{"id":"https://openalex.org/W2093735253","doi":"https://doi.org/10.1109/icnss.2011.6059953","title":"A misuse-based network Intrusion Detection System using Temporal Logic and stream processing","display_name":"A misuse-based network Intrusion Detection System using Temporal Logic and stream processing","publication_year":2011,"publication_date":"2011-09-01","ids":{"openalex":"https://openalex.org/W2093735253","doi":"https://doi.org/10.1109/icnss.2011.6059953","mag":"2093735253"},"language":"en","primary_location":{"id":"doi:10.1109/icnss.2011.6059953","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icnss.2011.6059953","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2011 5th International Conference on Network and System Security","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5028151452","display_name":"Abdulbasit Ahmed","orcid":"https://orcid.org/0000-0001-7700-5836"},"institutions":[{"id":"https://openalex.org/I146655781","display_name":"University of Liverpool","ror":"https://ror.org/04xs57h96","country_code":"GB","type":"education","lineage":["https://openalex.org/I146655781"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Abdulbasit Ahmed","raw_affiliation_strings":["Department of Computer Science, University of Liverpool, Liverpool, UK","Department of Computer Science, University of Liverpool, United Kingdom"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, Liverpool, UK","institution_ids":["https://openalex.org/I146655781"]},{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, United Kingdom","institution_ids":["https://openalex.org/I146655781"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5057274980","display_name":"Alexei Lisitsa","orcid":"https://orcid.org/0000-0002-3820-643X"},"institutions":[{"id":"https://openalex.org/I146655781","display_name":"University of Liverpool","ror":"https://ror.org/04xs57h96","country_code":"GB","type":"education","lineage":["https://openalex.org/I146655781"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Alexei Lisitsa","raw_affiliation_strings":["Department of Computer Science, University of Liverpool, Liverpool, UK","Department of Computer Science, University of Liverpool, United Kingdom"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, Liverpool, UK","institution_ids":["https://openalex.org/I146655781"]},{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, United Kingdom","institution_ids":["https://openalex.org/I146655781"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5013515770","display_name":"Clare Dixon","orcid":"https://orcid.org/0000-0002-4610-9533"},"institutions":[{"id":"https://openalex.org/I146655781","display_name":"University of Liverpool","ror":"https://ror.org/04xs57h96","country_code":"GB","type":"education","lineage":["https://openalex.org/I146655781"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Clare Dixon","raw_affiliation_strings":["Department of Computer Science, University of Liverpool, Liverpool, UK","Department of Computer Science, University of Liverpool, United Kingdom"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, Liverpool, UK","institution_ids":["https://openalex.org/I146655781"]},{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, United Kingdom","institution_ids":["https://openalex.org/I146655781"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I146655781"],"apc_list":null,"apc_paid":null,"fwci":0.5718,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":{"value":0.602676,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":88,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10317","display_name":"Advanced Database Systems and Queries","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.8292547464370728},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8201344609260559},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.6499353647232056},{"id":"https://openalex.org/keywords/anomaly-based-intrusion-detection-system","display_name":"Anomaly-based intrusion detection system","score":0.5144796371459961},{"id":"https://openalex.org/keywords/host-based-intrusion-detection-system","display_name":"Host-based intrusion detection system","score":0.4587036371231079},{"id":"https://openalex.org/keywords/rotation-formalisms-in-three-dimensions","display_name":"Rotation formalisms in three dimensions","score":0.45834633708000183},{"id":"https://openalex.org/keywords/data-stream","display_name":"Data stream","score":0.41606405377388},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.3808738589286804},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3682299852371216},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.3311871290206909},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.20294609665870667},{"id":"https://openalex.org/keywords/intrusion-prevention-system","display_name":"Intrusion prevention system","score":0.09031978249549866}],"concepts":[{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.8292547464370728},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8201344609260559},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.6499353647232056},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.5144796371459961},{"id":"https://openalex.org/C90936777","wikidata":"https://www.wikidata.org/wiki/Q917189","display_name":"Host-based intrusion detection system","level":4,"score":0.4587036371231079},{"id":"https://openalex.org/C171018156","wikidata":"https://www.wikidata.org/wiki/Q7370306","display_name":"Rotation formalisms in three