A database of anomalous traffic for assessing profile based IDS - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

A database of anomalous traffic for assessing profile based IDS

Philippe Owezarski

Résumé

This paper aims at proposing a methodology and the required tools for evaluating current IDS (commercial ones, as well as prototypes resulting from advanced research projects) capabilities of detecting attacks targeting the networks and their services. This methodology tries to be as realistic as possible and reproducible, i.e. it works with real attacks and real traffic in controlled environments. It especially relies on a database containing attack traces specifically created for that evaluation purpose. By confronting IDS to these attack traces, it is possible to get a statistical evaluation of IDS, and to rank them according to their detection capabilities without false alarms. For illustration purposes, this paper shows the results obtained with 3 public IDS. It also shows how the attack traces database impacts the results got for the same IDS.
Fichier principal
Vignette du fichier
owe_evalIDS.pdf (363.85 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00431470 , version 1 (12-11-2009)

Identifiants

  • HAL Id : hal-00431470 , version 1

Citer

Philippe Owezarski. A database of anomalous traffic for assessing profile based IDS. Traffic Monitoring and Analysis Workshop (TMA 2010), Apr 2010, Zurich, Switzerland. p. 59-72. ⟨hal-00431470⟩
70 Consultations
182 Téléchargements

Partager

Gmail Facebook X LinkedIn More