{"id":"https://openalex.org/W2518776528","doi":"https://doi.org/10.1007/978-3-319-45931-8_6","title":"An HMM-Based Anomaly Detection Approach for SCADA Systems","display_name":"An HMM-Based Anomaly Detection Approach for SCADA Systems","publication_year":2016,"publication_date":"2016-01-01","ids":{"openalex":"https://openalex.org/W2518776528","doi":"https://doi.org/10.1007/978-3-319-45931-8_6","mag":"2518776528"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-319-45931-8_6","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-319-45931-8_6","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://inria.hal.science/hal-01639609","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5033440062","display_name":"Kyriakos Stefanidis","orcid":"https://orcid.org/0000-0002-2090-2218"},"institutions":[{"id":"https://openalex.org/I4210135709","display_name":"Industrial Systems Institute","ror":"https://ror.org/02sy6k521","country_code":"GR","type":"nonprofit","lineage":["https://openalex.org/I4210135709"]}],"countries":["GR"],"is_corresponding":false,"raw_author_name":"Kyriakos Stefanidis","raw_affiliation_strings":["Industrial Systems Institute/RC \u2018Athena\u2019, Patras, Greece","Industrial Systems Institute/RC 'Athena', Patras, Greece"],"affiliations":[{"raw_affiliation_string":"Industrial Systems Institute/RC \u2018Athena\u2019, Patras, Greece","institution_ids":["https://openalex.org/I4210135709"]},{"raw_affiliation_string":"Industrial Systems Institute/RC 'Athena', Patras, Greece","institution_ids":["https://openalex.org/I4210135709"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5086067751","display_name":"Artemios G. Voyiatzis","orcid":null},"institutions":[{"id":"https://openalex.org/I4210167190","display_name":"SBA Research","ror":"https://ror.org/05nny6x17","country_code":"AT","type":"facility","lineage":["https://openalex.org/I4210167190"]}],"countries":["AT"],"is_corresponding":true,"raw_author_name":"Artemios G. Voyiatzis","raw_affiliation_strings":["SBA Research, Vienna, Austria"],"affiliations":[{"raw_affiliation_string":"SBA Research, Vienna, Austria","institution_ids":["https://openalex.org/I4210167190"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5086067751"],"corresponding_institution_ids":["https://openalex.org/I4210167190"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":6.8974,"has_fulltext":false,"cited_by_count":43,"citation_normalized_percentile":{"value":0.97543515,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"85","last_page":"99"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8416973352432251},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.807683527469635},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.759189248085022},{"id":"https://openalex.org/keywords/hidden-markov-model","display_name":"Hidden Markov model","score":0.7401537895202637},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.7008500099182129},{"id":"https://openalex.org/keywords/scada","display_name":"SCADA","score":0.6881619691848755},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.5407753586769104},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4794168174266815},{"id":"https://openalex.org/keywords/industrial-control-system","display_name":"Industrial control system","score":0.47214439511299133},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4692765772342682},{"id":"https://openalex.org/keywords/attack-patterns","display_name":"Attack patterns","score":0.4534646272659302},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.443543940782547},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4214553236961365},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3404451608657837},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.12332448363304138},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.08557146787643433}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8416973352432251},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.807683527469635},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.759189248085022},{"id":"https://openalex.org/C23224414","wikidata":"https://www.wikidata.org/wiki/Q176769","display_name":"Hidden Markov model","level":2,"score":0.7401537895202637},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.7008500099182129},{"id":"https://openalex.org/C113863187","wikidata":"https://www.wikidata.org/wiki/Q17498","display_name":"SCADA","level":2,"score":0.6881619691848755},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.5407753586769104},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4794168174266815},{"id":"https://openalex.org/C40071531","wikidata":"https://www.wikidata.org/wiki/Q2513962","display_name":"Industrial