{"id":"https://openalex.org/W1965189448","doi":"https://doi.org/10.1109/icc.2012.6364527","title":"An improved Hidden Markov Model for anomaly detection using frequent common patterns","display_name":"An improved Hidden Markov Model for anomaly detection using frequent common patterns","publication_year":2012,"publication_date":"2012-06-01","ids":{"openalex":"https://openalex.org/W1965189448","doi":"https://doi.org/10.1109/icc.2012.6364527","mag":"1965189448"},"language":"en","primary_location":{"id":"doi:10.1109/icc.2012.6364527","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icc.2012.6364527","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2012 IEEE International Conference on Communications (ICC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5113528630","display_name":"Afroza Sultana","orcid":"https://orcid.org/0009-0006-4136-5753"},"institutions":[{"id":"https://openalex.org/I105925353","display_name":"Concordia University Wisconsin","ror":"https://ror.org/04k83g518","country_code":"US","type":"education","lineage":["https://openalex.org/I105925353"]},{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA","US"],"is_corresponding":false,"raw_author_name":"Afroza Sultana","raw_affiliation_strings":["Software Behavioural Analysis Research Laboratory Department of Electrical and Computer Engineering, Concordia University, Canada","Software Behavioural Analysis Research Lab Department of Electrical and Computer Engineering Concordia University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Software Behavioural Analysis Research Laboratory Department of Electrical and Computer Engineering, Concordia University, Canada","institution_ids":["https://openalex.org/I60158472"]},{"raw_affiliation_string":"Software Behavioural Analysis Research Lab Department of Electrical and Computer Engineering Concordia University","institution_ids":["https://openalex.org/I105925353"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058884064","display_name":"Abdelwahab Hamou\u2010Lhadj","orcid":"https://orcid.org/0000-0002-3319-5006"},"institutions":[{"id":"https://openalex.org/I105925353","display_name":"Concordia University Wisconsin","ror":"https://ror.org/04k83g518","country_code":"US","type":"education","lineage":["https://openalex.org/I105925353"]},{"id":"https://openalex.org/I60158472","display_name":"Concordia University","ror":"https://ror.org/0420zvk78","country_code":"CA","type":"education","lineage":["https://openalex.org/I60158472"]}],"countries":["CA","US"],"is_corresponding":false,"raw_author_name":"Abdelwahab Hamou-Lhadj","raw_affiliation_strings":["Software Behavioural Analysis Research Laboratory Department of Electrical and Computer Engineering, Concordia University, Canada","Software Behavioural Analysis Research Lab Department of Electrical and Computer Engineering Concordia University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Software Behavioural Analysis Research Laboratory Department of Electrical and Computer Engineering, Concordia University, Canada","institution_ids":["https://openalex.org/I60158472"]},{"raw_affiliation_string":"Software Behavioural Analysis Research Lab Department of Electrical and Computer Engineering Concordia University","institution_ids":["https://openalex.org/I105925353"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5014912145","display_name":"Mario Couture","orcid":null},"institutions":[{"id":"https://openalex.org/I1297460800","display_name":"Defence Research and Development Canada","ror":"https://ror.org/00hgy8d33","country_code":"CA","type":"government","lineage":["https://openalex.org/I1297460800","https://openalex.org/I1336338359","https://openalex.org/I2802286613"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Mario Couture","raw_affiliation_strings":["Defense Research and Development Canada, Software Analysis and Robustness Group, Valcartier, QUE, Canada","Software Analysis and Robustness Group, Defense Research and Development Canada, Valcartier, QC, Canada"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Defense Research and Development Canada, Software Analysis and Robustness Group, Valcartier, QUE, Canada","institution_ids":["https://openalex.org/I1297460800"]},{"raw_affiliation_string":"Software Analysis and Robustness Group, Defense Research and Development Canada, Valcartier, QC, Canada","institution_ids":["https://openalex.org/I1297460800"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":2.6085,"has_fulltext":false,"cited_by_count":24,"citation_normalized_percentile":{"value":0.89541003,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1113","last_page":"1117"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hidden-markov-model","display_name":"Hidden Markov model","score":0.8900971412658691},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8479863405227661},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6610763669013977},{"id":"https://openalex.org/keywords/sort","display_name":"sort","score":0.6316499710083008},{"id":"https://openalex.org/keywords/trace","display_name":"TRACE (psycholinguistics)","score":0.6237417459487915},{"id":"https://openalex.org/keywords/system-call","display_name":"System call","score":0.6201791763305664},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.5976390838623047},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5902808308601379},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.5258379578590393},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4539213180541992},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.45254844427108765},{"id":"https://openalex.org/keywords/markov-model","display_name":"Markov model","score":0.44063591957092285},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.43476665019989014},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4233022630214691},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.34893476963043213},{"id":"https://openalex.org/keywords/markov-chain","display_name":"Markov