Design and Implementation of an Open Network and Host-Based Intrusion Detection Testbed with an Emphasis on Accuracy and Repeatability

Michael J. Shevenell, R. Erbacher
{"title":"Design and Implementation of an Open Network and Host-Based Intrusion Detection Testbed with an Emphasis on Accuracy and Repeatability","authors":"Michael J. Shevenell, R. Erbacher","doi":"10.1109/ITNG.2012.99","DOIUrl":null,"url":null,"abstract":"The Open Network and Host Based Intrusion Detection Test bed (ONBIT) has been designed to make use of both network and host-based monitoring while validating and evaluating IDS tools and algorithms. This test bed was found to be of critical need for scenarios in which external test beds cannot be used. The ONBIT test bed can be used to verify algorithms, concepts, and protocols, as well as discover more practical problems for future security research. This test bed is unique in its real-time nature and real-world performance and efficiency metrics, critical metrics for capabilities being readied for deployment. The ONBIT test bed was built using open source software and was designed to take accuracy and repeatability into consideration at each step of experimentation. Using a link emulator called Dummy Net, the ONBIT test bed has the ability to control how the network behaves. Dummy Net creates controlled packet loss, introduces latency, and allows for the configuration of various size network pipes. We show the benefit of correlating host-based and network-based IDS data in a real-world demonstration of the testbed's use.","PeriodicalId":117236,"journal":{"name":"2012 Ninth International Conference on Information Technology - New Generations","volume":"60 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-04-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Ninth International Conference on Information Technology - New Generations","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITNG.2012.99","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

The Open Network and Host Based Intrusion Detection Test bed (ONBIT) has been designed to make use of both network and host-based monitoring while validating and evaluating IDS tools and algorithms. This test bed was found to be of critical need for scenarios in which external test beds cannot be used. The ONBIT test bed can be used to verify algorithms, concepts, and protocols, as well as discover more practical problems for future security research. This test bed is unique in its real-time nature and real-world performance and efficiency metrics, critical metrics for capabilities being readied for deployment. The ONBIT test bed was built using open source software and was designed to take accuracy and repeatability into consideration at each step of experimentation. Using a link emulator called Dummy Net, the ONBIT test bed has the ability to control how the network behaves. Dummy Net creates controlled packet loss, introduces latency, and allows for the configuration of various size network pipes. We show the benefit of correlating host-based and network-based IDS data in a real-world demonstration of the testbed's use.
开放网络和基于主机的入侵检测试验台的设计与实现,重点是准确性和可重复性
开放网络和基于主机的入侵检测试验台(ONBIT)设计用于在验证和评估入侵检测工具和算法的同时利用基于网络和基于主机的监控。这个测试平台被发现对于不能使用外部测试平台的场景是非常需要的。ONBIT测试平台可以用于验证算法、概念和协议,并为未来的安全研究发现更多实际问题。该测试平台在其实时性和真实世界的性能和效率指标方面是独一无二的,这些指标是为部署做好准备的能力的关键指标。ONBIT测试平台是使用开源软件构建的,在设计时考虑了实验的每个步骤的准确性和可重复性。使用一个名为Dummy Net的链路仿真器,ONBIT测试平台能够控制网络的行为方式。虚拟网络创建了可控的数据包丢失,引入了延迟,并允许配置各种大小的网络管道。我们在实际的测试平台使用演示中展示了关联基于主机和基于网络的IDS数据的好处。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信