{"id":"https://openalex.org/W2887492447","doi":"https://doi.org/10.1109/icc.2018.8422622","title":"An Adaptive Real-Time Architecture for Zero-Day Threat Detection","display_name":"An Adaptive Real-Time Architecture for Zero-Day Threat Detection","publication_year":2018,"publication_date":"2018-05-01","ids":{"openalex":"https://openalex.org/W2887492447","doi":"https://doi.org/10.1109/icc.2018.8422622","mag":"2887492447"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/icc.2018.8422622","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007963200","display_name":"Antonio Gonzalez Pastana Lobato","orcid":"https://orcid.org/0000-0002-1544-2333"},"institutions":[{"id":"https://openalex.org/I122140584","display_name":"Universidade Federal do Rio de Janeiro","ror":"https://ror.org/03490as77","country_code":"BR","type":"education","lineage":["https://openalex.org/I122140584"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Antonio Gonzalez Pastana Lobato","raw_affiliation_strings":["Universidade Federal do Rio de Janeiro, GTA/COPPE/UFRJ, Rio de Janeiro, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Rio de Janeiro, GTA/COPPE/UFRJ, Rio de Janeiro, Brazil","institution_ids":["https://openalex.org/I122140584"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025235658","display_name":"Martin Andreoni Lopez","orcid":"https://orcid.org/0000-0002-4170-4341"},"institutions":[{"id":"https://openalex.org/I4210159731","display_name":"Laboratoire de Recherche en Informatique de Paris 6","ror":"https://ror.org/05krcen59","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I39804081","https://openalex.org/I4210159245","https://openalex.org/I4210159731"]},{"id":"https://openalex.org/I39804081","display_name":"Sorbonne Universit\u00e9","ror":"https://ror.org/02en5vm52","country_code":"FR","type":"education","lineage":["https://openalex.org/I39804081"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Martin Andreoni Lopez","raw_affiliation_strings":["Sorbonne Universit\u00e9s, Laboratoire d'Informatique de Paris 6, Paris, France"],"affiliations":[{"raw_affiliation_string":"Sorbonne Universit\u00e9s, Laboratoire d'Informatique de Paris 6, Paris, France","institution_ids":["https://openalex.org/I4210159731","https://openalex.org/I39804081"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022723490","display_name":"Igor Jochem Sanz","orcid":null},"institutions":[{"id":"https://openalex.org/I122140584","display_name":"Universidade Federal do Rio de Janeiro","ror":"https://ror.org/03490as77","country_code":"BR","type":"education","lineage":["https://openalex.org/I122140584"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Igor Jochem Sanz","raw_affiliation_strings":["Universidade Federal do Rio de Janeiro, GTA/COPPE/UFRJ, Rio de Janeiro, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Rio de Janeiro, GTA/COPPE/UFRJ, Rio de Janeiro, Brazil","institution_ids":["https://openalex.org/I122140584"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5016892225","display_name":"\u00c1lvaro A. C\u00e1rdenas","orcid":"https://orcid.org/0000-0002-5142-9750"},"institutions":[{"id":"https://openalex.org/I162577319","display_name":"The University of Texas at Dallas","ror":"https://ror.org/049emcs32","country_code":"US","type":"education","lineage":["https://openalex.org/I162577319"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alvaro A. Cardenas","raw_affiliation_strings":["University of Texas at Dallas, Cy-Phy Security Lab, Texas, USA"],"affiliations":[{"raw_affiliation_string":"University of Texas at Dallas, Cy-Phy Security Lab, Texas, USA","institution_ids":["https://openalex.org/I162577319"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026700596","display_name":"Otto Carlos M. B. Duarte","orcid":"https://orcid.org/0000-0002-6642-4100"},"institutions":[{"id":"https://openalex.org/I122140584","display_name":"Universidade Federal do Rio de Janeiro","ror":"https://ror.org/03490as77","country_code":"BR","type":"education","lineage":["https://openalex.org/I122140584"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Otto Carlos M. B. Duarte","raw_affiliation_strings":["Universidade Federal do Rio de Janeiro, GTA/COPPE/UFRJ, Rio de Janeiro, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Rio de Janeiro, GTA/COPPE/UFRJ, Rio de Janeiro, Brazil","institution_ids":["https://openalex.org/I122140584"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5104962716","display_name":"Guy Pujolle","orcid":"https://orcid.org/0000-0003-4147-7270"},"institutions":[{"id":"https://openalex.org/I4210159731","display_name":"Laboratoire de Recherche en Informatique de Paris 6","ror":"https://ror.org/05krcen59","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I39804081","https://openalex.org/I4210159245","https://openalex.org/I4210159731"]},{"id":"https://openalex.org/I39804081","display_name":"Sorbonne Universit\u00e9","ror":"https://ror.org/02en5vm52","country_code":"FR","type":"education","lineage":["https://openalex.org/I39804081"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Guy Pujolle","raw_affiliation_strings":["Sorbonne Universit\u00e9s, Laboratoire d'Informatique de Paris 6, Paris, France"],"affiliations":[{"raw_affiliation_string":"Sorbonne Universit\u00e9s, Laboratoire d'Informatique de Paris 