{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T09:58:01Z","timestamp":1774173481473,"version":"3.50.1"},"reference-count":42,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472298"],"award-info":[{"award-number":["62472298"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62332013"],"award-info":[{"award-number":["62332013"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202322"],"award-info":[{"award-number":["62202322"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572337"],"award-info":[{"award-number":["62572337"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1016\/j.comnet.2026.112199","type":"journal-article","created":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T08:03:30Z","timestamp":1772870610000},"page":"112199","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["MSFramework: Multi-stage similarity-based key flow identification in high-speed networks"],"prefix":"10.1016","volume":"280","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0001-9642-550X","authenticated-orcid":false,"given":"Tianyi","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-0104-8263","authenticated-orcid":false,"given":"Guoju","family":"Gao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-0018-4810","authenticated-orcid":false,"given":"Yu-E","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0003-2768-6607","authenticated-orcid":false,"given":"He","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0005-2308-8783","authenticated-orcid":false,"given":"Jianchun","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0003-4809-4897","authenticated-orcid":false,"given":"Haibo","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0003-3012-0778","authenticated-orcid":false,"given":"Yang","family":"Du","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.comnet.2026.112199_bib0001","series-title":"Proc. ACM Meas. Anal. Comput. Syst.","first-page":"1","article-title":"Fastflow: early yet robust network flow classification using the minimal number of time-series packets","volume":"9","author":"Babaria","year":"2025"},{"key":"10.1016\/j.comnet.2026.112199_bib0002","series-title":"IEEE ICDE","article-title":"A fast sketch method for mining user similarities over fully dynamic graph streams","author":"Jia","year":"2019"},{"issue":"1","key":"10.1016\/j.comnet.2026.112199_bib0003","doi-asserted-by":"crossref","first-page":"1031","DOI":"10.1109\/TNSM.2021.3050091","article-title":"Hierarchical anomaly-based detection of distributed DNS attacks on enterprise networks","volume":"18","author":"Lyu","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"10.1016\/j.comnet.2026.112199_bib0004","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2022.109387","article-title":"Classifying and tracking enterprise assets via dual-grained network behavioral analysis","volume":"218","author":"Lyu","year":"2022","journal-title":"Comput. Netw."},{"issue":"1","key":"10.1016\/j.comnet.2026.112199_bib0005","doi-asserted-by":"crossref","first-page":"505","DOI":"10.1109\/TNSE.2024.3503904","article-title":"TailoredSketch: a fast and adaptive sketch for efficient per-flow size measurement","volume":"12","author":"Gao","year":"2025","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"issue":"3","key":"10.1016\/j.comnet.2026.112199_bib0006","doi-asserted-by":"crossref","first-page":"1010","DOI":"10.1109\/TNET.2022.3212066","article-title":"Self-adaptive sampling based per-flow traffic measurement","volume":"31","author":"Du","year":"2023","journal-title":"IEEE\/ACM Trans. Network."},{"issue":"5","key":"10.1016\/j.comnet.2026.112199_bib0007","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MCOM.2019.1800819","article-title":"Deep learning for encrypted traffic classification: an overview","volume":"57","author":"Rezaei","year":"2019","journal-title":"IEEE Commun. Mag."},{"issue":"3","key":"10.1016\/j.comnet.2026.112199_bib0008","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s00500-019-04030-2","article-title":"Deep packet: a novel approach for encrypted traffic classification using deep learning","volume":"24","author":"Lotfollahi","year":"2020","journal-title":"Soft Comput."},{"issue":"6","key":"10.1016\/j.comnet.2026.112199_bib0009","doi-asserted-by":"crossref","first-page":"3672","DOI":"10.1109\/COMST.2025.3545541","article-title":"Unmasking the internet: a survey of fine-grained network traffic analysis","volume":"27","author":"Feng","year":"2025","journal-title":"IEEE Commun. Surv. Tut."