Title :
A metrics-based approach to intrusion detection system evaluation for distributed real-time systems
Author :
G.A. Fink;B.L. Chappell;T.G. Turner;K.F. O´Donoghue
fDate :
6/24/1905 12:00:00 AM
Abstract :
This paper describes a set of metrics that will help administrators of distributed, real-time (clustered) computer facilities to select the best intrusion detection system for their facilities. The metrics herein are the subset of our general metric set that particularly impact real-time and distributed processing issues. We discuss related works in this field, the role of intrusion detection in information assurance, some basic classes of intrusion detection systems, a general architecture of network intrusion detection systems, and the scorecard metrics and their application to real-time and distributed processing systems. Finally we discuss the lessons we learned using a preliminary version of the metric scorecard to test three commercial intrusion detection systems and the opportunities for further work in this area.
Keywords :
"Intrusion detection","Real time systems","Information security","Distributed computing","Distributed processing","Taxonomy","Military computing","System testing","Computer security","Costs"
Conference_Titel :
Parallel and Distributed Processing Symposium., Proceedings International, IPDPS 2002, Abstracts and CD-ROM
Print_ISBN :
0-7695-1573-8
DOI :
10.1109/IPDPS.2002.1016475