The current threat landscape identifies Distributed Denial of Service (DDoS) attacks as one of the most critical hazards for network security. Given the constant variation in attack dynamics, enhancing existing detection techniques has become imperative. Indeed, traditional rule-based Security Information and Event Management (SIEM) systems often fall short in accurately detecting DDoS attacks, due to their evolving nature and complex traffic patterns. To overcome such limitations, Artificial Intelligence (AI) techniques for intrusion detection have garnered increasing attention in the realm of network security. In this paper, we introduce a hybrid approach that amalgamates rule-based SIEM systems with AI-based intrusion detection techniques. Specifically, we present a hybrid Network Intrusion Detection System (NIDS). The proposed approach is aimed at bolstering the security of monitored systems and applications by facilitating a more accurate detection of cyberattacks. We present and test a proof-of-concept architecture against DDoS attacks, yielding promising preliminary results.

Towards Hybrid NIDS: Combining Rule-Based SIEM with AI-Based Intrusion Detectors

Uccello, Federica;D'Antonio, Salvatore;
2024-01-01

Abstract

The current threat landscape identifies Distributed Denial of Service (DDoS) attacks as one of the most critical hazards for network security. Given the constant variation in attack dynamics, enhancing existing detection techniques has become imperative. Indeed, traditional rule-based Security Information and Event Management (SIEM) systems often fall short in accurately detecting DDoS attacks, due to their evolving nature and complex traffic patterns. To overcome such limitations, Artificial Intelligence (AI) techniques for intrusion detection have garnered increasing attention in the realm of network security. In this paper, we introduce a hybrid approach that amalgamates rule-based SIEM systems with AI-based intrusion detection techniques. Specifically, we present a hybrid Network Intrusion Detection System (NIDS). The proposed approach is aimed at bolstering the security of monitored systems and applications by facilitating a more accurate detection of cyberattacks. We present and test a proof-of-concept architecture against DDoS attacks, yielding promising preliminary results.
2024
9783031569494
9783031569500
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11367/168801
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 12
  • ???jsp.display-item.citation.isi??? ND
social impact