Skip to content

Author

Muhammad Salman

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

A Comparative Effectiveness Analysis of Signature-Based IDS and Network Detection and Response (NDR) in a SIEM Environment

As cyber threats increasingly employ cryptographically concealed and stealthy communication, traditional signature-based Network Intrusion Detection Systems (NIDS) encounter severe limitations in achieving end-to-end operational visibility. This study delivers a quantitative comparative analysis contrasting signature-based frameworks against metadata-driven Network Detection and Response (NDR) within a unified Security Information and Event Management (SIEM) platform. Configured with a massive ruleset of 47,192 active signatures, the NIDS engine was evaluated against the behavioral metadata abstraction of NDR across five structured attack scenarios mapping the Cyber Kill Chain. Experimental results reveal a critical Visibility Gap in post-exploitation defenses; while NIDS achieved a 60\% Detection Rate by intercepting noisy initial reconnaissance and exploit payloads, it suffered total blindness during post-exploitation maneuvers. Conversely, the NDR engine achieved a 100\% Detection Rate, isolating deterministic forensic indicators including a 716.33-second encrypted command and control (C2) session and a 7.07 MB volumetric data exfiltration burst. Furthermore, architectural benchmarking revealed that massive rule compilation induced structural management plane synchronization failures. These findings synthesize into validated recommendations for sensor optimization, establishing an operational framework for specialized role allocation and computational efficiency to eliminate visibility blind spots within enterprise Security Operations Center (SOC) environments.

Christian Hary, Muhammad Salman · 0 citations