{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T16:59:20Z","timestamp":1774544360317,"version":"3.50.1"},"reference-count":31,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2019,8,17]],"date-time":"2019-08-17T00:00:00Z","timestamp":1566000000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Anomaly detection of network traffic flows is a non-trivial problem in the field of network security due to the complexity of network traffic. However, most machine learning-based detection methods focus on network anomaly detection but ignore the user anomaly behavior detection. In real scenarios, the anomaly network behavior may harm the user interests. In this paper, we propose an anomaly detection model based on time-decay closed frequent patterns to address this problem. The model mines closed frequent patterns from the network traffic of each user and uses a time-decay factor to distinguish the weight of current and historical network traffic. Because of the dynamic nature of user network behavior, a detection model update strategy is provided in the anomaly detection framework. Additionally, the closed frequent patterns can provide interpretable explanations for anomalies. Experimental results show that the proposed method can detect user behavior anomaly, and the network anomaly detection performance achieved by the proposed method is similar to the state-of-the-art methods and significantly better than the baseline methods.<\/jats:p>","DOI":"10.3390\/info10080262","type":"journal-article","created":{"date-parts":[[2019,8,19]],"date-time":"2019-08-19T06:10:14Z","timestamp":1566195014000},"page":"262","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Network Anomaly Detection by Using a Time-Decay Closed Frequent Pattern"],"prefix":"10.3390","volume":"10","author":[{"given":"Ying","family":"Zhao","sequence":"first","affiliation":[{"name":"College of Information Technology, Beijing University of Chemical Technology, Beijing 100029, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8902-2553","authenticated-orcid":false,"given":"Junjun","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Information Technology, Beijing University of Chemical Technology, Beijing 100029, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Di","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo 2007, Australia"},{"name":"Centre for Artificial Intelligence, University of Technology Sydney, Ultimo 2007, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Teng","sequence":"additional","affiliation":[{"name":"College of Information Technology, Beijing University of Chemical Technology, Beijing 100029, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nabin","family":"Sharma","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo 2007, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0445-0573","authenticated-orcid":false,"given":"Atul","family":"Sajjanhar","sequence":"additional","affiliation":[{"name":"School of Information Technology, Deakin University, Burwood 3125, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9908-3744","authenticated-orcid":false,"given":"Michael","family":"Blumenstein","sequence":"additional","affiliation":[{"name":"Centre for Artificial Intelligence, University of Technology Sydney, Ultimo 2007, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,8,17]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"Buczak","year":"2016","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_2","first-page":"640","article-title":"Survey of Attack Projection, Prediction, and Forecasting in Cyber Security","volume":"21","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"2986","DOI":"10.1109\/TC.2016.2519914","article-title":"Building an intrusion detection system using a filter-based feature selection algorithm","volume":"65","author":"Ambusaidi","year":"2016","journal-title":"IEEE Trans. Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"152","DOI":"10.1016\/j.jocs.2017.03.006","article-title":"Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model","volume":"25","author":"Aljawarneh","year":"2018","journal-title":"J. Comput. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"484","DOI":"10.1016\/j.ins.2016.04.019","article-title":"Fuzziness based semi-supervised learning approach for intrusion detection system","volume":"378","author":"Ashfaq","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Mirsky, Y., Doitshman, T., Elovici, Y., and Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. arXiv.","DOI":"10.14722\/ndss.2018.23204"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Zenati, H., Romain, M., Foo, C.S., Lecouat, B., and Chandrasekhar, V. (2018, January 17\u201320). Adversarially Learned Anomaly Detection. Proceedings of the 2018 IEEE International Conference on Data Mining (ICDM), Singapore.","DOI":"10.1109\/ICDM.2018.00088"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"2058","DOI":"10.1109\/TII.2017.2650206","article-title":"Big data analytics for user-activity analysis and user-anomaly detection in mobile wireless network","volume":"13","author":"Parwez","year":"2017","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Fawaz, A.M., and Sanders, W.H. (2017, January 22\u201325). Learning process behavioral baselines for anomaly detection. Proceedings of the 2017 IEEE 22nd Pacific Rim International Symposium on Dependable Computing (PRDC), Christchurch, New Zealand.","DOI":"10.1109\/PRDC.2017.28"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"503","DOI":"10.1109\/JSYST.2015.2438442","article-title":"Automated insider threat detection system using user and role-based profile assessment","volume":"11","author":"Legg","year":"2015","journal-title":"IEEE Syst. J."