Implicit Malpractice and Suspicious Traffic Detection in Large Scale IP Networks
Timo T. Seppälä, Teemu Alapaholuoma, Olli Knuuti, Jorma Ylinen, Pekka Loula, Kimmo Hätönen · 2010
Large-scale IP networks present special challenges to security. Such networks consist of a large number of devices with a vast variety of traffic behavior. Finding a suitable line-up for the intrusion detection and monitoring mechanism is challenging. In this paper, we study the Snort and Bro-IDS systems. We have built a test platform, where we put those two detection systems side by side and compare them in a real IP network. All the results presented in this paper are under protection of end user privacy and anonymity.