Repository logo
 
Publication

Open source IDS/IPS in a production environment: comparing, assessing and implementing

datacite.subject.fosDepartamento de Informáticapt_PT
dc.contributor.advisorMiranda, Hugo Alexandre Tavares, 1973-
dc.contributor.advisorBotas, Pedro Miguel Raminhos Ribeiro
dc.contributor.authorCalado, João Paulo da Costa
dc.date.accessioned2018-11-22T15:16:46Z
dc.date.available2018-11-22T15:16:46Z
dc.date.issued2018
dc.date.submitted2018
dc.descriptionTrabalho de projecto de mestrado, Segurança Informática, Universidade de Lisboa, Faculdade de Ciências, 2018pt_PT
dc.description.abstractThis work describes the realization of an IDS solution in a productive environment. It was intended to evaluate its feasibility comparing some options and thus opening the possibility of putting this solution in inline mode. Hence, the host organization may consider replacing a current security solution (proprietary hardware and software), with a Free Software or Open Source firewall and IPS. Typically the market presents products developed for this purpose using dedicated hardware, creating highly efficient and robust black boxes. For these products the manufacturers guarantee a series of commitments, taking advantage of high values for licensing, additional features or even product support. Sometimes these products are based on community projects being brought to market by vendors in proprietary variants. In this perspective, it was intended, in this work, to evaluate the possibility of creating a defense environment entirely based on alternatives to the manufacturers’, from the operating system to the application’s level evaluation layers. This work provides a series of laboratory simulations (using virtualization), the placement in staging of the IDS solution, the comparison of actual results with real traffic, and retrieving the physical evaluation of comparable resources. In this way an evaluation of this solution will be presented to the host organization so that an informed decision is made about its possible implementation in production, to replace a proprietary solution. We found that, in fact, it is possible to use commodity hardware to implement such solution in the tested environment, and with the presented traffic demand. At least one of the tested IDSs (Suricata) performed flawlessly, for several days, in a highly dense and complex network, where more than 3Gbps with peaks around 4.5Gbps were observed. The work also reports on scenarios where two concurrent instances were run, with each one inspecting a dedicated 10Gbps listening interface.pt_PT
dc.identifier.tid202191222
dc.identifier.urihttp://hdl.handle.net/10451/35418
dc.language.isoengpt_PT
dc.subjectIDSpt_PT
dc.subjectIPSpt_PT
dc.subjectSnortpt_PT
dc.subjectSuricatapt_PT
dc.subjectTrabalhos de projecto de mestrado - 2018pt_PT
dc.titleOpen source IDS/IPS in a production environment: comparing, assessing and implementingpt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameTrabalho de projecto de mestrado em Segurança Informáticapt_PT

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
ulfc121871_tm_João_Paulo_Calado.pdf
Size:
2.51 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.2 KB
Format:
Item-specific license agreed upon to submission
Description: