Towards Hybrid NIDS: Combining Rule-Based SIEM with AI-Based Intrusion Detectors
摘要
The current threat landscape identifies Distributed Denial of Service (DDoS) attacks as one of the most critical hazards for network security. Given the constant variation in attack dynamics, enhancing existing detection techniques has become imperative. Indeed, traditional rule-based Security Information and Event Management (SIEM) systems often fall short in accurately detecting DDoS attacks, due to their evolving nature and complex traffic patterns. To overcome such limitations, Artificial Intelligence (AI) techniques for intrusion detection have garnered increasing attention in the realm of network security. In this paper, we introduce a hybrid approach that amalgamates rule-based SIEM systems with AI-based intrusion detection techniques. Specifically, we present a hybrid Network Intrusion Detection System (NIDS). The proposed approach is aimed at bolstering the security of monitored systems and applications by facilitating a more accurate detection of cyberattacks. We present and test a proof-of-concept architecture against DDoS attacks, yielding promising preliminary results.