<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Methods for Anomaly Detection: a Survey</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>leonidandk@gmail.com</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Proceedings of the 16th All-Russian Conference “Digital Libraries: Advanced Methods and Technologies</institution>
          ,
          <addr-line>Digital Collections” ― RCDL-2014, Dubna</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Ivan Shanin Institute of Informatics Problems of RAS Moscow</institution>
        </aff>
      </contrib-group>
      <fpage>20</fpage>
      <lpage>25</lpage>
      <abstract>
        <p>In this article we review different approaches to the anomaly detection problems, their applications and specific features. We classify different methods according to the data specificity and discuss their applicability in different cases.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>Anomalies (or outliers, deviant objects, exceptions,
rare events, peculiar objects) is an important concept of
the data analysis. Data object is considered to be an
outlier if it has significant deviation from the regular
pattern of the common data behaviour in a specific
domain. Generally it means that this data object is
“dissimilar” to the other observations in the dataset. It is
very important to detect these objects during the data
analysis to treat them differently from the other data.
For instance, the anomaly detection methods are widely
used for the following purposes:</p>
      <p>
        • Credit card (and mobile phone) fraud detection
[
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ];
• Suspicious Web site detection [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ];
•
      </p>
      <sec id="sec-1-1">
        <title>Whole-genome DNA matching [4, 5]; • ECG-signal filtering [6]; • Suspicious transaction detection [7]; •</title>
      </sec>
      <sec id="sec-1-2">
        <title>Analysis of digital sky surveys [8, 9].</title>
        <p>
          The anomaly detection problem has become a
recognized rapidly-developing topic of the data
analysis. Many surveys and studies are devoted to this
problem [
          <xref ref-type="bibr" rid="ref1 ref10 ref11 ref3 ref4 ref5">1, 3, 4, 5, 10, 11</xref>
          ]. The main purpose of this
review is to reveal specific features of widely known
statistical and machine learning methods that are used to
detect anomalies. All considered methods will be
categorized by the data form they are applied to.
        </p>
        <p>The paper is organized as follows. In Section 2 we
introduce three generic data representations that are
most commonly used in anomaly detection problems:
Metric Data, Evolving Data and Multistructured Data.
In Sections 3, 4 and 5 these data forms are discussed in
detail, each form is related to a certain class of problems
and appropriate methods that are presented with the
application examples. In Section 6 we discuss specific
features of the anomaly detection problem that make
strong impact on the methods used in this area. Section
7 contains conclusions and results of this review.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2 Data forms</title>
      <p>The precise definition of the outlier depends on the
specific problem and its data representation. In this
survey we will establish a correspondence between
concrete data representation forms and suitable anomaly
detection methods. We assume that the data are usually
presented in one of three forms: Metric Data, Evolving
Data and Multistructured Data. Metric Data are the most
common form of data representation, when every object
in a dataset has a certain set of attributes that allows to
operate with notions of "distance" and "proximity".
Evolving Data are presented as well-studied objects:
Discrete Sequences, Time Series and Multidimensional
Data Streams. Third form is the Multistructured Data,
under this term we understand the data that are
presented in unstructured, semi-structured or structured
form. This data form may not have a rigid structure, and
yet it can contain various data dependencies. The most
usual task with this type of data is to extract attributes
that would allow using metric data oriented methods of
the outlier analysis. In our survey the Multistructured
Data are specialized as the Graph Data or Text Data.</p>
    </sec>
    <sec id="sec-3">
      <title>3 Metric Data Oriented Methods</title>
      <p>
        In this section the methods are considered that use
the concept of “metric” data: such as the distance
between objects, the correlation between them, and the
distribution of data. We assume that the data in this case
represents the objects in the space, so-called points.
Then the task is to determine regular and irregular
points, depending on the specific metric distance
between objects in the space, or the correlation, or the
spatial distribution of the points. In this case, we
consider a structured data type, i.e., objects, which do
not depend on time (time series are discussed in
Section 4). Metric data form is the most widely-used,
usually due to the fact that almost all entities can be
represented as a structured object, a set of attributes, and
thus as a point in a particular space [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Thus, these
methods are used in various applications, e.g., in
medicine and astronomy. We subdivide methods based
on the notion of distance, based on the correlations, data
distributions and finally related to the data with high
dimension and categorical attributes. We now turn to a
more detailed review of certain types of these methods.
      </p>
      <sec id="sec-3-1">
        <title>3.1 Distance-Based Data</title>
        <p>
          Basic set of methods that use the notion of distance
includes clustering methods, K nearest neighbors and
their derivatives. Clustering methods use the distance
defined in space to separate the data into homogenous
and dense groups (clusters). If we see that the point is not
included in large clusters, it is classified as anomaly. So
we can assume that small clusters can be clusters of
anomalous objects, because anomalies may also have a
similar structure, i.e., be clustered. K-nearest neighbors
method [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] is based on the concept of proximity. We
consider k nearest points on the basis of certain rules, that
decide whether the object is abnormal or not. A simple
example of such rule is the distance between objects, i.e.,
the farthest object from its neighbors the more likely is
abnormal. There are various kinds of rules starting from
the distance-based rules to the neighbor
distributionbased. For example, LOF (Local outlier factor) [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] is
based on the density of objects in a neighborhood.
