{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T13:12:51Z","timestamp":1783689171824,"version":"3.55.0"},"reference-count":46,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001659","name":"German Research Foundation","doi-asserted-by":"crossref","award":["DR 639\/20-1"],"award-info":[{"award-number":["DR 639\/20-1"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022,1,1]]},"DOI":"10.1109\/tdsc.2020.2973992","type":"journal-article","created":{"date-parts":[[2020,2,14]],"date-time":"2020-02-14T21:18:35Z","timestamp":1581715115000},"page":"495-506","source":"Crossref","is-referenced-by-count":57,"title":["On High-Speed Flow-Based Intrusion Detection Using Snort-Compatible Signatures"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5169-3060","authenticated-orcid":false,"given":"Felix","family":"Erlacher","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1989-1750","authenticated-orcid":false,"given":"Falko","family":"Dressler","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.31"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2002.1012428"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(98)00017-6"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.052213.00046"},{"key":"ref5","first-page":"229","article-title":"Snort - Lightweight intrusion detection for networks","volume-title":"Proc. 13th USENIX Conf. Syst. Admin.","author":"Roesch"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-017-9421-4"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN.2011.6006063"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2017.18"},{"key":"ref9","doi-asserted-by":"crossref","DOI":"10.17487\/rfc5101","article-title":"Specification of the IP flow information export (IPFIX) protocol for the exchange of IP traffic flow information","author":"Claise","year":"2008"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.17487\/rfc5102"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2014.2321898"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2342356.2342393"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-15509-8_14"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/LCN.2016.88"},{"key":"ref15","article-title":"A TLS interception proxy with real-time libpcap export","volume-title":"Proc. 41st IEEE Conf. Local Comput. Netw.","author":"Erlacher"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.4324\/9781315619309-5"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/PIMRC.2007.4394186"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2018.8406247"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-87403-4_7"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.1422"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICPP.2017.56"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330137"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOMW.2011.5928926"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2015.7140452"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879169"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2010.032210.00054"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.05.009"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CNSM.2013.6727841"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0204507"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/IWCIP.2005.2"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2014.2358817"},{"key":"ref32","first-page":"1","article-title":"Flow-based worm detection using correlated honeypot logs","volume-title":"Proc. Commun. Distrib. Syst. 15. ITG\/GI Symp.","author":"Dressler"},{"key":"ref33","first-page":"131","article-title":"Flow-based detection of RDP brute-force attacks","volume-title":"Proc. 7th Int. Conf. Secur. Protection Inf.","author":"Vizvary"},{"key":"ref34","article-title":"Unveiling SSHCure 3.0: Flow-based SSH compromise detection","volume-title":"Proc. Int. Conf. Netw. Syst.","author":"Hofstede"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2018.1331021"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.17487\/rfc3758"},{"key":"ref37","first-page":"1","article-title":"nProbe: An open source NetFlow probe for gigabit networks","volume-title":"Proc. TERENA Netw. Conf.","author":"Deri"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1921168.1921179"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1080\/19393555.2015.1125974"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.5220\/0006639801080116"},{"key":"ref41","first-page":"33","article-title":"Performance evaluation in high-speed networks by the example of intrusion detection systems","volume-title":"11. DFN-Forum Kommunikationstechnologien","author":"Lukaseder","year":"2018"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-34883-9_19"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3229598.3229601"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3234200.3234204"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3098583.3098590"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2011.5958211"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/9625881\/08999496.pdf?arnumber=8999496","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T22:37:05Z","timestamp":1704839825000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8999496\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,1]]},"references-count":46,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2020.2973992","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,1]]}}}