{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:07:16Z","timestamp":1781104036180,"version":"3.54.1"},"reference-count":0,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006,7,1]]},"abstract":"<p>Although statistical modeling techniques have been employed to detect anomaly intrusion and profile user behavior with network traffic data collected from multi-sites (IP addresses), the minimum sample size of audit data required for each site is unclear. Using the Intrusion Detection Evaluation off-line data developed by the Lincoln Laboratory at Massachusetts Institute of Technology under the Defense Advanced Research Projects Agency, this study aimed to address the challenge of determining sample size. Bivariate analysis was employed to construct a composite score to rank each site\u2019s probability of being an anomaly, and statistical simulations were conducted to evaluate the ranking variation between the population based \u201ctrue\u201d pattern of user behavior and different sample based \u201cobserved\u201d patterns. A sequence of hierarchical random effects logistic regression models was fitted to compare the performance of the full dataset-based and sample-based classifications. The results show that a minimum sample size of 500 per site provides a sensitivity value of 0.85, specificity value of 0.92 and kappa statistic of 0.77. Compared with the full dataset-based model, the minimum sample-based model had a similar Receiver Operating Characteristic area (0.983 vs. 0.997) and a slightly higher misclassification rate (3.16% vs. 1.71%) in detecting abnormal patterns.<\/p>","DOI":"10.4018\/jbdcn.2006070103","type":"journal-article","created":{"date-parts":[[2011,2,3]],"date-time":"2011-02-03T11:54:53Z","timestamp":1296734093000},"page":"31-45","source":"Crossref","is-referenced-by-count":1,"title":["Determining the Minimum Sample Size of Audit Data Required to Profile User Behavior and Detect Anomaly Intrusion"],"prefix":"10.4018","volume":"2","author":[{"given":"Yun","family":"Wang","sequence":"first","affiliation":[{"name":"Center for Outcomes Research and Evaluation, Yale University and Yale New Haven Health, and Qualidigm, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sharon-Lise T.","family":"Normand","sequence":"additional","affiliation":[{"name":"Department of Biostatistics, Harvard School of Public Health, and Department of Health Care, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","container-title":["International Journal of Business Data Communications and Networking"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=1425","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T13:51:53Z","timestamp":1654091513000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jbdcn.2006070103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2006,7,1]]},"references-count":0,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2006,7]]}},"URL":"https:\/\/doi.org\/10.4018\/jbdcn.2006070103","relation":{},"ISSN":["1548-0631","1548-064X"],"issn-type":[{"value":"1548-0631","type":"print"},{"value":"1548-064X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006,7,1]]}}}