<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-025-01-0002</article-id>
      <article-id pub-id-type="publisher-id">22573</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>L.4.0 - Security and Trust</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Balanced Efficient Lifelong Learning (B-ELLA) for Cyber Attack Detection</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Kozik</surname>
            <given-names>Rafał</given-names>
          </name>
          <email xlink:type="simple">rkozik@utp.edu.pl</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Choraś</surname>
            <given-names>Michał</given-names>
          </name>
          <xref ref-type="aff" rid="A2">2</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Keller</surname>
            <given-names>Jörg</given-names>
          </name>
          <uri content-type="orcid">https://orcid.org/0000-0003-0303-6140</uri>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">TP University of Science and Technology, Bydgoszcz, Poland</addr-line>
        <institution>TP University of Science and Technology</institution>
        <addr-line content-type="city">Bydgoszcz</addr-line>
        <country>Poland</country>
      </aff>
      <aff id="A2">
        <label>2</label>
        <addr-line content-type="verbatim">University of Science and Technology, Bydgoszcz, Poland</addr-line>
        <institution>University of Science and Technology</institution>
        <addr-line content-type="city">Bydgoszcz</addr-line>
        <country>Poland</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Rafał Kozik (<email xlink:type="simple">rkozik@utp.edu.pl</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2019</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>28</day>
        <month>01</month>
        <year>2019</year>
      </pub-date>
      <volume>25</volume>
      <issue>1</issue>
      <fpage>2</fpage>
      <lpage>15</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/04EB49F6-6E52-5D13-A8CB-AC04BA386A16">04EB49F6-6E52-5D13-A8CB-AC04BA386A16</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/4840772">4840772</uri>
      <history>
        <date date-type="received">
          <day>25</day>
          <month>01</month>
          <year>2018</year>
        </date>
        <date date-type="accepted">
          <day>28</day>
          <month>10</month>
          <year>2018</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>Rafał Kozik, Michał Choraś, Jörg Keller</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>This paper outlines and proposes a new approach to cyber attack detection on the basis of the practical application of the efficient lifelong learning cybersecurity system. One of the main difficulties in machine learning is to build intelligent systems that are capable of learning sequential tasks and then to transfer knowledge from a previously learnt foundation to learn new tasks. Such capability is termed as Lifelong Machine Learning (LML) or as Lifelong Learning Intelligent Systems (LLIS). This kind of solution would promptly address the current problems in the cybersecurity domain, where each new cyber attack can be considered as a new task. Our approach is an extension of the Efficient Lifelong Learning (ELLA) framework. Hereby, we propose the new B-ELLA (Balanced ELLA) framework to detect cyber attacks and to counter the problem of network data imbalance. Our proposition is evaluated on a malware benchmark dataset and we achieve promising results.</p>
      </abstract>
    </article-meta>
  </front>
</article>
