2003
DOI: 10.6028/nist.ir.7007
|View full text |Cite
|
Sign up to set email alerts
|

An overview of issues in testing intrusion detection systems

Abstract: While intrusion detection systems are becoming ubiquitous defenses in today's networks, currently we have no comprehensive and scientifically rigorous methodology to test the effectiveness of these systems. This paper explores the types of performa nce measurements that are desired and that have been used in the past. We review many past evaluations that have been designed to assess these metrics. We also discuss the hurdles that have blocked successful measurements in this area and present suggestions for res… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
79
1
1

Year Published

2004
2004
2017
2017

Publication Types

Select...
4
4
2

Relationship

0
10

Authors

Journals

citations
Cited by 111 publications
(81 citation statements)
references
References 15 publications
0
79
1
1
Order By: Relevance
“…The rule set used for the experiments consisted of only the TCP rules among the VRT Certified Rules for Snort version 2.7. As Allen points out in [14] and Mell states in [15], successful development and testing of IDSes' performance requires robust and accurate training data.…”
Section: Methodsmentioning
confidence: 99%
“…The rule set used for the experiments consisted of only the TCP rules among the VRT Certified Rules for Snort version 2.7. As Allen points out in [14] and Mell states in [15], successful development and testing of IDSes' performance requires robust and accurate training data.…”
Section: Methodsmentioning
confidence: 99%
“…We made use of a publicly available labelled dataset simply to avoid the problems described in [47] with recorded traffic from the real environment. Both datasets are available online and have been comprehensively used as a standard benchmark by many researchers in this field, for example, by [6,15,16,48].…”
Section: Dataset Descriptionmentioning
confidence: 99%
“…Mell et al [17] studied past evaluation efforts and listed a number of problems related to nIDS evaluation. The use of sanitized traffic, the effect of background traffic and the difficulties in generating traffic on a testbed network are some of the problems spotted.…”
Section: Previous Work In Nids Evaluationmentioning
confidence: 99%