{"title":"A method of network workload generation for evaluation of intrusion detection systems in SDN environment","authors":"Damian Jankowski, M. Amanowicz","doi":"10.1109/ICMCIS.2016.7496575","DOIUrl":null,"url":null,"abstract":"Software defined networks create new opportunities for an implementation of the intrusion detection and protection methods. Therefore, special data collections called datasets are necessary for the development, testing and evaluation of such mechanisms. For the SDN environment, there are no prepared datasets that could be used directly to develop IDS methods. These sets contain tuples with features, which represent the activities performed in the IT system. In the presented approach, normal and malicious traffic are generated in the SDN virtual environment. The workload for the dataset is generated in a random manner. The proposed method enables the generation of flows, which can be used for the evaluation of various SDN-based intrusion detection methods.","PeriodicalId":103155,"journal":{"name":"2016 International Conference on Military Communications and Information Systems (ICMCIS)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-05-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 International Conference on Military Communications and Information Systems (ICMCIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICMCIS.2016.7496575","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Software defined networks create new opportunities for an implementation of the intrusion detection and protection methods. Therefore, special data collections called datasets are necessary for the development, testing and evaluation of such mechanisms. For the SDN environment, there are no prepared datasets that could be used directly to develop IDS methods. These sets contain tuples with features, which represent the activities performed in the IT system. In the presented approach, normal and malicious traffic are generated in the SDN virtual environment. The workload for the dataset is generated in a random manner. The proposed method enables the generation of flows, which can be used for the evaluation of various SDN-based intrusion detection methods.