{"id":"https://openalex.org/W2100893630","doi":"https://doi.org/10.1145/1185347.1185372","title":"Packet pre-filtering for network intrusion detection","display_name":"Packet pre-filtering for network intrusion detection","publication_year":2006,"publication_date":"2006-12-03","ids":{"openalex":"https://openalex.org/W2100893630","doi":"https://doi.org/10.1145/1185347.1185372","mag":"2100893630"},"language":"en","primary_location":{"id":"doi:10.1145/1185347.1185372","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1185347.1185372","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2006 ACM/IEEE symposium on Architecture for networking and communications systems","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087174287","display_name":"Ioannis Sourdis","orcid":"https://orcid.org/0000-0002-0452-3664"},"institutions":[{"id":"https://openalex.org/I98358874","display_name":"Delft University of Technology","ror":"https://ror.org/02e2c7k09","country_code":"NL","type":"education","lineage":["https://openalex.org/I98358874"]}],"countries":["NL"],"is_corresponding":true,"raw_author_name":"Ioannis Sourdis","raw_affiliation_strings":["TU Delft, The Netherlands","Electr. Eng. Dept, Tech. Univ. Delft, Delft"],"affiliations":[{"raw_affiliation_string":"TU Delft, The Netherlands","institution_ids":["https://openalex.org/I98358874"]},{"raw_affiliation_string":"Electr. Eng. Dept, Tech. Univ. Delft, Delft","institution_ids":["https://openalex.org/I98358874"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5037369216","display_name":"Vasilis Dimopoulos","orcid":null},"institutions":[{"id":"https://openalex.org/I55741626","display_name":"Technical University of Crete","ror":"https://ror.org/03f8bz564","country_code":"GR","type":"education","lineage":["https://openalex.org/I55741626"]}],"countries":["GR"],"is_corresponding":false,"raw_author_name":"Vasilis Dimopoulos","raw_affiliation_strings":["Technical University of Crete, Crete, Greece","Technical Univ. of Crete, Crete, Greece#TAB#"],"affiliations":[{"raw_affiliation_string":"Technical University of Crete, Crete, Greece","institution_ids":["https://openalex.org/I55741626"]},{"raw_affiliation_string":"Technical Univ. of Crete, Crete, Greece#TAB#","institution_ids":["https://openalex.org/I55741626"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045649319","display_name":"Dionisios Pnevmatikatos","orcid":"https://orcid.org/0000-0003-3533-2761"},"institutions":[{"id":"https://openalex.org/I55741626","display_name":"Technical University of Crete","ror":"https://ror.org/03f8bz564","country_code":"GR","type":"education","lineage":["https://openalex.org/I55741626"]}],"countries":["GR"],"is_corresponding":false,"raw_author_name":"Dionisios Pnevmatikatos","raw_affiliation_strings":["Technical University of Crete, Crete, Greece and Institute of Computer Science (ICS), Crete, Greece","Technical University of Crete, Crete, Greece and Institute of Computer Science (ICS), Crete, Greece#TAB#"],"affiliations":[{"raw_affiliation_string":"Technical University of Crete, Crete, Greece and Institute of Computer Science (ICS), Crete, Greece","institution_ids":["https://openalex.org/I55741626"]},{"raw_affiliation_string":"Technical University of Crete, Crete, Greece and Institute of Computer Science (ICS), Crete, Greece#TAB#","institution_ids":["https://openalex.org/I55741626"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5113612474","display_name":"Stamatis Vassiliadis","orcid":null},"institutions":[{"id":"https://openalex.org/I98358874","display_name":"Delft University of Technology","ror":"https://ror.org/02e2c7k09","country_code":"NL","type":"education","lineage":["https://openalex.org/I98358874"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Stamatis Vassiliadis","raw_affiliation_strings":["TU Delft, The Netherlands","[TU Delft, the Netherlands]"],"affiliations":[{"raw_affiliation_string":"TU Delft, The Netherlands","institution_ids":["https://openalex.org/I98358874"]},{"raw_affiliation_string":"[TU Delft, the Netherlands]","institution_ids":["https://openalex.org/I98358874"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5087174287"],"corresponding_institution_ids":["https://openalex.org/I98358874"],"apc_list":null,"apc_paid":null,"fwci":3.9232,"has_fulltext":false,"cited_by_count":59,"citation_normalized_percentile":{"value":0.94069412,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"183","last_page":"192"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12326","display_name":"Network Packet Processing and Optimization","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9955000281333923,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8686269521713257},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.7496766448020935},{"id":"https://openalex.org/keywords/header","display_name":"Header","score":0.7008352279663086},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6997661590576172},{"id":"https://openalex.org/keywords/packet-processing","display_name":"Packet processing","score":0.5974060297012329},{"id":"https://openalex.org/keywords/deep-packet-inspection","display_name":"Deep packet inspection","score":0.5485036969184875},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.5394691824913025},{"id":"https://openalex.org/keywords/packet-analyzer","display_name":"Packet analyzer","score":0.5128657817840576},{"id":"https://openalex.org/keywords/throughput","display_name":"Throughput","score":0.4973428547382355},{"id":"https://openalex.org/keywords/processing-delay","display_name":"Processing delay","score":0.4802815616130829},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4672064185142517},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.45637571811676025},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.38530778884887695},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3187054693698883},{"id":"https://openalex.org/keywords/transmission-delay","display_name":"Transmission delay","score":0.2824016213417053},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.09738728404045105}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8686269521713257},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.7496766448020935},{"id":"https://openalex.org/C48105269","wikidata":"https://www.wikidata.org/wiki/Q1141160","display_name":"Header","level":2,"score":0.7008352279663086},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6997661590576172},{"id":"https://openalex.org/C2779581428","wikidata":"https://www.wikidata.org/wiki/Q7122997","display_name":"Packet processing","level":3,"score":0.5974060297012329},{"id":"https://openalex.org/C204679922","wikidata":"https://www.wikidata.org/wiki/Q734252","display_name":"Deep packet inspection","level":3,"score":0.5485036969184875},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.5394691824913025},{"id":"https://openalex.org/C95362637","wikidata":"https://www.wikidata.org/wiki/Q54366","display_name":"Packet analyzer","level":3,"score":0.5128657817840576},{"id":"https://openalex.org/C157764524","wikidata":"https://www.wikidata.org/wiki/Q1383412","display_name":"Throughput","level":3,"score":0.4973428547382355},{"id":"https://openalex.org/C21434264","wikidata":"https://www.wikidata.org/wiki/Q7247320","display_name":"Processing delay","level":4,"score":0.4802815616130829},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4672064185142517},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.45637571811676025},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.38530778884887695},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3187054693698883},{"id":"https://openalex.org/C108921912","wikidata":"https://www.wikidata.org/wiki/Q7834639","display_name":"Transmission delay","level":3,"score":0.2824016213417053},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.09738728404045105},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C555944384","wikidata":"https://www.wikidata.org/wiki/Q249","display_name":"Wireless","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/1185347.1185372","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1185347.1185372","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2006 ACM/IEEE symposium on Architecture for networking and communications