Examples of clustering methods of anomaly detection in
astronomy can be found in [
          <xref ref-type="bibr" rid="ref15 ref16 ref17">15, 16, 17</xref>
          ]. Besides classic
clustering methods, many machine learning techniques
can be used: e. g. modified methods of neural networks –
SOM (Self-organizing map) [
          <xref ref-type="bibr" rid="ref18 ref19">18, 19</xref>
          ].
        </p>
        <p>
          As an example, consider [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ]. Authors propose their
own clustering algorithm that also classifies anomalies.
The main task in this case is to find erroneous values and
interesting events in sensor data. Using Intel Berkeley
Research lab dataset (2.3 million readings from 54
sensors) and synthetic dataset their algorithm reached
Detection rate = 100%, False alarm rate = 0.10% and
0.09% respectively. These experimental results show
that their approach can detect dangerous events (such as
forest fire, air pollution, etc.) as well as erroneous or
noisy data.
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2 Correlated Dimension Data</title>
        <p>
          The idea of these methods is based on the concept of
correlation between data attributes. This situation is
often found in real data because different attributes can
be generated by the same processes. Thus, this effect
allows to use linear models and methods based on them.
A simple example of these methods is the linear
regression. Using the method of linear regression of the
data we are trying to bring some plane, which describes
our data, then as the anomalous objects we pick those
that are far away from this plane. Also often PCA
(Principal component analysis) [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ] can be used aiming
at the reducing of the dimensionality of the data. Due to
this the PCA is sometimes used in preprocessing data as
in [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. But it can also be directly used to separate
anomalies. In this case, the basic idea is that at new
dimensions it is easier to distinguish normal objects
from abnormal objects [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ].
        </p>
        <p>
          In probabilistic methods, the main approach is to
assume that the data satisfy some distribution law. Thus,
anomalous objects can be defined as objects that do not
satisfy such basic rule. A classic example of these
methods is the EM [
          <xref ref-type="bibr" rid="ref23 ref24">23, 24</xref>
          ], an iterative algorithm based
on the maximum likelihood method. Each iteration is an
expectation and maximization. Expectation supposes
the calculation of the likelihood function, and
maximization step is finding the parameter that
maximizes the likelihood function. As well there are
methods based on statistics, data distribution. These
include the tail analysis of distributions (e.g., normal)
and using the Markov, Chebyshev, Chernoff inequality.
        </p>
        <p>
          An example of finding anomalies in sensors of
rotating machinery is considered in [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ]. In this task
rolling element bearing failures are determined as
anomalies. In practice, such frequent errors are one of
the foremost causes of failures in the rotating
mechanical systems. Comparing with other SVM-based
approaches, the authors apply a Gaussian distribution.
After choosing threshold and calculating parameters of
distribution the anomalies are found. For testing they
use vibration data from the NSF I/UCR Center for
Intelligent Maintenance Systems (IMS –
www.imscenter.net) and reach 97% accuracy.
        </p>
        <p>
          Another examples of application of these methods
can be found in [
          <xref ref-type="bibr" rid="ref25 ref26">25, 26</xref>
          ].
        </p>
      </sec>
      <sec id="sec-3-3">
        <title>3.4 Categorical Data</title>
        <p>The appropriate anomaly detection methods operate
with continuous data - thus, one approach is to translate
the categorical into continuous attributes. As an
example, categorical data can be represented as a set of
binary attributes. Certainly this kind of transformation
may increase the dimension of the data, but this
problem can be solved with methods of dimensionality
reduction. Different probabilistic approaches also can be
used for processing categorical data. It is clear that these
approaches are not the only ones that can work with the
categorical data. For example, some methods may be
partially modified for using categorical data types:
distance and proximity can be extended for categorical
data.</p>
      </sec>
      <sec id="sec-3-4">
        <title>3.5 High-Dimensional Data</title>
        <p>
          In various applications the problem of the large
number of attributes often arises. This problem implies
the extra attributes, the incorrectness of the concepts of
the distance between the objects and the sophistication
of methods. For example, correlated dimension methods
will work much worse on a large number of attributes.
The main way of solving these problems is the search of
subspaces of attributes. Earlier we mentioned the PCA,
which is most commonly used for this task. But when
selecting a small number of attributes other problems
will be encountered. By changing the number of
attributes, we lose information. Because of the small
samples of anomalies, or the emergence of new types of
anomalies, previously "abnormal" attributes can be lost.
More subtle approach for this problem is the Sparse
Cube Method [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ]. This technique is based on analysis
of the density distributions of projections from the data,
then the grid discretization is performed (data is
forming a sparse hypercube at this point) and the
evolutionary algorithm is employed to find an
appropriate lower-dimensional subspace.
        </p>
        <p>
          Many applications are confronted with the problem
of high dimension. [
          <xref ref-type="bibr" rid="ref29">29</xref>
          ] will be taken as an example.
Here authors searched for images, characterized by low
quality, low illumination intensity or some collisions.
They compare the PCA-based approach and the
proposed one which is based on the random projections.
