{"id":"https://openalex.org/W4378373689","doi":"https://doi.org/10.1109/isdfs58141.2023.10131880","title":"Network Anomaly Detection Using NetFlow and Network Automation","display_name":"Network Anomaly Detection Using NetFlow and Network Automation","publication_year":2023,"publication_date":"2023-05-11","ids":{"openalex":"https://openalex.org/W4378373689","doi":"https://doi.org/10.1109/isdfs58141.2023.10131880"},"language":"en","primary_location":{"id":"doi:10.1109/isdfs58141.2023.10131880","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isdfs58141.2023.10131880","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 11th International Symposium on Digital Forensics and Security (ISDFS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5092023758","display_name":"Anthony Ni\u00f1o S. Aquino","orcid":null},"institutions":[{"id":"https://openalex.org/I95350115","display_name":"Technological Institute of the Philippines","ror":"https://ror.org/02p79p790","country_code":"PH","type":"education","lineage":["https://openalex.org/I95350115"]}],"countries":["PH"],"is_corresponding":true,"raw_author_name":"Anthony Ni\u00f1o S. Aquino","raw_affiliation_strings":["Technological Institute of the Philippines,Graduate School,Quezon City,Philippines","Graduate School, Technological Institute of the Philippines, Quezon City, Philippines"],"affiliations":[{"raw_affiliation_string":"Technological Institute of the Philippines,Graduate School,Quezon City,Philippines","institution_ids":["https://openalex.org/I95350115"]},{"raw_affiliation_string":"Graduate School, Technological Institute of the Philippines, Quezon City, Philippines","institution_ids":["https://openalex.org/I95350115"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5067987211","display_name":"Alonica Villanueva","orcid":"https://orcid.org/0009-0003-4453-5103"},"institutions":[{"id":"https://openalex.org/I95350115","display_name":"Technological Institute of the Philippines","ror":"https://ror.org/02p79p790","country_code":"PH","type":"education","lineage":["https://openalex.org/I95350115"]}],"countries":["PH"],"is_corresponding":false,"raw_author_name":"Alonica R. Villanueva","raw_affiliation_strings":["Technological Institute of the Philippines,Graduate School,Quezon City,Philippines","Graduate School, Technological Institute of the Philippines, Quezon City, Philippines"],"affiliations":[{"raw_affiliation_string":"Technological Institute of the Philippines,Graduate School,Quezon City,Philippines","institution_ids":["https://openalex.org/I95350115"]},{"raw_affiliation_string":"Graduate School, Technological Institute of the Philippines, Quezon City, Philippines","institution_ids":["https://openalex.org/I95350115"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5092023758"],"corresponding_institution_ids":["https://openalex.org/I95350115"],"apc_list":null,"apc_paid":null,"fwci":0.2009,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.46624234,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/netflow","display_name":"NetFlow","score":0.9901669025421143},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.684857964515686},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.6592329144477844},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.6405214071273804},{"id":"https://openalex.org/keywords/network-monitoring","display_name":"Network monitoring","score":0.507996141910553},{"id":"https://openalex.org/keywords/network-management-station","display_name":"Network management station","score":0.43068087100982666},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.4284323751926422},{"id":"https://openalex.org/keywords/network-traffic-control","display_name":"Network traffic control","score":0.42512619495391846},{"id":"https://openalex.org/keywords/networking-hardware","display_name":"Networking hardware","score":0.4136629104614258},{"id":"https://openalex.org/keywords/automation","display_name":"Automation","score":0.41079646348953247},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.32018184661865234},{"id":"https://openalex.org/keywords/network-architecture","display_name":"Network