... assumptionsregarding time monotonicity. For example, Bro derives its measureof time from the timestamps of the captured packets. For example ituses these timestamps to compute timer expirations ... several different concurrent queries.Regarding timestamps, retrieved packets include the time whenthe TM recorded them. However, this time is in the past and ifthe NIDS uses it directly, confusion ... managestate. The simple solution of rewriting the timestamps to reflect thecurrent time confounds any analysis that relies on either absolute time or on relative time between multiple connections. Such...