Abstract

Many Security Operations Centers rely on signature-based Network Intrusion Detection Systems like Suricata, yet detection rule engineering remains understudied. We investigate this process by introducing SuriCap, a platform for rule engineering exercises, and hosting CTF-style workshops where 60 participants, trained MSc students, and experienced SOC professionals, created rules for four scenarios. Participants produced 3146 valid rules, enabling analysis of their methods, performance, and iteration patterns. Surprisingly, prior experience had limited impact on rule quality, suggesting that less experienced engineers can produce rules comparable to experts. We also observed challenges in generalizing rules beyond available tests, underscoring the need for sufficient labeled data. From our study, we identify three phases and a common pattern in rule engineering, offering SOC managers insights to improve their processes and expectations of engineer expertise.

Keywords

Subject

Publication details

DOI
10.1145/3846375.3849098
Journal
Not available
Open access
Green open access

Cite this article

APA 7

Teuwen, K. T. W., Zambon, E., & Allodi, L. (2026). How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules. https://doi.org/10.1145/3846375.3849098

MLA 9

Teuwen, Koen T. W., et al. "How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules." https://doi.org/10.1145/3846375.3849098.

Chicago (author–date)

Teuwen, Koen T. W., Emmanuele Zambon, and Luca Allodi. 2026. "How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules." https://doi.org/10.1145/3846375.3849098.

Harvard

Teuwen, K. T. W., Zambon, E. and Allodi, L. (2026) 'How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules', doi:10.1145/3846375.3849098.

Vancouver

Teuwen KTW, Zambon E, Allodi L. How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules. doi:10.1145/3846375.3849098

IEEE

K. T. W. Teuwen, E. Zambon, and L. Allodi, "How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules," doi: 10.1145/3846375.3849098.