{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:34:24Z","timestamp":1780634064308,"version":"3.54.1"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2016,12,1]],"date-time":"2016-12-01T00:00:00Z","timestamp":1480550400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2016,12,5]],"date-time":"2016-12-05T00:00:00Z","timestamp":1480896000000},"content-version":"vor","delay-in-days":4,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000183","name":"US Army Research Office","doi-asserted-by":"crossref","award":["W911NF1310143"],"award-info":[{"award-number":["W911NF1310143"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000183","name":"US Army Research Office","doi-asserted-by":"crossref","award":["W911NF1310143"],"award-info":[{"award-number":["W911NF1310143"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Hum. Cent. Comput. Inf. Sci."],"published-print":{"date-parts":[[2016,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>As network traffic grows and attacks become more prevalent and complex, we must find creative new ways to enhance intrusion detection systems (IDSes). Recently, researchers have begun to harness both machine learning and cloud computing technology to better identify threats and speed up computation times. This paper explores current research at the intersection of these two fields by examining cloud-based network intrusion detection approaches that utilize machine learning algorithms (MLAs). Specifically, we consider clustering and classification MLAs, their applicability to modern intrusion detection, and feature selection algorithms, in order to underline prominent implementations from recent research. We offer a current overview of this growing body of research, highlighting successes, challenges, and future directions for MLA-usage in cloud-based network intrusion detection approaches.<\/jats:p>","DOI":"10.1186\/s13673-016-0076-z","type":"journal-article","created":{"date-parts":[[2016,9,6]],"date-time":"2016-09-06T15:20:42Z","timestamp":1473175242000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":78,"title":["A survey of cloud-based network intrusion detection analysis"],"prefix":"10.1186","volume":"6","author":[{"given":"Nathan","family":"Keegan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Soo-Yeon","family":"Ji","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aastha","family":"Chaudhary","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Claude","family":"Concolato","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Byunggu","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5271-293X","authenticated-orcid":false,"given":"Dong Hyun","family":"Jeong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2016,12,5]]},"reference":[{"issue":"4","key":"76_CR1","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/MC.2002.1012428","volume":"35","author":"RA Kemmerer","year":"2002","unstructured":"Kemmerer RA, Vigna G (2002) Intrusion detection: a brief history and overview. Computer 35(4):27\u201330. doi:10.1109\/mc.2002.1012428","journal-title":"Computer"},{"issue":"2","key":"76_CR2","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1109\/TNSM.2009.090604","volume":"6","author":"A Kind","year":"2009","unstructured":"Kind A, Stoecklin MP, Dimitropoulos X (2009) Histogram-based traffic anomaly detection. IEEE Trans Netw Serv Manag 6(2):110\u2013121. doi:10.1109\/TNSM.2009.090604","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"76_CR3","doi-asserted-by":"publisher","unstructured":"Fontugne R, Mazel J, Fukuda K (2014) Hashdoop: a mapreduce framework for network anomaly detection. In: 2014 IEEE conference on computer communications workshops (INFOCOM WKSHPS). pp 494\u2013499. doi:10.1109\/INFCOMW.2014.6849281","DOI":"10.1109\/INFCOMW.2014.6849281"},{"key":"76_CR4","doi-asserted-by":"publisher","unstructured":"Francois