Skip to main navigation Skip to search Skip to main content

Evaluation studies of three intrusion detection systems under various attacks and rule sets

  • Mahidol University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

35 Citations (Scopus)

Abstract

This paper investigates the performance and the detection accuracy of three popular open-source intrusion detection systems: Snort, Suricata and Bro. We evaluate all systems using various attack types including DoS attack, DNS attack, FTP attack, Scan port attack, and SNMP attack. The experiments were run under different traffic rates and different sets of active rules. The performance metrics used are the CPU utilization, the number of packets lost, and the number of alerts. The results illustrated that each attack type had significant effects on the IDS performance. But, Bro showed better performance than other IDS systems when evaluated under different attack types and using a specific set of rules. The results also indicated the drop of the accuracy when the three IDS tools activate the full rule set.

Original languageEnglish
Title of host publication2013 IEEE International Conference of IEEE Region 10, IEEE TENCON 2013 - Conference Proceedings
DOIs
Publication statusPublished - 2013
Event2013 IEEE International Conference of IEEE Region 10, IEEE TENCON 2013 - Xi'an, Shaanxi, China
Duration: 22 Oct 201325 Oct 2013

Publication series

NameIEEE Region 10 Annual International Conference, Proceedings/TENCON
ISSN (Print)2159-3442
ISSN (Electronic)2159-3450

Conference

Conference2013 IEEE International Conference of IEEE Region 10, IEEE TENCON 2013
Country/TerritoryChina
CityXi'an, Shaanxi
Period22/10/1325/10/13

Keywords

  • Bro
  • Intrusion Detection System
  • Performance Evaluation
  • Snort
  • Suricata

Fingerprint

Dive into the research topics of 'Evaluation studies of three intrusion detection systems under various attacks and rule sets'. Together they form a unique fingerprint.

Cite this