{"id":"https://openalex.org/W4390013300","doi":"https://doi.org/10.1007/s10207-023-00794-9","title":"A perspective\u2013retrospective analysis of diversity in signature-based open-source network intrusion detection systems","display_name":"A perspective\u2013retrospective analysis of diversity in signature-based open-source network intrusion detection systems","publication_year":2023,"publication_date":"2023-12-20","ids":{"openalex":"https://openalex.org/W4390013300","doi":"https://doi.org/10.1007/s10207-023-00794-9"},"language":"en","primary_location":{"id":"doi:10.1007/s10207-023-00794-9","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10207-023-00794-9","pdf_url":"https://link.springer.com/content/pdf/10.1007/s10207-023-00794-9.pdf","source":{"id":"https://openalex.org/S164062316","display_name":"International Journal of Information Security","issn_l":"1615-5262","issn":["1615-5262","1615-5270"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Journal of Information Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/s10207-023-00794-9.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087175163","display_name":"Hafizul Asad","orcid":"https://orcid.org/0000-0002-8506-5721"},"institutions":[{"id":"https://openalex.org/I180825142","display_name":"City, University of London","ror":"https://ror.org/04489at23","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I180825142"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"H. Asad","raw_affiliation_strings":["Department of Computer Science, School of Science and Technology, City, University of London, London, UK"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, School of Science and Technology, City, University of London, London, UK","institution_ids":["https://openalex.org/I180825142"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101610650","display_name":"Shashwat Adhikari","orcid":"https://orcid.org/0000-0003-2836-9531"},"institutions":[{"id":"https://openalex.org/I897542642","display_name":"University of Plymouth","ror":"https://ror.org/008n7pv89","country_code":"GB","type":"education","lineage":["https://openalex.org/I897542642"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"S. Adhikari","raw_affiliation_strings":["School of Engineering, Computing and Mathematics, University of Plymouth, Plymouth, UK"],"affiliations":[{"raw_affiliation_string":"School of Engineering, Computing and Mathematics, University of Plymouth, Plymouth, UK","institution_ids":["https://openalex.org/I897542642"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5037476990","display_name":"Ilir Gashi","orcid":"https://orcid.org/0000-0002-8017-3184"},"institutions":[{"id":"https://openalex.org/I180825142","display_name":"City, University of London","ror":"https://ror.org/04489at23","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I180825142"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Ilir Gashi","raw_affiliation_strings":["Department of Computer Science, School of Science and Technology, City, University of London, London, UK"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, School of Science and Technology, City, University of London, London, UK","institution_ids":["https://openalex.org/I180825142"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5087175163"],"corresponding_institution_ids":["https://openalex.org/I180825142"],"apc_list":{"value":2590,"currency":"EUR","value_usd":3190},"apc_paid":{"value":2590,"currency":"EUR","value_usd":3190},"fwci":4.3724,"has_fulltext":true,"cited_by_count":22,"citation_normalized_percentile":{"value":0.94950826,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":100},"biblio":{"volume":"23","issue":"2","first_page":"1331","last_page":"1346"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.815955400466919},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7854313850402832},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.6933413743972778},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.5950890779495239},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.54411780834198},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.4931330382823944},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4507668614387512},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.44556865096092224},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.43221551179885864},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.41200190782546997},{"id":"https://openalex.org/keywords/diversity","display_name":"Diversity (politics)","score":0.41006237268447876},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.1853514313697815},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.10772192478179932}],"concepts":[{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.815955400466919},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7854313850402832},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.6933413743972778},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.5950890779495239},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.54411780834198},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.4931330382823944},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4507668614387512},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.44556865096092224},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.43221551179885864},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.41200190782546997},{"id":"https://openalex.org/C2781316041","wikidata":"https://www.wikidata.org/wiki/Q1230584","display_name":"Diversity (politics)","level":2,"score":0.41006237268447876},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.1853514313697815},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.10772192478179932},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C19165224","wikidata":"https://www.wikidata.org/wiki/Q23404","display_name":"Anthropology","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/s10207-023-00794-9","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10207-023-00794-9","pdf_url":"https://link.springer.com/content/pdf/10.1007/s10207-023-00794-9.pdf","source":{"id":"https://openalex.org/S164062316","display_name":"International