{"id":"https://openalex.org/W4416513986","doi":"https://doi.org/10.1109/isncc66965.2025.11250446","title":"An Investigation on Packet Sampling between Kernel and User Space for NIDS","display_name":"An Investigation on Packet Sampling between Kernel and User Space for NIDS","publication_year":2025,"publication_date":"2025-10-27","ids":{"openalex":"https://openalex.org/W4416513986","doi":"https://doi.org/10.1109/isncc66965.2025.11250446"},"language":"en","primary_location":{"id":"doi:10.1109/isncc66965.2025.11250446","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isncc66965.2025.11250446","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Symposium on Networks, Computers and Communications (ISNCC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5032087610","display_name":"Luca Giacometti","orcid":"https://orcid.org/0009-0000-1203-3852"},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Luca Giacometti","raw_affiliation_strings":["Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy","institution_ids":["https://openalex.org/I93860229"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Dario Crippa","orcid":null},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Dario Crippa","raw_affiliation_strings":["Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy","institution_ids":["https://openalex.org/I93860229"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044441066","display_name":"Sebastiano Miano","orcid":"https://orcid.org/0000-0002-1247-9640"},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Sebastiano Miano","raw_affiliation_strings":["Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy","institution_ids":["https://openalex.org/I93860229"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5047350739","display_name":"Giacomo Verticale","orcid":"https://orcid.org/0000-0001-7508-9706"},"institutions":[{"id":"https://openalex.org/I93860229","display_name":"Politecnico di Milano","ror":"https://ror.org/01nffqt88","country_code":"IT","type":"education","lineage":["https://openalex.org/I93860229"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Giacomo Verticale","raw_affiliation_strings":["Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Politecnico di Milano,Department of Electronics, Information and Bioengineering,Italy","institution_ids":["https://openalex.org/I93860229"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.36370728,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.43970000743865967,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.43970000743865967,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.23479999601840973,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10138","display_name":"Network Traffic and Congestion Control","score":0.09269999712705612,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.7226999998092651},{"id":"https://openalex.org/keywords/testbed","display_name":"Testbed","score":0.7085000276565552},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.70660001039505},{"id":"https://openalex.org/keywords/packet-analyzer","display_name":"Packet analyzer","score":0.6284000277519226},{"id":"https://openalex.org/keywords/packet-processing","display_name":"Packet processing","score":0.5289000272750854},{"id":"https://openalex.org/keywords/sampling","display_name":"Sampling (signal processing)","score":0.5163000226020813},{"id":"https://openalex.org/keywords/throughput","display_name":"Throughput","score":0.4900999963283539},{"id":"https://openalex.org/keywords/deep-packet-inspection","display_name":"Deep packet inspection","score":0.47760000824928284},{"id":"https://openalex.org/keywords/processing-delay","display_name":"Processing delay","score":0.46880000829696655}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7376000285148621},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.7226999998092651},{"id":"https://openalex.org/C31395832","wikidata":"https://www.wikidata.org/wiki/Q1318674","display_name":"Testbed","level":2,"score":0.7085000276565552},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.70660001039505},{"id":"https://openalex.org/C95362637","wikidata":"https://www.wikidata.org/wiki/Q54366","display_name":"Packet analyzer","level":3,"score":0.6284000277519226},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.5687999725341797},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.5562000274658203},{"id":"https://openalex.org/C2779581428","wikidata":"https://www.wikidata.org/wiki/Q7122997","display_name":"Packet processing","level":3,"score":0.5289000272750854},{"id":"https://openalex.org/C140779682","wikidata":"https://www.wikidata.org/wiki/Q210868","display_name":"Sampling (signal processing)","level":3,"score":0.5163000226020813},{"id":"https://openalex.org/C157764524","wikidata":"https://www.wikidata.org/wiki/Q1383412","display_name":"Throughput","level":3,"score":0.4900999963283539},{"id":"https://openalex.org/C204679922","wikidata":"https://www.wikidata.org/wiki/Q734252","display_name":"Deep packet