{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T03:22:35Z","timestamp":1779074555064,"version":"3.51.4"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319469812","type":"print"},{"value":"9783319469829","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-46982-9_10","type":"book-chapter","created":{"date-parts":[[2016,9,19]],"date-time":"2016-09-19T15:41:08Z","timestamp":1474299668000},"page":"152-168","source":"Crossref","is-referenced-by-count":46,"title":["A Stream-Based Specification Language for Network Monitoring"],"prefix":"10.1007","author":[{"given":"Peter","family":"Faymonville","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bernd","family":"Finkbeiner","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sebastian","family":"Schirmer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hazem","family":"Torfah","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,20]]},"reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Ahmed, A., Lisitsa, A., Dixon, C.: A misuse-based network intrusion detection system using temporal logic and stream processing. In: 2011 5th International Conference on Network and System Security (NSS), pp. 1\u20138, September 2011","DOI":"10.1109\/ICNSS.2011.6059953"},{"key":"10_CR2","unstructured":"Ahmed, A., Lisitsa, A., Dixon, C.: TeStID: a high performance temporal intrusion detection system. In: Proceedings of the ICIMP, pp. 20\u201326 (2013)"},{"key":"10_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/978-3-642-32759-9_9","volume-title":"FM 2012: Formal Methods","author":"H Barringer","year":"2012","unstructured":"Barringer, H., Falcone, Y., Havelund, K., Reger, G., Rydeheard, D.: Quantified event automata: towards expressive and efficient runtime monitors. In: Giannakopoulou, D., M\u00e9ry, D. (eds.) FM 2012. LNCS, vol. 7436, pp. 68\u201384. Springer, Heidelberg (2012). doi: 10.1007\/978-3-642-32759-9_9"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Barringer, H., Rydeheard, D.E., Havelund, K.: Rule systems for run-time monitoring: from eagle to ruler. J. Log. Comput. 20(3), 675\u2013706 (2010). http:\/\/dx.doi.org\/10.1093\/logcom\/exn076","DOI":"10.1093\/logcom\/exn076"},{"key":"10_CR5","doi-asserted-by":"crossref","unstructured":"Berry, G.: Proof, Language, and Interaction: Essays in Honour of Robin Milner, Chap. The Foundations of Esterel, pp. 425\u2013454. MIT Press, Cambridge (2000)","DOI":"10.7551\/mitpress\/5641.003.0021"},{"key":"10_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-319-11164-3_6","volume-title":"Runtime Verification","author":"L Bozzelli","year":"2014","unstructured":"Bozzelli, L., S\u00e1nchez, C.: Foundations of boolean stream runtime verification. In: Bonakdarpour, B., Smolka, S.A. (eds.) RV 2014. LNCS, vol. 8734, pp. 64\u201379. Springer, Heidelberg (2014). doi: 10.1007\/978-3-319-11164-3_6"},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"D\u2019Angelo, B., Sankaranarayanan, S., S\u00e1nchez, C., Robinson, W., Finkbeiner, B., Sipma, H.B., Mehrotra, S., Manna, Z.: Lola: runtime monitoring of synchronous systems. In: 12th International Symposium on Temporal Representation and Reasoning (TIME 2005), pp. 166\u2013174. IEEE Computer Society Press, June 2005","DOI":"10.1109\/TIME.2005.26"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Debar, H., Becker, M., Siboni, D.: A neural network component for an intrusion detection system. In: Proceedings of 1992 IEEE Computer Society Symposium on Research in Security and Privacy, pp. 240\u2013250, May 1992","DOI":"10.1109\/RISP.1992.213257"},{"key":"10_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/978-3-642-54013-4_20","volume-title":"Verification, Model Checking, and Abstract Interpretation","author":"P Faymonville","year":"2014","unstructured":"Faymonville, P., Finkbeiner, B., Peled, D.: Monitoring parametric temporal logic. In: McMillan, K.L., Rival, X. (eds.) VMCAI 2014. LNCS, vol. 8318, pp. 357\u2013375. Springer, Heidelberg (2014). doi: 10.1007\/978-3-642-54013-4_20"},{"key":"10_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/3-540-18317-5_15","volume-title":"Functional Programming Languages and