DocumentCode :
2085046
Title :
LLSIM: network simulation for correlation and response testing
Author :
Haines, Joshua W. ; Goulet, Stephen A. ; Durst, Robert S. ; Champion, Terrance G.
fYear :
2003
fDate :
18-20 June 2003
Firstpage :
243
Lastpage :
250
Abstract :
The Lincoln Laboratory Simulator, LLSIM, is an easily configurable network simulator that can produce a wide variety of data sets without expensive testbeds. These data sets are useful for researchers who are developing general-purpose correlation and response systems. LLSIM is a Java-based, event-driven simulator consisting of user-configurable core models of networks and hosts. Event generators produce network and host events in the simulated system and models of intrusion detection sensors generate realistic streams of alerts in relation to these events. On a typical PC workstation, LLSIM can emulate arbitrary networks with hundreds of nodes and communication links, and can accurately simulate hundreds of intrusion detection sensors operating in these environments. Researchers can generate many different datasets using LLSIM and can also evaluate the effectiveness of simple response actions like altering firewall policies in response to an attack. Sensor alert datasets generated by LLSIM have been used in the DARPA Cyber Panel program.
Keywords :
Java; authorisation; computer crime; computer networks; discrete event simulation; sensors; telecommunication computing; workstations; DARPA cyber panel program; IDS sensors; Java-based event-driven simulator; LLSIM; Lincoln Laboratory Simulator; PC workstation; communication links; correlation testing; event generators; firewall policies alteration; general-purpose correlation system; host event; intrusion detection sensor model; network event; network modeling; network simulation; realistic alert stream; response system; response testing; sensor alert datasets; testbed; user-configurable core model; Automatic testing; Discrete event simulation; Force sensors; Hardware; Intrusion detection; Java; Laboratories; Sensor systems; System testing; Workstations;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance Workshop, 2003. IEEE Systems, Man and Cybernetics Society
Print_ISBN :
0-7803-7808-3
Type :
conf
DOI :
10.1109/SMCSIA.2003.1232429
Filename :
1232429
Link To Document :
بازگشت