{"id":"https://openalex.org/W2127961541","doi":"https://doi.org/10.1109/cyber.2003.1253494","title":"Utilizing statistical characteristics of N-grams for intrusion detection","display_name":"Utilizing statistical characteristics of N-grams for intrusion detection","publication_year":2004,"publication_date":"2004-05-13","ids":{"openalex":"https://openalex.org/W2127961541","doi":"https://doi.org/10.1109/cyber.2003.1253494","mag":"2127961541"},"language":"en","primary_location":{"id":"doi:10.1109/cyber.2003.1253494","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cyber.2003.1253494","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings. 2003 International Conference on Cyberworlds","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5060042692","display_name":"Zhuowei Li","orcid":"https://orcid.org/0000-0003-4631-3531"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":true,"raw_author_name":"Li Zhuowei","raw_affiliation_strings":["School of Computer Engineering, Nanyang Technological University, Singapore","Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore#TAB#"],"affiliations":[{"raw_affiliation_string":"School of Computer Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]},{"raw_affiliation_string":"Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore#TAB#","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090590044","display_name":"A. Das","orcid":"https://orcid.org/0000-0002-5000-4451"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"A. Das","raw_affiliation_strings":["School of Computer Engineering, Nanyang Technological University, Singapore","Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore#TAB#"],"affiliations":[{"raw_affiliation_string":"School of Computer Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]},{"raw_affiliation_string":"Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore#TAB#","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5053883070","display_name":"Sukumar Nandi","orcid":"https://orcid.org/0000-0002-5869-1057"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"S. Nandi","raw_affiliation_strings":["School of Computer Engineering, Nanyang Technological University, Singapore","Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore#TAB#"],"affiliations":[{"raw_affiliation_string":"School of Computer Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]},{"raw_affiliation_string":"Sch. of Comput. Eng., Nanyang Technol. Univ., Singapore#TAB#","institution_ids":["https://openalex.org/I172675005"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5060042692"],"corresponding_institution_ids":["https://openalex.org/I172675005"],"apc_list":null,"apc_paid":null,"fwci":1.854,"has_fulltext":false,"cited_by_count":19,"citation_normalized_percentile":{"value":0.88276673,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":"6","issue":null,"first_page":"486","last_page":"493"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.8670761585235596},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7660752534866333},{"id":"https://openalex.org/keywords/flexibility","display_name":"Flexibility (engineering)","score":0.7202181816101074},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6872115731239319},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.6833226680755615},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.6338776350021362},{"id":"https://openalex.org/keywords/anomaly-based-intrusion-detection-system","display_name":"Anomaly-based intrusion detection system","score":0.6006404757499695},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5357434153556824},{"id":"https://openalex.org/keywords/statistical-model","display_name":"Statistical model","score":0.534224808216095},{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.45400357246398926},{"id":"https://openalex.org/keywords/statistical-analysis","display_name":"Statistical analysis","score":0.44470205903053284},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4339714050292969},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3711206316947937},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3240332007408142},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.17335787415504456},{"id":"https://openalex.org/keywords/statistics","display_name":"Statistics","score":0.1523711085319519},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.1352890431880951}],"concepts":[{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.8670761585235596},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7660752534866333},{"id":"https://openalex.org/C2780598303","wikidata":"https://www.wikidata.org/wiki/Q65921492","display_name":"Flexibility (engineering)","level":2,"score":0.7202181816101074},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6872115731239319},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.6833226680755615},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.6338776350021362},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.6006404757499695},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5357434153556824},{"id":"https://openalex.org/C114289077","wikidata":"https://www.wikidata.org/wiki/Q3284399","display_name":"Statistical model","level":2,"score":0.534224808216095},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.45400357246398926},{"id":"https://openalex.org/C2986587452","wikidata":"https://www.wikidata.org/wiki/Q938438","display_name":"Statistical analysis","level":2,"score":0.44470205903053284},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4339714050292969},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3711206316947937},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3240332007408142},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.17335787415504456},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.1523711085319519},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.1352890431880951},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cyber.2003.1253494","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cyber.2003.1253494","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings. 2003 International Conference on Cyberworlds","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6600000262260437,"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W14760367","https://openalex.org/W1561150890","https://openalex.org/W1583975142","https://openalex.org/W1941427975","https://openalex.org/W2011604665","https://openalex.org/W2070535792","https://openalex.org/W2106649514","https://openalex.org/W2129860818","https://openalex.org/W2155378438","https://openalex.org/W3136767761","https://openalex.org/W6600609758","https://openalex.org/W6633548646","https://openalex.org/W6634829514","https://openalex.org/W6675849491"],"related_works":["https://openalex.org/W2183313954","https://openalex.org/W1969635302","https://openalex.org/W3004832009","https://openalex.org/W3146948916","https://openalex.org/W2148459958","https://openalex.org/W2061466315","https://openalex.org/W2355532322","https://openalex.org/W2368329025","https://openalex.org/W3157271777","https://openalex.org/W1485296229"],"abstract_inverted_index":{"Information":[0],"and":[1,26,101,114,125,149],"infrastructure":[2],"security":[3,18],"is":[4,46,79,147],"a":[5,53,72,82,90],"serious":[6],"issue":[7],"of":[8,15,40,61,71,84,87,93,98,104,127],"global":[9],"concern.":[10],"As":[11],"the":[12,68,77,96,102,105,119,123,128,133,141],"last":[13],"line":[14],"defense":[16],"for":[17,42],"infrastructure,":[19],"intrusion":[20,34],"detection":[21,35,145],"techniques":[22],"are":[23,64,108,130],"paid":[24],"more":[25,27],"attention.":[28],"In":[29],"this":[30],"paper,":[31],"one":[32],"anomaly-based":[33],"technique":[36,146],"(ScanAID:":[37],"Statistical":[38],"ChAracteristics":[39],"N-grams":[41],"Anomaly-based":[43],"Intrusion":[44],"Detection)":[45],"proposed":[47,142],"to":[48,66,110,157],"detect":[49],"intrusive":[50],"behaviors":[51,70],"in":[52,59,75],"computer":[54],"system.":[55],"The":[56],"statistical":[57,143],"properties":[58],"sequences":[60],"system":[62],"calls":[63],"abstracted":[65],"model":[67,78,129],"normal":[69],"privileged":[73],"process,":[74],"which":[76],"characterized":[80],"by":[81,132],"vector":[83],"anomaly":[85,144],"values":[86],"N-grams.":[88],"With":[89],"reasonable":[91],"definition":[92],"efficiency":[94,126],"parameter,":[95],"length":[97],"an":[99,112],"N-gram":[100],"size":[103],"training":[106],"dataset":[107],"optimized":[109],"get":[111],"efficient":[113],"compact":[115],"model.":[116],"Then,":[117],"with":[118],"optimal":[120],"modeling":[121],"parameters,":[122],"flexibility":[124],"evaluated":[131],"ROC":[134],"curves.":[135],"Our":[136],"experimental":[137],"results":[138],"show":[139],"that":[140],"promising":[148],"deserves":[150],"further":[151],"research":[152],"(such":[153],"as":[154],"applying":[155],"it":[156],"network":[158],"environments).":[159]},"counts_by_year":[{"year":2018,"cited_by_count":2},{"year":2013,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
