Detecting the Unknown: Evaluating the Efficacy of Host-Based Intrusion Detection Systems (IDS) in Zero-Day Attacks
摘要
The ever-changing landscape of cybersecurity poses challenges for safeguarding critical assets from sophisticated threats. Host-based intrusion detection systems (HIDS), like Splunk, ManageEngine: Event Log Analyzer, and MalwareBytes, play a vital role in identifying potential intrusions by monitoring individual endpoints for anomalous activities. This study evaluates the efficacy of these solutions, emphasizing the elusive nature of attacks and their consequences. Core HIDS functionalities, such as real-time monitoring and behavior-based detection, are explored. The research systematically analyzes the performance of each solution, highlighting Splunk’s failure in detecting a specific threat while noting success in ManageEngine: Event Log Analyzer and MalwareBytes. The study evaluates the unique capabilities, strengths, and limitations of each solution, emphasizing the need for advanced HIDS technologies to detect and respond to evolving threats. The findings contribute valuable insights to the cybersecurity community, guiding organizations in making informed decisions to enhance their defense mechanisms effectively.