control system","level":3,"score":0.47214439511299133},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4692765772342682},{"id":"https://openalex.org/C2780741293","wikidata":"https://www.wikidata.org/wiki/Q4818019","display_name":"Attack patterns","level":3,"score":0.4534646272659302},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.443543940782547},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4214553236961365},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3404451608657837},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.12332448363304138},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.08557146787643433},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/978-3-319-45931-8_6","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-319-45931-8_6","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:HAL:hal-01639609v1","is_oa":true,"landing_page_url":"https://inria.hal.science/hal-01639609","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"10th IFIP International Conference on Information Security Theory and Practice (WISTP), Sep 2016, Heraklion, Greece. pp.85-99, &#x27E8;10.1007/978-3-319-45931-8_6&#x27E9;","raw_type":"Conference papers"}],"best_oa_location":{"id":"pmh:oai:HAL:hal-01639609v1","is_oa":true,"landing_page_url":"https://inria.hal.science/hal-01639609","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"10th IFIP International Conference on Information Security Theory and Practice (WISTP), Sep 2016, Heraklion, Greece. pp.85-99, &#x27E8;10.1007/978-3-319-45931-8_6&#x27E9;","raw_type":"Conference papers"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure","score":0.5899999737739563}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":19,"referenced_works":["https://openalex.org/W214166028","https://openalex.org/W1911778649","https://openalex.org/W1933020797","https://openalex.org/W2021702566","https://openalex.org/W2061243822","https://openalex.org/W2066664409","https://openalex.org/W2075698219","https://openalex.org/W2081544377","https://openalex.org/W2091236895","https://openalex.org/W2103651917","https://openalex.org/W2111404412","https://openalex.org/W2121035740","https://openalex.org/W2149519294","https://openalex.org/W2184912958","https://openalex.org/W2235612455","https://openalex.org/W2244222752","https://openalex.org/W2246506387","https://openalex.org/W2296135712","https://openalex.org/W2328639092"],"related_works":["https://openalex.org/W2309980522","https://openalex.org/W2187618570","https://openalex.org/W4252573951","https://openalex.org/W2902958991","https://openalex.org/W2801513872","https://openalex.org/W2516092834","https://openalex.org/W2615554433","https://openalex.org/W2007955754","https://openalex.org/W3084463301","https://openalex.org/W2804225172"],"abstract_inverted_index":{"We":[0,50,84],"describe":[1],"the":[2,11,36,52],"architecture":[3],"of":[4,39,57,80,92],"an":[5],"anomaly":[6],"detection":[7,18,58],"system":[8,34,54],"based":[9],"on":[10],"Hidden":[12],"Markov":[13],"Model":[14],"(HMM)":[15],"for":[16],"intrusion":[17],"in":[19,26,55],"Industrial":[20],"Control":[21],"Systems":[22],"(ICS)":[23],"and":[24,42,76,96],"especially":[25],"SCADA":[27],"systems":[28],"interconnected":[29],"using":[30,60],"TCP/IP.":[31],"The":[32],"proposed":[33,53],"exploits":[35],"unique":[37],"characteristics":[38],"ICS":[40],"networks":[41,75],"protocols":[43],"to":[44,72],"efficiently":[45],"detect":[46],"multiple":[47],"attack":[48,82],"vectors.":[49,83],"evaluate":[51],"terms":[56],"accuracy":[59],"as":[61],"reference":[62],"datasets":[63,70],"made":[64],"available":[65],"by":[66],"other":[67],"researchers.":[68],"These":[69],"refer":[71],"real":[73],"industrial":[74],"contain":[77],"a":[78,89],"variety":[79],"identified":[81],"benchmark":[85],"our":[86,99],"findings":[87],"against":[88],"large":[90],"set":[91],"machine":[93],"learning":[94],"algorithms":[95],"demonstrate":[97],"that":[98],"proposal":[100],"exhibits":[101],"superior":[102],"performance":[103],"characteristics.":[104]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":9},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":7},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":3},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
