Evaluation studies of three intrusion detection systems under various attacks and rule sets

Evaluation studies of three intrusion detection systems under various attacks and rule sets
复制标题

三种入侵检测系统在不同攻击和规则集下的评估研究

DOI:
--
复制
发表时间:
2013
期刊:
IEEE Region 10 Conference
影响因子:
--
通讯作者:
V. Visoottiviseth
V. Visoottiviseth
中科院分区:
--
文献类型:
--
作者:
Kittikhun Thongkanchorn;S. Ngamsuriyaroj;V. Visoottiviseth

文献摘要

被引文献

相似文献

本文研究了三个流行的开源入侵检测系统:Snort,Suricata和Bro的性能和检测精度。我们使用各种攻击类型,包括DoS攻击,DNS攻击,FTP攻击,扫描端口攻击和SNMP攻击来评估所有系统。实验是在不同的流量率和不同的主动规则下进行的。使用的性能指标包括CPU利用率、数据包丢失数和警报数。实验结果表明,每种攻击类型对入侵检测系统的性能都有显著的影响。但是,在不同的攻击类型和使用一组特定的规则进行评估时,Bro表现出比其他IDS系统更好的性能。结果还表明,当三个IDS工具激活完整的规则集时,准确性下降。
This paper investigates the performance and the detection accuracy of three popular open-source intrusion detection systems: Snort, Suricata and Bro. We evaluate all systems using various attack types including DoS attack, DNS attack, FTP attack, Scan port attack, and SNMP attack. The experiments were run under different traffic rates and different sets of active rules. The performance metrics used are the CPU utilization, the number of packets lost, and the number of alerts. The results illustrated that each attack type had significant effects on the IDS performance. But, Bro showed better performance than other IDS systems when evaluated under different attack types and using a specific set of rules. The results also indicated the drop of the accuracy when the three IDS tools activate the full rule set.