A Comparison of a Machine Learning-Based Intrusion Detection System and Signature-Based Systems
Aleksandr Igorevich Getman, Maxim Nikolaevich Goryunov, Andrey Georgievich Matskevich, Dmitry Aleksandrovich Rybolovlev · Proceedings of the Institute for System Programming of RAS · 2022
The paper discusses the approach to the comparison of intrusion detection systems (IDS) that is based on several independent scenarios and comprehensive testing. This approach enabled to identify the advantages and disadvantages of the IDS based on machine learning methods (ML IDS), to identify the conditions under which ML IDS is able to outperform signature-based systems in terms of detection quality, to assess the practical applicability of ML IDS. The developed scenarios enabled to model the realization of both known attacks and a zero-day exploit. The conclusion is made about the advantage of ML IDS in the detection of previously unknown attacks and the feasibility of the construction of hybrid detection systems that combine the potential of signature-based and heuristic methods of analysis.