Less Is More: Host-Agent Based Simulator For Large-Scale Evaluation Of Security Systems

Computer Security - ESORICS 2014(2014)

引用 5|浏览42
暂无评分
摘要
Recently proposed network security systems have demonstrated the benefits of scale for achieving many security goals, including the detection of worm outbreaks, botnets, and denial of service attacks. However, scale is also a barrier to further advancement of such systems: obtaining and working with appropriately large data sets is difficult, and existing simulation techniques are ill suited for this domain. To overcome these challenges, we propose a host behavior simulator, LESS, designed for evaluating large scale network security systems. LESS build and automatically configures the behaviors of host agents using background traffic samples and malicious traffic models. In turn, host agents communicate with each other throughout a simulation, generating traffic records. We demonstrate the applicability and benefits of LESS by tuning it with publicly available traces, and then using generated records to reproduce results from several recently proposed systems. We also used LESS to extend the evaluations of these systems, highlighting dimensions of large scale security system performance that would be difficult to study without simulation.
更多
查看译文
关键词
Data Challenges,Large Scale Security,Simulation,Agent Based,Stochastic
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要