How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
研究通过SuriCap平台和CTF式工作坊,分析了60名参与者创建网络入侵检测规则的过程与方法,揭示经验对规则质量影响有限,并指出标记数据的重要性。
📝 Abstract
Many Security Operations Centers rely on signature-based Network Intrusion Detection Systems like Suricata, yet detection rule engineering remains understudied. We investigate this process by introducing SuriCap, a platform for rule engineering exercises, and hosting CTF-style workshops where 60 participants, trained MSc students, and experienced SOC professionals, created rules for four scenarios. Participants produced 3146 valid rules, enabling analysis of their methods, performance, and iteration patterns. Surprisingly, prior experience had limited impact on rule quality, suggesting that less experienced engineers can produce rules comparable to experts. We also observed challenges in generalizing rules beyond available tests, underscoring the need for sufficient labeled data. From our study, we identify three phases and a common pattern in rule engineering, offering SOC managers insights to improve their processes and expectations of engineer expertise.
Problem

Research questions and friction points this paper is trying to address.

Network Intrusion Detection Systems
rule engineering
Suricata
Innovation

Methods, ideas, or system contributions that make the work stand out.

SuriCap
rule engineering
network intrusion detection
labeled data
SOC processes