{"id":"https://openalex.org/W2120235625","doi":"https://doi.org/10.1109/hpcsim.2011.5999864","title":"Matryoshka: Tunneled packets breaking the rules","display_name":"Matryoshka: Tunneled packets breaking the rules","publication_year":2011,"publication_date":"2011-07-01","ids":{"openalex":"https://openalex.org/W2120235625","doi":"https://doi.org/10.1109/hpcsim.2011.5999864","mag":"2120235625"},"language":"en","primary_location":{"id":"doi:10.1109/hpcsim.2011.5999864","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hpcsim.2011.5999864","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2011 International Conference on High Performance Computing &amp; Simulation","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5040277386","display_name":"Cesar Ghali","orcid":"https://orcid.org/0000-0002-5312-7385"},"institutions":[{"id":"https://openalex.org/I98635879","display_name":"American University of Beirut","ror":"https://ror.org/04pznsd21","country_code":"LB","type":"education","lineage":["https://openalex.org/I98635879"]}],"countries":["LB"],"is_corresponding":true,"raw_author_name":"Cesar Ghali","raw_affiliation_strings":["Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon"],"affiliations":[{"raw_affiliation_string":"Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","institution_ids":["https://openalex.org/I98635879"]},{"raw_affiliation_string":"Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon","institution_ids":["https://openalex.org/I98635879"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045529534","display_name":"Faisal Hamady","orcid":null},"institutions":[{"id":"https://openalex.org/I98635879","display_name":"American University of Beirut","ror":"https://ror.org/04pznsd21","country_code":"LB","type":"education","lineage":["https://openalex.org/I98635879"]}],"countries":["LB"],"is_corresponding":false,"raw_author_name":"Faisal Hamady","raw_affiliation_strings":["Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon"],"affiliations":[{"raw_affiliation_string":"Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","institution_ids":["https://openalex.org/I98635879"]},{"raw_affiliation_string":"Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon","institution_ids":["https://openalex.org/I98635879"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061146388","display_name":"Imad H. Elhajj","orcid":"https://orcid.org/0000-0002-6461-4699"},"institutions":[{"id":"https://openalex.org/I98635879","display_name":"American University of Beirut","ror":"https://ror.org/04pznsd21","country_code":"LB","type":"education","lineage":["https://openalex.org/I98635879"]}],"countries":["LB"],"is_corresponding":false,"raw_author_name":"Imad H. Elhajj","raw_affiliation_strings":["Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon"],"affiliations":[{"raw_affiliation_string":"Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","institution_ids":["https://openalex.org/I98635879"]},{"raw_affiliation_string":"Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon","institution_ids":["https://openalex.org/I98635879"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5074578100","display_name":"Ayman Kayssi","orcid":"https://orcid.org/0000-0002-0569-1395"},"institutions":[{"id":"https://openalex.org/I98635879","display_name":"American University of Beirut","ror":"https://ror.org/04pznsd21","country_code":"LB","type":"education","lineage":["https://openalex.org/I98635879"]}],"countries":["LB"],"is_corresponding":false,"raw_author_name":"Ayman Kayssi","raw_affiliation_strings":["Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon"],"affiliations":[{"raw_affiliation_string":"Electrical and Computer Engineering Department, American University of Beirut, Beirut, Lebanon","institution_ids":["https://openalex.org/I98635879"]},{"raw_affiliation_string":"Electrical and Computer Engineering Department American University of Beirut  Beirut 1107 2020 Lebanon","institution_ids":["https://openalex.org/I98635879"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5040277386"],"corresponding_institution_ids":["https://openalex.org/I98635879"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.18357332,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":"800","issue":null,"first_page":"485","last_page":"490"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.6133283376693726},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5938183665275574},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.42283812165260315}],"concepts":[{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.6133283376693726},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5938183665275574},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.42283812165260315}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/hpcsim.2011.5999864","is_oa":false,"landing_page_url":"https://doi.org/10.1109/hpcsim.2011.5999864","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2011 International Conference on High Performance Computing &amp; Simulation","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.4000000059604645,"id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W62390653","https://openalex.org/W1626838828","https://openalex.org/W1669517233","https://openalex.org/W1674877186","https://openalex.org/W1720234221","https://openalex.org/W1733713784","https://openalex.org/W2007087405","https://openalex.org/W2008063947","https://openalex.org/W2086437504","https://openalex.org/W2103378897","https://openalex.org/W2107244388","https://openalex.org/W2117654928","https://openalex.org/W2117824363","https://openalex.org/W2140471436","https://openalex.org/W2244483357","https://openalex.org/W2678934292","https://openalex.org/W4253289766","https://openalex.org/W6636676646","https://openalex.org/W6637096788","https://openalex.org/W6637165743","https://openalex.org/W6637297404","https://openalex.org/W6637360728","https://openalex.org/W6677309853","https://openalex.org/W6739612070","https://openalex.org/W6814336774"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W2382290278","https://openalex.org/W2350741829","https://openalex.org/W2130043461","https://openalex.org/W2386317283","https://openalex.org/W2150112053"],"abstract_inverted_index":{"Intrusion":[0],"detection":[1],"and":[2,25,63,70,90,92,110,125,130,141],"prevention":[3],"systems":[4],"(IDPSs)":[5],"are":[6],"widely":[7],"used":[8],"to":[9,46,108],"secure":[10],"computer":[11],"networks.":[12],"They":[13],"monitor":[14],"network":[15],"traffic":[16],"by":[17],"searching":[18],"for":[19,26],"unusual":[20],"combinations":[21],"in":[22,29,53],"protocol":[23],"headers":[24],"malicious":[27,44,83,97,128],"patterns":[28],"the":[30,48,80,106,119,127,134,143],"packet":[31],"payloads.":[32],"In":[33],"this":[34],"paper":[35],"we":[36],"present":[37],"\"Matryoshka\",":[38],"a":[39,61,85],"vulnerability":[40],"that":[41,75,95],"allows":[42],"tunneled":[43,82,98,112],"packets":[45,99,113],"bypass":[47],"signature":[49],"mapping":[50],"procedures":[51],"implemented":[52,59],"many":[54],"industrial":[55],"IDPS.":[56],"Matryoshka":[57],"is":[58],"as":[60],"tool":[62],"tested":[64],"against":[65],"Snort":[66,86],"under":[67],"different":[68],"topologies":[69],"modes.":[71],"To":[72],"mitigate":[73],"attacks":[74],"can":[76],"be":[77],"initialized":[78],"using":[79],"bypassed":[81],"packets,":[84],"preprocessor":[87,107],"was":[88,114],"developed":[89],"tested,":[91],"results":[93],"demonstrated":[94],"all":[96],"were":[100],"successfully":[101],"detected.":[102],"Processing":[103],"overhead":[104,121,136],"of":[105,118,122,133,137],"inspect":[109],"decapsulate":[111],"measured":[115],"at":[116,131],"2%":[117],"overall":[120,135],"inspecting,":[123,138],"decapsulating,":[124,139],"matching":[126,142],"signature,":[129],"0:2%":[132],"assembling,":[140],"signature.":[144]},"counts_by_year":[{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