J, Wang S, Bronzi W, State R, Engel T (2011) Botcloud: detecting botnets using mapreduce. In: 2011 IEEE international workshop on Information Forensics and Security (WIFS). pp 1\u20136. doi:10.1109\/WIFS.2011.6123125","DOI":"10.1109\/WIFS.2011.6123125"},{"key":"76_CR5","doi-asserted-by":"publisher","unstructured":"Kumar M, Hanumanthappa M (2013) Scalable intrusion detection systems log analysis using cloud computing infrastructure. In: 2013 IEEE international conference on computational intelligence and computing research (ICCIC). pp 1\u20134. doi:10.1109\/ICCIC.2013.6724158","DOI":"10.1109\/ICCIC.2013.6724158"},{"key":"76_CR6","doi-asserted-by":"publisher","unstructured":"Lee Y, Lee Y (2011) Detecting ddos attacks with hadoop. In: Proceedings of The ACM CoNEXT Student Workshop, CoNEXT \u201911 Student. ACM, New York, pp 7\u2013172. doi:10.1145\/2079327.2079334","DOI":"10.1145\/2079327.2079334"},{"issue":"3","key":"76_CR7","doi-asserted-by":"publisher","first-page":"150","DOI":"10.4236\/jis.2013.43018","volume":"4","author":"S Tripathi","year":"2013","unstructured":"Tripathi S, Gupta B, Veluru S (2013) Hadoop based defense solution to handle distributed denial of service (ddos) attacks. J Inform Secur 4(3):150\u2013164. doi:10.4236\/jis.2013.43018","journal-title":"J Inform Secur"},{"key":"76_CR8","series-title":"Lecture notes in computer science","doi-asserted-by":"publisher","first-page":"674","DOI":"10.1007\/978-3-642-10665-1_71","volume-title":"Cloud computing","author":"W Zhao","year":"2009","unstructured":"Zhao W, Ma H, He Q (2009) Parallel k-means clustering based on mapreduce. In: Jaatun M, Zhao G, Rong C (eds) Cloud Computing, Lecture Notes in Computer Science. Springer, Berlin, pp 674\u2013679. doi:10.1007\/978-3-642-10665-1_71"},{"key":"76_CR9","unstructured":"Apache mahout: scalable machine learning and data mining. https:\/\/mahout.apache.org\/. Accessed 03 Sept 2014"},{"key":"76_CR10","doi-asserted-by":"publisher","unstructured":"Ghoting A, Krishnamurthy R, Pednault E, Reinwald B, Sindhwani V, Tatikonda S, Tian Y, Vaithyanathan S (2011) Systemml: declarative machine learning on mapreduce. In: Proceedings of the 2011 IEEE 27th international conference on data engineering, ICDE \u201911. IEEE Computer Society, Washington, DC, pp 231\u2013242. doi:10.1109\/ICDE.2011.5767930","DOI":"10.1109\/ICDE.2011.5767930"},{"key":"76_CR11","doi-asserted-by":"publisher","unstructured":"Ghoting A, Kambadur P, Pednault E, Kannan R (2011) Nimble: a toolkit for the implementation of parallel data mining and machine learning algorithms on mapreduce. In: Proceedings of the 17th ACM SIGKDD international conference on knowledge discovery and data mining. KDD \u201911. ACM, New York, pp 334\u2013342. doi:10.1145\/2020408.2020464 http:\/\/doi.acm.org\/10.1145\/2020408.2020464","DOI":"10.1145\/2020408.2020464"},{"key":"76_CR12","unstructured":"Kraska T, Talwalkar A, Duchi JC, Griffith R, Franklin MJ, Jordan MI (2013) Mlbase: a distributed machine-learning system. In: 6th biennial conference on innovative data systems reserch (CIDR). http:\/\/cidrdb.org\/cidr2013\/program.html. http:\/\/cidrdb.org\/cidr2013\/Papers\/CIDR13_Paper118.pdf"},{"issue":"8","key":"76_CR13","doi-asserted-by":"publisher","first-page":"716","DOI":"10.14778\/2212351.2212354","volume":"5","author":"Y Low","year":"2012","unstructured":"Low Y, Bickson D, Gonzalez J, Guestrin C, Kyrola A, Hellerstein JM (2012) Distributed graphlab: a framework for machine learning and data mining in the cloud. Proc VLDB Endow 5(8):716\u2013727. doi:10.14778\/2212351.2212354","journal-title":"Proc VLDB Endow"},{"issue":"3","key":"76_CR14","first-page":"63","volume":"37","author":"AG Crotty Andrew","year":"2014","unstructured":"Crotty Andrew AG, Kraska T (2014) Distributed machine learning on small clusters. IEEE