WinNTGen : Creation of a Windows NT 5.0+ network traffic generator
Thesis (M.Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, 2003. === Includes bibliographical references (leaves 65-67). === The Lincoln Adaptable Real Time Information Assurance Testbed (LARIAT) project is the first fully automatable network testbe...
Main Author: | |
---|---|
Other Authors: | |
Format: | Others |
Language: | English |
Published: |
Massachusetts Institute of Technology
2006
|
Subjects: | |
Online Access: | http://hdl.handle.net/1721.1/29667 |
id |
ndltd-MIT-oai-dspace.mit.edu-1721.1-29667 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-MIT-oai-dspace.mit.edu-1721.1-296672019-05-02T15:47:45Z WinNTGen : Creation of a Windows NT 5.0+ network traffic generator Boothe-Rabek, Jesse C. (Jesse Clayton), 1979- Robert K. Cunningham. Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science. Massachusetts Institute of Technology. Dept. of Electrical Engineering and Computer Science. Electrical Engineering and Computer Science. Thesis (M.Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, 2003. Includes bibliographical references (leaves 65-67). The Lincoln Adaptable Real Time Information Assurance Testbed (LARIAT) project is the first fully automatable network testbed for the evaluation of information assurance (IA) technologies. It allows researchers to easily set up experiments that evaluate the accuracy of host-based and network-based intrusion detection systems (IDSs). Initially, the network traffic it could produce used UNIX services and protocols as implemented for the Linux and Solaris platforms. However, due to the widespread deployment of Windows-based systems in production environments, it is necessary to include Windows-based traffic when testing IA systems in order to provide a comprehensive evaluation. This thesis describes WinNTGen, a Windows network traffic generation system that integrates into the existing LARIAT framework and enables it to produce Windows-based network traffic. To do this, WinNTGen simulates the actions of a user controlling applications that in turn use network resources. This frees WinNTGen from the need to re-implement network protocols and allows it to operate at a higher level of abstraction. WinNTGen controls applications via loadable libraries that encapsulate the manner in which a typical user interacts with a particular application. The statistical parameters that specify the behavior of a user with each application are derived from real users' behavioral data as they interacted with each application. The system is flexible and extensible so that different versions of the same application as well as additional applications can be controlled by modifying and adding libraries. Finally, the reality and the throughput of the network traffic produced by the WinNTGen system are evaluated. by Jesse C. Boothe-Rabek. M.Eng. 2006-03-24T16:13:20Z 2006-03-24T16:13:20Z 2003 2003 Thesis http://hdl.handle.net/1721.1/29667 53827739 eng M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission. http://dspace.mit.edu/handle/1721.1/7582 67 leaves 2449231 bytes 2449040 bytes application/pdf application/pdf application/pdf Massachusetts Institute of Technology |
collection |
NDLTD |
language |
English |
format |
Others
|
sources |
NDLTD |
topic |
Electrical Engineering and Computer Science. |
spellingShingle |
Electrical Engineering and Computer Science. Boothe-Rabek, Jesse C. (Jesse Clayton), 1979- WinNTGen : Creation of a Windows NT 5.0+ network traffic generator |
description |
Thesis (M.Eng.)--Massachusetts Institute of Technology, Dept. of Electrical Engineering and Computer Science, 2003. === Includes bibliographical references (leaves 65-67). === The Lincoln Adaptable Real Time Information Assurance Testbed (LARIAT) project is the first fully automatable network testbed for the evaluation of information assurance (IA) technologies. It allows researchers to easily set up experiments that evaluate the accuracy of host-based and network-based intrusion detection systems (IDSs). Initially, the network traffic it could produce used UNIX services and protocols as implemented for the Linux and Solaris platforms. However, due to the widespread deployment of Windows-based systems in production environments, it is necessary to include Windows-based traffic when testing IA systems in order to provide a comprehensive evaluation. This thesis describes WinNTGen, a Windows network traffic generation system that integrates into the existing LARIAT framework and enables it to produce Windows-based network traffic. To do this, WinNTGen simulates the actions of a user controlling applications that in turn use network resources. This frees WinNTGen from the need to re-implement network protocols and allows it to operate at a higher level of abstraction. WinNTGen controls applications via loadable libraries that encapsulate the manner in which a typical user interacts with a particular application. The statistical parameters that specify the behavior of a user with each application are derived from real users' behavioral data as they interacted with each application. The system is flexible and extensible so that different versions of the same application as well as additional applications can be controlled by modifying and adding libraries. Finally, the reality and the throughput of the network traffic produced by the WinNTGen system are evaluated. === by Jesse C. Boothe-Rabek. === M.Eng. |
author2 |
Robert K. Cunningham. |
author_facet |
Robert K. Cunningham. Boothe-Rabek, Jesse C. (Jesse Clayton), 1979- |
author |
Boothe-Rabek, Jesse C. (Jesse Clayton), 1979- |
author_sort |
Boothe-Rabek, Jesse C. (Jesse Clayton), 1979- |
title |
WinNTGen : Creation of a Windows NT 5.0+ network traffic generator |
title_short |
WinNTGen : Creation of a Windows NT 5.0+ network traffic generator |
title_full |
WinNTGen : Creation of a Windows NT 5.0+ network traffic generator |
title_fullStr |
WinNTGen : Creation of a Windows NT 5.0+ network traffic generator |
title_full_unstemmed |
WinNTGen : Creation of a Windows NT 5.0+ network traffic generator |
title_sort |
winntgen : creation of a windows nt 5.0+ network traffic generator |
publisher |
Massachusetts Institute of Technology |
publishDate |
2006 |
url |
http://hdl.handle.net/1721.1/29667 |
work_keys_str_mv |
AT bootherabekjessecjesseclayton1979 winntgencreationofawindowsnt50networktrafficgenerator |
_version_ |
1719028255705530368 |