{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T00:46:03Z","timestamp":1783730763613,"version":"3.55.0"},"reference-count":54,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2019,1,10]],"date-time":"2019-01-10T00:00:00Z","timestamp":1547078400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["BDCC"],"abstract":"<jats:p>A Security Operations Center (SOC) is a central technical level unit responsible for monitoring, analyzing, assessing, and defending an organization\u2019s security posture on an ongoing basis. The SOC staff works closely with incident response teams, security analysts, network engineers and organization managers using sophisticated data processing technologies such as security analytics, threat intelligence, and asset criticality to ensure security issues are detected, analyzed and finally addressed quickly. Those techniques are part of a reactive security strategy because they rely on the human factor, experience and the judgment of security experts, using supplementary technology to evaluate the risk impact and minimize the attack surface. This study suggests an active security strategy that adopts a vigorous method including ingenuity, data analysis, processing and decision-making support to face various cyber hazards. Specifically, the paper introduces a novel intelligence driven cognitive computing SOC that is based exclusively on progressive fully automatic procedures. The proposed \u03bb-Architecture Network Flow Forensics Framework (\u03bb-\u039dF3) is an efficient cybersecurity defense framework against adversarial attacks. It implements the Lambda machine learning architecture that can analyze a mixture of batch and streaming data, using two accurate novel computational intelligence algorithms. Specifically, it uses an Extreme Learning Machine neural network with Gaussian Radial Basis Function kernel (ELM\/GRBFk) for the batch data analysis and a Self-Adjusting Memory k-Nearest Neighbors classifier (SAM\/k-NN) to examine patterns from real-time streams. It is a forensics tool for big data that can enhance the automate defense strategies of SOCs to effectively respond to the threats their environments face.<\/jats:p>","DOI":"10.3390\/bdcc3010006","type":"journal-article","created":{"date-parts":[[2019,1,11]],"date-time":"2019-01-11T04:10:16Z","timestamp":1547179816000},"page":"6","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":37,"title":["The Next Generation Cognitive Security Operations Center: Adaptive Analytic Lambda Architecture for Efficient Defense against Adversarial Attacks"],"prefix":"10.3390","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1330-5228","authenticated-orcid":false,"given":"Konstantinos","family":"Demertzis","sequence":"first","affiliation":[{"name":"Department of Civil Engineering, School of Engineering, Democritus University of Thrace, 67100 Xanthi, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nikos","family":"Tziritas","sequence":"additional","affiliation":[{"name":"Research Center for Cloud Computing, Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen 518000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Panayiotis","family":"Kikiras","sequence":"additional","affiliation":[{"name":"Department of Computer Science, School of Science, University of Thessaly, 35131 Lamia, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3828-4136","authenticated-orcid":false,"given":"Salvador Llopis","family":"Sanchez","sequence":"additional","affiliation":[{"name":"Communications Department, Universitat Politecnica de Valencia, 46022 Valencia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lazaros","family":"Iliadis","sequence":"additional","affiliation":[{"name":"Department of Civil Engineering, School of Engineering, Democritus University of Thrace, 67100 Xanthi, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2019,1,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Dalvi, N., Domingos, P., Sanghai, S., and Verma, D. (2004, January 22\u201325). Adversarial classification. Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD), Seattle, WA, USA.","DOI":"10.1145\/1014052.1014066"},{"key":"ref_2","unstructured":"Nelson, B., Barreno, M., Chi, F.J., Joseph, A.D., Rubinstein, B.I.P., Saini, U., Sutton, C., Tygar, J.D., and Xia, K. (2008, January 15). Exploiting machine learning to subvert your spam filter. Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats (LEET\u201908), San Francisco, CA, USA."},{"key":"ref_3","unstructured":"Fogla, P., Sharif, M., Perdisci, R., Kolesnikov, O., and Lee, W. (August, January 31). Polymorphic blending attacks. Proceedings of the 15th Conference on USENIX Security Symposium (USENIX-SS\u201906), Vancouver, BC, Canada."