Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

Analysis and Results of the 1999 DARPA Off-Line Intrusion Detection Evaluation

Richard LippmannContact Information, Joshua W. HainesContact Information, David J. Fried7, Jonathan Korba7 and Kumar Das7

(7)  MIT Lincoln Laboratory, 244 Wood Street, Lexington, MA 02173-9108, USA
Abstract
Eight sites participated in the second DARPA off-line intrusion detection evaluation in 1999. Three weeks of training and two weeks of test data were generated on a test bed that emulates a small government site. More than 200 instances of 58 attack types were launched against victim UNIX and Windows NT hosts. False alarm rates were low (less than 10 per day). Best detection was provided by network-based systems for old probe and old denial-of-service (DoS) attacks and by host-based systems for Solaris user-to-root (U2R) attacks. Best overall performance would have been provided by a combined system that used both host- and network-based intrusion detection. Detection accuracy was poor for previously unseen new, stealthy, and Windows NT attacks. Ten of the 58 attack types were completely missed by all systems. Systems missed attacks because protocols and TCP services were not analyzed at all or to the depth required, because signatures for old attacks did not generalize to new attacks, and because auditing was not available on all hosts.

Contact Information Richard Lippmann
Email: rpl@sst.ll.mit.edu

Contact Information Joshua W. Haines
Email: jhaines@sst.ll.mit.edu
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Referenced by
2 newer articles

  1. Le, Tung (2008) . IEEE Transactions on Information Forensics and Security 3(3)
    [CrossRef]
  2. Hwang, Kai (2007) . IEEE Transactions on Dependable and Secure Computing 4(1)
    [CrossRef]
Remote Address: 38.107.191.108 • Server: MPWEB25
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)