Discussion:
Using Network Sniffers on DARPA Dataset
(too old to reply)
Divyata
2006-12-06 17:00:24 UTC
Permalink
I am doing a project on Computer Immune System, and I am not able to
decipher the importance of all the different files in the DARPA
dataset. There are the "bsm.list" files, "pascal.bsm" files,
"pascal.praudit" files, "pascal.psmonitor" files, "tcpdump" files, and
the "tcpdump.list" files. I am aware that the "tcpdump" file is the
most widely used, but on what basis is the decision made as to which
file to use?

Also, I am using the TCPDUMP file of the DARPA dataset.
(outside.tcmpdump) for my Intrusion Detection System. But, I am not
able to figure how to use the tcpdump files. I am aware that they can
be analyzed using network sniffers, and am trying to use Ethereal for
the same (I am working on Windows platform), but when Ethereal loads
around 80% of the "outside.tcpdump" file (this is the one I have to
use, right???), it says that the Virtual Memory is too low, and exits.
What shall I do??? Please help..................
David P. Drake
2006-12-11 17:24:10 UTC
Permalink
Ethereal is dead. You need to switch to WireShark
<www.wireshark.org>. Same developer, just working for a different
company and his old company would not let him keep the name. As to
your question. Perhaps someone else can help.

Dave.
Post by Divyata
I am doing a project on Computer Immune System, and I am not able to
decipher the importance of all the different files in the DARPA
dataset. There are the "bsm.list" files, "pascal.bsm" files,
"pascal.praudit" files, "pascal.psmonitor" files, "tcpdump" files, and
the "tcpdump.list" files. I am aware that the "tcpdump" file is the
most widely used, but on what basis is the decision made as to which
file to use?
Also, I am using the TCPDUMP file of the DARPA dataset.
(outside.tcmpdump) for my Intrusion Detection System. But, I am not
able to figure how to use the tcpdump files. I am aware that they can
be analyzed using network sniffers, and am trying to use Ethereal for
the same (I am working on Windows platform), but when Ethereal loads
around 80% of the "outside.tcpdump" file (this is the one I have to
use, right???), it says that the Virtual Memory is too low, and exits.
What shall I do??? Please help..................
David P. Drake, Contractor
Sr. Database Administrator
DTPCC
301-846-5285

Loading...