Environment Dependent Testing Platform for Intrusion Detection System

碩士 === 中原大學 === 資訊工程研究所 === 90 === Intrusion detection system (IDS) is an important mechanism in protecting computer system security. With assistance of IDS, we can discover abnormal behavior in the network environment and, in response to that, take corresponding actions to deal with it. Many intrus...

Full description

Bibliographic Details
Main Authors: Chun-Hong Chen, 陳俊宏
Other Authors: Hsiao-Rong Tyan
Format: Others
Language:zh-TW
Published: 2002
Online Access:http://ndltd.ncl.edu.tw/handle/59960874832421056602
id ndltd-TW-090CYCU5392007
record_format oai_dc
spelling ndltd-TW-090CYCU53920072015-10-13T17:35:24Z http://ndltd.ncl.edu.tw/handle/59960874832421056602 Environment Dependent Testing Platform for Intrusion Detection System 環境相依之入侵偵測系統測試平台 Chun-Hong Chen 陳俊宏 碩士 中原大學 資訊工程研究所 90 Intrusion detection system (IDS) is an important mechanism in protecting computer system security. With assistance of IDS, we can discover abnormal behavior in the network environment and, in response to that, take corresponding actions to deal with it. Many intrusion detection systems and their merits are different. Users want to know which candidate IDS among the availables will fit their needs best before making a procurement decision, or, if an Intrusion detection system is adapted already, how well it performs. It calls for an evaluation framework that takes the characteristic pertaining individual system and network environment into concern. In this thesis, an Intrusion Detection System testing platform was proposed. With this platform, the performance of various kind of IDSs can be evaluated in the contests of specific network environments. And users can select a proper IDS to protect their network environment according to the testing result. The proposed platform considers the dependence relation between IDS performance and the application environment, since the same IDS may have different detection performance in distinct environments. It consists of three subsystems: Environment Analysis, Test Planning and Log Analysis. The Environment Analysis subsystem examines the characteristic and critical flaws of the application environment. The Test Planning subsystem provides toolkit through an User Interface which allows users to construct specific test profile to their environment. According to the test result, Log Analysis Subsystem produces Receiver Operating Characteristic (ROC) curves of individual IDS. With ROC curves, the relation of detection rate and false alarm rate of an intrusion detection system can be comprehended easily. The proposed platform has been done a series of scanning, auditing and testing against the environment in our laboratory. The result was examined and analyzed. Hsiao-Rong Tyan Shih-Kun Huang 田筱榮 黃世昆 2002 學位論文 ; thesis 84 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 中原大學 === 資訊工程研究所 === 90 === Intrusion detection system (IDS) is an important mechanism in protecting computer system security. With assistance of IDS, we can discover abnormal behavior in the network environment and, in response to that, take corresponding actions to deal with it. Many intrusion detection systems and their merits are different. Users want to know which candidate IDS among the availables will fit their needs best before making a procurement decision, or, if an Intrusion detection system is adapted already, how well it performs. It calls for an evaluation framework that takes the characteristic pertaining individual system and network environment into concern. In this thesis, an Intrusion Detection System testing platform was proposed. With this platform, the performance of various kind of IDSs can be evaluated in the contests of specific network environments. And users can select a proper IDS to protect their network environment according to the testing result. The proposed platform considers the dependence relation between IDS performance and the application environment, since the same IDS may have different detection performance in distinct environments. It consists of three subsystems: Environment Analysis, Test Planning and Log Analysis. The Environment Analysis subsystem examines the characteristic and critical flaws of the application environment. The Test Planning subsystem provides toolkit through an User Interface which allows users to construct specific test profile to their environment. According to the test result, Log Analysis Subsystem produces Receiver Operating Characteristic (ROC) curves of individual IDS. With ROC curves, the relation of detection rate and false alarm rate of an intrusion detection system can be comprehended easily. The proposed platform has been done a series of scanning, auditing and testing against the environment in our laboratory. The result was examined and analyzed.
author2 Hsiao-Rong Tyan
author_facet Hsiao-Rong Tyan
Chun-Hong Chen
陳俊宏
author Chun-Hong Chen
陳俊宏
spellingShingle Chun-Hong Chen
陳俊宏
Environment Dependent Testing Platform for Intrusion Detection System
author_sort Chun-Hong Chen
title Environment Dependent Testing Platform for Intrusion Detection System
title_short Environment Dependent Testing Platform for Intrusion Detection System
title_full Environment Dependent Testing Platform for Intrusion Detection System
title_fullStr Environment Dependent Testing Platform for Intrusion Detection System
title_full_unstemmed Environment Dependent Testing Platform for Intrusion Detection System
title_sort environment dependent testing platform for intrusion detection system
publishDate 2002
url http://ndltd.ncl.edu.tw/handle/59960874832421056602
work_keys_str_mv AT chunhongchen environmentdependenttestingplatformforintrusiondetectionsystem
AT chénjùnhóng environmentdependenttestingplatformforintrusiondetectionsystem
AT chunhongchen huánjìngxiāngyīzhīrùqīnzhēncèxìtǒngcèshìpíngtái
AT chénjùnhóng huánjìngxiāngyīzhīrùqīnzhēncèxìtǒngcèshìpíngtái
_version_ 1717782854180536320