NBTRL: A Software Platform for Network Background Traffic Replay Based on Log
Zhao Kuo, Kuo Tang, Chu Jianfeng, Hu Liang · 2006
While the use of intrusion detection system (IDS), which monitors passively specific computing resources, and reports anomalous or intrusive activities, is becoming ubiquitous in today's network, evaluating IDS performance has been found to be challenging. Most IDS testing approaches are faced with selections with regard to their use of background traffic, which plays an important role in IDS testing. This paper presents the design and implementation of NBTRL, a software platform for network background traffic replay based on log files applied to IDS testing. NBTRL consists of information extraction module, packet preprocessing module and replay module. This software platform can extract traffic information from log files, control the speed of background traffic replay, process truncated packets, modify MAC address or IP address of packets, and provide a flexible and reusable experimental environment for IDS testing.