{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:46:59Z","timestamp":1750308419307,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,3,19]],"date-time":"2019-03-19T00:00:00Z","timestamp":1552953600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1700527"],"award-info":[{"award-number":["1700527"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,3,19]]},"DOI":"10.1145\/3309194.3309197","type":"proceedings-article","created":{"date-parts":[[2019,3,25]],"date-time":"2019-03-25T12:18:36Z","timestamp":1553516316000},"page":"17-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["PIQ"],"prefix":"10.1145","author":[{"given":"Oliver","family":"Michel","sequence":"first","affiliation":[{"name":"University of Colorado Boulder, Boulder, CO, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John","family":"Sonchack","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Keller","sequence":"additional","affiliation":[{"name":"University of Colorado Boulder, Boulder, CO, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonathan M.","family":"Smith","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,3,19]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Barefoot Deep Insight. https:\/\/www.barefootnetworks.com\/products\/brief-deep-insight\/.  Barefoot Deep Insight. https:\/\/www.barefootnetworks.com\/products\/brief-deep-insight\/."},{"key":"e_1_3_2_1_2_1","unstructured":"Data Plane Development Kit. https:\/\/dpdk.org.  Data Plane Development Kit. https:\/\/dpdk.org."},{"key":"e_1_3_2_1_3_1","unstructured":"DB Toaster. https:\/\/dbtoaster.github.io.  DB Toaster. https:\/\/dbtoaster.github.io."},{"key":"e_1_3_2_1_4_1","unstructured":"Talk: Rearchitecting a SQL Database for Time-Series Data. https:\/\/www.youtube.com\/watch?v=eQKbbCg0NqE.  Talk: Rearchitecting a SQL Database for Time-Series Data. https:\/\/www.youtube.com\/watch?v=eQKbbCg0NqE."},{"key":"e_1_3_2_1_5_1","unstructured":"Trace statistics for caida passive oc48 and oc192 traces -- 2015-02--19. https:\/\/www.caida.org\/data\/passive\/trace_stats\/.  Trace statistics for caida passive oc48 and oc192 traces -- 2015-02--19. https:\/\/www.caida.org\/data\/passive\/trace_stats\/."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2656877.2656890"},{"key":"e_1_3_2_1_7_1","first-page":"19","volume-title":"7th USENIX Symposium on Networked Systems Design and Implementation (NSDI 10)","volume":"7","author":"Al-Fares M.","year":"2010","unstructured":"Al-Fares , M. , Radhakrishnan , S. , Raghavan , B. , Huang , N. , and Vahdat , A . Hedera: Dynamic flow scheduling for data center networks . In 7th USENIX Symposium on Networked Systems Design and Implementation (NSDI 10) ( 2010 ), vol. 7 , pp. 19 -- 19 . Al-Fares, M., Radhakrishnan, S., Raghavan, B., Huang, N., and Vahdat, A. Hedera: Dynamic flow scheduling for data center networks. In 7th USENIX Symposium on Networked Systems Design and Implementation (NSDI 10) (2010), vol. 7, pp. 19--19."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2079296.2079304"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486011"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629578"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3230543.3230555"},{"key":"e_1_3_2_1_12_1","first-page":"71","volume-title":"11th USENIX Symposium on Networked Systems Design and Implementation (NSDI 14)","volume":"14","author":"Handigol N.","year":"2014","unstructured":"Handigol , N. , Heller , B. , Jeyakumar , V. , Mazi\u00e8res , D. , and McKeown , N. I know what your packet did last hop: Using packet histories to troubleshoot networks . In 11th USENIX Symposium on Networked Systems Design and Implementation (NSDI 14) ( 2014 ), vol. 14 , pp. 71 -- 85 . Handigol, N., Heller, B., Jeyakumar, V., Mazi\u00e8res, D., and McKeown, N. I know what your packet did last hop: Using packet histories to troubleshoot networks. In 11th USENIX Symposium on Networked Systems Design and Implementation (NSDI 14) (2014), vol. 14, pp. 71--85."},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 13th USENIX Conference on Networked Systems Design and Implementation","author":"Li Y.","year":"2016","unstructured":"Li , Y. , Miao , R. , Kim , C. , and Yu , M . FlowRadar: A Better NetFlow for Data Centers . In Proceedings of the 13th USENIX Conference on Networked Systems Design and Implementation ( Santa Clara, CA , 2016 ), USENIX Association, pp. 311--324. Li, Y., Miao, R., Kim, C., and Yu, M. FlowRadar: A Better NetFlow for Data Centers. In Proceedings of the 13th USENIX Conference on Networked Systems Design and Implementation (Santa Clara, CA, 2016), USENIX Association, pp. 311--324."