After projection LOF works with neighborhood that was
taken from source space. Both approaches show good
results, but the second is much faster at large
dimensions than PCA and LOF.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4 Evolving Data</title>
      <p>It is very common that data is given in a temporal
(or just consecutive) representation. Usually it is caused
by the origin of the data. The temporal feature can be
discrete or continuous, so the data can be presented in
sequences or in time series. Methods that we review in
this section can be applied to various common problems
in medicine, economy, earth science, etc. Also we
review methods suitable for "on-line" outlier analysis in
data streams.</p>
      <sec id="sec-4-1">
        <title>4.1 Discrete Sequences Data</title>
        <p>
          There are many problems that need outlier detection
in discrete sequences (web logs analysis, DNA analysis,
etc. [
          <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
          ]). There are several ways to determine an
outlier in the data presented as a discrete sequence. We
can analyze values on specific positions or test the
whole sequence to be deviant. Three models are used to
measure deviation in these problems: distance-based,
frequency-based and Hidden Markov Model [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. In the
survey [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ] the methods are divided in three groups:
sequence-based, contiguous subsequence-based and
pattern-based. The first group includes Kernel Based
Techniques, Window Based Techniques, Markovian
Techniques, contiguous subsequence methods include
Window Scoring Techniques and Segmentation Based
Techniques. Pattern-based methods include Substring
Matching, Subsequence Matching and Permutation
Matching Techniques [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ].
        </p>
        <p>
          In the work [
          <xref ref-type="bibr" rid="ref34">34</xref>
          ] the classic host-based anomaly
intrusion detection problem is solved. The study is
devoted to Windows Native API systems (a specific
WindowsNT API that is used mostly during system
boot), while most of other works consider UNIX-based
systems. Authors analyse system calls in order to detect
the abnormal behaviour that indicates an attack or
intrusion. In order to solve this problem authors use a
slide window method to establish a database of "normal
patterns". Then the SVM method is used for anomaly
detection, and in addition to that several window-based
features are used to construct a detection rule. The
method was tested on the real data from Win2K and
        </p>
        <p>
          WinXP systems (including logs of the important system
processes such as svchost, Lsass, Inetinfo) and showed
good results. One of the practical examples is given also
in [
          <xref ref-type="bibr" rid="ref31">31</xref>
          ].
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2 Time Series Data</title>
        <p>
          If the data strongly depends on time, then we are
facing the need to predict the forthcoming data and
analyze the current trends. The most common way to
determine an outlier is a surprising change of trends.
The methods considered are based on well-developed
apparatus of time series analysis including Kalman
Filtering, Autoregressive Modeling, detection of
unusual shapes with the Haar transform and various
statistic techniques. Historically, the first approach to
finding this sort of outliers used an idea from the
immunology [
          <xref ref-type="bibr" rid="ref33">33</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5 Multistructured Data</title>
      <p>Sometimes the data is presented in a more complex
form than numerical "attribute / value" table. In this
case it is important to understand what an outlier is by
using of the appropriate method of analysis. We will
review two cases that need specific analysis: textual
data (e.g., poll answers) and data presented as graph
(e.g., social network data).</p>
      <sec id="sec-5-1">
        <title>5.1 Text Data</title>
        <p>
          In connection with the development of
communications, world wide web, and especially with
the advent of social networks, an interest in the analysis
of texts on the Internet greatly increased. Considering
the text analytics and anomaly detection, several major
tasks can be distinguished: searching for abnormal texts
– such as spam detection and searching for non-standard
text – novelty detection. When solving these problems,
the main problem is to represent texts in metric data.
Thus we may use the previously defined methods. A
simple way is to use the standard metrics for texts, such
as the tf-idf. Extaction of entites from texts also is
widespread. Using natural language processing
techniques such as LSA (Latent semantic analysis) [
          <xref ref-type="bibr" rid="ref34">34</xref>
          ]
it is possible to group text, integrating it with the
standard anomaly detection methods. Due to the large
number of texts, often the learning may have supervised
character.
        </p>
        <p>
          In [
          <xref ref-type="bibr" rid="ref36">36</xref>
          ] a study is focused on spam detection. Using
the tf-idf measure their algorithm is based on computing
distances between messages. Then it constructs
“normal” area using training set. Afterwards area’s
threshold determines whether an email was a spam.
LingSpam (2412 ham, 480 spam), SpamAssassin(4150
ham, 1896 spam) and TREC(7368 ham , 14937 spam)
were selected as experimental data sets. The spam
detector shows high accuracy and low false positive rate
for each dataset.
        </p>
      </sec>
      <sec id="sec-5-2">
        <title>5.2 Graph Data</title>
        <p>
          In this section we review how methods of data
analysis depend on the graph structure. The main
difference is that the graph can be large and complex or,
in the contrary, can consist of many smaller and simpler
graphs. The main problem here is to extract appropriate
attributes from nodes, edges and subgraphs that allow to
use methods considered in Section 3. In the first case we
will review methods that extract numerical attributes
from smaller graphs and treat them like data objects
using algorithms from Section 3. In case of a large and
complex graph we may be interested in node outliers,
linkage outliers and subgraph outlier. Methods that
analyze node outliers usually extract attributes from the
given node and its neighborhood, but in case of a
linkage outlier detection the concept of an outlier itself
becomes very complex [
          <xref ref-type="bibr" rid="ref10 ref3">10, 3</xref>
          ]. We will consider that
edge is an outlier if it connects nodes from different
dense clusters of nodes. The most popular methods are
based on the random graph theory, matrix factorization
and spectral analysis techniques [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. Another problem
in this section is to detect subgraphs with a deviant
behavior and to determine its structure and attribute
extraction [
          <xref ref-type="bibr" rid="ref37">37</xref>
          ].