6, Paris, France","institution_ids":["https://openalex.org/I4210159731","https://openalex.org/I39804081"]}]}],"institution_assertions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":40,"citation_normalized_percentile":{"value":0.9808,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9995,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9984,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/honeypot","display_name":"Honeypot","score":0.76752365},{"id":"https://openalex.org/keywords/zero","display_name":"Zero (linguistics)","score":0.44904342}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7938559},{"id":"https://openalex.org/C191267431","wikidata":"https://www.wikidata.org/wiki/Q911932","display_name":"Honeypot","level":2,"score":0.76752365},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.5987455},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.5851736},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.52444655},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.48736578},{"id":"https://openalex.org/C157764524","wikidata":"https://www.wikidata.org/wiki/Q1383412","display_name":"Throughput","level":3,"score":0.48143977},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.44936433},{"id":"https://openalex.org/C2780813799","wikidata":"https://www.wikidata.org/wiki/Q3274237","display_name":"Zero (linguistics)","level":2,"score":0.44904342},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.40001008},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.35027596},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.34038863},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.28875065},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.123993665},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C555944384","wikidata":"https://www.wikidata.org/wiki/Q249","display_name":"Wireless","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/icc.2018.8422622","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://hal.sorbonne-universite.fr/hal-02099022","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":20,"referenced_works":["https://openalex.org/W1152223117","https://openalex.org/W1952056635","https://openalex.org/W1980794459","https://openalex.org/W1985987493","https://openalex.org/W2008224380","https://openalex.org/W2012568697","https://openalex.org/W2017004419","https://openalex.org/W2044439547","https://openalex.org/W2065890363","https://openalex.org/W2077488147","https://openalex.org/W2099940443","https://openalex.org/W2124808847","https://openalex.org/W2512166484","https://openalex.org/W2513180554","https://openalex.org/W2559341072","https://openalex.org/W2585050519","https://openalex.org/W2586025740","https://openalex.org/W2740271336","https://openalex.org/W2782220218","https://openalex.org/W4205841652"],"related_works":["https://openalex.org/W2594597562","https://openalex.org/W2392120181","https://openalex.org/W2390124310","https://openalex.org/W2361650029","https://openalex.org/W2352199719","https://openalex.org/W2312996858","https://openalex.org/W2307276533","https://openalex.org/W2158220440","https://openalex.org/W2149305257","https://openalex.org/W1852121458"],"abstract_inverted_index":{"Attackers":[0],"create":[1],"new":[2],"threats":[3,124],"and":[4,45,59,92,101,121,128,140,159,163,177],"constantly":[5],"change":[6],"their":[7,116],"behavior":[8,47,139,175],"to":[9,78,142],"mislead":[10],"security":[11],"systems.":[12],"In":[13],"this":[14],"paper,":[15],"we":[16],"propose":[17],"an":[18,153],"adaptive":[19,104],"threat":[20,157],"detection":[21,26,65,81,105,133,158],"architecture":[22,37,151],"that":[23,114,135,149],"trains":[24],"its":[25],"models":[27],"in":[28,50,56,90,96,118],"real":[29,57,76,119],"time.":[30],"The":[31,144],"major":[32,87],"contributions":[33],"of":[34,74,103,168],"the":[35,51,83,93,126],"proposed":[36,150],"are:":[38],"i)":[39],"gather":[40],"data":[41,55],"about":[42],"zero-day":[43,123,178],"attacks":[44],"attacker":[46],"using":[48],"honeypots":[49],"network;":[52],"ii)":[53],"process":[54],"time":[58,120],"achieve":[60],"high":[61,165],"processing":[62,70],"throughput":[63],"through":[64],"schemes":[66,106,113,134],"implemented":[67],"with":[68,173],"stream":[69],"technology;":[71],"iii)":[72],"use":[73],"two":[75],"datasets":[77],"evaluate":[79],"our":[80,97],"schemes,":[82],"first":[84],"from":[85,125],"a":[86],"network":[88],"operator":[89],"Brazil":[91],"other":[94],"created":[95],"lab;":[98],"iv)":[99],"design":[100],"development":[102],"including":[107],"both":[108],"online":[109,129],"trained":[110,130],"supervised":[111],"classification":[112,166],"update":[115],"parameters":[117],"learn":[122],"honeypots,":[127],"unsupervised":[131],"anomaly":[132],"model":[136],"legitimate":[137,174],"user":[138],"adapt":[141],"changes.":[143],"performance":[145],"evaluation":[146],"results":[147],"show":[148],"maintains":[152],"excellent":[154],"trade-off":[155],"between":[156],"false":[160],"positive":[161],"rates":[162],"achieves":[164],"accuracy":[167],"more":[169],"than":[170],"90%,":[171],"even":[172],"changes":[176],"threats.":[179]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2887492447","counts_by_year":[{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":8},{"year":2021,"cited_by_count":6},{"year":2020,"cited_by_count":13},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":1}],"updated_date":"2025-01-17T17:11:04.871154","created_date":"2018-08-22"}