Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.08k stars 522 forks source link

Add "mucus" tool #128

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
http://www.cs.ucsb.edu/~seclab/projects/mucus/index.html

"Signature-based intrusion detection systems use a set of attack descriptions 
to analyze event streams, looking for evidence of malicious behavior. If the 
signatures are expressed in a well-defined language, it is possible to analyze 
the attack signatures and automatically generate events or series of events 
that conform to the attack descriptions. This approach has been used in tools 
whose goal is to force intrusion detection systems to generate a large number 
of detection alerts. The resulting "alert storm" is used to desensitize 
intrusion detection system administrators and hide attacks in the event stream. 
We apply a similar technique to perform testing of intrusion detection systems. 
Signatures from one intrusion detection system are used as input to an event 
stream generator that produces randomized synthetic events that match the input 
signatures. The resulting event stream is then fed to a number of different 
intrusion detection systems and the results are analyzed.

Mucus-1 is our first Mucus prototype traffic generation tool, designed to test 
network IDSs against traffic corresponding to Snort rules. Below, source code 
and Linux binary versions of Mucus-1 are available for download."

Original issue reported on code.google.com by doug.bu...@gmail.com on 4 Oct 2011 at 6:29

GoogleCodeExporter commented 9 years ago
where can i download the tool?

Original comment by flyawayt...@gmail.com on 19 Mar 2013 at 7:10

GoogleCodeExporter commented 9 years ago
Good question.  Looks like 
http://www.cs.ucsb.edu/~seclab/projects/mucus/index.html has been taken down.  
Closing this issue.

Original comment by doug.bu...@gmail.com on 19 Mar 2013 at 9:50

GoogleCodeExporter commented 9 years ago
Oh no,I need the Mucus,can someone help me?

Original comment by flyawayt...@gmail.com on 19 Mar 2013 at 12:18