{"id":"https://openalex.org/W1585149031","doi":"https://doi.org/10.1007/11555827_16","title":"Towards a Theory of Intrusion Detection","display_name":"Towards a Theory of Intrusion Detection","publication_year":2005,"publication_date":"2005-01-01","ids":{"openalex":"https://openalex.org/W1585149031","doi":"https://doi.org/10.1007/11555827_16","mag":"1585149031"},"language":"en","primary_location":{"id":"doi:10.1007/11555827_16","is_oa":true,"landing_page_url":"https://doi.org/10.1007/11555827_16","pdf_url":"https://link.springer.com/content/pdf/10.1007/11555827_16.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/11555827_16.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5011460496","display_name":"Giovanni Di Crescenzo","orcid":"https://orcid.org/0000-0002-5138-1144"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Giovanni Di Crescenzo","raw_affiliation_strings":["Telcordia Technologies, Piscataway, NJ, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telcordia Technologies, Piscataway, NJ, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109224190","display_name":"Abhrajit Ghosh","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Abhrajit Ghosh","raw_affiliation_strings":["Telcordia Technologies, Piscataway, NJ, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telcordia Technologies, Piscataway, NJ, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084653601","display_name":"R. Talpade","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rajesh Talpade","raw_affiliation_strings":["Telcordia Technologies, Piscataway, NJ, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Telcordia Technologies, Piscataway, NJ, USA","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":1.9712,"has_fulltext":true,"cited_by_count":17,"citation_normalized_percentile":{"value":0.86928193,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"267","last_page":"286"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.8813472986221313},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8299490213394165},{"id":"https://openalex.org/keywords/probabilistic-logic","display_name":"Probabilistic logic","score":0.5413621664047241},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.5382214784622192},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.5233437418937683},{"id":"https://openalex.org/keywords/heuristic","display_name":"Heuristic","score":0.5127759575843811},{"id":"https://openalex.org/keywords/anomaly-based-intrusion-detection-system","display_name":"Anomaly-based intrusion detection system","score":0.5112991333007812},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.4533311128616333},{"id":"https://openalex.org/keywords/representation","display_name":"Representation (politics)","score":0.4162366986274719},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3244834840297699},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.25372105836868286}],"concepts":[{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.8813472986221313},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8299490213394165},{"id":"https://openalex.org/C49937458","wikidata":"https://www.wikidata.org/wiki/Q2599292","display_name":"Probabilistic logic","level":2,"score":0.5413621664047241},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5382214784622192},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.5233437418937683},{"id":"https://openalex.org/C173801870","wikidata":"https://www.wikidata.org/wiki/Q201413","display_name":"Heuristic","level":2,"score":0.5127759575843811},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.5112991333007812},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4533311128616333},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.4162366986274719},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3244834840297699},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.25372105836868286},{"id":"https://openalex.org/C94625758","wikidata":"https://www.wikidata.org/wiki/Q7163","display_name":"Politics","level":2,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1007/11555827_16","is_oa":true,"landing_page_url":"https://doi.org/10.1007/11555827_16","pdf_url":"https://link.springer.com/content/pdf/10.1007/11555827_16.