Paper
17 March 2008 Usefulness of DARPA dataset for intrusion detection system evaluation
Ciza Thomas, Vishwas Sharma, N. Balakrishnan
Author Affiliations +
Abstract
The MIT Lincoln Laboratory IDS evaluation methodology is a practical solution in terms of evaluating the performance of Intrusion Detection Systems, which has contributed tremendously to the research progress in that field. The DARPA IDS evaluation dataset has been criticized and considered by many as a very outdated dataset, unable to accommodate the latest trend in attacks. Then naturally the question arises as to whether the detection systems have improved beyond detecting these old level of attacks. If not, is it worth thinking of this dataset as obsolete? The paper presented here tries to provide supporting facts for the use of the DARPA IDS evaluation dataset. The two commonly used signature-based IDSs, Snort and Cisco IDS, and two anomaly detectors, the PHAD and the ALAD, are made use of for this evaluation purpose and the results support the usefulness of DARPA dataset for IDS evaluation.
© (2008) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Ciza Thomas, Vishwas Sharma, and N. Balakrishnan "Usefulness of DARPA dataset for intrusion detection system evaluation", Proc. SPIE 6973, Data Mining, Intrusion Detection, Information Assurance, and Data Networks Security 2008, 69730G (17 March 2008); https://doi.org/10.1117/12.777341
Lens.org Logo
CITATIONS
Cited by 62 scholarly publications.
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Computer intrusion detection

Sensors

Detection and tracking algorithms

Data modeling

Picosecond phenomena

Analytical research

Computer networks

Back to Top