| 2025 | CNSM | IoT Botnet Detection with Drift-Aligned Learning and DNS-Based C2 Identification. | Jeffrey A. Adjei, Nur Zincir-Heywood, Malcolm I. Heywood, Biswajit Nandy, Nabil Seddigh |
| 2025 | CNSM | Unsupervised Anomaly Detection for Wi-Fi Networks using RFFI. | Xinyi Li, Samer Lahoud, Nur Zincir-Heywood |
| 2025 | COMPSAC | SQL-GENIE: SQL Protection using GENerative Modeling for Anomaly Detection against Injection and Evolved Adversarial Attacks. | Sadia Afrin, Marwa A. Elsayed, Nur Zincir-Heywood |
| 2025 | COMPSAC | Lightweight Early-Warning Bot Detection on X (Twitter): Temporal Patterns and Entropy Insights. | Sanaz Adel Alipour, Jeannette Janssen, Rita Orji, Nur Zincir-Heywood |
| 2025 | COMPSAC | Network Identity Management: Application, Action and Device Aware Monitoring. | Cenab Batu Bora, Julia Silva Weber, Nur Zincir-Heywood |
| 2025 | GECCO | Discovering Blue Team Solutions for an Autonomous Cyber Operations Challenge using an Evolutionary Heuristic Search. | Yuxuan Wang, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2025 | NOMS | Can Flow Metadata Based Signatures Generalize for Identifying Attacks on IoT Devices? | Jeffrey A. Adjei, Nur Zincir-Heywood, Malcolm I. Heywood, Biswajit Nandy, Nabil Seddigh |
| 2025 | NOMS | Identifying Synchronous and Asynchronous Communications in IMA Traffic. | Srivathsan Thirumurugan, Julia Silva Weber, Riyad Alshammari, Nur Zincir-Heywood, Biswajit Nandy, Nabil Seddigh |
| 2025 | NOMS | Encrypted Network Traffic Analysis (ENTA) Platform: IMA VoIP Traffic Identification. | Julia Silva Weber, Srivathsan Thirumurugan, Riyad Alshammari, Nur Zincir-Heywood, Manjinder Nir, Donald Bennett, Delfin Y. Montuno, Biswajit Nandy, Nabil Seddigh |
| 2024 | CNSM | IoT Device and State Identification based on Usage Patterns. | Jeffrey A. Adjei, Nur Zincir-Heywood, Biswajit Nandy, Nabil Seddigh |
| 2024 | CNSM | Evaluating the Robustness of ADVENT on the VeReMi-Extension Dataset. | Hamideh Baharlouei, Adetokunbo Makanju, Nur Zincir-Heywood |
| 2024 | CNSM | Improving Real-Time Anomaly Detection using Multiple Instances of Micro-Cluster Detection. | Rafael Copstein, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2024 | NOMS | Identifying IoT Devices: A Machine Learning Analysis Using Traffic Flow Metadata. | Jeffrey Adjei, Nur Zincir-Heywood, Biswajit Nandy, Nabil Seddigh |
| 2023 | CNSM | MIMC: Anomaly Detection in Network Data via Multiple Instances of Micro-Cluster Detection. | Rafael Copstein, Brad Niblett, Andrew Johnston, Jeff Schwartzentruber, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2023 | CNSM | Preliminary Results on Exploring Data Exhaust of Consumer Internet of Things Devices. | Alexander Loginov, Jeffrey Adjei, Nur Zincir-Heywood, Srinivas Sampalli, Kevin de Snayer, Terri Dougall |
| 2023 | EUROGP | A Boosting Approach to Constructing an Ensemble Stack. | Zhilei Zhou, Ziyu Qiu, Brad Niblett, Andrew Johnston, Jeffrey Schwartzentruber, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2023 | ICCCN | Depicting Instant Messaging Encrypted Traffic Characteristics through an Empirical Study. | Zolboo Erdenebaatar, Riyad Alshammari, Biswajit Nandy, Nabil Seddigh, Marwa Elsayed, Nur Zincir-Heywood |
| 2023 | MSWIM | Exploring Real-Time Malicious Behaviour Detection in VANETs. | Hamideh Baharlouei, Adetokunbo Makanju, Nur Zincir-Heywood |
| 2023 | NOMS | Analyzing Traffic Characteristics of Instant Messaging Applications on Android Smartphones. | Zolboo Erdenebaatar, Riyad Alshammari, Nur Zincir-Heywood, Marwa Elsayed, Biswajit Nandy, Nabil Seddigh |
| 2023 | NOMS | Instant Messaging Application Encrypted Traffic Generation System. | Zolboo Erdenebaatar, Biswajit Nandy, Nabil Seddigh, Riyad Alshammari, Marwa Elsayed, Nur Zincir-Heywood |
| 2023 | NOMS | On the Fence: Anomaly Detection in IoT Networks. | Patrick Russell, Marwa A. Elsayed, Biswajit Nandy, Nabil Seddigh, Nur Zincir-Heywood |
| 2023 | VTC | Exploring Anomaly Detection Techniques for Enhancing VANET Availability. | Julia Silva Weber, Tiago Ferreto, Nur Zincir-Heywood |
| 2022 | MSWIM | Implementation of a Decentralized Traffic Congestion Avoidance Mechanism for VANETs. | Aishik Sanyal, Adetokunbo Makanju, Nur Zincir-Heywood |
| 2022 | NOMS | BoostGuard: Interpretable Misbehavior Detection in Vehicular Communication Networks. | Marwa A. Elsayed, Nur Zincir-Heywood |
| 2022 | VTC | Exploring Realistic VANET Simulations for Anomaly Detection of DDoS Attacks. | Hamideh Baharlouei, Adetokunbo Makanju, Nur Zincir-Heywood |
| 2021 | SP | Training regime influences to semi-supervised learning for insider threat detection. | Duc C. Le, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2020 | CNSM | Temporal Representations for Detecting BGP Blackjack Attacks. | Rafael Copstein, Nur Zincir-Heywood |
| 2020 | GECCO | COUGAR: clustering of unknown malware using genetic algorithm routines. | Zachary Wilkins, Nur Zincir-Heywood |
| 2020 | GECCO | Exploring an artificial arms race for malware detection. | Zachary Wilkins, Ibrahim Zincir, Nur Zincir-Heywood |
| 2019 | CNSM | Are There Bots even in FIFA World Cup 2018 Tweets? | Moath Bagarish, Riyad Alshammari, Nur Zincir-Heywood |
| 2019 | CNSM | Exploring Feature Normalization and Temporal Information for Machine Learning Based Insider Threat Detection. | Pedro Ferreira, Duc C. Le, Nur Zincir-Heywood |
| 2019 | CNSM | Compromised Tweet Detection Using Siamese Networks and fastText Representations. | Mihir Joshi, Parmeet Singh, Nur Zincir-Heywood |
| 2019 | CNSM | Exploring NAT Detection and Host Identification Using Machine Learning. | Ali Safari Khatouni, Lan Zhang, Khurram Aziz, Ibrahim Zincir, Nur Zincir-Heywood |
| 2019 | CNSM | Learning From Evolving Network Data for Dependable Botnet Detection. | Duc C. Le, Nur Zincir-Heywood |
| 2019 | GECCO | Benchmarking genetic programming in dynamic insider threat detection. | Duc C. Le, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2019 | GECCO | Darwinian malware detectors: a comparison of evolutionary solutions to android malware. | Zachary Wilkins, Nur Zincir-Heywood |
| 2019 | IM | Network Analytics for Streaming Traffic Analysis. | Sara Khanchi, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2019 | IM | Machine learning based Insider Threat Modelling and Detection. | Duc C. Le, Nur Zincir-Heywood |
| 2019 | RANLP | Classification of Micro-Texts Using Sub-Word Embeddings. | Mihir Joshi, Nur Zincir-Heywood |
| 2018 | GECCO | A genetic algorithm for dynamic controller placement in software defined networking. | Samuel Champagne, Tokunbo Makanju, Chengchao Yao, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2018 | GECCO | On botnet detection with genetic programming under streaming data, label budgets and class imbalance. | Sara Khanchi, Ali Vahdat, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2018 | GECCO | Benchmarking evolutionary computation approaches to insider threat detection. | Duc C. Le, Sara Khanchi, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2018 | NOMS | Streaming Botnet traffic analysis using bio-inspired active learning. | Sara Khanchi, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2018 | NOMS | How far can we push flow analysis to identify encrypted anonymity network traffic? | Khalid Shahbar, Nur Zincir-Heywood |
| 2018 | NOMS | A language model for compromised user analysis. | Nur Zincir-Heywood, Tien D. Phan |
| 2018 | SP | Evaluating Insider Threat Detection Workflow Using Supervised and Unsupervised Learning. | Duc C. Le, Nur Zincir-Heywood |
| 2017 | GECCO | Return-oriented programme evolution with ROPER: a proof of concept. | Olivia Lucca Fraser, Nur Zincir-Heywood, Malcolm I. Heywood, John T. Jacobs |
