2000
DOI: 10.1007/3-540-39945-3_11
|View full text |Cite
|
Sign up to set email alerts
|

Analysis and Results of the 1999 DARPA Off-Line Intrusion Detection Evaluation

Abstract: Abstract. Eight sites participated in the second DARPA off-line intrusion detection evaluation in 1999. Three weeks of training and two weeks of test data were generated on a test bed that emulates a small government site. More than 200 instances of 58 attack types were launched against victim UNIX and Windows NT hosts. False alarm rates were low (less than 10 per day). Best detection was provided by networkbased systems for old probe and old denial-of-service (DoS) attacks and by host-based systems for Solari… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
71
0
2

Year Published

2007
2007
2017
2017

Publication Types

Select...
5
2
2

Relationship

0
9

Authors

Journals

citations
Cited by 167 publications
(73 citation statements)
references
References 7 publications
0
71
0
2
Order By: Relevance
“…Hence, the proposed IDS operates at the packet level and not at the connection level as other models do [13,14]. Indeed, the design of the feature set is a crucial issue that has been thoroughly addressed in the literature [15].…”
Section: The Visual Inspection Of Traffic In Modern Ids'smentioning
confidence: 99%
“…Hence, the proposed IDS operates at the packet level and not at the connection level as other models do [13,14]. Indeed, the design of the feature set is a crucial issue that has been thoroughly addressed in the literature [15].…”
Section: The Visual Inspection Of Traffic In Modern Ids'smentioning
confidence: 99%
“…The compression component processes an n-dimensional vector that has been previously assembled by a "packet processing" module, which extracts numerical features associated with each network packet. Hence, unlike other models which operate at the connection level [8], [9], the proposed IDS operates at the packet level. The design of the feature set is a crucial issue that has been thoroughly addressed in the literature [10].…”
Section: Visual Inspection Of Traffic In Modern Ids'smentioning
confidence: 99%
“…The alerts have to be generated by running various sensors on the data. The 1999 dataset [10], which we used for this work, has many known shortcomings. Firstly, it is evidently and hopelessly outdated.…”
Section: Problem Statement and State Of The Artmentioning
confidence: 99%