},{"issue":"3","key":"10.1016\/j.comnet.2026.112199_bib0010","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3366699","article-title":"Generalized sketch families for network traffic measurement","volume":"3","author":"Zhou","year":"2019","journal-title":"Proc. ACM Meas. Anal. Comput. Syst."},{"key":"10.1016\/j.comnet.2026.112199_bib0011","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107391","article-title":"Detection of zero-day attacks: an unsupervised port-based approach","volume":"180","author":"Blaise","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112199_bib0012","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2023.100812","article-title":"Performance analysis of entropy variation-based detection of DDoS attacks in IoT","volume":"23","author":"Pandey","year":"2023","journal-title":"Internet Things"},{"key":"10.1016\/j.comnet.2026.112199_bib0013","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1007\/s10994-014-5473-9","article-title":"Analysis of network traffic features for anomaly detection","volume":"101","author":"Iglesias","year":"2015","journal-title":"Mach. Learn."},{"key":"10.1016\/j.comnet.2026.112199_bib0014","series-title":"Proceedings of ISOC NDSS","article-title":"A robust counting sketch for data plane intrusion detection","author":"Kim","year":"2023"},{"key":"10.1016\/j.comnet.2026.112199_bib0015","series-title":"Proceedings of ISOC NDSS","article-title":"SketchFeature: high-quality per-flow feature extractor towards security-aware data plane","author":"Kim","year":"2025"},{"key":"10.1016\/j.comnet.2026.112199_bib0016","series-title":"USENIX NSDI","article-title":"AutoSketch: automatic sketch-oriented compiler for query-driven network telemetry","author":"Sun","year":"2024"},{"issue":"1","key":"10.1016\/j.comnet.2026.112199_bib0017","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.jalgor.2003.12.001","article-title":"An improved data stream summary: the count-min sketch and its applications","volume":"55","author":"Cormode","year":"2005","journal-title":"J. Algor."},{"key":"10.1016\/j.comnet.2026.112199_bib0018","series-title":"ACM CoNEXT","article-title":"Fcm-sketch: generic network measurements with data plane support","author":"Song","year":"2020"},{"issue":"2","key":"10.1016\/j.comnet.2026.112199_bib0019","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3727135","article-title":"Universal and tight bounds on counting errors of count-min sketch with conservative updates","volume":"9","author":"Ben Mazziane","year":"2025","journal-title":"Proc. ACM Meas. Anal. Comput. Syst."},{"key":"10.1016\/j.comnet.2026.112199_bib0020","series-title":"Proceedings of the Twenty-Fifth Annual ACM-SIAM Symposium on Discrete Algorithms","article-title":"Improved concentration bounds for count-sketch","author":"Minton","year":"2014"},{"key":"10.1016\/j.comnet.2026.112199_bib0021","series-title":"European Symposium on Algorithms","article-title":"Loglog counting of large cardinalities","author":"Durand","year":"2003"},{"key":"10.1016\/j.comnet.2026.112199_bib0022","doi-asserted-by":"crossref","DOI":"10.46298\/dmtcs.3545","article-title":"Hyperloglog: the analysis of a near-optimal cardinality estimation algorithm","author":"Flajolet","year":"2007","journal-title":"Discr. Math. Theor. Comput. Sci."},{"key":"10.1016\/j.comnet.2026.112199_bib0023","series-title":"ACM SIGCOMM","article-title":"Elastic sketch: adaptive and fast network-wide measurements","author":"Yang","year":"2018"},{"key":"10.1016\/j.comnet.2026.112199_bib0024","series-title":"ACM SIGKDD","article-title":"A memory-efficient sketch method for estimating high similarities in streaming sets","author":"Wang","year":"2019"},{"key":"10.1016\/j.comnet.2026.112199_bib0025","unstructured":"F. Dong, Y. He, Y. Liang, Z. Liu, Y. Wu, P. Chen, T. Yang, SimiSketch: Efficiently Estimating Similarity of streaming Multisets, arXiv preprint arXiv: 2405.19711(2024)."},{"key":"10.1016\/j.comnet.2026.112199_bib0026","series-title":"Proceedings of the 23rd International Conference on World Wide Web","article-title":"Efficient estimation for high similarities using odd sketches","author":"Mitzenmacher","year":"2014"},{"issue":"3","key":"10.1016\/j.comnet.2026.112199_bib0027","doi-asserted-by":"crossref","first-page":"2399","DOI":"10.1109\/TNSE.2023.3275809","article-title":"Multi-resolution odd sketch for mining extended Jaccard similarity of dynamic streaming sets","volume":"11","author":"Xiao","year":"2023","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.comnet.2026.112199_bib0028","series-title":"ACM SIGKDD","article-title":"Sketch-based anomaly detection in streaming graphs","author":"Bhatia","year":"2023"},{"key":"10.1016\/j.comnet.2026.112199_bib0029","series-title":"Proceedings of the Twentieth Annual Symposium on Computational Geometry","article-title":"Locality-sensitive hashing scheme based on p-stable distributions","author":"Datar","year":"2004"},{"key":"10.1016\/j.comnet.2026.112199_bib0030","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109873","article-title":"PEDDA: Practical and effective detection of distributed attacks on enterprise networks via progressive multi-stage inference","volume":"233","author":"Lyu","year":"2023","journal-title":"Comput. Netw."