Data Eng Bull 37(3):63\u201376","journal-title":"IEEE Data Eng Bull"},{"issue":"4","key":"76_CR15","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1145\/2627534.2627557","volume":"41","author":"S Suthaharan","year":"2014","unstructured":"Suthaharan S (2014) Big data classification: problems and challenges in network intrusion prediction with machine learning. SIGMETRICS Perform Eval Rev 41(4):70\u201373. doi:10.1145\/2627534.2627557","journal-title":"SIGMETRICS Perform Eval Rev"},{"issue":"11","key":"76_CR16","first-page":"3161","volume":"9","author":"B Hu","year":"2012","unstructured":"Hu B, Shen Y (2012) Machine learning based network traffic classification: a survey. J Inform Comput Sci 9(11):3161\u20133170","journal-title":"J Inform Comput Sci"},{"key":"76_CR17","doi-asserted-by":"publisher","unstructured":"Yingqiu L, Wei L, Yunchun L (2007) Network traffic classification using k-means clustering. In: Second international multi-symposiums on computer and computational sciences, 2007. IMSCCS 2007, pp 360\u2013365. doi:10.1109\/IMSCCS.2007.52","DOI":"10.1109\/IMSCCS.2007.52"},{"key":"76_CR18","doi-asserted-by":"publisher","unstructured":"Sommer R, Paxson V (2010) Outside the closed world: on using machine learning for network intrusion detection. In: 2010 IEEE symposium on security and privacy (SP), pp 305\u2013316. IEEE, New York. doi:10.1109\/sp.2010.25","DOI":"10.1109\/sp.2010.25"},{"key":"76_CR19","doi-asserted-by":"publisher","unstructured":"Esteves RM, Pais R, Rong C (2011) K-means clustering in the cloud\u2014a mahout test. In: Proceedings of the 2011 IEEE workshops of international conference on advanced information networking and applications, WAINA \u201911. IEEE Computer Society, Washington, DC, pp 514\u2013519. doi:10.1109\/WAINA.2011.136","DOI":"10.1109\/WAINA.2011.136"},{"issue":"1","key":"76_CR20","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/TST.2013.6449406","volume":"18","author":"Z Chen","year":"2013","unstructured":"Chen Z, Han F, Cao J, Jiang X, Chen S (2013) Cloud computing-based forensic analysis for collaborative network security management system. Tsinghua Sci Technol 18(1):40\u201350. doi:10.1109\/TST.2013.6449406","journal-title":"Tsinghua Sci Technol"},{"key":"76_CR21","doi-asserted-by":"publisher","unstructured":"Lee Y, Kang W, Son H (2010) An internet traffic analysis method with mapreduce. In: 2010 IEEE\/IFIP network operations and management symposium workshops (NOMS Wksps). pp 357\u2013361. doi:10.1109\/NOMSW.2010.5486551","DOI":"10.1109\/NOMSW.2010.5486551"},{"key":"76_CR22","doi-asserted-by":"publisher","unstructured":"Marnerides A, Watson MR, Shirazi N, Mauthe A, Hutchison D (2013) Malware analysis in cloud computing: network and system characteristics. In: 2013 IEEE globecom workshops (GC Wkshps), pp 482\u2013487. doi:10.1109\/GLOCOMW.2013.6825034","DOI":"10.1109\/GLOCOMW.2013.6825034"},{"key":"76_CR23","doi-asserted-by":"crossref","unstructured":"Scarfone K, Scarfone K, Cybersecurity S, Mell P, Blank RM (2007) Secretary A: guide to intrusion detection and prevention systems (IDPS)","DOI":"10.6028\/NIST.SP.800-94"},{"issue":"8","key":"76_CR24","doi-asserted-by":"publisher","first-page":"805","DOI":"10.1016\/S1389-1286(98)00017-6","volume":"31","author":"H Debar","year":"1999","unstructured":"Debar H, Dacier M, Wespi A (1999) Towards a taxonomy of intrusion-detection systems. Comput Netw 31(8):805\u2013822","journal-title":"Comput Netw"},{"issue":"12","key":"76_CR25","doi-asserted-by":"publisher","first-page":"3448","DOI":"10.1016\/j.comnet.2007.02.001","volume":"51","author":"A Patcha","year":"2007","unstructured":"Patcha A, Park JM (2007) An overview of anomaly detection techniques: existing solutions and latest technological trends. Comput Netw 51(12):3448\u20133470. doi:10.1016\/j.comnet.2007.02.001","journal-title":"Comput