Skip to main navigation Skip to search Skip to main content

Attack traffic libraries for testing and teaching intrusion detection systems

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Various attack traffic libraries have been available for quite some time. However, a majority of these libraries contain additional miscellaneous or highly unorganized network traffic. Our research aims at creating a framework for building small, clean, reusable, attack specific network captures. These captures can be used for teaching intrusion detection system monitoring, access control list creation, device configuration, and testing. The lack of organized individual attack captures makes finding specific examples of attack traffic difficult. Our work takes the concept of attack traffic libraries and builds on it. The PCAP Attack Library (PAL) that we have created is simple to use and easily expandable. We captured individual examples of attack traffic and classified each attack according to the Common Attack Pattern Enumeration and Classification (CAPEC) library. Each of our cataloged attacks include; a re-playable traffic file, a corresponding CAPEC attack identification number for obtaining further attack details, and a working Snort Intrusion Detection System rule (SIDSr) which can be used to detect the specific attack. A framework for cataloging and extending the PCACP Attack Library is also presented. This work is equally valuable to instructors and professionals responsible for maintaining an intrusion detection system. Educators and professionals now have access to specific replayable attack traffic without needing the original tools or knowledge required to create the attack.

Original languageEnglish (US)
Title of host publicationIMCIC 2011 - 2nd International Multi-Conference on Complexity, Informatics and Cybernetics, Proceedings
EditorsHsing-Wei Chu, Nagib C. Callaos, C. Dale Zinn, William Lesso, Friederich Welsch, Michael J. Savoie
PublisherInternational Institute of Informatics and Systemics, IIIS
Pages155-160
Number of pages6
ISBN (Electronic)9781936338269
StatePublished - 2011
Externally publishedYes
Event2nd International Multi-Conference on Complexity, Informatics and Cybernetics, IMCIC 2011 - Orlando, United States
Duration: Mar 27 2011Mar 30 2011

Publication series

NameIMCIC 2011 - 2nd International Multi-Conference on Complexity, Informatics and Cybernetics, Proceedings
Volume2

Conference

Conference2nd International Multi-Conference on Complexity, Informatics and Cybernetics, IMCIC 2011
Country/TerritoryUnited States
CityOrlando
Period3/27/113/30/11

Keywords

  • Attack Library
  • CAPEC
  • Education
  • Ethical hacking
  • Intrusion detection
  • Network attack traffic
  • Network security
  • PCAP
  • Snort

ASJC Scopus subject areas

  • Artificial Intelligence
  • Information Systems
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Attack traffic libraries for testing and teaching intrusion detection systems'. Together they form a unique fingerprint.

Cite this