{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T02:36:18Z","timestamp":1768703778369,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,8,7]],"date-time":"2017-08-07T00:00:00Z","timestamp":1502064000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF 1138996, CNS-1513679, CNS-1218066"],"award-info":[{"award-number":["CCF 1138996, CNS-1513679, CNS-1218066"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,8,7]]},"DOI":"10.1145\/3098822.3098830","type":"proceedings-article","created":{"date-parts":[[2017,8,4]],"date-time":"2017-08-04T13:48:54Z","timestamp":1501854534000},"page":"99-112","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":45,"title":["Quantitative Network Monitoring with NetQRE"],"prefix":"10.1145","author":[{"given":"Yifei","family":"Yuan","sequence":"first","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dong","family":"Lin","sequence":"additional","affiliation":[{"name":"LinkedIn Inc."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ankit","family":"Mishra","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sajal","family":"Marwaha","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rajeev","family":"Alur","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Boon Thau","family":"Loo","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,8,7]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Application Layer Packet Classifier for Linux. http:\/\/www.mcafee.com\/us\/products\/network-security-platform.aspx.  Application Layer Packet Classifier for Linux. http:\/\/www.mcafee.com\/us\/products\/network-security-platform.aspx."},{"key":"e_1_3_2_2_2_1","unstructured":"CAIDA Traffic Trace. https:\/\/data.caida.org\/datasets\/security\/ddos-20070804\/.  CAIDA Traffic Trace. https:\/\/data.caida.org\/datasets\/security\/ddos-20070804\/."},{"key":"e_1_3_2_2_3_1","unstructured":"McAfee Network Security Platform. http:\/\/l7-filter.sourceforge.net\/.  McAfee Network Security Platform. http:\/\/l7-filter.sourceforge.net\/."},{"key":"e_1_3_2_2_4_1","unstructured":"OpenSketch reference code. https:\/\/github.com\/USC-NSL\/opensketch.  OpenSketch reference code. https:\/\/github.com\/USC-NSL\/opensketch."},{"key":"e_1_3_2_2_5_1","unstructured":"SIPp. http:\/\/sipp.sourceforge.net\/.  SIPp. http:\/\/sipp.sourceforge.net\/."},{"key":"e_1_3_2_2_6_1","unstructured":"SSL renegotiation DoS. https:\/\/www.ietf.org\/mail-archive\/web\/tls\/current\/msg07553.html.  SSL renegotiation DoS. https:\/\/www.ietf.org\/mail-archive\/web\/tls\/current\/msg07553.html."},{"key":"e_1_3_2_2_7_1","volume-title":"https:\/\/data.caida.org\/datasets\/passive-2015\/","author":"Internet Traces Anonymized","year":"2015","unstructured":"Anonymized 2015 Internet Traces . https:\/\/data.caida.org\/datasets\/passive-2015\/ , 2015 . Anonymized 2015 Internet Traces. https:\/\/data.caida.org\/datasets\/passive-2015\/, 2015."},{"key":"e_1_3_2_2_8_1","first-page":"19","volume-title":"NSDI","volume":"10","author":"Al-Fares Mohammad","year":"2010","unstructured":"Mohammad Al-Fares , Sivasankar Radhakrishnan , Barath Raghavan , Nelson Huang , and Amin Vahdat . Hedera : Dynamic Flow Scheduling for Data Center Networks . In NSDI , volume 10 , pages 19 -- 19 , 2010 . Mohammad Al-Fares, Sivasankar Radhakrishnan, Barath Raghavan, Nelson Huang, and Amin Vahdat. Hedera: Dynamic Flow Scheduling for Data Center Networks. In NSDI, volume 10, pages 19--19, 2010."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/3089528.3089530"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535838.2535862"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2934872.2934892"},{"key":"e_1_3_2_2_12_1","first-page":"19","volume-title":"Proceedings of the 21st USENIX Conference on Security Symposium, Security'12","author":"Borders Kevin","year":"2012","unstructured":"Kevin Borders , Jonathan Springer , and Matthew Burnside . Chimera : A declarative language for streaming network traffic analysis . In Proceedings of the 21st USENIX Conference on Security Symposium, Security'12 , pages 19 -- 19 , Berkeley, CA, USA , 2012 . USENIX Association. Kevin Borders, Jonathan Springer, and Matthew Burnside. Chimera: A declarative language for streaming network traffic analysis. In Proceedings of the 21st USENIX Conference on Security Symposium, Security'12, pages 19--19, Berkeley, CA, USA, 2012. USENIX Association."