• DocumentCode
    3219020
  • Title

    Extending the DARPA off-line intrusion detection evaluations

  • Author

    Haines, Joshua W. ; Rossey, Lee M. ; Lippmann, Richard P. ; Cunningham, Robert K.

  • Author_Institution
    Lincoln Lab., MIT, Lexington, MA, USA
  • Volume
    1
  • fYear
    2001
  • fDate
    2001
  • Firstpage
    35
  • Abstract
    The 1998 and 1999 DARPA off-line intrusion detection evaluations assessed the performance of intrusion detection systems using realistic background traffic and many examples of realistic attacks. This paper discusses three extensions to these evaluations. First, the Lincoln Adaptable Real-time Information Assurance Testbed (LARIAT) has been developed to simplify intrusion detection development and evaluation. LARIAT allows researchers and operational users to rapidly configure and run real-time intrusion detection and correlation tests with robust background traffic and attacks in their laboratories. Second, “Scenario Datasets” have been crafted to provide examples of multiple component attack scenarios instead of the atomic attacks as found in past evaluations. Third, extensive analysis of the 1999 evaluation data and results has provided understanding of many attacks, their manifestations, and the features used to detect them. This analysis is used to develop models of attacks, intrusion detection systems, and intrusion detection system alerts. Successful models could reduce the need for expensive experimentation, allow proof-of-concept analysis and simulations, and form the foundation of a theory of intrusion detection
  • Keywords
    computer network management; security of data; supervisory programs; DARPA off-line intrusion detection evaluations; LARIAT; Lincoln Adaptable Real-time Information Assurance Testbed; Scenario Datasets; intrusion detection systems; models of attacks; multiple component attack scenarios; realistic attacks; realistic background traffic; theory of intrusion detection; Analytical models; Computer vision; Intrusion detection; Labeling; Laboratories; Robustness; Software testing; System testing; Telecommunication traffic; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
  • Conference_Location
    Anaheim, CA
  • Print_ISBN
    0-7695-1212-7
  • Type

    conf

  • DOI
    10.1109/DISCEX.2001.932190
  • Filename
    932190