{"id":"https://openalex.org/W2056431591","doi":"https://doi.org/10.1145/1030083.1030087","title":"On the difficulty of scalably detecting network attacks","display_name":"On the difficulty of scalably detecting network attacks","publication_year":2004,"publication_date":"2004-10-25","ids":{"openalex":"https://openalex.org/W2056431591","doi":"https://doi.org/10.1145/1030083.1030087","mag":"2056431591"},"language":"en","primary_location":{"id":"doi:10.1145/1030083.1030087","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1030083.1030087","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 11th ACM conference on Computer and communications security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5024587249","display_name":"Kirill Levchenko","orcid":"https://orcid.org/0000-0003-4527-9749"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Kirill Levchenko","raw_affiliation_strings":["University of California at San Diego"],"affiliations":[{"raw_affiliation_string":"University of California at San Diego","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111512545","display_name":"Ramamohan Paturi","orcid":null},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ramamohan Paturi","raw_affiliation_strings":["University of California at San Diego"],"affiliations":[{"raw_affiliation_string":"University of California at San Diego","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102730096","display_name":"George Varghese","orcid":"https://orcid.org/0000-0002-8218-5701"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"George Varghese","raw_affiliation_strings":["University of California at San Diego"],"affiliations":[{"raw_affiliation_string":"University of California at San Diego","institution_ids":["https://openalex.org/I36258959"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5024587249"],"corresponding_institution_ids":["https://openalex.org/I36258959"],"apc_list":null,"apc_paid":null,"fwci":5.4795,"has_fulltext":false,"cited_by_count":37,"citation_normalized_percentile":{"value":0.95993929,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"12","last_page":"20"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7806856632232666},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.7579842209815979},{"id":"https://openalex.org/keywords/flooding","display_name":"Flooding (psychology)","score":0.6020830869674683},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.5930443406105042},{"id":"https://openalex.org/keywords/identifier","display_name":"Identifier","score":0.5709100961685181},{"id":"https://openalex.org/keywords/state","display_name":"State (computer science)","score":0.5386969447135925},{"id":"https://openalex.org/keywords/port","display_name":"Port (circuit theory)","score":0.5241156816482544},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.5158542990684509},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.5129911303520203},{"id":"https://openalex.org/keywords/flow-network","display_name":"Flow network","score":0.4710395634174347},{"id":"https://openalex.org/keywords/connection","display_name":"Connection (principal bundle)","score":0.4608897566795349},{"id":"https://openalex.org/keywords/intrusion","display_name":"Intrusion","score":0.4260832369327545},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4192259907722473},{"id":"https://openalex.org/keywords/matching","display_name":"Matching (statistics)","score":0.41442596912384033},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.15357112884521484},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.09203505516052246},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.07707676291465759}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7806856632232666},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.7579842209815979},{"id":"https://openalex.org/C186594467","wikidata":"https://www.wikidata.org/wiki/Q1429176","display_name":"Flooding (psychology)","level":2,"score":0.6020830869674683},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.5930443406105042},{"id":"https://openalex.org/C154504017","wikidata":"https://www.wikidata.org/wiki/Q853614","display_name":"Identifier","level":2,"score":0.5709100961685181},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.5386969447135925},{"id":"https://openalex.org/C32802771","wikidata":"https://www.wikidata.org/wiki/Q2443617","display_name":"Port (circuit theory)","level":2,"score":0.5241156816482544},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.5158542990684509},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.5129911303520203},{"id":"https://openalex.org/C114809511","wikidata":"https://www.wikidata.org/wiki/Q1412924","display_name":"Flow network","level":2,"score":0.4710395634174347},{"id":"https://openalex.org/C13355873","wikidata":"https://www.wikidata.org/wiki/Q2920850","display_name":"Connection (principal bundle)","level":2,"score":0.4608897566795349},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.4260832369327545},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4192259907722473},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.41442596912384033},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.15357112884521484},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.09203505516052246},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.07707676291465759},{"id":"https://openalex.org/C17409809","wikidata":"https://www.wikidata.org/wiki/Q161764","display_name":"Geochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.0},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.0},{"id":"https://openalex.org/C542102704","wikidata":"https://www.wikidata.org/wiki/Q183257","display_name":"Psychotherapist","level":1,"score":0.0},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.0},{"id":"https://openalex.org/C66938386","wikidata":"https://www.wikidata.org/wiki/Q633538","display_name":"Structural engineering","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/1030083.1030087","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1030083.1030087","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 11th ACM conference on Computer and communications security","raw_type":"proceedings-article"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.60.3083","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.60.3083","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.ucsd.edu/~varghese/PAPERS/anomalies14ccs.pdf","raw_type":"text"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W1516506771","https://openalex.org/W1540641082","https://openalex.org/W1553177637","https://openalex.org/W1563061804","https://openalex.org/W1920802909","https://openalex.org/W1980223785","https://openalex.org/W2001968297","https://openalex.org/W2012549717","https://openalex.org/W2034302520","https://openalex.org/W2057493578","https://openalex.org/W2064379477","https://openalex.org/W2112135709","https://openalex.org/W2127273221","https://openalex.org/W2340787257","https://openalex.org/W3021187106","https://openalex.org/W4229657284","https://openalex.org/W6633671634","https://openalex.org/W6678935822"],"related_works":["https://openalex.org/W2133389611","https://openalex.org/W2376886931","https://openalex.org/W2061466315","https://openalex.org/W2010561419","https://openalex.org/W2374845301","https://openalex.org/W2351448539","https://openalex.org/W1977863481","https://openalex.org/W2384741105","https://openalex.org/W1495178644","https://openalex.org/W2185594426"],"abstract_inverted_index":{"Most":[0],"network":[1,19,38,49],"intrusion":[2,39,139],"tools":[3,126],"(e.g.,":[4,21,30],"Bro)":[5],"use":[6,125],"per-flow":[7,65,155],"state":[8,66],"to":[9,17,42,130,163,166,170,179],"reassemble":[10],"TCP":[11],"connections":[12],"and":[13,27,112,149],"fragments":[14],"in":[15],"order":[16],"detect":[18],"attacks":[20],"SYN":[22,143],"Flooding":[23],"or":[24,96],"Connection":[25,147],"Hijacking)":[26],"preliminary":[28],"reconnaissance":[29],"Port":[31,145],"Scans).":[32],"On":[33],"the":[34,82,107,133],"other":[35],"hand,":[36],"if":[37],"detection":[40,117,140],"is":[41,56,67,75,81],"be":[43,164],"implemented":[44],"at":[45,48],"high":[46],"speeds":[47],"vantage":[50],"points,":[51],"some":[52,176],"form":[53],"of":[54,71,88,109,136],"aggregation":[55],"necessary.":[57],"While":[58],"many":[59,70,137],"security":[60,115],"analysts":[61],"believe":[62],"that":[63,79,132,161],"such":[64],"required":[68],"for":[69],"these":[72,171,181],"problems,":[73],"there":[74],"no":[76],"clear":[77],"proof":[78],"this":[80,103],"case.":[83],"In":[84,102],"fact,":[85],"a":[86,114,121],"number":[87],"problems":[89,141],"(such":[90],"as":[91],"detecting":[92],"large":[93],"traffic":[94],"footprints":[95],"counting":[97],"identifiers)":[98],"have":[99,120],"scalable":[100,122,168],"solutions.":[101],"paper,":[104],"we":[105,173],"initiate":[106],"study":[108],"identifying":[110],"when":[111],"how":[113],"attack":[116],"problem":[118],"can":[119],"solution.":[123],"We":[124],"from":[127],"Communication":[128],"Complexity":[129],"prove":[131],"common":[134],"formulations":[135],"well-known":[138],"(detecting":[142],"Flooding,":[144],"Scans,":[146],"Hijacking,":[148],"content":[150],"matching":[151],"across":[152],"fragments)":[153],"require":[154],"state.":[156],"Our":[157],"theory":[158],"exposes":[159],"assumptions":[160],"need":[162],"changed":[165],"provide":[167],"solutions":[169],"problems;":[172],"conclude":[174],"with":[175],"systems":[177],"techniques":[178],"circumvent":[180],"lower":[182],"bounds.":[183]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2013,"cited_by_count":1},{"year":2012,"cited_by_count":1}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
