{"id":"https://openalex.org/W2783810000","doi":"https://doi.org/10.1109/bigdata.2017.8258164","title":"A hybrid model for anomaly-based intrusion detection in SCADA networks","display_name":"A hybrid model for anomaly-based intrusion detection in SCADA networks","publication_year":2017,"publication_date":"2017-12-01","ids":{"openalex":"https://openalex.org/W2783810000","doi":"https://doi.org/10.1109/bigdata.2017.8258164","mag":"2783810000"},"language":"en","primary_location":{"id":"doi:10.1109/bigdata.2017.8258164","is_oa":false,"landing_page_url":"https://doi.org/10.1109/bigdata.2017.8258164","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2017 IEEE International Conference on Big Data (Big Data)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5091751624","display_name":"Imtiaz Ullah","orcid":"https://orcid.org/0000-0002-2952-7215"},"institutions":[{"id":"https://openalex.org/I39470171","display_name":"University of Ontario Institute of Technology","ror":"https://ror.org/016zre027","country_code":"CA","type":"education","lineage":["https://openalex.org/I39470171"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Imtiaz Ullah","raw_affiliation_strings":["Department of Electrical Computer and Software Engineering, University of Ontario Institute of Technology, Oshawa, ON, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Electrical Computer and Software Engineering, University of Ontario Institute of Technology, Oshawa, ON, Canada","institution_ids":["https://openalex.org/I39470171"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5011840659","display_name":"Qusay H. Mahmoud","orcid":"https://orcid.org/0000-0003-0472-5757"},"institutions":[{"id":"https://openalex.org/I39470171","display_name":"University of Ontario Institute of Technology","ror":"https://ror.org/016zre027","country_code":"CA","type":"education","lineage":["https://openalex.org/I39470171"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Qusay H. Mahmoud","raw_affiliation_strings":["Department of Electrical Computer and Software Engineering, University of Ontario Institute of Technology, Oshawa, ON, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Electrical Computer and Software Engineering, University of Ontario Institute of Technology, Oshawa, ON, Canada","institution_ids":["https://openalex.org/I39470171"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5091751624"],"corresponding_institution_ids":["https://openalex.org/I39470171"],"apc_list":null,"apc_paid":null,"fwci":4.3511,"has_fulltext":false,"cited_by_count":63,"citation_normalized_percentile":{"value":0.95182623,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"2160","last_page":"2167"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.996999979019165,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/scada","display_name":"SCADA","score":0.9685126543045044},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.8301404714584351},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7913902997970581},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6932752132415771},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.574669361114502},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.5114537477493286},{"id":"https://openalex.org/keywords/anomaly-based-intrusion-detection-system","display_name":"Anomaly-based intrusion detection system","score":0.4403042793273926},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4345545768737793},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.3657398223876953},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3595013916492462},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3230482041835785},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.1930798888206482},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.1176404356956482}],"concepts":[{"id":"https://openalex.org/C113863187","wikidata":"https://www.wikidata.org/wiki/Q17498","display_name":"SCADA","level":2,"score":0.9685126543045044},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.8301404714584351},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7913902997970581},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6932752132415771},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.574669361114502},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.5114537477493286},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.4403042793273926},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4345545768737793},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3657398223876953},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3595013916492462},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3230482041835785},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.1930798888206482},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.1176404356956482},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/bigdata.2017.8258164","is_oa":false,"landing_page_url":"https://doi.org/10.1109/bigdata.2017.8258164","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2017 IEEE International Conference on Big Data (Big Data)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":27,"referenced_works":["https://openalex.org/W38537450","https://openalex.org/W181041240","https://openalex.org/W260232723","https://openalex.org/W1553347404","https://openalex.org/W1579904204","https://openalex.org/W1863648891","https://openalex.org/W1983488804","https://openalex.org/W1995126785","https://openalex.org/W2013330146","https://openalex.org/W2061243822","https://openalex.org/W2085305295","https://openalex.org/W2091236895","https://openalex.org/W2091770693","https://openalex.org/W2100533733","https://openalex.org/W2127918528","https://openalex.org/W2133590498","https://openalex.org/W2133990480","https://openalex.org/W2154107003","https://openalex.org/W2167710876","https://openalex.org/W2253724380","https://openalex.org/W2522248003","https://openalex.org/W2604105233","https://openalex.org/W2751910234","https://openalex.org/W3140539032","https://openalex.org/W6601553728","https://openalex.org/W6607494380","https://openalex.org/W7047813972"],"related_works":["https://openalex.org/W2337148208","https://openalex.org/W3004832009","https://openalex.org/W1971929717","https://openalex.org/W3036013726","https://openalex.org/W1724519426","https://openalex.org/W2061466315","https://openalex.org/W2355532322","https://openalex.org/W2368329025","https://openalex.org/W3157271777","https://openalex.org/W1485296229"],"abstract_inverted_index":{"Supervisory":[0],"Control":[1],"and":[2,8,95,107,126,151,154,158],"Data":[3],"Acquisition":[4],"(SCADA)":[5],"systems":[6],"complexity":[7,153],"interconnectivity":[9],"increase":[10],"in":[11,54,75,89,100,147],"recent":[12],"years":[13],"have":[14,25],"exposed":[15],"the":[16,62,101,123,149],"SCADA":[17,55,76,90],"networks":[18,56,91],"to":[19,36],"numerous":[20],"potential":[21],"vulnerabilities.":[22],"Several":[23],"studies":[24],"shown":[26],"that":[27,139],"anomaly-based":[28,51,72,86],"Intrusion":[29],"Detection":[30],"Systems":[31],"(IDS)":[32],"achieves":[33],"improved":[34,156],"performance":[35],"identify":[37],"unknown":[38],"or":[39],"zero-day":[40],"attacks.":[41],"In":[42,61],"this":[43],"paper,":[44],"we":[45,65,79],"propose":[46],"a":[47,67,81,144],"hybrid":[48,69],"model":[49,70,84,142,166],"for":[50,71,85,172],"intrusion":[52,73,87],"detection":[53,74,88,159],"using":[57,115],"machine":[58],"learning":[59],"approach.":[60],"first":[63],"part,":[64],"present":[66,80],"robust":[68],"networks.":[77],"Finally,":[78],"feature":[82],"selection":[83],"by":[92],"removing":[93],"redundant":[94],"irrelevant":[96],"features.":[97],"Irrelevant":[98],"features":[99],"dataset":[102,120],"can":[103],"affect":[104],"modeling":[105],"power":[106],"reduce":[108],"predictive":[109],"accuracy.":[110],"These":[111],"models":[112],"were":[113],"evaluated":[114],"an":[116],"industrial":[117],"control":[118],"system":[119],"developed":[121],"at":[122],"Distributed":[124],"Analytics":[125],"Security":[127],"Institute":[128],"Mississippi":[129],"State":[130],"University":[131],"Starkville,":[132],"MS,":[133],"USA.":[134],"The":[135,161],"experimental":[136],"results":[137],"show":[138],"our":[140,164],"proposed":[141,165],"has":[143],"key":[145],"effect":[146],"reducing":[148],"time":[150],"computational":[152],"achieved":[155],"accuracy":[157,162],"rate.":[160],"of":[163],"was":[167],"measured":[168],"as":[169],"99.5":[170],"%":[171],"specific-attack-labeled.":[173]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":11},{"year":2022,"cited_by_count":11},{"year":2021,"cited_by_count":12},{"year":2020,"cited_by_count":11},{"year":2019,"cited_by_count":8},{"year":2018,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
