Signature-Based IDS
Definition
An intrusion detection system that compares network traffic against a database of known attack patterns (signatures). Snort and Suricata are the dominant open-source implementations. High precision on known attacks; blind to novel techniques.
- Detection method
- Compares traffic against a database of known attack patterns
- Common tools
- Snort, Suricata
- Strength
- High precision on known, previously catalogued attacks
- Weakness
- Blind to novel or previously unseen attack techniques
Common questions
Why do organisations still use signature-based IDS given its blindness to new attacks?+
It produces very few false positives on known threats and is computationally cheap compared to anomaly-based detection, so it remains effective at catching the large volume of commodity, already-catalogued attacks efficiently, freeing anomaly-based or behavioural detection resources to focus on the harder, novel-attack problem.
How does a signature-based IDS log entry help a forensic investigator reconstruct an intrusion timeline?+
Each triggered signature alert typically includes a timestamp, source and destination IP, and the specific pattern matched, letting an investigator correlate the alert with a known attack technique or tool and place it precisely within the broader sequence of events reconstructed from other logs.
Related terms
- Anomaly-Based IDS
- An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
- Five-Tuple
- The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Proxy Log
- A record generated by a forward proxy server for each HTTP or HTTPS request made by an internal client. Contains the URL,...
- True Positive / False Positive
- A true positive is an alert that correctly identifies malicious activity. A false positive is an alert that fires on legitimate traffic....