{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T04:25:05Z","timestamp":1777695905011,"version":"3.51.4"},"reference-count":25,"publisher":"SAGE Publications","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IDA"],"published-print":{"date-parts":[[2020,7,15]]},"DOI":"10.3233\/ida-194656","type":"journal-article","created":{"date-parts":[[2020,7,21]],"date-time":"2020-07-21T13:17:00Z","timestamp":1595337420000},"page":"743-758","source":"Crossref","is-referenced-by-count":10,"title":["An outlier ensemble for unsupervised anomaly detection in honeypots data"],"prefix":"10.1177","volume":"24","author":[{"given":"Lynda","family":"Boukela","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gongxuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Samia","family":"Bouzefrane","sequence":"additional","affiliation":[{"name":"CEDRIC lab, Conservatoire National des Arts et M\u00e9tiers, Paris, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junlong","family":"Zhou","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","reference":[{"key":"10.3233\/IDA-194656_ref1","doi-asserted-by":"crossref","unstructured":"A. Gr\u00e9gio, R. Santos and A. Montes, Evaluation of data mining techniques for suspicious network activity classification using honeypots data, in: Defense and Security Symposium International Society for Optics and Photonics, 2007.","DOI":"10.1117\/12.719023"},{"key":"10.3233\/IDA-194656_ref2","doi-asserted-by":"crossref","unstructured":"A. Lazarevic, L. Ertoz, V. Kumar, A. Ozgur and J. Srivastava, A comparative study of anomaly detection schemes in network intrusion detection, in: Proc. of the 2003 SIAM Int. Conf. on Data Mining, 2003.","DOI":"10.1137\/1.9781611972733.3"},{"key":"10.3233\/IDA-194656_ref3","doi-asserted-by":"crossref","unstructured":"A. Lazarevic and V. Kumar, Feature bagging for outlier detection, in: KDD \u201905 Proc. of the Eleventh ACM SIGKDD Int. Conf. on Knowledge Discovery in Data Mining, 2005, pp. 157\u2013166.","DOI":"10.1145\/1081870.1081891"},{"issue":"1","key":"10.3233\/IDA-194656_ref4","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1145\/2594473.2594476","article-title":"Ensembles for unsupervised outlier detection: challenges and research questions a position paper","volume":"15","author":"Zimek","year":"2013","journal-title":"ACM SIGKDD Explorations Newsletter"},{"issue":"2","key":"10.3233\/IDA-194656_ref5","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1145\/2481244.2481252","article-title":"Outlier ensembles: position paper","volume":"14","author":"Aggarwal","year":"2012","journal-title":"ACM SIGKDD Explorations Newsletter"},{"key":"10.3233\/IDA-194656_ref6","doi-asserted-by":"crossref","unstructured":"C.C. Aggarwal and P.S. Yu, Outlier Detection for High Dimensional Data, in: Proc. of the ACM SIGMOD Int. Conf. on Management of Data, 2001, pp. 37\u201346.","DOI":"10.1145\/376284.375668"},{"key":"10.3233\/IDA-194656_ref7","doi-asserted-by":"crossref","unstructured":"D. Fraunholz, M. Zimmermann, A. Hafner and H.D. Schotten, Data mining in long-term honeypot data, in: IEEE International Conference on Data Mining Workshops (ICDMW), 2017.","DOI":"10.1109\/ICDMW.2017.92"},{"key":"10.3233\/IDA-194656_ref8","unstructured":"F. Pouget and M. Dacier, Honeypot-based forensics, in: AusCERT Asia Pacific Information Technology Security Conference, 2004."},{"key":"10.3233\/IDA-194656_ref9","doi-asserted-by":"crossref","first-page":"79","DOI":"10.13052\/jsn2445-9739.2017.005","article-title":"Detection of severe SSH attacks using honeypot servers and machine learning techniques","author":"Sadasivam","year":"2017","journal-title":"Software Networking"},{"key":"10.3233\/IDA-194656_ref10","doi-asserted-by":"crossref","unstructured":"H.G. Kayacik, A.N. Zincir-Heywood and M.I. Heywood, Selecting Features for Intrusion Detection: A Feature Relevance Analysis on KDD 99 Intrusion Detection Datasets, in: Proc. of the 3rd Annual Conference on Privacy, Security and Trust, 2005.","DOI":"10.4018\/978-1-59140-561-0.ch071"},{"key":"10.3233\/IDA-194656_ref12","doi-asserted-by":"crossref","unstructured":"J. Song, H. Takakura, Y. Okabe, M. Eto, D. Inoue and K. Nakao, Statistical analysis of honeypot data and building of kyoto 2006+ dataset for nids evaluation, in: BADGERS \u201911 Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, 2011, pp. 29\u201336.","DOI":"10.1145\/1978672.1978676"},{"key":"10.3233\/IDA-194656_ref13","doi-asserted-by":"crossref","unstructured":"M. Goldstein and S. Uchida, A comparative evaluation of unsupervised anomaly detection algorithms for multivariate data, PLoS One 