{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T21:12:10Z","timestamp":1762981930666,"version":"3.40.3"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031708893"},{"type":"electronic","value":"9783031708909"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70890-9_11","type":"book-chapter","created":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T09:24:24Z","timestamp":1725528264000},"page":"202-221","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Process Identity-Based Firewalling"],"prefix":"10.1007","author":[{"given":"Radu","family":"Mantu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mihai","family":"Chiroiu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Costin","family":"Raiciu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,9,6]]},"reference":[{"issue":"1","key":"11_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3447382","volume":"5","author":"I Akbari","year":"2021","unstructured":"Akbari, I., et al.: A look behind the curtain: traffic classification in an increasingly encrypted web. Proc. ACM Meas. Anal. Comput. Syst. 5(1), 1\u201326 (2021)","journal-title":"Proc. ACM Meas. Anal. Comput. Syst."},{"key":"11_CR2","doi-asserted-by":"crossref","unstructured":"Basta, N., Ikram, M., Kaafar, M.A., Walker, A.: Towards a zero-trust micro-segmentation network security strategy: an evaluation framework. In: NOMS 2022-2022 IEEE\/IFIP Network Operations and Management Symposium, pp.\u00a01\u20137. IEEE (2022)","DOI":"10.1109\/NOMS54207.2022.9789888"},{"issue":"3","key":"11_CR3","doi-asserted-by":"publisher","first-page":"687","DOI":"10.1007\/s11219-022-09607-z","volume":"31","author":"S Butler","year":"2023","unstructured":"Butler, S., et al.: On business adoption and use of reproducible builds for open and closed source software. Softw. Qual. J. 31(3), 687\u2013719 (2023)","journal-title":"Softw. Qual. J."},{"key":"11_CR4","doi-asserted-by":"publisher","unstructured":"Camarillo, G., Audet, F., Rosenberg, J., Boulton, C.: NAT traversal practices for client-server SIP. RFC 6314 (2011). https:\/\/doi.org\/10.17487\/RFC6314, https:\/\/rfc-editor.org\/rfc\/rfc6314.txt","DOI":"10.17487\/RFC6314"},{"key":"11_CR5","unstructured":"Davidson, M., Marchuk, W., Zaugg, A., Garate, M., Buenzle, W.: Distributed firewall (DFW): network security at the host level at LinkedIn (2021). https:\/\/engineering.linkedin.com\/blog\/2021\/distributed-firewall-network-security"},{"key":"11_CR6","unstructured":"Fairhurst, G., Jones, T., Zullo, R.: Checksum compensation options for UDP options. Internet-Draft draft-fairhurst-udp-options-cco-00, Internet Engineering Task Force (2018). https:\/\/datatracker.ietf.org\/doc\/draft-fairhurst-udp-options-cco\/00\/, work in Progress"},{"key":"11_CR7","unstructured":"Fonseca, R., Porter, G., Katz, R., Shenker, S., Stoica, I.: IP options are not an option. Technical report, EECS Department, University of California, Berkeley (2005)"},{"key":"11_CR8","unstructured":"Gancheva, Z., Sattler, P., W\u00fcstrich, L.: TLS fingerprinting techniques. Network 15 (2020)"},{"key":"11_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-642-23644-0_2","volume-title":"Recent Advances in Intrusion Detection","author":"B Gilbert","year":"2011","unstructured":"Gilbert, B., Kemmerer, R., Kruegel, C., Vigna, G.: Dymo: tracking dynamic code identity. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol. 6961, pp. 21\u201340. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23644-0_2"},{"key":"11_CR10","unstructured":"Gon\u00e7alves, G., O\u2019Malley, K., Saltonstall, M., et\u00a0al.: BeyondCorp and the long tail of zero trust (2023)"},{"key":"11_CR11","doi-asserted-by":"crossref","unstructured":"Goodchild, B.J., et al.: The record route option is an option! In: Proceedings of the 2017 Internet Measurement Conference, pp. 311\u2013317 (2017)","DOI":"10.1145\/3131365.3131392"},{"issue":"1","key":"11_CR12","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1186\/s42400-022-00127-8","volume":"5","author":"J Heino","year":"2022","unstructured":"Heino, J., Hakkala, A., Virtanen, S.: Study of methods for endpoint aware inspection in a next generation firewall. Cybersecurity 5(1), 25 (2022)","journal-title":"Cybersecurity"},{"key":"11_CR13","doi-asserted-by":"crossref","unstructured":"Ioannidis, S., Keromytis, A.D., Bellovin, S.M., Smith, J.M.: Implementing a distributed firewall. In: Proceedings of the 7th ACM Conference on Computer and Communications Security, pp. 190\u2013199 (2000)","DOI":"10.1145\/352600.353052"},{"key":"11_CR14","unstructured":"John, P.: Transmission control protocol. RFC 793 (1981)"},{"key":"11_CR15","unstructured":"Kazemian, P., Varghese, G., McKeown, N.: Header space analysis: static checking for networks. In: 9th USENIX Symposium on Networked Systems Design and Implementation (NSDI 2012), pp. 113\u2013126 (2012)"},{"issue":"6","key":"11_CR16","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1145\/1323293.1294293","volume":"41","author":"M Krohn","year":"2007","unstructured":"Krohn, M., et al.: Information flow control for standard OS abstractions. ACM SIGOPS Oper. Syst. Rev. 41(6), 321\u2013334 (2007)","journal-title":"ACM SIGOPS Oper. Syst. Rev."