A Comparative Effectiveness Analysis of Signature-Based IDS and Network Detection and Response (NDR) in a SIEM Environment
DOI:
https://doi.org/10.58344/locus.v5i8.5976Keywords:
Behavioral Metadata, Encrypted Traffic Analysis, NDR, NIDS, Security Onion, Visibility GapAbstract
As cyber threats increasingly employ cryptographically concealed and stealthy communication, traditional signature-based Network Intrusion Detection Systems (NIDS) encounter severe limitations in achieving end-to-end operational visibility. This study delivers a quantitative comparative analysis contrasting signature-based frameworks against metadata-driven Network Detection and Response (NDR) within a unified Security Information and Event Management (SIEM) platform. Configured with a massive ruleset of 47,192 active signatures, the NIDS engine was evaluated against the behavioral metadata abstraction of NDR across five structured attack scenarios mapping the Cyber Kill Chain. Experimental results reveal a critical Visibility Gap in post-exploitation defenses; while NIDS achieved a 60\% Detection Rate by intercepting noisy initial reconnaissance and exploit payloads, it suffered total blindness during post-exploitation maneuvers. Conversely, the NDR engine achieved a 100\% Detection Rate, isolating deterministic forensic indicators including a 716.33-second encrypted command and control (C2) session and a 7.07 MB volumetric data exfiltration burst. Furthermore, architectural benchmarking revealed that massive rule compilation induced structural management plane synchronization failures. These findings synthesize into validated recommendations for sensor optimization, establishing an operational framework for specialized role allocation and computational efficiency to eliminate visibility blind spots within enterprise Security Operations Center (SOC) environments.
References
Barradas, D., Novo, C., Portela, B., Romeiro, S., & Santos, N. (2024). Extending C2 traffic detection methodologies: From TLS 1.2 to TLS 1.3-enabled malware. In Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses (pp. 181–196). ACM. https://doi.org/10.1145/3678890.3678921
Berger, S., et al. (2016). Closing the loop: Network and in-host monitoring tandem for comprehensive cloud security visibility. IBM Journal of Research and Development, 60(4), 10:1–10:12. https://doi.org/10.1147/JRD.2016.2571580
Bhardwaj, A., Bharany, S., Almogren, A., Rehman, A. U., & Hamam, H. (2024). Proactive threat hunting to detect persistent behaviour-based advanced adversaries. Egyptian Informatics Journal, 27, 100510.
Bhatia, G., & Almukhaini, G. (2024). Enhancing cyber attack detection: An analysis of Security Onion for small and midsize enterprise. In 2024 1st International Conference on Innovative Engineering Sciences and Technological Research (ICIESTR) (pp. 1–6). IEEE. https://doi.org/10.1109/ICIESTR60916.2024.10798271
Chung, M.-H., et al. (2023). Implementing data exfiltration defense in situ: A survey of countermeasures and human involvement. ACM Computing Surveys, 55(14s), 1–37. https://doi.org/10.1145/3582077
Hadi, H. J., Ahmad, N., Aziz, K., Cao, Y., & Alshara, M. A. (2024). Cost-effective resilience: A comprehensive survey and tutorial on assessing open-source cybersecurity tools for multi-tiered defense. IEEE Access, 12, 194053–194076. https://doi.org/10.1109/ACCESS.2024.3510533
Hajj, S., et al. (2023). Cross-layer federated learning for lightweight IoT intrusion detection systems. Sensors, 23(16), 7038. https://doi.org/10.3390/s23167038
Hore, S., Nguyen, Q. H., Xu, Y., Shah, A., Bastian, N. D., & Le, T. (2023). Empirical evaluation of autoencoder models for anomaly detection in packet-based NIDS. In 2023 IEEE Conference on Dependable and Secure Computing (DSC) (pp. 1–8). IEEE. https://doi.org/10.1109/DSC61021.2023.10354098
Hu, Q., Yu, S.-Y., & Asghar, M. R. (2020). Analysing performance issues of open-source intrusion detection systems in high-speed networks. Journal of Information Security and Applications, 51, 102426. https://doi.org/10.1016/j.jisa.2019.102426
Iglesias, F., & Zseby, T. (2015). Analysis of network traffic features for anomaly detection. Machine Learning, 101(1–3), 59–84. https://doi.org/10.1007/s10994-014-5473-9