Netw"},{"key":"76_CR26","unstructured":"Halme LR, Bauer RK (1995) Aint misbehaving: a taxonomy of anti-intrusion techniques. In: Proceedings of the 18th national information systems security conference"},{"key":"76_CR27","unstructured":"Cannady96 J, Harrel J (1996) A comparative analysis of current intrusion detection technologies. In: Technology in information security conference (TISC), pp 212\u2013218"},{"issue":"8","key":"76_CR28","doi-asserted-by":"publisher","first-page":"651","DOI":"10.1016\/j.patrec.2009.09.011","volume":"31","author":"AK Jain","year":"2010","unstructured":"Jain AK (2010) Data clustering: 50 years beyond k-means. Pattern Recognit Lett 31(8):651\u2013666","journal-title":"Pattern Recognit Lett"},{"issue":"4","key":"76_CR29","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1109\/SURV.2008.080406","volume":"10","author":"TTT Nguyen","year":"2008","unstructured":"Nguyen TTT, Armitage G (2008) A survey of techniques for internet traffic classification using machine learning. Commun Surveys Tutor 10(4):56\u201376. doi:10.1109\/SURV.2008.080406","journal-title":"Commun Surveys Tutor"},{"key":"76_CR30","doi-asserted-by":"crossref","unstructured":"McGregor A, Hall M, Lorier P, Brunskill J (2004) Flow clustering using machine learning techniques. In: Passive and active network measurement. Springer, Berlin, pp 205\u2013214","DOI":"10.1007\/978-3-540-24668-8_21"},{"issue":"2","key":"76_CR31","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1145\/1129582.1129589","volume":"36","author":"L Bernaille","year":"2006","unstructured":"Bernaille L, Teixeira R, Akodkenou I, Soule A, Salamatian K (2006) Traffic classification on the fly. ACM SIGCOMM Comput Commun Rev 36(2):23\u201326","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"issue":"2","key":"76_CR32","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1109\/65.912717","volume":"15","author":"P Gupta","year":"2001","unstructured":"Gupta P, McKeown N (2001) Algorithms for packet classification. IEEE Netw 15(2):24\u201332","journal-title":"IEEE Netw"},{"key":"76_CR33","doi-asserted-by":"publisher","unstructured":"Qi Y, Xu L, Yang B, Xue Y, Li J (2009) Packet classification algorithms: from theory to practice. In: INFOCOM 2009. IEEE, pp 648\u2013656. doi:10.1109\/INFCOM.2009.5061972","DOI":"10.1109\/INFCOM.2009.5061972"},{"key":"76_CR34","doi-asserted-by":"publisher","unstructured":"Erman J, Mahanti A, Arlitt M (2006) Internet traffic identification using machine learning. In: Global telecommunications conference, 2006, GLOBECOM \u201906. IEEE, pp 1\u20136. doi:10.1109\/GLOCOM.2006.443","DOI":"10.1109\/GLOCOM.2006.443"},{"key":"76_CR35","doi-asserted-by":"publisher","unstructured":"Li K, Gibson C, Ho D, Zhou Q, Kim J, Buhisi O, Brown DE, Gerber M (2013) Assessment of machine learning algorithms in cloud computing frameworks. In: 2013 IEEE systems and information engineering design symposium (SIEDS), pp 98\u2013103. doi:10.1109\/SIEDS.2013.6549501","DOI":"10.1109\/SIEDS.2013.6549501"},{"key":"76_CR36","unstructured":"Singh K, Agrawal S (2011) Performance evaluation of five machine learning algorithms and three feature selection algorithms for ip traffic classification. IJCA Special Issue on Evolution in Networks and Computer Communications (1):25\u201332. http:\/\/www.ijcaonline.org\/specialissues\/encc\/number1\/3716-encc005"},{"key":"76_CR37","doi-asserted-by":"publisher","unstructured":"Stevanovic M, Pedersen JM (2014) An efficient flow-based botnet detection using supervised machine learning. In: 2014 international conference on computing, networking and communications (ICNC). pp 797\u2013801. doi:10.1109\/ICCNC.2014.6785439","DOI":"10.1109\/ICCNC.2014.6785439"},{"key":"76_CR38","doi-asserted-by":"publisher","unstructured":"Xia T, Qu G, Hariri S, Yousif M () An efficient network intrusion detection method based on information theory and genetic algorithm. In: 24th IEEE international performance, computing, and communications conference, 2005. IPCCC 2005, pp 11\u201317. doi:10.1109\/PCCC.2005.1460505","DOI":"10.1109\/PCCC.2005.1460505"},{"issue":"8","key":"76_CR39","doi-asserted-by":"publisher","first-page":"662","DOI":"10.1016\/j.cose.2005.05.003","volume":"24","author":"Y Wang","year":"2005","unstructured":"Wang Y (2005) A multinomial logistic regression modeling approach for anomaly intrusion detection. Comput Secur 24(8):662\u2013674. doi:10.1016\/j.cose.2005.05.003","journal-title":"Comput Secur"},{"key":"76_CR40","unstructured":"Cannady J (1998) Artificial neural networks for misuse detection. In: National information systems security conference, pp 443\u2013456"},{"key":"76_CR41","doi-asserted-by":"publisher","unstructured":"Amor NB, Benferhat S, Elouedi Z (2004) Naive bayes vs decision trees in intrusion detection systems. In: Proceedings of the 2004 ACM symposium on applied computing, SAC \u201904. ACM, New York, pp 420\u2013424. doi:10.1145\/967900.967989","DOI":"10.1145\/967900.967989"},{"issue":"5","key":"76_CR42","doi-asserted-by":"publisher","first-page":"841","DOI":"10.1080\/18756891.2015.1084705","volume":"8","author":"M Albayati","year":"2015","unstructured":"Albayati M, Issac B (2015) Analysis of intelligent classifiers and enhancing the detection accuracy for intrusion detection system. Int J Comput Intel Syst 8(5):841\u2013853. doi:10.1080\/18756891.2015.1084705","journal-title":"Int J Comput Intel Syst"},{"issue":"4","key":"76_CR43","doi-asserted-by":"publisher","first-page":"507","DOI":"10.1007\/s00778-006-0002-5","volume":"16","author":"L Khan","year":"2007","unstructured":"Khan L, Awad M, Thuraisingham B (2007) A new intrusion detection system using support vector machines and hierarchical clustering. VLDB J 16(4):507\u2013521. doi:10.1007\/s00778-006-0002-5","journal-title":"VLDB J"},{"issue":"3","key":"76_CR44","first-page":"40","volume":"3","author":"SA Mulay","year":"2010","unstructured":"Mulay SA, Devale PR, Garje GV (2010) Intrusion detection system using support vector machine and decision tree. Int J Comput Appl 3(3):40\u201343","journal-title":"Int J Comput Appl"},{"key":"76_CR45","doi-asserted-by":"crossref","unstructured":"Yao J, Zhao S, Fan L (2006) An enhanced support vector machine model for intrusion detection. Proceedings of the first international conference on rough sets and knowledge technology., RSKT\u201906. Springer, Berlin, pp 538\u2013543","DOI":"10.1007\/11795131_78"},{"key":"76_CR46","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1016\/j.jnca.2015.12.004","volume":"62","author":"S-Y Ji","year":"2016","unstructured":"Ji S-Y, Jeong B-K, Choi S, Jeong DH (2016) A multi-level intrusion detection method for abnormal network behaviors. J Netw Comput Appl 62:9\u201317. doi:10.1016\/j.jnca.2015.12.004","journal-title":"J Netw Comput Appl"},{"key":"76_CR47","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1007\/978-3-642-25462-8_3","volume-title":"Proceedings, part III, informatics engineering and information science: international conference, ICIEIS 2011, Kuala Lumpur, Malaysia, November 14-16, 2011","author":"N Kausar","year":"2011","unstructured":"Kausar N, Belhaouari\u00a0Samir B, Abdullah A, Ahmad I, Hussain M (2011) A review of classification approaches using support vector machine in intrusion detection. In: Abd\u00a0Manaf A, Sahibuddin S, Ahmad R, Mohd\u00a0Daud S, El-Qawasmeh E (eds) Proceedings, part III, informatics engineering and information science: international conference, ICIEIS 2011, Kuala Lumpur, Malaysia, November 14-16, 2011. Springer, Berlin, pp 24\u201334. doi:10.1007\/978-3-642-25462-8"},{"issue":"3","key":"76_CR48","first-page":"233","volume":"5","author":"PG