|
|
|
A Methodology for Evaluation of Host-Based Intrusion Prevention Systems and Its ApplicationKeith Labbe, Neil Rowe and J. D. FulpThe 7th IEEE Information Assurance Workshop (IAWorkshop 2006)West Point, New York, USA, June 21-23, 2006
AbstractHost-based intrusion-prevention systems are recently popular technologies which attempt to prevent the exploits from succeeding on the host they protect. This research developed a methodology for testing them, and applied it to two current products, McAfee Entercept and the Cisco Security Agent. Our tests used live viruses, worms, Trojan horses, and remote exploits which were turned loose on an isolated two-computer network. The computers were networked together using a crossover cable and no other network connections were used. This configuration allowed us to use live exploits without infecting other computers or being affected by their traffic.
|
|