A Self-Revised Method of Protocol Identification Using Mutation Test

Meng Ma,Guoai Xu
DOI: https://doi.org/10.1049/cp.2010.0774
2010-01-01
Abstract:Protocol identification is the key technology of intrusion detection. There're much of traditional limitations exist in the process of character database development. This paper introduces the concept of mutation testing and designs several mutation operators for protocol identification based on Snort rules. A self-revised method is proposed and the efficiency of which is promoted. Experiment has shown that the method is effective in making automatic amendment against protocol rules within certain scope to improve the accuracy and efficiency.
What problem does this paper attempt to address?