{"id":"https://openalex.org/W2616593274","doi":"https://doi.org/10.1109/tifs.2017.2705629","title":"Burstiness of Intrusion Detection Process: Empirical Evidence and a Modeling Approach","display_name":"Burstiness of Intrusion Detection Process: Empirical Evidence and a Modeling Approach","publication_year":2017,"publication_date":"2017-05-18","ids":{"openalex":"https://openalex.org/W2616593274","doi":"https://doi.org/10.1109/tifs.2017.2705629","mag":"2616593274"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2017.2705629","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2017.2705629","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/1707.03927","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5033809782","display_name":"Richard Harang","orcid":null},"institutions":[{"id":"https://openalex.org/I166416128","display_name":"DEVCOM Army Research Laboratory","ror":"https://ror.org/011hc8f90","country_code":"US","type":"government","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I166416128","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]},{"id":"https://openalex.org/I2799483119","display_name":"Society for Public Health Education","ror":"https://ror.org/03hqq4p77","country_code":"US","type":"other","lineage":["https://openalex.org/I2799483119"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Richard Harang","raw_affiliation_strings":["Sophos, Fairfax, VA, USA","U.S. Army Research Laboratory, Adelphi, MD, USA",", U.S. Army Research Laboratory, Adelphi, MD, USA"],"affiliations":[{"raw_affiliation_string":"Sophos, Fairfax, VA, USA","institution_ids":["https://openalex.org/I2799483119"]},{"raw_affiliation_string":"U.S. Army Research Laboratory, Adelphi, MD, USA","institution_ids":["https://openalex.org/I166416128"]},{"raw_affiliation_string":", U.S. Army Research Laboratory, Adelphi, MD, USA","institution_ids":["https://openalex.org/I166416128"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012477590","display_name":"Alexander Kott","orcid":"https://orcid.org/0000-0003-1147-9726"},"institutions":[{"id":"https://openalex.org/I166416128","display_name":"DEVCOM Army Research Laboratory","ror":"https://ror.org/011hc8f90","country_code":"US","type":"government","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I166416128","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alexander Kott","raw_affiliation_strings":["U.S. Army Research Laboratory, Adelphi, MD, USA",", U.S. Army Research Laboratory, Adelphi, MD, USA"],"affiliations":[{"raw_affiliation_string":"U.S. Army Research Laboratory, Adelphi, MD, USA","institution_ids":["https://openalex.org/I166416128"]},{"raw_affiliation_string":", U.S. Army Research Laboratory, Adelphi, MD, USA","institution_ids":["https://openalex.org/I166416128"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5033809782"],"corresponding_institution_ids":["https://openalex.org/I166416128","https://openalex.org/I2799483119"],"apc_list":null,"apc_paid":null,"fwci":0.2193,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.56576818,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":"12","issue":"10","first_page":"2348","last_page":"2359"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10064","display_name":"Complex Network Analysis Techniques","score":0.9976999759674072,"subfield":{"id":"https://openalex.org/subfields/3109","display_name":"Statistical and Nonlinear Physics"},"field":{"id":"https://openalex.org/fields/31","display_name":"Physics and Astronomy"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10574","display_name":"Crime Patterns and Interventions","score":0.9869999885559082,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/burstiness","display_name":"Burstiness","score":0.9911360144615173},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6862866878509521},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6636801958084106},{"id":"https://openalex.org/keywords/hidden-markov-model","display_name":"Hidden Markov model","score":0.5862947702407837},{"id":"https://openalex.org/keywords/markov-chain","display_name":"Markov chain","score":0.4743928909301758},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.44149357080459595},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4369357228279114},{"id":"https://openalex.org/keywords/markov-process","display_name":"Markov process","score":0.4137265086174011},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3585638105869293},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.33893194794654846},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.18862169981002808},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.15663102269172668},{"id":"https://openalex.org/keywords/statistics","display_name":"Statistics","score":0.14810997247695923},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.11135956645011902}],"concepts":[{"id":"https://openalex.org/C2781023610","wikidata":"https://www.wikidata.org/wiki/Q17006304","display_name":"Burstiness","level":3,"score":0.9911360144615173},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6862866878509521},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6636801958084106},{"id":"https://openalex.org/C23224414","wikidata":"https://www.wikidata.org/wiki/Q176769","display_name":"Hidden Markov model","level":2,"score":0.5862947702407837},{"id":"https://openalex.org/C98763669","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov chain","level":2,"score":0.4743928909301758},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.44149357080459595},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4369357228279114},{"id":"https://openalex.org/C159886148","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov