{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,23]],"date-time":"2025-04-23T05:27:56Z","timestamp":1745386076277},"publisher-location":"Berlin, Heidelberg","reference-count":24,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540408789"},{"type":"electronic","value":"9783540452485"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2003]]},"DOI":"10.1007\/978-3-540-45248-5_9","type":"book-chapter","created":{"date-parts":[[2010,6,28]],"date-time":"2010-06-28T00:40:20Z","timestamp":1277685620000},"page":"155-172","source":"Crossref","is-referenced-by-count":48,"title":["Characterizing the Performance of Network Intrusion Detection Sensors"],"prefix":"10.1007","author":[{"given":"Lambert","family":"Schaelicke","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Slabach","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Branden","family":"Moore","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Curt","family":"Freeland","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"2","key":"9_CR1","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1109\/49.215015","volume":"11","author":"D. Banks","year":"1993","unstructured":"Banks, D., Prudence, M.: A High-performance Network Architecture for a PA-RISC Workstation. IEEE Journal on Selected Areas in Communications\u00a011(2), 191\u2013202 (1993)","journal-title":"IEEE Journal on Selected Areas in Communications"},{"key":"9_CR2","unstructured":"Cheung, S., Crawford, R., Dilger, M., Frank, J., Hoagland, J., Levitt, K., Staniford-Chen, S., Yip, R., Zerkle, D.: The Design of GrIDS: A Graph-Based Intrusion Detection System, tech. report CSE-99-02, Computer Science Dept., Univ. of California Davis, Calif (1999)"},{"key":"9_CR3","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1109\/35.29545","volume":"27","author":"D. Clark","year":"1989","unstructured":"Clark, D., Jacobson, V., Romkey, J., Salwen, M.: An Analysis of TCP Processing Overhead. IEEE Communications Magazine\u00a027, 23\u201329 (1989)","journal-title":"IEEE Communications Magazine"},{"key":"9_CR4","first-page":"367","volume-title":"Proc. DARPA Information Survivability Conference and Exposition (DISCEX II 2002)","author":"J. Coit","year":"2002","unstructured":"Coit, J., Staniford, S., McAlerney, J.: Towards Faster String Matching for Intrusion Detection or Exceeding the Speed of Snort. In: Proc. DARPA Information Survivability Conference and Exposition (DISCEX II 2002), pp. 367\u2013373. IEEE CS Press, Los Alamitos (2002)"},{"key":"9_CR5","unstructured":"Danyliw, R.: ACID: Analysis Console for Intrusion Databases (2001), http:\/\/acidlab.sourceforge.net"},{"key":"9_CR6","unstructured":"Edwards, S.: Vulnerabilities of Network Intrusion Detection Systems: Realizing and Overcoming the Risks. The Case for Flow Mirroring, whitepaper, Top Layer Networks, Inc. (2002)"},{"key":"9_CR7","unstructured":"Egorov, S., Savchuk, G.: SNORTRAN: An Optimizing Compiler for Snort Rules. whitepaper, Fidelis Security Systems, Inc."},{"key":"9_CR8","unstructured":"Gallatin, J.C., Yocum, K.: Trapeze\/IP: TCP\/IP at Near-Gigabit Speeds. In: Proc. 1999 Usenix Technical Conference, Usenix Assoc., Berkeley, Calif, pp. 109\u2013120 (1999)"},{"key":"9_CR9","doi-asserted-by":"crossref","unstructured":"Haines, J., Lippmann, R., Fried, D., Korba, J., Das, K.: 1999 DARPA Intrusion Detection System Evaluation: Design and Procedures, tech. report 1062, MIT Lincoln Laboratory Technical Report, Boston, Mass (2001)","DOI":"10.1016\/S1389-1286(00)00139-0"},{"key":"9_CR10","unstructured":"Hinton, G., et al.: The Microarchitecture of the Pentium 4 Processor. Intel Technology Journal, Q1 (2001)"},{"key":"9_CR11","unstructured":"Kruegel, C., Toth, T.: Automatic Rule Clustering for improved, signature-based Intrusion Detection, tech. report, Distributed Systems Group, Technical