MARATTO

article

Improving Open-Source Network Security Tooling for the Corporate Enterprise

Abstract

Enterprise networks are prime targets for intrusion attacks, yet the rapid evolution of the threat landscape complicates the development of effective network intrusion detection and prevention systems (NIDPSs). Among open-source solutions, Suricata and Snort have demonstrated lasting utility, but their reliance on signature-based rule sets limits their capacity for anomaly detection. This paper presents a novel approach designed to enhance the Suricata NIDPS by integrating machine learning to enable real-time anomaly detection and prevention. We virtualize Suricata and Squid (acting as a proxy server) within a GNS3-emulated network environment and use a malware dataset to train the anomaly detection model. We employed Python scripts to integrate the model into the system, and performance is compared before and after integration. Results are expected to demonstrate superior automated detection (both signature and anomaly-based) and improved intrusion prevention, positioning Suricata as a more robust solution for enterprise network security.

Research topics

  • Advanced Research in Systems and Signal Processing
  • Cybersecurity and Information Systems
  • Information and Cyber Security

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/nigercon62786.2024.10927387

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.