{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:14:45Z","timestamp":1785543285811,"version":"3.56.0"},"reference-count":54,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2013,4,1]],"date-time":"2013-04-01T00:00:00Z","timestamp":1364774400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2013,4]]},"abstract":"<jats:p>Real-time network- and host-based Anomaly Detection Systems (ADSs) transform a continuous stream of input data into meaningful and quantifiable anomaly scores. These scores are subsequently compared to a fixed detection threshold and classified as either benign or malicious. We argue that a real-time ADS\u2019 input changes considerably over time and a fixed threshold value cannot guarantee good anomaly detection accuracy for such a time-varying input. In this article, we propose a simple and generic technique to adaptively tune the detection threshold of any ADS that works on threshold method. To this end, we first perform statistical and information-theoretic analysis of network- and host-based ADSs\u2019 anomaly scores to reveal a consistent time correlation structure during benign activity periods. We model the observed correlation structure using Markov chains, which are in turn used in a stochastic target tracking framework to adapt an ADS\u2019 detection threshold in accordance with real-time measurements. We also use statistical techniques to make the proposed algorithm resilient to sporadic changes and evasion attacks. In order to evaluate the proposed approach, we incorporate the proposed adaptive thresholding module into multiple ADSs and evaluate those ADSs over comprehensive and independently collected network and host attack datasets. We show that, while reducing the need of human threshold configuration, the proposed technique provides considerable and consistent accuracy improvements for all evaluated ADSs.<\/jats:p>","DOI":"10.1145\/2445566.2445569","type":"journal-article","created":{"date-parts":[[2013,4,9]],"date-time":"2013-04-09T12:17:58Z","timestamp":1365509878000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["Automated Anomaly Detector Adaptation using Adaptive Threshold Tuning"],"prefix":"10.1145","volume":"15","author":[{"given":"Muhammad Qasim","family":"Ali","sequence":"first","affiliation":[{"name":"University of North Carolina Charlotte (UNCC)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ehab","family":"Al-Shaer","sequence":"additional","affiliation":[{"name":"University of North Carolina Charlotte (UNCC)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hassan","family":"Khan","sequence":"additional","affiliation":[{"name":"National University of Sciences and Technology (NUST), Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Syed Ali","family":"Khayam","sequence":"additional","affiliation":[{"name":"PLUMgrid Inc"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2013,4]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2006.69"},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 2nd USENIX Workshop on Tackling Computer Systems Problems with Machine Learning Techniques. USENIX Association","author":"Agosta J. M.","unstructured":"Agosta , J. M. , Wasser , C. D. , Chandrashekar , J. , and Livadas , C . 2007. An adaptive anomaly detector for worm detection . In Proceedings of the 2nd USENIX Workshop on Tackling Computer Systems Problems with Machine Learning Techniques. USENIX Association , Berkeley, CA, 3:1--3:6. Agosta, J. M., Wasser, C. D., Chandrashekar, J., and Livadas, C. 2007. An adaptive anomaly detector for worm detection. In Proceedings of the 2nd USENIX Workshop on Tackling Computer Systems Problems with Machine Learning Techniques. USENIX Association, Berkeley, CA, 3:1--3:6."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653700"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1823844.1823846"},{"key":"e_1_2_1_5_1","unstructured":"Arbor PeakFlow. Arbor networks\u2019 peakflow product. http:\/\/www.arbornetworks.com\/peakflowsp.  Arbor PeakFlow. Arbor networks\u2019 peakflow product. http:\/\/www.arbornetworks.com\/peakflowsp."