Publication:
Evaluation studies of three intrusion detection systems under various attacks and rule sets

dc.contributor.authorKittikhun Thongkanchornen_US
dc.contributor.authorSudsanguan Ngamsuriyarojen_US
dc.contributor.authorVasaka Visoottivisethen_US
dc.contributor.otherMahidol Universityen_US
dc.date.accessioned2018-10-19T04:50:32Z
dc.date.available2018-10-19T04:50:32Z
dc.date.issued2013-12-01en_US
dc.description.abstractThis paper investigates the performance and the detection accuracy of three popular open-source intrusion detection systems: Snort, Suricata and Bro. We evaluate all systems using various attack types including DoS attack, DNS attack, FTP attack, Scan port attack, and SNMP attack. The experiments were run under different traffic rates and different sets of active rules. The performance metrics used are the CPU utilization, the number of packets lost, and the number of alerts. The results illustrated that each attack type had significant effects on the IDS performance. But, Bro showed better performance than other IDS systems when evaluated under different attack types and using a specific set of rules. The results also indicated the drop of the accuracy when the three IDS tools activate the full rule set. © 2013 IEEE.en_US
dc.identifier.citationIEEE Region 10 Annual International Conference, Proceedings/TENCON. (2013)en_US
dc.identifier.doi10.1109/TENCON.2013.6718975en_US
dc.identifier.issn21593450en_US
dc.identifier.issn21593442en_US
dc.identifier.other2-s2.0-84894355725en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/31591
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=84894355725&origin=inwarden_US
dc.subjectComputer Scienceen_US
dc.subjectEngineeringen_US
dc.titleEvaluation studies of three intrusion detection systems under various attacks and rule setsen_US
dc.typeConference Paperen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=84894355725&origin=inwarden_US

Files

Collections