|
ABSTRACT
Network simulators serve a variety of purposes. Compared to the cost, time, and effort involved in setting up an entire test bed containing different types of network devices, network simulators are relatively fast and inexpensive. Computer intrusions are occurring almost routinely and have become a major issue in our networked society. Every organization is faced by the big challenge of selecting an intrusion detection system and testing its abilities. Therefore, it is worthwhile to investigate the possibility of implementing and thoroughly testing intrusion detection systems using network simulators. In this paper, we report our experience with implementing and testing intrusion detection systems using OMNeT++ simulator. We highlight how OMNeT++ is harnessed to test and evaluate the intrusion detection system in terms of detection accuracy and performance.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
International Telecommunication Union --- Telecommunication Standardization Section Recommendation G.114: One-way Transmission Time. May 2003. Retrieved March 2008, from ITU web site: http://www.itu.int.
|
| |
3
|
Mell, P., Hu, V., Lipmann, R., Haines, J., and Zissman, M. 2003 An Overview of Issues in Testing Intrusion Detection Systems. Technical Report. NIST IR 7007, National Institute of Standard and Technology. Available: http://csrc.nist.gov.
|
| |
4
|
MMSim --- Simulation of Multimedia Protocols using OMNeT++. Retrieved January 2008, from http://www.ibr.cs.tu-bs.de/projects/mmsim.
|
| |
5
|
|
| |
6
|
National Laboratory for Applied Network Research 2003. NLAR Network Traffic Packet Header Traces. Available: http://pma.nlanr.net.
|
| |
7
|
OMNeT++ Simulator. Retrieved January 2008, from OMNeT++ web site: http://www.omnetpp.org.
|
| |
8
|
OMNeT++ User Manual. Retrieved October 2008, from OMNeT++ web site: http://www.omnetpp.org/doc/usman.html.
|
| |
9
|
OPNET Modeler. Retrieved June 2008, from OPNET web site: http://www.opnet.com.
|
| |
10
|
|
| |
11
|
Schulzrinne, H. RTP Profile for Audio and Video Conferences with Minimal Control. RFC 1890, IETF Network Working Group. January 1996. Retrieved March 2008, from IETF web site: http://tools.ietf.org.
|
| |
12
|
Sengar, H., Wijesekera, D., Wang, H., and Jajodia, S. 2006 Fast Detection of Denial-of-Service Attacks on IP Telephony. In Proceedings of IEEE Fourteenth International Workshop on Quality of Service, (New Haven, CT, 2006).
|
| |
13
|
|
| |
14
|
The Network Simulator Ns-2. Retrieved March 2008, from Ns-2 web site: http://www.isi.edu/nsnam/ns/.
|
| |
15
|
The NSS Group 2003. Intrusion Detection System Group Test (Edition 4). Available: http://www.nss.co.uk.
|
| |
16
|
Voip-Info.org, QoS, 2004. Available: http://www.voipinfo.org
|
| |
17
|
VOIPSA. VoIP Security and Privacy Threat Taxonomy, October 2005. Available: http://www.voipsa.org.
|
| |
18
|
|
| |
19
|
|
|