},{"key":"11_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-030-52683-2_2","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"M Ohm","year":"2020","unstructured":"Ohm, M., Plate, H., Sykosch, A., Meier, M.: Backstabber\u2019s knife collection: a review of open source software supply chain attacks. In: Maurice, C., Bilge, L., Stringhini, G., Neves, N. (eds.) DIMVA 2020. LNCS, vol. 12223, pp. 23\u201343. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-52683-2_2"},{"key":"11_CR18","unstructured":"Osborn, B., McWilliams, J., Beyer, B., Saltonstall, M.: BeyondCorp: design to deployment at Google (2016)"},{"key":"11_CR19","doi-asserted-by":"crossref","unstructured":"Parno, B., Zhou, Z., Perrig, A.: Using trustworthy host-based information in the network. In: Proceedings of the Seventh ACM Workshop on Scalable Trusted Computing, pp. 33\u201344 (2012)","DOI":"10.1145\/2382536.2382544"},{"key":"11_CR20","unstructured":"Richard, S.: Four paths to true network security. Technical report, Commentary COM-20-0571, Gartner Research (2003)"},{"key":"11_CR21","doi-asserted-by":"crossref","unstructured":"Radivilova, T., Kirichenko, L., Ageyev, D., Tawalbeh, M., Bulakh, V.: Decrypting SSL\/TLS traffic for hidden threats detection. In: 2018 IEEE 9th International Conference on Dependable Systems, Services and Technologies (DESSERT), pp. 143\u2013146. IEEE (2018)","DOI":"10.1109\/DESSERT.2018.8409116"},{"key":"11_CR22","doi-asserted-by":"crossref","unstructured":"Mantu, R., Chiroiu, M., T\u0103pus, N.: Framework for evaluating TCP\/IP extensions in communication protocols. Int. J. Comput. Commun. Control (April) 19 (2024)","DOI":"10.15837\/ijccc.2024.2.4906"},{"key":"11_CR23","doi-asserted-by":"crossref","unstructured":"Salim, J., Khosravi, H., Kleen, A., Kuznetsov, A.: Linux netlink as an IP services protocol. RFC\u00a03549, RFC Editor (2003)","DOI":"10.17487\/rfc3549"},{"key":"11_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-540-87403-4_3","volume-title":"Recent Advances in Intrusion Detection","author":"A Srivastava","year":"2008","unstructured":"Srivastava, A., Giffin, J.: Tamper-resistant, application-aware blocking of malicious network connections. In: Lippmann, R., Kirda, E., Trachtenberg, A. (eds.) RAID 2008. LNCS, vol. 5230, pp. 39\u201358. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-87403-4_3"},{"key":"11_CR25","unstructured":"Stafford, V.: Zero trust architecture. NIST Spec. Publ. 800, 207 (2020)"},{"key":"11_CR26","doi-asserted-by":"publisher","unstructured":"Touch, D.J.D.: Shared use of experimental TCP options. RFC 6994 (2013). https:\/\/doi.org\/10.17487\/RFC6994, https:\/\/rfc-editor.org\/rfc\/rfc6994.txt","DOI":"10.17487\/RFC6994"},{"key":"11_CR27","unstructured":"Touch, D.J.D.: Transport options for UDP. Internet-Draft draft-ietf-tsvwg-udp-options-23, Internet Engineering Task Force (2023). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-tsvwg-udp-options\/23\/. Work in Progress"},{"key":"11_CR28","unstructured":"Touch, D.J.D., Eddy, W.: TCP extended data offset option. Internet-Draft draft-ietf-tcpm-tcp-edo-13, Internet Engineering Task Force (2022). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-tcpm-tcp-edo\/13\/. Work in Progress"},{"key":"11_CR29","unstructured":"Trieu, H., Touch, J., Faber, T.: Implementation of the TCP extended data offset option. USC Information Sciences Institute, Marina Del Rey, CA, USA, Technical report, ISI-TR-696 (2015)"},{"key":"11_CR30","unstructured":"Ward, R., Beyer, B.: BeyondCorp: a new approach to enterprise security (2014)"},{"key":"11_CR31","doi-asserted-by":"crossref","unstructured":"Yun, X., Wang, Y., Zhang, Y., Zhao, C., Zhao, Z.: Encrypted TLS traffic classification on cloud platforms. IEEE\/ACM Trans. Netw. (2022)","DOI":"10.1109\/TNET.2022.3191312"},{"issue":"11","key":"11_CR32","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1145\/2018396.2018419","volume":"54","author":"N Zeldovich","year":"2011","unstructured":"Zeldovich, N., Boyd-Wickizer, S., Kohler, E., Mazieres, D.: Making information flow explicit in HiStar. Commun. ACM 54(11), 93\u2013101 (2011)","journal-title":"Commun. ACM"},{"key":"11_CR33","unstructured":"Zeldovich, N., Boyd-Wickizer, S., Mazieres, D.: Securing distributed systems with information flow control. In: NSDI, vol.\u00a08, pp. 293\u2013308 (2008)"},{"key":"11_CR34","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Zhao, S., Zhang, J., Ma, X., Huang, F.: STNN: a novel TLS\/SSL encrypted traffic classification system based on stereo transform neural network. In: 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS), pp. 907\u2013910. IEEE (2019)","DOI":"10.1109\/ICPADS47876.2019.00133"},{"key":"11_CR35","unstructured":"Zullo, R., Jones, T., Fairhurst, G.: Overcoming the sorrows of the young UDP options. In: TMA (2020)"},{"key":"11_CR36","doi-asserted-by":"crossref","unstructured":"Zungur, O., Suarez-Tangil, G., Stringhini, G., Egele, M.: BorderPatrol: securing BYOD using fine-grained contextual information. In: 2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 460\u2013472. IEEE (2019)","DOI":"10.1109\/DSN.2019.00054"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70890-9_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T09:26:37Z","timestamp":1725528397000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70890-9_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031708893","9783031708909"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70890-9_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"6 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}