• Home
  • Search
  • Evaluating Snort Alerts as a Classification Features Set
  • Cite Icon2
  • https://doi.org/10.1007/978-981-33-4604-8_62Copy DOI Icon

Evaluating Snort Alerts as a Classification Features Set

  • Jan 1, 2021
  • Anas I Al Suwailem +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Nowadays, cyber-attacks are beginning to be smart and hard to be detected, these attacks can be classified as Advance Persistence Threat(APT), which are hard to be detected and need sophisticated mechanisms of cybersecurity detection systems to be implemented to detect these types of attacks. Snort is an Intrusion Detection System (IDS) open source application that gained a high level of trust from hundreds of companies by using it as an IDS sensor whether Host-based Intrusion Detection System (HIDS) or Network Intrusion Detection System (NIDS) mode. Snort is depending on rules that are predefined to detect known attacks where if there is a new attack released and have not been registered to CheckPoint as an attack, then Snort will not detect it as an attack and the attack will bypass. The main problem that stands with traditional IDS (Snort) is the rate of false positive alerts. A new technique has been revealed by understanding the behavior of the traffic flow and deciding if the traffic flow matches the attributes that have abnormal activities that the traditional misuse IDS cannot detect. The new technique is a machine learning process that depending on training and testing the data of the traffic after converting the PCAP file to CSV file through an application that calls CICFlowMeter. it is an open source machine learning application that used as GUI mode calls Weka. After the PCAP file converted through CICFlowMeter, a dataset end with CSV extension will be generated with 80 plus attributes that Weka will learn as the training phase after that the testing phase will determine the matched traffic if they are normal or abnormal.

Similar Papers
  • Book Chapter
  • Citations3

Research of Snort Rule Extension and APT Detection Based on APT Network Behavior Analysis

  • Jan 01, 2019
  • Yan Cui +4
  • Research Article
  • Citations1

A NOVEL APPROACH FOR ADDRESSING IOT NETWORKS VULNERABILITIES IN DETECTION AND CLASSIFICATION OF DOS/DDOS ATTACKS

  • Oct 02, 2024
  • International Journal of Software Engineering and Computer Systems
  • Aisha Ibrahim Gide +1
  • Research Article
  • Citations48

A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity.

  • Jan 28, 2025
  • Frontiers in artificial intelligence
  • Vincent Zibi Mohale +1
  • Conference Article
  • Citations6

Network security intrusion detection system based on incremental improved convolutional neural network model

  • Oct 01, 2016
  • Chao Deng +1
  • Conference Article
  • Citations5

Towards Analysis of the Performance of IDSs in Software-Defined Networks

  • Oct 01, 2022
  • Nadia Niknami +2
  • Research Article
  • Citations2

Collaborative Intrusion Detection System with Snort Machine Learning Plugin

  • Sep 30, 2024
  • JOIV : International Journal on Informatics Visualization
  • Dimas Febriyan Priambodo +5
  • Research Article

Development of algorithms for early detection of cyberattacks on networks using machine learning

  • Dec 12, 2024
  • Communication, informatization and cybersecurity systems and technologies
  • I Maltseva +2
  • Research Article
  • Citations1

Bijective Network-to-Image Encoding for Interpretable CNN-Based Intrusion Detection System

  • Sep 25, 2025
  • Network
  • Omesh A Fernando +2
  • PDF
  • Research Article
  • Citations8

LDES: detector design for version number attack detection using linear temporal logic based on discrete event system

  • Mar 17, 2023
  • International Journal of Information Security
  • Abhay Deep Seth +2
  • Research Article
  • Citations22

An Artificial Neural Network Technique for Prediction of Cyber-Attack using Intrusion Detection System

  • Feb 24, 2023
  • Journal of Artificial Intelligence, Machine Learning and Neural Network
  • Jay Kumar Jain +1
  • Research Article

Enhancing Performance Using New Hybrid Intrusion Detection System

  • Aug 12, 2022
  • Journal of Management and Informatics
  • Candra Supriadi +4
  • Conference Article
  • Citations71

Anomaly detection in Network Traffic Using Unsupervised Machine learning Approach

  • Jun 01, 2020
  • Aditya Vikram +1
  • PDF
  • Research Article
  • Citations40

Federated Learning for Privacy-Preserving Intrusion Detection in Software-Defined Networks

  • Jan 01, 2024
  • IEEE Access
  • Mubashar Raza +3
  • Research Article
  • Citations252

A Novel Ensemble of Hybrid Intrusion Detection System for Detecting Internet of Things Attacks

  • Oct 23, 2019
  • Electronics
  • Ansam Khraisat +4
  • Conference Article
  • Citations6

Deploying agents in the network to detect intrusions

  • Jun 01, 2015
  • Shankar M Banik +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.