DocumentCode :
3219020
Title :
Extending the DARPA off-line intrusion detection evaluations
Author :
Haines, Joshua W. ; Rossey, Lee M. ; Lippmann, Richard P. ; Cunningham, Robert K.
Author_Institution :
Lincoln Lab., MIT, Lexington, MA, USA
Volume :
1
fYear :
2001
fDate :
2001
Firstpage :
35
Abstract :
The 1998 and 1999 DARPA off-line intrusion detection evaluations assessed the performance of intrusion detection systems using realistic background traffic and many examples of realistic attacks. This paper discusses three extensions to these evaluations. First, the Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) has been developed to simplify intrusion detection development and evaluation. LARIAT allows researchers and operational users to rapidly configure and run real-time intrusion detection and correlation tests with robust background traffic and attacks in their laboratories. Second, “Scenario Datasets” have been crafted to provide examples of multiple component attack scenarios instead of the atomic attacks as found in past evaluations. Third, extensive analysis of the 1999 evaluation data and results has provided understanding of many attacks, their manifestations, and the features used to detect them. This analysis is used to develop models of attacks, intrusion detection systems, and intrusion detection system alerts. Successful models could reduce the need for expensive experimentation, allow proof-of-concept analysis and simulations, and form the foundation of a theory of intrusion detection
Keywords :
computer network management; security of data; supervisory programs; DARPA off-line intrusion detection evaluations; LARIAT; Lincoln Adaptable Real-time Information Assurance Testbed; Scenario Datasets; intrusion detection systems; models of attacks; multiple component attack scenarios; realistic attacks; realistic background traffic; theory of intrusion detection; Analytical models; Computer vision; Intrusion detection; Labeling; Laboratories; Robustness; Software testing; System testing; Telecommunication traffic; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
Conference_Location :
Anaheim, CA
Print_ISBN :
0-7695-1212-7
Type :
conf
DOI :
10.1109/DISCEX.2001.932190
Filename :
932190
Link To Document :
بازگشت