},{"issue":"3","key":"10.1016\/j.comnet.2026.112199_bib0031","first-page":"1","article-title":"Memory-efficient and flexible detection of heavy hitters in high-speed networks","volume":"1","author":"Huang","year":"2023","journal-title":"ACM SIGMOD"},{"key":"10.1016\/j.comnet.2026.112199_bib0032","series-title":"ACM CIKM","article-title":"Bubble sketch: a high-performance and memory-efficient sketch for finding top-k items in data streams","author":"Cao","year":"2024"},{"issue":"6","key":"10.1016\/j.comnet.2026.112199_bib0033","doi-asserted-by":"crossref","first-page":"5491","DOI":"10.1109\/TNET.2024.3469196","article-title":"Scout sketch+: finding both promising and damping items simultaneously in data streams","volume":"32","author":"Gao","year":"2024","journal-title":"IEEE\/ACM Trans. Network."},{"key":"10.1016\/j.comnet.2026.112199_bib0034","series-title":"ACM SIGMOD","article-title":"Augmented sketch: faster and more accurate stream processing","author":"Roy","year":"2016"},{"issue":"2","key":"10.1016\/j.comnet.2026.112199_bib0035","doi-asserted-by":"crossref","first-page":"208","DOI":"10.1145\/78922.78925","article-title":"A linear-time probabilistic counting algorithm for database applications","volume":"15","author":"Whang","year":"1990","journal-title":"ACM Trans. Database Syst."},{"issue":"6","key":"10.1016\/j.comnet.2026.112199_bib0036","doi-asserted-by":"crossref","first-page":"3738","DOI":"10.1109\/TNET.2017.2753842","article-title":"Cardinality estimation for elephant flows: a compact solution based on virtual register sharing","volume":"25","author":"Xiao","year":"2017","journal-title":"IEEE\/ACM Trans. Network."},{"key":"10.1016\/j.comnet.2026.112199_bib0037","series-title":"IEEE ICDE","article-title":"Utilizing dynamic properties of sharing bits and registers to estimate user cardinalities over time","author":"Wang","year":"2019"},{"issue":"8","key":"10.1016\/j.comnet.2026.112199_bib0038","doi-asserted-by":"crossref","first-page":"4758","DOI":"10.1109\/TKDE.2025.3573812","article-title":"Per-flow quantile estimation using M4 framework","volume":"37","author":"Fan","year":"2025","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.comnet.2026.112199_bib0039","series-title":"IEEE ICDE","article-title":"Histsketch: a compact data structure for accurate per-key distribution monitoring","author":"He","year":"2023"},{"key":"10.1016\/j.comnet.2026.112199_bib0040","series-title":"ACM SIGKDD","article-title":"Dothash: estimating set similarity metrics for link prediction and document deduplication","author":"Nunes","year":"2023"},{"key":"10.1016\/j.comnet.2026.112199_bib0041","series-title":"Proceedings of the Thirtieth Annual ACM Symposium on Theory of Computing","article-title":"Min-wise independent permutations","author":"Broder","year":"1998"},{"issue":"10","key":"10.1016\/j.comnet.2026.112199_bib0042","doi-asserted-by":"crossref","first-page":"3438","DOI":"10.1109\/TKDE.2020.2969423","article-title":"Streaming algorithms for estimating high set similarities in loglog space","volume":"33","author":"Qi","year":"2020","journal-title":"IEEE Trans. Knowl. Data Eng."}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128626002112?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128626002112?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T09:41:38Z","timestamp":1774172498000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626002112"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":42,"alternative-id":["S1389128626002112"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.comnet.2026.112199","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,5]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"MSFramework: Multi-stage similarity-based key flow identification in high-speed networks","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.comnet.2026.112199","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112199"}}