On Thu, Aug 27, 2015 at 4:44 AM, 'Miroslav S' via ossec-list
<[email protected]> wrote:
> Well from what I gathered from the dataset documentation, the contents of
> these datasets are system call traces. They have been generated on a test
> system during normal activities of the host which ranged from web browsing
> to latex document preparation, and there's approximately 800 traces used for
> training data and approximately 4000 used for validation data, and there's
> the attack traces too representing 6 different methods of attacks
>
> However, while reading up the documentation of the dataset just now I came
> across the following:
>
>  "The ADFA-LD12 is designed for anomaly based systems, not signature
> recognition IDS"
>
>  And since OSSEC is based on signatures, it looks to me that this dataset is
> in fact useless for my task. Am I correct in that assumption?
>

OSSEC currently has no facilities to interpret that data.

> On Wednesday, August 26, 2015 at 9:31:28 PM UTC+2, Santiago Bassett wrote:
>>
>> Miroslav, could you briefly explain what are the contents of the datasets?
>> OSSEC is a log analysis based HIDS based on signatures (rules). It also has
>> a module to detect malware/rookits that looks for hidden processes,
>> suspicious files, registry keys etc.
>>
>> On Wed, Aug 26, 2015 at 9:03 AM, dan (ddp) <[email protected]> wrote:
>>>
>>> On Wed, Aug 26, 2015 at 11:35 AM, 'Miroslav S' via ossec-list
>>> <[email protected]> wrote:
>>> > Hello everyone.
>>> >
>>> > I have been tasked to test effectiveness of OSSEC HIDS (by
>>> > effectiveness I
>>> > mean detection rate it achieves as well as false positives rate) when a
>>> > dataset of raw system call traces are used.
>>> >
>>> > The dataset itself is the AFDA-LD dataset which can be found here
>>> > http://www.cybersecurity.unsw.adfa.edu.au/ADFA%20IDS%20Datasets/
>>> >
>>> > This dataset consists of 3 groups of raw system call traces generated
>>> > with
>>> > auditd UNIX program:
>>> >
>>> > 1. Normal training data
>>> > 2. Normal validation data
>>> > 3. Attack data.
>>> >
>>> > The method used to perform this task is irrelevant as long as I manage
>>> > to
>>> > use this particular dataset with OSSEC.
>>> >
>>> >
>>> > So far I have the latest version of OSSEC installed on Ubuntu 14.04. I
>>> > suppose that in order to perform my task, OSSEC should first be trained
>>> > using the normal training data of the dataset and then tested for false
>>> > positives using the normal validation data and for attack detection
>>> > using
>>> > the attack data. I am however quite new when it comes to OSSEC and IDS
>>> > in
>>> > general so I could very easily be wrong when it comes to that
>>> > assumption.
>>> >
>>> >
>>> > So my question is - Can OSSEC be trained and tested with raw system
>>> > call
>>> > traces in the first place, and if yes, how? If not, can the data from
>>> > this
>>> > particular dataset be used in any other way in order to test
>>> > effectiveness
>>> > of OSSEC?
>>> >
>>>
>>> I don't see anything in the data that would be all that useful to OSSEC.
>>>
>>> >
>>> > Thank you
>>> >
>>> > Miroslav
>>> >
>>> > --
>>> >
>>> > ---
>>> > You received this message because you are subscribed to the Google
>>> > Groups
>>> > "ossec-list" group.
>>> > To unsubscribe from this group and stop receiving emails from it, send
>>> > an
>>> > email to [email protected].
>>> > For more options, visit https://groups.google.com/d/optout.
>>>
>>> --
>>>
>>> ---
>>> You received this message because you are subscribed to the Google Groups
>>> "ossec-list" group.
>>> To unsubscribe from this group and stop receiving emails from it, send an
>>> email to [email protected].
>>> For more options, visit https://groups.google.com/d/optout.
>>
>>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to