Table 5.
Resulting true positive rate (TPR) of different types of signatures against the tested traffic. Signatures and tested traffic are part of the attack samples from the “Reconnaissance” category. The signatures are generated after a combination of packet direction and packet payload size.
Packet Sequence Length | |||||
---|---|---|---|---|---|
Direction | 4 | 6 | 8 | 10 | 12 |
Source → Destination | 100% | 89% | 89% | 89% | 87% |
Destination → Source | 100% | 98% | 74% | 70% | 68% |
Source ↔ Destination | 100% | 100% | 89% | 86% | 82% |