{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:46Z","timestamp":1777806286482,"version":"3.51.4"},"reference-count":32,"publisher":"SAGE Publications","issue":"6","license":[{"start":{"date-parts":[[2025,7,23]],"date-time":"2025-07-23T00:00:00Z","timestamp":1753228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2025,11]]},"abstract":"<jats:p>In recent years, intrusion detection has become an important topic in data analytics for network protection and security measures. In this paper, a new diagnostic method for data recorded over a working computer network is presented. It can be used in information security applications such as intrusion detection and prevention. The proposed technique considers a generalized correlation data representation and applies a digit distribution. The current techniques were evaluated, documented, and presented by conducting various tests on the recorded features of the network using the UNSW-NB15 dataset. The evaluation results illustrate the high-detection rates achieved.<\/jats:p>","DOI":"10.1177\/0926227x251360421","type":"journal-article","created":{"date-parts":[[2025,7,23]],"date-time":"2025-07-23T09:15:06Z","timestamp":1753262106000},"page":"386-401","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":0,"title":["Network intrusion detection based on a generalized correlation function"],"prefix":"10.1177","volume":"33","author":[{"given":"Spiros","family":"Chountasis","sequence":"first","affiliation":[{"name":"Independent Power Transmission Operator, Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9415-1392","authenticated-orcid":false,"given":"Dimitrios","family":"Pappas","sequence":"additional","affiliation":[{"name":"Department of Statistics, Athens University of Economics and Business, Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dimitris","family":"Sklavounos","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Metropolitan College, Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2025,7,23]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.08.003"},{"key":"e_1_3_2_3_2","unstructured":"Ireland E. Intrusion detection with genetic algorithms and fuzzy logic. In: UMMC Sci senior seminar conference Morris MN December 2013 pp.1\u201330."},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-010-0102-5"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/s102070100001"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2019.113105"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.4218\/etrij.2019-0476"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13163-019-00335-w"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.11591\/eei.v10i5.2833"},{"key":"e_1_3_2_10_2","doi-asserted-by":"crossref","unstructured":"Sethi K Kumar R Prajapati N et al. A lightweight intrusion detection system using Benford\u2019s law and network flow size difference. In: 2020 international conference on communication systems and networks (COMSNETS) Bengaluru India 2020 pp. 1\u20136. DOI: https:\/\/doi.org\/10.1109\/COMSNETS48256.2020.9027422.","DOI":"10.1109\/COMSNETS48256.2020.9027422"},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","unstructured":"Xu X Ali S Yue T. Digital twin-based anomaly detection in cyber-physical systems. In: 14th IEEE conference on software testing verification and validation (ICST) Porto de Galinhas Brazil 2021. pp. 205\u2013216.\u00a0DOI: https:\/\/doi.org\/10.1109\/ICST49551.2021.00031.","DOI":"10.1109\/ICST49551.2021.00031"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113252"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-020-03203-1"},{"key":"e_1_3_2_14_2","doi-asserted-by":"crossref","unstructured":"Prandl S Lazarescu M Soh ST et al. An investigation of power law probability distributions for network anomaly detection. In: 2017 IEEE symposium on security and privacy workshops (SPW) San Jose CA USA 2017. pp. 217\u2013222.\u00a0DOI: https:\/\/doi.org\/10.1109\/SPW.2017.20.","DOI":"10.1109\/SPW.2017.20"},{"key":"e_1_3_2_15_2","first-page":"226","article-title":"A review of intrusion alerts correlation frameworks","volume":"5","author":"Chahira J","year":"2016","unstructured":"Chahira J, Kiruki J, Kemei P. A review of intrusion alerts correlation frameworks. Int J Comput Appl Technol Res 2016; 5: 226\u2013233.","journal-title":"Int J Comput Appl Technol Res"},{"key":"e_1_3_2_16_2","article-title":"Network anomaly detection based on wavelet analysis","volume":"2009","author":"Lu W","year":"2009","unstructured":"Lu W, Ghorbani AA. Network anomaly detection based on wavelet analysis. EURASIP J Adv Signal Process 2009; 2009: Article number: 837601.","journal-title":"EURASIP J Adv Signal Process"},{"key":"e_1_3_2_17_2","article-title":"Multilayer statistical intrusion detection in wireless networks","volume":"2009","author":"Hamdi M","year":"2009","unstructured":"Hamdi M, Meddeb-Makhlouf A, Boudriga N. Multilayer statistical intrusion detection in wireless networks. EURASIP J Adv Signal Process 2009; 2009: Article number: 368589.","journal-title":"EURASIP J Adv Signal Process"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1155\/2009\/752818"},{"key":"e_1_3_2_19_2","first-page":"17","article-title":"The effective use of Benford\u2019s law in detecting fraud in accounting data","volume":"5","author":"Durtschi C","year":"2004","unstructured":"Durtschi C, Hillison W, Pacini C. The effective use of Benford\u2019s law in detecting fraud in accounting data. J Forensic Account 2004; 5: 17\u201334.","journal-title":"J Forensic Account"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1002\/0471663085"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.30749"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/79.127284"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1112\/S0024610705006903"},{"key":"e_1_3_2_24_2","first-page":"551","article-title":"The law of anomalous numbers","volume":"78","author":"Benford F","year":"1938","unstructured":"Benford F. The law of anomalous numbers. Proc Am Philos Soc 1938; 78: 551\u2013572.","journal-title":"Proc Am Philos Soc"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.2308\/jeta-51247"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2013.09.007"},{"key":"e_1_3_2_27_2","volume-title":"Applications for forensic accounting, auditing and fraud detection","author":"Nigrini M","year":"2012","unstructured":"Nigrini M. Applications for forensic accounting, auditing and fraud detection. Hoboken, NJ: John Wiley and Sons, 2012."},{"key":"e_1_3_2_28_2","doi-asserted-by":"crossref","unstructured":"Moustafa N Slay J. UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 IEEE military communications and information systems conference (MilCIS) Canberra ACT Australia 2015 pp. 1\u20136. DOI: https:\/\/doi.org\/10.1109\/MilCIS.2015.7348942.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"e_1_3_2_29_2","doi-asserted-by":"crossref","unstructured":"Moustafa N Slay J. The significant features of the UNSW-NB15 and the KDD99 data sets for network intrusion detection systems. In: 2015 4th international workshop on building analysis datasets and gathering experience returns for security (BADGERS) Kyoto Japan 2015 pp. 25\u201331. DOI: https:\/\/doi.org\/10.1109\/BADGERS.2015.014","DOI":"10.1109\/BADGERS.2015.014"},{"key":"e_1_3_2_30_2","first-page":"18","article-title":"The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set","volume":"25","author":"Moustafa N","year":"2016","unstructured":"Moustafa N, Slay J. The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Inf Secur J 2016; 25: 18\u201331.","journal-title":"Inf Secur J"},{"key":"e_1_3_2_31_2","volume-title":"Networked graphics","author":"Steed A","year":"2010","unstructured":"Steed A, Oliveira MF. Networked graphics.\u00a0Burlington, Massachusetts: Morgan Kaufmann, 2010."},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","unstructured":"Sangodoyin A Sigwele T Pillai P et al. DoS attack impact assessment on software defined networks. In: Proceedings of the 9th International Conference on Wireless and Satellite Systems WiSATS 2017 \u2013 Oxford United Kingdom Springer 2018. pp. 11\u201322. DOI: https:\/\/doi.org\/10.1007\/978-3-319-76571-62.","DOI":"10.1007\/978-3-319-76571-6_2"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.3390\/stats4020027"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251360421","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0926227X251360421","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251360421","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:55Z","timestamp":1777495555000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0926227X251360421"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,23]]},"references-count":32,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2025,11]]}},"alternative-id":["10.1177\/0926227X251360421"],"URL":"https:\/\/doi.org\/10.1177\/0926227x251360421","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,23]]}}}