Intrusion Detection Systems (IDS) play a crucial role in detecting malicious activities and preventing unauthorized access within enterprise networks. This paper presents the deployment and evaluation of the Suricata IDS integrated with vulnerability simulation in a controlled network environment. The study explores the IDS configuration process, rule optimization, and real‑time detection of simulated network probes. The experiment demonstrates Suricata’s capacity for high‑performance network monitoring, rule‑based threat detection, and forensic log interpretation. Results show that integrating IDS with simulated attack traffic and structured logging enhances visibility into system weaknesses, thereby improving network resilience and supporting proactive security management.
John Onyango Agumba (Tue,) studied this question.