The paper presents hybrid anomaly detection preprocessor for SNORT IDS - Intrusion Detection System [1] base on statistical test and DWT - Discrete Wavelet Transform coefficient analysis. Preprocessor increases functionality of SNORT IDS system and has complementary properties. Possibility of detection network anomalies is increased by using two different algorithms. SNORT captures network traffic features which are used by ADS (Anomaly Detection System) preprocessor for detecting anomalies. Chi-square statistical test and DWT subband coefficients energy values are used for calculating of normal network traffic profiles. We evaluated proposed SNORT extension with the use of test network.
CITATION STYLE
Saganowski, Ł., & Andrysiak, T. (2012). Snort IDS Hybrid ADS Preprocessor. Ipc, 17(4), 17–22. https://doi.org/10.2478/v10248-012-0024-0
Mendeley helps you to discover research relevant for your work.