[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120176-en":3,"doc-seo-120176-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120176,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Collaborative Intrusion Detection System with Snort Machine Learning Plugin","Increasing cybercrime and cyber-attacks demand stronger network security measures, yet many Intrusion Detection Systems (IDS) rely on single-sensor or same-type approaches such as HIDS or NIDS, which limits detection coverage and reliability. This study proposes a collaborative IDS combining NIDS and HIDS to broaden intrusion detection scope, while mitigating elevated false positive and false negative alerts. Machine learning is integrated through Snort plugins and comparison methods to improve detection precision. Results show a 99% DoS detection rate and 98% Probe detection rate using an SVM on NSL-KDD, with real-time simulations accurately identifying DoS variants and improving SYN Flooding recognition beyond standard Snort community rules.","INTERNATIONAL JOURNAL ON INFORMATICS VISUALIZATION  \n[journal homepage : www.joiv.org/index.php/joiv](journal homepage : www.joiv.org/index.php/joiv)  \nCollaborative Intrusion Detection System with Snort Machine  \nLearning Plugin  \nDimas Febriyan Priambodo a,*, Achmad Husein Noor Faizib, Fika Dwi Rahmawatib, Septia Ulfa Sunaringtyasa, Jeckson Sidabutar a, Tiyas Yulita a  \na Cybersecurity Engineering, National Cyber and Crypto Polytechnic, Ciseeng, Bogor, Indonesia b National Cyber and Crypto Agency, Bojongsari., Depok, Indonesia  \nCorresponding author:*[dimas.febriyan@poltekssn.ac.id](dimas.febriyan@poltekssn.ac.id)  \nAbstract—The increasing prevalence of cybercrime and cyber-attacks underscores the imperative need for organizations to implement robust network security measures. Nevertheless, current Intrusion Detection Systems (IDS) often rely on single-sensor or multi-sensor in the same type of IDS, including Host-Based IDS (HIDS) or Network-Based IDS (NIDS), which inherently possess limited detection capabilities. To address this limitation, this research combines NIDS and HIDS components into a collaborative-IDS system, thus expanding the scope of intrusion detection and enhancing the efficacy of the established attack mitigation system. However, the integration of NIDS and HIDS introduces formidable challenges, notably the elevated rates of False Positive and False Negative alerts. To surmount these challenges, the researcher employs machine learning techniques in the form of Snort plugins and comparison methods to heighten the precision of attack detection. The obtained results unequivocally illustrate the effectiveness of this approach. Using a Support Vector Machine for static analysis of the NSL-KDD dataset attains an outstanding 99% detection rate for Denial of Service (DoS) attacks and an impressive 98% detection rate for Probe attacks. Furthermore, in dynamic real-time attack simulations, the machine learning plugins exhibit remarkable proficiency in detecting various types of DoS attacks, concurrently offering more comprehensive identification of SYN Flooding DoS attacks compared to the Snort community rules set. These findings signify a significant advancement in intrusion detection, paving the way for more robust and accurate network security systems in an era of escalating cyber threats.  \nKeywords—Artificial intelligence; machine learning; NIDS; HIDS; snort plugin.  \nManuscript received 5 Agt. 2023; revised 25 Dec. 2023; accepted 19 Jan. 2024. Date of publication 30 Sep. 2024.  \nInternational Journal on Informatics Visualization is licensed under a Creative Commons Attribution-Share Alike 4.0 International License.  \nI. INTRODUCTION  \nBased on its scope, intrusion detection is divided into the Network-Based Intrusion Detection System (NIDS) and the Host-Based Intrusion Detection System (HIDS) . The NIDS is designed to observe the traffic within specific network segments or devices and analyze network protocols, transport, and applications. Its primary purpose is to detect abnormal or suspicious activity within the targeted network segments or devices. HIDS operates by monitoring the attributes ofa host system and capturing events transpiring within it to identify any potentially suspicious or anomalous activity [1] .  \nIn supervised machine learning, a dataset is necessary to train and test the built attack mitigation system to achieve detection accuracy. This study focuses explicitly on DoS attack data and attack probes. Consequently, the NSL-KDD Dataset is chosen for this research due to its inclusion of  \nlabeled data comprising both training and test data, making ita complex dataset [2]. This aligns with the trends outlined by [3], employs the second most widely used dataset. Flask is used to predict the dataset and visualize system packet detection results. After Flask successfully predicts the dataset, researchers use Flask to become the main page for predictions of real-time network traffic that has bee","cbCaicaSPG8aGsWt","https://ap.wps.com/l/cbCaicaSPG8aGsWt","pdf",3835103,1,9,"English","en",105,"# Introduction\n## Intrusion detection overview (NIDS vs HIDS)\n## Dataset and attack focus (NSL-KDD, DoS and probe)\n## Related work on Snort, Suricata, and other IDS research","[{\"question\":\"What problem does the collaborative IDS address compared with traditional NIDS or HIDS?\",\"answer\":\"Traditional IDS often uses a single sensor type or same-type multi-sensor setup, limiting detection ability. The collaborative approach combines NIDS and HIDS to expand detection scope while improving mitigation effectiveness.\"},{\"question\":\"How does machine learning improve detection accuracy in this study?\",\"answer\":\"Machine learning is implemented via Snort plugins and comparison methods to increase attack detection precision and reduce false positive and false negative alerts.\"},{\"question\":\"What detection performance is reported using the SVM model on the NSL-KDD dataset?\",\"answer\":\"The approach achieves 99% detection rate for Denial of Service (DoS) attacks and 98% detection rate for Probe attacks using Support Vector Machine for static analysis.\"}]","Collaborative Intrusion Detection System with Snort Machine Learning Plugin | PDF",1785728564,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"collaborative-intrusion-detection-system-with-snort-machine-learning-plugin","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/collaborative-intrusion-detection-system-with-snort-machine-learning-plugin/120176/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the collaborative IDS address compared with traditional NIDS or HIDS?","Question",{"text":75,"@type":76},"Traditional IDS often uses a single sensor type or same-type multi-sensor setup, limiting detection ability. The collaborative approach combines NIDS and HIDS to expand detection scope while improving mitigation effectiveness.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does machine learning improve detection accuracy in this study?",{"text":80,"@type":76},"Machine learning is implemented via Snort plugins and comparison methods to increase attack detection precision and reduce false positive and false negative alerts.",{"name":82,"@type":73,"acceptedAnswer":83},"What detection performance is reported using the SVM model on the NSL-KDD dataset?",{"text":84,"@type":76},"The approach achieves 99% detection rate for Denial of Service (DoS) attacks and 98% detection rate for Probe attacks using Support Vector Machine for static analysis.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]