PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 26, 2026Computers0 citationsOpen Access

R-Snort: A Performance-Optimized Multi-Agent NIDS Architecture for SOHO and Edge-of-Things Networks Using Snort 3 on Raspberry Pi 5

View Full Paper
JLJulio Gómez LópezDTDeian Orlando Petrovics TabacuNSNicolás Padilla Soriano

Key Points

  • To develop a low-cost, performance-optimized multi-agent Network Intrusion Detection System (NIDS) suitable for SOHO and Edge-of-Things environments.
  • Developed R-Snort as an open-source NIDS based on Snort 3 for Raspberry Pi 5.
  • Implemented a multi-agent architecture for distributed deployment with centralized traffic analysis.
  • Created an Infrastructure as Code (IaC) framework for automated deployment with a user-friendly web interface.
  • Achieved 1 Gbps throughput in the NIDS agent.
  • Enabled centralized event correlation to detect multi-vector attacks effectively.
  • Facilitated the use of professional-grade security tools in environments with limited resources and expertise.

Abstract

Network Intrusion Detection Systems (NIDSs) are critical to ensuring the resilience of modern digital infrastructures. Although traditionally deployed in large-scale corporate environments, the expanding threat landscape requires the integration of robust security measures into Small Office/Home Office (SOHO) and Edge-of-Things (EoT) networks. However, these environments often face significant constraints in terms of specialized hardware and technical expertise. This article presents R-Snort, an open-source NIDS based on Snort 3, optimized for low-cost Raspberry Pi 5 hardware. Its multi-agent architecture enables distributed deployment with centralized traffic analysis and cross-agent attack correlation, while an intuitive web interface simplifies alert visualization and system management for non-expert administrators. Its main contributions are: (1) a performance-optimized NIDS agent achieving 1 Gbps throughput; (2) a distributed multi-agent architecture enabling centralized event correlation and detection of multi-vector attacks; and (3) an IaC-based automated deployment framework with an intuitive web interface, democratizing professional-grade security for SOHO and EoT environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

López et al. (2026) studied this question.

synapsesocial.com/papers/69edacbd4a46254e215b4775https://doi.org/10.3390/computers15050270
Ask AI
Helpful
Bookmark
Share
View Full Paper