Comparison of Different Intrusion Detection and Prevention Systems
Chintan Kacha, Kirtee A. Shevade · 2012
Abstract—Intrusion Detection Systems (IDS’s) try to detect network anomalies and maintain the secure state of network hosts. They have a long history but even nowadays their efficiency is not 100 % and correlates proportionally to the number of detected false positives. Nevertheless, IDS’s are considered useful especially when new community hacking tools are emerging. This allows for greater number of users to experiment with modern exploits and increases the average security risk of every online system. Snort, the de-facto industry standard open-source solution, is a mature product that has been available for over a decade. Suricata offers a new approach to signature-based intrusion detection and takes advantage of current technology such as process multi-threading to improve processing speed. This paper evaluates two rule-based open sourced network intrusion detection systems – Snort and Suricata. We ran each product on a multi-core computer and evaluated the speed, memory requirements, and accuracy of the detection engines in a variety of experiments.