Majeed","year":"2014","unstructured":"Majeed PG, Kumar S (2014) Genetic algorithms in intrusion detection systems: a survey. Int J Innov Appl Stud 5(3):233\u2013240","journal-title":"Int J Innov Appl Stud"},{"issue":"3","key":"76_CR49","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/s11633-014-0870-x","volume":"12","author":"SN Pawar","year":"2015","unstructured":"Pawar SN, Bichkar RS (2015) Genetic algorithm with variable length chromosomes for network intrusion detection. Int J Autom Comput 12(3):337\u2013342. doi:10.1007\/s11633-014-0870-x","journal-title":"Int J Autom Comput"},{"issue":"3","key":"76_CR50","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1109\/SURV.2011.032211.00087","volume":"13","author":"S Sakr","year":"2011","unstructured":"Sakr S, Liu A, Batista DM, Alomari M (2011) A survey of large scale data management approaches in cloud environments. IEEE Commun Surv Tutor 13(3):311\u2013336","journal-title":"IEEE Commun Surv Tutor"},{"key":"76_CR51","unstructured":"Muthurajkumar S, Kulothungan K, Vijayalakshmi M, Jaisankar N, Kannan A (2013) A rough set based feature selection algorithm for effective intrusion detection in cloud model. In: Proceedings of the international conference on advances in communication, network, and computing, pp 8\u201313"},{"key":"76_CR52","volume-title":"Mahout in action","author":"S Owen","year":"2011","unstructured":"Owen S, Anil R, Dunning T, Friedman E (2011) Mahout in action. Manning Publications Co., Greenwich"},{"issue":"34","key":"76_CR53","first-page":"1","volume":"17","author":"X Meng","year":"2015","unstructured":"Meng X, Bradley JK, Yavuz B, Sparks ER, Venkataraman S, Liu D, Freeman J, Tsai DB, Amde M, Owen S, Xin D, Xin R, Franklin MJ, Zadeh R, Zaharia M, Talwalkar A (2015) Mllib: machine learning in apache spark. JMLR 17(34):1\u20137","journal-title":"JMLR"},{"key":"76_CR54","unstructured":"Boehm M, Evfimievski AV, Pansare N, Reinwald B (2016) Declarative machine learning\u2014a classification of basic properties and types. CoRR abs\/1605.05826"},{"issue":"2","key":"76_CR55","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1016\/j.jnca.2012.12.020","volume":"36","author":"B Li","year":"2013","unstructured":"Li B, Springer J, Bebis G, Hadi Gunes M (2013) A survey of network flow applications. J Netw Comput Appl 36(2):567\u2013581. doi:10.1016\/j.jnca.2012.12.020","journal-title":"J Netw Comput Appl"},{"key":"76_CR56","doi-asserted-by":"publisher","unstructured":"Stein G, Chen B, Wu AS, Hua KA (2005) Decision tree classifier for network intrusion detection with GA-based feature selection. In: ACM-SE 43: Proceedings of the 43rd annual southeast regional conference. ACM, New York, pp 136\u2013141. doi:10.1145\/1167253.1167288","DOI":"10.1145\/1167253.1167288"},{"issue":"13","key":"76_CR57","doi-asserted-by":"publisher","first-page":"5972","DOI":"10.1016\/j.eswa.2014.04.009","volume":"41","author":"T Chen","year":"2014","unstructured":"Chen T, Zhang X, Jin S, Kim O (2014) Efficient classification using parallel and scalable compressed model and its application on intrusion detection. Expert Syst Appl 41(13):5972\u20135983","journal-title":"Expert Syst Appl"},{"key":"76_CR58","doi-asserted-by":"publisher","unstructured":"Shu X, Smiy J, Yao DD, Lin H (2013) Massive distributed and parallel log analysis for organizational security. In: 2013 IEEE Globecom workshops (GC Wkshps), pp 194\u2013199. doi:10.1109\/GLOCOMW.2013.6824985","DOI":"10.1109\/GLOCOMW.2013.6824985"},{"issue":"3","key":"76_CR59","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MCI.2014.2326099","volume":"9","author":"Y Zhai","year":"2014","unstructured":"Zhai Y, Ong YS, Tsang IW (2014) The emerging \u201cbig dimensionality\u201d. IEEE Comput Intel Mag 9(3):14\u201326. doi:10.1109\/MCI.2014.2326099","journal-title":"IEEE Comput Intel