|
Focus on IDS
Re: Re: Intrusion Detection Evaluation Datasets Mar 10 2009 08:55AM zubair shafiq yahoo com (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 10 2009 08:40PM Stefano Zanero (s zanero securenetwork it) (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 12 2009 03:40PM \Zow\ Terry Brugger (zow acm org) (3 replies) Re: Intrusion Detection Evaluation Datasets Mar 13 2009 10:56AM Stefano Zanero (zanero elet polimi it) Re: Intrusion Detection Evaluation Datasets Mar 12 2009 10:55PM Stuart Staniford (sstaniford FireEye com) (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 13 2009 11:03AM Stefano Zanero (zanero elet polimi it) (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 13 2009 03:21PM \Zow\ Terry Brugger (zow acm org) (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 13 2009 06:52PM Paul Palmer (paul_palmer us ibm com) (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 13 2009 07:58PM Stefano Zanero (zanero elet polimi it) (1 replies) Re: Intrusion Detection Evaluation Datasets Mar 13 2009 08:53PM Paul Palmer (b paul palmer gmail com) Re: Intrusion Detection Evaluation Datasets Mar 12 2009 08:43PM Paul Palmer (paul_palmer us ibm com) |
|
Privacy Statement |
I agree that it is very hard to obtain datasets with payloads due to privacy constraints. Good anonymization procedures mostly retain the relative statistics of the data. For example, you may consult the following work by people at ICSI.
http://www.icir.org/enterprise-tracing/devil-ccr-jan06.pdf
An overwhelming majority of network based IDSs use only spatial information present in packet headers. The datasets that I have mentioned in my earlier post can be used to evaluate such IDSs. Moreover, you can find details of the endpoint worm propagation dataset in the following papers:
http://www.nexginrc.org/papers/tr15-zubair.pdf
http://www.nexginrc.org/papers/gecco08-zubair.pdf
In my view, there are two directions to take dataset labeling further:
1. Improving injection procedures to ensure minimization of artifacts. This is more feasible if you know all parameters and environmental conditions during trace collection -- Know Thy Data.
2. Use "semi-automated" ~ "semi-manual" procedures.
@Stefano: You have probably missed this point. Semi-automated procedures still require manual intervention, however, it will help to reduce its magnitude significantly. So, we are not exactly developing a typical anomaly detection system.
let me know what you think.
[ reply ]