{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T12:13:05Z","timestamp":1763727185373,"version":"3.37.3"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2017,12,1]],"date-time":"2017-12-01T00:00:00Z","timestamp":1512086400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61501447"],"award-info":[{"award-number":["61501447"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2017,12]]},"DOI":"10.1109\/tifs.2017.2730581","type":"journal-article","created":{"date-parts":[[2017,7,21]],"date-time":"2017-07-21T18:25:53Z","timestamp":1500661553000},"page":"3011-3023","source":"Crossref","is-referenced-by-count":52,"title":["Double Behavior Characteristics for One-Class Classification Anomaly Detection in Networked Control Systems"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9195-8422","authenticated-orcid":false,"given":"Ming","family":"Wan","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8332-9036","authenticated-orcid":false,"given":"Wenli","family":"Shang","sequence":"additional","affiliation":[]},{"given":"Peng","family":"Zeng","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2014.2330796"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SAI.2014.6918252"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2009.5178592"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCP.2014.6937009"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2013.2270373"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2015.2512522"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI.2015.22"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CICYBS.2011.5949392"},{"key":"ref35","first-page":"171","article-title":"New genetic algorithm based intrusion detection system for SCADA","volume":"2","author":"anoop","year":"2013","journal-title":"Int J Electron Commun Comput Eng"},{"key":"ref34","first-page":"1","article-title":"On SCADA control system command and response injection and intrusion detection","author":"gao","year":"2010","journal-title":"Proc IEEE eCrime Res Summit"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2010.2099234"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2443793"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.2015.2415763"},{"article-title":"Guide to industrial control systems (ICS) security","year":"2013","author":"stouffer","key":"ref2"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIE.2009.2035462"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2012.2223512"},{"key":"ref22","first-page":"85","article-title":"Cyber-critical infrastructure protection using real-time payload-based anomaly detection","author":"dussel","year":"2009","journal-title":"Proc 4th Int Workshop Critical Inf Infrastruct Secur"},{"key":"ref21","first-page":"1","article-title":"SCADA-specific intrusion detection\/prevention systems: A survey and taxonomy","author":"zhu","year":"2010","journal-title":"Proc Workshop Secure Control Systems (SCS)"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.08.003"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2009.5168010"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/PTC.2015.7232339"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/JCN.2012.6253092"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2002.1007589"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/IGARSS.2003.1293752"},{"key":"ref52","first-page":"1523","article-title":"PSO based Kernel principal component analysis and multi-class support vector machine for power quality problem classification","volume":"8","author":"pahasa","year":"2012","journal-title":"Int J Innov Comput Inf Control"},{"journal-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","year":"2016","author":"lee","key":"ref10"},{"journal-title":"Nccic\/ics-cert year in review 2015","year":"2016","key":"ref11"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1049\/el.2014.2897"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-014-1870-0"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2013.2257594"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2016.109"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/iThings\/CPSCom.2011.34"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2013.05.001"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s11235-016-0223-x"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.114"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ITNEC.2016.7560424"},{"article-title":"Recommendations for implementing the strategic initiative INDUSTRIE 4.0","year":"2013","author":"kagermann","key":"ref4"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.06.007"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRS.2008.2002298"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/MCG.2015.45"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2016.2594178"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2012.2198666"},{"journal-title":"Kernel Methods in Computer Vision","year":"2009","author":"lampert","key":"ref49"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2509994"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1162\/089976698300017467"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1162\/089976601750264965"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2006.07.009"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/s11634-010-0068-1"},{"key":"ref42","first-page":"2314","article-title":"Modbus\/TCP communication anomaly detection algorithm based on PSO-SVM","volume":"42","author":"shang","year":"2014","journal-title":"ACTA Electron Sinica"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2016.32"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1398"},{"key":"ref43","first-page":"21","article-title":"Industrial communication intrusion detection algorithm based on improved one-class SVM","author":"shang","year":"2015","journal-title":"Proc World Congr Ind Control Syst Secur"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/8017695\/07987719.pdf?arnumber=7987719","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:22:18Z","timestamp":1642004538000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7987719\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,12]]},"references-count":52,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2017.2730581","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2017,12]]}}}