首页> 外文会议>European symposium on research in computer security >LESS Is More: Host-Agent Based Simulator for Large-Scale Evaluation of Security Systems
【24h】

LESS Is More: Host-Agent Based Simulator for Large-Scale Evaluation of Security Systems

机译:更少:基于主机代理的模拟器,用于对安全系统进行大规模评估

获取原文

摘要

Recently proposed network security systems have demonstrated the benefits of scale for achieving many security goals, including the detection of worm outbreaks, botnets, and denial of service attacks. However, scale is also a barrier to further advancement of such systems: obtaining and working with appropriately large data sets is difficult, and existing simulation techniques are ill suited for this domain. To overcome these challenges, we propose a host behavior simulator, LESS, designed for evaluating large scale network security systems. LESS build and automatically configures the behaviors of host agents using background traffic samples and malicious traffic models. In turn, host agents communicate with each other throughout a simulation, generating traffic records. We demonstrate the applicability and benefits of LESS by tuning it with publicly available traces, and then using generated records to reproduce results from several recently proposed systems. We also used LESS to extend the evaluations of these systems, highlighting dimensions of large scale security system performance that would be difficult to study without simulation.
机译:最近建议的网络安全系统已经证明了达到许多安全目标的规模的好处,包括检测蠕虫爆发,僵尸网络和拒绝服务攻击。然而,规模也是这种系统进一步进步的障碍:获得和使用适当大的数据集是困难的,并且存在适合该域的现有仿真技术。为了克服这些挑战,我们提出了一个主机行为模拟器,较少,专为评估大规模网络安全系统而设计。更少的构建并自动使用背景流量样本和恶意流量模型配置主机代理的行为。反过来,主机代理在整个模拟中相互通信,生成流量记录。我们通过用公开的迹线调整它来展示更少的适用性和益处,然后使用生成的记录来重现来自几个最近提出的系统的结果。我们还少少用于扩展这些系统的评估,突出显示大规模安全系统性能的尺寸,而不会模拟难以研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号