Nidsbench - a Network Intrusion Detection Test Suite

نویسندگان

  • Dug Song
  • G. Shaffer
  • M. Undy
چکیده

Dug Song is a Senior Engineer at Anzen Computing, where he focuses on intrusion detection system integration and security consulting. He has been involved in the deployment of enterprise-wide, distributed security solutions at several large government, corporate, and educational sites. Before joining Anzen, Dug was security administrator with the University of Michigan, where he authored the AFS/Kerberos support in SSH in the course of protecting a distributed computing environment with over 70,000 user accounts. Dug is also a regular contributor to the OpenBSD project. Abstract Nidsbench is a lightweight, portable toolkit for testing network intrusion detection systems. It implements the specific fault injection techniques outlined in Ptacek and Newsham's seminal paper on network intrusion detection evasion. It is designed for both real-time and automated use, and allows for the replay of arbitrary attacks or reference network data for comparative analysis. This paper describes the design and implementation of our test suite, and our experimental evaluation of several popular network intrusion detection systems. [Note: Sorry for the short abstract, but we are still in the process of determining the scope of our paper-we haven't finished procuring all the systems we wish to test, etc. We plan to have all of our research done well before July, however-may we send you a preliminary copy of our paper as an update once we write it?-dugsong]

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Review of Intrusion Detection Defense Solutions Based on Software Defined Network

Most networks without fixed infrastructure are based on cloud computing face various challenges. In recent years, different methods have been used to distribute software defined network to address these challenges. This technology, while having many capabilities, faces some vulnerabilities in the face of some common threats and destructive factors such as distributed Denial of Service. A review...

متن کامل

Moving dispersion method for statistical anomaly detection in intrusion detection systems

A unified method for statistical anomaly detection in intrusion detection systems is theoretically introduced. It is based on estimating a dispersion measure of numerical or symbolic data on successive moving windows in time and finding the times when a relative change of the dispersion measure is significant. Appropriate dispersion measures, relative differences, moving windows, as well as tec...

متن کامل

تولید خودکار الگوهای نفوذ جدید با استفاده از طبقه‌بندهای تک کلاسی و روش‌های یادگیری استقرایی

In this paper, we propose an approach for automatic generation of novel intrusion signatures. This approach can be used in the signature-based Network Intrusion Detection Systems (NIDSs) and for the automation of the process of intrusion detection in these systems. In the proposed approach, first, by using several one-class classifiers, the profile of the normal network traffic is established. ...

متن کامل

Category-Based Selection of Effective Parameters for Intrusion Detection

Existing intrusion detection techniques emphasize on building intrusion detection model based on all features provided. In feature-based intrusion detection, some selected features may found to be redundant and useless. Feature selection can reduce the computation power requirements and model complexity. This paper proposes a category-based selection of effective parameters for intrusion detect...

متن کامل

A New Method for Intrusion Detection Using Genetic Algorithm and Neural Network

    The article attempts to have neural network and genetic algorithm techniques present a model for classification on dataset. The goal is design model can the subject acted a firewall in network and this model with compound optimized algorithms create reliability and accuracy and reduce error rate couse of this is article use feedback neural network and compared to previous methods increase a...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999