Implementação de um sistema de detecção de intrusão de redes de computadores na rede local de ensino

This work describes a implementation and tests of a network intrusion detection system in the local teaching network of the informatics department of the Technological Federal University of Paraná, using a Debian Linux server as a passive sensor connected in promiscuous mode in the main switch, the...

ver descrição completa

Autor principal: Effting, Cintia Elisa
Formato: Trabalho de Conclusão de Curso (Graduação)
Idioma: Português
Publicado em: Universidade Tecnológica Federal do Paraná 2020
Assuntos:
Acesso em linha: http://repositorio.utfpr.edu.br/jspui/handle/1/9812
Tags: Adicionar Tag
Sem tags, seja o primeiro a adicionar uma tag!
Resumo: This work describes a implementation and tests of a network intrusion detection system in the local teaching network of the informatics department of the Technological Federal University of Paraná, using a Debian Linux server as a passive sensor connected in promiscuous mode in the main switch, the Snort tool integrated with MySQL database, and the AcidBase web console. Four tests were performed in this implementation using penetration testing techniques.The work also covers a theoretical background about the intrusion detection systems, its main characteristics, its benefits and drawbacks, types (based in host, based in network, and hybrids), methodologies of detection (based in knowledge and based in behavior), and network position.