2019/05/01 by Carlos García Cordero, Cordero, Carlos Garcia, Emmanouil Vasilomanolakis +7 · 5 citations
Computer Science · #Network Security and Intrusion Detection #Internet Traffic Analysis and Secure E-voting #Anomaly Detection Techniques and Applications
paper · pdf · doi:10.48550/arxiv.1905.00304
Most research in the area of intrusion detection requires datasets to\ndevelop, evaluate or compare systems in one way or another. In this field,\nhowever, finding suitable datasets is a challenge on to itself. Most publicly\navailable datasets have negative qualities that limit their usefulness. In this\narticle, we propose ID2T (Intrusion Detection Dataset Toolkit) to tackle this\nproblem. ID2T facilitates the creation of labeled datasets by injecting\nsynthetic attacks into background traffic. The injected synthetic attacks blend\nthemselves with the background traffic by mimicking the background traffic's\nproperties to eliminate any trace of ID2T's usage.\n This work has three core contribution areas. First, we present a\ncomprehensive survey on intrusion detection datasets. In the survey, we propose\na classification to group the negative qualities we found in the datasets.\nSecond, the architecture of ID2T is revised, improved and expanded. The\narchitectural changes enable ID2T to inject recent and advanced attacks such as\nthe widespread EternalBlue exploit or botnet communication patterns. The\ntoolkit's new functionality provides a set of tests, known as TIDED (Testing\nIntrusion Detection Datasets), that help identify potential defects in the\nbackground traffic into which attacks are injected. Third, we illustrate how\nID2T is used in different use-case scenarios to evaluate the performance of\nanomaly and signature-based intrusion detection systems in a reproducible\nmanner. ID2T is open source software and is made available to the community to\nexpand its arsenal of attacks and capabilities.\n