A Logical Combination Based Application Layer Intrusion Detection Model
作者
Hao Wang,Jian Yang,Yueming Lu
标识
DOI:10.1145/3444370.3444590
摘要
In enterprise network attack intrusion detection system, false positives and false negatives are the opposite of each other, and it is difficult to achieve both, so reducing false positives rate and false negatives rate is one of the core problems of IDS. Snort and Suricata adopts misuse detection mode, which has low calculation cost and high accuracy, but it has a high false negatives rate and cannot detect unknown attacks. The anomaly detection system based on machine learning and data mining has a high detection rate for unknown attacks, but a high false positives rate.