A Comparative Effectiveness Analysis of Signature-Based IDS and Network Detection and Response (NDR) in a SIEM Environment

Authors

  • Christian Hary Universitas Indonesia
  • Muhammad Salman Universitas Indonesia

DOI:

https://doi.org/10.58344/locus.v5i8.5976

Keywords:

Behavioral Metadata, Encrypted Traffic Analysis, NDR, NIDS, Security Onion, Visibility Gap

Abstract

As cyber threats increasingly employ cryptographically concealed and stealthy communication, traditional signature-based Network Intrusion Detection Systems (NIDS) encounter severe limitations in achieving end-to-end operational visibility. This study delivers a quantitative comparative analysis contrasting signature-based frameworks against metadata-driven Network Detection and Response (NDR) within a unified Security Information and Event Management (SIEM) platform. Configured with a massive ruleset of 47,192 active signatures, the NIDS engine was evaluated against the behavioral metadata abstraction of NDR across five structured attack scenarios mapping the Cyber Kill Chain. Experimental results reveal a critical Visibility Gap in post-exploitation defenses; while NIDS achieved a 60\% Detection Rate by intercepting noisy initial reconnaissance and exploit payloads, it suffered total blindness during post-exploitation maneuvers. Conversely, the NDR engine achieved a 100\% Detection Rate, isolating deterministic forensic indicators including a 716.33-second encrypted command and control (C2) session and a 7.07 MB volumetric data exfiltration burst. Furthermore, architectural benchmarking revealed that massive rule compilation induced structural management plane synchronization failures. These findings synthesize into validated recommendations for sensor optimization, establishing an operational framework for specialized role allocation and computational efficiency to eliminate visibility blind spots within enterprise Security Operations Center (SOC) environments.

References

Barradas, D., Novo, C., Portela, B., Romeiro, S., & Santos, N. (2024). Extending C2 traffic detection methodologies: From TLS 1.2 to TLS 1.3-enabled malware. In Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses (pp. 181–196). ACM. https://doi.org/10.1145/3678890.3678921

Berger, S., et al. (2016). Closing the loop: Network and in-host monitoring tandem for comprehensive cloud security visibility. IBM Journal of Research and Development, 60(4), 10:1–10:12. https://doi.org/10.1147/JRD.2016.2571580

Bhardwaj, A., Bharany, S., Almogren, A., Rehman, A. U., & Hamam, H. (2024). Proactive threat hunting to detect persistent behaviour-based advanced adversaries. Egyptian Informatics Journal, 27, 100510.

Bhatia, G., & Almukhaini, G. (2024). Enhancing cyber attack detection: An analysis of Security Onion for small and midsize enterprise. In 2024 1st International Conference on Innovative Engineering Sciences and Technological Research (ICIESTR) (pp. 1–6). IEEE. https://doi.org/10.1109/ICIESTR60916.2024.10798271

Chung, M.-H., et al. (2023). Implementing data exfiltration defense in situ: A survey of countermeasures and human involvement. ACM Computing Surveys, 55(14s), 1–37. https://doi.org/10.1145/3582077

Hadi, H. J., Ahmad, N., Aziz, K., Cao, Y., & Alshara, M. A. (2024). Cost-effective resilience: A comprehensive survey and tutorial on assessing open-source cybersecurity tools for multi-tiered defense. IEEE Access, 12, 194053–194076. https://doi.org/10.1109/ACCESS.2024.3510533

Hajj, S., et al. (2023). Cross-layer federated learning for lightweight IoT intrusion detection systems. Sensors, 23(16), 7038. https://doi.org/10.3390/s23167038

Hore, S., Nguyen, Q. H., Xu, Y., Shah, A., Bastian, N. D., & Le, T. (2023). Empirical evaluation of autoencoder models for anomaly detection in packet-based NIDS. In 2023 IEEE Conference on Dependable and Secure Computing (DSC) (pp. 1–8). IEEE. https://doi.org/10.1109/DSC61021.2023.10354098

Hu, Q., Yu, S.-Y., & Asghar, M. R. (2020). Analysing performance issues of open-source intrusion detection systems in high-speed networks. Journal of Information Security and Applications, 51, 102426. https://doi.org/10.1016/j.jisa.2019.102426

Iglesias, F., & Zseby, T. (2015). Analysis of network traffic features for anomaly detection. Machine Learning, 101(1–3), 59–84. https://doi.org/10.1007/s10994-014-5473-9