process","level":2,"score":0.4137265086174011},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3585638105869293},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.33893194794654846},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.18862169981002808},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.15663102269172668},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.14810997247695923},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.11135956645011902},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1109/tifs.2017.2705629","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2017.2705629","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},{"id":"pmh:oai:arXiv.org:1707.03927","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1707.03927","pdf_url":"https://arxiv.org/pdf/1707.03927","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"mag:2616593274","is_oa":true,"landing_page_url":"http://arxiv.org/pdf/1707.03927.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"doi:10.48550/arxiv.1707.03927","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.1707.03927","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:1707.03927","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1707.03927","pdf_url":"https://arxiv.org/pdf/1707.03927","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320338295","display_name":"Army Research Laboratory","ror":"https://ror.org/011hc8f90"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W1511986666","https://openalex.org/W1887038067","https://openalex.org/W1949404224","https://openalex.org/W1965586806","https://openalex.org/W1969456244","https://openalex.org/W1969562629","https://openalex.org/W1970143540","https://openalex.org/W1972309850","https://openalex.org/W1973253288","https://openalex.org/W1985793456","https://openalex.org/W2005002286","https://openalex.org/W2006879182","https://openalex.org/W2011505318","https://openalex.org/W2016456216","https://openalex.org/W2031052047","https://openalex.org/W2037981185","https://openalex.org/W2040237110","https://openalex.org/W2042037139","https://openalex.org/W2077028504","https://openalex.org/W2084391800","https://openalex.org/W2089803230","https://openalex.org/W2103908937","https://openalex.org/W2110732075","https://openalex.org/W2115464714","https://openalex.org/W2120867648","https://openalex.org/W2134269391","https://openalex.org/W2144443219","https://openalex.org/W2145076372","https://openalex.org/W2148534890","https://openalex.org/W2149372699","https://openalex.org/W2164368775","https://openalex.org/W2282743468","https://openalex.org/W2588755944","https://openalex.org/W2903919837","https://openalex.org/W3033751064","https://openalex.org/W3103408694","https://openalex.org/W4232383088","https://openalex.org/W4237831889","https://openalex.org/W4388297583","https://openalex.org/W6639415379"],"related_works":["https://openalex.org/W2964308319","https://openalex.org/W1563456831","https://openalex.org/W92799952","https://openalex.org/W3201597800","https://openalex.org/W3101175853","https://openalex.org/W3209250328","https://openalex.org/W2157547297","https://openalex.org/W3024302202","https://openalex.org/W2038571076","https://openalex.org/W2562210893","https://openalex.org/W2903944587","https://openalex.org/W2000041166","https://openalex.org/W2023633440","https://openalex.org/W2585036375","https://openalex.org/W2094691793","https://openalex.org/W2783947262","https://openalex.org/W2741954253","https://openalex.org/W2906529926","https://openalex.org/W2528796102","https://openalex.org/W2359746616"],"abstract_inverted_index":{"We":[0,72,105],"analyze":[1],"sets":[2],"of":[3,11,20,32,42,59,76,109,136,158,162],"intrusion":[4,21,33],"detection":[5,22,34,153],"records":[6],"observed":[7,85,130,164],"on":[8,83],"the":[9,30,107,110,122,155,163],"networks":[10,37],"several":[12],"large,":[13],"nonresidential":[14],"organizations":[15],"protected":[16],"by":[17,63],"a":[18,39,88,134,173],"form":[19],"and":[23,51,119,168,176],"prevention":[24],"service.":[25],"Our":[26],"analyses":[27],"reveal":[28],"that":[29,54,121],"process":[31],"in":[35],"these":[36,77],"exhibits":[38],"significant":[40],"degree":[41],"burstiness":[43,50,165],"as":[44,46,133],"well":[45],"strong":[47],"memory,":[48],"with":[49,92,113],"memory":[52],"properties":[53,118],"are":[55,166],"comparable":[56],"to":[57,115,151],"those":[58],"natural":[60],"processes":[61],"driven":[62],"threshold":[64],"effects,":[65],"but":[66],"different":[67],"from":[68],"bursty":[69],"human":[70],"activities.":[71],"explore":[73],"time-series":[74],"models":[75],"observable":[78],"network":[79,131],"security":[80],"incidents":[81,132],"based":[82],"partially":[84],"data":[86],"using":[87,99],"hidden":[89,94],"Markov":[90,100],"model":[91,112,123],"restricted":[93],"states,":[95],"which":[96],"we":[97],"fit":[98],"Chain":[101],"Monte":[102],"Carlo":[103],"techniques.":[104],"examine":[106],"output":[108],"fitted":[111],"respect":[114],"its":[116],"statistical":[117],"demonstrate":[120],"adequately":[124],"accounts":[125],"for":[126,171],"intrinsic":[127],"\u201cbursting\u201d":[128],"within":[129],"result":[135],"alternation":[137],"between":[138],"two":[139],"or":[140],"more":[141],"stochastic":[142],"processes.":[143],"While":[144],"our":[145],"analysis":[146],"does":[147],"not":[148],"lead":[149],"directly":[150],"new":[152],"capabilities,":[154],"practical":[156],"implications":[157],"gaining":[159],"better":[160],"understanding":[161],"significant,":[167],"include":[169],"opportunities":[170],"quantifying":[172],"network's":[174],"risks":[175],"defensive":[177],"efforts.":[178]},"counts_by_year":[{"year":2019,"cited_by_count":1}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
