错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Towards Hybrid NIDS: Combining Rule-Based SIEM with AI-Based Intrusion Detectors

  • Federica Uccello,
  • Marek Pawlicki,
  • Salvatore D’Antonio,
  • Rafał Kozik,
  • Michał Choraś

摘要

The current threat landscape identifies Distributed Denial of Service (DDoS) attacks as one of the most critical hazards for network security. Given the constant variation in attack dynamics, enhancing existing detection techniques has become imperative. Indeed, traditional rule-based Security Information and Event Management (SIEM) systems often fall short in accurately detecting DDoS attacks, due to their evolving nature and complex traffic patterns. To overcome such limitations, Artificial Intelligence (AI) techniques for intrusion detection have garnered increasing attention in the realm of network security. In this paper, we introduce a hybrid approach that amalgamates rule-based SIEM systems with AI-based intrusion detection techniques. Specifically, we present a hybrid Network Intrusion Detection System (NIDS). The proposed approach is aimed at bolstering the security of monitored systems and applications by facilitating a more accurate detection of cyberattacks. We present and test a proof-of-concept architecture against DDoS attacks, yielding promising preliminary results.