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"547","DOI":"10.1007\/s12652-015-0341-4","article-title":"Anomaly detection model of user behavior based on principal component analysis","volume":"7","author":"Bi","year":"2016","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Najafabadi, M.M., Khoshgoftaar, T.M., Calvert, C., and Kemp, C. (2017, January 4\u20136). User behavior anomaly detection for application layer ddos attacks. Proceedings of the 2017 IEEE International Conference on Information Reuse and Integration (IRI), San Diego, CA, USA.","DOI":"10.1109\/IRI.2017.44"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1007\/s10618-006-0059-1","article-title":"Frequent pattern mining: Current status and future directions","volume":"15","author":"Han","year":"2007","journal-title":"Data Min. Knowl. Discov."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"566","DOI":"10.1109\/TMM.2019.2893549","article-title":"Hybrid Deep Learning-based Anomaly Detection Scheme for Suspicious Flow Detection in SDN: A Social Multimedia Perspective","volume":"21","author":"Garg","year":"2019","journal-title":"IEEE Trans. Multimed."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/TETCI.2017.2772792","article-title":"A deep learning approach to network intrusion detection","volume":"2","author":"Shone","year":"2018","journal-title":"IEEE Trans. Emerg. Top. Comput. Intell."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Brahmi, H., Brahmi, I., and Yahia, S.B. (2012). OMC-IDS: At the cross-roads of OLAP mining and intrusion detection. Pacific-Asia Conference on Knowledge Discovery and Data Mining, Springer.","DOI":"10.1007\/978-3-642-30220-6_2"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1016\/j.eswa.2011.07.032","article-title":"An efficient intrusion detection system based on support vector machines and gradually feature removal method","volume":"39","author":"Li","year":"2012","journal-title":"Expert Syst. Appl."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"558","DOI":"10.1016\/j.future.2017.09.056","article-title":"Dendron: Genetic trees driven rule induction for network intrusion detection systems","volume":"79","author":"Papamartzivanos","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1109\/TVCG.2015.2467196","article-title":"Targetvue: Visual analysis of anomalous user behaviors in online communication systems","volume":"22","author":"Cao","year":"2015","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"e3002","DOI":"10.1002\/dac.3002","article-title":"An incremental intrusion detection system using a new semi-supervised stream classification method","volume":"30","author":"Noorbehbahani","year":"2017","journal-title":"Int. J. Commun. Syst."},{"key":"ref_21","first-page":"275","article-title":"Exploiting Incremental Classifiers for the Training of an Adaptive Intrusion Detection Model","volume":"21","author":"Mohamed","year":"2019","journal-title":"IJ Netw. Secur."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Saurav, S., Malhotra, P., TV, V., Gugulothu, N., Vig, L., Agarwal, P., and Shroff, G. (2018, January 11\u201313). Online anomaly detection with concept drift adaptation using recurrent neural networks. Proceedings of the ACM India Joint International Conference on Data Science and Management of Data, Goa, India.","DOI":"10.1145\/3152494.3152501"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Yen, S.J., Lee, Y.S., Wu, C.W., and Lin, C.L. (2009). An efficient algorithm for maintaining frequent closed itemsets over data stream. International Conference on Industrial, Engineering and Other Applications of Applied Intelligent Systems, Springer.","DOI":"10.1007\/978-3-642-02568-6_78"},{"key":"ref_24","first-page":"851","article-title":"TDMCS: An efficient method for mining closed frequent patterns over data streams based on time decay model","volume":"14","author":"Han","year":"2017","journal-title":"Int. Arab J. Inf. Technol."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Deri, L., Martinelli, M., Bujlow, T., and Cardigliano, A. (2014, January 4\u20138). ndpi: Open-source high-speed deep packet inspection. Proceedings of the 2014 International Wireless Communications and Mobile Computing Conference (IWCMC), Nicosia, Cyprus.","DOI":"10.1109\/IWCMC.2014.6906427"},{"key":"ref_26","unstructured":"Carlson, J.L. (2013). Redis in Action, Manning Publications Co."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kobayashi, T.H., Batista, A.B., Brito, A.M., and Pires, P.S.M. (2007, January 25\u201328). Using a packet manipulation tool for security analysis of industrial network protocols. Proceedings of the 2007 IEEE Conference on Emerging Technologies and Factory Automation (EFTA 2007), Patras, Greece.","DOI":"10.1109\/EFTA.2007.4416847"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"949","DOI":"10.1007\/s10586-017-1117-8","article-title":"A survey of deep learning-based network anomaly detection","volume":"22","author":"Kwon","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Zhao, Y., Chen, J., You, G., and Teng, J. (2016). Network Traffic Classification Model Based on MDL Criterion. Advanced Multimedia and Ubiquitous Engineering, Springer.","DOI":"10.1007\/978-981-10-1536-6_1"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Han, J., Pei, J., and Yin, Y. (2000). Mining Frequent Patterns without Candidate Generation, ACM. ACM Sigmod Record.","DOI":"10.1145\/342009.335372"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/10\/8\/262\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:11:49Z","timestamp":1760188309000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/10\/8\/262"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,8,17]]},"references-count":31,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2019,8]]}},"alternative-id":["info10080262"],"URL":"https:\/\/doi.org\/10.3390\/info10080262","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,8,17]]}}}