A Risk-Aware Network Intrusion Detection System using Rule-based Detection and EPSS-based Alert Prioritization
Abstract
As the interconnection of digital infrastructures grows at a fast pace, businesses are facing ever-evolving cyber threats. Efficient detection of intrusions is required due to the growing complexity of cyber threats. Classical Network Intrusion Detection Systems (NIDS) have a good capability to detect intrusion events based on certain signatures; nevertheless, they produce lots of unfiltered alerts, increasing the workloads of SOC analysts. In this regard, this research suggests a NIDS with a built-in capability of alert generation and priority assignment based on the Exploit Prediction Scoring System (EPSS). The suggested NIDS can perform real-time monitoring of the network and offline PCAP file analysis for discovering such intrusion events as port scans, brute force, unauthorized access attempts, and protocols misuses. Generated alerts will be sent through an HTTPS connection and will be supplemented with CVE-related vulnerability information. The EPSS scores will be employed to determine actual exploitability of identified vulnerabilities and assign alerts to particular priority categories. Besides, the introduced method includes explainable alert generation and SOC-style visualizing tool. Experiment shows that such NIDS will help to optimize the process of alert management and provide a better user experience for SOC analysts.