{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:31:53Z","timestamp":1750307513634,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2009,9,20]],"date-time":"2009-09-20T00:00:00Z","timestamp":1253404800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2009,9,20]]},"DOI":"10.1145\/1614320.1614355","type":"proceedings-article","created":{"date-parts":[[2009,9,22]],"date-time":"2009-09-22T14:18:08Z","timestamp":1253629088000},"page":"309-320","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":29,"title":["OpenLIDS"],"prefix":"10.1145","author":[{"given":"Fabian","family":"Hugelshofer","sequence":"first","affiliation":[{"name":"Lancaster University, Lancaster, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Smith","sequence":"additional","affiliation":[{"name":"Lancaster University, Lancaster, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Hutchison","sequence":"additional","affiliation":[{"name":"Lancaster University, Lancaster, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas J.P.","family":"Race","sequence":"additional","affiliation":[{"name":"Lancaster University, Lancaster, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,9,20]]},"reference":[{"volume-title":"August","year":"2008","key":"e_1_3_2_1_1_1","unstructured":"aMule. http:\/\/www.amule.org , August 2008 . aMule. http:\/\/www.amule.org, August 2008."},{"key":"e_1_3_2_1_2_1","volume-title":"The USENIX magazine, 32(3):34--39","author":"Ayuso P.","year":"2006","unstructured":"P. Ayuso . Netfilter's connection tracking system. LOGIN; , The USENIX magazine, 32(3):34--39 , 2006 . P. Ayuso. Netfilter's connection tracking system. LOGIN;, The USENIX magazine, 32(3):34--39, 2006."},{"key":"e_1_3_2_1_3_1","first-page":"238","volume-title":"An Active Traffic Splitter Architecture for Intrusion Detection. In MASCOTS 2003. 11th IEEE\/ACM International Symposium on Modeling, Analysis and Simulation of Computer Telecommunications Systems","author":"Charitakis I.","year":"2003","unstructured":"I. Charitakis , K. Anagnostakis , and E. Markatos . An Active Traffic Splitter Architecture for Intrusion Detection. In MASCOTS 2003. 11th IEEE\/ACM International Symposium on Modeling, Analysis and Simulation of Computer Telecommunications Systems , pages 238 -- 241 , 2003 . I. Charitakis, K. Anagnostakis, and E. Markatos. An Active Traffic Splitter Architecture for Intrusion Detection. In MASCOTS 2003. 11th IEEE\/ACM International Symposium on Modeling, Analysis and Simulation of Computer Telecommunications Systems, pages 238--241, 2003."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1201\/b13595-4"},{"key":"e_1_3_2_1_5_1","volume-title":"December","author":"Worm Conficker","year":"2008","unstructured":"Conficker Worm . http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2008-123015-3826-99 , December 2008 . Conficker Worm. http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2008-123015-3826-99, December 2008."},{"key":"e_1_3_2_1_6_1","volume-title":"July","author":"Decker A.","year":"2009","unstructured":"A. Decker , D. Sancho , L. Kharouni , M. Goncharov , and R. McArdle . Pushdo \/ Cutwail Botnet . http:\/\/us.trendmicro.com\/imperia\/md\/content\/us\/pdf\/threats\/securitylibrary\/study_of_pushdo.pdf , July 2009 . A. Decker, D. Sancho, L. Kharouni, M. Goncharov, and R. McArdle. Pushdo \/ Cutwail Botnet. http:\/\/us.trendmicro.com\/imperia\/md\/content\/us\/pdf\/threats\/securitylibrary\/study_of_pushdo.pdf, July 2009."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of SANE, 2004","author":"Deri L.","year":"2004","unstructured":"L. Deri . Improving Passive Packet Capture: Beyond Device Polling . Proceedings of SANE, 2004 , 2004 . L. Deri. Improving Passive Packet Capture: Beyond Device Polling. Proceedings of SANE, 2004, 2004."