{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,21]],"date-time":"2025-03-21T04:14:23Z","timestamp":1742530463767,"version":"3.40.1"},"reference-count":27,"publisher":"Elsevier BV","issue":"2","license":[{"start":{"date-parts":[[2002,6,1]],"date-time":"2002-06-01T00:00:00Z","timestamp":1022889600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2002,6]]},"DOI":"10.1016\/s1389-1286(01)00301-2","type":"journal-article","created":{"date-parts":[[2012,2,14]],"date-time":"2012-02-14T21:30:18Z","timestamp":1329255018000},"page":"93-112","source":"Crossref","is-referenced-by-count":8,"title":["Evaluation of the performance of ID systems in a switched and distributed environment: the RealSecure case study"],"prefix":"10.1016","volume":"39","author":[{"given":"Charles","family":"Iheagwara","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrew","family":"Blyth","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"year":"1995","author":"Chapman","series-title":"Building Internet Firewalls","key":"10.1016\/S1389-1286(01)00301-2_BIB1"},{"year":"1994","author":"Cheswick","series-title":"Firewalls and Internet security: repelling the wily hacker","key":"10.1016\/S1389-1286(01)00301-2_BIB2"},{"unstructured":"D. Chapman, Network (in) security through IP packet filtering, in: Proceedings of the Third USENIX UNIX Security Symposium, Baltimore, MD, September, 1992","key":"10.1016\/S1389-1286(01)00301-2_BIB3"},{"unstructured":"D. Anderson, T. Frivold, A. Valdes, Next-generation intrusion-detection expert system (NIDES): final technical report, Technical report, Computer Science Laboratory, SRI International, Menlo Park, CA, 16 November, 1994","key":"10.1016\/S1389-1286(01)00301-2_BIB4"},{"issue":"2","key":"10.1016\/S1389-1286(01)00301-2_BIB5","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1109\/TSE.1987.232894","article-title":"An intrusion-detection model","volume":"13","author":"Denning","year":"1987","journal-title":"IEEE Transactions on Software Engineering"},{"unstructured":"T.F. Lunt, R. Jagannathan, R. Lee, A. Whitehurst, S. Listgarten, Knowledge-based intrusion detection, in: Proceedings of the 1989 AI systems in Government Conference, March 1989","key":"10.1016\/S1389-1286(01)00301-2_BIB6"},{"unstructured":"T.F. Lunt, A. Tamaru, F. Gilham, R. Jagannathan, C. Jalali, P.G. Neumann, H.S. Javitz, A. Valdes, A real-time intrusion-detection expert system (IDES), Technical report, Computer Science Laboratory, SRI International, Menlo Park, CA, 28 February, 1992","key":"10.1016\/S1389-1286(01)00301-2_BIB7"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB8","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1109\/65.244794","article-title":"Alarm correlation","author":"Jakobson","year":"1993","journal-title":"IEEE Network"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB9","series-title":"Proceedings of the Fourth International Symposium on Integrated Network Management (IFIP\/IEEE), Santa Barbara, CA","first-page":"266","article-title":"A coding approach to event correlation","author":"Kliger","year":"1995"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB10","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/65.244791","article-title":"Monitoring distributed systems","author":"Mansouri-Samani","year":"1993","journal-title":"IEEE Network"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB11","series-title":"Proceedings of the Fourth International Symposium on Integrated Network Management (IFIP\/IEEE), Santa Barbara, CA","first-page":"4","article-title":"Decentralizing control and intelligence in network management","author":"Meyer","year":"1995"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB12","series-title":"Proceedings of the 1990 Symposium on Research in Security and Privacy, Oakland, CA","first-page":"296","article-title":"A network security monitor","author":"Heberlein","year":"1990"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB13","series-title":"Proceedings of the Fourteenth Computer Security Group Conference","article-title":"An expert system