Evaluating Computer Intrusion Detection Systems: A Survey of Common Practices

Published: 29 September 2015


The evaluation of computer intrusion detection systems (which we refer to as intrusion detection systems) is an active research area. In this article, we survey and systematize common practices in the area of evaluation of such systems. For this purpose, we define a design space structured into three parts: workload, metrics, and measurement methodology. We then provide an overview of the common practices in evaluation of intrusion detection systems by surveying evaluation approaches and methods related to each part of the design space. Finally, we discuss open issues and challenges focusing on evaluation methodologies for novel intrusion detection systems.

Published: 29 September 2015

Published: 29 September 2015
Accepted: 01 June 2015
Revised: 01 March 2015
Received: 01 October 2014
Published in CSUR Volume 48, Issue 1


Author Tags

  1. Computer intrusion detection systems
  2. measurement methodology
  3. metrics
  4. workload generation