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030086"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2008.76"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/820749.821443"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830527"},{"key":"e_1_3_2_1_12_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"252","DOI":"10.1007\/3-540-36084-0_14","volume-title":"Performance Adaptation in Real-Time Intrusion Detection Systems","author":"Lee W.","year":"2002","unstructured":"W. Lee , J. Cabrera , A. Thomas , N. Balwalli , S. Saluja , and Y. Zhang . Performance Adaptation in Real-Time Intrusion Detection Systems . Lecture Notes in Computer Science , pages 252 -- 273 , 2002 . W. Lee, J. Cabrera, A. Thomas, N. Balwalli, S. Saluja, and Y. Zhang. Performance Adaptation in Real-Time Intrusion Detection Systems. Lecture Notes in Computer Science, pages 252--273, 2002."},{"key":"e_1_3_2_1_13_1","unstructured":"libpcap: Packet Capture Library. http:\/\/www.tcpdump.org April 2008.  libpcap: Packet Capture Library. http:\/\/www.tcpdump.org April 2008."},{"volume-title":"May","year":"2008","key":"e_1_3_2_1_14_1","unstructured":"Madwifi. http:\/\/www.madwifi.org , May 2008 . Madwifi. http:\/\/www.madwifi.org, May 2008."},{"key":"e_1_3_2_1_15_1","volume-title":"Proc. Winter'93 USENIX Conference","author":"McCanne S.","year":"1993","unstructured":"S. McCanne and V. Jacobson . The BSD packet Filter: A new architecture for user-level packet capture . Proc. Winter'93 USENIX Conference , 1993 . S. McCanne and V. Jacobson. The BSD packet Filter: A new architecture for user-level packet capture. Proc. Winter'93 USENIX Conference, 1993."},{"key":"e_1_3_2_1_16_1","volume-title":"Proc. ICETA2004","author":"Musashi Y.","year":"2004","unstructured":"Y. Musashi , R. Matsuba , and K. Sugitani . Indirect Detection of Mass Mailing Worm-Infected PC terminals for Learners . Proc. ICETA2004 , 2004 . Y. Musashi, R. Matsuba, and K. Sugitani. Indirect Detection of Mass Mailing Worm-Infected PC terminals for Learners. Proc. ICETA2004, 2004."},{"key":"e_1_3_2_1_17_1","volume-title":"May","author":"Project Netfilter","year":"2008","unstructured":"Netfilter Project . http:\/\/www.netfilter.org , May 2008 . Netfilter Project. http:\/\/www.netfilter.org, May 2008."},{"key":"e_1_3_2_1_18_1","volume-title":"April","author":"Wireless Open","year":"2008","unstructured":"Open Wireless . http:\/\/www.openwireless.ch , April 2008 . Open Wireless. http:\/\/www.openwireless.ch, April 2008."},{"key":"e_1_3_2_1_19_1","volume-title":"April","author":"WRT.","year":"2008","unstructured":"Open WRT. http:\/\/www.openwrt.org , April 2008 . OpenWRT. http:\/\/www.openwrt.org, April 2008."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_21_1","volume-title":"Bro Intrusion Detection System Hands-On Workshop: Bro Overwiew. Technical report, Lawrence Berkeley National Laboratory","author":"Paxson V.","year":"2007","unstructured":"V. Paxson . Bro Intrusion Detection System Hands-On Workshop: Bro Overwiew. Technical report, Lawrence Berkeley National Laboratory , 2007 . V. Paxson. Bro Intrusion Detection System Hands-On Workshop: Bro Overwiew. Technical report, Lawrence Berkeley National Laboratory, 2007."},{"key":"e_1_3_2_1_22_1","volume-title":"May","author":"Procps","year":"2008","unstructured":"Procps - The \/proc File system utilities. http:\/\/procps.sourceforge.net , May 2008 . Procps - The \/proc File system utilities. http:\/\/procps.sourceforge.net, May 2008."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1159913.1159947"},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of the 1999 USENIX LISA Systems Administration Conference","author":"Roesch M.","year":"1999","unstructured":"M. Roesch . Snort-Lightweight Intrusion Detection for Networks . Proceedings of the 1999 USENIX LISA Systems Administration Conference , 1999 . M. Roesch. Snort-Lightweight Intrusion Detection for Networks. Proceedings of the 1999 USENIX LISA Systems Administration Conference, 1999."},{"key":"e_1_3_2_1_25_1","volume-title":"RFC 3350: RTP: A Transport Protocol for Real-Time Applications","author":"Schulzrinne H.","year":"2003","unstructured":"H. Schulzrinne , S. Casner , R. Frederick , and V. Jacobso . RFC 3350: RTP: A Transport Protocol for Real-Time Applications , 2003 . H. Schulzrinne, S. Casner, R. Frederick, and V. Jacobso. RFC 3350: RTP: A Transport Protocol for Real-Time Applications, 2003."},{"key":"e_1_3_2_1_26_1","volume-title":"April","author":"Wireless Seattle","year":"2008","unstructured":"Seattle Wireless . http:\/\/www.seattlewireless.net , April 2008 . Seattle Wireless. http:\/\/www.seattlewireless.net, April 2008."