        </p>
        <p>
          Concrete definition of the outlier node or edge can
differ according to a specific problem. For example, in
[
          <xref ref-type="bibr" rid="ref38">38</xref>
          ] several types of anomaly are considered: near-star,
near-clique, heavy-vicinity and dominant edge.
Anomalous subgraphs are often detected using the
Minimal Description Length principle [
          <xref ref-type="bibr" rid="ref39 ref40 ref41">39, 40, 41</xref>
          ]. One
of the most important application today is Social
Network Data – many popular modern techniques are
used in this area: Bayesian Models [
          <xref ref-type="bibr" rid="ref42">42</xref>
          ], Markov
Random Field, Ising Model [
          <xref ref-type="bibr" rid="ref43">43</xref>
          ], EM algorithm [
          <xref ref-type="bibr" rid="ref44">44</xref>
          ] as
well as LOF [
          <xref ref-type="bibr" rid="ref45">45</xref>
          ].
        </p>
        <p>
          In [
          <xref ref-type="bibr" rid="ref44">44</xref>
          ] authors perform anomaly detection methods
for social networks. Social network contains
information about its members and their meetings. The
problem statement is to find abnormal meeting and to
measure its degree of abnormality. The problem
specificity is that the number of meetings is very small
compared to the number of members, that makes
challenging to use common statistical methods. In order
to solve the problem authors use the notion of
hypergraph. The vertices of the hypergraph are
considered as members of the social network and the
edges are considered as meetings of the members (each
edge of a hypergraph connects some set of vertices
together). The anomalies are detected through density
estimation of p-dimensional hypercube (the EM
algorithm tunes a two-component mixture). The method
is tested on a synthetic data and shows relatively low
estimation error. It is also considered to be a scalable
method, which makes it very valuable to use on large
social networks.
        </p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6 Specific features of the anomaly detection methods comparing to the general machine learning and statistics methods</title>
      <p>In this article we show the application for the
anomaly detection of various data mining methods that
can re-use of the general machine learning and
statistical algorithms. The anomaly detection problem
has its own specific features making possible to tune the
appropriate general algorithms properly turning them
into the more efficient ones.</p>
      <p>Let us consider one of the basic concept of machine
learning – the classification problem. The anomaly
detection problem can be considered as a classification
problem, in that case the data is assumed to have the
class of anomalies. Most of the methods that solve
classification problems assume that data classes have
some sort of inner predictable structure. But the only
prediction that can be made about anomalies is that
these objects do not resemble non-outlier "normal" data.
In this case, in order to solve the anomaly detection
problem, the outlier class modeling can be senseless and
unproductive. Instead of this, one should pay attention
to the structure of the normal data, its laws of
distribution.</p>
      <p>The machine learning methods can be divided in
three groups: supervised, semi-supervised and
unsupervised methods. The first group is the most
learned. It requires the labeled "training" dataset, and
this is exactly the situation described above: the
information about the outlier class is used to tune a
model of it in order to predict it's structure, which has
often very complex or random nature. The
semisupervised methods use information only about the
"normal" class, so these methods have better
specifications for anomaly detection problem as well as
unsupervised methods, which do not use any
information besides the structure and configuration of
the unlabeled data.</p>
      <p>
        Another important specific feature of the anomaly
detection problem is that usually abnormal objects are
significantly rare (compared to the non-outlier objects).
This effect makes hard to construct a reliable training
dataset for supervised methods. Also, if this effect is not
presented in the data, most of known methods will
suffer from high alarm rates [
        <xref ref-type="bibr" rid="ref47 ref48">47, 48</xref>
        ].
      </p>
    </sec>
    <sec id="sec-7">
      <title>7 Conclusion</title>
      <p>In this paper we introduced an approach to classify
different anomaly detection problems according to the
way the data are presented. We reviewed different
applications of the outlier analysis in various cases. At
the end we summarized specific features of the methods
suitable for the outlier analysis problem. Our future
plans include preparing of a university master level
course focused on the anomaly detection as well as
working on the anomaly detection in various fields (e.g.
finding peculiar objects in massive digital sky
astronomy surveys).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Chandola</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Banerjee</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Kumar</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          (
          <year>2009</year>
          ).
          <article-title>Anomaly detection: A Survey</article-title>
          .
          <source>ACM Computing Surveys</source>
          ,
          <volume>41</volume>
          (
          <issue>3</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>58</lpage>
          . Doi:
          <volume>10</volume>
          .1145/1541880.1541882
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Kou</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lu</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sinvongwattana</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2004</year>
          ).
          <source>Survey of Fraud Detection Techniques Yo-Ping Huang</source>
          ,
          <fpage>749</fpage>
          -
          <lpage>754</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Pan</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ding</surname>
            <given-names>X</given-names>
          </string-name>
          .
          <article-title>Anomaly based web phishing</article-title>
          page detection // Computer Security Applications Conference,
          <year>2006</year>
          . ACSAC'
          <volume>06</volume>
          . 22nd Annual. - IEEE,
          <year>2006</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>381</fpage>
          -
          <lpage>392</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Tzeng</surname>
          </string-name>
          , J.-Y.,
          <string-name>
            <surname>Byerley</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Devlin</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Roeder</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Wasserman</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2003</year>
          ).
          <article-title>Outlier Detection and False Discovery Rates for Whole-Genome DNA Matching</article-title>
          .
