Regarding the Intrusion Detection System there are different data-sets, each one contains a lot of features, these features is divided in different ways.
My question which of these features is considered as flow-based features and which one is considered as packet-based features?