{"id":"https://openalex.org/W3215963980","doi":"https://doi.org/10.1145/3454127.3456576","title":"A Review of Intrusion Detection Systems: Datasets and machine learning methods","display_name":"A Review of Intrusion Detection Systems: Datasets and machine learning methods","publication_year":2021,"publication_date":"2021-04-01","ids":{"openalex":"https://openalex.org/W3215963980","doi":"https://doi.org/10.1145/3454127.3456576","mag":"3215963980"},"language":"en","primary_location":{"id":"doi:10.1145/3454127.3456576","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3454127.3456576","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 4th International Conference on Networking, Information Systems &amp; Security","raw_type":"proceedings-article"},"type":"review","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5022031215","display_name":"Aouatif Arqane","orcid":"https://orcid.org/0000-0003-4499-7546"},"institutions":[{"id":"https://openalex.org/I4210125507","display_name":"Chouaib Doukkali University","ror":"https://ror.org/036kgyt43","country_code":"MA","type":"education","lineage":["https://openalex.org/I4210125507"]}],"countries":["MA"],"is_corresponding":true,"raw_author_name":"Aouatif Arqane","raw_affiliation_strings":["Chouaib Doukkali University, Morocco"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chouaib Doukkali University, Morocco","institution_ids":["https://openalex.org/I4210125507"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022830832","display_name":"Omar Boutkhoum","orcid":"https://orcid.org/0000-0002-0945-7520"},"institutions":[{"id":"https://openalex.org/I4210125507","display_name":"Chouaib Doukkali University","ror":"https://ror.org/036kgyt43","country_code":"MA","type":"education","lineage":["https://openalex.org/I4210125507"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Omar Boutkhoum","raw_affiliation_strings":["Chouaib Doukkali University, Morocco"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chouaib Doukkali University, Morocco","institution_ids":["https://openalex.org/I4210125507"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064262834","display_name":"Hicham Boukhriss","orcid":null},"institutions":[{"id":"https://openalex.org/I4210125507","display_name":"Chouaib Doukkali University","ror":"https://ror.org/036kgyt43","country_code":"MA","type":"education","lineage":["https://openalex.org/I4210125507"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Hicham Boukhriss","raw_affiliation_strings":["Chouaib Doukkali University, Morocco"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chouaib Doukkali University, Morocco","institution_ids":["https://openalex.org/I4210125507"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5073085685","display_name":"Abdelmajid El Moutaouakkil","orcid":null},"institutions":[{"id":"https://openalex.org/I4210125507","display_name":"Chouaib Doukkali University","ror":"https://ror.org/036kgyt43","country_code":"MA","type":"education","lineage":["https://openalex.org/I4210125507"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Abdelmajid El Moutaouakkil","raw_affiliation_strings":["Chouaib Doukkali University, Morocco"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chouaib Doukkali University, Morocco","institution_ids":["https://openalex.org/I4210125507"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5022031215"],"corresponding_institution_ids":["https://openalex.org/I4210125507"],"apc_list":null,"apc_paid":null,"fwci":0.8006,"has_fulltext":false,"cited_by_count":8,"citation_normalized_percentile":{"value":0.75360798,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.8567745685577393},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.817258358001709},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.536204993724823},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5012187957763672},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.47851717472076416},{"id":"https://openalex.org/keywords/intrusion","display_name":"Intrusion","score":0.4554866850376129},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.43447935581207275},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4301651120185852},{"id":"https://openalex.org/keywords/cyber-threats","display_name":"Cyber