          <source>Journal of the American Statistical Association</source>
          ,
          <volume>98</volume>
          (
          <issue>461</issue>
          ),
          <fpage>236</fpage>
          -
          <lpage>246</lpage>
          . doi:
          <volume>10</volume>
          .1198/016214503388619256
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Wu</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>Cancer outlier differential gene expression detection</article-title>
          .
          <source>Biostatistics (Oxford, England)</source>
          ,
          <volume>8</volume>
          (
          <issue>3</issue>
          ),
          <fpage>566</fpage>
          -
          <lpage>75</lpage>
          . doi:
          <volume>10</volume>
          .1093/biostatistics/kxl029
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Lourenço</surname>
            <given-names>A.</given-names>
          </string-name>
          et al.
          <article-title>Outlier detection in nonintrusive ECG biometric system // Image Analysis</article-title>
          and
          <string-name>
            <surname>Recognition</surname>
          </string-name>
          . - Springer Berlin Heidelberg,
          <year>2013</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>43</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>F. T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ting</surname>
            ,
            <given-names>K. M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Zhou</surname>
            ,
            <given-names>Z.-H.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>Isolation-Based Anomaly Detection</article-title>
          .
          <source>ACM Transactions on Knowledge Discovery from Data</source>
          ,
          <volume>6</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>39</lpage>
          . doi:
          <volume>10</volume>
          .1145/2133360.2133363
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Djorgovski</surname>
            ,
            <given-names>S. G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brunner</surname>
            ,
            <given-names>R. J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mahabal</surname>
            ,
            <given-names>A. A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Odewahn</surname>
            ,
            <given-names>S. C.</given-names>
          </string-name>
          (
          <year>2001</year>
          ).
          <source>Exploration of Large Digital Sky Surveys. Observatory</source>
          ,
          <volume>1</volume>
          -
          <fpage>18</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Djorgovski</surname>
            ,
            <given-names>S. G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mahabal</surname>
            ,
            <given-names>A. A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brunner</surname>
            ,
            <given-names>R. J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gal</surname>
            ,
            <given-names>R. R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Castro</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Observatory</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Carvalho</surname>
            ,
            <given-names>R. R.</given-names>
          </string-name>
          <string-name>
            <surname>De</surname>
          </string-name>
          , et al. (
          <year>2001a</year>
          ).
          <source>Searches for Rare and New Types of Objects</source>
          ,
          <volume>225</volume>
          ,
          <fpage>52</fpage>
          -
          <lpage>63</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Aggarwal</surname>
            ,
            <given-names>C. C.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>Outlier Analysis (introduction)</article-title>
          .
          <source>doi:10.1007/978-1-4614-6396-2</source>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Chandola</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Banerjee</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Kumar</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          (
          <year>2009</year>
          ).
          <article-title>Anomaly detection: A Survey</article-title>
          .
          <source>ACM Computing Surveys</source>
          ,
          <volume>41</volume>
          (
          <issue>3</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>58</lpage>
          . doi:
          <volume>10</volume>
          .1145/1541880.1541882
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Berti-équille</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2009</year>
          ). Data Quality Mining : New Research Directions. Current.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Stevens</surname>
            ,
            <given-names>K. N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cover</surname>
            ,
            <given-names>T. M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Hart</surname>
            ,
            <given-names>P. E.</given-names>
          </string-name>
          (
          <year>1967</year>
          ).
          <article-title>Nearest Neighbor Pattern Classification</article-title>
          .
          <source>EEE Transactions on Information Theory 13</source>
          , I,
          <fpage>21</fpage>
          -
          <lpage>27</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Breunig</surname>
            ,
            <given-names>M. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kriegel</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ng</surname>
            ,
            <given-names>R. T.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sander</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2000</year>
          ).
          <source>LOF?: Identifying Density-Based Local Outliers</source>
          ,
          <fpage>1</fpage>
          -
          <lpage>12</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Borne</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Vedachalam</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2010</year>
          ).
          <article-title>EFFECTIVE OUTLIER DETECTION IN SCIENCE DATA STREAMS</article-title>
          .
          <source>ReCALL</source>
          ,
          <fpage>1</fpage>
          -
          <lpage>15</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Borne</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          (n.d.).
          <source>Surprise Detection in Multivariate Astronomical Data.</source>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Henrion</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hand</surname>
            ,
            <given-names>D. J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gandy</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Mortlock</surname>
            ,
            <given-names>D. J.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>CASOS: a Subspace Method for Anomaly Detection in High Dimentional Astronomical Databases</article-title>
          .
          <source>Statistical Analysis and Data Mining</source>
          ,
          <volume>6</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>89</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Networks</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          (n.d.).
          <source>Data Mining Self - Organizing Maps</source>
          ,
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Manikantan</surname>
            <given-names>Ramadas</given-names>
          </string-name>
          , Shawn Ostermann,
          <article-title>Brett TjadenDetecting Anomalous Network Traffic with Self-organizing Maps</article-title>
          .
          <source>(2003) Recent Advances in Intrusion Detection Lecture Notes in Computer Science</source>
          . Vol.
          <volume>2820</volume>
          ,
          <fpage>36</fpage>
          -
          <lpage>54</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Purarjomandlangrudi</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ghapanchi</surname>
            <given-names>A. H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Esmalifalak</surname>
            <given-names>M.</given-names>
          </string-name>
          <article-title>A Data Mining Approach for Fault Diagnosis: An Application of</article-title>
          Anomaly Detection Algorithm // Measurement. -
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Abdi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Williams</surname>
            ,
            <given-names>L. J.</given-names>
          </string-name>
          (
          <year>2010</year>
          ).
