Enhancing Wireshark with Advanced Filtering and Traffic Classification for IDS Applications
摘要
This paper presents an enhanced version of Wireshark which, as a lightweight IDS, incorporates various advanced filtering techniques, an ML-based traffic classification, and real-time alerting capabilities. Still based on traditional signature-based filters, the system tags specific attack patterns; a traffic classifier based on Random Forest classifies network traffic as benign or attendant to malicious activity. Because of Lua scripting, the real-time alert capability has been integrated to respond to an on-time threat. The upgrades have been evaluated against KDD Cup 1999 dataset in a simulated cloud environment, within which a high-performance accuracy rate of 98.2 was achieved. Results establish the feasibility of Wireshark as a scalable and effective IDS, suitable both for classical and cloud-based networks.