chain","score":0.28892046213150024},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.08255934715270996}],"concepts":[{"id":"https://openalex.org/C23224414","wikidata":"https://www.wikidata.org/wiki/Q176769","display_name":"Hidden Markov model","level":2,"score":0.8900971412658691},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8479863405227661},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6610763669013977},{"id":"https://openalex.org/C88548561","wikidata":"https://www.wikidata.org/wiki/Q347599","display_name":"sort","level":2,"score":0.6316499710083008},{"id":"https://openalex.org/C75291252","wikidata":"https://www.wikidata.org/wiki/Q1315756","display_name":"TRACE (psycholinguistics)","level":2,"score":0.6237417459487915},{"id":"https://openalex.org/C2778579508","wikidata":"https://www.wikidata.org/wiki/Q722192","display_name":"System call","level":2,"score":0.6201791763305664},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5976390838623047},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5902808308601379},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.5258379578590393},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4539213180541992},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.45254844427108765},{"id":"https://openalex.org/C163836022","wikidata":"https://www.wikidata.org/wiki/Q6771326","display_name":"Markov model","level":3,"score":0.44063591957092285},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.43476665019989014},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4233022630214691},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.34893476963043213},{"id":"https://openalex.org/C98763669","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov chain","level":2,"score":0.28892046213150024},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.08255934715270996},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icc.2012.6364527","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icc.2012.6364527","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2012 IEEE International Conference on Communications (ICC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":31,"referenced_works":["https://openalex.org/W91862604","https://openalex.org/W1535668279","https://openalex.org/W1543388142","https://openalex.org/W1574503756","https://openalex.org/W1578367810","https://openalex.org/W1717533658","https://openalex.org/W1978845641","https://openalex.org/W2016070752","https://openalex.org/W2064806155","https://openalex.org/W2086469601","https://openalex.org/W2086699924","https://openalex.org/W2100215068","https://openalex.org/W2101916222","https://openalex.org/W2105594594","https://openalex.org/W2109969076","https://openalex.org/W2121227244","https://openalex.org/W2122646361","https://openalex.org/W2129860818","https://openalex.org/W2139731313","https://openalex.org/W2140190241","https://openalex.org/W2150484836","https://openalex.org/W2150847526","https://openalex.org/W2152448081","https://openalex.org/W2186428165","https://openalex.org/W3136767761","https://openalex.org/W6603716672","https://openalex.org/W6632547301","https://openalex.org/W6675021112","https://openalex.org/W6678277124","https://openalex.org/W6682481173","https://openalex.org/W7039235811"],"related_works":["https://openalex.org/W1996865198","https://openalex.org/W11100131","https://openalex.org/W2385758958","https://openalex.org/W2183313954","https://openalex.org/W1969635302","https://openalex.org/W1510894296","https://openalex.org/W2134386692","https://openalex.org/W1975539049","https://openalex.org/W1805274772","https://openalex.org/W2082284720"],"abstract_inverted_index":{"Host-based":[0],"intrusion":[1,24],"detection":[2,25,63],"techniques":[3,71],"are":[4,72],"needed":[5],"to":[6,46,166],"ensure":[7],"the":[8,40,43,48,68,73,77,92,99,103,118,133,138,160,167,174],"safety":[9],"and":[10],"security":[11],"of":[12,31,42,64,79,91,106,120,141],"software":[13],"systems,":[14],"especially,":[15],"if":[16],"these":[17],"systems":[18,26],"handle":[19],"sensitive":[20],"data.":[21],"Most":[22],"host-based":[23],"involve":[27],"building":[28],"some":[29],"sort":[30],"reference":[32],"models":[33,53,129],"offline,":[34],"usually":[35],"from":[36],"execution":[37],"traces":[38,139],"(in":[39],"absence":[41],"source":[44],"code),":[45],"characterize":[47],"system":[49],"healthy":[50],"behavior.":[51,66],"The":[52],"can":[54,158],"later":[55],"be":[56],"used":[57],"as":[58],"a":[59,152],"baseline":[60],"for":[61],"online":[62],"abnormal":[65],"Perhaps":[67],"most":[69],"popular":[70],"ones":[74],"based":[75,130],"on":[76,131,146],"use":[78],"Hidden":[80],"Markov":[81],"Models":[82],"(HMM).":[83],"These":[84],"techniques,":[85],"however,":[86],"require":[87],"long":[88],"training":[89,161],"time":[90,162],"models,":[93],"which":[94],"makes":[95],"them":[96],"computationally":[97],"infeasible,":[98],"main":[100],"reason":[101],"being":[102],"large":[104],"size":[105],"typical":[107],"traces.":[108],"In":[109,124],"this":[110],"paper,":[111],"we":[112,127],"propose":[113],"an":[114],"improved":[115],"HMM":[116,169],"using":[117],"concept":[119],"frequent":[121],"common":[122],"patterns.":[123],"other":[125],"words,":[126],"build":[128],"extracting":[132],"largest":[134],"n-grams":[135],"(patterns)":[136],"in":[137],"instead":[140],"taking":[142],"each":[143],"trace":[144],"event":[145],"its":[147],"own.":[148],"We":[149],"show":[150],"through":[151],"case":[153],"study":[154],"that":[155],"our":[156],"approach":[157],"reduce":[159],"by":[163],"31.96%-48.44%":[164],"compared":[165],"original":[168],"algorithms":[170],"while":[171],"keeping":[172],"almost":[173],"same":[175],"accuracy":[176],"rate.":[177]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":5},{"year":2018,"cited_by_count":3},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":3},{"year":2014,"cited_by_count":3},{"year":2013,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
