MARATTO

article

Hybrid NIDS Architecture Leveraging Suricata, Zeek and the ELK Stack

Abstract

Network protection has become a cardinal priority in organizations due to the growing sophistication of cyber threats. We implement a Network Intrusion Detection System by showing how three open-source tools can be used: Suricata performs deep packet inspection and uses signaturebased threat detection, Zeek (formerly Bro) provides advanced network traffic analysis and logging, and Elastic Stack (Filebeat, Elasticsearch, Kibana) allows real-time data indexing, search, and interactive visualization. For comprehensive threat detection, our integrated solution uses the Suricata rule-based engine with the behavioral analysis provided by Zeek. We offer centralized monitoring using the scalable log management of Elastic Stack and the Kibana dashboards. Thus, this contribution achieves enterprise-grade network visibility without vendor lock-in and is specifically suitable for organizations operating on a limited security budget. Future improvements will be related to machine learning integration for anomaly detection, and support for encrypted traffic analysis will be extended.

Research topics

  • Network Security and Intrusion Detection
  • Software System Performance and Reliability
  • Internet Traffic Analysis and Secure E-voting

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/sita67914.2025.11273397

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.