• DocumentCode
    2085046
  • Title

    LLSIM: network simulation for correlation and response testing

  • Author

    Haines, Joshua W. ; Goulet, Stephen A. ; Durst, Robert S. ; Champion, Terrance G.

  • fYear
    2003
  • fDate
    18-20 June 2003
  • Firstpage
    243
  • Lastpage
    250
  • Abstract
    The Lincoln Laboratory Simulator, LLSIM, is an easily configurable network simulator that can produce a wide variety of data sets without expensive testbeds. These data sets are useful for researchers who are developing general-purpose correlation and response systems. LLSIM is a Java-based, event-driven simulator consisting of user-configurable core models of networks and hosts. Event generators produce network and host events in the simulated system and models of intrusion detection sensors generate realistic streams of alerts in relation to these events. On a typical PC workstation, LLSIM can emulate arbitrary networks with hundreds of nodes and communication links, and can accurately simulate hundreds of intrusion detection sensors operating in these environments. Researchers can generate many different datasets using LLSIM and can also evaluate the effectiveness of simple response actions like altering firewall policies in response to an attack. Sensor alert datasets generated by LLSIM have been used in the DARPA Cyber Panel program.
  • Keywords
    Java; authorisation; computer crime; computer networks; discrete event simulation; sensors; telecommunication computing; workstations; DARPA cyber panel program; IDS sensors; Java-based event-driven simulator; LLSIM; Lincoln Laboratory Simulator; PC workstation; communication links; correlation testing; event generators; firewall policies alteration; general-purpose correlation system; host event; intrusion detection sensor model; network event; network modeling; network simulation; realistic alert stream; response system; response testing; sensor alert datasets; testbed; user-configurable core model; Automatic testing; Discrete event simulation; Force sensors; Hardware; Intrusion detection; Java; Laboratories; Sensor systems; System testing; Workstations;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance Workshop, 2003. IEEE Systems, Man and Cybernetics Society
  • Print_ISBN
    0-7803-7808-3
  • Type

    conf

  • DOI
    10.1109/SMCSIA.2003.1232429
  • Filename
    1232429