dimensions","level":2,"score":0.45834633708000183},{"id":"https://openalex.org/C2778484313","wikidata":"https://www.wikidata.org/wiki/Q1172540","display_name":"Data stream","level":2,"score":0.41606405377388},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.3808738589286804},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3682299852371216},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3311871290206909},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.20294609665870667},{"id":"https://openalex.org/C27061796","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion prevention system","level":3,"score":0.09031978249549866},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/icnss.2011.6059953","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icnss.2011.6059953","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2011 5th International Conference on Network and System Security","raw_type":"proceedings-article"},{"id":"pmh:oai:pure.atira.dk:openaire_cris_publications/591e1157-56c2-4b9b-a6e8-e7fc01b8bb6b","is_oa":false,"landing_page_url":"https://research.manchester.ac.uk/en/publications/591e1157-56c2-4b9b-a6e8-e7fc01b8bb6b","pdf_url":null,"source":{"id":"https://openalex.org/S4306400662","display_name":"Research Explorer (The University of Manchester)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I28407311","host_organization_name":"University of Manchester","host_organization_lineage":["https://openalex.org/I28407311"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Ahmed, A, Lisitsa, A & Dixon, C 2011, A misuse-based network intrusion detection system using temporal logic and stream processing. in Proceedings - 2011 5th International Conference on Network and System Security, NSS 2011. https://doi.org/10.1109/ICNSS.2011.6059953","raw_type":"info:eu-repo/semantics/conferenceObject"},{"id":"pmh:oai:pure.atira.dk:publications/591e1157-56c2-4b9b-a6e8-e7fc01b8bb6b","is_oa":false,"landing_page_url":"http://www.scopus.com/inward/record.url?eid=2-s2.0-81055137276&partnerID=MN8TOARS","pdf_url":null,"source":{"id":"https://openalex.org/S4306400662","display_name":"Research Explorer (The University of Manchester)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I28407311","host_organization_name":"University of Manchester","host_organization_lineage":["https://openalex.org/I28407311"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Ahmed, A, Lisitsa, A & Dixon, C 2011, A misuse-based network intrusion detection system using temporal logic and stream processing. in Proceedings - 2011 5th International Conference on Network and System Security, NSS 2011. https://doi.org/10.1109/ICNSS.2011.6059953","raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W55301369","https://openalex.org/W245277704","https://openalex.org/W1499438245","https://openalex.org/W1505757964","https://openalex.org/W1516176889","https://openalex.org/W1591094652","https://openalex.org/W1603652346","https://openalex.org/W1785492489","https://openalex.org/W1825341937","https://openalex.org/W1885037678","https://openalex.org/W1891842933","https://openalex.org/W2026629052","https://openalex.org/W2056431591","https://openalex.org/W2115503987","https://openalex.org/W2129700391","https://openalex.org/W2132851185","https://openalex.org/W2144261930","https://openalex.org/W2269788763","https://openalex.org/W2678934292","https://openalex.org/W6609345438","https://openalex.org/W6635505653","https://openalex.org/W6636105770","https://openalex.org/W6638317425","https://openalex.org/W6639600413","https://openalex.org/W6639741120","https://openalex.org/W6677231548"],"related_works":["https://openalex.org/W2184360008","https://openalex.org/W3148526535","https://openalex.org/W2188427116","https://openalex.org/W2368379890","https://openalex.org/W2183313954","https://openalex.org/W2209997499","https://openalex.org/W1585406410","https://openalex.org/W2148459958","https://openalex.org/W1971929717","https://openalex.org/W2357468538"],"abstract_inverted_index":{"Intrusion":[0],"Detection":[1],"Systems":[2],"(IDS)":[3],"aim":[4],"to":[5,11,39,88,109],"detect":[6,89],"the":[7,13,23,56,91,97,101],"actions":[8],"that":[9,82,94],"attempt":[10],"compromise":[12],"confidentiality,":[14],"availability,":[15],"and":[16,106,114,118],"integrity":[17],"of":[18,41,58,93],"a":[19,35,46,59,104],"resource":[20],"by":[21,64],"monitoring":[22],"events":[24],"occurring":[25],"in":[26,96],"computer":[27],"systems":[28],"and/or":[29],"networks.":[30],"Stream":[31],"data":[32],"processing":[33,74],"is":[34,45,116],"database":[36],"technology":[37],"applied":[38],"flows":[40],"data.":[42,99],"Temporal":[43],"Logic":[44],"formalism":[47],"for":[48,68,75],"representing":[49,69],"change":[50],"over":[51],"time.":[52],"This":[53],"paper":[54],"proposes":[55],"development":[57],"network":[60],"intrusion":[61],"detection":[62],"system":[63],"combining":[65],"temporal":[66],"formalisms":[67],"attack":[70,112],"patterns":[71],"with":[72],"stream":[73],"intruder":[76],"detection.":[77],"The":[78],"experimental":[79],"results":[80],"show":[81],"this":[83],"combination":[84],"successfully":[85],"was":[86],"able":[87],"all":[90],"attacks":[92],"type":[95],"test":[98],"Additionally,":[100],"solution":[102],"provides":[103],"concise":[105],"unambiguous":[107],"way":[108],"formally":[110],"represent":[111],"signatures":[113],"it":[115],"extensible":[117],"scalable.":[119]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2016,"cited_by_count":2},{"year":2015,"cited_by_count":2},{"year":2013,"cited_by_count":2}],"updated_date":"2026-08-26T07:47:46.906454","created_date":"2025-10-10T00:00:00"}
