• DocumentCode
    1915215
  • Title

    Specification-Based Testing of Intrusion Detection Engines Using Logical Expression Testing Criteria

  • Author

    Massicotte, Frédéric ; Labiche, Yvan

  • Author_Institution
    Commun. Res. Centre Canada, Ottawa, ON, Canada
  • fYear
    2010
  • fDate
    14-15 July 2010
  • Firstpage
    102
  • Lastpage
    111
  • Abstract
    An Intrusion Detection System (IDS) protects computer networks against attacks and intrusions. One class of IDS is called signature-based network IDSs as they monitor network traffic, looking for evidence of malicious behaviour as specified in attack descriptions (referred to as signatures). Many studies report that IDSs have problems accurately identifying attacks. Therefore, it is important to precisely understand under which conditions IDSs accurately identify attacks or fail to do so. However, no systematic approach has so far been defined and used to study this problem. Recognizing that signatures in essence provide the specification of an IDS engine, studying the accuracy of an IDS engine becomes a black-box testing problem. We therefore precisely and systematically evaluate which mature testing techniques can be used (and adapted) to derive tests from IDS signatures. We experiment with those criteria on one widely used and maintained IDS and show that our approach is effective at systematically revealing problems in this IDS engine (e.g., problems that prevent the detection of attacks).
  • Keywords
    computer network security; program testing; IDS; computer network protection; intrusion detection engines; logical expression testing criteria; malicious behaviour; network traffic monitoring; specification based testing; Accuracy; Adaptation model; Engines; Payloads; Protocols; Software testing; Intrusion Detection System; automation; black-box testing; logical expression;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Quality Software (QSIC), 2010 10th International Conference on
  • Conference_Location
    Zhangjiajie
  • ISSN
    1550-6002
  • Print_ISBN
    978-1-4244-8078-4
  • Electronic_ISBN
    1550-6002
  • Type

    conf

  • DOI
    10.1109/QSIC.2010.25
  • Filename
    5562949