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/1433006.1433031"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1557019.1557041"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.2"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2008.4497501"},{"key":"e_1_2_1_10_1","unstructured":"Cisco Anomaly Guard. Cisco anomaly guard module homepage. www.cisco.com\/en\/US\/products\/ps6235\/.  Cisco Anomaly Guard. Cisco anomaly guard module homepage. www.cisco.com\/en\/US\/products\/ps6235\/."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04342-0_3"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.650143"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 1996 IEEE Symposium on Security and Privacy (SP\u201996)","author":"Forrest S.","unstructured":"Forrest , S. , Hofmeyr , S. A. , Somayaji , A. , and Longstaff , T. A . 1996. A sense of self for unix processes . In Proceedings of the 1996 IEEE Symposium on Security and Privacy (SP\u201996) . IEEE Computer Society, Los Alamitos, CA, 120--128. Forrest, S., Hofmeyr, S. A., Somayaji, A., and Longstaff, T. A. 1996. A sense of self for unix processes. In Proceedings of the 1996 IEEE Symposium on Security and Privacy (SP\u201996). IEEE Computer Society, Los Alamitos, CA, 120--128."},{"key":"e_1_2_1_14_1","unstructured":"FTP Brute Forcer. Ssh2ftpcrack ftp\/ssh brute forcer. http:\/\/packetstormsecurity.org\/files\/98155\/SSH2FTPCrack-FTP-SSH-Brute-Forcer.html.  FTP Brute Forcer. Ssh2ftpcrack ftp\/ssh brute forcer. http:\/\/packetstormsecurity.org\/files\/98155\/SSH2FTPCrack-FTP-SSH-Brute-Forcer.html."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_4"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2007.96"},{"key":"e_1_2_1_17_1","unstructured":"Gartner Report. 2003. Gartner information security hype cycle declares Intrusion detection systems a market failure money slated for intrusion detection should be invested in firewalls. http:\/\/www.gartner.com\/about\/press_releases\/pr11june2003c.jsp.  Gartner Report. 2003. Gartner information security hype cycle declares Intrusion detection systems a market failure money slated for intrusion detection should be invested in firewalls. http:\/\/www.gartner.com\/about\/press_releases\/pr11june2003c.jsp."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/11863908_32"},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement (IMC\u201905)","author":"Gu Y.","unstructured":"Gu , Y. , McCullum , A. , and Towsley , D . 2005. Detecting anomalies in network traffic using maximum entropy estimation . In Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement (IMC\u201905) . USENIX Association, Berkeley, CA, 32--32. Gu, Y., McCullum, A., and Towsley, D. 2005. Detecting anomalies in network traffic using maximum entropy estimation. In Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement (IMC\u201905). USENIX Association, Berkeley, CA, 32--32."},{"key":"e_1_2_1_20_1","unstructured":"Heap Profiler. HPROF: A heap\/CPU profiling tool in j2se5.0. http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/samples\/hprof.html.  Heap Profiler. HPROF: A heap\/CPU profiling tool in j2se5.0. http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/samples\/hprof.html."},{"key":"e_1_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Hollinger G. Djugash J. and Singh S. 2008. Tracking a moving target in cluttered environments with ranging radios: Extended results. Tech. rep. CMU-RI-TR-08-07 Robotics Institute Carnegie Mellon University.  Hollinger G. Djugash J. and Singh S. 2008. Tracking a moving target in cluttered environments with ranging radios: Extended results. Tech. rep. CMU-RI-TR-08-07 Robotics Institute Carnegie Mellon University.","DOI":"10.1109\/ROBOT.2008.4543403"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014102"},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP\u201904)","author":"Jung J.","unstructured":"Jung , J. , Paxson , V. , Berger , A. W. , and Balakrishnan , H . 2004. Fast portscan detection using sequential hypothesis testing . In Proceedings of the IEEE Symposium on Security and Privacy (SP\u201904) . IEEE Computer Society, Los Alamitos, CA. Jung, J., Paxson, V., Berger, A. W., and Balakrishnan, H. 2004. Fast portscan detection using sequential hypothesis testing. In Proceedings of the IEEE Symposium on Security and Privacy (SP\u201904). IEEE Computer Society, Los Alamitos, CA."