architecture","score":0.2584325075149536},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.19015443325042725},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.16816261410713196},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.15202596783638}],"concepts":[{"id":"https://openalex.org/C188067584","wikidata":"https://www.wikidata.org/wiki/Q219363","display_name":"NetFlow","level":2,"score":0.9901669025421143},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.684857964515686},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.6592329144477844},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.6405214071273804},{"id":"https://openalex.org/C81877898","wikidata":"https://www.wikidata.org/wiki/Q1965787","display_name":"Network monitoring","level":2,"score":0.507996141910553},{"id":"https://openalex.org/C16986412","wikidata":"https://www.wikidata.org/wiki/Q918419","display_name":"Network management station","level":3,"score":0.43068087100982666},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.4284323751926422},{"id":"https://openalex.org/C201100257","wikidata":"https://www.wikidata.org/wiki/Q393287","display_name":"Network traffic control","level":3,"score":0.42512619495391846},{"id":"https://openalex.org/C159631557","wikidata":"https://www.wikidata.org/wiki/Q1546066","display_name":"Networking hardware","level":2,"score":0.4136629104614258},{"id":"https://openalex.org/C115901376","wikidata":"https://www.wikidata.org/wiki/Q184199","display_name":"Automation","level":2,"score":0.41079646348953247},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.32018184661865234},{"id":"https://openalex.org/C193415008","wikidata":"https://www.wikidata.org/wiki/Q639681","display_name":"Network architecture","level":2,"score":0.2584325075149536},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.19015443325042725},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.16816261410713196},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.15202596783638},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isdfs58141.2023.10131880","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isdfs58141.2023.10131880","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 11th International Symposium on Digital Forensics and Security (ISDFS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W26074071","https://openalex.org/W2003883850","https://openalex.org/W2400071878","https://openalex.org/W2554587807","https://openalex.org/W2742721505","https://openalex.org/W2761434285","https://openalex.org/W2798340389","https://openalex.org/W2902764283","https://openalex.org/W2917409084","https://openalex.org/W2948019709","https://openalex.org/W2971981837","https://openalex.org/W2996864509","https://openalex.org/W2997270780","https://openalex.org/W2998251512","https://openalex.org/W3093652512","https://openalex.org/W3160450178","https://openalex.org/W3175570601","https://openalex.org/W4205711033","https://openalex.org/W4281568696","https://openalex.org/W4283659829","https://openalex.org/W4285327829","https://openalex.org/W6601098373","https://openalex.org/W6729803391","https://openalex.org/W6763362507"],"related_works":["https://openalex.org/W2336419978","https://openalex.org/W3184048398","https://openalex.org/W2185542535","https://openalex.org/W3002744051","https://openalex.org/W3027309809","https://openalex.org/W1135722627","https://openalex.org/W2001320494","https://openalex.org/W2379371707","https://openalex.org/W2385694529","https://openalex.org/W4378373689"],"abstract_inverted_index":{"NetFlow":[0],"is":[1,15],"a":[2],"Cisco":[3,23],"proprietary":[4],"protocol":[5,28],"that":[6,40],"can":[7,41,63],"be":[8,42,64],"useful":[9,43],"other":[10],"than":[11],"network":[12,37,47,59,84,97,101],"monitoring.":[13],"It":[14,52],"available":[16],"as":[17,74],"an":[18],"embedded":[19],"system":[20],"in":[21],"most":[22],"routers":[24],"and":[25,35,49,57],"switches.":[26],"This":[27],"provides":[29],"the":[30,80,83,94],"ability":[31],"to":[32,78],"collect":[33],"ingress":[34],"egress":[36],"traffic":[38,60,85],"statistics":[39],"for":[44],"detection":[45,54],"of":[46,55,82],"anomaly":[48,89],"subsequent":[50],"defense.":[51],"allows":[53],"unusual":[56],"suspicious":[58],"conditions":[61],"which":[62],"characterized":[65],"based":[66],"on":[67],"its":[68],"communication":[69],"behavior.":[70],"Network":[71,88],"automation":[72],"such":[73],"ansible":[75],"was":[76,90],"used":[77],"automate":[79],"collection":[81],"using":[86],"NetFlow.":[87],"detected":[91],"by":[92],"comparing":[93],"baseline":[95],"normal":[96],"operation":[98],"from":[99],"abnormal":[100],"operation.":[102]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