},{"key":"e_1_3_2_2_13_1","volume-title":"Anomaly Detection: A Survey. ACM computing surveys (CSUR), 41(3):15","author":"Chandola Varun","year":"2009","unstructured":"Varun Chandola , Arindam Banerjee , and Vipin Kumar . Anomaly Detection: A Survey. ACM computing surveys (CSUR), 41(3):15 , 2009 . Varun Chandola, Arindam Banerjee, and Vipin Kumar. Anomaly Detection: A Survey. ACM computing surveys (CSUR), 41(3):15, 2009."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/872757.872857"},{"key":"e_1_3_2_2_15_1","volume-title":"Cisco systems NetFlow services export version 9","author":"Claise Benoit","year":"2004","unstructured":"Benoit Claise . Cisco systems NetFlow services export version 9 . 2004 . Benoit Claise. Cisco systems NetFlow services export version 9. 2004."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/872757.872838"},{"key":"e_1_3_2_2_17_1","volume-title":"Proceedings of SANE","volume":"2006","author":"Deri Luca","year":"2006","unstructured":"Luca Deri . Open source VoIP traffic monitoring . In Proceedings of SANE , volume 2006 , 2006 . Luca Deri. Open source VoIP traffic monitoring. In Proceedings of SANE, volume 2006, 2006."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/863955.863992"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/633025.633056"},{"key":"e_1_3_2_2_20_1","first-page":"817","volume-title":"Michael Bailey. Bohatei: Flexible and Elastic DDoS Defense. In 24th USENIX Security Symposium (USENIX Security 15)","author":"Fayaz Seyed K.","year":"2015","unstructured":"Seyed K. Fayaz , Yoshiaki Tobioka , Vyas Sekar , and Michael Bailey. Bohatei: Flexible and Elastic DDoS Defense. In 24th USENIX Security Symposium (USENIX Security 15) , pages 817 -- 832 , Washington, D.C. , August 2015 . USENIX Association. Seyed K. Fayaz, Yoshiaki Tobioka, Vyas Sekar, and Michael Bailey. Bohatei: Flexible and Elastic DDoS Defense. In 24th USENIX Security Symposium (USENIX Security 15), pages 817--832, Washington, D.C., August 2015. USENIX Association."},{"key":"e_1_3_2_2_21_1","first-page":"279","volume-title":"ACM SIGPLAN Notices","author":"Foster Nate","year":"2011","unstructured":"Nate Foster , Rob Harrison , Michael J Freedman , Christopher Monsanto , Jennifer Rexford , Alec Story , and David Walker . Frenetic: A Network Programming Language . In ACM SIGPLAN Notices , volume 46 , pages 279 -- 291 . ACM , 2011 . Nate Foster, Rob Harrison, Michael J Freedman, Christopher Monsanto, Jennifer Rexford, Alec Story, and David Walker. Frenetic: A Network Programming Language. In ACM SIGPLAN Notices, volume 46, pages 279--291. ACM, 2011."},{"key":"e_1_3_2_2_22_1","volume-title":"Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges. computers & security, 28(1):18--28","author":"Garcia-Teodoro Pedro","year":"2009","unstructured":"Pedro Garcia-Teodoro , J Diaz-Verdejo , Gabriel Maci\u00e1-Fern\u00e1ndez , and Enrique V\u00e1zquez . Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges. computers & security, 28(1):18--28 , 2009 . Pedro Garcia-Teodoro, J Diaz-Verdejo, Gabriel Maci\u00e1-Fern\u00e1ndez, and Enrique V\u00e1zquez. Anomaly-based Network Intrusion Detection: Techniques, Systems and Challenges. computers & security, 28(1):18--28, 2009."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3005745.3005748"},{"key":"e_1_3_2_2_24_1","unstructured":"DPDK Intel. Data Plane Development Kit. http:\/\/dpdk.org.  DPDK Intel. Data Plane Development Kit. http:\/\/dpdk.org."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1868447.1868466"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1592761.1592785"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3062341.3062369"},{"key":"e_1_3_2_2_28_1","volume-title":"http:\/\/www.tcpdump.org","author":"McCanne Steve","year":"1989","unstructured":"Steve McCanne , Craig Leres , and Van Jacobson . Libpcap. http:\/\/www.tcpdump.org , 1989 . Steve McCanne, Craig Leres, and Van Jacobson. Libpcap. http:\/\/www.tcpdump.org, 1989."