DocumentCode
3219020
Title
Extending the DARPA off-line intrusion detection evaluations
Author
Haines, Joshua W. ; Rossey, Lee M. ; Lippmann, Richard P. ; Cunningham, Robert K.
Author_Institution
Lincoln Lab., MIT, Lexington, MA, USA
Volume
1
fYear
2001
fDate
2001
Firstpage
35
Abstract
The 1998 and 1999 DARPA off-line intrusion detection evaluations assessed the performance of intrusion detection systems using realistic background traffic and many examples of realistic attacks. This paper discusses three extensions to these evaluations. First, the Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) has been developed to simplify intrusion detection development and evaluation. LARIAT allows researchers and operational users to rapidly configure and run real-time intrusion detection and correlation tests with robust background traffic and attacks in their laboratories. Second, “Scenario Datasets” have been crafted to provide examples of multiple component attack scenarios instead of the atomic attacks as found in past evaluations. Third, extensive analysis of the 1999 evaluation data and results has provided understanding of many attacks, their manifestations, and the features used to detect them. This analysis is used to develop models of attacks, intrusion detection systems, and intrusion detection system alerts. Successful models could reduce the need for expensive experimentation, allow proof-of-concept analysis and simulations, and form the foundation of a theory of intrusion detection
Keywords
computer network management; security of data; supervisory programs; DARPA off-line intrusion detection evaluations; LARIAT; Lincoln Adaptable Real-time Information Assurance Testbed; Scenario Datasets; intrusion detection systems; models of attacks; multiple component attack scenarios; realistic attacks; realistic background traffic; theory of intrusion detection; Analytical models; Computer vision; Intrusion detection; Labeling; Laboratories; Robustness; Software testing; System testing; Telecommunication traffic; Traffic control;
fLanguage
English
Publisher
ieee
Conference_Titel
DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
Conference_Location
Anaheim, CA
Print_ISBN
0-7695-1212-7
Type
conf
DOI
10.1109/DISCEX.2001.932190
Filename
932190
Link To Document