This paper describes Honeycomb, a system for automated generation of attack signatures for network intrusion detection systems (NIDSs). Our system applies pattern detection techniques and protocol conformance checks on multiple levels in the protocol hierarchy to network traffic captured on a honeypot system. While running Honeycomb on an unprotected cable modem connection for 24 hours, the sys...