A Logical Combination Based Application Layer Intrusion Detection Model
Hao Henry Wang, Jian Kang Yang, Yueming Lu
Abstract
Hao Henry Wang, Jian Kang Yang, Yueming Lu
Abstract
In enterprise network attack intrusion detection system, false positives and false negatives are the opposite of each other, and it is difficult to achieve both, so reducing false positives rate and false negatives rate is one of the core problems of IDS. Snort and Suricata adopts misuse detection mode, which has low calculation cost and high accuracy, but it has a high false negatives rate and cannot detect unknown attacks. The anomaly detection system based on machine learning and data mining has a high detection rate for unknown attacks, but a high false positives rate.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In enterprise network attack intrusion detection system, false positives and false negatives are the opposite of each other, and it is difficult to achieve both, so reducing false positives rate and false negatives rate is one of the core problems of IDS. Snort and Suricata adopts misuse detection mode, which has low calculation cost and high accuracy, but it has a high false negatives rate and cannot detect unknown attacks. The anomaly detection system based on machine learning and data mining has a high detection rate for unknown attacks, but a high false positives rate.
Key concepts: False positive paradox, Intrusion detection system, False positives and false negatives, False positive rate, Computer science, True positive rate, Anomaly detection, Anomaly-based intrusion detection system