Intrusion detection system (IDS) : Investigating snort performance in windows and Ubuntu due to flooding attack / Abidah Mat Taib and Nur Syahirah Shayuthi

Mat Taib, Abidah and Shayuthi, Nur Syahirah (2017) Intrusion detection system (IDS) : Investigating snort performance in windows and Ubuntu due to flooding attack / Abidah Mat Taib and Nur Syahirah Shayuthi. Journal of Computing Research and Innovation (JCRINN), 2 (2): 3. pp. 18-25. ISSN 2600-8793

Abstract

Intrusion detection is an important technology that can help in managing threats and vulnerabilities in this changing environment. Computer technology is more and more ubiquitous, the penetration of computer in society is a welcome step towards modernization but society needs to be better equipped with challenges associated with technology. Thus, with the help of intrusion detection system (IDS) that can be used to monitor network for any attack and intrusion, it can reduce the security issues and help people to curb with the advance threat. This project aims to provide insight to small organization, employee and student to have a secure environment in their personal computer. The objectives of this project is to set up an isolate local area network (LAN) to imitate a real network environment using Graphical Network Simulator-3 (GNS3) and to create the scenario for analyzing Snort IDS performance in Windows and Ubuntu due to flooding attack. Basically, this project uses a router in GNS3 that can act as a real router. The IDS was implemented on the PC1 while PC2 acts as an attacker that send a flooding attack to PC 1. The timer was set for 2 minutes and the performance was analyzed based on drop packet and throughput. The result shows that the performance of Snort is better in Ubuntu compared to Windows in term of its drop packet and throughput.

Metadata

Item Type: Article
Creators:
Creators
Email / ID Num.
Mat Taib, Abidah
UNSPECIFIED
Shayuthi, Nur Syahirah
UNSPECIFIED
Subjects: T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring
T Technology > TK Electrical engineering. Electronics. Nuclear engineering > Telecommunication > Computer networks. General works. Traffic monitoring > Intrusion detection systems (Computer security). Computer network security. Hackers
Divisions: Universiti Teknologi MARA, Perlis > Arau Campus > Faculty of Computer and Mathematical Sciences
Journal or Publication Title: Journal of Computing Research and Innovation (JCRINN)
UiTM Journal Collections: UiTM Journal > Journal of Computing Research and Innovation (JCRINN)
ISSN: 2600-8793
Volume: 2
Number: 2
Page Range: pp. 18-25
Keywords: Intrusion Detection System, Snort, GNS3, performance analysis, flooding attack
Date: 2017
URI: https://ir.uitm.edu.my/id/eprint/54301
Edit Item
Edit Item

Download

[thumbnail of 54301.pdf] Text
54301.pdf

Download (581kB)

ID Number

54301

Indexing

Statistic

Statistic details