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Newsome, J., Karp, B., and Song, D. (2006). Paragraph: Thwarting signature learning by training maliciously. Recent Advances in Intrusion Detection, Springer.","DOI":"10.1007\/11856214_5"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1016\/j.jvlc.2009.01.010","article-title":"Robustness of multimodal biometric fusion methods against spoof attacks","volume":"20","author":"Rodrigues","year":"2009","journal-title":"J. Vis. Lang. Comput."},{"key":"ref_6","first-page":"1","article-title":"Machine Learning Methods for Computer Security (Dagstuhl Perspectives Workshop 12371)","volume":"Volume 3","author":"Joseph","year":"2013","journal-title":"Dagstuhl Manifestos"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Dedi\u0107, N., and Stanier, C. (2017). Towards Differentiating Business Intelligence, Big Data, Data Analytics and Knowledge Discovery, Springer International Publishing. OCLC 909580101.","DOI":"10.1007\/978-3-319-58801-8_10"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Llopis, S., Hingant, J., P\u00e9rez, I., Esteve, M., Carvajal, F., Mees, W., and Debatty, T. (2018, January 22\u201323). A comparative analysis of visualisation techniques to achieve cyber situational awareness in the military. Proceedings of the 2018 International Conference on Military Communications and Information Systems (ICMCIS), Warsaw, Poland.","DOI":"10.1109\/ICMCIS.2018.8398693"},{"key":"ref_9","unstructured":"Sideridis, A., Kardasiadou, Z., Yialouris, C., and Zorkadis, V. (2014). A Hybrid Network Anomaly and Intrusion Detection Approach Based on Evolving Spiking Neural Network Classification. E-Democracy 2013: E-Democracy, Security, Privacy and Trust in a Digital World, Springer."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"322","DOI":"10.1007\/978-3-319-07869-4_30","article-title":"Evolving Computational Intelligence System for Malware Detection","volume":"Volume 178","author":"Demertzis","year":"2014","journal-title":"Advanced Information Systems Engineering Workshops"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Daras, N., and Rassias, M. (2014). Bio-Inspired Hybrid Artificial Intelligence Framework for Cyber Security. Computation, Cryptography, and Network Security, Springer.","DOI":"10.1007\/978-3-319-18275-9"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Iliadis, L., Papazoglou, M., and Pohl, K. (2014, January 6\u20138). Bio-Inspired Hybrid Intelligent Method for Detecting Android Malware. Proceedings of the Advanced Information Systems Engineering Workshops (CAiSE 2014), Limassol, Cyprus. Lecture Notes in Business Information Processing Series.","DOI":"10.1007\/978-3-319-07869-4"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Gammerman, A., Vovk, V., and Papadopoulos, H. (2015). Evolving Smart URL Filter in a Zone-based Policy Firewall for Detecting Algorithmically Generated Malicious Domains. Statistical Learning and Data Sciences (SLDS 2015), Springer.","DOI":"10.1007\/978-3-319-17091-6"},{"key":"ref_14","unstructured":"N\u00fa\u00f1ez, M., Nguyen, N., Camacho, D., and Trawi\u0144ski, B. (2015). SAME: An Intelligent Anti-Malware Extension for Android ART Virtual Machine. Computational Collective Intelligence, Springer."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1007\/s40595-017-0095-3","article-title":"Computational Intelligence Anti-Malware Framework for Android OS","volume":"4","author":"Demertzis","year":"2017","journal-title":"Vietnam. J. Comput. Sci."},{"key":"ref_16","first-page":"45","article-title":"Ladon: A Cyber-Threat Bio-Inspired Intelligence Management System","volume":"6","author":"Demertzis","year":"2016","journal-title":"J. Appl. Math. Bioinform."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1080\/17512549.2017.1325401","article-title":"An innovative soft computing system for smart energy grids cybersecurity","volume":"12","author":"Demertzis","year":"2018","journal-title":"Adv. Build. Energy Res."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Scandariato, R., and Walden, J. (2012, January 21). Predicting vulnerable classes in an android application. Proceedings of the 4th International Workshop on Security Measurements and Metrics, Lund, Sweden.","DOI":"10.1145\/2372225.2372231"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Shabtai, A., Fledel, Y., and Elovici, Y. (2010, January 11\u201314). Automated static code analysis for classifying android applications using machine learning. Proceedings of the 2010 International Conference on Computational Intelligence and Security, Nanning, China.","DOI":"10.1109\/CIS.2010.77"},{"key":"ref_20","unstructured":"Chin, E., Felt, A., Greenwood, K., and Wagner, D. (July, January 28). Analyzing inter-application communication in android. Proceedings of the 9th Conference on Mobile Systems, Applications, and Services, Bethesda, MD, USA."