Network traffic monitoring and attack detection using snort tool

Mohd Ishak, Mohamad Hamizan and Abdul Halim, Syafnidar (2025) Network traffic monitoring and attack detection using snort tool. Progress in Computer and Mathematics Journal (PCMJ), 3. pp. 198-208. ISSN 3030-6728

Official URL: https://fskmjebat.uitm.edu.my/pcmj/

Abstract

Snort an open-source intrusion detection and prevention system (IDS/IPS), for monitoring network traffic and detecting Distributed Denial of Service (DDoS) attacks. The research addresses the growing concern of network vulnerabilities aggravated by the emergence of sophisticated DDoS attack techniques. A key objective is to design and customized Snort rules to identify and differentiate between normal and malicious network traffic, particularly focusing on TCP SYN flood and UDP flood attacks. The project using Hping3 tool to generate various traffic scenarios, facilitating comprehensive testing in both real-world and simulated environments. Performance evaluation metrics, including detection accuracy and confusion matrix analysis, are used to validate Snort effectiveness in identifying attack patterns. Results testing that the system achieves a detection accuracy of 100%, effectively mitigating threats by triggering alerts and proactively dropping malicious traffic. Although the project successfully proves real-time traffic monitoring and DDoS detection, limitations include the focus on specific protocols and reliance on predefined rules, which may not cover more sophisticated attack methods. Future enhancements suggest integrating visualization tools like Kibana and SIEM systems such as Sguil to improve analytics and response times. This research underscores the potential of Snort as a scalable and adaptable solution for modern network security challenges.

Metadata

Item Type: Article
Creators:
Creators
Email / ID Num.
Mohd Ishak, Mohamad Hamizan
mhamizan480@gmail.com
Abdul Halim, Syafnidar
syafnidar@uitm.edu.my
Subjects: T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring > Quality of service (Computer networks). Computer network management
Divisions: Universiti Teknologi MARA, Melaka > Jasin Campus > Faculty of Computer and Mathematical Sciences
Journal or Publication Title: Progress in Computer and Mathematics Journal (PCMJ)
ISSN: 3030-6728
Volume: 3
Page Range: pp. 198-208
Keywords: DDoS, Snort, IDS, IPS, Accuracy, Confusion metric
Date: November 2025
URI: https://ir.uitm.edu.my/id/eprint/127581
Edit Item
Edit Item

Download

[thumbnail of 127581.pdf] Text
127581.pdf

Download (1MB)

ID Number

127581

Indexing

Statistic

Statistic details