Miroslav, could you briefly explain what are the contents of the datasets? OSSEC is a log analysis based HIDS based on signatures (rules). It also has a module to detect malware/rookits that looks for hidden processes, suspicious files, registry keys etc.
On Wed, Aug 26, 2015 at 9:03 AM, dan (ddp) <[email protected]> wrote: > On Wed, Aug 26, 2015 at 11:35 AM, 'Miroslav S' via ossec-list > <[email protected]> wrote: > > Hello everyone. > > > > I have been tasked to test effectiveness of OSSEC HIDS (by effectiveness > I > > mean detection rate it achieves as well as false positives rate) when a > > dataset of raw system call traces are used. > > > > The dataset itself is the AFDA-LD dataset which can be found here > > http://www.cybersecurity.unsw.adfa.edu.au/ADFA%20IDS%20Datasets/ > > > > This dataset consists of 3 groups of raw system call traces generated > with > > auditd UNIX program: > > > > 1. Normal training data > > 2. Normal validation data > > 3. Attack data. > > > > The method used to perform this task is irrelevant as long as I manage to > > use this particular dataset with OSSEC. > > > > > > So far I have the latest version of OSSEC installed on Ubuntu 14.04. I > > suppose that in order to perform my task, OSSEC should first be trained > > using the normal training data of the dataset and then tested for false > > positives using the normal validation data and for attack detection using > > the attack data. I am however quite new when it comes to OSSEC and IDS in > > general so I could very easily be wrong when it comes to that assumption. > > > > > > So my question is - Can OSSEC be trained and tested with raw system call > > traces in the first place, and if yes, how? If not, can the data from > this > > particular dataset be used in any other way in order to test > effectiveness > > of OSSEC? > > > > I don't see anything in the data that would be all that useful to OSSEC. > > > > > Thank you > > > > Miroslav > > > > -- > > > > --- > > You received this message because you are subscribed to the Google Groups > > "ossec-list" group. > > To unsubscribe from this group and stop receiving emails from it, send an > > email to [email protected]. > > For more options, visit https://groups.google.com/d/optout. > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
