A Comparative Analysis of Signature-Based and Anomaly-Based Intrusion Detection Systems
Authors
Vasudev Karthik Ravindran
Senior Software Development Engineer, Amazon, Seattle, WA, USA (IN)
Sharad Shyam Ojha
Software Development Manager, Amazon, Austin, United States (IN)
Arvind Kamboj
Department of Computer Science & Engineering, Shivalik College of Engineering, Dehradun (IN)
Article Information
DOI: 10.51583/IJLTEMAS.2025.140500026
Subject Category: Threat Detection
Volume/Issue: 14/5 | Page No: 209-214
Publication Timeline
Submitted: 2025-06-03
Published: 2025-06-03
Abstract
Abstract: This paper presents a comprehensive comparative analysis of Signature-Based and Anomaly-Based Intrusion Detection Systems (IDS) using key performance metrics such as detection accuracy, false positive rate, adaptability to new threats, computational overhead, maintenance effort, scalability, and real-time performance. By examining these metrics, the study highlights the strengths and limitations of each IDS approach in handling both known and emerging cybersecurity threats. Signature-Based IDS demonstrates high accuracy and low false positives but struggles with adaptability and maintenance demands, while Anomaly-Based IDS offers better adaptability and threat detection versatility at the cost of increased false positives and resource consumption. The analysis emphasizes that an optimal IDS solution should consider the specific security needs and operational context of the deployment environment. The findings suggest that a hybrid approach, leveraging the complementary advantages of both techniques, can provide a more robust and resilient defense against the growing complexity of cyberattacks in modern networks.
Keywords
Intrusion Detection Systems, Signature-Based IDS, Anomaly-Based IDS, Cybersecurity, Threat Detection
Downloads
References
1. Axelsson, S. (2000). Intrusion detection systems: A survey and taxonomy. Technical Report, Department of Computer Engineering, Chalmers University of Technology. [Google Scholar] [Crossref]
2. Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, SE-13(2), 222–232. [https://doi.org/10.1109/TSE.1987.232894] (https://doi.org/10.1109/TSE.1987.232894) [Google Scholar] [Crossref]
3. Liao, H. J., Lin, C. H. R., Lin, Y. C., & Tung, K. Y. (2013). Intrusion detection system: A comprehensive review. Journal of Network and Computer Applications, 36(1), 16–24. [https://doi.org/10.1016/j.jnca.2012.09.004] (https://doi.org/10.1016/j.jnca.2012.09.004) [Google Scholar] [Crossref]
4. Scarfone, K., & Mell, P. (2007). Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800-94. National Institute of Standards and Technology. [Google Scholar] [Crossref]
5. Patcha, A., & Park, J. M. (2007). An overview of anomaly detection techniques: Existing solutions and latest technological trends. Computer Networks, 51(12), 3448–3470. [https://doi.org/10.1016/j.comnet.2006.09.001] (https://doi.org/10.1016/j.comnet.2006.09.001) [Google Scholar] [Crossref]
6. Modi, C., Patel, D., Borisaniya, B., Patel, A., & Rajarajan, M. (2013). A survey of intrusion detection techniques in cloud. Journal of Network and Computer Applications, 36(1), 42–57. [https://doi.org/10.1016/j.jnca.2012.05.003] (https://doi.org/10.1016/j.jnca.2012.05.003) [Google Scholar] [Crossref]
7. Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. [https://doi.org/10.1109/COMST.2015.2494502] (https://doi.org/10.1109/COMST.2015.2494502) [Google Scholar] [Crossref]
8. Garcia-Teodoro, P., Diaz-Verdejo, J., Maciá-Fernández, G., & Vázquez, E. (2009). Anomaly-based network intrusion detection: Techniques, systems and challenges. Computers & Security, 28(1–2), 18–28. [https://doi.org/10.1016/j.cose.2008.08.003] (https://doi.org/10.1016/j.cose.2008.08.003) [Google Scholar] [Crossref]
9. Roesch, M. (1999). Snort - Lightweight Intrusion Detection for Networks. Proceedings of the 13th USENIX Conference on System Administration, 229–238. [Google Scholar] [Crossref]
10. Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. 2010 IEEE Symposium on Security and Privacy, 305–316. [https://doi.org/10.1109/SP.2010.25] (https://doi.org/10.1109/SP.2010.25) [Google Scholar] [Crossref]
11. Tsai, C. F., Hsu, Y. F., Lin, C. Y., & Lin, W. Y. (2009). Intrusion detection by machine learning: A review. Expert Systems with Applications, 36(10), 11994–12000. [https://doi.org/10.1016/j.eswa.2009.05.029] (https://doi.org/10.1016/j.eswa.2009.05.029) [Google Scholar] [Crossref]
12. Ahmed, M., Mahmood, A. N., & Hu, J. (2016). A survey of network anomaly detection techniques. Journal of Network and Computer Applications, 60, 19–31. [https://doi.org/10.1016/j.jnca.2015.11.016] (https://doi.org/10.1016/j.jnca.2015.11.016) [Google Scholar] [Crossref]
13. Debar, H., Dacier, M., & Wespi, A. (2000). A revised taxonomy for intrusion-detection systems. Annales des Télécommunications, 55(7–8), 361–378. [https://doi.org/10.1007/BF02994709] (https://doi.org/10.1007/BF02994709) [Google Scholar] [Crossref]
14. Lee, W., & Stolfo, S. J. (1998). Data mining approaches for intrusion detection. Proceedings of the 7th USENIX Security Symposium, 79–93. [Google Scholar] [Crossref]
15. Kim, G., Lee, S., & Kim, S. (2014). A novel hybrid intrusion detection method integrating anomaly detection with misuse detection. Expert Systems with Applications, 41(4), 1690–1700. [https://doi.org/10.1016/j.eswa.2013.08.066] (https://doi.org/10.1016/j.eswa.2013.08.066) [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Wind Turbine Design for Low Wind Speed Applications: Advancing Renewable Energy Systems Through Wind Tunnel Experiments
- Fast Identification for Evidences in Crime Scene with Macroscopic Properties and Portable Techniques
- Evaluating the Impact of Hello Interval Timer on OSPF Performance for Real-Time Applications Using OPNET
- The Algorithmic Fortress: Ai-Powered Cybersecurity and Anti-Fraud in The Future of Fintech
- Accident Detection on Curved Roads Using Infrared Sensors in Hilly Regions A Case of Chadoora Tehsil, Badgam (J&K)