DocumentCode
3613572
Title
A metrics-based approach to intrusion detection system evaluation for distributed real-time systems
Author
G.A. Fink;B.L. Chappell;T.G. Turner;K.F. O´Donoghue
fYear
2002
fDate
6/24/1905 12:00:00 AM
Abstract
This paper describes a set of metrics that will help administrators of distributed, real-time (clustered) computer facilities to select the best intrusion detection system for their facilities. The metrics herein are the subset of our general metric set that particularly impact real-time and distributed processing issues. We discuss related works in this field, the role of intrusion detection in information assurance, some basic classes of intrusion detection systems, a general architecture of network intrusion detection systems, and the scorecard metrics and their application to real-time and distributed processing systems. Finally we discuss the lessons we learned using a preliminary version of the metric scorecard to test three commercial intrusion detection systems and the opportunities for further work in this area.
Keywords
"Intrusion detection","Real time systems","Information security","Distributed computing","Distributed processing","Taxonomy","Military computing","System testing","Computer security","Costs"
Publisher
ieee
Conference_Titel
Parallel and Distributed Processing Symposium., Proceedings International, IPDPS 2002, Abstracts and CD-ROM
Print_ISBN
0-7695-1573-8
Type
conf
DOI
10.1109/IPDPS.2002.1016475
Filename
1016475
Link To Document