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., and Nadjm-Tehrani, S. (2011, January 17). Crowdroid: Behavior-based malware detection system for android. Proceedings of the1st ACM Workshop on Security and Privacy in Smartphones and Mobile Devices, Chicago, IL, USA.","DOI":"10.1145\/2046614.2046619"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Glodek, W., and Harang, R.R. (2013, January 18\u201320). Permissions-based Detection and Analysis of Mobile Malware Using Random Decision Forests. Proceedings of the IEEE Military Communications Conference, San Diego, CA, USA.","DOI":"10.1109\/MILCOM.2013.170"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1109\/TNSM.2013.022713.120250","article-title":"An effective network traffic classification method with unknown flow detection","volume":"10","author":"Zhang","year":"2013","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Joseph, G., and Nagaraja, S. (2014, January 19\u201321). On the reliability of network measurement techniques used for malware traffic analysis. Proceedings of the Cambridge International Workshop on Security Protocols, Cambridge, UK.","DOI":"10.1007\/978-3-319-12400-1_32"},{"key":"ref_25","unstructured":"Hsu, C.-H., Huang, C.-Y., and Chen, K.-T. (2010, January 15\u201317). Fast-flux bot detection in real time. Proceedings of the 13th International Conference on Recent Advances in Intrusion Detection (Ser. RAID\u201910), Ottawa, ON, Canada."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Haffner, P., Sen, S., Spatscheck, O., and Wang, D. (2005, January 22\u201326). ACAS: Auto-mated Construction of Application Signatures. Proceedings of the 2005 ACM SIGCOMM Workshop on Mining Network Data, Philadelphia, PA, USA.","DOI":"10.1145\/1080173.1080183"},{"key":"ref_27","unstructured":"Holz, T., Gorecki, C., Rieck, K., and Freiling, F. (2008, January 10\u201313). Measuring and detecting fast-flux service networks. Proceedings of the Network & Distributed System Security Symposium (NDSS\u201908), San Diego, CA, USA."},{"key":"ref_28","first-page":"10","article-title":"A Model for Detecting Tor Encrypted Traffic using Supervised Machine Learning","volume":"7","author":"Almubayed","year":"2015","journal-title":"Int. J. Comput. Netw. Inf. Secur."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"HoseinyFarahabady, M., Taheri, J., Tari, Z., and Zomaya, A.Y. (2017, January 14\u201317). A Dynamic Resource Controller for a Lambda Architecture. Proceedings of the 2017 46th International Conference on Parallel Processing (ICPP), Bristol, UK.","DOI":"10.1109\/ICPP.2017.42"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Suthakar, U., Magnoni, L., Smith, D.R., and Khan, A. (November, January 29). Optimised lambda architecture for monitoring WLCG using spark and spark streaming. Proceedings of the 2016 IEEE Nuclear Science Symposium, Medical Imaging Conference and Room-Temperature Semiconductor Detector Workshop (NSS\/MIC\/RTSD), Strasbourg, France.","DOI":"10.1109\/NSSMIC.2016.8069637"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Kiran, M., Murphy, P., Monga, I., Dugan, J., and Baveja, S.S. (November, January 29). Lambda architecture for cost-effective batch and speed big data processing. Proceedings of the 2015 IEEE International Conference on Big Data (Big Data), Santa Clara, CA, USA.","DOI":"10.1109\/BigData.2015.7364082"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Yamato, Y., Kumazaki, H., and Fukumoto, Y. (2016, January 22\u201325). Proposal of Lambda Architecture Adoption for Real Time Predictive Maintenance. Proceedings of the 2016 Fourth International Symposium on Computing and Networking (CANDAR), Hiroshima, Japan.","DOI":"10.1109\/CANDAR.2016.0130"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Yong, S.Z., Foo, M.Q., and Frazzoli, E. (2016, January 6\u20138). Robust and resilient estimation for Cyber-Physical Systems under adversarial attacks. Proceedings of the 2016 American Control Conference (ACC), Boston, MA, USA.","DOI":"10.1109\/ACC.2016.7524933"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Chong, M.S., Wakaiki, M., and Hespanha, J.P. (2015, January 1\u20133). Observability of linear systems under adversarial attacks. Proceedings of the 2015 American Control Conference (ACC), Chicago, IL, USA.","DOI":"10.1109\/ACC.2015.7171098"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Chen, L., Ye, Y., and Bourlai, T. (2017, January 11\u201313). Adversarial Machine Learning in Malware Detection: Arms Race between Evasion Attack and Defense. Proceedings of the 2017 European Intelligence and Security Informatics Conference (EISIC), Athens, Greece.","DOI":"10.1109\/EISIC.2017.21"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1109\/MNET.2011.5772054","article-title":"Network traffic monitoring, analysis and anomaly detection [Guest Editorial]","volume":"25","author":"Wang","year":"2011","journal-title":"IEEE Netw."