A perspective-retrospective analysis of diversity in signature-based open-source network intrusion detection systems

A perspective-retrospective analysis of diversity in signature-based open-source network intrusion detection systems
复制标题

基于签名的开源网络入侵检测系统多样性的透视回顾性分析

DOI:
10.1007/s10207-023-00794-9
复制
发表时间:
2023
影响因子:
3.2
通讯作者:
Asad H
Asad H
中科院分区:
计算机科学4区
文献类型:
--
作者:
Asad H

文献摘要

相似文献

基于签名的网络入侵检测系统依赖于预先建立的签名和IP地址,这些签名和IP地址经常更新,以跟上快速发展的威胁形势。为了有效地评价这些更新的效果,需要对ids的表现进行全面、长期的评估。本文使用在4年期间收集的规则对Snort和Suricata ids进行透视图-回顾性分析。该研究考察了这些ids在使用过去的规则监控恶意流量时的表现,以及它们在使用未来更新的规则监控相同流量时的表现。为此,从2017年到2020年收集了一组Snort订阅和Suricata新兴威胁规则,并使用相对于PCAP日期的过去和未来规则分析了2017年至2018年的标记PCAP数据。除了探索Snort和Suricata入侵防御系统的演变,本研究还分析了这些入侵防御系统之间存在的功能多样性。通过研究基于签名的入侵防御系统的演化行为及其不同的配置,本研究为如何影响其性能提供了有价值的见解。这些见解可以帮助安全架构师在纵深防御部署中对ids进行组合和分层。
The signature-based network intrusion detection systems (IDSs) entail relying on a pre-established signatures and IP addresses that are frequently updated to keep up with the rapidly evolving threat landscape. To effectively evaluate the efficacy of these updates, a comprehensive, long-term assessment of the IDSs’ performance is required. This article presents a perspective–retrospective analysis of the Snort and Suricata IDSs using rules that were collected over a 4-year period. The study examines how these IDSs perform when monitoring malicious traffic using rules from the past, as well as how they behave when monitoring the same traffic using updated rules in the future. To accomplish this, a set of Snort Subscribed and Suricata Emerging Threats rules were collected from 2017 to 2020, and a labeled PCAP data from 2017 to 2018 was analyzed using past and future rules relative to the PCAP date. In addition to exploring the evolution of Snort and Suricata IDSs, the study also analyses the functional diversity that exists between these IDSs. By examining the evolutionary behavior of signature-based IDSs and their diverse configurations, the research provides valuable insights into how their performance can be impacted. These insights can aid security architects in combining and layering IDSs in a defence-in-depth deployment.