This appendix presents NSM's intellectual history, the collection of formal papers that shaped the environment for modern network-based detection and response. I concentrate on formally published papers still available online, although I make a few exceptions and note them explicitly. I determined their relevance by assessing their messages and by tracing citation histories. In other words, current researchers seem to find certain older papers to be especially relevant to their work.
Papers in the following categories are included:
• Sensor architecture
• Packet analysis
• Flow-based monitoring
• Alert-centric intrusion detection
• Complimentary technologies
Students of NSM will ...