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"2991","DOI":"10.1109\/COMST.2016.2566669","article-title":"A Survey on Regular Expression Matching for Deep Packet Inspection: Applications, Algorithms, and Hardware Platforms","volume":"18","author":"Xu","year":"2016","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Zhang, H., Papadopoulos, C., and Massey, D. (2013, January 14\u201319). Detecting encrypted botnet traffic. Proceedings of the 2013 IEEE Conference on Computer Communications Workshops, Turin, Italy.","DOI":"10.1109\/INFCOM.2013.6567180"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"413","DOI":"10.1016\/j.ijforecast.2009.10.008","article-title":"Asymmetric Loss Functions and the Rationality of Expected Stock Returns","volume":"27","author":"Aretz","year":"2011","journal-title":"Int. J. Forecast."},{"key":"ref_40","unstructured":"Kushner, H.J., and Yin, G.G. (2003). Stochastic Approximation and Recursive Algorithms and Applications, Springer. [2nd ed.]."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1109\/MIS.2013.140","article-title":"Extreme learning machines [trends & controversies]","volume":"28","author":"Cambria","year":"2013","journal-title":"IEEE Intell. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"376","DOI":"10.1007\/s12559-014-9255-2","article-title":"An Insight into Extreme Learning Machines: Random Neurons, Random Features and Kernels","volume":"6","author":"Huang","year":"2014","journal-title":"Cogn. Comput."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1007\/s12559-015-9333-0","article-title":"What are Extreme Learning Machines? Filling the Gap between Frank Rosenblatt\u2019s Dream and John von Neumann\u2019s Puzzle","volume":"7","author":"Huang","year":"2015","journal-title":"Cogn. Comput."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Losing, V., Hammer, B., and Wersing, H. (2016, January 12\u201315). KNN Classifier with Self Adjusting Memory for Heterogeneous Concept Drift. Proceedings of the 2016 IEEE 16th International Conference on Data Mining (ICDM), Barcelona, Spain.","DOI":"10.1109\/ICDM.2016.0040"},{"key":"ref_45","unstructured":"Haining, W., Danlu, Z., and Kang, G.S. (2002, January 23\u201327). Detecting SYN flooding attacks. Proceedings of the INFOCOM 2002\u2014Twenty-First Annual Joint Conference of the IEEE Computer and Communications Societies, New York, NY, USA."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Arndt, D.J., and Zincir-Heywood, A.N. (2011, January 11\u201315). A Comparison of Three Machine Learning Techniques for Encrypted Network Traffic Analysis. Proceedings of the 2011 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), Paris, France.","DOI":"10.1109\/CISDA.2011.5945941"},{"key":"ref_47","unstructured":"(2018, September 27). contagiodump. Available online: http:\/\/contagiodump.blogspot.gr\/."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Demertzis, K., Kikiras, P., Tziritas, N., Sanchez, S.L., and Iliadis, L. (2018). The Next Generation Cognitive Security Operations Center: Network Flow Forensics Using Cybersecurity Intelligence. Big Data Cogn. Comput., 2.","DOI":"10.3390\/bdcc2040035"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/34.824819","article-title":"Statistical pattern recognition: A review","volume":"22","author":"Mao","year":"2000","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"861","DOI":"10.1016\/j.patrec.2005.10.010","article-title":"An introduction to ROC analysis","volume":"27","author":"Fawcett","year":"2006","journal-title":"Pattern Recognit. Lett."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"455","DOI":"10.1007\/s10994-014-5441-4","article-title":"Evaluation methods and decision theory for classification of streaming data with temporal dependence","volume":"98","author":"Bifet","year":"2015","journal-title":"Mach. Learn."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Corr\u00eaa, D.G., Enembreck, F., and Silla, C.N. (2017, January 14\u201319). An investigation of the hoeffding adaptive tree for the problem of network intrusion detection. Proceedings of the 2017 International Joint Conference on Neural Networks (IJCNN), Anchorage, AK, USA.","DOI":"10.1109\/IJCNN.2017.7966369"},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s10107-010-0420-4","article-title":"Pegasos: Primal estimated sub-gradient solver for SVM","volume":"127","author":"Singer","year":"2011","journal-title":"Math. Program."},{"key":"ref_54","unstructured":"Vinagre, J., Jorge, A.M., and Gama, J. (2014, January 10). Evaluation of recommender systems in streaming environments. Proceedings of the Workshop on \u2018Recommender Systems Evaluation: Dimensions and Design\u2019 (REDD 2014), Silicon Valley, CA, USA."}],"container-title":["Big Data and Cognitive Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-2289\/3\/1\/6\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:25:01Z","timestamp":1760185501000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-2289\/3\/1\/6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,10]]},"references-count":54,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2019,3]]}},"alternative-id":["bdcc3010006"],"URL":"https:\/\/doi.org\/10.3390\/bdcc3010006","relation":{},"ISSN":["2504-2289"],"issn-type":[{"value":"2504-2289","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,1,10]]}}}