首页> 外国专利> Systems and methods for testing and evaluating an intrusion detection system

Systems and methods for testing and evaluating an intrusion detection system

机译:用于测试和评估入侵检测系统的系统和方法

摘要

Systems, methods and devices according to this invention include a plurality of defined modification rules for modifying a sequence of packets that form an attack on an intrusion detection system. These modification rules include both rules that expand the number of packets and rules that reduce the number of packets. The reducing rules can be applied to a given attack instance to identify one or more root attack instances. The expanding rules can then be applied to each root attack instance to generate a corpus of modified attack instances. The modification rules can preserve the semantics of the attack, so that any modified attack instance generated from the given attack instance remains a true attack. To test an intrusion detection system, the corpus of modified attack instances can be used to determine whether an intrusion detection system detects every modified attack instance.
机译:根据本发明的系统,方法和设备包括多个定义的修改规则,用于修改对入侵检测系统构成攻击的分组序列。这些修改规则既包括扩大数据包数量的规则,也包括减少数据包数量的规则。减少规则可以应用于给定的攻击实例,以标识一个或多个根攻击实例。然后可以将扩展规则应用于每个根攻击实例,以生成经过修改的攻击实例的语料库。修改规则可以保留攻击的语义,因此从给定攻击实例生成的任何修改后的攻击实例仍是真正的攻击。为了测试入侵检测系统,可以使用经过修改的攻击实例的语料库来确定入侵检测系统是否检测到每个经过修改的攻击实例。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号