2020•Unpublished venueRequires access

A Logical Combination Based Application Layer Intrusion Detection Model

Hao Henry Wang, Jian Kang Yang, Yueming Lu

Open publisher page 2 citations

Abstract

In enterprise network attack intrusion detection system, false positives and false negatives are the opposite of each other, and it is difficult to achieve both, so reducing false positives rate and false negatives rate is one of the core problems of IDS. Snort and Suricata adopts misuse detection mode, which has low calculation cost and high accuracy, but it has a high false negatives rate and cannot detect unknown attacks. The anomaly detection system based on machine learning and data mining has a high detection rate for unknown attacks, but a high false positives rate.

About this research paper

What this paper is about

In enterprise network attack intrusion detection system, false positives and false negatives are the opposite of each other, and it is difficult to achieve both, so reducing false positives rate and false negatives rate is one of the core problems of IDS. Snort and Suricata adopts misuse detection mode, which has low calculation cost and high accuracy, but it has a high false negatives rate and cannot detect unknown attacks. The anomaly detection system based on machine learning and data mining has a high detection rate for unknown attacks, but a high false positives rate.

Why it matters

OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In enterprise network attack intrusion detection system, false positives and false negatives are the opposite of each other, and it is difficult to achieve both, so reducing false positives rate and false negatives rate is one of the core problems of IDS. Snort and Suricata adopts misuse detection mode, which has low calculation cost and high accuracy, but it has a high false negatives rate and cannot detect unknown attacks. The anomaly detection system based on machine learning and data mining has a high detection rate for unknown attacks, but a high false positives rate.

Key concepts: False positive paradox, Intrusion detection system, False positives and false negatives, False positive rate, Computer science, True positive rate, Anomaly detection, Anomaly-based intrusion detection system

Related papers

Back to paper searchBrowse research topicsOriginal source
A Logical Combination Based Application Layer Intrusion Detection Model — Research Paper | ScholarLens