{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T22:47:48Z","timestamp":1776811668133,"version":"3.51.2"},"reference-count":9,"publisher":"European Society of Computational Methods in Sciences and Engineering","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCM"],"published-print":{"date-parts":[[2023,5,30]]},"abstract":"<jats:p>This paper uses a real-time anomaly attack detection based on improved variable length sequences and data mining. The method is mainly used for host-based intrusion detection systems on Linux or Unix platforms which use shell commands. The algorithm first generates a stream of command sequences with different lengths and subsumes them into a generic sequence library, de-duplicats and sortes shell command sequences. The shell command sequences are then stratified according to their weighted frequency of occurrence to define the state. Next, the behavioural patterns of normal users are mined to output the state stream and a Markov chain is constructed. Then, the state sequences are calculated based on a primary probability distribution and a transfer probability matrix. The System will check decision values of the short sequence stream. Finally, the decision values of the behavioural sequences are analysed to determine whether the current session user is behaving abnormally. The improved algorithm introduces the concept of multi-order frequencies and proposes a new separation mechanism. The extension module is integrated into the variable length model. By comparing the performance of the old and new separation mechanisms on the SEA dataset and the self-made dataset (SD), it is found that the improved model greatly improves the performance of the model and shortens the running time.<\/jats:p>","DOI":"10.3233\/jcm-226663","type":"journal-article","created":{"date-parts":[[2023,2,14]],"date-time":"2023-02-14T10:49:46Z","timestamp":1676371786000},"page":"1179-1195","source":"Crossref","is-referenced-by-count":2,"title":["Real-time anomaly attack detection based on an improved variable length model"],"prefix":"10.66113","volume":"23","author":[{"given":"Xiaomei","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianlong","family":"Yue","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"55691","reference":[{"key":"10.3233\/JCM-226663_ref2","first-page":"304","article-title":"Analysis of two anomaly detection methods in intrusion detection system","author":"Xian","journal-title":"Network Security Technology and Application"},{"key":"10.3233\/JCM-226663_ref4","first-page":"58","article-title":"Computerintrusion: Detecting masquerades","author":"Schonlau","journal-title":"Statistical Science"},{"issue":"2","key":"10.3233\/JCM-226663_ref8","doi-asserted-by":"crossref","first-page":"160","DOI":"10.1016\/j.cose.2004.08.007","article-title":"Empirical evaluation of SVM-based masquerade detection using UNIX commands","volume":"24","author":"Kim","year":"2005","journal-title":"Computer Security"},{"key":"10.3233\/JCM-226663_ref9","first-page":"164","article-title":"A data-drivensemi-global alignment approach for detecting masquerade attacks","author":"Kholidy","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.3233\/JCM-226663_ref10","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2019.2904330"},{"key":"10.3233\/JCM-226663_ref11","doi-asserted-by":"publisher","DOI":"10.1109\/OJSP.2020.3036276"},{"key":"10.3233\/JCM-226663_ref14","doi-asserted-by":"crossref","first-page":"210140","DOI":"10.1109\/ACCESS.2020.3039166","article-title":"Model for detection of masquerade attacks based on variable-length sequences","volume":"8","author":"Ghazaros","year":"2020","journal-title":"IEEE Access"},{"issue":"6","key":"10.3233\/JCM-226663_ref15","first-page":"500","article-title":"Network user camouflage intrusion detection for UNIX and Linux platforms","volume":"4","author":"Tian","year":"2010","journal-title":"Journal of Frontiers of Computer Science and Technology"},{"issue":"11","key":"10.3233\/JCM-226663_ref16","doi-asserted-by":"crossref","first-page":"2470","DOI":"10.1016\/j.jss.2012.05.049","article-title":"A variable-length model for masquerade detection","volume":"85","author":"Xiao","year":"2012","journal-title":"The Journal of Systems and Software"}],"container-title":["Journal of Computational Methods in Sciences and Engineering"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/JCM-226663","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T22:06:51Z","timestamp":1776809211000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/JCM-226663"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,30]]},"references-count":9,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.3233\/jcm-226663","relation":{},"ISSN":["1472-7978","1875-8983"],"issn-type":[{"value":"1472-7978","type":"print"},{"value":"1875-8983","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,30]]}}}