Three years of running a Raspberry Pi NIDS: Snort3 detection shipped via Filebeat into a self-hosted Elastic SIEM, with the tuning lessons that came with it.
Building an anomaly-based IDS for UNIX systems at the KCL Secure Systems Lab — from strace captures to a probabilistic model that caught a stack-based buffer overflow.