Journal of Information Security","issn_l":"1615-5262","issn":["1615-5262","1615-5270"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Journal of Information Security","raw_type":"journal-article"},{"id":"pmh:oai:openaccess.city.ac.uk:31746","is_oa":true,"landing_page_url":"https://openaccess.city.ac.uk/view/creators_id/hafizul=2Easad.html>,","pdf_url":"https://openaccess.city.ac.uk/id/eprint/31746/8/s10207-023-00794-9.pdf","source":{"id":"https://openalex.org/S4306401940","display_name":"City Research Online (City University London)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I180825142","host_organization_name":"City, University of London","host_organization_lineage":["https://openalex.org/I180825142"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"}],"best_oa_location":{"id":"doi:10.1007/s10207-023-00794-9","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10207-023-00794-9","pdf_url":"https://link.springer.com/content/pdf/10.1007/s10207-023-00794-9.pdf","source":{"id":"https://openalex.org/S164062316","display_name":"International Journal of Information Security","issn_l":"1615-5262","issn":["1615-5262","1615-5270"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Journal of Information Security","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1147893575","display_name":null,"funder_award_id":"EU H2020","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"},{"id":"https://openalex.org/G5045220161","display_name":null,"funder_award_id":"H2020","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"},{"id":"https://openalex.org/G5413299184","display_name":"Diversity and Defence in Depth for Security - A Probabilistic Approach (D3S)","funder_award_id":"EP/M019462/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"},{"id":"https://openalex.org/G6928308837","display_name":null,"funder_award_id":"700692","funder_id":"https://openalex.org/F4320332999","funder_display_name":"Horizon 2020 Framework Programme"},{"id":"https://openalex.org/G7331901853","display_name":null,"funder_award_id":"EU H2020","funder_id":"https://openalex.org/F4320332999","funder_display_name":"Horizon 2020 Framework Programme"},{"id":"https://openalex.org/G971583128","display_name":null,"funder_award_id":"EP/M019462/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320332999","display_name":"Horizon 2020 Framework Programme","ror":"https://ror.org/00k4n6c32"},{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4390013300.pdf"},"referenced_works_count":22,"referenced_works":["https://openalex.org/W1549725782","https://openalex.org/W1756225116","https://openalex.org/W2033779093","https://openalex.org/W2045367121","https://openalex.org/W2068748869","https://openalex.org/W2111142701","https://openalex.org/W2160841769","https://openalex.org/W2589108464","https://openalex.org/W2762301816","https://openalex.org/W2765181145","https://openalex.org/W2789828921","https://openalex.org/W2791788846","https://openalex.org/W2801256139","https://openalex.org/W2886393674","https://openalex.org/W2901373939","https://openalex.org/W2951105308","https://openalex.org/W2973862992","https://openalex.org/W2983270658","https://openalex.org/W3093410479","https://openalex.org/W3198221136","https://openalex.org/W3210361010","https://openalex.org/W4385730947"],"related_works":["https://openalex.org/W2061466315","https://openalex.org/W2376886931","https://openalex.org/W2010561419","https://openalex.org/W2374845301","https://openalex.org/W2351448539","https://openalex.org/W1977863481","https://openalex.org/W2384741105","https://openalex.org/W3157271777","https://openalex.org/W2377372927","https://openalex.org/W1495178644"],"abstract_inverted_index":{"Abstract":[0],"The":[1,69],"signature-based":[2,171],"network":[3],"intrusion":[4],"detection":[5],"systems":[6],"(IDSs)":[7],"entail":[8],"relying":[9],"on":[10],"a":[11,38,51,66,105,122,201],"pre-established":[12],"signatures":[13],"and":[14,57,110,121,134,150,173,197],"IP":[15],"addresses":[16],"that":[17,62,160],"are":[18],"frequently":[19],"updated":[20,97],"to":[21,119,128,138,144],"keep":[22],"up":[23],"with":[24],"the":[25,33,43,55,83,93,100,139,146,153,157,167,177],"rapidly":[26],"evolving":[27],"threat":[28],"landscape.":[29],"To":[30,102],"effectively":[31],"evaluate":[32],"efficacy":[34],"of":[35,42,54,107,148,170],"these":[36,73,163],"updates,":[37],"comprehensive,":[39],"long-term":[40],"assessment":[41],"IDSs\u2019":[44],"performance":[45,185],"is":[46],"required.":[47],"This":[48],"article":[49],"presents":[50],"perspective\u2013retrospective":[52],"analysis":[53],"Snort":[56,108,149],"Suricata":[58,111,151],"IDSs":[59,74,172,199],"using":[60,80,96,132],"rules":[61,81,98,114,136],"were":[63,115],"collected":[64,116],"over":[65],"4-year":[67],"period.":[68],"study":[70,154],"examines":[71],"how":[72,88,183],"perform":[75],"when":[76,91],"monitoring":[77,92],"malicious":[78],"traffic":[79,95],"from":[82,117,126],"past,":[84],"as":[85,87],"well":[86],"they":[89],"behave":[90],"same":[94],"in":[99,195,200],"future.":[101],"accomplish":[103],"this,":[104],"set":[106],"Subscribed":[109],"Emerging":[112],"Threats":[113],"2017":[118,127],"2020,":[120],"labeled":[123],"PCAP":[124,140],"data":[125],"2018":[129],"was":[130],"analyzed":[131],"past":[133],"future":[135],"relative":[137],"date.":[141],"In":[142],"addition":[143],"exploring":[145],"evolution":[147],"IDSs,":[152],"also":[155],"analyses":[156],"functional":[158],"diversity":[159],"exists":[161],"between":[162],"IDSs.":[164],"By":[165],"examining":[166],"evolutionary":[168],"behavior":[169],"their":[174,184],"diverse":[175],"configurations,":[176],"research":[178],"provides":[179],"valuable":[180],"insights":[181,190],"into":[182],"can":[186,191],"be":[187],"impacted.":[188],"These":[189],"aid":[192],"security":[193],"architects":[194],"combining":[196],"layering":[198],"defence-in-depth":[202],"deployment.":[203]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":14},{"year":2024,"cited_by_count":5}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