11(4) (2016).","DOI":"10.1371\/journal.pone.0152173"},{"key":"10.3233\/IDA-194656_ref14","doi-asserted-by":"crossref","unstructured":"M. Hus\u00e1k and J. Ka\u0161par, Towards Predicting Cyber Attacks Using Information Exchange and Data Mining, in: 14th International Wireless Communications & Mobile Computing Conference (IWCMC), 2018, pp. 536\u2013541.","DOI":"10.1109\/IWCMC.2018.8450512"},{"key":"10.3233\/IDA-194656_ref15","doi-asserted-by":"crossref","unstructured":"M.M. Breunig, H.P. Kriegel, R.T. Ng and J. Sander, LOF: Identifying Density Based Local Outliers, in: SIGMOD \u201900 Proc. of the 2000 ACM SIGMOD Int. Conf. on Management of Data, 2000, pp. 93\u2013104.","DOI":"10.1145\/342009.335388"},{"issue":"1","key":"10.3233\/IDA-194656_ref16","doi-asserted-by":"crossref","first-page":"128","DOI":"10.1016\/j.diin.2008.05.012","article-title":"A framework for attack patterns\u2019 discovery in honeynet data","volume":"5","author":"Thonnard","year":"2008","journal-title":"Digital Investigation"},{"issue":"4","key":"10.3233\/IDA-194656_ref17","doi-asserted-by":"crossref","first-page":"570","DOI":"10.1093\/comjnl\/bxr026","article-title":"A survey of outlier detection methods in network anomaly identification","volume":"54","author":"Gogoi","year":"2011","journal-title":"The Computer Journal"},{"key":"10.3233\/IDA-194656_ref18","doi-asserted-by":"crossref","unstructured":"P. Owezarski, A Near Real-Time Algorithm for Autonomous Identification and Characterization of Honeypot Attacks, in: Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security \u2013 ASIA CCS \u201915, 2015.","DOI":"10.1145\/2714576.2714580"},{"key":"10.3233\/IDA-194656_ref19","doi-asserted-by":"crossref","unstructured":"P. Owezarski, Unsupervised classification and characterization of honeypot attacks, in: 10th Int. Conf. on Network and Service Management (CNSM) and Workshop, 2014, pp. 10\u201318.","DOI":"10.1109\/CNSM.2014.7014136"},{"key":"10.3233\/IDA-194656_ref20","doi-asserted-by":"crossref","unstructured":"S. Almotairi, A. Clark, G. Mohay and J. Zimmermann, A technique for detecting new attacks in low-interaction honeypot traffic, in: Fourth International Conference on Internet Monitoring and Protection, 2009, pp. 7\u201313.","DOI":"10.1109\/ICIMP.2009.9"},{"key":"10.3233\/IDA-194656_ref21","doi-asserted-by":"crossref","unstructured":"S. Almotairi, A. Clark, G. Mohay and J. Zimmermann, Characterization of attackers\u2019 activities in honeypot traffic using principal component analysis, in: 2008 IFIP Int. Conf. on Network and Parallel Computing, 2008, pp. 147\u2013154.","DOI":"10.1109\/NPC.2008.82"},{"key":"10.3233\/IDA-194656_ref23","doi-asserted-by":"crossref","unstructured":"S. Nanda, F. Zafari, C. DeCusatis, E. Wedaa and B. Yang, Predicting Network Attack Patterns in SDN using Machine Learning Approach, in: 2016 IEEE Conf. on Network Function Virtualization and Software Defined Networks (NFV-SDN), 2016.","DOI":"10.1109\/NFV-SDN.2016.7919493"},{"key":"10.3233\/IDA-194656_ref24","doi-asserted-by":"crossref","unstructured":"V. Chandola, A. Banerjee and V. Kumar, Anomaly detection: a survey, ACM Computing Surveys 41(3) (2009).","DOI":"10.1145\/1541880.1541882"},{"key":"10.3233\/IDA-194656_ref25","first-page":"1","article-title":"Enabling an anatomic view to investigate honeypot systems: a survey","author":"Fan","year":"2017","journal-title":"IEEE Systems Journal"},{"issue":"11","key":"10.3233\/IDA-194656_ref26","doi-asserted-by":"crossref","first-page":"1775","DOI":"10.1109\/TIFS.2013.2279800","article-title":"Characterizing honeypot-captured cyber attacks: statistical framework and case study","volume":"8","author":"Zhan","year":"2013","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"8","key":"10.3233\/IDA-194656_ref27","doi-asserted-by":"crossref","first-page":"1666","DOI":"10.1109\/TIFS.2015.2422261","article-title":"Predicting cyber attack rates with extreme values","volume":"10","author":"Zhan","year":"2015","journal-title":"IEEE Transactions on Information Forensics and Security"}],"container-title":["Intelligent Data Analysis"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/IDA-194656","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:18:45Z","timestamp":1777454325000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/IDA-194656"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,15]]},"references-count":25,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.3233\/ida-194656","relation":{},"ISSN":["1088-467X","1571-4128"],"issn-type":[{"value":"1088-467X","type":"print"},{"value":"1571-4128","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7,15]]}}}