• DocumentCode
    1462596
  • Title

    A methodology for testing intrusion detection systems

  • Author

    Puketza, Nicholas J. ; Zhang, Kui ; Chung, Mandy ; Mukherjee, Biswanath ; Olsson, Ronald A.

  • Author_Institution
    Dept. of Comput. Sci., California Univ., Davis, CA, USA
  • Volume
    22
  • Issue
    10
  • fYear
    1996
  • fDate
    10/1/1996 12:00:00 AM
  • Firstpage
    719
  • Lastpage
    729
  • Abstract
    Intrusion detection systems (IDSs) attempt to identify unauthorized use, misuse, and abuse of computer systems. In response to the growth in the use and development of IDSs, the authors have developed a methodology for testing IDSs. The methodology consists of techniques from the field of software testing which they have adapted for the specific purpose of testing IDSs. They identify a set of general IDS performance objectives which is the basis for the methodology. They present the details of the methodology, including strategies for test-case selection and specific testing procedures. They include quantitative results from testing experiments on the Network Security Monitor (NSM), an IDS developed at UC Davis. They present an overview of the software platform that has been used to create user-simulation scripts for testing experiments. The platform consists of the UNIX tool expect and enhancements that they have developed, including mechanisms for concurrent scripts and a record-and-replay feature. They also provide background information on intrusions and IDSs to motivate their work
  • Keywords
    computer crime; security of data; testing; Network Security Monitor; UNIX tool expect; computer system abuse; computer system misuse; concurrent scripts; intrusion detection system testing; record-and-replay feature; software testing; test-case selection; testing procedures; unauthorized computer system use; user-simulation scripts; Computational modeling; Computer networks; Computer security; Computer simulation; Computerized monitoring; Expert systems; Intrusion detection; National security; Software testing; System testing;
  • fLanguage
    English
  • Journal_Title
    Software Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0098-5589
  • Type

    jour

  • DOI
    10.1109/32.544350
  • Filename
    544350