          <article-title>Principal component analysis</article-title>
          .
          <source>Wiley Interdisciplinary Reviews: Computational Statistics</source>
          ,
          <volume>2</volume>
          (
          <issue>4</issue>
          ),
          <fpage>433</fpage>
          -
          <lpage>459</lpage>
          . doi:
          <volume>10</volume>
          .1002/wics.101
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Dutta</surname>
            <given-names>H.</given-names>
          </string-name>
          et al. Distributed
          <string-name>
            <surname>Top-K Outlier Detection from Astronomy</surname>
          </string-name>
          <article-title>Catalogs using the DEMAC System /</article-title>
          / SDM. -
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Cansado</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Soto</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2008</year>
          ).
          <article-title>Unsupervised Anomaly Detection in Large Databases Using Bayesian Networks</article-title>
          .
          <source>Network</source>
          ,
          <volume>1</volume>
          -
          <fpage>37</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Zhu</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          (
          <year>2007</year>
          ).
          <fpage>CS838</fpage>
          -1
          <string-name>
            <surname>Advanced</surname>
            <given-names>NLP</given-names>
          </string-name>
          <string-name>
            <surname> : The EM Algorithm K-means</surname>
            <given-names>Clustering</given-names>
          </string-name>
          , (
          <volume>6</volume>
          ),
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>Spence</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Parra</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Sajda</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          (
          <year>2001</year>
          ).
          <article-title>Detection, Synthesis and Compression in Mammographic Image Analysis with a Hierarchical Image Probability Model</article-title>
          ,
          <fpage>3</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Pelleg</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Moore</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (n.d.).
          <article-title>Active Learning for Anomaly and Rare-Category Detection</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Fawzy</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mokhtar</surname>
            <given-names>H. M. O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hegazy</surname>
            <given-names>O</given-names>
          </string-name>
          .
          <article-title>Outliers detection and classification in wireless sensor networks // Egyptian Informatics Journal</article-title>
          .
          <article-title>-</article-title>
          <year>2013</year>
          . -
          <fpage>Т</fpage>
          .
          <volume>14</volume>
          , №
          <fpage>2</fpage>
          . -
          <lpage>С</lpage>
          .
          <fpage>157</fpage>
          -
          <lpage>164</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Aggarwal</surname>
            <given-names>C. C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Philip</surname>
            <given-names>S. Y.</given-names>
          </string-name>
          <article-title>An effective and efficient algorithm for high-dimensional outlier detection // The VLDB journal</article-title>
          . -
          <source>2005</source>
          . -
          <fpage>Т</fpage>
          .
          <volume>14</volume>
          , №
          <fpage>2</fpage>
          . -
          <lpage>С</lpage>
          .
          <fpage>211</fpage>
          -
          <lpage>221</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <surname>De Vries</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chawla</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Houle</surname>
            ,
            <given-names>M. E.</given-names>
          </string-name>
          (
          <year>2010</year>
          ).
          <article-title>Finding Local Anomalies in Very High Dimensional Space</article-title>
          .
          <source>2010 IEEE InternationalConferenceonDataMining</source>
          ,
          <volume>128</volume>
          -
          <fpage>137</fpage>
          . doi:
          <volume>10</volume>
          .1109/ICDM.
          <year>2010</year>
          .151
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <surname>Chandola</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Banerjee</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kumar</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Anomaly detection for discrete sequences: A survey // Knowledge and Data Engineering</article-title>
          , IEEE Transactions on.
          <source>- 2012</source>
          . -
          <fpage>Т</fpage>
          .
          <volume>24</volume>
          , №
          <fpage>5</fpage>
          . -
          <lpage>С</lpage>
          .
          <fpage>823</fpage>
          -
          <lpage>839</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Budalakoti</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Srivastava</surname>
            <given-names>A. N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Otey</surname>
            <given-names>M. E.</given-names>
          </string-name>
          <article-title>Anomaly detection and diagnosis algorithms for discrete symbol sequences with applications to airline safety // Systems</article-title>
          , Man, and
          <string-name>
            <surname>Cybernetics</surname>
          </string-name>
          , Part C:
          <article-title>Applications</article-title>
          and Reviews,
          <source>IEEE Transactions on. - 2009</source>
          . -
          <fpage>Т</fpage>
          .
          <volume>39</volume>
          ,
          <issue>№</issue>
          . 1. -
          <fpage>С</fpage>
          .
          <fpage>101</fpage>
          -
          <lpage>113</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Wang</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhang</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yu</surname>
            <given-names>J</given-names>
          </string-name>
          .
          <article-title>Native API based windows anomaly intrusion detection method using SVM // Sensor Networks</article-title>
          , Ubiquitous, and Trustworthy Computing,
          <year>2006</year>
          . IEEE International Conference on.
          <source>- IEEE</source>
          ,
          <year>2006</year>
          . -
          <fpage>Т</fpage>
          . 1. -
          <fpage>С</fpage>
          . 6.
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Dasgupta</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Forrest</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>Novelty detection in time series data using ideas from immunology //</article-title>
          <source>Proceedings of the international conference on intelligent systems. - 1996</source>
          . -
          <fpage>С</fpage>
          .
