English

Analyzing Root Causes of Intrusion Detection False-Negatives: Methodology and Case Study

Cryptography and Security 2019-09-20 v1

Abstract

Intrusion Detection Systems (IDSs) are a necessary cyber defense mechanism. Unfortunately, their capability has fallen behind that of attackers. This motivates us to improve our understanding of the root causes of their false-negatives. In this paper we make a first step towards the ultimate goal of drawing useful insights and principles that can guide the design of next-generation IDSs. Specifically, we propose a methodology for analyzing the root causes of IDS false-negatives and conduct a case study based on Snort and a real-world dataset of cyber attacks. The case study allows us to draw useful insights.

Keywords

Cite

@article{arxiv.1909.08725,
  title  = {Analyzing Root Causes of Intrusion Detection False-Negatives: Methodology and Case Study},
  author = {Eric Ficke and Kristin M. Schweitzer and Raymond M. Bateman and Shouhuai Xu},
  journal= {arXiv preprint arXiv:1909.08725},
  year   = {2019}
}

Comments

6 pages

R2 v1 2026-06-23T11:19:44.600Z