Pre-decision Detection Engine for Signature-Based Network Intrusion Detection System

LONG Xiao-fei,FENG Yan,WANG Rui-jie
DOI: https://doi.org/10.3785/j.issn.1008-973x.2006.10.009
2006-01-01
Abstract:A pre-decision detection engine to mitigate false positives generated by signature-based network intrusion detection system and improve the performance of processing packets was proposed.By utilizing hosts'software information on monitored network,predecision detection engine makes a decision before pattern match to filter out unnecessary rules,which minimizes average pattern-match times for each packet,and reduces false positives and improves performance as a result.Experimental results showed that pre-decision detection engine can decrease false positives and improve the performance of processing packets,without increasing the false negative rate.
What problem does this paper attempt to address?