threats","score":0.4278463125228882},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.3417028486728668}],"concepts":[{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.8567745685577393},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.817258358001709},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.536204993724823},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5012187957763672},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.47851717472076416},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.4554866850376129},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.43447935581207275},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4301651120185852},{"id":"https://openalex.org/C3018725008","wikidata":"https://www.wikidata.org/wiki/Q4071928","display_name":"Cyber threats","level":2,"score":0.4278463125228882},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.3417028486728668},{"id":"https://openalex.org/C17409809","wikidata":"https://www.wikidata.org/wiki/Q161764","display_name":"Geochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3454127.3456576","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3454127.3456576","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 4th International Conference on Networking, Information Systems &amp; Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure","score":0.6600000262260437}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":19,"referenced_works":["https://openalex.org/W2099940443","https://openalex.org/W2794400414","https://openalex.org/W2913975235","https://openalex.org/W2921871306","https://openalex.org/W2926367029","https://openalex.org/W2968414504","https://openalex.org/W3006708276","https://openalex.org/W3011747232","https://openalex.org/W3017080938","https://openalex.org/W3017217726","https://openalex.org/W3045661671","https://openalex.org/W3047793363","https://openalex.org/W3087196177","https://openalex.org/W3087417123","https://openalex.org/W3094908868","https://openalex.org/W3099461454","https://openalex.org/W3128434951","https://openalex.org/W4230154166","https://openalex.org/W4242552899"],"related_works":["https://openalex.org/W2133389611","https://openalex.org/W2061466315","https://openalex.org/W2376886931","https://openalex.org/W2010561419","https://openalex.org/W2374845301","https://openalex.org/W2351448539","https://openalex.org/W1977863481","https://openalex.org/W2384741105","https://openalex.org/W3157271777","https://openalex.org/W2377372927"],"abstract_inverted_index":{"At":[0],"the":[1,53,59,73,90,95,113,124,145,153],"present":[2],"time,":[3],"Security":[4],"is":[5],"a":[6],"crucial":[7],"issue":[8],"for":[9,66,116],"all":[10],"organizations":[11],"and":[12,44,69,81,93,109],"companies,":[13],"because":[14,119],"intruders":[15],"are":[16],"constantly":[17],"developing":[18],"new":[19,39],"techniques":[20,76],"to":[21,25,41,57,88,132,151],"infiltrate":[22],"their":[23,156],"infrastructure":[24],"steal":[26],"or":[27],"manipulate":[28],"sensitive":[29],"data.":[30],"Thus,":[31],"Intrusion":[32],"Detection":[33],"System":[34],"(IDS)":[35],"has":[36],"emerged":[37],"as":[38],"technology":[40],"protect":[42],"networks":[43],"systems":[45,63],"against":[46],"suspicious":[47,67],"activities.":[48],"Numerous":[49],"cybersecurity":[50,140],"experts":[51,148],"highlight":[52,144],"importance":[54],"of":[55,62,98,106,126,155],"IDS":[56],"strength":[58],"defensive":[60],"capacities":[61],"by":[64],"alerting":[65],"activities":[68],"malicious":[70,127],"attacks.":[71],"Over":[72],"years,":[74],"many":[75],"like":[77],"Machine":[78],"learning":[79],"(ML)":[80],"Deep":[82],"Learning":[83],"(DL)":[84],"have":[85],"been":[86],"used":[87,115],"increase":[89],"detection":[91],"accuracy":[92],"reduce":[94],"false":[96],"alerts":[97],"IDSs.":[99],"This":[100],"survey":[101],"paper":[102],"presents":[103],"an":[104],"overview":[105],"some":[107,137],"ML":[108],"DL":[110],"algorithms":[111,121],"among":[112],"most":[114],"IDS.":[117],"Additionally,":[118],"these":[120],"depend":[122],"on":[123],"characteristics":[125],"events":[128],"stored":[129],"in":[130],"datasets":[131],"identify":[133],"anomalies,":[134],"we":[135,143],"list":[136],"publicly":[138],"available":[139],"datasets.":[141],"Furthermore,":[142],"challenges":[146],"that":[147],"must":[149],"overcome":[150],"enhance":[152],"performance":[154],"methods.":[157]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-25T08:17:42.794288","created_date":"2025-10-10T00:00:00"}