},{"key":"e_1_3_2_1_27_1","unstructured":"S. Shalunov. Thrulay - Network capacity tester. http:\/\/shlang.com\/thrulay\/ August 2008.  S. Shalunov. Thrulay - Network capacity tester. http:\/\/shlang.com\/thrulay\/ August 2008."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_15"},{"key":"e_1_3_2_1_29_1","volume-title":"February","author":"Attack Smurf","year":"2007","unstructured":"Smurf Attack . http:\/\/www.cert.org\/advisories\/CA-1998-01.html , February 2007 . Smurf Attack. http:\/\/www.cert.org\/advisories\/CA-1998-01.html, February 2007."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWIA.2005.1"},{"key":"e_1_3_2_1_31_1","volume-title":"February","author":"Stewart J.","year":"2007","unstructured":"J. Stewart . Storm Worm DDoS Attack . http:\/\/www.secureworks.com\/research\/threats\/storm-worm , February 2007 . J. Stewart. Storm Worm DDoS Attack. http:\/\/www.secureworks.com\/research\/threats\/storm-worm, February 2007."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/1791949.1791980"},{"key":"e_1_3_2_1_33_1","unstructured":"Tcpreplay: Pcap editing and replay tools for *NIX. http:\/\/tcpreplay.synfin.net April 2008.  Tcpreplay: Pcap editing and replay tools for *NIX. http:\/\/tcpreplay.synfin.net April 2008."},{"volume-title":"August","year":"2008","key":"e_1_3_2_1_34_1","unstructured":"Transmission. http:\/\/www.transmissionbt.com , August 2008 . Transmission. http:\/\/www.transmissionbt.com, August 2008."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/11790754_11"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029620"},{"key":"e_1_3_2_1_37_1","unstructured":"P. Wood. libpcap-mmap: Memory Mapped Packet Capture Library. http:\/\/public.lanl.gov\/cpw\/ April 2008.  P. Wood. libpcap-mmap: Memory Mapped Packet Capture Library. http:\/\/public.lanl.gov\/cpw\/ April 2008."},{"key":"e_1_3_2_1_38_1","volume-title":"Spamming Botnets: Signatures and Characteristics","author":"Xie Y.","year":"2008","unstructured":"Y. Xie , F. Yu , K. Achan , R. Panigrahy , G. Hulten , and I. Osipkov . Spamming Botnets: Signatures and Characteristics . 2008 . Y. Xie, F. Yu, K. Achan, R. Panigrahy, G. Hulten, and I. Osipkov. Spamming Botnets: Signatures and Characteristics. 2008."},{"key":"e_1_3_2_1_39_1","first-page":"1","volume-title":"Proceedings of 17th International Conference on Computer Communications and Networks. ICCCN 2008","author":"Yoshioka A.","year":"2008","unstructured":"A. Yoshioka , S. Shaikot , and M. Kim . Rule Hashing for Efficient Packet Classiffication in Network Intrusion Detection . In Proceedings of 17th International Conference on Computer Communications and Networks. ICCCN 2008 , pages 1 -- 6 , August 2008 . A. Yoshioka, S. Shaikot, and M. Kim. Rule Hashing for Efficient Packet Classiffication in Network Intrusion Detection. In Proceedings of 17th International Conference on Computer Communications and Networks. ICCCN 2008, pages 1--6, August 2008."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/345910.345958"}],"event":{"name":"MobiCom'09: Annual International Conference on Mobile Computing and Networking","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing","ACM Association for Computing Machinery"],"location":"Beijing China","acronym":"MobiCom'09"},"container-title":["Proceedings of the 15th annual international conference on Mobile computing and networking"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1614320.1614355","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1614320.1614355","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:18:05Z","timestamp":1750249085000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1614320.1614355"}},"subtitle":["a lightweight intrusion detection system for wireless mesh networks"],"short-title":[],"issued":{"date-parts":[[2009,9,20]]},"references-count":40,"alternative-id":["10.1145\/1614320.1614355","10.1145\/1614320"],"URL":"https:\/\/doi.org\/10.1145\/1614320.1614355","relation":{},"subject":[],"published":{"date-parts":[[2009,9,20]]},"assertion":[{"value":"2009-09-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}