Focus on IDS
Re: Intrusion Detection Evaluation Datasets Mar 13 2009 02:47AM
Sam Gorton (sam gorton gmail com) (3 replies)
On Thu, Mar 12, 2009 at 08:40:04AM -0700, Zow Terry Brugger wrote:
>
> I see a lot of people saying (correctly) that advanced (non-signature
> based) NIDS can't be researched until we have good evaluation
> datasets, and I see a lot of people ignoring them and doing it anyway.
> Is anyone (else) actually working on fixing the data problem?

There's been some progress, but it's unfortunately not public. The
DHS PREDICT project (www.predict.org) includes various captured data
sets, including about 200 gig of artificial data sets we generated to
support a research project. PREDICT data's only available to
researchers based in the US who meet the program requirements.

There's no good answer right now to the problem of having a good
shared dataset, but I think that 'bad data' is a worse answer than 'no
data'. When the data does have problems, if the problems are clearly
labeled then hopefully researchers won't try to build systems around
artifacts.

--
Sam Gorton | Skaion Corporation
sgorton (at) skaion (dot) com [email concealed] | www.skaion.com

[ reply ]
Re: Exploit-based signature is dead, or not? Mar 18 2009 02:18PM
tanyoo10 (tanyoo10 163 com)
Exploit-based signature is dead, or not? Mar 13 2009 05:20PM
tanyoo10 (tanyoo10 163 com) (4 replies)
Re: Exploit-based signature is dead, or not? Mar 29 2009 01:11AM
Joel Esler (eslerj gmail com)
Re: Re: Exploit-based signature is dead, or not? Mar 17 2009 06:52AM
tanyoo10 (tanyoo10 163 com)
RE: Exploit-based signature is dead, or not? Mar 16 2009 08:27PM
Addepalli Srini-B22160 (saddepalli freescale com)
Re: Exploit-based signature is dead, or not? Mar 16 2009 06:16PM
Sergio 'shadown' Alvarez (shadown gmail com) (1 replies)
Re: Exploit-based signature is dead, or not? Mar 17 2009 03:12AM
Jackie Lai (gclai draytek com)
Re: Intrusion Detection Evaluation Datasets Mar 13 2009 02:56PM
Raffael Marty (rmarty splunk com)


 

Privacy Statement
Copyright 2010, SecurityFocus