{"id":"https://openalex.org/W2143305710","doi":"https://doi.org/10.1109/icsmc.2007.4414006","title":"A flow based approach for SSH traffic detection","display_name":"A flow based approach for SSH traffic detection","publication_year":2007,"publication_date":"2007-10-01","ids":{"openalex":"https://openalex.org/W2143305710","doi":"https://doi.org/10.1109/icsmc.2007.4414006","mag":"2143305710"},"language":"en","primary_location":{"id":"doi:10.1109/icsmc.2007.4414006","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icsmc.2007.4414006","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2007 IEEE International Conference on Systems, Man and Cybernetics","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5064562846","display_name":"Riyad Alshammari","orcid":"https://orcid.org/0000-0002-0529-2458"},"institutions":[{"id":"https://openalex.org/I129902397","display_name":"Dalhousie University","ror":"https://ror.org/01e6qks80","country_code":"CA","type":"education","lineage":["https://openalex.org/I129902397"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Riyad Alshammari","raw_affiliation_strings":["Faculty of Computer Science, Dalhousie University, Halifax, NS, Canada","Dalhousie University Halifax"],"affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, Dalhousie University, Halifax, NS, Canada","institution_ids":["https://openalex.org/I129902397"]},{"raw_affiliation_string":"Dalhousie University Halifax","institution_ids":["https://openalex.org/I129902397"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5008462534","display_name":"A. Nur Zincir\u2010Heywood","orcid":"https://orcid.org/0000-0003-2796-7265"},"institutions":[{"id":"https://openalex.org/I129902397","display_name":"Dalhousie University","ror":"https://ror.org/01e6qks80","country_code":"CA","type":"education","lineage":["https://openalex.org/I129902397"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"A. Nur Zincir-Heywood","raw_affiliation_strings":["Faculty of Computer Science, Dalhousie University, Halifax, NS, Canada"],"affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, Dalhousie University, Halifax, NS, Canada","institution_ids":["https://openalex.org/I129902397"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5064562846"],"corresponding_institution_ids":["https://openalex.org/I129902397"],"apc_list":null,"apc_paid":null,"fwci":7.9789,"has_fulltext":false,"cited_by_count":60,"citation_normalized_percentile":{"value":0.97313222,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"296","last_page":"301"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/payload","display_name":"Payload (computing)","score":0.802800714969635},{"id":"https://openalex.org/keywords/adaboost","display_name":"AdaBoost","score":0.7610695362091064},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7098206281661987},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.6588553190231323},{"id":"https://openalex.org/keywords/false-positive-rate","display_name":"False positive rate","score":0.4527882933616638},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.45165032148361206},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4210284352302551},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.32881754636764526},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.31435614824295044},{"id":"https://openalex.org/keywords/support-vector-machine","display_name":"Support vector machine","score":0.2160005271434784},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.14568665623664856},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.12867122888565063}],"concepts":[{"id":"https://openalex.org/C134066672","wikidata":"https://www.wikidata.org/wiki/Q1424639","display_name":"Payload (computing)","level":3,"score":0.802800714969635},{"id":"https://openalex.org/C141404830","wikidata":"https://www.wikidata.org/wiki/Q2823869","display_name":"AdaBoost","level":3,"score":0.7610695362091064},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7098206281661987},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.6588553190231323},{"id":"https://openalex.org/C95922358","wikidata":"https://www.wikidata.org/wiki/Q5432725","display_name":"False positive rate","level":2,"score":0.4527882933616638},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.45165032148361206},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4210284352302551},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.32881754636764526},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.31435614824295044},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.2160005271434784},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.14568665623664856},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.12867122888565063}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icsmc.2007.4414006","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icsmc.2007.4414006","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2007 IEEE International Conference on Systems, Man and Cybernetics","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9","score":0.44999998807907104}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":27,"referenced_works":["https://openalex.org/W149529048","https://openalex.org/W1521553548","https://openalex.org/W1540371141","https://openalex.org/W1670263352","https://openalex.org/W1849161695","https://openalex.org/W1993028889","https://openalex.org/W1995945562","https://openalex.org/W2006607452","https://openalex.org/W2012095206","https://openalex.org/W2073089243","https://openalex.org/W2118020653","https://openalex.org/W2119271160","https://openalex.org/W2121973001","https://openalex.org/W2122226347","https://openalex.org/W2133473417","https://openalex.org/W2134632326","https://openalex.org/W2137555637","https://openalex.org/W2145073242","https://openalex.org/W2148035254","https://openalex.org/W2751318774","https://openalex.org/W4255738146","https://openalex.org/W4255918660","https://openalex.org/W4312681280","https://openalex.org/W6639048092","https://openalex.org/W6679864962","https://openalex.org/W6681651645","https://openalex.org/W6980278418"],"related_works":["https://openalex.org/W2364921833","https://openalex.org/W2302028273","https://openalex.org/W1525643724","https://openalex.org/W2067938758","https://openalex.org/W2314307679","https://openalex.org/W2382623646","https://openalex.org/W3087771547","https://openalex.org/W2003125512","https://openalex.org/W2143305710","https://openalex.org/W2413122674"],"abstract_inverted_index":{"The":[0],"basic":[1],"objective":[2],"of":[3,11,50,63,70],"this":[4,118],"work":[5],"is":[6,38,97],"to":[7,40,44,87,99],"assess":[8],"the":[9,41],"utility":[10],"two":[12],"supervised":[13],"learning":[14,56],"algorithms":[15],"AdaBoost":[16],"and":[17,34,65,114],"RIPPER":[18,84],"for":[19,54],"classifying":[20],"SSH":[21,101],"traffic":[22,42,47,102],"from":[23],"log":[24],"files":[25],"without":[26,106],"using":[27,75,107],"features":[28,108],"such":[29,109],"as":[30,46,110],"payload,":[31,111],"IP":[32,112],"addresses":[33,113],"source/destination":[35,115],"ports.":[36],"Pre-processing":[37],"applied":[39],"data":[43],"express":[45],"flows.":[48],"Results":[49],"10-fold":[51],"cross":[52],"validation":[53],"each":[55],"algorithm":[57],"indicate":[58],"that":[59],"a":[60,66,120],"detection":[61],"rate":[62,69],"99%":[64],"false":[67],"positive":[68],"0.7%":[71],"can":[72],"be":[73],"achieved":[74],"RIPPER.":[76],"Moreover,":[77],"promising":[78],"preliminary":[79],"results":[80],"were":[81],"obtained":[82],"when":[83,124],"was":[85,91],"employed":[86],"identify":[88],"which":[89],"service":[90],"running":[92],"over":[93],"SSH.":[94],"Thus,":[95],"it":[96],"possible":[98],"detect":[100],"with":[103],"high":[104],"accuracy":[105],"ports,":[116],"where":[117],"represents":[119],"particularly":[121],"useful":[122],"characteristic":[123],"requiring":[125],"generic,":[126],"scalable":[127],"solutions.":[128]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":4},{"year":2018,"cited_by_count":6},{"year":2017,"cited_by_count":3},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":5},{"year":2014,"cited_by_count":2},{"year":2013,"cited_by_count":6},{"year":2012,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