Univ. Vienna, Austria"},{"key":"9_CR12","volume-title":"Proc. IEEE Symposium Security and Privacy","author":"C. Kruegel","year":"2002","unstructured":"Kruegel, C., Valeur, F., Vigna, G., Kemmerer, R.: Stateful Intrusion Detection for High- Speed Networks. In: Proc. IEEE Symposium Security and Privacy, IEEE Computer Society Press, Calif (2002)"},{"issue":"1","key":"9_CR13","first-page":"4","volume":"6","author":"D. Marr","year":"2002","unstructured":"Marr, D., et al.: Hyper-Threading Technology Architecture and Microarchitecture. Intel Technology Journal\u00a06(1), 4\u201315 (2002)","journal-title":"Intel Technology Journal"},{"issue":"23-24","key":"9_CR14","doi-asserted-by":"publisher","first-page":"2435","DOI":"10.1016\/S1389-1286(99)00112-7","volume":"31","author":"V. Paxson","year":"1999","unstructured":"Paxson, V.: Bro: A System for Detecting Network Intruders in Real-Time. Computer Networks\u00a031(23-24), 2435\u20132463 (1999)","journal-title":"Computer Networks"},{"key":"9_CR15","unstructured":"Protocol Analysis vs. Pattern Matching. whitepaper, Network ICE (2000)"},{"issue":"10","key":"9_CR16","doi-asserted-by":"publisher","first-page":"719","DOI":"10.1109\/32.544350","volume":"22","author":"N. Puketza","year":"1996","unstructured":"Puketza, N., Zhang, K., Chung, M., Mukherjee, B., Olsson, R.: A Methodology for Testing Intrusion Detection Systems. IEEE Transactions Software Engineering\u00a022(10), 719\u2013729 (1996)","journal-title":"IEEE Transactions Software Engineering"},{"key":"9_CR17","unstructured":"Ranum, M.: Experiences Benchmarking Intrusion Detection Systems. whitepaper, Network Flight Recorder Security, Inc., http:\/\/www.snort.org\/docs\/Benchmarking-IDS-NFR.pdf"},{"key":"9_CR18","unstructured":"Roesch, M.: Snort \u2013 Lightweight Intrusion Detection for Networks. In: Proc. Usenix LISA 1999 Conf. (November 1999), http:\/\/www.snort.org\/docs\/lisapaper.txt"},{"key":"9_CR19","volume-title":"Proc. 15th ACM Symp. Operating System Principles","author":"M. Rosenblum","year":"1995","unstructured":"Rosenblum, M., Bugnion, E., Herrod, S., Witchel, E., Gupta, A.: The Impact of Architectural Trends on Operating System Performance. In: Proc. 15th ACM Symp. Operating System Principles, ACM Press, New York (1995)"},{"key":"9_CR20","volume-title":"Proc. 6th ACM Symp. Computer and Communication Security","author":"R. Sekar","year":"1999","unstructured":"Sekar, R., Guang, Y., Verma, S., Shanbhag, T.: A High-Performance Network Intrusion Detection System. In: Proc. 6th ACM Symp. Computer and Communication Security, ACM Press, New York (1999)"},{"key":"9_CR21","unstructured":"Snort 2.0 - Detection Revisited. whitepaper, Sourcefire Network Security Inc. (2002)"},{"key":"9_CR22","unstructured":"Snort Rules for Version 1.9.x as of (March 25, 2003), http:\/\/www.snort.org\/dl\/rules\/snortrules-stable.tar.gz"},{"issue":"3","key":"9_CR23","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1109\/2.268886","volume":"27","author":"P. Steenkiste","year":"1994","unstructured":"Steenkiste, P.: A Systematic Approach to Host Interface Design for High-Speed Networks. IEEE Computer\u00a027(3), 47\u201357 (1994)","journal-title":"IEEE Computer"},{"key":"9_CR24","unstructured":"McVoy, L., Staelin, C.: lmbench: Portable Tools for Performance Analysis. In: Proc. USENIX Ann. Technical Conference, Usenix Assoc., Berkeley, Calif., pp. 279\u2013294 (1998)"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-45248-5_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,30]],"date-time":"2019-05-30T09:40:10Z","timestamp":1559209210000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-45248-5_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003]]},"ISBN":["9783540408789","9783540452485"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-45248-5_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2003]]}}}