article
Enterprise networks are prime targets for intrusion attacks, yet the rapid evolution of the threat landscape complicates the development of effective network intrusion detection and prevention systems (NIDPSs). Among open-source solutions, Suricata and Snort have demonstrated lasting utility, but their reliance on signature-based rule sets limits their capacity for anomaly detection. This paper presents a novel approach designed to enhance the Suricata NIDPS by integrating machine learning to enable real-time anomaly detection and prevention. We virtualize Suricata and Squid (acting as a proxy server) within a GNS3-emulated network environment and use a malware dataset to train the anomaly detection model. We employed Python scripts to integrate the model into the system, and performance is compared before and after integration. Results are expected to demonstrate superior automated detection (both signature and anomaly-based) and improved intrusion prevention, positioning Suricata as a more robust solution for enterprise network security.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1109/nigercon62786.2024.10927387
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.