TL;DR
This paper introduces SOCBED, a reproducible and adaptable testbed for generating realistic cybersecurity log data, addressing reproducibility and customization challenges in cybersecurity research.
Contribution
The paper presents SOCBED, the first testbed designed specifically for reproducible and adaptable cybersecurity log data generation, facilitating valid and controlled experiments.
Findings
SOCBED enables reproduction of testbed instances on commodity hardware.
The generated log data supports realistic cybersecurity experiments.
Experiments using SOCBED are validated as valid, controlled, and reproducible.
Abstract
Artifacts such as log data and network traffic are fundamental for cybersecurity research, e.g., in the area of intrusion detection. Yet, most research is based on artifacts that are not available to others or cannot be adapted to own purposes, thus making it difficult to reproduce and build on existing work. In this paper, we identify the challenges of artifact generation with the goal of conducting sound experiments that are valid, controlled, and reproducible. We argue that testbeds for artifact generation have to be designed specifically with reproducibility and adaptability in mind. To achieve this goal, we present SOCBED, our proof-of-concept implementation and the first testbed with a focus on generating realistic log data for cybersecurity experiments in a reproducible and adaptable manner. SOCBED enables researchers to reproduce testbed instances on commodity computers, adapt…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