| 2017 | GECCO | Properties of a GP active learning framework for streaming data with class imbalance. | Sara Khanchi, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2017 | GECCO | On evolutionary computation for moving target defense in software defined networks. | Adetokunbo Makanju, Nur Zincir-Heywood, Shinsaku Kiyomoto |
| 2017 | GECCO | Evolutionary computation in network management and security: GECCO 2017 tutorial. | Nur Zincir-Heywood, Gnes Kayacik |
| 2017 | IM | Exploring a service-based normal behaviour profiling system for botnet detection. | Weikeng Chen, Xiao Luo, Nur Zincir-Heywood |
| 2017 | SP | Effects of Shared Bandwidth on Anonymity of the I2P Network Users. | Khalid Shahbar, Nur Zincir-Heywood |
| 2016 | EUROGP | On the Impact of Class Imbalance in GP Streaming Classification with Label Budgets. | Sara Khanchi, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2016 | GECCO | Women@GECCO 2016 Chairs' Welcome. | Carola Doerr, Julia Handl, Emma Hart, Gabriela Ochoa, Amarda Shehu, Tea Tusar, Anya E. Vostinar, Christine Zarges, Nur Zincir-Heywood |
| 2016 | ICDM | Smart Phone User Behaviour Characterization Based on Autoencoders and Self Organizing Maps. | Deepthi Rajashekar, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2016 | NOMS | Autonomous system based flow marking scheme for IP-Traceback. | Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2016 | NOMS | How to choose from different botnet detection systems? | Fariba Haddadi, Duong-Tien Phan, Nur Zincir-Heywood |
| 2015 | CNSM | Deterministic flow marking for IPv6 traceback (DFM6). | Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2015 | CNSM | Traffic flow analysis of tor pluggable transports. | Khalid Shahbar, Nur Zincir-Heywood |
| 2015 | DIS | Predictive Analysis on Tracking Emails for Targeted Marketing. | Xiao Luo, Revanth Nadanasabapathy, Nur Zincir-Heywood, Keith Gallant, Janith Peduruge |
| 2015 | DIS | Benchmarking Stream Clustering for Churn Detection in Dynamic Networks. | Serdar Baran Tatar, Andrew R. McIntyre, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2015 | EUROGP | Tapped Delay Lines for GP Streaming Data Classification with Label Budgets. | Ali Vahdat, Jillian Morgan, Andrew R. McIntyre, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2015 | GECCO | Botnet Detection System Analysis on the Effect of Botnet Evolution and Feature Representation. | Fariba Haddadi, Nur Zincir-Heywood |
| 2015 | IM | Investigating unique flow marking for tracing back DDoS attacks. | Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2015 | ISPEC | On the Effectiveness of Different Botnet Detection Approaches. | Fariba Haddadi, Duc Le Cong, Laura Porter, Nur Zincir-Heywood |
| 2015 | LCN | Feature selection for robust backscatter DDoS detection. | Eray Balkanli, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2014 | AINA | TDFA: Traceback-Based Defense against DDoS Flooding Attacks. | Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2014 | AINA | Botnet Behaviour Analysis Using IP Flows: With HTTP Filters Using Classifiers. | Fariba Haddadi, Jillian Morgan, Eduardo Gomes Filho, Nur Zincir-Heywood |
| 2014 | CHI | Exploring the need for visualizations in system administration tools. | Jeevitha Mahendiran, Kirstie Hawkey, Nur Zincir-Heywood |
| 2014 | GECCO | On botnet behaviour analysis using GP and C4.5. | Fariba Haddadi, Dylan Runkel, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2014 | LCN | On the analysis of backscatter traffic. | Eray Balkanli, Nur Zincir-Heywood |
| 2014 | NOMS | A case study for a secure and robust geo-fencing and access control framework. | Hossein Rahimi, Tuerxun Maimaiti, Nur Zincir-Heywood |