},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of 6th IEEE Systems Man and Cybernetics Information Assurance Workshop (IAW\u201905)","author":"Kang D. K.","unstructured":"Kang , D. K. , Fuller , D. , and Honavar , V . 2005. Learning classifiers for misuse and anomaly detection using a bag of system calls representation . In Proceedings of 6th IEEE Systems Man and Cybernetics Information Assurance Workshop (IAW\u201905) . Kang, D. K., Fuller, D., and Honavar, V. 2005. Learning classifiers for misuse and anomaly detection using a bag of system calls representation. In Proceedings of 6th IEEE Systems Man and Cybernetics Information Assurance Workshop (IAW\u201905)."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102351.1102408"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015492"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1080091.1080118"},{"key":"e_1_2_1_28_1","unstructured":"LBNL Dataset. LBNL\/ICSI enterprise tracing project. http:\/\/www.icir.org\/enterprise-tracing\/Overview.html.  LBNL Dataset. LBNL\/ICSI enterprise tracing project. http:\/\/www.icir.org\/enterprise-tracing\/Overview.html."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"e_1_2_1_30_1","volume-title":"PHAD: Packet header anomaly detection for indentifying hostile network traffic. Tech. rep. CS-2001-4, Florida Tech.","author":"Mahoney M. V.","year":"2001","unstructured":"Mahoney , M. V. and Chan , P. K . 2001 . PHAD: Packet header anomaly detection for indentifying hostile network traffic. Tech. rep. CS-2001-4, Florida Tech. Mahoney, M. V. and Chan, P. K. 2001. PHAD: Packet header anomaly detection for indentifying hostile network traffic. Tech. rep. CS-2001-4, Florida Tech."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2010.160"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.61"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/18.42210"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2008.69"},{"key":"e_1_2_1_35_1","unstructured":"MIT Dataset. MIT lincoln laboratory information systems technology. http:\/\/www.ll.mit.edu\/mission\/communications\/ist\/corpora\/ideval\/data\/index.html.  MIT Dataset. MIT lincoln laboratory information systems technology. http:\/\/www.ll.mit.edu\/mission\/communications\/ist\/corpora\/ideval\/data\/index.html."},{"key":"e_1_2_1_36_1","volume-title":"Code-red: A case study on the spread and victims of an internet worm. In Code-Red: A Case Study on the Spread and Victims of an Internet Worm","author":"Moore D.","year":"2002","unstructured":"Moore , D. , Shannon , C. , and Claffy , K . 2002 . Code-red: A case study on the spread and victims of an internet worm. In Code-Red: A Case Study on the Spread and Victims of an Internet Worm , ACM , New York . Moore, D., Shannon, C., and Claffy, K. 2002. Code-red: A case study on the spread and victims of an internet worm. In Code-Red: A Case Study on the Spread and Victims of an Internet Worm, ACM, New York."},{"key":"e_1_2_1_37_1","unstructured":"Netsparker tool. Netsparker web application security scanner. http:\/\/www.mavitunasecurity.com\/netsparker\/.  Netsparker tool. Netsparker web application security scanner. http:\/\/www.mavitunasecurity.com\/netsparker\/."},{"key":"e_1_2_1_38_1","unstructured":"Nexgin Dataset. Nexgin rc dataset. http:\/\/www.nexginrc.org\/Datasets\/Default.aspx.  Nexgin Dataset. Nexgin rc dataset. http:\/\/www.nexginrc.org\/Datasets\/Default.aspx."},{"key":"e_1_2_1_39_1","unstructured":"NUST Dataset. NUST traffic datasets. http:\/\/wisnet.seecs.nust.edu.pk\/projects\/nes\/datasets.html.  NUST Dataset. NUST traffic datasets. http:\/\/wisnet.seecs.nust.edu.pk\/projects\/nes\/datasets.html."},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement (IMC\u201905)","author":"Pang R.","unstructured":"Pang , R. , Allman , M. , Bennett , M. , Lee , J. , Paxson , V. , and Tierney , B . 