IDS mailing list archives
Re: Intrusion Detection Evaluation Datasets
From: Stefano Zanero <s.zanero () securenetwork it>
Date: Mon, 09 Mar 2009 18:02:01 +0100
zubair.shafiq () yahoo com wrote:
1. CAIDA backscatter dataset (contains reflected suspicious traffic)
This is just reflected backscatter from DoS attacks, how you would use it to evaluate an IDS is beyond me.
2. LBNL/ICSI enterprise router dataset (contains segregated scan and benign traffic)
Just packet traces, anonymized, no content 3. DEFCON 8-10 CTF datasets (contain only attack
traffic during DEFCON competition)
Only attacks, in a non-realistic network
4. UMASS gateway link dataset (is manually labeled by Yu Gu at University of Massachusetts)
See 2
5. Endpoint worm dataset (both benign and worm traffic, logged by argus -- probably the only data available at endpoints)
I can't understand how this was generated or collected. Pointers ?
tricky task. There are two standard ways to create labeled IDS datasets: (1) separately collecting benign and malicious traffic and then injecting to create infected traffic profiles,
Which generates the artifacts present in IDEVAL
(2) collecting data and then labeling it via manual inspection or a combination of heuristics.
Which is a tedious task no one wants to do (manually). What do you mean by heuristics ?
have been working on some semi-automated procedures to label anomalies in network traffic.
Which is the same as developing an anomaly detector. Thus, you are effectively using an anomaly detector to evaluate another, opening up a can of worms you really don't want to open. SZ
Current thread:
- Intrusion Detection Evaluation Datasets snort user (Mar 04)
- Re: Intrusion Detection Evaluation Datasets "Zow" Terry Brugger (Mar 06)
- Re: Intrusion Detection Evaluation Datasets Damiano Bolzoni (Mar 09)
- Re: Intrusion Detection Evaluation Datasets Jamie Riden (Mar 09)
- <Possible follow-ups>
- Re: Re: Intrusion Detection Evaluation Datasets zubair . shafiq (Mar 09)
- Re: Intrusion Detection Evaluation Datasets Stefano Zanero (Mar 09)
- Re: Re: Intrusion Detection Evaluation Datasets zubair . shafiq (Mar 10)
- Re: Intrusion Detection Evaluation Datasets Stefano Zanero (Mar 11)
- Re: Intrusion Detection Evaluation Datasets "Zow" Terry Brugger (Mar 12)
- Re: Intrusion Detection Evaluation Datasets Paul Palmer (Mar 12)
- Re: Intrusion Detection Evaluation Datasets Stuart Staniford (Mar 13)
- Re: Intrusion Detection Evaluation Datasets Stefano Zanero (Mar 13)
- Re: Intrusion Detection Evaluation Datasets "Zow" Terry Brugger (Mar 13)
- Re: Intrusion Detection Evaluation Datasets Paul Palmer (Mar 13)
- Re: Intrusion Detection Evaluation Datasets Stefano Zanero (Mar 13)
- Re: Intrusion Detection Evaluation Datasets Paul Palmer (Mar 13)
- Re: Intrusion Detection Evaluation Datasets Stefano Zanero (Mar 11)