          <fpage>82</fpage>
          -
          <lpage>87</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <surname>Susan</surname>
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Dumais</surname>
          </string-name>
          (
          <year>2005</year>
          ).
          <article-title>"Latent Semantic Analysis"</article-title>
          .
          <source>Annual Review of Information Science and Technology</source>
          <volume>38</volume>
          :
          <fpage>188</fpage>
          . doi:
          <volume>10</volume>
          .1002/aris.1440380105
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <surname>Allan</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Papka</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lavrenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          (
          <year>1998</year>
          ).
          <article-title>Online New Event Detection and Tracking</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <surname>Laorden</surname>
            <given-names>C.</given-names>
          </string-name>
          et al.
          <article-title>Study on the effectiveness of anomaly detection for spam filtering</article-title>
          // Information Sciences.
          <article-title>-</article-title>
          <year>2014</year>
          . -
          <fpage>Т</fpage>
          .
          <year>277</year>
          . - С.
          <fpage>421</fpage>
          -
          <lpage>444</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <surname>Kil</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Oh</surname>
            ,
            <given-names>S.-C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Elmacioglu</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nam</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2009</year>
          ).
          <article-title>Graph Theoretic Topological Analysis of Web Service Networks</article-title>
          .
          <source>WorldWideWeb</source>
          ,
          <volume>12</volume>
          (
          <issue>3</issue>
          ),
          <fpage>321</fpage>
          -
          <lpage>343</lpage>
          . doi:
          <volume>10</volume>
          .1007/s11280-009-0064-6
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [38]
          <string-name>
            <surname>Akoglu</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McGlohon</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Faloutsos</surname>
            <given-names>C</given-names>
          </string-name>
          .
          <article-title>Oddball: Spotting anomalies in weighted graphs // Advances in Knowledge Discovery</article-title>
          and
          <string-name>
            <given-names>Data</given-names>
            <surname>Mining</surname>
          </string-name>
          . - Springer Berlin Heidelberg,
          <year>2010</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>410</fpage>
          -
          <lpage>421</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [39]
          <string-name>
            <surname>Noble</surname>
            <given-names>C. C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cook</surname>
            <given-names>D. J.</given-names>
          </string-name>
          <article-title>Graph-based anomaly detection // Proceedings of the ninth ACM SIGKDD international conference on Knowledge discovery and data mining</article-title>
          .
          <source>- ACM</source>
          ,
          <year>2003</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>631</fpage>
          -
          <lpage>636</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          [40]
          <string-name>
            <surname>Eberle</surname>
            <given-names>W.</given-names>
          </string-name>
          , Holder L.
          <article-title>Discovering structural anomalies in graph-based data // Data Mining Workshops</article-title>
          ,
          <year>2007</year>
          . ICDM Workshops
          <year>2007</year>
          . Seventh IEEE International Conference on.
          <source>- IEEE</source>
          ,
          <year>2007</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>393</fpage>
          -
          <lpage>398</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          [41]
          <string-name>
            <surname>Chakrabarti</surname>
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Autopart</surname>
          </string-name>
          :
          <article-title>Parameter-free graph partitioning</article-title>
          and outlier detection // Knowledge Discovery in Databases: PKDD
          <year>2004</year>
          . - Springer Berlin Heidelberg,
          <year>2004</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>112</fpage>
          -
          <lpage>124</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          [42]
          <string-name>
            <surname>Heard</surname>
            <given-names>N. A.</given-names>
          </string-name>
          et al.
          <article-title>Bayesian anomaly detection methods for social networks //</article-title>
          <source>The Annals of Applied Statistics. - 2010</source>
          . -
          <fpage>Т</fpage>
          . 4, № 2. -
          <fpage>С</fpage>
          .
          <fpage>645</fpage>
          -
          <lpage>662</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          [43]
          <string-name>
            <surname>Horn</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Willett</surname>
            <given-names>R</given-names>
          </string-name>
          .
          <article-title>Online anomaly detection with expert system feedback in social networks // Acoustics, Speech and Signal Processing (ICASSP</article-title>
          ),
          <source>2011 IEEE International Conference on. - IEEE</source>
          ,
          <year>2011</year>
          . -
          <fpage>С</fpage>
          .
          <year>1936</year>
          -
          <fpage>1939</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          [44]
          <string-name>
            <surname>Silva</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Willett</surname>
            <given-names>R</given-names>
          </string-name>
          .
          <article-title>Detection of anomalous meetings in a social network //</article-title>
          <source>Information Sciences and Systems</source>
          ,
          <year>2008</year>
          .
          <source>CISS 2008. 42nd Annual Conference on. - IEEE</source>
          ,
          <year>2008</year>
          . -
          <fpage>С</fpage>
          .
          <fpage>636</fpage>
          -
          <lpage>641</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref45">
        <mixed-citation>
          [45]
          <string-name>
            <surname>Bhuyan</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bhattacharyya</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kalita</surname>
            <given-names>J</given-names>
          </string-name>
          .
