Title :
Computer Network Testbed at Binghamton University
Author :
Dolgikh, Andrey ; Nykodym, Tomas ; Skormin, Victor ; Antonakos, James
Author_Institution :
Binghamton Univ., Binghamton, NY, USA
Abstract :
The Network Testbed at Binghamton University was designed to facilitate security research in the area of advanced IDS. It offers a secure, controlled environment for experimental analysis of the efficiency of various intrusion detection/mitigation and computer forensics systems. It allows for staging large scale experiments with real self-propagating malware on thousands of interacting heterogeneous nodes. This paper addresses some principles implemented in the Testbed design including the architecture, accessibility, security, and visualization. The Testbed provides effective ways to collect data representing the network and software operation. It facilitates secure time sharing of the hardware among different research projects. Its enhanced security is achieved by separation and hardening of the core services. The application of the Testbed is demonstrated by the following three experiments featuring novel IDS technologies: behavior-based IDS extracting predefined malicious functionalities from the system call data by semantic analysis, demonstration of the alarm propagation concept for the minimization of false alarms and the detection of distributed low and slow attacks, and network-wide IDS capable of automatic detection of functionalities and statistically significant variations of their relative frequencies indicative of information attacks.
Keywords :
computer forensics; computer network performance evaluation; computer network security; invasive software; minimisation; Binghamton University; alarm propagation concept; behavior-based IDS; computer forensics system; computer network testbed design; data represention; false alarm minimization; information attacks; intrusion detection; network-wide IDS; secure time sharing; security research; self-propagating malware; semantic analysis; Educational institutions; Hardware; Internet; Malware; Servers; Software; Testbed; intrusion detection; security research; software behavior; system calls;
Conference_Titel :
MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
Conference_Location :
Baltimore, MD
Print_ISBN :
978-1-4673-0079-7
DOI :
10.1109/MILCOM.2011.6127454