LLSIM: Network simulation for correlation and response testing

被引:2
作者
Haines, JW
Goulet, SA
Durst, RS
Champion, TG
机构
来源
IEEE SYSTEMS, MAN AND CYBERNETICS SOCIETY INFORMATION ASSURANCE WORKSHOP | 2003年
关键词
simulation; IDS sensors; network modeling;
D O I
10.1109/SMCSIA.2003.1232429
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Lincoln Laboratory Simulator, LLSIM, is an easily configurable network simulator that can produce a wide variety of data sets without expensive testbeds. These data sets are useful for researchers who are developing general-purpose correlation and response systems. LLSIM is a Java-based, event-driven simulator consisting of user-configurable core models of networks and hosts. Event generators produce network and host events in the simulated system and models of intrusion detection sensors generate realistic streams of alerts in relation to these events. On a typical PC workstation, LLSIM can emulate arbitrary networks with hundreds of nodes and communication links, and can accurately simulate hundreds of intrusion detection sensors operating in these environments. Researchers can generate many different datasets using LLSIM and can also evaluate the effectiveness of simple response actions like altering firewall policies in response to an attack. Sensor alert datasets generated by LLSIM have been used in the DARPA Cyber Panel program.
引用
收藏
页码:243 / 250
页数:8
相关论文
共 12 条
[1]  
GIOVANNI C, FUN PACKETS DESIGNIN
[2]  
GOLDMAN RP, P DARPA INF SURV C 2, V1, P329
[3]  
Haines JW, 2001, DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL I, PROCEEDINGS, P35, DOI 10.1109/DISCEX.2001.932190
[4]  
Jorgensen J, 2001, DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL II, PROCEEDINGS, P287, DOI 10.1109/DISCEX.2001.932180
[5]   The 1999 DARPA off-line intrusion detection evaluation [J].
Lippmann, R ;
Haines, JW ;
Fried, DJ ;
Korba, J ;
Das, K .
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2000, 34 (04) :579-595
[6]  
*NS, LBNL NETW SIM
[7]  
ROSSEY L, P 2002 AER C, V6, P2671
[8]  
SHEYNER J, P 2002 IEEE S SEC PR, P273
[9]  
Templeton S.J., 2000, P NEW SEC PAR WORKSH
[10]  
VALDES, P REC ADV INTR DET 2, P54