Design and Realization of Evaluation Environment for Intrusion Detection Systems

蔡忠闽,孙国基,卫军胡,管晓宏
DOI: https://doi.org/10.3969/j.issn.1004-731x.2002.03.030
2002-01-01
Abstract:Intrusion Detection System (IDS) plays a key role in defense-in-depth computer security architecture and is an important complement to the peripheral defense elements such as firewalls and authentication mechanisms. But due to the complexity in both its design and interactions with the deploying environment, an objective testing of IDS is very difficult. In this paper, we first propose a set of performance indexes for IDS evaluation. Then we present the architecture of a simulation environment to test intrusion detection systems automatically. Next, under the framework of this architecture, we discuss three key issues in the realization of such a testing environment: network traffic simulation, computer usage simulation and computer attack simulation. At the end, we give some testing results of an IDS developed by ourselves in a basic testing environment we built.
What problem does this paper attempt to address?