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277180.3277190"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098822.3098829"},{"key":"e_1_3_2_1_16_1","first-page":"203","volume-title":"OSDI","author":"Panda A.","year":"2016","unstructured":"Panda , A. , Han , S. , Jang , K. , Walls , M. , Ratnasamy , S. , and Shenker , S . Netbricks: Taking the v out of nfv . In OSDI ( 2016 ), pp. 203 -- 216 . Panda, A., Han, S., Jang, K., Walls, M., Ratnasamy, S., and Shenker, S. Netbricks: Taking the v out of nfv. In OSDI (2016), pp. 203--216."},{"key":"e_1_3_2_1_17_1","unstructured":"Postgres. Postgresql database system. https:\/\/www.postgresql.org.  Postgres. Postgresql database system. https:\/\/www.postgresql.org."},{"key":"e_1_3_2_1_18_1","unstructured":"Postgres. Postgresql documentation: Copy. https:\/\/www.postgresql.org\/docs\/current\/sql-copy.html.  Postgres. Postgresql documentation: Copy. https:\/\/www.postgresql.org\/docs\/current\/sql-copy.html."},{"key":"e_1_3_2_1_19_1","first-page":"101","volume-title":"2012 USENIX Annual Technical Conference (USENIX ATC 12)","author":"Rizzo L.","year":"2012","unstructured":"Rizzo , L. netmap : A Novel Framework for Fast Packet I\/O . In 2012 USENIX Annual Technical Conference (USENIX ATC 12) (Boston, MA, 2012 ), USENIX Association , pp. 101 -- 112 . Rizzo, L. netmap: A Novel Framework for Fast Packet I\/O. In 2012 USENIX Annual Technical Conference (USENIX ATC 12) (Boston, MA, 2012), USENIX Association, pp. 101--112."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2934872.2934900"},{"key":"e_1_3_2_1_21_1","volume-title":"A survey of network traffic monitoring and analysis tools. Cse 576m computer system analysis project","author":"So-In C.","year":"2009","unstructured":"So-In , C. A survey of network traffic monitoring and analysis tools. Cse 576m computer system analysis project , Washington University in St. Louis ( 2009 ). So-In, C. A survey of network traffic monitoring and analysis tools. Cse 576m computer system analysis project, Washington University in St. Louis (2009)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190508.3190558"},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 2018 USENIX Annual Technical Conference (ATC)","author":"Sonchack J.","year":"2018","unstructured":"Sonchack , J. , Michel , O. , Aviv , A. J. , Keller , E. , and Smith , J. M . Scaling hardware accelerated monitoring to concurrent and dynamic queries with *flow . In Proceedings of the 2018 USENIX Annual Technical Conference (ATC) ( Boston, MA , 2018 ), USENIX Association. Sonchack, J., Michel, O., Aviv, A. J., Keller, E., and Smith, J. M. Scaling hardware accelerated monitoring to concurrent and dynamic queries with *flow. In Proceedings of the 2018 USENIX Annual Technical Conference (ATC) (Boston, MA, 2018), USENIX Association."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2010.032210.00054"},{"key":"e_1_3_2_1_25_1","unstructured":"Timescale. Timescale db. https:\/\/www.timescale.com\/.  Timescale. Timescale db. https:\/\/www.timescale.com\/."}],"event":{"name":"CODASPY '19: Ninth ACM Conference on Data and Application Security and Privacy","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Richardson Texas USA","acronym":"CODASPY '19"},"container-title":["Proceedings of the ACM International Workshop on Security in Software Defined Networks &amp; Network Function Virtualization"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3309194.3309197","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3309194.3309197","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3309194.3309197","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:22Z","timestamp":1750268962000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3309194.3309197"}},"subtitle":["Persistent Interactive Queries for Network Security Analytics"],"short-title":[],"issued":{"date-parts":[[2019,3,19]]},"references-count":25,"alternative-id":["10.1145\/3309194.3309197","10.1145\/3309194"],"URL":"https:\/\/doi.org\/10.1145\/3309194.3309197","relation":{},"subject":[],"published":{"date-parts":[[2019,3,19]]},"assertion":[{"value":"2019-03-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}