Skip to content

Signature-Based IDS

Definition

An intrusion detection system that compares network traffic against a database of known attack patterns (signatures). Snort and Suricata are the dominant open-source implementations. High precision on known attacks; blind to novel techniques.

Detection method
Compares traffic against a database of known attack patterns
Common tools
Snort, Suricata
Strength
High precision on known, previously catalogued attacks
Weakness
Blind to novel or previously unseen attack techniques

Common questions

Why do organisations still use signature-based IDS given its blindness to new attacks?+

It produces very few false positives on known threats and is computationally cheap compared to anomaly-based detection, so it remains effective at catching the large volume of commodity, already-catalogued attacks efficiently, freeing anomaly-based or behavioural detection resources to focus on the harder, novel-attack problem.

How does a signature-based IDS log entry help a forensic investigator reconstruct an intrusion timeline?+

Each triggered signature alert typically includes a timestamp, source and destination IP, and the specific pattern matched, letting an investigator correlate the alert with a known attack technique or tool and place it precisely within the broader sequence of events reconstructed from other logs.

Related terms

Anomaly-Based IDS
An intrusion detection system that models normal traffic behaviour and alerts when observed traffic deviates significantly from that baseline. Detects novel attacks...
Five-Tuple
The five fields that uniquely identify a network flow: source IP address, source port, destination IP address, destination port, and transport protocol...
Lateral Movement
Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
Proxy Log
A record generated by a forward proxy server for each HTTP or HTTPS request made by an internal client. Contains the URL,...
True Positive / False Positive
A true positive is an alert that correctly identifies malicious activity. A false positive is an alert that fires on legitimate traffic....

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.