An Architecture of Hybrid Intrusion Detection System

DOI: 10.11591/ijins.v2i2.1753

Intrusion Detection System (IDS) is renowned and widely-deployed security tool to detect attacks and malicious activities in information system. It is an essential element of any contemporary information system. There are mainly two techniques for intrusion detection: i) signature-based (misuse) detection and ii) anomaly-based detection technique. Both the techniques have their advantages and disadvantages. This paper presents research from an ongoing study on the use of features of both the intrusion detection techniques to design a novel and efficient hybrid IDS. An architecture and implementation details of our hybrid IDS are presented. Furthermore, unique characteristics of our hybrid IDS are described. This paper concludes with future research directions and challenges in IDS.


