A Novel Approach for Anomaly Detection using Snort Integrated with Machine Learning
Thakkalapally Preethi, Ponnuru Rakshitha Reddy, Lekkala Likhitha, P. Pavan Kumar, Abhinav Kamani · 2024
In today’s digital world, it is crucial to keep a company’s information safe from cyber threats. With new and more sophisticated network attacks emerging all the time, better security measures and ways to monitor our networks are needed. Intrusion Detection Systems (IDS) can act as digital guards to help protect our networks from these malicious threats. Snort is a widely used open-source IDS, but it can struggle with the ever-changing nature of these threats. Our research focuses on enhancing Snort’s capabilities by integrating it with ML algorithms such as Random Forest, Decision Tree, Support Vector Machine (SVM), K-Nearest Neighbours (KNN), and Naive Bayes. We also conducted subset testing using the NSL-KDD dataset. Our results indicate that combining these ML algorithms with Snort can improve our ability to detect and stop malicious network activities. This research can be helpful for anyone interested in developing smarter and more effective intrusion detection systems.