{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:43:47Z","timestamp":1750308227335,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":11,"publisher":"ACM","license":[{"start":{"date-parts":[[2004,8,22]],"date-time":"2004-08-22T00:00:00Z","timestamp":1093132800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2004,8,22]]},"DOI":"10.1145\/1014052.1014084","type":"proceedings-article","created":{"date-parts":[[2004,10,7]],"date-time":"2004-10-07T17:39:48Z","timestamp":1097170788000},"page":"276-285","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["Selection, combination, and evaluation of effective software sensors for detecting abnormal computer usage"],"prefix":"10.1145","author":[{"given":"Jude","family":"Shavlik","sequence":"first","affiliation":[{"name":"University of Wisconsin, Madison, WI"}]},{"given":"Mark","family":"Shavlik","sequence":"additional","affiliation":[{"name":"Shavlik Technologies, Roseville, MN"}]}],"member":"320","published-online":{"date-parts":[[2004,8,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"PNrule: A New Framework for Learning Classifier Models in Data Mining (A Case-Study in Network Intrusion Detection) Proc. First SIAM Intl. Conf. on Data Mining","author":"Agarwal R.","year":"2001","unstructured":"R. Agarwal & M. Joshi , PNrule: A New Framework for Learning Classifier Models in Data Mining (A Case-Study in Network Intrusion Detection) Proc. First SIAM Intl. Conf. on Data Mining , 2001 . R. Agarwal & M. Joshi, PNrule: A New Framework for Learning Classifier Models in Data Mining (A Case-Study in Network Intrusion Detection) Proc. First SIAM Intl. Conf. on Data Mining, 2001."},{"key":"e_1_3_2_1_3_1","volume-title":"DARPA Workshop Report","author":"Research DARPA","year":"1999","unstructured":"DARPA , Research and Development Initiatives Focused on Preventing , Detecting, and Responding to Insider Misuse of Critical Defense Information Systems , DARPA Workshop Report , 1999 . DARPA, Research and Development Initiatives Focused on Preventing, Detecting, and Responding to Insider Misuse of Critical Defense Information Systems, DARPA Workshop Report, 1999."},{"key":"e_1_3_2_1_4_1","volume-title":"USENIX Workshop on Intrusion Detection & Network Monitoring","author":"Ghosh A.","year":"1999","unstructured":"A. Ghosh , A. Schwartzbard , & M. Schatz , Learning Program Behavior Profiles for Intrusion Detection , USENIX Workshop on Intrusion Detection & Network Monitoring , April 1999 . A. Ghosh, A. Schwartzbard, & M. Schatz, Learning Program Behavior Profiles for Intrusion Detection, USENIX Workshop on Intrusion Detection & Network Monitoring, April 1999."},{"key":"e_1_3_2_1_5_1","first-page":"259","volume-title":"Proc. KDD","author":"Lane T.","year":"1998","unstructured":"T. Lane & C. Brodley , Approaches to Online Learning and Concept Drift for User Identification in Computer Security , Proc. KDD , pp 259 -- 263 , 1998 . T. Lane & C. Brodley, Approaches to Online Learning and Concept Drift for User Identification in Computer Security, Proc. KDD, pp 259--263, 1998."},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. SIAM Conf. Data Mining","author":"Lazarevic A.","year":"2003","unstructured":"A. Lazarevic , L. Ertoz , A. Ozgur , J. Srivastava & V. Kumar , A Comparative Study of Anomaly Detection Schemes in Network Intrusion Detection , Proc. SIAM Conf. Data Mining , 2003 . A. Lazarevic, L. Ertoz, A. Ozgur, J. Srivastava & V. Kumar, A Comparative Study of Anomaly Detection Schemes in Network Intrusion Detection, Proc. SIAM Conf. Data Mining, 2003."},{"key":"e_1_3_2_1_7_1","volume-title":"Proc. IEEE Symp. on Security and Privacy","author":"Lee W.","year":"1999","unstructured":"W. Lee , S.J. Stolfo , and K. Mok , A Data Mining Framework for Building Intrusion Detection Models , Proc. IEEE Symp. on Security and Privacy , 1999 . W. Lee, S.J. Stolfo, and K. Mok, A Data Mining Framework for Building Intrusion Detection Models, Proc. IEEE Symp. on Security and Privacy, 1999."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022869011914"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(93)90029-5"},{"volume-title":"Machine Learning","author":"Mitchell T.","key":"e_1_3_2_1_10_1","unstructured":"T. Mitchell , Machine Learning , McGraw-Hill . T. Mitchell, Machine Learning, McGraw-Hill."},{"key":"e_1_3_2_1_12_1","volume-title":"April","author":"Shavlik J.","year":"2002","unstructured":"J. Shavlik & M. Shavlik , Final Project Report for DARPA's Insider Threat Active Profiling (ITAP) program , April 2002 . J. Shavlik & M. Shavlik, Final Project Report for DARPA's Insider Threat Active Profiling (ITAP) program, April 2002."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1999.766910"}],"event":{"name":"KDD04: ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data","ACM Association for Computing Machinery"],"location":"Seattle WA USA","acronym":"KDD04"},"container-title":["Proceedings of the tenth ACM SIGKDD international conference on Knowledge discovery and data mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1014052.1014084","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1014052.1014084","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:30Z","timestamp":1750264290000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1014052.1014084"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2004,8,22]]},"references-count":11,"alternative-id":["10.1145\/1014052.1014084","10.1145\/1014052"],"URL":"https:\/\/doi.org\/10.1145\/1014052.1014084","relation":{},"subject":[],"published":{"date-parts":[[2004,8,22]]},"assertion":[{"value":"2004-08-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}