Koumar, J., & ?ejka, T. (2022). Network traffic classification based on periodic behavior detection. In 2022 18th International Conference on Network and Service Management (CNSM) (pp. 359–363). IEEE. https://doi.org/10.23919/CNSM55787.2022.9964556

Koumar, J., Hynek, K., & ?ejka, T. (2023). Network traffic classification based on single flow time series analysis. In 2023 19th International Conference on Network and Service Management (CNSM) (pp. 1–7). IEEE. https://doi.org/10.23919/CNSM59352.2023.10327876

Majigi, M. U., Idris, I., Abdulhamid, S. M., & Ikuesan, R. A. (2025). Big data transfer service architecture for cloud data centers: Problems, methods, applications, and future trends. Discover Computing, 28(1), 163. https://doi.org/10.1007/s10791-025-09682-3

Mohammed, A., et al. (2022). Data security and protection: A mechanism for managing data theft and cybercrime in online platforms of educational institutions. In 2022 International Conference on Machine Learning, Big Data, Cloud and Parallel Computing (COM-IT-CON) (pp. 758–761). IEEE. https://doi.org/10.1109/COM-IT-CON54601.2022.9850702

Mocanu, F., & Scripcariu, L. (2023). Implementation of a security operation center—An essential cybersecurity solution for organizations. In 2023 27th International Conference on System Theory, Control and Computing (ICSTCC) (pp. 539–544). IEEE. https://doi.org/10.1109/ICSTCC59206.2023.10308432

Muttaqien, H., Niswar, M., Syarif, S., & Zainuddin, Z. (2025). Efficient identification of malicious traffic in TLS networks using machine learning. In 2025 IEEE International Conference on Artificial Intelligence and Mechatronics Systems (AIMS) (pp. 1–6). IEEE. https://doi.org/10.1109/AIMS66189.2025.11229622

Papadogiannaki, E., Tsirantonakis, G., & Ioannidis, S. (2022). Network intrusion detection in encrypted traffic. In 2022 IEEE Conference on Dependable and Secure Computing (DSC) (pp. 1–8). IEEE. https://doi.org/10.1109/DSC54232.2022.9888942

Piet, J., Anderson, B., & McGrew, D. (2018). An in-depth study of open-source command and control frameworks. In 2018 13th International Conference on Malicious and Unwanted Software (MALWARE) (pp. 1–8). IEEE. https://doi.org/10.1109/MALWARE.2018.8659361

Pranav, H., Suryaa, E., & Venugopalan, M. (2024). Comprehensive C2 analysis and anomaly detection in HTTP traffic: A MongoDB-based approach. In 2024 International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI) (pp. 1–6). IEEE. https://doi.org/10.1109/ACCAI61061.2024.10602244

Raharjo, D. H. K., Nurmala, A., Pambudi, R. D., & Sari, R. F. (2022). Performance evaluation of intrusion detection system performance for traffic anomaly detection based on active IP reputation rules. In 2022 3rd International Conference on Electrical Engineering and Informatics (ICon EEI) (pp. 75–79). IEEE. https://doi.org/10.1109/IConEEI55709.2022.9972298

Rabbani, M., et al. (2025). Device identification and anomaly detection in IoT environments. IEEE Internet of Things Journal, 12(10), 13625–13643. https://doi.org/10.1109/JIOT.2024.3522863

Sai, A. N. H. D., Tilak, B. H., Sanjith, N. S., Suhas, P., & Sanjeetha, R. (2022). Detection and mitigation of low and slow DDoS attack in an SDN environment. In 2022 International Conference on Distributed Computing, VLSI, Electrical Circuits and Robotics (DISCOVER) (pp. 106–111). IEEE. https://doi.org/10.1109/DISCOVER55800.2022.9974724

Salazar, L. A. G. (2026). Provenance analysis of advanced persistent threats in operational technology environments [Doctoral dissertation, The University of Texas at El Paso].

Waleed, A., Jamali, A. F., & Masood, A. (2022). Which open-source IDS? Snort, Suricata or Zeek. Computer Networks, 213, 109116. https://doi.org/10.1016/j.comnet.2022.109116

Zhang, H., et al. (2025). Explainable and transferable adversarial attack for ML-based network intrusion detectors. IEEE Transactions on Dependable and Secure Computing, 22(5), 5090–5107. https://doi.org/10.1109/TDSC.2025.3560486

Zhou, J., Fu, W., Hu, W., Sun, Z., He, T., & Zhang, Z. (2024). Challenges and advances in analyzing TLS 1.3-encrypted traffic: A comprehensive survey. Electronics, 13(20), 4000. https://doi.org/10.3390/electronics13204000

Downloads

Published

2026-08-12