          <article-title>Network anomaly detection: methods, systems</article-title>
          and tools. -
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref46">
        <mixed-citation>
          [46]
          <string-name>
            <surname>Portnoy</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Eskin</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stolfo</surname>
            <given-names>S. Intrusion</given-names>
          </string-name>
          <article-title>Detection with Unlabeled Data Using Clustering (</article-title>
          <year>2001</year>
          ) // ACM Workshop on Data Mining Applied to Security
          <source>(DMSA 01).</source>
        </mixed-citation>
      </ref>
      <ref id="ref47">
        <mixed-citation>
          [47]
          <string-name>
            <surname>Laorden</surname>
            <given-names>C.</given-names>
          </string-name>
          et al.
          <article-title>Study on the effectiveness of anomaly detection for spam filtering</article-title>
          // Information Sciences.
          <article-title>-</article-title>
          <year>2014</year>
          . -
          <fpage>Т</fpage>
          .
          <year>277</year>
          . - С.
          <fpage>421</fpage>
          -
          <lpage>444</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref48">
        <mixed-citation>
          [48]
          <string-name>
            <surname>Fawzy</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mokhtar</surname>
            <given-names>H. M. O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hegazy</surname>
            <given-names>O</given-names>
          </string-name>
          .
          <article-title>Outliers detection and classification in wireless sensor networks // Egyptian Informatics Journal</article-title>
          .
          <article-title>-</article-title>
          <year>2013</year>
          . -
          <fpage>Т</fpage>
          .
          <volume>14</volume>
          , №
          <fpage>2</fpage>
          . -
          <lpage>С</lpage>
          .
          <fpage>157</fpage>
          -
          <lpage>164</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref49">
        <mixed-citation>
          [49]
          <string-name>
            <surname>Yu</surname>
            <given-names>M.</given-names>
          </string-name>
          <article-title>A nonparametric adaptive CUSUM method and its application in network anomaly detection //</article-title>
          <source>International Journal of Advancements in Computing Technology. - 2012</source>
          . -
          <fpage>Т</fpage>
          . 4, № 1. -
          <fpage>С</fpage>
          .
          <fpage>280</fpage>
          -
          <lpage>288</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref50">
        <mixed-citation>
          [50]
          <string-name>
            <surname>Muniyandi</surname>
            <given-names>A.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rajeswari</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rajaram</surname>
            <given-names>R</given-names>
          </string-name>
          .
          <article-title>Network anomaly detection by cascading k-Means clustering and C4. 5 decision tree algorithm /</article-title>
          / Procedia Engineering.
          <article-title>-</article-title>
          <year>2012</year>
          . -
          <fpage>Т</fpage>
          .
          <year>30</year>
          . - С.
          <fpage>174</fpage>
          -
          <lpage>182</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref51">
        <mixed-citation>
          [51]
          <string-name>
            <surname>Muda</surname>
            <given-names>Z.</given-names>
          </string-name>
          et al.
          <article-title>A K-Means and Naive Bayes learning approach for better intrusion detection // Information technology journal</article-title>
          .
          <source>- 2011</source>
          . -
          <fpage>Т</fpage>
          .
          <volume>10</volume>
          ,
          <issue>№</issue>
          . 3. -
          <fpage>С</fpage>
          .
          <fpage>648</fpage>
          -
          <lpage>655</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref52">
        <mixed-citation>
          [52]
          <string-name>
            <surname>Kavuri</surname>
            <given-names>V. C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            <given-names>H</given-names>
          </string-name>
          .
          <article-title>Hierarchical clustering method to improve transrectal ultrasound-guided diffuse optical tomography for prostate cancer imaging // Academic radiology</article-title>
          . -
          <source>2014</source>
          . -
          <fpage>Т</fpage>
          .
          <volume>21</volume>
          , №
          <fpage>2</fpage>
          . -
          <lpage>С</lpage>
          .
          <fpage>250</fpage>
          -
          <lpage>262</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref53">
        <mixed-citation>
          [53]
          <string-name>
            <surname>Li</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tung</surname>
            <given-names>W. L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ng</surname>
            <given-names>W. K.</given-names>
          </string-name>
          <article-title>A novelty detection machine and its application to bank failure prediction</article-title>
          // Neurocomputing. -
          <year>2014</year>
          . -
          <fpage>Т</fpage>
          .
          <year>130</year>
          . - С.
          <fpage>63</fpage>
          -
          <lpage>72</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref54">
        <mixed-citation>
          [54]
          <string-name>
            <surname>Cogranne</surname>
            <given-names>R.</given-names>
          </string-name>
          , Retraint F.
          <article-title>Statistical detection of defects in radiographic images using an adaptive parametric model // Signal Processing</article-title>
          .
          <article-title>-</article-title>
          <year>2014</year>
          . -
          <fpage>Т</fpage>
          .
          <year>96</year>
          . - С.
          <fpage>173</fpage>
          -
          <lpage>189</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref55">
        <mixed-citation>
          [55]
          <string-name>
            <surname>Daneshpazouh</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sami</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Entropy-Based Outlier Detection Using Semi-Supervised Approach with Few Positive Examples // Pattern Recognition Letters</article-title>
          .
          <article-title>- 2014.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref56">
        <mixed-citation>
          [56]
          <string-name>
            <surname>Rahmani</surname>
            <given-names>A.</given-names>
          </string-name>
          et al.
          <article-title>Graph-based approach for outlier detection in sequential data and its application on stock market and weather data // Knowledge-Based Systems</article-title>
          . - 2014. -
          <fpage>Т</fpage>
          .
          <year>61</year>
          . - С.
          <fpage>89</fpage>
          -
          <lpage>97</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>