Network Security White Papers
Recent Advances in Network Intrusion Detection System Tuning
Overview This paper describes a traffic generation framework for online evaluation and tuning network intrusion detection systems over a wide range of realistic conditions. The framework integrates both benign and malicious traffic, enabling generation of IP packet streams with diverse characteristics from the perspective of packet content (both header and payload), packet mix (order of packets in streams) and packet volume (arrival rate of packets in streams). The paper describes a methodology for benign traffic generation that combines payload pools (possibly culled from traces of live traffic) with application-specific automata to generate streams with representative characteristics. It also describes a methodology for malicious traffic generation, and techniques for integration with benign traffic to produce a range of realistic workload compositions.
| Publisher | University of Wisconsin-Madison | File Format | |
|---|---|---|---|
| Date Published | February 2006 | ||
| Format | White Papers | ||
| Topics | |||



