|
Re: IDS data sets: msg#00019security.ids
Hallo Salim, I am a newbie to the forum. I am looking for some pointers as far as The data are intended for IDS evaluation, thus you can analyze them with any IDS / Network traffic analysis tool (as far as the TCPDump logs are concerned) or with a BSM auditing tool for the rest of them. My attempts thus far have resulted in Well, what operation doesn't crash a windows system nowadays :) Seriously: those datasets are HUGE. I advise you to use stable, simple utilities to analyze them. And lots of RAM would help, also. The data available is five years old and I There is an awfully good critique of that dataset in J. McHugh, "Testing Intrusion detection systems: a critique of the 1998 and 1999 DARPA intrusion detection system evaluations as performed by Lincoln Laboratory", ACM Transactions on Information and System Security (TISSEC), Volume 3, Issue 4 (November 2000) http://portal.acm.org/citation.cfm?id=382923 -- Cordiali saluti, Stefano Zanero Dottorando di Ricerca / Ph.D. Student Politecnico di Milano - Dip. Elettronica e Informazione Via Ponzio, 34/5 I-20133 Milano - ITALY Tel. +39 02 2399-4010/3660 Fax. +39 02 2399-3411 E-mail: zanero@xxxxxxxxxxxxxx Web: www.elet.polimi.it/upload/zanero -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. -------------------------------------------------------------------------- |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | RE: performance metrics for IPS systems?: 00019, THolman |
|---|---|
| Next by Date: | Re: Tripwire for Solaris 8: 00019, John Meyers |
| Previous by Thread: | IDS data setsi: 00019, Zafar, Salim |
| Next by Thread: | High availability design of NIDS: 00019, Vincent IP |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |