Innovative signature based intrusion detection system: Parallel processing and minimized database
Abdullah H. Almutairi, Nabih T. Abdelmajeed · 2017
Securing information systems these days in not an option rather than it is a must. The increasing number of attacks on networks and individual systems raised the need for a fast, light, and reliable Intrusion Detection System (IDS). There are two types of detection that an IDS uses: anomaly based detection and signature based detection. This paper focus on the signature based detection. Signature based IDS suffers from the huge number of signatures stored in its database. Some researchers provided the concept of frequent signature database to solve database size problem but never discussed how to deal with new signatures and the old signature that became unnecessary. This paper represents a proposed module that uses parallel processing with small databases with most frequent signatures and an updating agent. This module could be used for both Host based IDS and Network based IDS.