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"}],"best_oa_location":{"id":"doi:10.1007/11555827_16","is_oa":true,"landing_page_url":"https://doi.org/10.1007/11555827_16","pdf_url":"https://link.springer.com/content/pdf/10.1007/11555827_16.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"sustainable_development_goals":[{"score":0.6299999952316284,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W1585149031.pdf","grobid_xml":"https://content.openalex.org/works/W1585149031.grobid-xml"},"referenced_works_count":20,"referenced_works":["https://openalex.org/W65918548","https://openalex.org/W174918044","https://openalex.org/W1551436681","https://openalex.org/W1577117059","https://openalex.org/W1883625630","https://openalex.org/W1884606608","https://openalex.org/W1965142549","https://openalex.org/W2005983304","https://openalex.org/W2008697975","https://openalex.org/W2045460927","https://openalex.org/W2048465382","https://openalex.org/W2050749090","https://openalex.org/W2061106457","https://openalex.org/W2150847526","https://openalex.org/W2151613123","https://openalex.org/W2165313080","https://openalex.org/W3214373139","https://openalex.org/W4210300416","https://openalex.org/W4244691952","https://openalex.org/W4248932050"],"related_works":["https://openalex.org/W2337148208","https://openalex.org/W3004832009","https://openalex.org/W3036013726","https://openalex.org/W1971929717","https://openalex.org/W1724519426","https://openalex.org/W2351051591","https://openalex.org/W2369534771","https://openalex.org/W2357468538","https://openalex.org/W1548126107","https://openalex.org/W2209997499"],"abstract_inverted_index":{"We":[0,230],"embark":[1],"into":[2],"theoretical":[3],"approaches":[4],"for":[5,21,80,123],"the":[6,42,96,106,132,136,143,155,164,167,201,208,218],"investigation":[7],"of":[8,31,108,135,142,145,158,176,203,211],"intrusion":[9,22,43,51,81,125,188,213],"detection":[10,23,44,82,126,171,189,209,214],"schemes.":[11],"Our":[12,34],"main":[13,120],"motivation":[14],"is":[15,149,173],"to":[16,151,154,161,220,242,247],"provide":[17],"rigorous":[18,174],"security":[19,55,121],"requirements":[20,56],"systems":[24,117,168,190,241],"that":[25,114,166,191],"can":[26,112,192],"be":[27,193],"used":[28],"by":[29],"designers":[30],"such":[32,46,234],"systems.":[33],"model":[35],"captures":[36],"and":[37,49,53,63,91,98,175,178,205,237],"generalizes":[38],"well-known":[39,60,64],"methodologies":[40],"in":[41,66],"area,":[45],"as":[47,69,235],"anomaly-based":[48],"signature-based":[50],"detection,":[52],"formulates":[54],"based":[57,85,93],"on":[58,86,94,105,139,187],"both":[59,95,129],"complexity-theoretic":[61],"notions":[62,65],"cryptography":[67],"(such":[68],"computational":[70],"indistinguishability).":[71],"Under":[72,101],"our":[73,115,119,182],"model,":[74],"we":[75,111,199],"present":[76,243],"two":[77,116],"efficient":[78],"paradigms":[79],"systems,":[83],"one":[84,92],"nearest":[87],"neighbor":[88],"search":[89],"algorithms,":[90],"latter":[97,219],"clustering":[99],"algorithms.":[100],"formally":[102],"specified":[103],"assumptions":[104],"representation":[107,144],"network":[109,146],"traffic,":[110],"prove":[113],"satisfy":[118,169],"requirement":[122],"an":[124,197],"system.":[127],"In":[128],"cases,":[130],"while":[131],"potential":[133],"truth":[134],"assumption":[137],"rests":[138],"heuristic":[140],"properties":[141,172],"traffic":[147,227],"(which":[148],"hard":[150],"avoid":[152],"due":[153],"unpredictable":[156],"nature":[157],"external":[159],"attacks":[160],"a":[162],"network),":[163],"proof":[165],"desirable":[170],"probabilistic":[177],"algorithmic":[179],"nature.":[180],"Additionally,":[181],"framework":[183],"raises":[184],"open":[185],"questions":[186],"rigorously":[194],"studied.":[195],"As":[196],"example,":[198],"study":[200],"problem":[202],"arbitrarily":[204],"efficiently":[206],"extending":[207],"window":[210],"any":[212],"system,":[215],"which":[216],"allows":[217],"catch":[221],"attack":[222],"sequences":[223],"interleaved":[224],"with":[225],"normal":[226],"packet":[228],"sequences.":[229],"use":[231],"combinatoric":[232],"tools":[233],"time":[236],"space-efficient":[238],"covering":[239],"set":[240],"provably":[244],"correct":[245],"solutions":[246],"this":[248],"problem.":[249]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2012,"cited_by_count":4}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
