Hybrid IDS Using Signature-Based and Anomaly-Based Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Boutassetta, Messaouda, Makhlouf, Amina, Messaoudi, Newfel, Benmachiche, Abdelmadjid, Boutabia, Ines
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911382603038720
author Boutassetta, Messaouda
Makhlouf, Amina
Messaoudi, Newfel
Benmachiche, Abdelmadjid
Boutabia, Ines
author_facet Boutassetta, Messaouda
Makhlouf, Amina
Messaoudi, Newfel
Benmachiche, Abdelmadjid
Boutabia, Ines
contents Intrusion detection systems (IDS) are essential for protecting computer systems and networks against a wide range of cyber threats that continue to evolve over time. IDS are commonly categorized into two main types, each with its own strengths and limitations, such as difficulty in detecting previously unseen attacks and the tendency to generate high false positive rates. This paper presents a comprehensive survey and a conceptual overview of Hybrid IDS, which integrate signature-based and anomaly-based detection techniques to enhance attack detection capabilities. The survey examines recent research on Hybrid IDS, classifies existing models into functional categories, and discusses their advantages, limitations, and application domains, including financial systems, air traffic control, and social networks. In addition, recent trends in Hybrid IDS research, such as machine learning-based approaches and cloud-based deployments, are reviewed. Finally, this work outlines potential future research directions aimed at developing more cost-effective Hybrid IDS solutions with improved ability to detect emerging and sophisticated cyberattacks.
format Preprint
id arxiv_https___arxiv_org_abs_2601_11998
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Hybrid IDS Using Signature-Based and Anomaly-Based Detection
Boutassetta, Messaouda
Makhlouf, Amina
Messaoudi, Newfel
Benmachiche, Abdelmadjid
Boutabia, Ines
Cryptography and Security
Artificial Intelligence
Intrusion detection systems (IDS) are essential for protecting computer systems and networks against a wide range of cyber threats that continue to evolve over time. IDS are commonly categorized into two main types, each with its own strengths and limitations, such as difficulty in detecting previously unseen attacks and the tendency to generate high false positive rates. This paper presents a comprehensive survey and a conceptual overview of Hybrid IDS, which integrate signature-based and anomaly-based detection techniques to enhance attack detection capabilities. The survey examines recent research on Hybrid IDS, classifies existing models into functional categories, and discusses their advantages, limitations, and application domains, including financial systems, air traffic control, and social networks. In addition, recent trends in Hybrid IDS research, such as machine learning-based approaches and cloud-based deployments, are reviewed. Finally, this work outlines potential future research directions aimed at developing more cost-effective Hybrid IDS solutions with improved ability to detect emerging and sophisticated cyberattacks.
title Hybrid IDS Using Signature-Based and Anomaly-Based Detection
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2601.11998