| 2014 | SP | Can We Identify NAT Behavior by Analyzing Traffic Flows? | Yasemin Gokcen, Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2013 | AINA | Deterministic and Authenticated Flow Marking for IP Traceback. | Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2013 | CEC | Analyzing string format-based classifiers for botnet detection: GP and SVM. | Fariba Haddadi, Nur Zincir-Heywood |
| 2013 | CEC | How far an evolutionary approach can go for protocol state analysis and discovery. | Patrick LaRoche, Aimee Burrows, Nur Zincir-Heywood |
| 2013 | DocEng | Beyond term clusters: assigning Wikipedia concepts to scientific documents. | Ozge Yeloglu, Evangelos E. Milios, Nur Zincir-Heywood |
| 2013 | GECCO | Label free change detection on streaming data with cooperative multi-objective genetic programming. | Sara Rahimi, Andrew R. McIntyre, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2013 | IM | Automatic optimization for a clustering based approach to support IT management. | Can Bozdogan, Nur Zincir-Heywood, Yasemin Gokcen |
| 2013 | IM | Investigating event log analysis with minimum apriori information. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios |
| 2013 | SP | On Evaluating IP Traceback Schemes: A Practical Perspective. | Vahid Aghaei Foroushani, Nur Zincir-Heywood |
| 2012 | CEC | Symbiotic evolutionary subspace clustering. | Ali Vahdat, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2012 | GECCO | GP under streaming data constraints: a case for pareto archiving? | Aaron Atwater, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2012 | ICCCN | The Impact of Evasion on the Generalization of Machine Learning Algorithms to Classify VoIP Traffic. | Riyad Alshammari, Nur Zincir-Heywood |
| 2012 | NOMS | Data mining for supporting IT management. | Can Bozdogan, Nur Zincir-Heywood |
| 2012 | NOMS | Interactive learning of alert signatures in High Performance Cluster system logs. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios |
| 2012 | SAC | Spatio-temporal decomposition, clustering and identification for alert detection in system logs. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios, Markus Latzel |
| 2011 | CEC | Is machine learning losing the battle to produce transportable signatures against VoIP traffic? | Riyad Alshammari, Nur Zincir-Heywood |
| 2011 | IM | A next generation entropy based framework for alert detection in system logs. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios |
| 2011 | SAC | Storage and retrieval of system log events using a structured schema based on message type transformation. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios |
| 2011 | SAC | Multi-document summarization of scientific corpora. | Ozge Yeloglu, Evangelos E. Milios, Nur Zincir-Heywood |
| 2010 | CEC | Unveiling Skype encrypted tunnels using GP. | Riyad Alshammari, Nur Zincir-Heywood |
| 2010 | CEC | An analysis of clustering objectives for feature selection applied to encrypted traffic identification. | Carlos Bacquet, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2010 | CEC | Bottom-up evolutionary subspace clustering. | Ali Vahdat, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2010 | CNSM | An investigation on the identification of VoIP traffic: Case study on Gtalk and Skype. | Riyad Alshammari, Nur Zincir-Heywood |
| 2010 | DSN | Fast entropy based alert detection in super computer logs. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios |
| 2009 | GECCO | Classifying SSH encrypted traffic with minimum packet header features using genetic programming. | Riyad Alshammari, Peter Lichodzijewski, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2009 | KDD | Clustering event logs using iterative partitioning. | Adetokunbo Makanju, Nur Zincir-Heywood, Evangelos E. Milios |
| 2008 | PST | Investigating Two Different Approaches for Encrypted Traffic Classification. | Riyad Alshammari, Nur Zincir-Heywood |
