IMPROVING EFFECTIVENESS OF INTRUSION DETECTION SYSTEM BY INTEGRATING YARA AND SURICATA.
Intrusion detection system (IDS) are essential for safeguarding organizational resources; however, their practical deployment is often hindered by alert fatigue and the need for extensive rule configuration and tuning, which can reduce detection efficiency. YARA is a pattern-matching tool for detect...
| Publicado en: | Scientific Culture Vol. 12; no. 5 Part 1; pp. 858 - 871 |
|---|---|
| Autores principales: | , |
| Formato: | Artículo |
| Publicado: |
University of the Aegean
2026
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=193975236&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 193975236 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 24080071 I6HU jtl: Scientific Culture issn: 24080071 maglogo: N pubinfo: dt: 2026 vid: 12 iid: 5 Part 1 pid: 47715 pub: University of the Aegean artinfo: ui: 193975236 10.5281/zenodo.12511069 ppf: 858 ppct: 13 formats: tig: atl: IMPROVING EFFECTIVENESS OF INTRUSION DETECTION SYSTEM BY INTEGRATING YARA AND SURICATA. aug: au: Kadam, Vandana Verma, Rakesh affil: Research Scholar, Indian Institute of Management, Mumbai-400 087, India Professor, Indian Institute of Management, Mumbai-400 0087, India su: Intrusion detection systems (Computer security) Computer network security Internet security Malware sug: subj: Intrusion detection systems (Computer security) Computer network security Internet security Malware keyword: deployment of IDS false alerts intrusion detection Intrusion detection system (IDS) Suricata YARA ab: Intrusion detection system (IDS) are essential for safeguarding organizational resources; however, their practical deployment is often hindered by alert fatigue and the need for extensive rule configuration and tuning, which can reduce detection efficiency. YARA is a pattern-matching tool for detecting malware and intrusions indicators in cybersecurity contexts. This study investigates the integration of Suricata, an open-source IDS, with YARA to enhance intrusion detection performance. The implementation was conducted in a virtual environment and the integrated system was tested using live network traffic captured using Wireshark, a network monitoring tool. The results show that there is 20% reduction in the total number of alerts following the integration of Suricata and YARA rules, indicating a decrease in redundant or false alerts. These findings provide empirical evidence that IDS performance is strongly influenced by rule configuration and tuning strategies. The observed reduction in alerts confirms that YARA-based customization can improve IDS efficiency and mitigate alert-fatigue. The study highlights the potential of YARA--Suricata integration is an effective fine-tuning strategy and underscores its relevance for future research on automated rule optimization, false-positive reduction methods, and adaptive intrusion detection systems aimed at strengthening real-world cybersecurity operations. pubtype: Academic Journal doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2026 holdings: @attributes: islocal: N |
|---|