{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:20:42Z","timestamp":1771698042461,"version":"3.50.1"},"reference-count":29,"publisher":"Wiley","license":[{"start":{"date-parts":[[2019,5,2]],"date-time":"2019-05-02T00:00:00Z","timestamp":1556755200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Ministry of Science, Research & Technology"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2019,5,2]]},"abstract":"<jats:p>In spite of the tangible advantages of cloud computing, it is still vulnerable to potential attacks and threats. In light of this, security has turned into one of the main concerns in the adoption of cloud computing. Therefore, an anomaly detection method plays an important role in providing a high protection level for network security. One of the challenges in anomaly detection, which has not been seriously considered in the literature, is applying the dynamic nature of cloud traffic in its prediction while maintaining an acceptable level of accuracy besides reducing the computational cost. On the other hand, to overcome the issue of additional training time, introducing a high-speed algorithm is essential. In this paper, a network traffic anomaly detection model grounded in Catastrophe Theory is proposed. This theory is effective in depicting sudden change processes of the network due to the dynamic nature of the cloud. Exponential Moving Average (EMA) is applied for the state variable in sliding window to better show the dynamicity of cloud network traffic. Entropy is used as one of the control variables in catastrophe theory to analyze the distribution of traffic features. Our work is compared with Wei Xiong et al.\u2019s Catastrophe Theory and achieved a maximum improvement in the percentage of Detection Rate in week 4 Wednesday (7.83%) and a 0.31% reduction in False Positive Rate in week 5 Monday. Additional accuracy parameters are checked and the impact of sliding window size in sensitivity and specificity is considered.<\/jats:p>","DOI":"10.1155\/2019\/5306395","type":"journal-article","created":{"date-parts":[[2019,5,2]],"date-time":"2019-05-02T19:35:10Z","timestamp":1556825710000},"page":"1-11","source":"Crossref","is-referenced-by-count":13,"title":["Applying Catastrophe Theory for Network Anomaly Detection in Cloud Computing Traffic"],"prefix":"10.1155","volume":"2019","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7675-228X","authenticated-orcid":true,"given":"Leila","family":"Khatibzadeh","sequence":"first","affiliation":[{"name":"Electrical Engineering and Information Technology Department, Iranian Research Organization for Science and Technology (IROST), Tehran 3353136846, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2628-2005","authenticated-orcid":true,"given":"Zarrintaj","family":"Bornaee","sequence":"additional","affiliation":[{"name":"Electrical Engineering and Information Technology Department, Iranian Research Organization for Science and Technology (IROST), Tehran 3353136846, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abbas","family":"Ghaemi Bafghi","sequence":"additional","affiliation":[{"name":"Computer Department, Faculty of Engineering, Ferdowsi University of Mashhad, Mashhad, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","reference":[{"key":"1","doi-asserted-by":"crossref","first-page":"9800","DOI":"10.1109\/ACCESS.2016.2631543","volume":"4","year":"2016","journal-title":"IEEE Access"},{"key":"4","doi-asserted-by":"crossref","first-page":"403","DOI":"10.1016\/j.ins.2013.04.009","volume":"258","year":"2014","journal-title":"Information Sciences"},{"key":"5","doi-asserted-by":"crossref","first-page":"338","DOI":"10.1016\/j.procs.2015.04.191","volume":"48","year":"2015","journal-title":"Procedia Computer Science"},{"issue":"3","key":"7","volume":"18","year":"2016","journal-title":"International Journal of Fuzzy Systems"},{"key":"9","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-016-9392-x"},{"key":"10","doi-asserted-by":"publisher","DOI":"10.1002\/nem.1934"},{"issue":"6","key":"14","volume":"2","year":"2013","journal-title":"International Journal of Application or Innovation in Engineering and Management"},{"key":"15","first-page":"726","volume-title":"A hybrid anomaly detection framework in cloud computing using one-class and two-class support vector machines","year":"2012"},{"issue":"2","key":"17","volume":"31","year":"2012","journal-title":"Computing and Informatics"},{"key":"18","doi-asserted-by":"publisher","DOI":"10.1007\/s11036-015-0644-x"},{"key":"21","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2011.08.045"},{"key":"12","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2015.07.007"},{"key":"13","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-014-5473-9"},{"key":"16","doi-asserted-by":"crossref","first-page":"708","DOI":"10.1016\/j.procs.2015.08.220","volume":"60","year":"2015","journal-title":"Procedia Computer Science"},{"key":"20","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-011-0644-y"},{"key":"23","doi-asserted-by":"publisher","DOI":"10.1137\/1019036"},{"key":"24","year":"2013","journal-title":"Chaos and Complexity Seminar"},{"key":"25","doi-asserted-by":"publisher","DOI":"10.1007\/BF00869575"},{"key":"26","doi-asserted-by":"publisher","DOI":"10.1016\/S0020-7683(01)00060-9"},{"key":"27","doi-asserted-by":"publisher","DOI":"10.1038\/scientificamerican0476-65"},{"key":"28","doi-asserted-by":"publisher","DOI":"10.1137\/1020043"},{"issue":"8","key":"29","first-page":"1046","volume":"37","year":"2005","journal-title":"Journal of Harbin Institute of Technology"},{"key":"30","year":"2012"},{"key":"31","year":"1993"},{"key":"32","doi-asserted-by":"publisher","DOI":"10.1007\/s00591-010-0080-8"},{"key":"33","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2010.06.066"},{"key":"34","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2007.03.025"},{"key":"36","year":"1992"},{"key":"38","doi-asserted-by":"publisher","DOI":"10.1109\/surv.2013.052213.00046"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2019\/5306395.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2019\/5306395.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2019\/5306395.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,2]],"date-time":"2019-05-02T19:35:14Z","timestamp":1556825714000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2019\/5306395\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,5,2]]},"references-count":29,"alternative-id":["5306395","5306395"],"URL":"https:\/\/doi.org\/10.1155\/2019\/5306395","relation":{},"ISSN":["1939-0114","1939-0122"],"issn-type":[{"value":"1939-0114","type":"print"},{"value":"1939-0122","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,5,2]]}}}