@se-group

Evaluating Computer Intrusion Detection Systems: A Survey of Common Practices

, , , , and . ACM Computing Surveys, 48 (1): 12:1--12:41 (September 2015)<b>5-year Impact Factor (2014): 5.949</b>.

Abstract

The evaluation of computer intrusion detection systems (which we refer to as intrusion detection systems) is an active research area. In this paper, we survey and systematize common practices in the area of evaluation of intrusion detection systems. For this purpose, we define a design space structured into three parts: workload, metrics, and measurement methodology. We then provide an overview of the common practices in evaluation of intrusion detection systems by surveying evaluation approaches and methods related to each part of the design space. Finally, we discuss open issues and challenges focusing on evaluation methodologies for novel intrusion detection systems.

Links and resources

Tags

community