<div class="csl-bib-body">
<div class="csl-entry">Landauer, M., Frank, M., Skopik, F., Hotwagner, W., Wurzenberger, M., & Rauber, A. (2022). A Framework for Automatic Labeling of Log Datasets from Model-driven Testbeds for HIDS Evaluation. In <i>Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems</i> (pp. 77–86). Association for Computing Machinery. https://doi.org/10.1145/3510547.3517924</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/230294
-
dc.description.abstract
Intrusion detection systems are essential for network security. To verify their detection capabilities and facilitate comparison, benchmark log datasets are used to measure evaluation metrics such as accuracy and false alarm rates. Thereby, it is necessary that these datasets come with a correct ground truth that differentiates normal and attacker behavior. While it is relatively straightforward to generate labels for network-based datasets by selecting events according to IP addresses of attacker hosts, system logs do not necessarily involve such identifiers and are possibly only recognizable as malicious by their combined occurrences. Even more problems emerge when log data is collected in model-driven testbeds, i.e., automatically generated networks that simulate differently parameterized attack scenarios in diverse infrastructures. In these testbeds, parameters such as IP addresses are subject to change and thus cannot simply be used for matching. We thus propose a framework that integrates template-based labeling rules for model-driven testbeds. In this paper we describe the syntax for rule templates with different query types specifically designed to match sequential or interrelated system log events. An evaluation of our open-source implementation shows that only 27 rules are necessary to assign 15 labels to 8 system log files containing attack manifestations.
en
dc.language.iso
en
-
dc.subject
Detection rules
en
dc.subject
Intrusion detection
en
dc.subject
Log data analysis
en
dc.subject
Log testbed
en
dc.title
A Framework for Automatic Labeling of Log Datasets from Model-driven Testbeds for HIDS Evaluation
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
Austrian Institute of Technology, Austria
-
dc.contributor.affiliation
Austrian Institute of Technology, Austria
-
dc.contributor.affiliation
Austrian Institute of Technology, Austria
-
dc.contributor.affiliation
Austrian Institute of Technology, Austria
-
dc.contributor.affiliation
Austrian Institute of Technology, Austria
-
dc.relation.isbn
978-1-4503-9229-7
-
dc.description.startpage
77
-
dc.description.endpage
86
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems
-
tuw.relation.publisher
Association for Computing Machinery
-
tuw.relation.publisherplace
New York
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
100
-
tuw.publication.orgunit
E194-04 - Forschungsbereich Data Science
-
tuw.publication.orgunit
E057-09 - Fachbereich ASC Research Center
-
tuw.publisher.doi
10.1145/3510547.3517924
-
dc.description.numberOfPages
10
-
tuw.author.orcid
0000-0003-3813-3151
-
tuw.author.orcid
0000-0002-1922-7892
-
tuw.author.orcid
0000-0003-3259-6972
-
tuw.author.orcid
0000-0002-9272-6225
-
tuw.event.name
2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems
en
tuw.event.startdate
27-04-2022
-
tuw.event.enddate
27-04-2022
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Baltimore
-
tuw.event.country
US
-
tuw.event.presenter
Landauer, Max
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Wirtschaftswissenschaften
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
5020
-
wb.sciencebranch.value
90
-
wb.sciencebranch.value
10
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.grantfulltext
none
-
item.openairetype
conference paper
-
item.languageiso639-1
en
-
item.fulltext
no Fulltext
-
item.cerifentitytype
Publications
-
crisitem.author.dept
Austrian Institute of Technology, Austria
-
crisitem.author.dept
Austrian Institute of Technology, Austria
-
crisitem.author.dept
Austrian Institute of Technology, Austria
-
crisitem.author.dept
Austrian Institute of Technology, Austria
-
crisitem.author.dept
Austrian Institute of Technology, Austria
-
crisitem.author.dept
E194-04 - Forschungsbereich Data Science
-
crisitem.author.orcid
0000-0003-3813-3151
-
crisitem.author.orcid
0000-0002-1922-7892
-
crisitem.author.orcid
0000-0003-3259-6972
-
crisitem.author.orcid
0000-0002-9272-6225
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering