{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T01:40:56Z","timestamp":1755826856035,"version":"3.44.0"},"reference-count":30,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T00:00:00Z","timestamp":1755734400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T00:00:00Z","timestamp":1755734400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"DOI":"10.1186\/s13635-025-00210-w","type":"journal-article","created":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T08:22:04Z","timestamp":1755764524000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Semi-supervised method for anomaly detection in HTTP traffic"],"prefix":"10.1186","volume":"2025","author":[{"given":"Malki\u00a0Ishara","family":"Wasundara","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junwei","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yanchao","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dongdong","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianwen","family":"Xiang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,21]]},"reference":[{"key":"210_CR1","unstructured":"P. Barford, J. Kline, D. Plonka, A. Ron, in Proceedings of the 2nd ACM SIGCOMM Workshop on Internet Measurement. Anomaly detection in backbone network traffic (Association for Computing Machinery (ACM),\u00a0New York, 2002), pp. 191\u2013202"},{"key":"210_CR2","unstructured":"J. Zhang, M. Zulkernine, in Proceedings of the 3rd International Conference on Communication Systems and Networks (COMSNETS 2011). Anomaly detection in network traffic using time domain modeling (IEEE,\u00a0Piscataway, 2009), pp. 1\u201310"},{"key":"210_CR3","unstructured":"M. Roesch, in Proceedings of the 13th USENIX conference on System administration. Snort: Lightweight intrusion detection for networks, vol 99 (1999), pp. 229\u2013238"},{"key":"210_CR4","doi-asserted-by":"crossref","unstructured":"R. Sommer, V. Paxson, in 2010 IEEE Symposium on Security and Privacy. Outside the closed world: On using machine learning for network intrusion detection (IEEE, 2010), pp. 305\u2013316","DOI":"10.1109\/SP.2010.25"},{"key":"210_CR5","doi-asserted-by":"publisher","unstructured":"S. Das, M. Ashrafuzzaman, F.T. Sheldon, S. Shiva, in 2020 IEEE Symposium Series on Computational Intelligence (SSCI). Network intrusion detection using natural language processing and ensemble machine learning (2020), pp. 829\u2013835. https:\/\/doi.org\/10.1109\/SSCI47803.2020.9308268","DOI":"10.1109\/SSCI47803.2020.9308268"},{"key":"210_CR6","doi-asserted-by":"publisher","first-page":"141787","DOI":"10.1109\/ACCESS.2020.3013849","volume":"8","author":"J Li","year":"2020","unstructured":"J. Li, H. Zhang, Z. Wei, The weighted word2vec paragraph vectors for anomaly detection over http traffic. IEEE Access 8, 141787\u2013141798 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.3013849","journal-title":"IEEE Access"},{"key":"210_CR7","doi-asserted-by":"publisher","unstructured":"A.M. Vartouni, S.S. Kashi, M. Teshnehlab, in 2018 6th Iranian Joint Congress on Fuzzy and Intelligent Systems (CFIS). An anomaly detection method to detect web attacks using stacked auto-encoder (2018), pp. 131\u2013134. https:\/\/doi.org\/10.1109\/CFIS.2018.8336654","DOI":"10.1109\/CFIS.2018.8336654"},{"issue":"4","key":"210_CR8","doi-asserted-by":"publisher","first-page":"31","DOI":"10.22667\/JOWUA.2020.12.31.031","volume":"11","author":"C Johnson","year":"2020","unstructured":"C. Johnson, B. Khadka, R.B. Basnet, T. Doleck, Towards detecting and classifying malicious urls using deep learning. J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl. 11(4), 31\u201348 (2020). https:\/\/doi.org\/10.22667\/JOWUA.2020.12.31.031","journal-title":"J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl."},{"issue":"C","key":"210_CR9","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1016\/j.neucom.2021.01.146","volume":"485","author":"J Liu","year":"2022","unstructured":"J. Liu, X. Song, Y. Zhou, X. Peng, Y. Zhang, P. Liu, D. Wu, C. Zhu, Deep anomaly detection in packet payload. Neurocomput. 485(C), 205\u2013218 (2022). https:\/\/doi.org\/10.1016\/j.neucom.2021.01.146","journal-title":"Neurocomput."},{"issue":"8","key":"210_CR10","doi-asserted-by":"publisher","first-page":"5810","DOI":"10.1109\/TII.2020.3038761","volume":"17","author":"C Luo","year":"2021","unstructured":"C. Luo, Z. Tan, G. Min, J. Gan, W. Shi, Z. Tian, A novel web attack detection system for internet of things via ensemble classification. IEEE Trans. Ind. Inform. 17(8), 5810\u20135818 (2021). https:\/\/doi.org\/10.1109\/TII.2020.3038761","journal-title":"IEEE Trans. Ind. Inform."},{"issue":"4","key":"210_CR11","doi-asserted-by":"publisher","first-page":"4197","DOI":"10.1109\/TNSM.2021.3120804","volume":"18","author":"S Dong","year":"2021","unstructured":"S. Dong, Y. Xia, T. Peng, Network abnormal traffic detection model based on semi-supervised deep reinforcement learning. IEEE Trans. Netw. Serv. Manag. 18(4), 4197\u20134212 (2021). https:\/\/doi.org\/10.1109\/TNSM.2021.3120804","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"210_CR12","doi-asserted-by":"publisher","unstructured":"L. Zhang, W. Chen, M. Zhao, Network abnormal traffic detection framework based on deep reinforcement learning. IEEE Wirel. Commun. (2024). https:\/\/doi.org\/10.1109\/MWC.2024.1234567","DOI":"10.1109\/MWC.2024.1234567"},{"key":"210_CR13","doi-asserted-by":"publisher","unstructured":"S. Dong, L. Shu, Q. Xia, J. Kamruzzaman, Y. Xia, T. Peng, Device identification method for internet of things based on spatial-temporal feature residuals. IEEE Trans. Serv. Comput. (2024). https:\/\/doi.org\/10.1109\/TSC.2024.3440013","DOI":"10.1109\/TSC.2024.3440013"},{"key":"210_CR14","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1007\/s12243-021-00876-6","volume":"77","author":"S Dong","year":"2022","unstructured":"S. Dong, Y. Xia, T. Peng, Traffic identification model based on generative adversarial deep convolutional network. Ann. Telecommun. 77, 573\u2013587 (2022). https:\/\/doi.org\/10.1007\/s12243-021-00876-6","journal-title":"Ann. Telecommun."},{"key":"210_CR15","doi-asserted-by":"publisher","first-page":"473","DOI":"10.1007\/s00521-017-3081-x","volume":"31","author":"S Dong","year":"2019","unstructured":"S. Dong, R. Li, Traffic identification method based on multiple probabilistic neural network model. Neural Comput. Appl. 31, 473\u2013487 (2019). https:\/\/doi.org\/10.1007\/s00521-017-3081-x","journal-title":"Neural Comput. Appl."},{"key":"210_CR16","doi-asserted-by":"publisher","first-page":"8579","DOI":"10.1109\/TASE.2024.3486688","volume":"22","author":"M Yao","year":"2025","unstructured":"M. Yao, D. Tao, P. Qi, R. Gao, Rethinking discrepancy analysis: Anomaly detection via meta-learning powered dual-source representation differentiation. IEEE Trans. Autom. Sci. Eng. 22, 8579\u20138592 (2025). https:\/\/doi.org\/10.1109\/TASE.2024.3486688","journal-title":"IEEE Trans. Autom. Sci. Eng."},{"issue":"1","key":"210_CR17","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/TII.2024.3421600","volume":"21","author":"M Yao","year":"2025","unstructured":"M. Yao, D. Tao, R. Gao, P. Qi, Anomaly detection for mec enabled hierarchical industrial iot with transformer enhanced variational auto encoder. IEEE Trans. Ind. Inform. 21(1), 40\u201348 (2025). https:\/\/doi.org\/10.1109\/TII.2024.3421600","journal-title":"IEEE Trans. Ind. Inform."},{"key":"210_CR18","doi-asserted-by":"publisher","unstructured":"Y. Yang, C. Zhang, T. Zhou, Q. Wen, L. Sun, in Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. Dcdetector: Dual attention contrastive representation learning for time series anomaly detection (Association for Computing Machinery, 2023), pp. 3033\u20133045. https:\/\/doi.org\/10.1145\/3580305.3599295","DOI":"10.1145\/3580305.3599295"},{"key":"210_CR19","unstructured":"C. Torrano Gim\u00e9nez, A. P\u00e9rez Villegas, G. \u00c1lvarez Mara\u00f1\u00f3n, Http data set csic 2010. Technical report, Information Security Institute of CSIC (Spanish Research National Council) (2010)"},{"key":"210_CR20","doi-asserted-by":"publisher","unstructured":"M. Mamun, M. Rathore, A. Habibi Lashkari, N. Stakhanova, A. Ghorbani, Detecting malicious urls using lexical analysis (2016), pp. 467\u2013482. https:\/\/doi.org\/10.1007\/978-3-319-46298-1_30","DOI":"10.1007\/978-3-319-46298-1_30"},{"key":"210_CR21","doi-asserted-by":"publisher","unstructured":"M. Gniewkowski, H. Maciejewski, T. Surmacz, W. Walentynowicz, in Proceedings of the 38th ACM\/SIGAPP Symposium on Applied Computing. Sec2vec: Anomaly detection in http traffic and malicious urls, SAC \u201923 (Association for Computing Machinery, New York, 2023), pp. 1154\u20131162. https:\/\/doi.org\/10.1145\/3555776.3577663","DOI":"10.1145\/3555776.3577663"},{"key":"210_CR22","doi-asserted-by":"crossref","unstructured":"N. Moustafa, J. Slay, in 2015 military communications and information systems conference (MilCIS). Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set) (IEEE,\u00a0Piscataway, 2015), pp. 1\u20136","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"210_CR23","unstructured":"C. Zhou, X. He, Y. Huang, in 2019 IEEE International Conference on Big Data (Big Data). Cnn-based autoencoder for intrusion detection system in internet of things (IEEE,\u00a0Piscataway,  2019), pp. 2566\u20132573"},{"key":"210_CR24","unstructured":"P. Malhotra, A. Ramakrishnan, G.\u00a0Anand, L. Vig, P. Agarwal,\u00a0 G. Shroff, LSTM-based Encoder-Decoder for Multi-sensor Anomaly Detection.\u00a0ArXiv.\u00a0abs\/1607.00148 (2016).\u00a0https:\/\/api.semanticscholar.org\/CorpusID:9286983"},{"key":"210_CR25","unstructured":"V. Sanh, L. Debut, J. Chaumond, T. Wolf, Distilbert, a distilled version of bert: smaller, faster, cheaper and lighter.\u00a0(2019)\u00a0arXiv\u00a0preprint\u00a0arXiv:1910.01108"},{"key":"210_CR26","doi-asserted-by":"crossref","unstructured":"F.T. Liu, K.M. Ting, Z.H. Zhou, in 2008 Eighth IEEE International Conference on Data Mining. Isolation forest (IEEE,\u00a0Piscataway,  2008), pp. 413\u2013422","DOI":"10.1109\/ICDM.2008.17"},{"key":"210_CR27","doi-asserted-by":"crossref","unstructured":"I. Jolliffe, Principal component analysis (Springer,\u00a0Heidelberg, 2011)","DOI":"10.1007\/978-3-642-04898-2_455"},{"key":"210_CR28","doi-asserted-by":"crossref","unstructured":"M. Sakurada, T. Yairi, in Proceedings of the MLSDA. Anomaly detection using autoencoders with nonlinear dimensionality reduction (Association for Computing Machinery (ACM),\u00a0New York, 2014), pp. 4\u201311","DOI":"10.1145\/2689746.2689747"},{"issue":"11","key":"210_CR29","first-page":"2579","volume":"9","author":"L Van der Maaten","year":"2008","unstructured":"L. Van der Maaten, G. Hinton, Visualizing data using t-sne. J. Mach. Learn. Res. 9(11), 2579\u20132605 (2008)","journal-title":"J. Mach. Learn. Res."},{"key":"210_CR30","unstructured":"Y. Shi, B. Chen, Z. Liu et al.,\u00a0Bert4http: A bert-based semi-supervised method for http traffic anomaly detection. Comput Secur, vol.\u00a0133 (Elsevier, 2023), p.\u00a0103387"}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00210-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-025-00210-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00210-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T08:22:13Z","timestamp":1755764533000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-025-00210-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,21]]},"references-count":30,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["210"],"URL":"https:\/\/doi.org\/10.1186\/s13635-025-00210-w","relation":{},"ISSN":["2510-523X"],"issn-type":[{"type":"electronic","value":"2510-523X"}],"subject":[],"published":{"date-parts":[[2025,8,21]]},"assertion":[{"value":"13 December 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 July 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 August 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"25"}}