Computer Architecture","author":"T Gautier","year":"1987","unstructured":"Gautier, T., Guernic, P., Besnard, L.: SIGNAL: a declarative language for synchronous programming of real-time systems. In: Kahn, G. (ed.) FPCA 1987. LNCS, vol. 274, pp. 257\u2013277. Springer, Heidelberg (1987). doi: 10.1007\/3-540-18317-5_15"},{"key":"10_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-89247-2_1","volume-title":"Runtime Verification","author":"J Goubault-Larrecq","year":"2008","unstructured":"Goubault-Larrecq, J., Olivain, J.: A smell of Orchids. In: Leucker, M. (ed.) RV 2008. LNCS, vol. 5289, pp. 1\u201320. Springer, Heidelberg (2008). doi: 10.1007\/978-3-540-89247-2_1"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Halbwachs, N., Caspi, P., Raymond, P., Pilaud, D.: The synchronous data-flow programming language lustre. Proc. IEEE 79(9), 1305\u20131320. citeseer.ist.psu.edu\/halbwachs91synchronous.html","DOI":"10.1109\/5.97300"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Havelund, K.: Rule-based runtime verification revisited. Int. J. Softw. Tools Technol. Transf. 17(2), 143\u2013170 (2015). http:\/\/dx.doi.org\/10.1007\/s10009-014-0309-2","DOI":"10.1007\/s10009-014-0309-2"},{"key":"10_CR14","unstructured":"Lee, W., Park, C.T., Stolfo, S.J.: Automated intrusion detection using NFR: methods and experiences. In: Proceedings of the Workshop on Intrusion Detection and Network Monitoring, Santa Clara, 9\u201312 April 1999, pp. 63\u201372. USENIX (1999). http:\/\/www.usenix.org\/publications\/library\/proceedings\/detection99\/lee.html"},{"key":"10_CR15","unstructured":"Lee, W., Stolfo, S.J., Mok, K.W.: A data mining framework for building intrusion detection models. In: Proceedings of the 1999 IEEE Symposium on Security and Privacy, pp. 120\u2013132 (1999)"},{"key":"10_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-540-30232-2_23","volume-title":"Formal Techniques for Networked and Distributed Systems \u2013 FORTE 2004","author":"P Naldurg","year":"2004","unstructured":"Naldurg, P., Sen, K., Thati, P.: A temporal logic based framework for intrusion detection. In: Frutos-Escrig, D., N\u00fa\u00f1ez, M. (eds.) FORTE 2004. LNCS, vol. 3235, pp. 359\u2013376. Springer, Heidelberg (2004). doi: 10.1007\/978-3-540-30232-2_23"},{"key":"10_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"286","DOI":"10.1007\/11513988_28","volume-title":"Computer Aided Verification","author":"J Olivain","year":"2005","unstructured":"Olivain, J., Goubault-Larrecq, J.: The Orchids intrusion detection tool. In: Etessami, K., Rajamani, S.K. (eds.) CAV 2005. LNCS, vol. 3576, pp. 286\u2013290. Springer, Heidelberg (2005). doi: 10.1007\/11513988_28"},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"Paxson, V.: Bro: a system for detecting network intruders in real-time. Comput. Netw. 31(23\u201324), 2435\u20132463. http:\/\/dx.doi.org\/10.1016\/S1389-1286(99)00112-7","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"10_CR19","unstructured":"Roesch, M.: Snort - lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration. LISA 1999, USENIX Association, Berkeley, pp. 229\u2013238 (1999). http:\/\/dl.acm.org\/citation.cfm?id=1039834.1039864"},{"key":"10_CR20","doi-asserted-by":"crossref","unstructured":"Roger, M., Goubault-Larrecq, J.: Log auditing through model-checking. In: Computer Security Foundations Workshop, p. 0220. IEEE (2001)","DOI":"10.1109\/CSFW.2001.930148"},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"Rosu, G., Chen, F.: Semantics and algorithms for parametric monitoring. Log. Methods Comput. Sci. 8(1) (2012). http:\/\/dx.doi.org\/10.2168\/LMCS-8(1:9)2012","DOI":"10.2168\/LMCS-8(1:9)2012"}],"container-title":["Lecture Notes in Computer Science","Runtime Verification"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-46982-9_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T12:58:47Z","timestamp":1718801927000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-46982-9_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319469812","9783319469829"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-46982-9_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}