| 2008 | PST | Mimicry Attacks Demystified: What Can Attackers Do to Evade Detection? | Hilmi Gnes Kayacik, Nur Zincir-Heywood |
| 2008 | PST | LogView: Visualizing Event Log Clusters. | Adetokunbo Makanju, Stephen Brooks, Nur Zincir-Heywood, Evangelos E. Milios |
| 2007 | AINA | On the Contribution of Preamble to Information Hiding in Mimicry Attacks. | Hilmi Gnes Kayacik, Nur Zincir-Heywood |
| 2007 | ICDE | Incorporating Temporal Information for Document Classification. | Xiao Luo, Nur Zincir-Heywood |
| 2007 | SMC | A flow based approach for SSH traffic detection. | Riyad Alshammari, Nur Zincir-Heywood |
| 2007 | SMC | Growing recurrent self organizing map. | Ozge Yeloglu, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2006 | CEC | Evolving Recurrent Linear-GP for Document Classification and Word Tracking. | Xiao Luo, Nur Zincir-Heywood |
| 2006 | EUROGP | 802.11 De-authentication Attack Detection Using Genetic Programming. | Patrick LaRoche, Nur Zincir-Heywood |
| 2006 | GECCO | On evolving buffer overflow attacks using genetic programming. | Hilmi Gnes Kayacik, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2006 | PST | Using self-organizing maps to build an attack map for forensic analysis. | Hilmi Gnes Kayacik, Nur Zincir-Heywood |
| 2005 | ACSAC | Evolving Successful Stack Overflow Attacks for Vulnerability Testing. | Hilmi Gnes Kayacik, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2005 | CEC | CasGP: building cascaded hierarchical models using niching. | Peter Lichodzijewski, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2005 | GECCO | 802.11 network intrusion detection using genetic programming. | Patrick LaRoche, Nur Zincir-Heywood |
| 2005 | GECCO | Evolving recurrent models using linear GP. | Xiao Luo, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2005 | IJCNN | Comparison of a SOM based sequence analysis system and naive Bayesian classifier for spam filtering. | Xiao Luo, Nur Zincir-Heywood |
| 2005 | ISI | Analysis of Three Intrusion Detection System Benchmark Datasets Using Machine Learning Algorithms. | Hilmi Gnes Kayacik, Nur Zincir-Heywood |
| 2005 | ISMIS | Evaluation of Two Systems on Multi-class Multi-label Document Classification. | Xiao Luo, Nur Zincir-Heywood |
| 2005 | PST | Selecting Features for Intrusion Detection: A Feature Relevance Analysis on KDD 99. | Hilmi Gnes Kayacik, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2004 | AI | Term-Based Clustering and Summarization of Web Page Collections. | Yongzheng Zhang, Nur Zincir-Heywood, Evangelos E. Milios |
| 2004 | CEC | Cascaded GP models for data mining. | Peter Lichodzijewski, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2004 | KES | Analyzing the Temporal Sequences for Text Categorization. | Xiao Luo, Nur Zincir-Heywood |
| 2003 | AI | Post-supervised Template Induction for Dynamic Web Sources. | Zhongmin Shi, Evangelos E. Milios, Nur Zincir-Heywood |
| 2003 | AI | Summarizing Web Sites Automatically. | Yongzheng Zhang, Nur Zincir-Heywood, Evangelos E. Milios |
| 2003 | GECCO | A Linear Genetic Programming Approach to Intrusion Detection. | Dong Song, Malcolm I. Heywood, Nur Zincir-Heywood |
| 2003 | IM | A Case Study of Three Open Source Security Management Tools. | Hilmi Gnes Kayacik, Nur Zincir-Heywood |
| 2003 | SAC | SOM - Feature Extraction from Patient Discharge Summaries. | Dyan J. Tufts-Conrad, Nur Zincir-Heywood, David Zitner |
| 2002 | CEC | The effect of routing under local information using a social insect metaphor. | Suiliong Liang, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2002 | GECCO | Intelligent Packets For Dynamic Network Routing Using Distributed Genetic Algorithm. | Suihong Liang, Nur Zincir-Heywood, Malcolm I. Heywood |
| 2000 | EUROGP | Register Based Genetic Programming on FPGA Computing Platforms. | Malcolm I. Heywood, Nur Zincir-Heywood |