application for network intrusion detection","author":"Jackson","year":"1991"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB14","series-title":"Proceedings of the Fourteenth National Computer Security Conference, Washington DC","first-page":"167","article-title":"DID SYSTEM (Distributed ID system)\u2013motivation, architecture, and an early prototype","author":"Snapp","year":"1991"},{"unstructured":"S. Staniford-Chen, L.T. Heberlein., Holding intruders accountable on the Internet, in: Proceedings of the IEEE Symposium on Security and Privacy, 1995","key":"10.1016\/S1389-1286(01)00301-2_BIB15"},{"unstructured":"R.T. Morris, A weakness in the 4.2BSD UNIX TCP\/IP software, in: Computing Science Technical Report 117. AT&T Bell Laboratories, Murray Hills, NJ, 25 February, 1985","key":"10.1016\/S1389-1286(01)00301-2_BIB16"},{"unstructured":"U. Maimon, Port scanning without the SYN flag, Phrack Magazine 7 (49) (1997)","key":"10.1016\/S1389-1286(01)00301-2_BIB17"},{"doi-asserted-by":"crossref","unstructured":"A. Mounji, B. Le Charlier, D. Zampunieris, Distributed audit trail analysis, in: Proceedings of the ISOC 1995 Symposium on Network and Distributed system Security, February 1995, pp. 102\u2013112","key":"10.1016\/S1389-1286(01)00301-2_BIB18","DOI":"10.1109\/NDSS.1995.390641"},{"unstructured":"P.A. Porras, STAT: A state transition analysis tool for intrusion detection, Master's thesis, Computer Science Department, University of California, Santa Barbara, July 1992","key":"10.1016\/S1389-1286(01)00301-2_BIB19"},{"unstructured":"J. Postel, Internet protocol, request for comment, RFC 791, Technical report, Information Sciences Institute, September 1981","key":"10.1016\/S1389-1286(01)00301-2_BIB20"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB21","series-title":"Proceedings of the COMPSEC-95 Conference","article-title":"Project SATAN: UNIX\/Internet security","author":"Venema","year":"1995"},{"key":"10.1016\/S1389-1286(01)00301-2_BIB22","doi-asserted-by":"crossref","first-page":"671","DOI":"10.1016\/S0167-4048(99)80131-X","article-title":"Network based intrusion detection: a review of technologies","volume":"18","author":"Richards","year":"1999","journal-title":"Computers & Security"},{"unstructured":"P.A. Porras, A. Valdes, Live traffic analysis of TCP\/IP Gateways, Internet Society's Networks and Distributed systems Security Symposium, March 1998","key":"10.1016\/S1389-1286(01)00301-2_BIB23"},{"unstructured":"P.A. Porras, P.G. Neumann, EMERALD: event monitoring enabling responses to anomalous live disturbances, in: National Information systems Security Conference, Baltimore, MD, October 1997, pp. 353\u2013365","key":"10.1016\/S1389-1286(01)00301-2_BIB24"},{"year":"1999","author":"Ptacek","series-title":"Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection","key":"10.1016\/S1389-1286(01)00301-2_BIB25"},{"unstructured":"S. Kumar, Classification and Detection of Computer Intrusions, Ph.D. Dissertation, Department of Computer Sciences, Purdue University, 1995","key":"10.1016\/S1389-1286(01)00301-2_BIB26"},{"doi-asserted-by":"crossref","unstructured":"Internet Security Systems and Top Layer Network, Inc., Gigabit Ethernet intrusion detection solutions: performance test and results, Technical Manual, 25 July, 2000","key":"10.1016\/S1389-1286(01)00301-2_BIB27","DOI":"10.1016\/S1353-4858(00)10012-1"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128601003012?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128601003012?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,3,20]],"date-time":"2025-03-20T20:12:45Z","timestamp":1742501565000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128601003012"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2002,6]]},"references-count":27,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2002,6]]}},"alternative-id":["S1389128601003012"],"URL":"https:\/\/doi.org\/10.1016\/s1389-1286(01)00301-2","relation":{},"ISSN":["1389-1286"],"issn-type":[{"type":"print","value":"1389-1286"}],"subject":[],"published":{"date-parts":[[2002,6]]}}}