Defining categories to select representative attack test-cases

  • Authors:
  • Mohammed S. GADELRAB;Anas Abou El Kalam;Yves Deswarte

  • Affiliations:
  • LAAS-CNRS, Toulouse, France;INP/ENSEEIHT, Toulouse, France;LAAS-CNRS, Toulouse, France

  • Venue:
  • Proceedings of the 2007 ACM workshop on Quality of protection
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

To ameliorate the quality of protection provided by intrusion detection systems (IDS) we strongly need more effective evaluation and testing procedures. Evaluating an IDS against all known and unknown attacks is probably impossible. Nevertheless, a sensible selection of representative attacks is necessary to obtain an unbiased evaluation of such systems. To overcome the problem of an unmanageably large set of possible inputs, software testers usually divide the data input domain into categories (or equivalence classes), and select representative instances from each category as test cases. We believe that the same principle could be applied to IDS testing if we have a reasonable classification. In this paper we make a thorough analysis of existing attack classifications in order to determine whether they could be helpful in selecting attack test cases. Then, we construct a new scheme to classify attacks relying on those attributes that appear to be the best classification criteria.