• DocumentCode
    2975795
  • Title

    Computer Network Testbed at Binghamton University

  • Author

    Dolgikh, Andrey ; Nykodym, Tomas ; Skormin, Victor ; Antonakos, James

  • Author_Institution
    Binghamton Univ., Binghamton, NY, USA
  • fYear
    2011
  • fDate
    7-10 Nov. 2011
  • Firstpage
    1146
  • Lastpage
    1151
  • Abstract
    The Network Testbed at Binghamton University was designed to facilitate security research in the area of advanced IDS. It offers a secure, controlled environment for experimental analysis of the efficiency of various intrusion detection/mitigation and computer forensics systems. It allows for staging large scale experiments with real self-propagating malware on thousands of interacting heterogeneous nodes. This paper addresses some principles implemented in the Testbed design including the architecture, accessibility, security, and visualization. The Testbed provides effective ways to collect data representing the network and software operation. It facilitates secure time sharing of the hardware among different research projects. Its enhanced security is achieved by separation and hardening of the core services. The application of the Testbed is demonstrated by the following three experiments featuring novel IDS technologies: behavior-based IDS extracting predefined malicious functionalities from the system call data by semantic analysis, demonstration of the alarm propagation concept for the minimization of false alarms and the detection of distributed low and slow attacks, and network-wide IDS capable of automatic detection of functionalities and statistically significant variations of their relative frequencies indicative of information attacks.
  • Keywords
    computer forensics; computer network performance evaluation; computer network security; invasive software; minimisation; Binghamton University; alarm propagation concept; behavior-based IDS; computer forensics system; computer network testbed design; data represention; false alarm minimization; information attacks; intrusion detection; network-wide IDS; secure time sharing; security research; self-propagating malware; semantic analysis; Educational institutions; Hardware; Internet; Malware; Servers; Software; Testbed; intrusion detection; security research; software behavior; system calls;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
  • Conference_Location
    Baltimore, MD
  • ISSN
    2155-7578
  • Print_ISBN
    978-1-4673-0079-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2011.6127454
  • Filename
    6127454