Security"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2013.6761301"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2010.2099234"},{"key":"ref27","year":"2011","journal-title":"Daily Residential Water Use for Melbourne"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.86"},{"key":"ref6","first-page":"1872","article-title":"Wind turbine condition monitoring and reliability analysis by SCADA information","author":"yang","year":"2011","journal-title":"Proc 2nd Int Conf Mech Autom Control Eng (MACE)"},{"key":"ref29","first-page":"144","article-title":"Efficient and effective clustering methods for spatial data mining","author":"ng","year":"1994","journal-title":"Proc 20th Int Conf Very Large Data Bases"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIE.2011.2181132"},{"key":"ref8","article-title":"Composite intrusion detection in process control networks","author":"rrushi","year":"2009"},{"key":"ref7","first-page":"1","article-title":"Anomaly detection in electricity cyber infrastructures","author":"jin","year":"2006","journal-title":"Proc Int Workshop Complex Netw Infrastruct Protect (CNIP)"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2009.10.001"},{"key":"ref9","first-page":"301","article-title":"Application of data driven methods for condition monitoring maintenance","volume":"33","author":"marton","year":"2013","journal-title":"Chem Eng Trans"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-75462-8_6"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.07.005"},{"key":"ref22","author":"frank","year":"2010","journal-title":"UCI Machine Learning Repository"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511809071"},{"key":"ref24","year":"2011","journal-title":"ModBus\/TCP Simulator"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ISSNIP.2010.5706782"},{"key":"ref26","year":"2011","journal-title":"Software That Models the Hydraulic and Water Quality Behavior of Water Distribution Piping Systems"},{"key":"ref25","year":"2004","journal-title":"MODBUS Messaging on TCP\/IP Implementation Guide v1 0a"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/7419279\/7366594.pdf?arnumber=7366594","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:48:30Z","timestamp":1642006110000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7366594\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,5]]},"references-count":38,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2015.2512522","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,5]]}}}