Title :
A self-revised method of protocol identification using mutation test
Author :
Meng Ma ; Guoai Xu
Author_Institution :
Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, China
Abstract :
Protocol identification is the key technology of intrusion detection. There´re much of traditional limitations exist in the process of character database development. This paper introduces the concept of mutation testing and designs several mutation operators for protocol identification based on Snort rules. A self-revised method is proposed and the efficiency of which is promoted. Experiment has shown that the method is effective in making automatic amendment against protocol rules within certain scope to improve the accuracy and efficiency.
Keywords :
intrusion detection; mutation testing; protocol identification; self-revise;
Conference_Titel :
Advanced Intelligence and Awarenss Internet (AIAI 2010), 2010 International Conference on
Conference_Location :
Beijing, China
DOI :
10.1049/cp.2010.0774