},{"key":"e_1_3_2_2_29_1","volume-title":"POX: A Python-based Openflow Controller","author":"Mccauley J","year":"2014","unstructured":"J Mccauley . POX: A Python-based Openflow Controller , 2014 . J Mccauley. POX: A Python-based Openflow Controller, 2014."},{"key":"e_1_3_2_2_30_1","first-page":"1","volume-title":"NSDI","author":"Monsanto Christopher","year":"2013","unstructured":"Christopher Monsanto , Joshua Reich , Nate Foster , Jennifer Rexford , David Walker , Composing Software Defined Networks . In NSDI , pages 1 -- 13 , 2013 . Christopher Monsanto, Joshua Reich, Nate Foster, Jennifer Rexford, David Walker, et al. Composing Software Defined Networks. In NSDI, pages 1--13, 2013."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2626291"},{"key":"e_1_3_2_2_32_1","volume-title":"NSDI","author":"Nelson Tim","year":"2014","unstructured":"Tim Nelson , Andrew D Ferguson , Michael JG Scheer , and Shriram Krishnamurthi . Tierless Programming and Reasoning for Software-Defined Networks . NSDI , Apr , 2014 . Tim Nelson, Andrew D Ferguson, Michael JG Scheer, and Shriram Krishnamurthi. Tierless Programming and Reasoning for Software-Defined Networks. NSDI, Apr, 2014."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_2_34_1","first-page":"229","volume-title":"Snort: Lightweight Intrusion Detection for Networks. In LISA","volume":"99","author":"Martin","year":"1999","unstructured":"Martin Roesch et al . Snort: Lightweight Intrusion Detection for Networks. In LISA , volume 99 , pages 229 -- 238 , 1999 . Martin Roesch et al. Snort: Lightweight Intrusion Detection for Networks. In LISA, volume 99, pages 229--238, 1999."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879186"},{"key":"e_1_3_2_2_36_1","unstructured":"David Senecal. Slow DoS on the rise. https:\/\/blogs.akamai.com\/2013\/09\/slow-dos-on-the-rise.html.  David Senecal. Slow DoS on the rise. https:\/\/blogs.akamai.com\/2013\/09\/slow-dos-on-the-rise.html."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663735"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486030"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2004.1281630"},{"key":"e_1_3_2_2_40_1","first-page":"29","volume-title":"NSDI","volume":"13","author":"Yu Minlan","year":"2013","unstructured":"Minlan Yu , Lavanya Jose , and Rui Miao . Software Defined Traffic Measurement with OpenSketch . In NSDI , volume 13 , pages 29 -- 42 , 2013 . Minlan Yu, Lavanya Jose, and Rui Miao. Software Defined Traffic Measurement with OpenSketch. In NSDI, volume 13, pages 29--42, 2013."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"crossref","unstructured":"Lihua Yuan Chen-Nee Chuah and Prasant Mohapatra. ProgME: Towards Programmable Network Measurement. IEEE\/ACM Transactions on Networking (TON) 19(1):115--128 2011.  Lihua Yuan Chen-Nee Chuah and Prasant Mohapatra. ProgME: Towards Programmable Network Measurement. IEEE\/ACM Transactions on Networking (TON) 19(1):115--128 2011.","DOI":"10.1109\/TNET.2010.2066987"}],"event":{"name":"SIGCOMM '17: ACM SIGCOMM 2017 Conference","location":"Los Angeles CA USA","acronym":"SIGCOMM '17","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication"]},"container-title":["Proceedings of the Conference of the ACM Special Interest Group on Data Communication"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3098822.3098830","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3098822.3098830","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3098822.3098830","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T19:07:21Z","timestamp":1750273641000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3098822.3098830"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,7]]},"references-count":41,"alternative-id":["10.1145\/3098822.3098830","10.1145\/3098822"],"URL":"https:\/\/doi.org\/10.1145\/3098822.3098830","relation":{},"subject":[],"published":{"date-parts":[[2017,8,7]]},"assertion":[{"value":"2017-08-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}