2005. A first look at modern enterprise traffic . In Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement (IMC\u201905) . USENIX Association, Berkeley, CA, 2--2. Pang, R., Allman, M., Bennett, M., Lee, J., Paxson, V., and Tierney, B. 2005. A first look at modern enterprise traffic. In Proceedings of the 5th ACM SIGCOMM Conference on Internet Measurement (IMC\u201905). USENIX Association, Berkeley, CA, 2--2."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1380564.1380566"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.59"},{"key":"e_1_2_1_43_1","unstructured":"Sqlninja tool. Sqlninja a SQL server injection and takeover tool. http:\/\/sqlninja.sourceforge.net\/.  Sqlninja tool. Sqlninja a SQL server injection and takeover tool. http:\/\/sqlninja.sourceforge.net\/."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.37"},{"key":"e_1_2_1_45_1","unstructured":"Symantec Security. Symantec security response. http:\/\/securityresponse.symantec.com\/avcenter.  Symantec Security. Symantec security response. http:\/\/securityresponse.symantec.com\/avcenter."},{"key":"e_1_2_1_46_1","unstructured":"TADM toolkit. Tadm toolkit for advanced discriminative modeling. http:\/\/tadm.sourceforge.net.  TADM toolkit. Tadm toolkit for advanced discriminative modeling. http:\/\/tadm.sourceforge.net."},{"key":"e_1_2_1_47_1","unstructured":"Tcpdump tool. Tcpdump\/libpcap public repository. http:\/\/www.tcpdump.org\/.  Tcpdump tool. Tcpdump\/libpcap public repository. http:\/\/www.tcpdump.org\/."},{"key":"e_1_2_1_48_1","volume-title":"Detection, Estimation and Modulation Theory: Part I","author":"Trees H. L. V.","unstructured":"Trees , H. L. V. 2001. Detection, Estimation and Modulation Theory: Part I 1 st Ed. Wiley-Interscience . Trees, H. L. V. 2001. Detection, Estimation and Modulation Theory: Part I 1st Ed. Wiley-Interscience.","edition":"1"},{"key":"e_1_2_1_49_1","volume-title":"Proceedings of the 12th Conference on USENIX Security Symposium. USENIX Association","author":"Twycross J.","unstructured":"Twycross , J. and Williamson , M. M . 2003. Implementing and testing a virus throttle . In Proceedings of the 12th Conference on USENIX Security Symposium. USENIX Association , Berkeley, CA, 20--20. Twycross, J. and Williamson, M. M. 2003. Implementing and testing a virus throttle. In Proceedings of the 12th Conference on USENIX Security Symposium. USENIX Association, Berkeley, CA, 20--20."},{"key":"e_1_2_1_50_1","unstructured":"UNM Dataset. Computer immune systems datasets. http:\/\/www.cs.unm.edu\/~immsec\/data\/synth-sm.html.  UNM Dataset. Computer immune systems datasets. http:\/\/www.cs.unm.edu\/~immsec\/data\/synth-sm.html."},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID). 203--222","author":"Wang K.","unstructured":"Wang , K. and Stolfo , S. J . 2004. Anomalous payload-based network intrusion detection . In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID). 203--222 . Wang, K. and Stolfo, S. J. 2004. Anomalous payload-based network intrusion detection. In Proceedings of the 7th International Symposium on Recent Advances in Intrusion Detection (RAID). 203--222."},{"key":"e_1_2_1_52_1","unstructured":"WisNet ADS. Wisnet ADS comparison homepage. http:\/\/wisnet.niit.edu.pk\/projects\/adeval.  WisNet ADS. Wisnet ADS comparison homepage. http:\/\/wisnet.niit.edu.pk\/projects\/adeval."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCB.2006.885306"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1380422.1380425"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2445566.2445569","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2445566.2445569","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:34:09Z","timestamp":1750239249000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2445566.2445569"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,4]]},"references-count":54,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,4]]}},"alternative-id":["10.1145\/2445566.2445569"],"URL":"https:\/\/doi.org\/10.1145\/2445566.2445569","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,4]]},"assertion":[{"value":"2011-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-01-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-04-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}