Mag"},{"key":"76_CR60","unstructured":"Hyunjoo\u00a0Kim IK, Jonghyun K, Chung Tm (2015) Behavior-based anomaly detection on big data. In: Proceedings of 13th australian information security management conference, pp 73\u201380"},{"key":"76_CR61","unstructured":"Amy Xuyang\u00a0Tan MK, Li\u00a0Liu V, Thuraisingham B (2010) A comparison of approaches for large-scale data mining. Technical Report UTDSC-24-10, University of Texas at Dallas, Department of Computer Science"},{"key":"76_CR62","doi-asserted-by":"publisher","unstructured":"Aljarah I, Ludwig SA (2013) Mapreduce intrusion detection system based on a particle swarm optimization clustering algorithm. In: 2013 IEEE congress on evolutionary computation, pp 955\u2013962. doi:10.1109\/CEC.2013.6557670","DOI":"10.1109\/CEC.2013.6557670"},{"key":"76_CR63","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1016\/j.ins.2014.03.043","volume":"285","author":"S del R\u00edo","year":"2014","unstructured":"del R\u00edo S, L\u00f3pez V, Ben\u00edtez JM, Herrera F (2014) On the use of mapreduce for imbalanced big data using random forest. Inform Sci 285:112\u2013137. doi:10.1016\/j.ins.2014.03.043","journal-title":"Inform Sci"},{"key":"76_CR64","first-page":"38","volume":"4","author":"K Vieira","year":"2009","unstructured":"Vieira K, Schulter A, Westphall C, Westphall C (2009) Intrusion detection for grid and cloud computing. IT Prof Mag 4:38\u201343","journal-title":"IT Prof Mag"},{"key":"76_CR65","doi-asserted-by":"publisher","first-page":"488","DOI":"10.1016\/j.ins.2014.03.066","volume":"278","author":"K Singh","year":"2014","unstructured":"Singh K, Guntuku SC, Thakur A, Hota C (2014) Big data analytics framework for peer-to-peer botnet detection using random forests. Inform Sci 278:488\u2013497. doi:10.1016\/j.ins.2014.03.066","journal-title":"Inform Sci"},{"key":"76_CR66","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-014-9335-3","volume":"26","author":"SY Ji","year":"2014","unstructured":"Ji SY, Choi S, Jeong D (2014) Designing an internet traffic predictive model by applying a signal processing method. J Netw Syst Manag 26:1\u201318. doi:10.1007\/s10922-014-9335-3","journal-title":"J Netw Syst Manag"},{"issue":"6","key":"76_CR67","first-page":"56","volume":"2","author":"AH Bhat","year":"2013","unstructured":"Bhat AH, Patra S, Jena D (2013) Machine learning approach for intrusion detection on cloud virtual machines. Int J Appl Innov Eng Manag (IJAIEM) 2(6):56\u201366","journal-title":"Int J Appl Innov Eng Manag (IJAIEM)"},{"key":"76_CR68","doi-asserted-by":"publisher","unstructured":"Wang H, Ding W, Xia Z (2012) A cloud-pattern based network traffic analysis platform for passive measurement. In: 2012 international conference on, cloud and service computing (CSC), pp 1\u20137. doi:10.1109\/CSC.2012.8","DOI":"10.1109\/CSC.2012.8"}],"container-title":["Human-centric Computing and Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-016-0076-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13673-016-0076-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13673-016-0076-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,30]],"date-time":"2021-07-30T07:53:03Z","timestamp":1627631583000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13673-016-0076-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,12]]},"references-count":68,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2016,12]]}},"alternative-id":["76"],"URL":"https:\/\/doi.org\/10.1186\/s13673-016-0076-z","relation":{},"ISSN":["2192-1962"],"issn-type":[{"value":"2192-1962","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,12]]},"assertion":[{"value":"14 April 2015","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 August 2016","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 December 2016","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"19"}}