Anomaly Detection Preprocessor for SNORT IDS System

In this paper we propose anomaly detection preprocessor for SNORT IDS Intrusion Detection System [1] base on probabilistic and signal processing algorithms working in parallel. Two different algorithms increasing probability of detecting anomalies in network traffic. 25 network traffic features were used by preprocessor for detecting anomalies. Preprocessor calculated Chi-square statistic test and energy from DWT Discrete Wavelet Transform subband coefficients. Usability of proposed SNORT extension was evaluated in local LAN network.