inspection","level":3,"score":0.47760000824928284},{"id":"https://openalex.org/C21434264","wikidata":"https://www.wikidata.org/wiki/Q7247320","display_name":"Processing delay","level":4,"score":0.46880000829696655},{"id":"https://openalex.org/C54108766","wikidata":"https://www.wikidata.org/wiki/Q391064","display_name":"Packet loss","level":3,"score":0.37389999628067017},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.3666999936103821},{"id":"https://openalex.org/C108921912","wikidata":"https://www.wikidata.org/wiki/Q7834639","display_name":"Transmission delay","level":3,"score":0.36629998683929443},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.36320000886917114},{"id":"https://openalex.org/C74193536","wikidata":"https://www.wikidata.org/wiki/Q574844","display_name":"Kernel (algebra)","level":2,"score":0.30889999866485596},{"id":"https://openalex.org/C37624559","wikidata":"https://www.wikidata.org/wiki/Q5375776","display_name":"End-to-end delay","level":3,"score":0.30090001225471497},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.2671000063419342},{"id":"https://openalex.org/C137524506","wikidata":"https://www.wikidata.org/wiki/Q2247688","display_name":"Anomaly-based intrusion detection system","level":3,"score":0.26669999957084656},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.26489999890327454},{"id":"https://openalex.org/C163099246","wikidata":"https://www.wikidata.org/wiki/Q1978975","display_name":"Network scheduler","level":5,"score":0.2603999972343445},{"id":"https://openalex.org/C106131492","wikidata":"https://www.wikidata.org/wiki/Q3072260","display_name":"Filter (signal processing)","level":2,"score":0.25619998574256897},{"id":"https://openalex.org/C90936777","wikidata":"https://www.wikidata.org/wiki/Q917189","display_name":"Host-based intrusion detection system","level":4,"score":0.2533999979496002},{"id":"https://openalex.org/C178484546","wikidata":"https://www.wikidata.org/wiki/Q7123009","display_name":"Packet segmentation","level":5,"score":0.25110000371932983}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/isncc66965.2025.11250446","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isncc66965.2025.11250446","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Symposium on Networks, Computers and Communications (ISNCC)","raw_type":"proceedings-article"},{"id":"pmh:oai:re.public.polimi.it:11311/1305188","is_oa":false,"landing_page_url":"https://hdl.handle.net/11311/1305188","pdf_url":null,"source":{"id":"https://openalex.org/S4306400312","display_name":"Virtual Community of Pathological Anatomy (University of Castilla La Mancha)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79189158","host_organization_name":"University of Castilla-La Mancha","host_organization_lineage":["https://openalex.org/I79189158"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":4,"referenced_works":["https://openalex.org/W2963197901","https://openalex.org/W4366493235","https://openalex.org/W4390685455","https://openalex.org/W4402040227"],"related_works":[],"abstract_inverted_index":{"Extended":[0],"Berkeley":[1],"Packet":[2],"Filter":[3],"technology":[4],"has":[5],"been":[6,95,124],"successfully":[7],"used":[8,104],"to":[9,44,48,60,72,89,105,142],"accelerate":[10],"several":[11],"data-plane":[12],"algorithms.":[13],"An":[14],"application":[15],"area":[16],"of":[17,55,77],"growing":[18],"interest":[19],"is":[20,30,155],"Intrusion":[21],"Detection,":[22],"where":[23],"timely":[24],"packet":[25,57,91,112],"processing":[26],"at":[27],"high":[28,118],"speed":[29],"critical.":[31],"In":[32],"this":[33],"paper,":[34],"we":[35],"focus":[36],"on":[37,127,138],"anomaly":[38],"detection,":[39],"which":[40],"uses":[41],"machine":[42],"learning":[43],"identify":[45],"packets":[46],"belonging":[47],"a":[49,56,69,111,117],"malicious":[50],"flow":[51],"with":[52,63],"the":[53,64,74,78,90,101,107,139,144],"intervention":[54],"sampling":[58,92,113],"policy":[59,93],"keep":[61],"up":[62],"traffic":[65],"network":[66,151],"pace":[67],"in":[68],"kernel-to-user-space":[70],"pipeline,":[71],"investigate":[73],"deployment":[75],"feasibility":[76],"designed":[79,150],"anomaly-based":[80],"kernel-enhanced":[81],"intrusion":[82,152],"detection":[83,153],"system.":[84],"The":[85,120],"performance":[86],"tests":[87],"related":[88],"have":[94,123],"carried":[96],"out":[97,126],"taking":[98],"into":[99],"account":[100],"same":[102],"dataset":[103],"test":[106],"inference":[108],"algorithm,":[109],"establishing":[110],"rate":[114],"threshold":[115],"maintaining":[116],"accuracy.":[119],"throughput":[121],"measurements":[122],"tried":[125],"our":[128,149],"testbed":[129],"composed":[130],"by":[131],"two":[132],"back-to-back":[133],"connected":[134],"programmable":[135],"middlebox":[136],"leveraging":[137],"iperf3":[140],"tool":[141],"employ":[143],"stress":[145],"test,":[146],"validating":[147],"that":[148],"system":[154],"suitable":[156],"for":[157],"deployment.<sup":[158],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[159],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>":[160]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-23T00:00:00"}
