Development of a methodology for functional testing of intrusion detection and prevention systems
Abstract
This article discusses the development of a universal, comprehensive testing methodology for intrusion detection and prevention systems, designed to objectively evaluate their effectiveness in the face of increasingly complex network attacks. Existing approaches are often vendor-specific, which hinders independent comparative analysis. The methodology is based on a modular approach and is implemented on a test bench with the system directly integrated into the network traffic path. The study formulates requirements for the methodology, including universality, reproducibility, ease of use, and transparency of results analysis. Functional tests verify real-time attack blocking, logging accuracy, rule processing for various protocols, content filtering, and system behavior in failure mode. The article proposes an evaluation framework consistent with the recommendations of ISO/IEC 27034-1 and NIST SP 800-94. The developed solution enables independent, vendor-neutral comparative analysis of security measures, reduces testing costs, ensures test reproducibility, and enhances the soundness of security measure selection for critical infrastructure.