systems","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321012","display_name":"Technische Universiteit Delft","ror":"https://ror.org/02e2c7k09"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W1507645144","https://openalex.org/W1548282082","https://openalex.org/W1551666721","https://openalex.org/W1569514888","https://openalex.org/W1707172707","https://openalex.org/W1891233321","https://openalex.org/W1960511147","https://openalex.org/W2026164946","https://openalex.org/W2115025779","https://openalex.org/W2135932040","https://openalex.org/W2141607151","https://openalex.org/W2148462679","https://openalex.org/W2149375166","https://openalex.org/W2153102141","https://openalex.org/W2911708692"],"related_works":["https://openalex.org/W2037047765","https://openalex.org/W2009829758","https://openalex.org/W1993620881","https://openalex.org/W2071499953","https://openalex.org/W2390663577","https://openalex.org/W2991062139","https://openalex.org/W159301790","https://openalex.org/W2514988192","https://openalex.org/W2161402239","https://openalex.org/W2122762499"],"abstract_inverted_index":{"As":[0],"Intrusion":[1],"Detection":[2],"Systems":[3],"(IDS)utilize":[4],"more":[5,87],"complex":[6,11],"syntax":[7],"to":[8,54,82,108,143,169,199,253],"efficiently":[9],"describe":[10],"attacks,":[12],"their":[13],"processing":[14,225,249],"requirements":[15],"increase":[16],"rapidly.":[17],"Hardware":[18],"and,":[19],"even":[20],"more,":[21],"software":[22],"platforms":[23],"face":[24,36],"difficulties":[25],"in":[26,111,251],"keeping":[27],"up":[28,168],"with":[29],"the":[30,60,112,165,194,215,228,231,238,255],"computationally":[31],"intensive":[32],"IDS":[33,93,106,160],"tasks,":[34],"and":[35,65,157,167,220,226,236,240],"overheads":[37],"that":[38,72,127,140,163,183,246],"can":[39,141,150,181],"substantially":[40],"diminish":[41],"performance.In":[42],"this":[43,98,118,135],"paper":[44],"we":[45],"introduce":[46],"a":[47,52,78,89,101,122,131,144,146,222,243],"packet":[48,81,180,208,219],"pre-filtering":[49,113,209],"approach":[50],"as":[51,221],"means":[53],"resolve,":[55],"or":[56,84],"at":[57,212],"least":[58,213],"alleviate,":[59],"increasing":[61],"needs":[62],"of":[63,92,117,125,138,197,230,242,257],"current":[64],"future":[66],"intrusion":[67],"detection":[68],"systems.":[69],"We":[70,95,233],"observe":[71],"it":[73],"is":[74,121,205],"very":[75],"rare":[76],"for":[77,130,173],"single":[79],"incoming":[80,179],"fully":[83],"partially":[85],"match":[86,120],"than":[88],"few":[90],"tens":[91],"rules.":[94],"capitalize":[96],"on":[97,177,184,190],"observation":[99],"selecting":[100],"small":[102,123],"portion":[103],"from":[104],"each":[105,174,178,191],"rule":[107,176],"be":[109,200],"matched":[110],"step.":[114],"The":[115],"result":[116,223],"partial":[119],"subset":[124],"rules":[126,139,187,198,217],"are":[128],"candidates":[129],"full":[132],"match.":[133],"Given":[134],"pruned":[136],"set":[137],"apply":[142,189],"packet,":[145,192],"second-stage,":[147],"full-match":[148],"engine":[149],"sustain":[151],"higher":[152],"throughput.We":[153],"use":[154],"DefCon":[155],"traces":[156],"recent":[158],"Snort":[159],"rule-set,and":[161],"show":[162],"matching":[164,211],"header":[166],"an":[170],"8-character":[171],"prefix":[172],"payload":[175],"determine":[182],"average":[185],"1.8":[186],"may":[188],"while":[193],"maximum":[195],"number":[196],"checked":[201],"across":[202],"all":[203],"packets":[204],"32.":[206],"Effectively,":[207],"prevents":[210],"99%of":[214],"SNORT":[216],"per":[218],"minimizes":[224],"improves":[227],"scalability":[229],"system.":[232],"also":[234],"propose":[235],"evaluate":[237],"cost":[239],"performance":[241],"reconfigurable":[244],"architecture":[245],"uses":[247],"multiple":[248],"engines":[250],"order":[252],"exploit":[254],"benefits":[256],"pre-filtering.":[258]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":2},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":1},{"year":2015,"cited_by_count":1},{"year":2014,"cited_by_count":6},{"year":2013,"cited_by_count":8},{"year":2012,"cited_by_count":8}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