Koumar, J., & ?ejka, T. (2022). Network traffic classification based on periodic behavior detection. In 2022 18th International Conference on Network and Service Management (CNSM) (pp. 359–363). IEEE. https://doi.org/10.23919/CNSM55787.2022.9964556
Koumar, J., Hynek, K., & ?ejka, T. (2023). Network traffic classification based on single flow time series analysis. In 2023 19th International Conference on Network and Service Management (CNSM) (pp. 1–7). IEEE. https://doi.org/10.23919/CNSM59352.2023.10327876
Majigi, M. U., Idris, I., Abdulhamid, S. M., & Ikuesan, R. A. (2025). Big data transfer service architecture for cloud data centers: Problems, methods, applications, and future trends. Discover Computing, 28(1), 163. https://doi.org/10.1007/s10791-025-09682-3
Mohammed, A., et al. (2022). Data security and protection: A mechanism for managing data theft and cybercrime in online platforms of educational institutions. In 2022 International Conference on Machine Learning, Big Data, Cloud and Parallel Computing (COM-IT-CON) (pp. 758–761). IEEE. https://doi.org/10.1109/COM-IT-CON54601.2022.9850702
Mocanu, F., & Scripcariu, L. (2023). Implementation of a security operation center—An essential cybersecurity solution for organizations. In 2023 27th International Conference on System Theory, Control and Computing (ICSTCC) (pp. 539–544). IEEE. https://doi.org/10.1109/ICSTCC59206.2023.10308432
Muttaqien, H., Niswar, M., Syarif, S., & Zainuddin, Z. (2025). Efficient identification of malicious traffic in TLS networks using machine learning. In 2025 IEEE International Conference on Artificial Intelligence and Mechatronics Systems (AIMS) (pp. 1–6). IEEE. https://doi.org/10.1109/AIMS66189.2025.11229622
Papadogiannaki, E., Tsirantonakis, G., & Ioannidis, S. (2022). Network intrusion detection in encrypted traffic. In 2022 IEEE Conference on Dependable and Secure Computing (DSC) (pp. 1–8). IEEE. https://doi.org/10.1109/DSC54232.2022.9888942
Piet, J., Anderson, B., & McGrew, D. (2018). An in-depth study of open-source command and control frameworks. In 2018 13th International Conference on Malicious and Unwanted Software (MALWARE) (pp. 1–8). IEEE. https://doi.org/10.1109/MALWARE.2018.8659361
Pranav, H., Suryaa, E., & Venugopalan, M. (2024). Comprehensive C2 analysis and anomaly detection in HTTP traffic: A MongoDB-based approach. In 2024 International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI) (pp. 1–6). IEEE. https://doi.org/10.1109/ACCAI61061.2024.10602244
Raharjo, D. H. K., Nurmala, A., Pambudi, R. D., & Sari, R. F. (2022). Performance evaluation of intrusion detection system performance for traffic anomaly detection based on active IP reputation rules. In 2022 3rd International Conference on Electrical Engineering and Informatics (ICon EEI) (pp. 75–79). IEEE. https://doi.org/10.1109/IConEEI55709.2022.9972298
Rabbani, M., et al. (2025). Device identification and anomaly detection in IoT environments. IEEE Internet of Things Journal, 12(10), 13625–13643. https://doi.org/10.1109/JIOT.2024.3522863
Sai, A. N. H. D., Tilak, B. H., Sanjith, N. S., Suhas, P., & Sanjeetha, R. (2022). Detection and mitigation of low and slow DDoS attack in an SDN environment. In 2022 International Conference on Distributed Computing, VLSI, Electrical Circuits and Robotics (DISCOVER) (pp. 106–111). IEEE. https://doi.org/10.1109/DISCOVER55800.2022.9974724
Salazar, L. A. G. (2026). Provenance analysis of advanced persistent threats in operational technology environments [Doctoral dissertation, The University of Texas at El Paso].
Waleed, A., Jamali, A. F., & Masood, A. (2022). Which open-source IDS? Snort, Suricata or Zeek. Computer Networks, 213, 109116. https://doi.org/10.1016/j.comnet.2022.109116
Zhang, H., et al. (2025). Explainable and transferable adversarial attack for ML-based network intrusion detectors. IEEE Transactions on Dependable and Secure Computing, 22(5), 5090–5107. https://doi.org/10.1109/TDSC.2025.3560486
Zhou, J., Fu, W., Hu, W., Sun, Z., He, T., & Zhang, Z. (2024). Challenges and advances in analyzing TLS 1.3-encrypted traffic: A comprehensive survey. Electronics, 13(20), 4000. https://doi.org/10.3390/electronics13204000
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Christian Hary, Muhammad Salman

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




